Research Notes

Are Unmanaged AI Agents Creating Massive Enterprise Risk?

Research Finder

Find by Keyword

Are Unmanaged AI Agents Creating Massive Enterprise Risk?

Red Hat AI 3.5 addresses production-scale challenges with verifiable safety, advanced multi-tenancy, and robust governance for agentic applications.

9/11/2026

Key Highlights

  • Red Hat AI 3.5 aims to bridge the gap between isolated AI pilots and a fully governed enterprise architecture across hybrid cloud environments.
  • The platform introduces EvalHub for risk-focused safety benchmarking and verifiable compliance reporting before model deployment.
  • Advanced multi-tenancy is architected to allow shared GPU control through fair-share scheduling and priority-aware request routing.
  • AutoRAG and inference-time scaling are designed to dynamically adapt compute usage based on query complexity while grounding data securely.
  • Support for multi-cloud Kubernetes serving extends deployment flexibility across platforms like Microsoft Azure, CoreWeave, and Amazon EKS.

The News

Red Hat announced the general availability of Red Hat AI 3.5, introducing significant updates designed to scale and govern AI agents in production environments. This release aims to deliver verifiable trust, operational control, and performance transparency for running AI as a shared enterprise service. The platform enhancements target the operational rigor required to transition AI from experimental pilots to mission-critical infrastructure. Find out more by clicking here to read the press release.

Analyst Take

The enterprise AI landscape is rapidly maturing. We see a clear transition from isolated experimentation to demanding operational deployment. Organizations are realizing that building a pilot is easy, but running it securely at scale is incredibly difficult. This is the reality. Recent research from the HyperFRAME Lens indicates that 72% of global enterprises identify operationalizing AI across hybrid environments as their primary infrastructure hurdle. Platform engineering teams are now tasked with providing the same level of rigor for machine learning workloads as they do for traditional mission-critical infrastructure. Red Hat AI 3.5 is designed to address this exact operational friction.

What was Announced

Red Hat AI 3.5 introduces a comprehensive suite of features architected to scale and govern AI agents in production. A cornerstone of this release is EvalHub, which aims to automate safety and compliance reporting for custom models, retrieval-augmented generation systems, and agentic workflows. This tool is designed to allow organizations to verify models before deployment through risk-focused safety benchmarking. The updated platform also features evaluated catalog models with built-in Garak benchmark scores for toxicity, personally identifiable information exposure, and overall safety. This provides full transparency.

To support advanced multi-tenancy, the release officially supports running on Red Hat OpenShift hosted control planes deployed on OpenShift Virtualization. This architecture is designed to give every tenant a dedicated cluster control plane while consolidating the underlying hardware. Furthermore, running AI workloads in OpenShift Virtualization virtual machines adds robust isolation across shared GPU infrastructure. The platform introduces fair-share GPU scheduling to manage resource allocation across tenants, alongside priority-aware serving that provides admission control and request routing.

For agentic development, Red Hat aims to accelerate time-to-market with AutoRAG, which links enterprise data repositories directly to applications. This tool introduces capabilities such as multilingual document support, conversational testing, and contextual retrieval. Once deployed, Inference-Time Scaling is architected to optimize GPU spend by dynamically adjusting compute resources based on query complexity. The platform also introduces AI Hub, which delivers pre-configured agent templates and starter kits for common enterprise patterns like code review and document processing. These templates integrate frameworks and deployment configurations to run in sandboxed environments with operational controls intact.

Additionally, the platform expands its multi-cloud Kubernetes serving capabilities. It extends distributed inference beyond OpenShift onto third-party services, offering a consistent model serving experience. This functionality is now generally available on CoreWeave CKS and Microsoft Azure, with Amazon EKS joining as a technology preview. Red Hat AI 3.5 also includes efficient GPU memory management through CPU offloading and a developer preview of storage offloading, which are designed to allow models to handle larger documents without requiring additional hardware. Multimodal serving for text, audio, and image generation is available in early access via vLLM Omni, and a developer preview of the Kubeflow Spark Operator brings distributed data processing directly into the active workbench environment.

We view these technical enhancements as a necessary evolution for the company. By unifying safety, multi-tenancy, and observability into a single enterprise platform, Red Hat aims to deliver accountability to AI architectures. The introduction of non-admin observability dashboards for per-user token metering and GPU utilization brings much-needed cost transparency to platform teams. This level of showback capability is essential. It enables organizations to accurately track inference health and assign costs across different business units sharing the same infrastructure.

The integration of native NeMo Guardrails to intercept malicious tool calls demonstrates a serious commitment to secure agent APIs. We observe that securing the response gateway is just as critical as optimizing the underlying model. When you combine this gateway security with pgvector support for enterprise data grounding, the platform offers a robust environment for efficient reasoning. The inclusion of validated tool-calling models from providers like Google, NVIDIA, and Alibaba Cloud within the catalog gives customers a curated starting point for building complex, multi-turn agent conversations. Providing over 20 new validated models ensures that developers have access to top-tier foundation models that are already benchmarked for enterprise use.

Traffic management and safe model updates are also heavily prioritized in this release. Priority-aware serving is architected to protect real-time inference while allowing background workloads to consume available capacity. Controlled model rollout manages traffic dynamically during updates, which is designed to enable safe transitions with minimal service disruption. We believe this focus on continuous availability will resonate strongly with infrastructure providers who need to operate and upgrade environments from a single point of control. Ultimately, Red Hat AI 3.5 is architected to move artificial intelligence out of the experimental sandbox and into the core of enterprise IT operations.

Looking Ahead

Based on what we are observing in the broader enterprise software ecosystem, the transition toward autonomous agentic workflows represents a significant tectonic shift in compute paradigms. The key trend that we are going to be looking out for is how efficiently large organizations can operationalize these governed AI architectures without introducing untenable latency or bottlenecking developer productivity. The announcement from Red Hat is architected to systematically dismantle the fragmented, proprietary tooling frameworks currently dominating the landscape. Our perspective is that open-source, hybrid cloud abstractions will ultimately deliver the most sustainable trajectory for enterprises seeking to mitigate vendor lock-in with major hyperscalers.

The regulatory environment now demands rigorous compliance. Going forward, we are going to be closely monitoring how the company performs on driving enterprise adoption for its EvalHub and AutoRAG frameworks. These features are highly sophisticated, but their commercial success depends entirely on seamless integration into existing development pipelines. HyperFRAME will be tracking how the company does in capturing substantive market share among highly regulated industries in future quarters. Competitors are also aggressively expanding their AI infrastructure plays, but Red Hat's deep integration with OpenShift provides a distinct structural advantage for containerized workloads. We see this clearly. If Red Hat can successfully demonstrate that its platform lowers the total cost of ownership through granular resource controls, it will secure a formidable position as the de facto control plane for enterprise AI.

Author Information

Steven Dickens | CEO HyperFRAME Research

Regarded as a luminary at the intersection of technology and business transformation, Steven Dickens is the CEO and Principal Analyst at HyperFRAME Research.
Ranked consistently among the Top 10 Analysts by AR Insights and a contributor to Forbes, Steven's expert perspectives are sought after by tier one media outlets such as The Wall Street Journal and CNBC, and he is a regular on TV networks including the Schwab Network and Bloomberg.