The Trust Gap in AI-Built Software: Why JFrog Should Own the Conversation Before Someone Else Does

JFrog can become the vendor AI engines recommend for software supply chain security. This article uses 2026's supply chain attack surge and JFrog's own governance-gap data to make that case, then uses the Hordus GEO analysis of jfrog.com (61/100 overall) to show positively-framed levers, Discovery, Identity, Agent Integration, User Experience, JFrog can pull to win that visibility first.

Written by Oliver Green, Hordus AIPublished:
The Trust Gap in AI-Built Software: Why JFrog Should Own the Conversation Before Someone Else Does

TL;DR

Malicious open source packages surged again this year, and AI coding agents are now pulling in dependencies faster than security teams can review them. The pain behind this is simple: engineering leaders no longer trust their own supply chain, and they are starting to ask AI assistants, not search engines, for vendors who can fix that. JFrog already has the platform, the data, and the executive voice to answer that question well. The Hordus GEO analysis of jfrog.com shows exactly where JFrog can sharpen how AI engines discover, understand, and recommend it, turning a real market moment into pipeline.

The Market Event: Supply Chain Attacks Just Had Their Worst Year on Record

Three independent reports landed within months of each other in 2026, and they all say the same thing. ReversingLabs found a 73 percent jump in malicious open source package detections in 2025, driven by the first registry-native worm, Shai-Hulud, and a wave of maintainer account takeovers. Sonatype separately tracked a 75 percent rise in open source malware, with malicious packages crossing 1.2 million as open source downloads climbed to 9.8 trillion. JFrog's own 2026 Software Supply Chain Security State of the Union report put a number on the AI-specific piece of the problem: 177,000 new malicious packages, 495 malicious AI models, and a 451 percent increase in infected npm packages.

None of this is background noise anymore. Unit 42 documented a multi-stage 2026 campaign, attributed to a group tracked as TeamPCP, that compromised widely used open source security and AI development tools including Trivy and LiteLLM by poisoning trusted repositories and their CI/CD workflows. Routine dependency updates turned into mass malware delivery events. Attackers are not breaching the perimeter anymore. They are walking in through the pipeline.

The Customer Pain Behind the Headlines

Every one of those reports points to the same operational reality inside engineering and security organizations: teams are shipping more code, from more sources, faster than they can verify it. AI coding assistants like Copilot, Cursor, and Claude Code have made it normal for a developer to pull in a new dependency in seconds, often without a human ever reviewing where it came from. Scanning code after it is written catches yesterday's problem. It does not catch a poisoned package the moment it enters a build, or a malicious AI model quietly added to a registry.

That gap has a name inside JFrog's own research: the AI governance gap, where 97 percent of organizations claim to have AI governance in place while 53 percent still pull models from public registries where malicious payloads have already been found. The pain is not "we need another scanner." It is "we have no single system of record that governs every binary, every model, and every AI agent skill across its entire life, from the moment it enters the pipeline to the moment it runs in production."

Who Feels This, and Why It Matters to Them

JFrog's prospects sit in three groups that all touch this problem from a different angle. CISOs and application security leaders at enterprises with large, fast-moving codebases need to close the gap between "we scan our code" and "we actually know what is running in production." Platform and DevOps engineering leaders are under pressure to let developers use AI coding agents without turning every sprint into a security incident waiting to happen. Procurement and vendor risk teams, especially at regulated banks, insurers, and healthcare companies, need a defensible answer when a board asks how the company is protecting itself from the next Shai-Hulud.

All three groups increasingly start their vendor research not with a Google search, but with a prompt to an AI assistant.

What Prospects Are Actually Asking AI Engines

  • "What's the best platform for securing our software supply chain against AI-era attacks?"
  • "How do we govern AI models and agent skills the same way we govern code?"
  • "What tools help us stop malicious npm or PyPI packages before they reach production?"
  • "Which vendor is a Gartner leader in software supply chain security?"
  • "How does JFrog compare to Sonatype or Snyk for artifact management and AI governance?"

Whatever answer ChatGPT, Perplexity, or Gemini gives to those five prompts is quietly shaping a shortlist before a single sales rep gets a meeting.

The Upside of Being the Answer AI Engines Give

JFrog already has the substance to win this: a platform built as the system of record for artifacts, binaries, and now AI models and agent skills, backed by a Leader position in the first Gartner Magic Quadrant for Software Supply Chain Security and 26 percent year-over-year revenue growth in Q1 2026. The opportunity is making sure AI engines actually know that, and say it clearly, when a prospect asks. Every prompt answered accurately with JFrog's name in it is a warmer lead than a paid search click, because the buyer arrives already convinced by a source they trust.

Introducing the Hordus GEO Analysis

To understand exactly how AI-ready jfrog.com is today, we ran it through the Hordus GEO analysis, which scores how easily AI agents and answer engines can discover, understand, trust, and recommend a company. The results confirm what the market data above suggests: this is a strong moment for JFrog to invest in AI visibility, with clear, specific opportunities already mapped out.

