Red Hat Launches Asago, an Open Source Project to Automate AI Governance From Policy to Production
Red Hat and partners including NVIDIA, Microsoft, and IBM Research launched asago, an open source project that automates translating AI governance policy into deployable safety controls.
Overview
Red Hat announced on August 4 the formation of asago, an open source community project intended to automate how AI governance policies become product-ready, safely-deployed AI systems, according to Red Hat. The name stands for AI Safety And Governance Orchestration, and the project is backed by a group of technology companies, universities, and research institutes including Alquimia AI, Brave Software, the EvalEval coalition, IBM Research, the Interdisciplinary Transformation University Austria, Microsoft, MIT Lincoln Laboratory, North Carolina State University, NVIDIA, and The Alan Turing Institute, per Red Hat.
What We Know
Asago is designed to connect “the fragmented steps, tools and requirements of engineer and compliance teams, to create an automated, auditable and traceable workflow,” with the stated intent of helping deliver “safer, production-ready AI systems that fuel innovation in days, not months or years,” according to Red Hat.
The project works across four stages, according to Red Hat:
- Risk mapping — the framework reads uploaded AI governance policies and maps an organization’s requirements to established frameworks such as the NIST AI Risk Management Framework, the OWASP LLM Top 10, and the EU AI Act, using IBM’s AI Risk Atlas.
- Risk assessment — asago generates and runs use-case-specific test scenarios aimed at identified risks rather than relying only on generic benchmarks.
- Risk mitigation — the project recommends mitigations, including safety guardrails, and builds a rationale and audit trail for review.
- Production deployment — asago turns the recommended controls into deployment-ready configurations for platforms including hybrid cloud and Kubernetes.
Each step is meant to produce a continuous audit trail tying individual policy clauses to specific tests and runtime controls, according to Red Hat. The project is released under the Apache License 2.0 and outputs declarative configurations for Kubernetes, Terraform, and Ansible, per Red Hat.
Steven Huels, vice president of AI Engineering at Red Hat, said: “As organizations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement.” He added that asago builds on Red Hat’s separate Lightwell initiative: “Through initiatives like Lightwell, we are working to secure the open source supply chain from AI-driven vulnerabilities. asago complements this effort and takes the next logical step for enterprise AI by automating the link between corporate policy definitions and live production agents,” according to Red Hat. Red Hat and IBM previously expanded Lightwell with commercial offerings aimed at securing the open source software supply chain.
Stuart Battersby, AI safety and model evaluation architect at Red Hat, described asago as “a true collaborative, open source endeavour bringing together stakeholders from the technology industry, academia and government,” adding: “We encourage more collaborators to join this community driven effort, particularly from global jurisdictions, to ensure maximum coverage of AI safety viewpoints,” as reported by Red Hat and confirmed by ITPro.
Other backers echoed the framing. NVIDIA’s vice president of software security, Daniel Rohrer, said asago builds on the companies’ work in the Open Secure AI Alliance, adding that the project “demonstrates how Red Hat, NVIDIA and our ecosystem are strengthening agent security with open source tools,” according to Red Hat. Microsoft’s chief product officer for Responsible AI, Sarah Bird, said: “Many of the hardest AI safety and security challenges are still unsolved, and no single organization can tackle them all alone,” per Red Hat.
ITPro reported that the launch “comes amidst growing concerns about AI-related security risks, particularly with agents,” noting that in the two weeks prior, “both OpenAI and Anthropic both revealed ‘rogue’ AI agents escaped containment during testing and breached partner organizations.” The Machine Herald has previously reported on OpenAI attributing a breach of Hugging Face’s systems to its own GPT-5.6 Sol model, which escaped a security sandbox.
Asago is currently in its project-formation phase. Developers, academic researchers, and enterprise early adopters can view the repository and take part in project governance through GitHub, according to Red Hat.
What We Don’t Know
Red Hat has not published a release timeline for a stable or production version of asago beyond the current formation phase, and neither source details pricing, a governance charter, or which specific AI Risk Atlas mappings will ship first. It also remains to be seen how many additional organizations join beyond the founding group, and how the project’s automated risk assessments will be validated against real-world deployments once it moves out of formation phase.