

As artificial intelligence transitions from pilot projects to autonomous, enterprise-grade agents, organisations worldwide face a growing operational bottleneck. On one hand, emerging regulations such as the EU AI Act demand rigorous oversight, risk assessments, and enforceable guardrails. On the other hand, traditional compliance reviews are notoriously manual, slow, and disconnected from software deployment pipelines.
To solve this friction, Red Hat—alongside tech leaders including NVIDIA, IBM Research, Microsoft, and premier academic institutions—has launched asago. This open-source community initiative aims to bridge the gap between compliance documentation and live software infrastructure by automatically converting AI governance policies into production-ready deployment code.
Until now, enterprise IT and compliance teams have effectively operated in separate silos. Compliance officers draft extensive governance policies based on frameworks like the NIST AI Risk Management Framework (RMF) or the EU AI Act. Meanwhile, DevOps and software engineers build infrastructure without real-time, programmatic mechanisms to enforce those rules.
This disconnect leaves organisations with two unappealing options:
Project asago aims to eliminate this trade-off by treating AI safety as a continuous engineering discipline rather than a static, one-time audit exercise.
At its core, asago provides an automated, auditable workflow designed to turn high-level regulatory text into enforceable runtime controls. The framework operates across four distinct stages:
1. Automated Risk Mapping
When an organisation uploads its governance policy, asago parses the text and automatically maps its specific requirements against recognised industry standards. By cross-referencing catalogued frameworks—such as the NIST AI RMF, the OWASP LLM Top 10, and the EU AI Act via IBM’s AI Risk Atlas—the system generates a comprehensive risk profile without requiring manual policy translation.
2. Context-Aware Risk Assessment
Rather than relying on generic evaluation checklists, asago dynamically generates and executes testing scenarios tailored to the specific use case. It actively probes the system for the specific harmful behaviours flagged during the risk mapping phase, ensuring that evaluations reflect real-world operational threats.
3. Automated Mitigation and Cloud Orchestration
Following scenario testing, asago recommends concrete guardrails and builds a rationale trail designed to withstand regulatory scrutiny. It then orchestrates these recommended controls directly into deployment configurations for hybrid cloud and Kubernetes environments using declarative tools like Ansible and Terraform. By automating this infrastructure coding, Red Hat aims to collapse deployment timelines from months down to days.
4. Continuous Audit-Trail-as-a-Product
Traceability forms the cornerstone of the asago framework. Every policy clause is linked to a specific risk test, which in turn correlates directly to a live runtime control. This enables auditors and security teams to trace any active control in production back to the exact policy line that mandated it, providing an ongoing, transparent audit trail.
Released under the Apache License 2.0, asago is not a single-vendor solution. It stems from foundational work within the Open Secure AI Alliance and boasts contributions from a diverse ecosystem across industry, academia, and government.
Founding contributors include Brave Software, IBM Research, Microsoft, MIT Lincoln Laboratory, North Carolina State University, The Alan Turing Institute, the EvalEval coalition, Austria’s Interdisciplinary Transformation University (IT:U), and Alquimia AI.
Industry leaders emphasise that AI safety is too complex for any single organisation to tackle in isolation. Furthermore, experts from academia highlight that AI safety must be treated as a core engineering problem rather than a purely legal or administrative burden.
Project asago is currently in its initial formation phase, with its repository hosted publicly on GitHub. Because the framework generates declarative configurations for Kubernetes, Ansible, and Terraform, its outputs are inherently infrastructure-agnostic—allowing organisations to maintain a consistent security posture across multi-cloud environments.
While the vision is ambitious, the project has yet to undergo extensive production testing or public enterprise case studies. Its success will ultimately depend on how effectively the open-source community adopts the repository, refines risk-mapping standards, and proves its deployment claims under real-world regulatory audits.
Nevertheless, by establishing an automated link between corporate policy definitions and live production agents, asago represents a significant step towards practical, operationalised AI governance.
Disclaimer: This article is provided for informational purposes only, mistakes may be made, and it's not offered or intended to be used as legal, tax, investment, financial, or any other advice.
