On Aug. 4, 2026, Red Hat announced asago (AI Safety And Governance Orchestration), an open-source community project intended to automate the conversion of written AI governance policies into deployable controls for live systems. Founding collaborators include IBM Research, Microsoft, NVIDIA, MIT Lincoln Laboratory, NC State University, and The Alan Turing Institute.
As planned, asago will ingest an uploaded governance policy and map it to NIST AI RMF, the OWASP LLM Top 10, and the EU AI Act using IBM’s AI Risk Atlas. It is then meant to generate safety-test scenarios, mitigation recommendations, and audit trails, emitting declarative configurations for Kubernetes, Terraform, and Ansible. The workflow spans risk mapping, assessment, mitigation, and production deployment. It ships under Apache License 2.0.
For governance officers managing overlapping state, sector, and international rules with no federal U.S. rulebook, the appeal is a common translation layer instead of hand-building controls per jurisdiction. The vendor-neutral, multi-backer structure also reduces single-vendor lock-in on governance tooling, which matters for federal and enterprise buyers.
Two cautions. The project is in “formation phase” with a live GitHub repo but no deployed customer case study, and Red Hat’s claim that it cuts deployment “from months to days” carries no independent benchmark. Treat asago as a roadmap signal worth piloting, not a production-ready compliance guarantee.



Leave a Reply