Wednesday, August 5, 2026

Operationalizing AI Compliance: Red Hat Launches Open Source ‘asago’ Community

Related stories

As AI moves beyond pilot projects to full deployment, companies encounter a major stumbling block: converting abstract policies for governance into code that runs in production.

To overcome this challenge, Red Hat revealed its launch of asago (AI Safety And Governance Orchestration), an open-source community project dedicated to automating the transition from enterprise governance policy to safely deployed AI.

Developed in collaboration with industry giants and research powerhouses including Microsoft, NVIDIA, IBM Research, Brave Software, MIT Lincoln Laboratory, and The Alan Turing Institute asago aims to eliminate manual compliance overhead while creating auditable, traceable workflows for enterprise AI models and autonomous agents.

What is asago? Bridging Policy and Production

A misalignment between the two teams of people who are supposed to ensure compliance with policy (policy team) and the team of people developing software products (engineering leads) has become a bottleneck for AI adoption by enterprises. The compliance team creates policies that are based on legislation (like the EU AI Act or the NIST AI RMF). Then, the engineers need to manually convert these policies to infrastructure configurations, which may take months and pose a risk of mistakes or untracked shadow AI projects.

Released under the Apache License 2.0, asago provides a fully automated framework spanning over four major stages:

  1. Risk Mapping: Automated reading of AI policies and mapping them to the recognized risk frameworks (such as the OWASP LLM Top 10, NIST AI RMF, the EU AI Act) using the IBM AI Risk Atlas.
  2. Risk Assessment: Creation of use-case-specific adversarial safety tests to uncover the weaknesses in the models, as opposed to benchmark testing.
  3. Risk Mitigation: Generation of concrete guardrails and mitigations, complete with an explanation.
  4. Production Deployment: Turning of the approved controls into declarative infrastructure configurations (such as Kubernetes, Terraform, and Ansible).

Also Read: ReliaQuest Launches GreyMatter Attack: How Agentic AI Is Redefining Cybersecurity & Exposure Management

Impact on the Enterprise AI & IT Software Industry

The launch of asago signals a pivotal shift in how the enterprise IT industry handles AI governance.

  1. Shift from “Manual Compliance” to “DevOps-Native Guardrails”

Traditionally, security and legal reviews functioned as external checkpoints that delayed deployment schedules. By integrating governance into standard GitOps and CI/CD pipelines, asago elevates compliance from a static post-hoc report into a continuous, programmatic utility.

  1. Industry Standard for Both Hybrid and Multi-Cloud

Since asago generates platform-independent deployment specifications, the same AI safety standards can be deployed in data centers, private clouds, and multi-cloud platforms (AWS, Azure, Google Cloud). This avoids any kind of platform or vendor lock-in and fragmentation issues in AI governance.

  1. Collaborative Approach Instead of Silos

This is because the project enables technology competitors such as Microsoft, NVIDIA, and Red Hat along with universities and IT:U to collaborate to create one standard for AI safety. This collaborative approach reduces the burden on smaller vendors and companies to develop their own governance engine.

Broader Effects on Businesses Operating in the Sector

For businesses leveraging AI agents and large language models (LLMs), asago offers tangible strategic and operational advantages:

  • Faster Time-to-Market: Automation of the policy-to-code workflow cuts the time to deploy from months to days, offering early adopters a strong competitive advantage.
  • Continuous, Auditable Assurance: All guardrails deployed are tied to the policy clause. This provides a continuous chain of audit evidence, which makes it easy to report on compliance in light of emerging global legislation such as the EU AI Act.
  • Risk Mitigation & Brand Safety: Automated adversarial testing allows enterprises to avoid catastrophic failure, data breaches, and liability issues stemming from hallucinations.

Looking Ahead

As AI agents take on greater operational autonomy, safety can no longer remain a manual, spreadsheet-driven process. The formation of the asago community marks a major step toward making enterprise AI safety predictable, scalable, and open by default. Enterprise engineering and legal teams can participate in the project’s governance and code base via GitHub and asago.ai.

Subscribe

- Never miss a story with notifications


    Latest stories