Software development operates under relentless pressure to move faster, yet enterprise demands for security and compliance are equally unforgiving. As artificial intelligence begins to reshape every phase of the development lifecycle—from code generation to testing and deployment—strategic planning becomes essential for vendors navigating this transformation.
Kernelwire spoke with Gal Marder, chief strategy officer at JFrog, to explore how the company is preparing for an AI-driven future while maintaining equilibrium between velocity and governance. Marder's role encompasses three primary responsibilities: anticipating shifts in development practices over the next three to five years, evaluating merger and acquisition opportunities, and managing technology partnerships with resellers and other vendors.
Building, Buying, and Partnering
When addressing new market demands or emerging operational challenges, Marder applies a flexible decision-making framework. "In most cases, the optimal solution is a combination of all three," he explained, referring to the build-buy-partner approach. This strategy allows JFrog to leverage internal capabilities, acquire specialized competencies, and establish alliances to deliver comprehensive solutions.
JFrog's recent introduction of UpTrust exemplifies this integrated approach. The initiative tackles DevGovOps—the challenge organizations face when balancing development speed with governance and regulatory compliance. Since governance spans processes beyond JFrog's core domain, such as planning and coding, partnerships became essential. "We needed to partner with many partners," Marder said, drawing a parallel between JFrog's collaborative nature and the foundational principles of DevOps itself.
Governance Without Sacrificing Speed
For years, the software industry prioritized velocity at the expense of trust and governance—an unsustainable trade-off that has now corrected itself. Software-creation governance establishes rules, policies and practices that guide the entire development lifecycle, ensuring consistency, security and efficiency while aligning with business objectives. It encompasses strategic alignment, risk management, compliance and quality assurance through clear roles, responsibilities and automated policy enforcement.
The central challenge today is maintaining—or even accelerating—delivery speed while implementing rigorous, trustworthy processes. "You cannot drive very fast without having a seat belt and without having different precautions," Marder said. Most organizations still depend on manual governance practices, screenshots and spreadsheets, methods that cannot sustain modern release cadences.
Security and Regulatory Complexity
Sophisticated threat actors continue to raise the security stakes, adding another dimension to governance challenges. Recent legislation underscores this complexity: the European Union's Digital Operational Resilience Act (DORA), which took full effect in January 2025, mandates that financial institutions, insurers, investment firms and their third-party technology providers ensure their IT systems can withstand, respond to and recover from all types of information and communication technology disruptions and cyberattacks. Similarly, the U.S. executive order from 2021 requires organizations to provide a software bill of materials (SBOM)—essentially a detailed inventory of software components—addressing broader quality and governance concerns beyond security alone.
Five Strategic Priorities
Marder outlined JFrog's roadmap around five key areas. First is the system of record for software releases—a function already central to JFrog's platform but increasingly critical as control requirements intensify in speed-driven environments. The rise of AI-powered coding assistants and agentic release processes demands robust checkpoints where human review and testing occur before code integration. "The agent is kind of an enforcer or editor, capable of dynamic decision-making and enforcing policies," Marder explained, describing how AI agents serve as safeguards when automating tasks.
Second is managing new asset types, particularly AI models themselves. This requires scanning for vulnerabilities, ensuring transparency in model creation and maintaining auditable lineage. "A model is just another artifact" that must be tracked within the system of record, Marder noted, highlighting the commonalities between traditional software and AI assets despite their distinct challenges.
The third priority addresses DevGovOps—embedding governance directly into development workflows, a relatively new bottleneck JFrog is actively tackling. Fourth is evolving developer expectations around user experience. Developers increasingly demand high agency from AI agents, expecting them to comprehend intent and autonomously determine how to achieve it. Finally, JFrog is advancing agentic releases, exemplified by JFrog Fly, which deeply integrate repositories and release processes with AI agents to reshape the engineering experience.
When asked what new customers often overlook about JFrog, Marder emphasized that many fail to fully appreciate "the importance of a single source of truth or system of record for their release." In an accelerated development world, this foundational principle anchors everything JFrog delivers.
Source: The New Stack