Red Hat has announced the launch of asago (AI Safety And Governance Orchestration), an open-source project aimed at automating one of the biggest challenges in enterprise artificial intelligence: turning governance policies and regulatory compliance into technical controls that can be directly deployed on production AI systems. The initiative is backed by organizations such as Microsoft, NVIDIA, IBM Research, Brave Software, MIT Lincoln Laboratory, The Alan Turing Institute, along with various universities and research institutions.
Key points about asago in 20 seconds
- Red Hat introduces an open-source project to automate AI governance.
- Converts policies like the European AI Act or NIST AI RMF into deployable technical controls.
- Integrates risk assessment, mitigation, auditing, and automated deployment.
- Microsoft, NVIDIA, IBM Research, and other organizations participate as founding partners.
The adoption of artificial intelligence in businesses is growing much faster than the tools to govern it. While models and autonomous agents reach production in weeks, translating corporate policies or regulatory requirements into technical controls remains a manual process that can take months of work among legal teams, compliance officers, data scientists, and platform engineers.
Red Hat aims to bridge this gap with asago, an open platform designed to automatically convert governance standards into configurations ready to run in enterprise environments.
From legal document to automated deployment
asago’s proposal involves creating a fully traceable chain that connects corporate policies with deployed AI systems.
To achieve this, the project structures the process into four main phases:
- Risk mapping: automatically interpreting internal policies and regulations to relate them to frameworks such as NIST AI RMF, OWASP LLM Top 10, IBM’s AI Risk Atlas, or the European AI Regulation (AI Act).
- Automatic evaluation: generating specific tests tailored to each use case instead of relying solely on generic benchmarks.
- Mitigation: recommending technical controls and documented security barriers.
- Deployment: producing configurations ready for platforms like Kubernetes, Terraform, or Ansible.
All steps are documented through a continuous audit trail that demonstrates which regulatory requirement gave rise to each control implemented.
Automating compliance to accelerate enterprise AI
One of the main goals of the project is to prevent regulatory compliance from becoming a bottleneck for innovation.
Currently, many organizations manually interpret regulations, translate them into technical requirements, and coordinate very different teams before deploying an AI-based application.
Red Hat proposes automating this work through a shared platform where compliance officers, developers, infrastructure engineers, and auditors work on the same information flow.
Open source to build a common standard
asago is released under the Apache 2.0 license and aims to become an open standard for AI governance.
The project is part of the Open Secure AI Alliance ecosystem and focuses on integrating existing tools rather than replacing them, acting as an orchestration layer capable of coordinating various evaluation, mitigation, and deployment solutions.
Participating organizations include:
- Red Hat
- Microsoft
- NVIDIA
- IBM Research
- Brave Software
- MIT Lincoln Laboratory
- The Turing Institute
- North Carolina State University
- Interdisciplinary Transformation University Austria
- EvalEval Coalition
- Alquimia AI
Governance becomes part of the DevOps cycle
One of the most interesting aspects of the project is that it brings AI governance into the same workflow where cloud applications are managed today.
Instead of treating compliance as a post-development review, asago seeks to embed it from the start within DevOps and GitOps processes, automatically generating the necessary infrastructure to enforce organizational policies.
This approach is especially relevant with the advent of autonomous agents and language model-based applications, where security decisions no longer impact only traditional software but also the dynamic behavior of AI systems.
A growing trend in enterprise AI
The launch reflects a recognizable evolution in the tech sector. While the past two years focused on deploying AI models, the focus is increasingly shifting towards governance, traceability, and regulatory compliance.
With initiatives like asago, Red Hat aims to position itself in this new infrastructure layer, where automation influences not just application deployment but also risk management, auditing, and AI security.
Frequently Asked Questions
What is asago?
It is an open-source project led by Red Hat to automate the transformation of AI governance policies into deployable technical controls.
What problems does it aim to solve?
Red Hat seeks to reduce the time required to apply regulatory and security requirements to production AI systems, replacing manual processes with automated workflows.
Which standards is it compatible with?
The project considers integration with frameworks like NIST AI RMF, OWASP LLM Top 10, IBM’s AI Risk Atlas, and the European AI Act.
Who participates in the project?
In addition to Red Hat, participants include Microsoft, NVIDIA, IBM Research, Brave Software, MIT Lincoln Laboratory, The Turing Institute, and other academic and tech organizations.

