JFrog Extends DevSecOps Playbook to AI Governance
Platform Integration
[cite author="Sunny Rao, JFrog SVP Asia-Pacific" source="Computer Weekly, Sept 2 2025"]AI models are nothing but analogous to software. We're already maintaining the system of record as a registry for all software artefacts, so it's only logical that we are the system of records for all AI models.[/cite]
[cite author="Sunny Rao, JFrog" source="Computer Weekly, Sept 2 2025"]All of the old practices that we had fixed with DevSecOps were creeping into AI. Trying to bring the same DevSecOps methodology to AIOps became very important.[/cite]
ML-BOM Innovation
[cite author="Computer Weekly" source="Sept 2 2025"]Central to JFrog's efforts to manage AI models is the introduction of machine learning bills of materials (ML-BOM), which is akin to a traditional software bill of materials (SBOM).[/cite]
[cite author="Sunny Rao, JFrog" source="Computer Weekly, Sept 2 2025"]ML-BOM must account for two distinct layers of provenance. One is the model itself, and the second is the data sets used to train the model.[/cite]
[cite author="Sunny Rao, JFrog" source="Computer Weekly, Sept 2 2025"]How did you source this data? How much bias did you introduce? These concepts are enshrined into our ML-BOM.[/cite]
Governance Framework Integration
[cite author="Computer Weekly" source="Sept 2 2025"]JFrog incorporates governance frameworks like Singapore's fairness, ethics, accountability and transparency principles, with digital signatures at every stage to ensure a clear audit trail.[/cite]
[cite author="Sunny Rao, JFrog" source="Computer Weekly, Sept 2 2025"]If a particular AI model comes in with certain restrictions, or you don't know the provenance of the data, we will flag it to you.[/cite]
Platform Capabilities
[cite author="Computer Weekly" source="Sept 2 2025"]JFrog acquired Qwak AI (now JFrog ML) in 2024, delivering capabilities such as real-time monitoring of model performance, A/B testing and model experimentation, as well as cost benchmarking.[/cite]
[cite author="Sunny Rao, JFrog" source="Computer Weekly, Sept 2 2025"]We're seeing a flurry of activity and deployments in the SecOps space in order to get ready for what is coming down the line.[/cite]
