Semgrep Guardian now reports its setup, runtime status, scan summary, findings, sign-in requirements, and server errors inside the AI coding agent, giving release owners direct evidence that AI-assisted coding was scanned.
For organizations moving AI coding tools into governed delivery workflows, the September updates address a practical control gap: security checks must be visible, attributable, and exportable without forcing teams to reconstruct evidence after a release.
Make AI-assisted coding controls visible
Guardian’s new in-agent reporting confirms whether the service is active and summarizes what was scanned and found when an agent finishes a turn. It also communicates authentication and server problems where developers can act on them.
This changes the workflow in useful ways:
- Developers can see whether scan feedback was actually available during AI-assisted work.
- Engineering leaders gain a clearer operational signal than a silent background integration.
- Release owners can investigate scan coverage exceptions before approving promotion.
- Platform teams can distinguish configuration or access failures from an absence of findings.
The feature does not replace CI policy gates or formal review. It strengthens the developer-side evidence trail that supports those controls.
Export Agentic Workflows findings for governance
Semgrep Multimodal now supports CSV export of Agentic Workflows issues from the Issues page and through the public API. This is important for enterprises that need findings to move beyond a single product interface.
Teams can use exports to:
- Feed security findings into GRC, data warehouses, or internal reporting pipelines.
- Reconcile AI-assisted development findings with tickets and remediation owners.
- Measure recurring issue categories across repositories and business units.
- Preserve release evidence according to internal audit and retention requirements.
Older Agentic Workflows runs also display a banner linking to the newest run of the same workflow on that branch. That reduces the chance of a reviewer making a decision from stale results. Governance teams can review exports with less manual reconciliation.
Improve branch fidelity and finding context
A correction to scheduled AI-powered detection scans ensures Semgrep Managed Scans uses configured branches rather than the source-code manager default branch. When necessary, the system falls back to the project primary branch.
For release governance, branch selection is not a minor implementation detail. Default branches may not represent a release candidate, a supported maintenance line, or a regulated deployment stream. Security teams should confirm that configured scan branches match their actual promotion model.
The release also fixes an issue in which an Agentic Workflows finding could display snippets and links from the wrong repository within the same deployment. Correct repository attribution is fundamental for triage, remediation ownership, and audit defensibility. A finding attached to the wrong codebase can create wasted investigation work and inaccurate reporting.
Remove friction in private delivery environments
Branch checks now work when branch names contain slashes for deployments using Semgrep Network Broker or a private-link gateway. This matters for organizations that use private connectivity and conventional branch structures such as feature/service-name or release/2026.09.
The AppSec Platform also corrects Autofix messaging when Semgrep Multimodal is disabled. Instead of referring to a missing AWS Bedrock provider, the product now directs users to the relevant Semgrep Multimodal setting. Clear error messages reduce support effort and shorten incident diagnosis.
Semgrep Supply Chain additionally improves the performance of scan configuration requests. While this is not a policy change, faster configuration retrieval can reduce operational drag in large-scale scanning environments.
Recommended actions for platform and security leaders
Review the September changes against existing AI coding and release-control practices:
- Enable and test Guardian status reporting in approved AI coding agent environments.
- Define who consumes Agentic Workflows exports and where findings become systems of record.
- Compare Managed Scans branch settings with release, hotfix, and long-term support branch policies.
- Validate repository links and branch checks in private-network deployment paths.
- Update operational runbooks for Multimodal settings and Autofix troubleshooting.
These checks help turn product behavior into an accountable delivery control, not merely a developer convenience.
How Merito helps
Merito helps enterprises map Semgrep capabilities to release governance, CI/CD controls, and evidence requirements. Our teams can assess branch and repository coverage, design export integrations for reporting and ticketing, and establish practical ownership for AI-assisted development findings.
The goal is clear: security signals should reach the right engineer quickly while giving release leaders dependable evidence for decisions.
Merito is an authorized Semgrep reseller and services partner. Our Semgrep team can scope licensing, sizing, and rollout for September 2026, and our enterprise upgrade services help you plan and validate the upgrade with minimal disruption to release schedules.

.png&w=2560&q=75)