AI coding agents are moving software-development activity beyond the conventional CI/CD pipeline. They can suggest and fetch dependencies, invoke tools, modify files and trigger builds before a human developer reviews every action, creating new questions around identity, policy enforcement and auditability.
TNGlobal previously covered JFrog’s Traffic Controller launch, which is intended to route package requests from developers and AI agents through policy controls. In this TNGlobal Q&A, Yashaswi Mudumbai, Senior Director of Solutions Engineering for APAC at JFrog, discusses where autonomous development creates gaps around traditional software-supply-chain controls, what should remain subject to human approval and what enterprises should retain for audit and incident reconstruction.

As AI coding agents gain the ability to fetch dependencies and invoke build processes autonomously, which assumptions in traditional software supply-chain security no longer hold?
The first assumption is that every dependency request reflects a clear human decision. With AI coding agents, a package may be suggested, fetched or installed by an automated workflow before a developer fully reviews the choice. That makes identity, intent and accountability harder to establish.
The second is that CI/CD is the main control point. Agents can act earlier, from the IDE, terminal, workstation or network layer. If organizations only inspect code once it reaches the pipeline, they may miss what entered the environment before that point.
That shift matters as package risk rises. JFrog’s 2026 Software Supply Chain State of the Union found 171,592 malicious npm packages in 2025, up 451 percent year on year. Enterprises increasingly need to govern packages, models, plugins, MCP servers and other software assets consumed or produced by AI-driven workflows as part of the software supply chain.
Enterprises have spent years putting controls into CI/CD pipelines. Where are AI agents creating paths around those controls, and which gaps are proving hardest to see?
The biggest gap can appear before CI/CD begins. An AI coding agent can operate from an IDE or developer machine, select a dependency and pull it directly from a public registry. If that request does not pass through the organization’s approved repository or control point, CI/CD controls may never see it.
The hard part is that this may not look malicious. The agent may simply be completing a task through a route the organization did not anticipate. That can leave security teams unable to answer basic questions: what was downloaded, where did it come from, which policy applied and where was it later used?
Enterprises therefore need earlier enforcement and clearer traceability. JFrog Package Traffic Controller is one example of this approach, routing package requests from developers and AI agents through policy checks before packages enter the organization.
How should organizations decide which package or dependency actions an AI agent can perform autonomously and which should still require explicit human approval?
The decision should depend on the risk of the action, not simply on whether a human or AI agent performs it. Routine and reversible actions can be automated when a package comes from a trusted source and meets the organization’s security, license and quality policies.
Human approval should apply when the action materially changes risk: adding a new dependency, overriding a policy, using an unapproved source, accepting unresolved vulnerabilities or making an exception for a business-critical build.
The right model is bounded autonomy. Automate decisions that policy can make confidently, and escalate the exceptions. The organization should still retain evidence of what the agent did, which policy applied and why the action was allowed, blocked or reviewed.
Network-edge controls can add another enforcement point. How should these work alongside repository, endpoint, CI/CD and developer-workflow controls without creating overlapping policies or blind spots?
Each layer should manage a different part of the risk. Developer controls guide what gets requested. Network controls can catch requests that bypass expected routes. Repositories govern approved packages. CI/CD verifies what gets built and released. Runtime controls provide visibility into what is actually running.
Problems start when these layers use inconsistent rules. If one system allows a package while another blocks it, developers receive conflicting signals and security teams lose a clean evidence trail.
The aim should be a consistent policy model applied across several enforcement points, with each layer contributing to the same decision and audit trail rather than operating as a separate security silo. Network-edge enforcement should close bypass routes, not replace repository, endpoint or pipeline controls.
Security controls that introduce too much friction can encourage workarounds. What have you learned from APAC enterprises about designing package governance that developers will actually follow?
APAC shows that strong governance can still fail if it moves too slowly. Singapore leads the surveyed markets on network proxy enforcement, but JFrog’s Singapore findings also show that 59 percent of developers wait a week or more for open-source package approvals.
