At its SwampIUP 2026 occasion in New York Metropolis, JFrog has unveiled DevGovOps for the AI-era – a brand new class of capabilities in JFrog AppTrust that automates governance throughout the software program provide chain to assist organizations hold tempo with agent-driven growth and rising regulatory calls for.
“AI is altering how software program will get constructed and shipped. Autonomous brokers are actually first-class members of our prospects’ growth groups, committing code and delivery releases at machine pace. The problem is – governance and compliance nonetheless run on human timelines. The truth is: governance can’t be one thing you do after the very fact, in a spreadsheet or a quarterly audit – it should be constructed into the discharge itself,” stated Shlomi Ben Haim, Co-Founder and CEO, JFrog. “With JFrog AppTrust, compliance enforcement is automated. It’s not about insurance policies and code. It’s about ensuring governance retains tempo together with your growth velocity – whether or not your code comes from a human or an agent. That’s the subsequent evolution of DevGovOps.”
Enterprises constructing AI factories face a elementary operational problem: autonomous brokers and AI-assisted builders can plan, code, check, and deploy in hours. Handbook governance processes take weeks. Moreover, regulatory necessities from the ECB AI Cyber Directive, EU Cyber Resilience Act (CRA), NIST SSDF, and FedRAMP mandate that organizations show lively compliance for each supported software program model or face steep fines and restrictions. For instance, CRA fines can attain as much as €15 million or 2.5% of worldwide annual turnover. Individually, beneath the EU’s NIS2 Directive, administration our bodies, together with named executives, can face private accountability, as much as short-term bans from managerial roles.
The 4 Dimensions of DevGovOps at Scale: Codify, Attest, Implement, Monitor
The brand new JFrog AppTrust capabilities embed governance into the software program provide chain throughout DevGovOps’s 4 steady pillars – Codify, Attest, Implement and Monitor – making governance an always-on property of the infrastructure, not a checkpoint utilized after the very fact.
- Codify: Automated coverage enforcement. For customized compliance insurance policies, JFrog’s AI-assisted Coverage-as-Code Playground lets safety groups write and validate governance guidelines in plain English – with no need Rego experience – then check in opposition to actual utility variations earlier than deployment. Validated insurance policies will be saved as reusable templates which can be then enforced constantly and deterministically throughout the group.
- Attest: Computerized evidence-based seize. Immediate-to-Launch Traceability collects approvals, builds, scans, and promotions with no handbook logging step, bridging the hole created by a scarcity of provenance in AI brokers. It connects the agent’s intent to the artifact that was shipped and delivers a full audit path for each agent resolution and consumed asset throughout the software program lifecycle.
- Implement: Coverage guardrails at machine pace. For widespread compliance necessities, JFrog affords new Out-of-the-Field (OOTB) Compliance Frameworks with pre-built guidelines aligned with regulatory requirements and mechanically enforced with one click on. Templates for CRA and NIST SSDF can be found now, with further requirements coming quickly.
- Monitor: DevGovOps that doesn’t cease on the launch gate. With Publish-Launch Governance, JFrog AppTrust extends compliance visibility with steady monitoring of each lively manufacturing model inside its help window, so organizations can show compliance and observe newly launched safety dangers at any time limit.
JFrog AppTrust will deliver DevGovOps at scale capabilities to JFrog Platform prospects in Q3 2026. To study extra about JFrog AppTrust and DevGovOps take a look at this weblog or register for the “Regain Management Over Compliance” webinar on Thursday, Oct. 1 at 11 AM PT/2 PM ET.






