Thursday, November 20, 2025

Top 5 This Week

Related News

JFrog introduces shadow AI detection for secure software supply chain

JFrog Ltd, the Liquid Software company, today announced an expansion of its AI governance capabilities within the JFrog Software Supply Chain Platform with the introduction of Shadow AI Detection. The new capability, introduced at JFrog swampUP Europe, is designed to equip enterprises with the visibility and control needed to govern and secure the entire AI supply chain, guarding against the uncontrolled use of AI models and APIs, known as Shadow AI, which can introduce significant security and compliance risks.

“Recognizing and mitigating the risks of shadow AI is becoming a critical priority for CIOs and CISOs who must strike a balance between innovating while maintaining security. Organizations should follow proven software development practices by creating developer-friendly workflows with strong security and robust governance,” said Yuval Fernbach, VP and CTO, JFrog ML. “The addition of Shadow AI Detection capabilities is intended to strengthen JFrog’s leadership in securing the AI supply chain 360-degrees, helping companies utilize AI safely and responsibly.”

Delivering Transparency for Better Governance of AI Models and APIs

The rapid integration of AI across development pipelines has created a major governance challenge for organizations. For example, developers and data science teams frequently integrate AI models and services directly from providers such as Anthropic, OpenAI, and Google without organizational oversight. This ungoverned activity, often referred to as Shadow AI, creates dangerous blind spots that leave enterprises vulnerable to compliance violations, data leaks, and supply chain attacks.

JFrog’s new Shadow AI Detection helps automatically detect and create an inventory of all internal AI models and external API gateways used across the organization to access data from either approved or ad-hoc third-party sources. Once discovered, these newly visible models and services can be governed centrally, empowering teams to:

  • Enforce security and compliance policies across all AI assets.
  • Establish defined paths for authorized users to access and utilize third-party AI services, ensuring controlled and fully auditable interactions.
  • Track and monitor usage of external AI models and APIs such as OpenAI or Gemini.

Meeting the Global AI Compliance Imperative

The need for a full audit trail of AI activity is becoming an imperative due to emerging global regulations and security risks. JFrog’s new AI detection capabilities are intended to enable enterprises to uphold compliance and security in line with key frameworks such as the US Transparency in Frontier AI ActEU Cyber Resilience ActEU AI Act, Germany’s BSI Guidelines, the EU’s NIS2, and the Guidelines and Companion Guide for Securing AI Systems. Collectively, these regulations aim to deliver provenance, accountability, and establish resilience across the AI and software supply chain by:

  • Ensuring responsible AI development
  • Enforcing rigorous risk management and reporting standards
  • Mandating visibility into software components
  • Securing AI systems from design to deployment

JFrog Shadow AI Detection is available as part of JFrog AI Catalog, with a GA release planned in 2025. For more information on the entire JFrog Software Supply Chain Platform visit https://jfrog.com/

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream formerly known as CIO News LinkedIn Account | The Mainstream formerly known as CIO News Facebook | The Mainstream formerly known as CIO News Youtube | The Mainstream formerly known as CIO News Twitter

About us:

The Mainstream formerly known as CIO News is a premier platform dedicated to delivering latest news, updates, and insights from the tech industry. With its strong foundation of intellectual property and thought leadership, the platform is well-positioned to stay ahead of the curve and lead conversations about how technology shapes our world. From its early days as CIO News to its rebranding as The Mainstream on November 28, 2024, it has been expanding its global reach, targeting key markets in the Middle East & Africa, ASEAN, the USA, and the UK. The Mainstream is a vision to put technology at the center of every conversation, inspiring professionals and organizations to embrace the future of tech.

Popular Articles