Red Hat has launched asago, an open-source community project that aims to turn AI governance policy into production-ready deployment code.
The project describes itself as an automated, auditable workflow that connects the âfragmented steps, tools, and requirementsâ of engineering and compliance teams. With regulation such as the EU AI Act now taking effect, Red Hat frames the choice facing organisations as: either grind AI innovation down through manual review, or let ungoverned agents run in production without anyone checking their behaviour against policy.
asago builds on Red Hat and NVIDIAâs work inside the Open Secure AI Alliance. It is being released under the Apache License 2.0, and the project is currently in its formation phase, with a repository open on GitHub for developers, academic researchers, and enterprise early adopters to review and contribute to governance.
Four stages from policy text to running controls
The workflow Red Hat describes runs across four stages. Risk mapping comes first: the framework reads an organisationâs uploaded governance policy and maps its specific requirements against established frameworks, including the NIST AI RMF, the OWASP LLM Top 10, and the EU AI Act as catalogued via IBMâs AI Risk Atlas. Policy language becomes a risk profile automatically, rather than through a compliance teamâs manual cross-referencing.
From there, asago moves into risk assessment. The project generates and runs scenarios tailored to the specific use case, probing for the harmful behaviours that its risk mapping flagged rather than testing against a standard checklist. Risk mitigation follows: the system recommends guardrails based on what the testing surfaced, and builds a rationale trail meant to survive a reviewerâs scrutiny.
asago orchestrates the recommended controls into deployment-ready configurations for hybrid cloud and Kubernetes environments, according to Red Hat, cutting out the manual infrastructure coding that would otherwise sit between a mitigation recommendation and a running control. Red Hatâs stated aim is to cut deployment timelines from months to days.
Audit-trail-as-a-product
Every stage is meant to feed a single, continuous audit trail. Each policy clause ties to a specific test, and each test ties to a runtime control. A reviewer, in principle, can trace any active control in a live deployment straight back to the policy line that justified it.
That traceability is the actual selling point. Red Hatâs own framing treats AI safety less as a one-off certification exercise and more as an ongoing enterprise utility (i.e. something that stays checkable as agents keep running, not just at the point theyâre first approved.)
Steven Huels, Red Hatâs VP of AI Engineering, says: âAs organisations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement.â
Huels connects asago to Red Hatâs separate Lightwell initiative, which focuses on securing the open-source supply chain from AI-driven vulnerabilities, calling asago âthe next logical step for enterprise AI by automating the link between corporate policy definitions and live production agents.â
Stuart Battersby, Red Hatâs AI safety and model evaluation architect, is more direct about the projectâs intended shape: âThe asago project is a true collaborative, open-source endeavour bringing together stakeholders from the technology industry, academia, and government.
âWe encourage more collaborators to join this community-driven effort, particularly from global jurisdictions, to ensure maximum coverage of AI safety viewpoints.â
A roster of major contributors, not a single vendor
The founding list runs far wider than Red Hat and NVIDIA. Brave Software, IBM Research, Microsoft, MIT Lincoln Laboratory, North Carolina State University, and The Alan Turing Institute all appear as contributors, alongside the EvalEval coalition and Austriaâs Interdisciplinary Transformation University (IT:U). Alquimia AI, a partner rather than a founding research institution, is also named.
Sarah Bird, Chief Product Officer for Responsible AI at Microsoft, comments: âMany of the hardest AI safety and security challenges are still unsolved, and no single organisation can tackle them all alone.â
Academic voices push a similar line from a different angle. NC Stateâs Veena Misra, Interim Dean of the College of Engineering, calls AI safety âan engineering problem as much as a policy problem.â
asagoâs outputs are meant to be infrastructure-agnostic: declarative configurations for Kubernetes, Terraform, and Ansible, according to Red Hat, so a safety posture set in one cloud doesnât need re-engineering in another.
Nothing about the project is production-tested yet. Thereâs no deployed customer case study in Red Hatâs announcement, no benchmark showing the âdays, not monthsâ claim holding up under a live regulatory audit, and no indication of how disputes between contributing organisations over risk-mapping standards get resolved once the code moves past formation.
For now, the project exists as a repository and a governance structure on GitHub, open to developers, researchers, and enterprise teams willing to build alongside a list of contributors rather than adopt a finished product.
See also: OpenAI aligns safety practices with EU AI Actâs GPAI Code
Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
Read the full article here