Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
Frontier AI firm open-sources coding assistant after silent workspace ...
Consecutive series of agentic AI security breaches expose industry rea...
Cohesity Introduces Agent Resilience to Protect and Recover AI Agent I...
LRQA Named ‘Best in Critical Infrastructure Protection’ at...
Ransomware group alleges attack and exfiltration of data linked to maj...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Addressing the AI-driven vulnerability debt

      Addressing the AI-driven vulnerability debt

      Thursday, September 17, 2026, 10:03 AM Asia/Singapore | Features, Sponsored
    • Featured

      Cybercriminals zero In on APAC’s digital boom, SMBs in the crosshairs

      Cybercriminals zero In on APAC’s digital boom, SMBs in the crosshairs

      Monday, September 14, 2026, 2:30 PM Asia/Singapore | Features, Sponsored
    • Featured

      The recovery-first approach to data resilience

      The recovery-first approach to data resilience

      Monday, September 7, 2026, 4:21 PM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

Features

In AI missions, who governs the agents? 

By Victor Ng | Thursday, June 4, 2026, 3:23 PM Asia/Singapore

In AI missions, who governs the agents? 

Like the secret agents in famous movie franchises, autonomous agents can go rogue. That’s why there are “handlers” to manage them. But who’s managing the AI agents in our organizations?

As enterprises in Asia Pacific move from AI copilots to autonomous AI agents within their business operations, an evolving AI supply chain is emerging that many organizations currently lack visibility or governance over.

We find out from Sunny Rao, SVP APAC, JFrog what this means for enterprise AI infrastructure and governance, and for the people managing it.

As enterprises move from AI copilots to autonomous agents operating inside production systems, a new “AI supply chain” is emerging. Why are AI supply chains diverging from traditional software pipelines?

Sunny Rao (SR): The divergence is happening because we are moving away from static code toward a dynamic world of verified skills, MCP servers, models, and software packages. Traditional pipelines weren’t built for autonomous “agents” that can act on their own. In this new landscape, the software supply chain must not only track but also govern the autonomous behaviors and real-time interactions of these agents with enterprise systems.

As IDC noted, the technology underpinning AI Agents is still immature, and issues of reliability, transparency, security and quality still need to be resolved. For this reason, JFrog has partnered with NVIDIA to provide the governance and verifiable trust layer required for agentic workforces to operate securely at enterprise speed and scale.

With support NVIDIA Agent Toolkit – including NVIDIA NemoClaw, an open-source runtime for building and deploying safe, autonomous, long-running AI agents – solutions such as JFrog Agent Skills Registry and JFrog Artifactory will provide the secure operational infrastructure agents need to access verified skills and internal data, ensuring the AI supply chain is protected in a way traditional software pipelines never required.

As AI agents are fundamentally reshaping how software is created and used, what should businesses and developers watch out for in terms of governance and secure workflows?

SR: AI agents are fundamentally reshaping how software is created and operated, but without a dedicated trust layer to enforce governance and secure workflows, they introduce significant enterprise risk. Just as a malicious software package can compromise an application, an unvetted skill can guide an agent to perform harmful actions. To safely deploy autonomous agents at scale, organizations must move beyond blind trust.

For example, working closely with the NVIDIA Enterprise AI Factory team, we have established a reliable system of record to store, scan, and govern all agentic binary assets across the software supply chain. By establishing an integrated, secure registry for NVIDIA AI-Q Blueprint and NVIDIA NemoClaw such as the JFrog Platform, enterprises will be able to safely operate agents using verified skills, MCP servers, models, and software packages.

This ensures that every skill is approved and safe for use at enterprise scale, preventing agents from performing unauthorized actions.

Furthermore, businesses should look for automated systems that automatically scan, verify and sign all AI skills upon upload to detect vulnerabilities, malicious payloads, and compliance risks before NVIDIA NemoClaw – or other agents – ever adopt them. By implementing this scalable, automated governance, developers can continue innovating quickly using pre-approved agents without compromising the security of the enterprise.

