ARTIFICIAL INTELLIGENCE AI GOVERNANCE

Red Hat Launches asago to Standardise AI Governance Across the Enterprise

TM
Techmediaglobal
| 4 min read
4+
FOUNDING PARTNERS
2
RESEARCH BODIES
Open
SOURCE MODEL
GitHub
PROJECT STAGE

Red Hat has launched an open-source community project called asago (AI Safety and Governance Orchestration), bringing together IBM, Microsoft, Brave Software, MIT and The Alan Turing Institute to turn written AI governance policies into automated, deployment-ready safety controls across hybrid cloud environments.

Bridging Policy and Deployment

Rather than relying on generic technical tooling, asago is designed to work directly from an organisation's own custom policy documents, translating governance language into measurable risk profiles and deployable safety controls. The platform can read uploaded AI governance policies and convert that language into actionable risk assessments.

Red Hat points to frameworks such as the EU AI Act, via the IBM AI Risk Atlas, and the NIST AI Risk Management Framework as examples of the kinds of policy documents the system may be able to interpret. Rather than testing against generic benchmarks, asago will generate scenarios tailored to specific use cases, then recommend mitigations and orchestrate them into deployment-ready configurations complete with audit trails.

"asago intends to holistically smooth and streamline how AI safety controls are operationalised within an enterprise organisation, not with the technical tooling, but with the organisation's own custom policy documents."

— Stuart Battersby, AI Safety & Model Evaluation Architect, Red Hat

From AI Pilots to Autonomous Agents

According to Steven Huels, Vice President of AI Engineering at Red Hat, operational guardrails have become critical infrastructure as organisations shift from experimental AI pilots toward autonomous agents running in production. He frames asago as a complement to Red Hat's existing Lightwell initiative, which focuses on securing the open-source supply chain from AI-driven vulnerabilities.

The goal is to give compliance teams, data scientists and infrastructure administrators a single open standard to work from, reducing the inconsistencies that manual translation introduces when converting abstract policy guidelines into operational, engineering-ready controls that fit within DevOps and GitOps workflows.

Why Open Standards, Not Vendor Features

Even as major cloud vendors roll out their own proprietary safety tools for agentic AI, Red Hat argues that AI governance should be built as an open-source standard rather than locked to a single platform. Battersby notes that fragmented tooling and processes increase the risk of AI systems producing harmful outcomes, particularly because safety testing results need to be comparable across different systems.

Red Hat also warns that unmonitored, unsanctioned "shadow AI" deployments lacking safety guardrails could expose organisations to data vulnerabilities and AI-driven attacks, adding urgency to the case for standardised, auditable governance processes.

Open for Community Participation

asago is currently in its project formation phase on GitHub, with developers, academic researchers and enterprise early adopters invited to view the repository and take part in project governance. Red Hat is specifically encouraging collaborators from a wide range of global jurisdictions to ensure the project captures diverse AI safety viewpoints and regulatory perspectives.

Key Takeaways

  • Red Hat's asago project unites IBM, Microsoft, Brave Software, MIT and The Alan Turing Institute around open-source AI governance.
  • The platform translates an organisation's own policy documents into risk profiles and deployable safety controls.
  • It references frameworks like the EU AI Act and NIST AI RMF as examples of policies it can interpret.
  • asago complements Red Hat's Lightwell initiative for securing the open-source AI supply chain.
  • Red Hat is positioning AI safety as an open standard rather than a proprietary vendor feature.
  • The project is in its formation phase on GitHub, open to developers, researchers and enterprise early adopters worldwide.
Tags: Red Hat AI Governance Open Source AI Safety Hybrid Cloud EU AI Act Enterprise IT