Red Hat officially launched ‘Asago,’ an open-source project aimed at closing the gap between artificial intelligence policy creation and actual operational deployment, on August 5. The core objective is to automate AI governance procedures, slashing the preparation time for AI system operations from months to just a few days.
Asago is a tool that analyzes AI policies established by enterprises and regulators and converts them into risk control frameworks applicable to real-world systems. By connecting procedures and tools previously scattered across engineering and compliance teams into a single workflow, it automates the policy interpretation and safety review processes that were traditionally done manually.
Red Hat explained that with global AI regulations, such as the EU AI Act, coming into full effect, companies can no longer afford lengthy manual reviews or tolerate uncontrolled ‘Shadow AI’ operations. The strategy is to establish an open standard that can be commonly utilized by compliance teams, data scientists, and infrastructure managers to consistently manage safety controls for autonomous AI agents and enterprise-grade large language models (LLMs).
Asago’s operational procedure consists of four main stages. The first is risk mapping, where organizational policy requirements are linked to proven standards such as the U.S. National Institute of Standards and Technology (NIST) AI Risk Management Framework, the OWASP Top 10 for LLMs, and the IBM AI Risk Atlas, converting them into actionable risk profiles.
In the second evaluation stage, safety test scenarios are automatically generated and executed for each use case based on the identified risks. This goes beyond simple general-purpose performance evaluation to intensively verify the potential for harmful behavior during actual operations.
The third mitigation stage proposes risk mitigation measures, including safety guardrails, based on the test results. It documents the rationale for each action, related policy clauses, and test outcomes, allowing compliance officers, developers, and external auditors to verify the same evidence base.
Finally, in the production deployment stage, the reviewed control measures are converted into configurations deployable in hybrid cloud and Kubernetes environments. By outputting declarative configurations for Kubernetes, Terraform, and Ansible, the same safety standards can be applied across multiple clouds and on-premises environments without being tied to a specific infrastructure.
Asago is released under the Apache License 2.0. In addition to Red Hat, participants in the project include Brave Software, the EvalEval Consortium, IBM Research, Microsoft, MIT Lincoln Laboratory, North Carolina State University, Nvidia, and the Alan Turing Institute.
The launch of the Asago project aligns with the SAFE (Shared AI Findings Exchange) guidelines recently announced by the Nvidia-led Open Secure AI Alliance. The alliance, which currently involves over 120 organizations, unveiled the draft SAFE guidelines on August 4 at the Black Hat cybersecurity conference in Las Vegas. SAFE presents a standardized approach for confidentially reporting AI incidents and risk situations, analyzing recurring failure cases, and distributing actionable recommendations to mitigate systemic risks.
Key contributors to the Open Secure AI Alliance include Nvidia, Red Hat, Cisco, CrowdStrike, and Hugging Face, operating under the guidance of the Linux Foundation. The alliance emphasized that “cybersecurity is a race with no finish line,” and that sharing threat intelligence within a trusted ecosystem gives defenders a significant advantage in responding to new risks.
Steven Huels, Vice President of AI Engineering at Red Hat, stated, “As enterprises transition from experimental AI pilots to long-running autonomous agents, establishing clear operational guardrails is becoming a core infrastructure requirement.” He added, “Asago represents the next phase of enterprise AI, automatically connecting corporate policy definitions with agents operating in production.”
The industry is watching closely to see if this project can accelerate enterprise AI adoption while simultaneously reducing the burden of regulatory compliance. Global corporations are expected to show significant interest, particularly because the automated workflow can fulfill the risk management and documentation obligations required by the EU AI Act. Given Red Hat’s established trust in the enterprise open-source market and its influence within the Kubernetes ecosystem, there is speculation that Asago could become the de facto standard in the AI governance field.