AI-written code is a supply chain problem first. GitLab's governed software factory starts there
GitLab announced controls for dependencies, secrets, artifacts and AI spend around its agent platform. Each ships at a different maturity, and the order matters more than the headline.
Listen to this article · 5 min
AI-generated narration of the full article.

The debate about AI coding agents is still mostly about productivity: how much faster, how many more pull requests, how many hours back. That is the visible effect. The one that compounds is quieter. An agent that writes more changes also pulls in more packages, touches more credentials and opens more paths to production. Before AI-written code is a productivity question, it is a supply chain question.
GitLab’s announcement on October 6 reads as if it starts from the same premise. It calls the package a “governed software factory”, and its chief product and marketing officer, Manav Khurana, puts the problem plainly: “Every enterprise already runs a software factory, but few have intentionally designed the systems and controls that govern it.”
Controls where agent-written code meets the outside world
The interesting parts of the release are not the agents. They are the controls placed at the points where generated code touches something the organization did not write.
Dependencies. The Dependency Firewall, in early access, checks every package against policy before it enters a build, and warns, blocks or quarantines it based on rules for package age, vulnerability severity, malicious package detection and license. Package age is the quietly important rule. Coding assistants have been shown to suggest packages that do not exist, and attackers register those names. A rule that holds back packages published yesterday closes much of that gap without anyone reviewing a single suggestion.
Secrets. Secrets Manager, generally available on GitLab.com and arriving for self-managed customers in version 19.5, keeps build-time secrets in one place and scopes each one to the job that needs it. When an agent triggers a pipeline, job scoping decides how much a compromised step could reach.
Artifacts. Artifact Central, in beta on GitLab.com with self-managed availability planned for later this month, brings containers and packages into one control plane with source code and CI. The value for governance is traceability: which artifact came from which change, authored by whom or by what.
Remediation. The GitLab Security Standard, available now, sets five controls for agentic development and uses detection to verified remediation time as its core metric. The word that matters is verified. A security program measured by findings rewards volume; one measured by verified fixes rewards evidence.
Spend. Impact Analytics for the Duo Agent Platform, in early access, reports AI cost and impact by team, task and model, and new usage caps let administrators set ceilings at subscription, group or user level.
GitLab also says Anthropic’s Claude Mythos 5 and 5.1 will power new security flows next month, and that its Orbit context service will reach general availability next month. GitLab’s own efficiency claims, such as up to 50% lower total cost of ownership for Artifact Central and up to 50% savings for Secrets Manager against separate vaults, are vendor figures and should be read that way.
Read the maturity, not the headline
Lay the statuses side by side and an uncomfortable order appears. The goal-driven flows that let agents move work across the lifecycle are generally available today. The firewall that checks what those agents pull into a build is in early access. The analytics that show what they cost are in early access. The unified artifact control plane is in beta.
That is not a criticism of GitLab, which is shipping controls faster than most. It is a description of how most organizations adopt AI coding: throughput first, controls when they arrive. The safer order is the reverse. Turn on agent-driven flows for a team when the packages, secrets and artifacts those flows touch are governed at least as well as the code they write.
This connects to an argument we made about agents as authors of production changes: the control that governs them already exists in the delivery pipeline, and it needs to know when the author is an agent. GitLab is putting more of that pipeline under policy. It is also a reminder of why security agents work best inside code review, where their output meets a gate a person already owns, and why AI spend needs guardrails set by the same people who set permissions.
The measure of an AI coding program is not how much code agents write. It is whether every package, secret and artifact that code depends on passed through a control someone can name.