What gives rise to unmanaged AI artifacts such as models and agent connectors?

SR: Unmanaged AI artifacts typically arise when developer experimentation moves faster than governance frameworks. Currently, many enterprise AI projects fail to reach production due to compliance, fragmentation, and security risks. In the rush to innovate, developers may pull MCPs, agent skills, models, and software packages from public hubs that haven’t been properly vetted, creating a “Shadow AI” ecosystem.

A common misconception is that simple text-based files, like .md files, don’t need the same level of oversight as traditional code. In reality, any asset – whether it’s an NVIDIA NIM or a markdown-based skill – must be managed, secured and governed like any other software package/binary. Without a central way to track these, organizations lose visibility into what their agents are actually doing.

A secure system of record for scanning and governing these diverse assets helps to identify those with malicious intent or vulnerabilities. This allows IT leaders to move past the fragmentation of experimental stages and safely scale AI initiatives from pilot to profitable production faster. When these workflows are deployed securely at scale, they create tangible business value. For example, in the financial sector, agentic AI systems that autonomously optimize transaction routing can deliver basis point improvements that translate directly into clear, measurable revenue.

How does a dedicated trust layer help enforce governance and security, especially in areas where we lack visibility in the AI supply chain?

SR: A dedicated trust layer eliminates the “visibility gap” by acting as a single, central control plane to track, audit, and manage the provenance of all AI models, agent skills, NVIDIA NIMs, and agentic binary assets across the entire software supply chain. Without this, organizations struggle to see what’s actually happening inside their AI “black boxes.”

Such visibility, in the case of JFrog Artifactory, is enforced through deep integration with NVIDIA NemoClaw, where it natively integrates with the NVIDIA NemoClaw runtime and the NVIDIA AI-Q Blueprint to serve as a secure repository for agent skills.

This built-in governance allows organizations to set strict, centralized approval workflows, ensuring that AI agents and developers can only execute permitted and verified code within sandboxed environments.

Crucially, this layer provides automated verification and scanning. The JFrog Platform automatically scans, verifies, and signs all AI skills upon upload, detecting malicious payloads and vulnerabilities before NVIDIA NemoClaw or other agents can ever adopt them.

Share:

PreviousWorld Cup 2026 cyber threats: Phishing, fake ticketing and infrastructure risks top the list
NextDelta Thailand Showcases Integrated Building Automation Solutions for Smarter, Healthier and More Sustainable Spaces at NOVA Expo 2026

Related Posts

Database security concerns in the cloud

Database security concerns in the cloud

Monday, November 29, 2021

How the UAE proactively protects its digital economy

How the UAE proactively protects its digital economy

Monday, May 19, 2025

Why today’s approach to customer identity is failing and must change

Why today’s approach to customer identity is failing and must change

Monday, August 7, 2023

Why strong cybersecurity is an inextricable part of the Net Zero journey

Why strong cybersecurity is an inextricable part of the Net Zero journey

Thursday, May 23, 2024

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

LEARN MORE

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Cohesity Introduces Agent Resilience to Protect and Recover AI Agent Infrastructure

    Tuesday, September 22, 2026
    Cohesity Agent Resilience launches with …Read More »
  • LRQA Named ‘Best in Critical Infrastructure Protection’ at CybersecAsia Readers’ Choice Awards 2026

    Monday, September 21, 2026
    Prestigious regional recognition highlights LRQA’s …Read More »
  • Cyble and Cyber Security Council of UAE Sign MOU to Strengthen National Threat Intelligence Capabilities

    Thursday, September 17, 2026
    ABU DHABI, UAE, Sept. 17, …Read More »
  • Cohesity Research Finds Most Cyber Recovery Plans Are Built for the Wrong Outcome

    Thursday, September 17, 2026
    78% organizations prioritize restoring systems …Read More »
  • SU Group Secures Exclusive Distribution Rights for Portable X-Ray System in Hong Kong and Macau

    Tuesday, September 15, 2026
    Second International Distribution Deal of …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.