Is Your Internal Platform Prepared for the Future?
The discussion regarding the necessity of an internal platform for enterprises has reached a conclusion. Google’s 2025 DORA research revealed that 90 percent of organizations now claim to utilize an internal platform, with 76 percent having created specialized platform teams. The inquiry for IT leaders has transformed from “should we develop a platform?” to “will the platform we’ve constructed endure the future?” The stark truth for most IT organizations is no — unless efforts are made. The platform established in recent years was intended for human developers delivering containerized applications at a human pace. That environment has passed.
AI and Platforms: A Transformative Era
Numerous influences have converged on platforms over the last two years, collectively revealing their vulnerabilities. At the core of each vulnerability lies infrastructure — the developer-focused foundation that was never intended to allocate GPUs on demand, govern AI agents, or implement cost management at the moment of allocation.
AI Coding Assistants: The New Standard
The majority of developers are currently utilizing AI coding assistants. AI-assisted development has achieved mainstream status, significantly boosting the volume of code that organizations can create and assess. The constraint has shifted. It’s no longer centered on writing code — it’s about delivering it. Your pipelines were never designed for that level of throughput, and the developer’s role has subtly evolved from author to reviewer and orchestrator of machine-generated content.
Who’s at the Door? AI Agents
Now there’s a completely new form of user at the door: the AI agent. This is the non-human identity that platform teams have increasingly been required to develop for over the past decade. Agents necessitate authentication, token usage oversight and management at both the organizational and user levels, GPU distribution, MCP compatibility, scoped permissions, non-human identities, audit logging, and strict boundaries regarding their permitted actions. Most platforms lack a built-in solution for any of these needs.
The Cost Control Challenge
Cost represents a third pressure point. According to Broadcom’s Private Cloud Outlook 2026 report, 97 percent of IT leaders believe a portion of their public cloud expenditures is squandered, with 52 percent estimating that this waste surpasses 25 percent of their overall public cloud budget. AI infrastructure exacerbates the situation significantly. GPU instances, inference endpoints, and training jobs overwhelm traditional spending. On top of this lies the cost associated with every prompt and retry — a category that many cost-tracking tools simply fail to recognize. Retrospective FinOps, the monthly evaluations and quarterly cleanup efforts, cannot identify a misconfigured AI workload that depletes the budget overnight.
The Security and Compliance Challenge
Privacy, security, and sovereignty complete the list. AI introduces extensive new attack surfaces — shadow AI expansion, prompt injection, model poisoning, inference data leaks — that no SAST or DAST scan in your pipeline was designed to detect. Simultaneously, the EU AI Act, US executive orders, and data residency regulations continue to impose additional compliance demands.
Platform Engineering 2.0: Growth, Not a Reconstruction
Here’s the essential message: none of this implies dismantling what you’ve constructed. The fundamentals — Platform as Product, golden paths, shift-left security, self-service Internal Developer Platforms (IDPs) — remain solid. The discipline does not restart at every new phase. It progresses. What is referred to as Platform Engineering 2.0 is an expansion of those fundamentals across five pillars, not a complete overhaul.
Pillars of Platform Engineering 2.0
The initial pillar is an AI-native platform. Your IDP evolves into what is increasingly termed an Agentic Development Platform (ADP), recognizing AI workloads as primary entities and AI agents as principal users. The same operational framework, but with a broadened foundation.
A Multi-Persona Interface
The second pillar is a multi-persona interface. Most platforms today cater well to application developers while relegating all others to a secondary status. This results in considerable unrealized value. Security teams, data scientists, ML engineers, FinOps analysts, business executives, and agents all require access to the platform, each needing their own interface built on shared APIs.
Integrated FinOps
The third pillar is integrated FinOps. The transition is from retrospective reporting to cost-related decisions being made during the provisioning stage. Each developer automatically becomes a FinOps participant — not via formal training, but because the platform presents cost data at the point of decision.
Security Moves Downstream
The fourth pillar involves security moving downstream. Shift-left security advanced protection earlier in the pipeline but placed the burden on developers, with many vulnerabilities still appearing in production. Moving downstream means integrating security into the platform and runtime layers themselves, making it seamless for developers and built to be unchangeable by design.
Designed for Composability
The fifth pillar is composable by design. The future does not hinge on build versus buy — it’s about composition. API-first, interchangeable building blocks allow you to swap one CI/CD tool or observability system without triggering cascading adjustments. The CNCF projects ecosystem has expanded from about 50 projects in 2018 to over 200 today; inflexible platforms cannot keep up with that diversity.
Getting Started: AI Native Platform Preparedness
Platform Engineering 2.0 begins with the modernization of that foundational infrastructure. Avoid attempting all five changes simultaneously. Assess your platform against its limitations and commence where the friction is greatest — that’s where you’ll have executive backing and a clear ROI narrative. For most organizations, the key 12-month target is AI-native readiness: support for GPU workloads; agent management; non-human identity capability; token economy; and MCP gateway exposure.
Review Your Platform
Begin by reviewing your current IDP for three shortcomings: GPU/accelerator provisioning; management of non-human identities; and immediate cost attribution at the time of provisioning. If all three are lacking, your platform is already falling behind. The teams that created golden paths for developer independence are now being entrusted with the keys to organization-wide agentic autonomy. This represents the most substantial mandate the discipline has ever faced. The opportunity is here, and the foundations are already established. What remains is the extension of them — before the platform becomes the very bottleneck it was created to eliminate.
Read more: Platform Engineering 2.0 whitepaper from Broadcom and Platformengineering.org — a comprehensive framework for this evolution: brcm.tech/PE2WhitePaper
Conclusion: Prevent Your Platform from Deteriorating
Contributed by Broadcom
Image alt tags: Platform Engineering 2.0 Insights for Techies