At its SwampIUP 2026 occasion in New York Metropolis, JFrog has unveiled DevGovOps for the AI-era – a brand new class of capabilities in JFrog AppTrust that automates governance throughout the software program provide chain to assist organizations maintain tempo with agent-driven improvement and rising regulatory calls for.
“AI is altering how software program will get constructed and shipped. Autonomous brokers at the moment are first-class members of our clients’ improvement groups, committing code and transport releases at machine pace. The problem is – governance and compliance nonetheless run on human timelines. The truth is: governance can’t be one thing you do after the actual fact, in a spreadsheet or a quarterly audit – it should be constructed into the discharge itself,” mentioned Shlomi Ben Haim, Co-Founder and CEO, JFrog. “With JFrog AppTrust, compliance enforcement is automated. It’s not about insurance policies and code. It’s about ensuring governance retains tempo along with your improvement velocity – whether or not your code comes from a human or an agent. That’s the following evolution of DevGovOps.”
Enterprises constructing AI factories face a elementary operational problem: autonomous brokers and AI-assisted builders can plan, code, check, and deploy in hours. Guide governance processes take weeks. Moreover, regulatory necessities from the ECB AI Cyber Directive, EU Cyber Resilience Act (CRA), NIST SSDF, and FedRAMP mandate that organizations show energetic compliance for each supported software program model or face steep fines and restrictions. For instance, CRA fines can attain as much as €15 million or 2.5% of worldwide annual turnover. Individually, underneath the EU’s NIS2 Directive, administration our bodies, together with named executives, can face private accountability, as much as short-term bans from managerial roles.
The 4 Dimensions of DevGovOps at Scale: Codify, Attest, Implement, Monitor
The brand new JFrog AppTrust capabilities embed governance into the software program provide chain throughout DevGovOps’s 4 steady pillars – Codify, Attest, Implement and Monitor – making governance an always-on property of the infrastructure, not a checkpoint utilized after the actual fact.
- Codify: Automated coverage enforcement. For customized compliance insurance policies, JFrog’s AI-assisted Coverage-as-Code Playground lets safety groups write and validate governance guidelines in plain English – without having Rego experience – then check towards actual software variations earlier than deployment. Validated insurance policies may be saved as reusable templates which might be then enforced persistently and deterministically throughout the group.
- Attest: Computerized evidence-based seize. Immediate-to-Launch Traceability collects approvals, builds, scans, and promotions with no handbook logging step, bridging the hole created by an absence of provenance in AI brokers. It connects the agent’s intent to the artifact that was shipped and delivers a full audit path for each agent determination and consumed asset throughout the software program lifecycle.
- Implement: Coverage guardrails at machine pace. For frequent compliance necessities, JFrog affords new Out-of-the-Field (OOTB) Compliance Frameworks with pre-built guidelines aligned with regulatory requirements and mechanically enforced with one click on. Templates for CRA and NIST SSDF can be found now, with extra requirements coming quickly.
- Monitor: DevGovOps that doesn’t cease on the launch gate. With Publish-Launch Governance, JFrog AppTrust extends compliance visibility with steady monitoring of each energetic manufacturing model inside its assist window, so organizations can show compliance and monitor newly launched safety dangers at any time limit.
JFrog AppTrust will carry DevGovOps at scale capabilities to JFrog Platform clients in Q3 2026. To be taught extra about JFrog AppTrust and DevGovOps take a look at this weblog or register for the “Regain Management Over Compliance” webinar on Thursday, Oct. 1 at 11 AM PT/2 PM ET.
