JFrog warns 80% enterprises lack AI agent governance
At swampUP 2026, JFrog emphasized the growing security risks associated with agentic software development, noting that 80% of enterprises currently operate without a governance framework for AI coding agents. With malicious packages and AI assets surging 7.4x over the past three years, the rapid transition to autonomous development tools presents new software supply chain vulnerabilities that existing security models fail to address.
As software engineering rapidly transitions into an agentic paradigm, security and compliance frameworks are struggling to keep pace. Autonomous coding agents that pull dependencies and generate code without strict governance expose enterprises to unprecedented supply chain risks.
- –Autonomous coding tools frequently fetch dependencies without rigorous human oversight, expanding the attack surface for malicious packages.
- –Malicious AI assets and packages have grown 7.4x in three years, specifically targeting modern automated developer workflows.
- –Enterprises must modernize their DevSecOps pipelines to incorporate real-time governance specifically tailored to AI agents and third-party AI assets.
DISCOVERED
1d ago
2026-08-06
PUBLISHED
1d ago
2026-08-06
RELEVANCE
AUTHOR
jfrog