That delay creates practical risk. Developers and AI agents do not stop needing packages because approval queues are slow. They may look for faster routes, and those routes can bypass the controls the organization invested in.
The lesson is to automate predictable decisions. Trusted packages should clear quickly through policy-based checks, while security teams focus on exceptions. Governance works best when the approved route is also the easiest and fastest route.
AI agents can operate much faster than human developers. Does this change how quickly organizations need to detect, assess and respond to a malicious or newly compromised dependency?
Yes. The response window is compressing. When an AI agent can fetch dependencies, modify files and trigger builds at machine speed, organizations cannot rely solely on overnight scans, manual ticket queues or lengthy approval cycles.
This is why response needs to move from delayed detection toward continuous enforcement and remediation. Risky dependency requests should be blocked, rerouted or escalated before they spread across branches, builds or developer environments.
This also connects to a broader industry shift toward more automated remediation. At swampUP 2026, JFrog introduced Zero-Touch Remediation in beta, an approach designed to identify applicable fixes, apply policy-driven remediation and retain evidence of the action. The broader principle is that as development becomes more autonomous, remediation also needs to become faster, more contextual and increasingly automated.
What should an enterprise log or retain so that it can reconstruct what an AI agent downloaded, why it selected a dependency and what happened afterward?
Enterprises need an audit trail that connects the agent’s action to the resulting software outcome. At minimum, they should retain the package name, version, source registry, time of request, requesting user or service account, agent identity, project, build context and policy decision.
The decision context matters as much as the action itself. Where appropriate and permitted by organizational policy, teams should retain relevant task or prompt context, dependency-file changes, tool or plugin invocations, and links to associated tickets or pull requests. The objective is not to reconstruct an AI model’s hidden reasoning, but to preserve enough observable context to understand why an action occurred and under what authority.
The final question is impact. Teams need to know where the dependency landed, which builds consumed it, whether it reached production and whether new vulnerability intelligence subsequently changed its risk status.
Across APAC, are there differences in regulatory requirements, development practices, cloud environments or organizational maturity that materially change how companies should approach agentic software governance?
APAC should not be treated as one market. A bank in Singapore, a digital-native company in India and a public-sector supplier in Australia will not govern AI agents in exactly the same way.
The sharper distinction is operating posture. Some enterprises rely heavily on cloud APIs. Others run AI models on internal infrastructure. Some have mature DevSecOps teams, while others still depend on manual approvals. These differences affect how much autonomy an organization can safely give to agents.
The baseline remains consistent: software assets consumed by agents and material actions performed by them need appropriate policy controls and traceability. But the enforcement model should reflect the organization’s regulatory burden, technical maturity and tolerance for automated decisions.
Over the next 12 to 18 months, what signs would indicate that an organization’s controls are keeping pace with autonomous development rather than simply adding more security tooling?
The clearest sign is a shorter time from dependency request to trusted use. If developers and AI agents can access approved packages quickly, while risky packages are blocked, replaced or escalated automatically, control is improving without unnecessarily slowing delivery.
The second sign is audit speed. Security teams should be able to show which agent or workflow requested a package, what policy decision applied, where the dependency was used and whether it reached production. If reconstructing that chain takes days, governance has not kept pace.
The third sign is better signal quality: fewer unmanaged downloads, fewer policy exceptions, faster compliance evidence and clearer prioritization of exploitable risk. Success is not more tooling. It is proving control at software speed.
Yashaswi Mudumbai is Senior Director of Solutions Engineering for APAC at JFrog, where he works with enterprises on the technical and operational aspects of secure software delivery as AI adoption scales.
Editor’s note: This Q&A has been lightly edited for clarity and TNGlobal house style. The substance of the interviewee’s responses has been preserved.
Share your perspective: TNGlobal welcomes contributed insights and expert commentary from across Asia’s technology and innovation ecosystem. Submit a contribution for editorial consideration, or explore more conversations in our TNGlobal INSIDER and TNGlobal Q&A and Interviews archive.
JFrog launches Traffic Controller to govern software package downloads by developers and AI agents

