JFrog Charts Course Through AI-Driven Development With Governance at the Core
JFrog's chief strategy officer outlines how the company is positioning itself to navigate AI-powered software development while maintaining speed, trust and regulatory compliance.

Software development moves at an ever-quickening pace, driven by enterprise demands that show no signs of slowing. As this landscape shifts, strategic foresight—the ability to see beyond immediate challenges and anticipate what comes next—has become essential, particularly in intensely competitive sectors.
The New Stack recently spoke with Gal Marder, chief strategy officer at JFrog, a data management software company, to examine how his organization is preparing for a development future shaped by artificial intelligence. Code writing, testing, suggestions and deployment are now being handled by AI-assisted tools—capabilities that seemed impossible just months ago.
Marder's responsibilities center on three primary areas. First, he looks ahead three to five years to position JFrog for coming shifts in how developers work. "Especially in these early days of AI, it's very hard to guess," Marder said. A forward-looking strategy, he emphasized, draws strength from ongoing input across multiple channels.
Three Roles to Fill
"We definitely listen to customers, to partners, and also to different people inside the organization," Marder said. Bringing together varied viewpoints and allowing open discussion creates insights that even in today's connected world, face-to-face conversation often delivers most effectively—particularly when tackling complex, abstract challenges.
The second component of his role involves mergers and acquisitions, making Marder the company's corporate development leader. He identifies potential acquisitions that could strengthen or accelerate JFrog's strategic direction. Third is technology partnerships—relationships with resellers and other software makers.
When addressing new market opportunities or emerging operational challenges, Marder applies a structured decision framework: build, buy or partner. In most situations, he noted, the strongest approach combines all three. This flexibility allows JFrog to leverage internal capabilities, acquire missing pieces or form alliances to deliver solutions quickly.
What UpTrust Brings to the DevGovOps Party
JFrog's recent launch of UpTrust exemplifies this strategy. The initiative directly tackles DevGovOps—the challenge organizations face when balancing rapid development with governance and regulatory requirements. Delivering a comprehensive answer requires multiple partners, since certain activities like planning and coding sit outside JFrog's core focus.
"We needed to partner with many partners," Marder said, drawing a parallel between JFrog's collaborative nature and the fundamental philosophy of DevOps itself—eliminating barriers to enable seamless software movement from developers (or increasingly, AI agents) to end users.
Software-Creation Governance
JFrog's focus centers on software-creation governance, an area that has undergone substantial change. For years, the sector emphasized velocity at the expense of trust and oversight. That imbalance has now corrected itself, Marder observed.
Software-creation governance comprises the rules, policies and practices that shape the entire software development life cycle to support business goals. It guarantees that software emerges consistently, securely and efficiently, covering strategic alignment, risk management, compliance and quality assurance. Effective governance demands transparent roles, defined responsibilities and tools that enable automated policy enforcement and ongoing refinement.
"You cannot drive very fast without having a seat belt and without having different precautions," Marder said. Industry maturation has brought heightened attention to trust, safety and governance without sacrificing development speed, he said.
The real challenge now lies in sustaining—or even accelerating—velocity while maintaining a controlled, trustworthy process. Most organizations still depend on manual methods, screenshots and spreadsheets for governance, approaches that cannot match today's rapid release schedules, he said.
Security Gets Even More Complicated
Increasingly sophisticated attackers have added another layer of difficulty. While Marder believes the industry is largely managing the balance effectively, the challenge remains substantial. Regulations including the European Union's DORA Act of 2025 and the U.S. executive order requiring a software bill of materials (SBOM) from 2021, though prompted by security breaches, ultimately address broader quality and governance concerns.
The Digital Operational Resilience Act (DORA) is a comprehensive EU regulation that took full effect in January of this year. DORA strengthens the financial sector's digital operational resilience. It mandates that banks, insurers, investment firms and other financial institutions—along with the third-party technology providers they rely on—confirm their IT systems can endure, respond to and recover from all varieties of Information and Communication Technology (ICT) disruptions and cyberattacks.
An SBOM functions as a detailed inventory of software components.
What the JFrog Roadmap Entails
Marder outlined his company's strategic direction, which revolves around five key areas. The first involves the changing importance of the system of record for software releases.
Though JFrog already has this capability, the pressure for oversight in a speed-focused environment makes it increasingly vital. The rise of AI in coding, evident in tools like copilots, highlights the necessity for strong control mechanisms within this system of record—enabling human review and testing before code moves forward. This extends to agentic release processes, where AI agents might handle testing, distribution and even deployment choices, Marder said.
"The agent is kind of an enforcer or editor, capable of dynamic decision-making and enforcing policies—an important safeguard when delegating tasks to AI," Marder explained.
Managing New Assets
Second, JFrog is addressing the management of new assets, including AI models themselves. This requires scanning models for security flaws, guaranteeing visibility into how they were built and making their origin traceable. Though distinct challenges emerge, Marder stressed the similarities: "A model is just another artifact" that must be tracked within the system of record, he said.
The third area is DevGovOps, weaving governance into the development workflow—a relatively recent constraint that JFrog is actively tackling. Shifting developer expectations drive the fourth focus area: user experience. Developers, Marder noted, want AI agents to have broad autonomy, anticipating they will comprehend intent and independently determine how to accomplish it.
Finally, JFrog's vision for "agentic releases," demonstrated by JFrog Fly, points toward a future where repositories and release workflows are tightly connected with AI agents, transforming how engineering teams operate.
When asked what new customers sometimes overlook about JFrog, Marder responded that "while customers are often well-informed, some don't fully realize the importance of a single source of truth or system of record for their release."
For many, a single source of truth represents an ideal—the endless search for one authoritative, reliable information origin. For JFrog, this foundational concept anchors everything the company does in the fast-moving world of software development.
Source: The New Stack