Analyst(s): Vikram Rathnam, Mitch Ashley
Publication Date: October 6, 2026
The DevOps Institute, part of PeopleCert, has released The DevOps Standard, a free official book that brings ITIL (Version 5) ‘s AI governance agenda into software delivery. It does not cite the existing IEEE DevOps standard, and its human-centric model must evolve with AI-native development, or agents will outgrow it.
What Is Covered in This Article:
- What the DevOps Institute published in The DevOps Standard, and how PeopleCert is distributing it.
- Why PeopleCert is extending its ITIL and PRINCE2 certification business into AI-driven software delivery.
- What The Futurum Group’s survey data shows about DevOps maturity, AI adoption in development, and agent governance.
- How the book’s agent authorization model handles the verification bottleneck in AI-assisted delivery.
- What enterprise technology leaders and platform vendors should do in response.
The News: The DevOps Institute, which PeopleCert acquired in February 2023, released The DevOps Standard (Version 1.0) in October 2026. PeopleCert describes the book as “the vendor-neutral model for the AI-driven world” and offers the digital edition free in exchange for a registration form. In an October 2026 LinkedIn post, Pascal Mevellec of PeopleCert called it “the first ever DEVOPS INSTITUTE Official Book.
The book defines the DevOps Institute (DOI) Operating Model around Nine Pillars of practice, a four-layer DevOps Blueprint, a maturity self-assessment, a 90-day transformation playbook, and a metrics reference that includes DevOps Research and Assessment (DORA) metrics and AI-specific measures. A chapter on AI-native DevOps defines controls for generative and agentic AI, including agent authorization by class of action. Marc Hornbeek is the lead contributor, and the book credits contributors from companies including Dynatrace, Cisco, Adobe, and Visa.
The book says it serves as the body of knowledge for the DevOps Institute certification portfolio within PeopleCert, which also owns ITIL and PRINCE2. PeopleCert released ITIL Foundation (Version 5) in February 2026, with AI Governance as the scheme’s only extension module.
Details are on PeopleCert’s page for The DevOps Standard.
Does a 17-Year-Old Movement Need a DevOps Standard?
Analyst Take: DevOps turns 17 this month, and PeopleCert now offers a formal DevOps standard. The first devopsdays met in Ghent, Belgium, on October 30 and 31, 2009.
PeopleCert is building an AI governance franchise across its portfolio. ITIL (Version 5) added AI governance to IT service management in 2026, and The DevOps Standard from the DevOps Institute carries the same agenda into software delivery. We view the move as commercially sound and the book as a well-built retrofit: useful today, but built on a human-centric delivery model that must evolve in parallel with the AI development lifecycle (AI DLC), or agents will outgrow it.
PeopleCert calls the book “the common language DevOps has been missing.” DevOps already has a formal standard. IEEE 2675-2021, adopted internationally as ISO/IEC/IEEE 32675 in 2022, defines DevOps processes for building and deploying software with compliance controls, and the book does not cite it.
Google Cloud’s DORA program also publishes an AI Capabilities Model, updated in November 2025, that names seven capabilities organizations need to get value from AI. A standard that wants to be the common language will have to explain how it relates to both.
PeopleCert Extends Its ITIL Franchise Into AI Delivery
PeopleCert is extending a commercial qualification franchise that includes the highly successful adopted ITIL, PRINCE2, and the DevOps Institute. Now, PeopleCert moves into AI-driven software engineering, and The DevOps Standard doubles as the curriculum for its DevOps Institute certifications.
Just as DevOps changed the process and flow of how software is created, built, and operated, rapid advances in AI-native development are upending development methods and delivery on a near-weekly basis. Teams adopting AI coding assistants and agents face tool sprawl across cloud, on-premises, and multi-vendor environments, while cloud providers and tool vendors offer adoption frameworks tied to their own ecosystems. PeopleCert is addressing that gap by placing the DOI Operating Model above individual toolchains as a neutral baseline for risk, governance, and maturity for DevOps and the move to AI.
ITIL governs how IT services run, PRINCE2 governs how projects run, and the book places DevOps as the delivery system that connects them. A DevOps standard with AI controls lets PeopleCert sell AI delivery governance to the IT governance buyers who already certify their teams on ITIL.
The Futurum Group’s survey data shows why the timing works. DevOps is mature in just over half of organizations. In the 2H 2026 Software Lifecycle Engineering Global Enterprise Decision Maker Survey (n=839, fielded June 2026), 58% of organizations rated their DevOps practices as standardizing or mastering (1H 2026 Software Lifecycle Engineering Decision Maker Survey Report, January 2026, document 1H26DMSLCEMA202601), yet governance has not kept pace with AI adoption.
In the same survey, 40% of organizations said AI generated or substantially modified most (51% or more) of the production code they merged during the previous 90 days. Only 18% rated their AI-agent governance practices as standardizing or mastering, making governance the least mature practice measured. That governance gap is the market PeopleCert wants.
