GitLab Scales Agentic AI Across Trusted DevSecOps Workflows
News | 28.08.2026
Enterprises want the productivity of agentic AI without loosening the security, residency, and permission boundaries their auditors already trust. GitLab 19.3 addresses this gap by embedding agentic workflows directly inside existing DevSecOps controls.
Regulated and data-sensitive organizations face a difficult trade-off: adopt agentic AI to accelerate software delivery, or preserve the strict isolation, secrets governance, and vulnerability management practices they already rely on. GitLab is closing that gap by extending its intelligent orchestration platform with new agentic capabilities that operate inside the same trusted boundaries.
What was announced
On August 20, 2026, GitLab announced updates to help enterprises scale agentic software development with more control. GitLab Dedicated AI Gateway is now generally available, allowing customers to run GitLab Duo Agent Platform inside GitLab Dedicated single-tenant SaaS infrastructure, connect their own inference models, and keep AI-processed data within their existing security boundary.
GitLab 19.3 also ships with GitLab Secrets Manager in limited availability as a paid add-on billed through GitLab Credits. It now supports Kubernetes, Terraform, OpenTofu, and custom tools, applying one permission model to every secret used inside or outside CI pipelines.
Bulk SAST False Positive Detection and Agentic SAST Vulnerability Resolution, now in beta, let security teams triage thousands of open findings in a single action and receive ready-to-merge fixes for confirmed risks. Flow Creator Agent, now generally available, converts plain-language descriptions into complete, runnable custom flows without requiring knowledge of the Flow Registry schema.
Why this matters
For CIOs, CISOs, IT directors, and procurement leaders, these updates directly address the core blockers to enterprise-scale agentic AI adoption: data residency, secret sprawl, unresolved vulnerability backlogs, and slow custom automation. Running the AI Gateway inside GitLab Dedicated means agentic workloads follow the same isolation and residency model auditors already understand.
Secrets Manager consolidates credential control across pipelines and infrastructure, reducing the number of separate permission systems teams must maintain. Bulk SAST remediation helps clear years of accumulated risk with a single action, freeing security teams from one-by-one triage. Together, these capabilities preserve enterprise control while unlocking measurable productivity gains for development, security, and process-owner teams.
Technical details
- Dedicated AI Gateway: generally available inside GitLab Dedicated single-tenant SaaS with bring-your-own-model inference.
- Secrets Manager: limited availability as a paid add-on via GitLab Credits, supports Kubernetes, Terraform, OpenTofu, and custom tools.
- Bulk SAST False Positive Detection and Agentic SAST Vulnerability Resolution: in beta, covers every SAST finding in the Vulnerability Report with confidence scoring and ready-to-merge fixes.
- Flow Creator Agent: generally available through Agentic Chat, produces runnable flows registered from the AI Catalog with scoped service accounts and composite identity.
- GitLab Credits usage caps: generally available with subscription, default per-user, and per-user override controls via the Customers Portal and GraphQL API.
- Group-level restricted visibility: generally available for custom agents and flows across multiple projects within a GitLab group.
Every capability we shipped this month, from where an agent runs to which secret it can touch, extends that same control into the trusted software delivery workflows enterprises already depend on
Softprom and GitLab
Softprom is the official partner of GitLab. Our team helps enterprises deploy, license, and scale GitLab Duo Agent Platform, GitLab Dedicated, and adjacent DevSecOps capabilities across regulated environments.
Ready to bring agentic AI into your DevSecOps workflows? Contact Softprom to plan your GitLab rollout, licensing, and enablement.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.