Cyber security data privacy concept on virtual screen.
Home Page Products & Services VMware vSphere Foundation

Your First Line of Defense: How VMware vSphere Foundation 9.1 Addresses AI-Era Security Threats

The AI era has reshaped what it means to keep infrastructure secure. The most urgent shift is not the workloads themselves. It is how AI is being used against organizations. Frontier AI security models are now capable of what researchers call “vulnerability chaining”—combining two or three low-severity findings into a single, critical exploit path. That capability operates at a velocity and volume that traditional security operations were never designed to handle. AI workloads also expand the physical attack surface: accelerated hardware, high-speed data movement, large memory pools, and continuous operation leave fewer natural windows for patching and remediation.

The question many IT leaders are asking right now is not whether they need to modernize their security posture. It is how to do that without disrupting what is already running, and without committing to a full platform overhaul before the organization is ready.

VMware vSphere Foundation (VVF) 9.1 addresses that question directly. We designed this release to deliver a security-by-default infrastructure that protects modern workloads, including AI and machine learning environments, without requiring a full platform overhaul. It is built for organizations that need to act now and build toward the future.

76.5% of enterprises report a lack of confidence in their ability to recover from a sophisticated infrastructure-level cyberattack. [1] VVF 9.1 is designed to close that gap.

Figure 1: VVF 9.1 Security Layer Architecture: hardware (TPM 2.0, Intel QAT), hypervisor (Live Patching, FIPS 140-2), operations (VCF Operations compliance dashboards)

Security Built into the Platform, Not Bolted On

Legacy security models treat hardening as a Day 2 operation, something applied after deployment through manual processes, scheduled audits, and periodic patch windows. VMware vSphere Foundation 9.1 inverts that model. Security is the default state, not a configuration target.

Live Patching for hosts equipped with a Trusted Platform Module (TPM) is a clear execution of this philosophy. Security updates can now be applied without taking hosts offline or evacuating virtual machines. The result is zero downtime for up to 80% of security patches [2], eliminating the gap between vulnerability disclosure and remediation that has historically been an attacker’s opportunity.

Encrypted vMotion with Intel QAT extends that protection to data in motion. Workload migrations, including AI inference jobs and GPU-backed training tasks, are encrypted end to end, with hardware acceleration offloading the cryptographic work to dedicated silicon. Source CPU consumption drops by up to 70% [2], removing the historical performance trade-off that caused many teams to skip encryption during high-velocity migrations.

FIPS 140-2 compliance is enabled out of the box. TLS 1.3 is the default transport protocol. TPM 2.0 attestation, VM encryption, vSphere Trust Authority, and identity federation with Microsoft Active Directory, Entra ID, ADFS, PingFederate, and Okta are all included.

Visibility Is Half the Battle

Security failures do not always begin with an attack. They often begin with a blind spot: a transient anomaly that existing monitoring tools averaged away, a misconfiguration that drifted undetected, a compliance gap that only surfaced at the quarterly audit.

VMware vSphere Foundation 9.1 addresses this with high-fidelity telemetry that captures granular data across ESXi, vCenter, and vSAN at sub-minute intervals. Traditional five-minute polling averages suppress exactly the kind of transient spikes that matter in AI workload environments. With VVF 9.1, those spikes are visible and actionable in real time.

The built-in compliance framework covers NIST SP 800-171, NIST SP 800-53 R5, CIS, PCI DSS 4.0, ISO/IEC 27001:2022, and HIPAA. When benchmarks are active in the platform, drift is detected and remediated continuously rather than discovered at the next scheduled review.

Figure 2: VVF 9.1 Compliance Coverage Map: NIST SP 800-171, NIST SP 800-53 R5, CIS, PCI DSS 4.0, ISO/IEC 27001:2022, HIPAA, FIPS 140-2, TLS 1.3

Securing AI Without Sacrificing Infrastructure Economics

DRAM prices surged between 80 and 170% year over year in 2026, driven largely by AI demand [3]. Enterprises deploying AI workloads are managing a new threat landscape while simultaneously managing a hardware cost crisis. VMware vSphere Foundation 9.1 addresses both pressures.

NVMe Memory Tiering expands effective memory capacity without additional DRAM investment, offloading 20 to 25% of memory accesses to high-performance NVMe [2]. GPU vMotion is now up to 6x faster [2], enabling AI training and inference workloads to migrate cleanly during maintenance without interrupting model execution. Monster VM support covers up to 960 vCPUs and 16TB of memory per VM, ensuring that large AI workloads run without artificial infrastructure constraints. Together, these capabilities establish a private infrastructure that can run AI workloads securely, observe them precisely, and protect them continuously.

A Strong Foundation. A Clear Path Forward.

VMware vSphere Foundation 9.1 delivers enterprise-grade security for organizations that need to act now, without waiting for a full platform migration. It provides live patching, hardware-accelerated encryption, continuous compliance monitoring, and high-fidelity telemetry on a platform that integrates naturally with existing vSphere environments.

For organizations ready to go further, to add full network security with NSX, extended automation, sovereign AI infrastructure, and advanced cyber recovery, VMware Cloud Foundation (VCF) 9.1 is the comprehensive private cloud platform built for that level of scale. VVF 9.1 does not just protect your infrastructure today. It positions organizations to make that transition on their terms, at their pace, without disruption. By standardizing on VVF 9.1 now, organizations establish the security foundation they need today and the architectural readiness for VMware Cloud Foundation 9.1 when the time is right.

Guidance for Existing VVF Deployments

Broadcom is analyzing in-support VMware products using frontier AI security models. For vSphere 8.x, VCF/VVF 5.x, and VCF/VVF 9.0 environments, patch releases will continue on the existing schedule based on Broadcom’s standard Security Advisory processes. The overall guidance for existing deployments is to upgrade to VCF/VVF 9.1 as soon as possible to access its enhanced security capabilities. To make adoption easier, VVF 9.1 supports new upgrade paths from vSphere 8.x and VVF 5.x environments. Upgrading from VVF 9.0 to VVF 9.1 is a seamless, in-place process.

Work with your Broadcom team to get to VVF 9.1

Broadcom is committed to delivering the most secure platform possible for our customers. The new reality is that organizations must adapt to the latest phase of cybersecurity risk with urgency. Speed is no longer optional in secured environments. Upgrading to VVF 9.1 puts the enhanced security capabilities you need in place now. Contact your Broadcom account team or Broadcom partner to conduct a VVF 9.1 upgrade readiness review, and accelerate the process through professional services.

Explore the latest resources:

Sources:

Disclaimer: All performance and cost improvement claims based on Broadcom internal engineering estimates and hardware test results, 2026, unless otherwise specified. Results subject to change.


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.