<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/devgovops-how-the-ai-era-dictates-that-governance-lives-inside-the-pipeline-cuwlmhazh" -->

---
title: DevGovOps: How the AI Era Dictates That Governance Lives...
description: JFrog argues that AI coding agents break traditional human-in-the-loop compliance models, since agents can plan, write, review, and ship code without human...
canonical: https://daily.dev/posts/devgovops-how-the-ai-era-dictates-that-governance-lives-inside-the-pipeline-cuwlmhazh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: DevGovOps: How the AI Era Dictates That Governance Lives inside the Pipeline | daily.dev
og:description: JFrog argues that AI coding agents break traditional human-in-the-loop compliance models, since agents can plan, write, review, and ship code without human...
og:url: https://daily.dev/posts/devgovops-how-the-ai-era-dictates-that-governance-lives-inside-the-pipeline-cuwlmhazh
og:image: https://api.daily.dev/og/posts/cUwlMhAzH.png
og:image:alt: DevGovOps: How the AI Era Dictates That Governance Lives inside the Pipeline
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# DevGovOps: How the AI Era Dictates That Governance Lives inside the Pipeline

**[JFrog](https://daily.dev/sources/jfrog)** · 6 min read · 1 upvotes · 0 comments

## Summary

JFrog argues that AI coding agents break traditional human-in-the-loop compliance models, since agents can plan, write, review, and ship code without human approval. It cites the August 2026 Shai-Hulud npm worm (1,300+ compromised package versions, ~2 billion monthly installs) and regulatory pressure from CRA, NIST SSDF, DORA, and FedRAMP, plus an ECB directive requiring European bank CEOs to submit AI-threat action plans by October 31st. The proposed solution is 'DevGovOps' - embedding governance directly into the pipeline via four dimensions (Codify, Attest, Enforce, Monitor). JFrog positions its AppTrust product, with capabilities announced at swampUP 2026 (Policy-as-Code Playground, Prompt-to-Release Traceability, Out-of-the-Box Compliance Frameworks, Post-Release Governance), as the implementation of this model.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://jfrog.com/blog/devgovops-to-prove-compliance>

## Questions this post answers

### What was the Shai-Hulud npm worm and how many packages did it affect?

The Shai-Hulud worm was a supply chain attack that compromised more than 1,300 versions of widely used npm packages, reaching an estimated 2 billion monthly installs before defenders could fully contain it. It resurfaced in August 2026, illustrating how quickly a compromised package can spread through the npm ecosystem before detection.

_Teams tracking npm supply chain threats can follow developments like this one on daily.dev._

### What fines can companies face under the EU Cyber Resilience Act (CRA)?

The EU Cyber Resilience Act carries fines of up to 2.5% of global annual revenue for non-compliance, and it shifts personal legal liability directly onto CISOs and executive leadership rather than just the organization. This makes software supply chain governance a direct executive accountability issue, not only a technical one.

_Security leaders weighing CRA exposure can track compliance and supply chain coverage on daily.dev._

### What did the European Central Bank require European banks to do about AI-driven cyber threats?

In July 2026 the European Central Bank directed the CEOs of every major European bank to submit a concrete action plan by October 31st, including named controls and named owners, for protecting against Frontier AI-accelerated threats. This signals regulators moving toward continuous, provable supply chain governance rather than periodic audits.

_Developers navigating new AI-security regulation can stay current on directives like this via daily.dev._

## Similar posts on daily.dev

- [The Governance Gap Between Your Policy and Your Pipeline](https://daily.dev/posts/the-governance-gap-between-your-policy-and-your-pipeline-sggyudheo) · JFrog · 0 upvotes · 0 comments
- [The Tide of AI – Surfing the Tsunami of Binaries](https://daily.dev/posts/the-tide-of-ai-surfing-the-tsunami-of-binaries-328i1uqqf) · JFrog · 1 upvotes · 0 comments
- [Governance at the Speed of AI: How DevGovOps Closes the DORA Compliance Gap](https://daily.dev/posts/governance-at-the-speed-of-ai-how-devgovops-closes-the-dora-compliance-gap-wnwko9syk) · JFrog · 1 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#compliance](https://daily.dev/tags/compliance), [#devsecops](https://daily.dev/tags/devsecops), [#jfrog](https://daily.dev/tags/jfrog)

[View this post on daily.dev](https://daily.dev/posts/devgovops-how-the-ai-era-dictates-that-governance-lives-inside-the-pipeline-cuwlmhazh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"DevGovOps: How the AI Era Dictates That Governance Lives inside the Pipeline","url":"https://daily.dev/posts/devgovops-how-the-ai-era-dictates-that-governance-lives-inside-the-pipeline-cuwlmhazh","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/devgovops-how-the-ai-era-dictates-that-governance-lives-inside-the-pipeline-cuwlmhazh"},"datePublished":"2026-09-02T11:59:58.656Z","dateModified":"2026-09-03T15:20:54.775Z","description":"JFrog argues that AI coding agents break traditional human-in-the-loop compliance models, since agents can plan, write, review, and ship code without human...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/470ac5f70b26b40022b6447cb5e6c90c?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/470ac5f70b26b40022b6447cb5e6c90c?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"JFrog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"JFrog","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/b11bf37102384ac9983be701b2cf7cd5","url":"https://daily.dev/sources/jfrog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/devgovops-how-the-ai-era-dictates-that-governance-lives-inside-the-pipeline-cuwlmhazh","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,compliance,devsecops,jfrog","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"JFrog","item":"https://daily.dev/sources/jfrog"},{"@type":"ListItem","position":3,"name":"DevGovOps: How the AI Era Dictates That Governance Lives inside the Pipeline"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/devgovops-how-the-ai-era-dictates-that-governance-lives-inside-the-pipeline-cuwlmhazh#faq","mainEntity":[{"@type":"Question","name":"What was the Shai-Hulud npm worm and how many packages did it affect?","acceptedAnswer":{"@type":"Answer","text":"The Shai-Hulud worm was a supply chain attack that compromised more than 1,300 versions of widely used npm packages, reaching an estimated 2 billion monthly installs before defenders could fully contain it. It resurfaced in August 2026, illustrating how quickly a compromised package can spread through the npm ecosystem before detection. Teams tracking npm supply chain threats can follow developments like this one on daily.dev."}},{"@type":"Question","name":"What fines can companies face under the EU Cyber Resilience Act (CRA)?","acceptedAnswer":{"@type":"Answer","text":"The EU Cyber Resilience Act carries fines of up to 2.5% of global annual revenue for non-compliance, and it shifts personal legal liability directly onto CISOs and executive leadership rather than just the organization. This makes software supply chain governance a direct executive accountability issue, not only a technical one. Security leaders weighing CRA exposure can track compliance and supply chain coverage on daily.dev."}},{"@type":"Question","name":"What did the European Central Bank require European banks to do about AI-driven cyber threats?","acceptedAnswer":{"@type":"Answer","text":"In July 2026 the European Central Bank directed the CEOs of every major European bank to submit a concrete action plan by October 31st, including named controls and named owners, for protecting against Frontier AI-accelerated threats. This signals regulators moving toward continuous, provable supply chain governance rather than periodic audits. Developers navigating new AI-security regulation can stay current on directives like this via daily.dev."}}]}
```

