Red Hat Unveils Asago Open Source Project for AI Governance
New framework automates translation of compliance policies into production-ready AI controls with full audit trails.

Red Hat tackles enterprise AI compliance bottleneck
Red Hat announced the formation of asago, an open source initiative designed to automate the translation of AI governance policies into operational controls for production systems. The project addresses a critical friction point: organizations struggle to convert abstract regulatory requirements into functional software configurations, a process that currently takes months and introduces compliance risk.
According to details first reported by Red Hat on August 4, 2026, asago (AI Safety And Governance Orchestration) creates an automated workflow connecting compliance teams, data scientists, and infrastructure administrators through a single platform. The framework is released under the Apache License 2.0 and builds on work from the Open Secure AI Alliance.
Four-stage automation workflow
The asago framework operates through four integrated stages. First, it automatically interprets uploaded governance policies and maps them to established frameworks including NIST AI RMF, OWASP LLM Top 10, and EU AI Act requirements via the IBM AI Risk Atlas. Second, it generates use-case-specific safety testing scenarios tailored to identified risks rather than relying on generic benchmarks.
Third, the system recommends specific mitigations and guardrails based on test results, creating documentation ready for compliance review. Finally, asago orchestrates these controls into deployment configurations for Kubernetes, Terraform, and Ansible, eliminating manual infrastructure coding.
Each stage produces a continuous audit trail linking individual policy clauses to tests and runtime controls, enabling reviewers to verify exactly which risks each action addresses.
Why it matters
As regulations like the EU AI Act take effect, enterprises face a critical choice: delay AI deployment for months of manual compliance work or risk unmonitored shadow AI systems lacking safety controls. This automation framework could determine whether organizations can scale AI responsibly at the speed business demands. The open source approach also means governance standards won't be locked behind proprietary vendor tools.
Broad coalition backing
The project unites participants from industry, academia, and government including Brave Software, EvalEval coalition, IBM Research, Interdisciplinary Transformation University Austria, Microsoft, MIT Lincoln Laboratory, North Carolina State University, NVIDIA, and The Alan Turing Institute.
"As organizations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement," said Steven Huels, vice president of AI Engineering at Red Hat. The company positions asago as complementary to its Lightwell initiative for securing open source supply chains from AI-driven vulnerabilities.
Stuart Battersby, AI safety and model evaluation architect at Red Hat, emphasized the collaborative nature of the effort and encouraged participation from global jurisdictions to ensure broad coverage of AI safety perspectives.
Current status and access
The asago project is currently in its formation phase. Developers, researchers, and enterprise early adopters can access the repository and participate in governance through GitHub. Interested parties can learn more at asago.ai or through the community group form.
These details were first reported by Red Hat.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call