JFrog Introduces Shadow AI Detection
November 13, 2025

JFrog announced an expansion of its AI governance capabilities within the JFrog Software Supply Chain Platform with the introduction of Shadow AI Detection.

The new capability, introduced at JFrog swampUP Europe, is designed to equip enterprises with the visibility and control needed to govern and secure the entire AI supply chain, guarding against the uncontrolled use of AI models and APIs, known as Shadow AI, which can introduce significant security and compliance risks.

“Recognizing and mitigating the risks of shadow AI is becoming a critical priority for CIOs and CISOs who must strike a balance between innovating while maintaining security. Organizations should follow proven software development practices by creating developer-friendly workflows with strong security and robust governance,” said Yuval Fernbach, VP and CTO, JFrog ML. “The addition of Shadow AI Detection capabilities is intended to strengthen JFrog’s leadership in securing the AI supply chain 360-degrees, helping companies utilize AI safely and responsibly.”

JFrog’s new Shadow AI Detection helps automatically detect and create an inventory of all internal AI models and external API gateways used across the organization to access data from either approved or ad-hoc third-party sources. Once discovered, these newly visible models and services can be governed centrally, empowering teams to:

- Enforce security and compliance policies across all AI assets.

- Establish defined paths for authorized users to access and utilize third-party AI services, ensuring controlled and fully auditable interactions.

- Track and monitor usage of external AI models and APIs such as OpenAI or Gemini.

JFrog’s new AI detection capabilities are intended to enable enterprises to uphold compliance and security in line with key frameworks such as the US Transparency in Frontier AI Act, EU Cyber Resilience Act, EU AI Act, Germany’s BSI Guidelines, the EU’s NIS2, and the Guidelines and Companion Guide for Securing AI Systems. Collectively, these regulations aim to deliver provenance, accountability, and establish resilience across the AI and software supply chain by:

- Ensuring responsible AI development

- Enforcing rigorous risk management and reporting standards

- Mandating visibility into software components

- Securing AI systems from design to deployment

JFrog Shadow AI Detection is available as part of JFrog AI Catalog, with a GA release planned in 2025.

Share this

Industry News

November 25, 2025

Check Point® Software Technologies Ltd. announced its inclusion in Newsweek and Statista’s ranking of America’s Most Reliable Companies 2026. The annual list recognizes the top 300 U.S. B2B companies that earn the highest marks in trust, dependability, and client satisfaction.

November 24, 2025

Opsera announced a strategic partnership with Koantek, an Elite Databricks Partner and Databricks Ventures–backed SI.

November 20, 2025

Check Point® Software Technologies Ltd. is collaborating with Microsoft to deliver enterprise-grade AI security for Microsoft Copilot Studio. The collaboration enables enterprises to safely build and deploy generative-AI agents with continuous protection, compliance, and governance integrated directly into their development workflows.

November 20, 2025

Google announced that Gemini 3 Pro is now officially available for developers.

November 20, 2025

Stack Overflow announced the evolution of its enterprise knowledge system, Stack Internal, formerly known as Stack Overflow for Teams, and a reflection of our ongoing mission to be the most trusted source for technologists.

November 19, 2025

Red Hat announced Project Hummingbird, an early access program for Red Hat subscription customers that provides a catalog of minimal, hardened container images.

November 19, 2025

Sonatype announced the launch of Nexus One, a single, agentic software supply chain infrastructure unifying open source intelligence, governance, and automation across enterprise software development.

November 19, 2025

Progress Software announced its SaaS Retrieval-Augmented Generation (RAG) platform, Progress® Agentic RAG, is now available in AWS Marketplace, a digital catalog that helps customers find, buy, deploy and manage software, data products and professional services from thousands of vendors.

November 18, 2025

Parasoft announced a significant leap forward in autonomous software quality with its latest 2025.2 releases of Jtest and dotTEST.

November 18, 2025

CloudBees announced the launch of the Unify AI Design Partner (AIDP) program.

November 18, 2025

noBGP announced the launch of pi GPT, a custom GPT for OpenAI's ChatGPT that allows users to bring their Raspberry Pi devices into the vibe coding ecosystem.

November 17, 2025

Postman announced its acquisition of liblab, a platform for developers that automates the generation and maintenance of Software Development Kits (SDKs).

November 13, 2025

JFrog announced an expansion of its AI governance capabilities within the JFrog Software Supply Chain Platform with the introduction of Shadow AI Detection.

November 13, 2025

Red Hat introduced the general availability of Red Hat Enterprise Linux 10.1 and 9.7, building on the innovations of Red Hat Enterprise Linux 10 for a more intelligent and future-ready computing foundation.

November 13, 2025

Solo.io announced the launch of agentregistry, a centralized, trusted, and curated open source registry for AI applications and artifacts.