AI-assisted development is changing what’s actually inside government software — and fast. JFrog’s 2026 Software Supply Chain Security State of the Union report found over 48,000 new CVEs disclosed in 2025, a 20% year-over-year jump partially driven by AI-generated code. At the same time, Canadian federal departments are operating under a converging set of requirements — PSPC’s Software Supply Chain Risk Mandate, Bill C-26, and Treasury Board cyber directives — that all point to the same foundational practice: the Software Bill of Materials (SBOM). The departments that get ahead of this will know exactly what’s in every release, whether a human or an AI wrote it.
Join JFrog Field CISO Paul Davis and DCI’s Lester Wong for a practical look at governing software supply chain risk in the AI-accelerated development era: what’s changing, what departments are accountable for, and how to build an audit-ready compliance posture without slowing delivery down.
We’ll close with how Canadian public sector organizations can access the JFrog Platform through the SLSA Catalogue via DCI.
What You Will Learn:
- How to govern AI-generated code like any other supply chain risk. Extend SBOM and component visibility to AI-assisted and AI-generated code, so “who wrote this” stops being a blind spot.
- How to answer “are we affected?” in minutes, not days. Use continuous component visibility to identify exposure across your application portfolio the moment a new CVE is disclosed.
- How to procure a proven platform through an approved vehicle. Access JFrog’s SBOM and software supply chain capabilities through the SLSA Catalogue via DCI, without a full procurement cycle.
