Red Hat has unveiled asago, a new open-source initiative designed to bridge the gap between AI governance policies and real-world deployment practices by automatically converting regulatory and organizational requirements into executable, production-ready controls.
The project aims to address one of the biggest challenges facing organizations deploying Artificial Intelligence at scale: ensuring that AI systems remain compliant with evolving regulations and internal governance frameworks without slowing innovation through manual review processes.
Released under the Apache 2.0 open-source license, asago is currently in its early formation stage and is available on GitHub for developers, researchers, enterprises, and policy experts interested in contributing to its development.
Turning AI Policies Into Actionable Controls
According to Red Hat, asago was created to eliminate the disconnect that often exists between compliance teams defining governance requirements and engineering teams responsible for deploying AI applications.
As AI regulations such as the European Union AI Act begin taking effect, organizations face increasing pressure to demonstrate that AI systems are being deployed responsibly and in accordance with regulatory obligations. However, translating policy documents into enforceable technical controls remains a largely manual and resource-intensive process.
Asago seeks to automate that workflow by creating a continuous pipeline that connects governance requirements directly to testing, risk assessment, mitigation, and deployment mechanisms.
Four-Step Governance Workflow
The framework operates through four primary stages designed to transform policy language into practical security and compliance controls.
1. Risk Mapping
The process begins by analyzing an organization's governance policies and aligning them with recognized AI risk-management frameworks.
Asago can map requirements against standards and guidance including:
- NIST AI Risk Management Framework (AI RMF)
- OWASP LLM Top 10
- EU AI Act requirements
- IBM's AI Risk Atlas
This allows governance policies to be automatically transformed into structured risk profiles rather than relying on manual interpretation by compliance teams.
2. Risk Assessment
Once risks are identified, the platform generates testing scenarios tailored to the organization's specific AI use cases.
Rather than using generic checklists, asago focuses testing efforts on the actual risks associated with a given application and evaluates how the AI system behaves under those conditions.
3. Risk Mitigation
After assessing results, the framework recommends appropriate safeguards and mitigation strategies.
The system also maintains detailed documentation explaining why each recommendation was selected, creating transparency and helping organizations justify decisions during internal reviews or external audits.
4. Deployment Automation
The final stage translates approved controls into deployment-ready configurations.
According to Red Hat, these controls can be automatically orchestrated across:
- Kubernetes environments
- Hybrid cloud infrastructures
- Terraform deployments
- Ansible automation frameworks
By automating implementation, organizations can significantly reduce the time required to move from risk identification to operational protection.
Red Hat claims the approach could potentially reduce deployment timelines from months to days.
Continuous Audit Trail and End-to-End Traceability
One of the project's most notable capabilities is its focus on traceability.
Asago continuously links:
- Policy requirements
- Risk assessments
- Security tests
- Mitigation recommendations
- Runtime controls
This creates a unified audit trail that enables organizations to trace any active safeguard directly back to the policy requirement that originally justified its implementation.
The goal is to make AI governance a continuous operational function rather than a one-time certification exercise.
Instead of validating compliance only before deployment, organizations can maintain ongoing visibility into whether AI systems continue operating within approved governance boundaries.
Supporting the Rise of Autonomous AI Agents
Red Hat positions asago as particularly important as enterprises move beyond experimental AI projects and begin deploying autonomous AI agents that operate continuously in production environments.
According to company executives, organizations increasingly need mechanisms that can automatically enforce governance requirements without requiring constant manual oversight.
The initiative also complements Red Hat's broader AI security efforts, including projects focused on securing open-source software supply chains and reducing risks introduced by AI-generated code and dependencies.
Broad Industry and Academic Collaboration
Although Red Hat and NVIDIA initiated much of the foundational work through the Open Secure AI Alliance, asago is being developed as a community-driven project supported by a diverse coalition of organizations.
Contributors include:
- NVIDIA
- IBM Research
- Microsoft
- MIT Lincoln Laboratory
- Brave Software
- North Carolina State University
- The Alan Turing Institute
- EvalEval Coalition
- Interdisciplinary Transformation University (IT:U)
- Alquimia AI
The broad participation reflects growing recognition that AI governance challenges cannot be solved by any single vendor, government, or research institution alone.
The project's organizers are actively encouraging contributions from additional stakeholders, including international regulators, academic researchers, and private-sector organizations, to ensure that multiple perspectives on AI safety and governance are represented.
Infrastructure-Agnostic Design
A key architectural principle behind asago is portability.
The framework is designed to generate infrastructure-independent deployment artifacts, allowing governance controls to be applied consistently across different cloud providers and environments.
This approach helps organizations avoid rebuilding compliance and security controls each time workloads move between platforms or cloud providers.
Still in Early Development
Despite the project's ambitious goals, asago remains in its early stages.
At present:
- No large-scale production deployments have been publicly documented.
- No customer case studies have been released.
- No independent validation exists for claims regarding deployment speed improvements.
- Governance processes for resolving conflicts among contributors have yet to be fully demonstrated.
As a result, the initiative currently serves more as a collaborative development effort than a finished enterprise product.
Conclusion
As AI adoption accelerates and regulatory scrutiny increases worldwide, organizations are searching for practical ways to operationalize AI governance at scale. Red Hat's asago project addresses this challenge by automating the transformation of policy requirements into deployable technical controls, creating a continuous link between governance, security testing, risk mitigation, and production enforcement.
Backed by major technology companies, research institutions, and academic organizations, asago represents an emerging effort to treat AI governance not simply as a compliance exercise, but as a programmable, auditable, and continuously enforceable part of modern infrastructure. Whether it can achieve its goal of turning AI policy into executable code remains to be seen, but it reflects a growing industry shift toward automation-driven governance in the age of AI.
Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post.
