IBM Brings Bob to Self-Hosted and Air-Gapped Environments: Agentic Software Development Without Moving Your Code

IBM has released its self-hosted version of Bob, an agentic software development platform, for general availability. Enterprises can now run the system…

By Vane October 3, 2026 3 min read
IBM Brings Bob to Self-Hosted and Air-Gapped Environments: Agentic Software Development Without Moving Your Code

IBM has released its self-hosted version of Bob, an agentic software development platform, for general availability. Enterprises can now run the system on-premises, in private clouds, or within air-gapped networks without moving their code to the public internet. Customers must source and license their own supported models to operate the environment.

What IBM shipped at general availability

The new deployment option allows Bob to function inside customer-managed enterprise environments. It retains core capabilities such as the IDE experience, BobShell, parallel tool calling, the agent harness, and various skills and modes. The system supports self-hosted, air-gapped, and hybrid model configurations.

Eligible users can bring their own license for models on IBM’s supported list. The package includes integration with supported IDEs and infrastructure environments. Optional Premium Packages are available for Java modernization, IBM i, and IBM Z.

The model layer decides where inference runs

Bob self-hosted does not bundle a model. Customers must select one from IBM’s supported list. The vendor groups these options by deployment method:

Deployment methodWho hosts the modelSupported models at GA
Self-hostedCustomer, on its own infrastructureNVIDIA Nemotron, Poolside Laguna
Hybrid or private SaaSExternal service via an approved private connectivity patternClaude Sonnet 5.0, Claude Opus 4.8, Gemini 3.7 Flash, OpenAI GPT 5.6 Sol

This choice determines where code and context get processed. With a self-hosted model, development context and build artifacts remain inside the customer environment.

IBM cites a bank as a concrete example. The institution could run on-premises inference for core banking applications while routing less restricted workloads to an approved external model. Developers see a consistent core Bob experience in both cases, while security teams control the underlying architecture.

IBM plans to expand the model portfolio and add multi-model routing. Treat that as a roadmap item, not a shipped feature.

How Bob self-hosted compares with its closest competitors

FeatureIBM Bob (self-hosted)GitLab Duo Agent Platform Self-HostedMistral Vibe for Code (Enterprise)GitHub Copilot CLI (BYOK)
On-prem or private cloudYesYes, on GitLab Self-ManagedYes, on-prem or private cloudCLI only; core Copilot runs on GitHub.com or GHE.com
Air-gappedYes, with supported self-hosted modelsYes, with an offline licenseOpen-weight Devstral models suit air-gapped useYes, offline mode with a local model
Hybrid local plus external modelsYes, per workloadYes, hybrid AI GatewayOn-prem, private cloud or Mistral CloudYes, via BYOK providers
Models when self-hostedNVIDIA Nemotron, Poolside LagunaSupported list on vLLM, Bedrock or Azure OpenAIMistral models, fine-tuning via ForgeAny provider with tool calling and streaming
Developer surfacesIDE, BobShellGitLab UI, IDE, CLI (beta)CLI; VS Code, JetBrains, ZedTerminal
Commercial modelEnterprise, via IBM salesPremium or Ultimate plus add-onEnterprise, contact salesNo Copilot license needed with BYOK

Sources: IBM, GitLab docs, Mistral Vibe, Mistral coding stack, GitHub changelog, GitHub Docs.

The differentiator is scope. GitLab and GitHub bring agents to their own DevOps platforms. Mistral pairs its agent with its own open-weight models. IBM targets modernization of long-lived estates, especially Java, IBM i and mainframe code, inside environments that cannot touch the public internet.

What it means for developers and security teams

The release changes the operational reality for large organisations with strict data governance rules. Previously, using an agentic developer required sending code to external services. Now, teams can keep all processing local. This allows security teams to approve the architecture without blocking development velocity. Developers retain a consistent interface whether running internal models or approved external ones. The main constraint remains the need to manage and license the underlying AI models separately.

Scroll to Top