Key Takeaways

  • Nick Kuhn spent 14 years inside large corporate IT environments before his 5 years at VMware Tanzu, learning that assuming external internet access kills enterprise deals on day one.
  • Real enterprise deployments frequently enforce physical airgaps where engineers must walk hardware and code directly into data centers with zero outside web access.
  • Enterprise AI systems must satisfy strict compliance regimes like PCI, SOX, HIPAA, and FIPS rather than sending raw internal data to public API endpoints.
  • Network physics ruin agent performance when a model sits 30 network hops away from the production microservices or CI/CD pipelines calling it.
  • Public cloud model providers suffer unexpected outages that violate the strict reliability demands and service level agreements required by large corporations.

The Airgap Trap

When startup founders pitch AI agents to enterprise buyers, they usually bring a cloud demo powered by external third-party APIs. Nick Kuhn spent 14 years inside corporate IT environments before joining VMware Tanzu. He watched vendor after vendor make the exact same mistake.

“When we had vendors come in, it would always be like they would always assume that we could just go to the Internet,” Kuhn said. “And it was always like, 'Well, try again, cuz that's not going to work here.'”

Large enterprise installations often run without public internet connectivity. Kuhn pointed out that some of his customers “actually have the real airgap where we're carrying in things, you know, physically into the data center because there is no Internet access type of thing.” If an agent architecture depends on outbound calls to commercial model APIs or remote context stores, it will not pass the security review.

Compliance and the Physics of Latency

Selling software to high-stakes buyers means meeting regulatory mandates including PCI, SOX, HIPAA, and FIPS. Kuhn noted that enterprise operators must constantly handle “all the different compliance tiers that you have to deal with.” Pushing proprietary customer data or financial records across the public internet violates these compliance baselines immediately.

Even when compliance allows external connections, network physics will throttle agent execution if the compute is separated from internal applications. Kuhn explained that companies need AI execution embedded directly beside their operational software:

"Enterprises want agents to be on demand and like usable kind of in a say in a CI/CD pipeline or like on, you know, within part of their you know e-commerce suite or just just normal applications, and you want those to be... kind of really close to the apps, right? Because if you're if you have them way off, you know, even just from a pure networking perspective, if you have, you know, the agent, or the LLM, or whatever that's like, you know, 30 hops away from the the microservice that's trying to call it, there's you know physics that are going to add on to all of that latency and potentially at scale even be problematic."

When an agent performs multi-step reasoning cycles, latency accumulates with every single network hop. A delay of several hundred milliseconds per request compounds quickly, creating unacceptable lag in e-commerce workflows and automated deployment pipelines.

Why Consumer SaaS Reliability Fails in Production

External SaaS model providers create serious availability risks for critical workflows. A two-hour outage is a minor inconvenience for consumer apps, but it halts production lines and revenue engines in enterprise settings.

As Kuhn put it: “And not to mention, if you're using some of these SaaS providers, they're maybe not the most reliable in terms of what traditional enterprises expect and demand. So you can't just have them, you know, going offline for hours.”

Building agentic software for large buyers requires moving away from pure cloud-hosted dependencies. Successful enterprise architectures prioritize local execution, private model deployments, and tight co-location with the core application database.

What to Do With This

Disconnect your development machine from Wi-Fi and attempt to run your agent locally. If your agent fails to initialize, retrieve context, or run its inference loop without active internet calls, spend this sprint building a self-contained runtime that can run on isolated enterprise infrastructure.