On October 1, IBM announced that Bob, its agentic software-development platform, is now generally available as a self-hosted deployment. The release lists the environments it now runs in, on-premises, private cloud, sovereign cloud and air-gapped, and names what stays inside the customer’s own infrastructure: “sensitive source code, application context, regulated customer information, and intellectual property.” Models can be ones the customer has licensed, or external model services reached through what IBM calls hybrid configurations. Neel Sundaresan, IBM’s General Manager of AI and Automation, put the reasoning in one sentence: “Organizations need AI that operates inside environments they have control over, especially when working with sensitive code and regulated data.”
Read that again with the vendor’s name removed and it is a statement about architecture, not about IBM. The largest enterprise software company in the world has decided that an AI coding agent belongs where the code lives, and has built the product to match. For anyone who read last week’s piece on why we built an on-prem version of Olakai, this is the same argument arriving one layer down the stack, from a company whose customers are the banks, insurers and governments that make the argument for a living.
Why IBM did it
IBM did not have to guess what its buyers wanted. In June its Institute for Business Value published a study of 1,000 senior executives across 16 countries, surveyed between February and April, and the numbers describe an enterprise that feels it has lost control of its own AI estate. Sixty-eight percent said meeting data-residency and sovereignty requirements across geographies is challenging. Seventy-one percent said switching their primary AI vendor or model would be difficult. Ninety-one percent admitted they do not fully understand their AI dependencies across vendors, models and infrastructure. Only 7% operate at what IBM calls an advanced level of AI control, and that small group protects 55% more operating profit from AI-driven disruption than everyone else. Perhaps most telling, 72% said they would accept a 20% cost increase in exchange for more strategic flexibility.
Ana Paula Assis, IBM’s Senior Vice President and Chair for EMEA and APAC, summarized the study this way: “AI has introduced new forms of dependency that evolve faster than traditional governance, procurement, or technology cycles were designed to handle.” Self-hosted Bob is IBM’s product answer to its own research, and it lands in a market that was already moving. The repatriation and sovereign-cloud data we covered last week, from Cloudian, Broadcom and Gartner, point the same way: the buyer has decided that the model, the data and the tooling will sit inside a boundary they control, and vendors can either meet them there or lose the deal.
The layer IBM’s release does not mention
Here is what the announcement describes: where the agent runs, what data it keeps inside the perimeter, which models it can call. Here is what it does not describe: how an enterprise will know whether that agent is earning its cost, what it touched, which developers are using it well, and how its output compares with the three other coding tools the same engineering organization is almost certainly running. That is not a criticism of IBM. A coding agent’s job is to write software, and measurement and governance belong to a different layer. But it is the layer that decides whether the deployment was worth it, and it has a location too.
Follow the data path. An enterprise moves its coding agent on-prem so that source code, application context and regulated customer information never leave. Then it adopts a SaaS tool to measure that agent’s productivity and govern what it does. That tool ingests pull requests, repository metadata, developer identities, spend, and in many cases the prompts and sessions themselves, and sends all of it to a vendor’s multi-tenant cloud. The code stayed home. The record of everything that happened to the code went back out the door. Every argument that justified self-hosting the agent applies with at least equal force to the system that watches the agent, because that system holds a more complete picture of the engineering organization than any single tool ever will.
This is why Olakai Enterprise runs the same platform on-prem that it runs as SaaS: one Linux VM you own, your choice of analysis model, and nothing leaving your network when you route that analysis to a server inside it. A regulated enterprise that has just brought its coding agent inside the boundary should expect the measurement and governance layer to come with it, under the same deployment review and the same network allowlist, rather than being the one AI tool in the stack that is still phoning home.
What this means for a multi-vendor tool stack
Two more numbers from the IBM study matter here. Seventy-three percent of executives describe their AI environment as intentionally multi-vendor, and 71% say switching their primary vendor would be hard. Both are true at once in most engineering organizations we see: Cursor on one team, GitHub Copilot on another, Claude Code for the platform group, and now perhaps Bob for the modernization program that touches the mainframe. Nobody is going to standardize on one, and nobody can easily leave any of them. The only way to compare them fairly is to measure from a vantage point none of them controls.
That vantage point is the repository. Olakai Agentic detects AI-assisted work from pull-request data in your own version control: bot authors, co-author trailers and PR markers, with a classifier reading the gray-area pull requests that carry no machine-readable signature. Because the signal comes from your repositories rather than from any tool’s own telemetry, it does not matter whether the agent that wrote the code ran in a vendor’s cloud or on a server in your basement, and it does not matter when you swap one agent for another. The spend, adoption cohorts and cycle-time deltas are computed against the same baseline for every tool. That is what a vendor-neutral AI system of record is for: it is the one part of the stack that is supposed to outlive every vendor decision, which is exactly the flexibility 72% of IBM’s respondents said they would pay a premium for.
What leaders should do this quarter
For a VP of Engineering or CISO evaluating self-hosted Bob, or any coding agent moving inside the perimeter, the practical rule is that governance telemetry follows the workload. If the agent passes a deployment review, a network allowlist and a data-classification check, the system that measures and governs it should pass the same three, in the same environment, before either goes live. Ask every vendor in the stack the question IBM’s buyers evidently asked IBM: where does our data go, and can we make the answer “nowhere”?
For a CFO, the IBM study’s most useful line is the 7% who protect 55% more operating profit through control of their AI stack. Control is not a security slogan; it shows up in the P&L. Insist that the ROI evidence for every AI coding investment is computed where the data already sits, by a system that does not depend on the vendor being measured, so the number survives both the audit and the next vendor change. Paul made the cost half of this case in July, when IBM’s own AI bill was the story; the sovereignty half is what October added.
IBM has now said out loud what regulated buyers have been saying in procurement for two years: the agent runs where the code lives. The organizations that get this right will govern and measure AI from inside the same walls, with Olakai or something like it. The ones that do not will eventually find that the single AI tool still sending data out of the building is the one they bought to keep an eye on all the others.
Bringing a coding agent inside your perimeter? Talk to an expert about measuring and governing it from the same place.