The risk is pace. ITIL has rightfully taken criticism for being slow to adopt DevOps and update the framework. Certification frameworks have moved on to multi-year cycles, and ITIL went from v3 in 2007 to ITIL 4 in 2019. Then, it waited seven years for Version 5 and its AI module. A syllabus on that cycle, it will quickly trail agent platforms that ship changes every few months, and the gap between static compliance models and platform execution will widen.
Most Organizations Haven’t Made Verification Mandatory
In the same 2H 2026 survey, three-quarters of organizations reported a production incident in the past 12 months where AI was a contributing factor, yet only 43% make human review of AI-generated code mandatory. At most organizations, the review gate the book assumes is still optional.
Eliyahu M. Goldratt’s Theory of Constraints explains the pressure (The Goal, with Jeff Cox, 1984; Theory of Constraints, 1999). When one constraint is removed, another becomes the limit, and AI has moved software delivery’s limit from writing code to proving it works. Verification debt, a term Sonar credits to AWS CTO Werner Vogels for AI output no one has checked, grows faster than organizations can hire reviewers.
Organizations without mandatory review should start with the book’s agent authorization model now. It sorts agent actions by risk, from output a person reads and decides on, to changes a person must approve, to high-impact actions that need explicit sign-off from a named owner.
The DevOps Standard – Surviving the AI-Native Onslaught
AI bolted onto human-centric delivery models hits a ceiling that AI-native models don’t, and The DevOps Standard is built on human-centric design. Its own framing says so: AI changes the DevOps system “while the fundamentals still apply.”
The ceiling is human approval, and the person who performs the work. When every assisted code change needs a person to review and authorize it, the people approving agent work becomes the throughput limit, the same limit we flagged in our analysis of OpenAI’s agent platform this week. In the same survey, 58% of organizations expect AI to create 80% or more of their software within three years, and per-change approval won’t hold at that volume.
The book has a better answer, but treats it as the exception. For low-risk operational tasks, such as gathering diagnostics or restarting an approved non-critical service, people approve a type of action once and then review only the exceptions.
Extending that approach to code changes would help, but it wouldn’t be enough. As our colleague Fernando Montenegro argued in June 2026, people authorize an agent’s goal, and the agent then infers actions nobody anticipated, so a list of pre-approved action classes will miss some of what agents actually do. A second edition will need governance at the level of goals and outcomes, and it will be needed sooner than PeopleCert’s certification cycle suggests.
What Buyers and Vendors Should Do Now
For CIOs, CTOs, and engineering leaders:
- Fund verification alongside generation. Keep scaling AI coding tools and agents, and put automated testing, contract testing, and pipeline policy enforcement in the same budget. Code generation without automated validation adds verification debt and production incidents.
- Authorize agents by action class. Require platform and security teams to give every agent workflow-bound permissions, traceable provenance, a tested kill switch, and a named human owner for high-impact changes.
- Pilot The DevOps Standard on one workflow before rolling it out. Baseline waiting time, rework, failed changes, and recovery, then track whether the assessment leads to funded improvements.
For platform and tool vendors, including GitHub, GitLab, Harness, Atlassian, and Dynatrace:
- Publish agent evidence in open formats. Buyers running mixed stacks need provenance, agent context logs, and test results they can pull into their own release controls. Vendors should back the open OpenSSF proposal for an in-toto attestation that records AI authorship, alongside Supply-chain Levels for Software Artifacts (SLSA) provenance, and adopt OpenTelemetry’s generative AI conventions for agent traces.
- Put policy hooks where developers work. Agents and automated remediation need policy checks, security scanning, and cost telemetry inside the developer workflow. Platforms without observable audit trails and reversible actions will struggle to pass enterprise risk and compliance reviews.
What to Watch:
- Whether PeopleCert launches a certification built on The DevOps Standard, bundles it with ITIL (Version 5) AI Governance, and reports how many practitioners hold it by the end of 2027.
- Whether PeopleCert addresses IEEE 2675 and DORA’s AI Capabilities Model, or positions The DevOps Standard as a replacement for both.
- Whether DevOps vendors, including GitHub, GitLab, Harness, or Atlassian, publish agent evidence in open formats such as SLSA provenance or OpenTelemetry traces, or keep it inside their own platforms.
- Whether regulated buyers in financial services or the public sector adopt the maturity self-assessment as audit evidence.
- Whether a second edition moves beyond human approval toward governance designed for agent goals and volume, and how soon it ships.
See the complete details on the book from PeopleCert on PeopleCert’s website.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
Atlassian Bets the Work Surface on Governed Agentic Workflows
OpenAI Moves Up the Stack and Competes With the Platforms It Powers
Platform Engineering Goes Mainstream: Strategy Beats Technology
