JFrog
Read post

Governance at the Speed of AI: How DevGovOps Closes the DORA Compliance Gap

AI coding agents are outpacing traditional Governance, Risk, and Compliance (GRC) frameworks, creating a structural compliance gap — especially under the EU's Digital Operational Resilience Act (DORA). DORA, which took effect in January 2025, now requires six months of continuous documented attestations rather than periodic point-in-time reviews. AI agents commit and deploy code 10–50x faster than human-gated processes, yet 48% of organizations still need a week or more to produce audit proof on demand. DevGovOps is proposed as a new engineering discipline that embeds governance directly into CI/CD pipelines via policy-as-code gates, cryptographic attestations, automated SBOM generation, and continuous artifact provenance tracking. Five specific DORA compliance gaps caused by agentic development are mapped to DevGovOps solutions covering ICT risk management, change management, vulnerability management, third-party risk, and incident reporting. The JFrog Platform (Curation and AppTrust) is presented as the tooling implementation for these principles.

    #jfrog#policy-as-code
Jul 19•9m read time•From jfrog.com
Post cover image
Table of contents
Why DORA’s Enforcement Phase Changes EverythingHow Does DevGovOps Close the AI Compliance Gap in DORA?What Does a Real Governance Failure Look Like?Three Principles of DevGovOps for DORA Governance at Agentic SpeedThe Gap Is There. The Question Is When You Close It.Frequently Asked Questions
1.2K Impressions
JFrog's image
JFrog

JFrog is a leading provider of DevOps and software distribution solutions, offering tools for artifa...

22 Followers

•

126 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard