GitLab AI Catalog Update Brings Stronger AI Governance Controls

GitLab just gave enterprise teams a reason to breathe easier. On June 18, the company rolled out fresh AI governance controls inside its AI Catalog, and the timing couldn’t be better. Many security teams have struggled to answer one simple question: what’s actually running in our environment, and who approved it?
With GitLab 19.1, that question finally gets a clear answer. The release ships event-driven triggers for Duo Flows alongside the governance controls and config validation that make running them safely possible. As a result, teams can now run AI workflows continuously. No one needs to sit around waiting to pull a trigger.
Previously, every flow needed a human to start it. Every GitLab Duo Flow trigger required a manual action in the GitLab UI, such as a mention, an assignment, or a reviewer assignment. That setup blocked teams from running flows automatically or fitting them into production pipelines. Now, four new triggers change the game entirely. For instance, GitLab can detect merge conflicts the moment they happen and immediately suggest a fix. Likewise, marking a request “ready for review” can trigger an automatic compliance check. Meanwhile, an approved merge request can kick off deployment checks on its own.
These AI governance controls don’t stop at automation, though. GitLab also added two settings that protect production environments from risk. Admins can now block custom-built agents entirely, or restrict the AI Catalog to approved content within their own group hierarchy. Consequently, unvetted community tools and third-party flows can no longer sneak into sensitive systems.
Equally important, GitLab tackled a quieter but costly problem: misconfigured flows. Therefore, before any flow saves, GitLab now validates it against the Duo Workflow Service. If something’s missing or broken, the system flags it instantly. This way, mistakes get caught early, not during a 2 a.m. pipeline failure.
Finally, GitLab introduced a public beta for model governance. Admins can build an allowlist of approved AI models and set an organization default. This feature currently works with GitLab Duo Agentic Chat, and broader coverage across additional surfaces will follow soon.
Altogether, these updates push GitLab Duo closer to safe, production-ready automation.