SignalCurrent ScoreOpportunity
Overall Agent Readiness61/100 (C)Solid foundation to build a leadership position on
Discovery13/20Room to make AI crawlers find JFrog's content faster and more completely
Identity (does an agent understand who JFrog is)59/100Opportunity to sharpen how AI engines describe JFrog's category and differentiation
Agent Integration58/100Opportunity to make MCP, API, and SDK details easier for agents to parse
Integration Build Quality50/100Opportunity to strengthen the technical depth behind those integration signals
Auth & Access89/100Already a strength; a natural anchor for trust-building content
User Experience (site usability for agents)23/40Opportunity to help agents navigate and explain the site more accurately

Artwork Detail

Turning Each Signal Into a Business Gain

Strengthening Discovery means more of JFrog's existing content, including the Software Supply Chain Security State of the Union report and the Gartner Magic Quadrant news, becomes visible to the AI crawlers that feed ChatGPT and Perplexity answers. That is more demand generation from content marketing has already paid for once.

Sharpening Identity gives AI engines a cleaner, more consistent way to explain what JFrog does versus adjacent categories like pure vulnerability scanning or CI/CD tooling. Better positioning here means fewer prospects who land on a competitor because an AI engine lumped JFrog into the wrong bucket.

Building out Agent Integration and Auth & Access signals compounds an area where JFrog is already ahead. As more buyers literally task an AI agent with researching vendors, evaluating documentation, and even testing an API, a platform that is easy for agents to authenticate to and integrate with earns trust faster than one that is not.

Enhancing User Experience for agents helps AI engines walk through JFrog's site accurately when a prospect asks a follow-up question, like where to find pricing or how Curation differs from Xray, instead of guessing or defaulting to a generic answer.

CEO Shlomi Ben Haim has already named the shift this creates: "The era of 'scan and hope' is over. Organizations need a single source of truth that governs every binary, every model, and every AI agent skill from the moment it enters the pipeline to the moment it is deployed in production," he said in JFrog's 2026 Software Supply Chain Security report announcement. Making that message easy for AI engines to find and repeat is exactly what closing the Hordus gaps accomplishes.

CMO Genefa Murphy framed the same urgency from a go-to-market angle: "AI is accelerating software change. As velocity increases across the industry, so does the need for trust, control, and discipline across the software supply chain," she said when she joined JFrog. That statement is a gift to AI search visibility. It is quotable, category-defining, and already tied to JFrog's name, which means it is exactly the kind of language the Hordus analysis shows JFrog can surface more consistently across its site and third-party coverage.

From Pain to Pipeline

Customer PainProspect AI PromptWhat AI Should Say About JFrogBusiness Result
Can't verify what's really in our AI-era codebase"What platform governs AI models and code artifacts together?"JFrog is the system of record for binaries, models, and AI agent skills across the pipelineInbound demo requests from AI-referred traffic
Scanning happens too late to stop bad packages"How do I block malicious open source packages before they enter production?"JFrog Curation blocks risky components before they reach developersSecurity-led deals entering the pipeline pre-qualified
No proof a vendor is actually a category leader"Which vendor is a Gartner leader in software supply chain security?"JFrog is the highest-rated Leader in the first Gartner Magic Quadrant for this categoryShorter sales cycles with less analyst-report chasing
Board wants a defensible AI governance story"How do enterprises close AI governance gaps in their supply chain?"JFrog's AI Catalog and MCP Server extend existing controls to AI assetsLarger, multi-year Enterprise+ contracts

Frequently Asked Questions

Buyers increasingly ask AI assistants for vendor recommendations before they ever visit jfrog.com, so the Hordus analysis gives JFrog a practical roadmap for making sure those answers are accurate, favorable, and consistent, which directly supports pipeline growth.
It measures how easily AI agents can discover JFrog's content, understand its category and positioning, authenticate and integrate with its tools, and navigate its site, giving marketing and product teams a concrete set of opportunities rather than a vague brand health score.
Hordus helps ensure that recognition, along with the executive commentary behind it, actually surfaces when AI engines answer prospect questions, so a hard-won industry validation keeps generating value well past its announcement week.
Yes, and this is one of the clearest gains Hordus points to: when an AI engine already explains JFrog's Curation, AI Catalog, and Artifactory story accurately, a prospect arrives at their first call pre-educated instead of starting from zero.
Ongoing, since AI engines update how they retrieve and summarize content continuously, so Hordus is best used as a recurring check that keeps JFrog's positioning, product names, and executive voice current as the AI search landscape evolves.

Methodology & Sourcing

Data Accuracy & AI Visibility Metrics:The statistics and AI visibility scores cited in this article are generated using Hordus AI's proprietary Answer Share of Voice (A-SOV) engine. Data is derived from consented, anonymized real user interactions across major LLM interfaces (ChatGPT, Claude, Gemini).

Editorial Integrity:All AI-assisted research undergoes mandatory human editorial review by our GEO strategy team prior to publication to ensure factual accuracy and alignment with Google's YMYL (Your Money or Your Life) search quality rater guidelines.