JFrog Delivers DevGovOps at Scale: Continuous Compliance for theAI-Era Software Supply Chain

JFrog Ltd. the Liquid Software company and creators of the JFrog Software
Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI
assets, today unveiled DevGovOps for the AI-era – a new class of capabilities in JFrog
AppTrust that automates governance across the entire software supply chain to help
organizations keep pace with agent-driven development and growing regulatory demands.
“AI is changing how software gets built and shipped. Autonomous agents are now first-class
members of our customers’ development teams, committing code and shipping releases at
machine speed. The challenge is – governance and compliance still run on human timelines.
The reality is: governance can’t be something you do after the fact, in a spreadsheet or a
quarterly audit – it must be built into the release itself,” said Shlomi Ben Haim, Co-Founder
and CEO, JFrog. “With JFrog AppTrust, compliance enforcement is automatic. It’s not about
policies and code. It’s about making sure governance keeps pace with your development
velocity – whether your code comes from a human or an agent. That’s the next evolution of DevGovOps.”


Enterprises building AI factories face a fundamental operational challenge: autonomous
agents and AI-assisted developers can plan, code, test, and deploy in hours. Manual
governance processes take weeks. Additionally, regulatory requirements from the ECB AI
Cyber Directive, EU Cyber Resilience Act (CRA), NIST SSDF, and FedRAMP mandate that
organizations prove active compliance for every supported software version or face steep
fines and restrictions. For example, CRA fines can reach up to €15 million or 2.5% of global
annual turnover. Separately, under the EU’s NIS2 Directive, management bodies, including
named executives, can face personal accountability, up to temporary bans from managerial
roles.
The Four Dimensions of DevGovOps at Scale: Codify, Attest, Enforce, Monitor
The new JFrog AppTrust capabilities embed governance into the software supply chain
across DevGovOps’s four continuous pillars – Codify, Attest, Enforce and Monitor – making
governance an always-on property of the infrastructure, not a checkpoint applied after the fact.

Codify: Automated policy enforcement. For custom compliance policies, JFrog’s AIassisted Policy-as-Code Playground lets security teams write and validate governance
rules in plain English – without needing Rego expertise – then test against real
application versions before deployment. Validated policies can be saved as reusable
templates that are then enforced consistently and deterministically across the
organization.
● Attest: Automatic evidence-based capture. Prompt-to-Release Traceability collects
approvals, builds, scans, and promotions with no manual logging step, bridging the
gap created by a lack of provenance in AI agents. It connects the agent’s intent to the
artifact that was shipped and delivers a full audit trail for every agent decision and
consumed asset across the software lifecycle.
● Enforce: Policy guardrails at machine speed. For common compliance
requirements, JFrog offers new Out-of-the-Box (OOTB) Compliance Frameworks with
pre-built rules aligned with regulatory standards and automatically enforced with one
click. Templates for CRA and NIST SSDF are available now, with additional standards
coming soon.
● Monitor: DevGovOps that doesn’t stop at the release gate. With Post-Release
Governance, JFrog AppTrust extends compliance visibility with continuous monitoring
of every active production version within its support window, so organizations can
prove compliance and track newly introduced security risks at any point in time.

Governance no longer has to slow teams down and control doesn’t have to be feared. JFrog
AppTrust will bring DevGovOps at scale capabilities to JFrog Platform customers in Q3 2026.
To learn more about JFrog AppTrust and DevGovOps check out this blog or register for the
“Regain Control Over Compliance” webinar on Thursday, October 1 at 11 AM PT/2 PM ET.

Share on