Connect with us

Hi, what are you looking for?

AI Business

JFrog Launches Shadow AI Detection to Mitigate Hidden Risks in Software Supply Chains

JFrog unveils Shadow AI Detection to secure software supply chains by cataloging unsanctioned AI models and API calls, enhancing compliance with emerging regulations.

JFrog has introduced a new feature, Shadow AI Detection, as part of its Software Supply Chain Platform, aimed at enhancing visibility and control over the “shadow AI” models and API calls that often infiltrate development pipelines without organizational oversight. This development comes in response to the increasing security, compliance, and risk issues associated with informal AI integrations adopted by various teams.

The Shadow AI Detection feature automatically scans and inventories both internal AI models and external API gateways used within an organization. This includes unsanctioned tools from providers such as OpenAI and Anthropic, as well as other third-party services. The capability allows enterprises to implement centralized governance over these tools, enabling them to enforce security and compliance policies, define authorized access paths, track usage, and maintain a comprehensive audit trail.

Yuval Fernbach, JFrog’s VP and CTO of ML, characterized the rollout as a necessary response to the growing blind spots in AI adoption. He stated that Shadow AI Detection “strengthens JFrog’s leadership in securing the AI supply chain 360 degrees, helping companies utilize AI safely and responsibly.” The timing of this launch is crucial, as businesses increasingly embed AI into their applications and workflows without centralized policy, elevating the risk of unmanaged or insecure AI usage.

The implications of unmanaged AI extend beyond security; they open avenues for regulatory infractions, data leaks, and vulnerabilities within the supply chain. JFrog emphasizes the need for governance mechanisms typically applied to software packages and dependencies to be extended to AI models and interactions. This new capability positions JFrog’s platform not just as a traditional artifact repository but as a comprehensive system of record for an organization’s software and AI supply chain.

Organizations adopting Shadow AI Detection will be better prepared to comply with emerging global AI regulations, including the upcoming EU AI Act and evolving transparency rules in the U.S. related to frontier AI. With the increasing emphasis on compliance under frameworks like NIS2 and other cyber-resilience guidelines, this feature aligns with the growing need for structured governance in AI applications.

JFrog is not the only player addressing AI governance. ModelOp Center offers an “AI control tower” designed for lifecycle management and governance across all AI within an organization, covering in-house models, third-party vendor models, and generative AI solutions. It facilitates the registration of new AI use cases, risk assessment, policy enforcement, audit trails, and continuous monitoring, differentiating itself from traditional MLOps or data platforms by focusing specifically on governance and compliance.

Another notable entrant in this space is Aurva, which provides real-time monitoring and observability for AI/ML systems, including agentic workloads and API-based AI model calls. Aurva markets its AIOStack as offering “deep, kernel-level visibility and control,” assisting organizations in detecting unauthorized data access, potential data leakages, and suspicious behavior by AI agents. Its approach to “shadow-AI visibility” parallels JFrog’s efforts, enabling firms to discover unmanaged or unsanctioned AI usage.

Shadow AI Detection is set to be integrated into the existing JFrog AI Catalog, with general availability anticipated in 2025. As the landscape of AI continues to evolve rapidly, this feature underscores the growing importance of governance and oversight in the integration of AI technologies across enterprises.

See also
Marcus Chen
Written By

At AIPressa, my work focuses on analyzing how artificial intelligence is redefining business strategies and traditional business models. I've covered everything from AI adoption in Fortune 500 companies to disruptive startups that are changing the rules of the game. My approach: understanding the real impact of AI on profitability, operational efficiency, and competitive advantage, beyond corporate hype. When I'm not writing about digital transformation, I'm probably analyzing financial reports or studying AI implementation cases that truly moved the needle in business.

You May Also Like

AI Business

Pentagon partners with OpenAI to integrate ChatGPT into GenAI.mil, granting 3 million personnel access to advanced AI capabilities for enhanced mission readiness.

AI Education

UGA invests $800,000 to launch a pilot program providing students access to premium AI tools like ChatGPT Edu and Gemini Pro starting spring 2026.

AI Generative

OpenAI has retired the GPT-4o model, impacting 0.1% of users who formed deep emotional bonds with the AI as it transitions to newer models...

AI Technology

CodePath partners with Anthropic to integrate Claude into AI courses, empowering low-income students to access high-demand skills with a 56% wage premium.

Top Stories

Anthropic's Claude Cowork triggers a $300 billion market shift as investors pivot to resilient sectors like Vertical SaaS and Cybersecurity amidst AI disruption.

AI Generative

ChatBCI introduces a pioneering P300 speller BCI that integrates GPT-3.5 for dynamic word prediction, enhancing communication speed for users with disabilities.

Top Stories

Microsoft’s AI chief Mustafa Suleyman outlines a bold shift to self-sufficiency by developing proprietary models, aiming for superintelligence and reducing reliance on OpenAI.

Top Stories

Mistral AI commits €1.2B to build Nordic data centers, boosting Europe's A.I. autonomy and positioning itself as a rival to OpenAI and Microsoft.

© 2025 AIPressa · Part of Buzzora Media · All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site. Some images used on this website are generated with artificial intelligence and are illustrative in nature. They may not accurately represent the products, people, or events described in the articles.