AI coding agents are outpacing traditional Governance, Risk, and Compliance (GRC) frameworks, creating a structural compliance gap — especially under the EU's Digital Operational Resilience Act (DORA). DORA, which took effect in January 2025, now requires six months of continuous documented attestations rather than periodic point-in-time reviews. AI agents commit and deploy code 10–50x faster than human-gated processes, yet 48% of organizations still need a week or more to produce audit proof on demand. DevGovOps is proposed as a new engineering discipline that embeds governance directly into CI/CD pipelines via policy-as-code gates, cryptographic attestations, automated SBOM generation, and continuous artifact provenance tracking. Five specific DORA compliance gaps caused by agentic development are mapped to DevGovOps solutions covering ICT risk management, change management, vulnerability management, third-party risk, and incident reporting. The JFrog Platform (Curation and AppTrust) is presented as the tooling implementation for these principles.