Red Hat has unveiled “asago,” a new open-source community initiative designed to bridge the gap between AI governance policies and deployable production code. The project aims to automate and audit the complex journey of AI development, streamlining the “fragmented steps, tools, and requirements” faced by engineering and compliance teams.
With the increasing scrutiny on AI, exemplified by regulations like the EU AI Act, organizations are at a crossroads. They can either stifle AI innovation through manual oversight or risk deploying AI systems without adequate controls, potentially leading to unpredictable behavior. Asago positions itself as a solution to navigate this dilemma.
This initiative builds upon the collaborative efforts within the Open Secure AI Alliance, a partnership between Red Hat and NVIDIA focused on enhancing AI security through open-source development. Asago is released under the Apache License 2.0 and is currently in its early stages, with its GitHub repository open for contributions from developers, academic researchers, and early enterprise adopters. This community-driven approach emphasizes collective input and refinement of AI governance standards.
Four Stages From Policy Text to Operational Controls
Red Hat outlines a four-stage workflow for asago:
1. Risk Mapping: The framework ingests an organization’s AI governance policies and automatically maps their specific requirements against established standards. This includes frameworks such as NIST AI RMF, the OWASP LLM Top 10, and regulatory requirements cataloged via IBM’s AI Risk Atlas. This automation transforms policy language into a risk profile, eliminating the need for manual cross-referencing by compliance teams.
2. Risk Assessment: Asago then generates and executes tailored scenarios based on the specific AI use case. This testing goes beyond standard checklists, actively probing for harmful behaviors identified during the risk mapping phase.
3. Risk Mitigation: Following the assessment, the system provides recommendations for “guardrails”—controls designed to prevent identified risks. It also generates a detailed rationale for these recommendations, intended to withstand rigorous review.
4. Deployment Orchestration: Finally, asago translates these recommended controls into deployment-ready configurations for hybrid cloud and Kubernetes environments. This automation significantly reduces the manual coding required to implement mitigation strategies, aiming to cut deployment timelines from months to days.
An Audit Trail as a Core Feature
A key design principle of asago is the creation of a continuous, end-to-end audit trail. Each policy clause is linked to a specific test, and each test is connected to a runtime control. This ensures that any control actively running in a live deployment can be traced directly back to the policy that mandated it, providing unparalleled transparency and accountability.
This traceability is a significant selling point, framing AI safety not as a one-time certification but as an ongoing operational utility. Red Hat emphasizes that as agents continue to run, their behavior remains verifiable against policy, not just at the point of initial approval.
Steven Huels, Red Hat’s VP of AI Engineering, highlights the critical need for clear operational guardrails as organizations scale from experimental AI pilots to autonomous agents. He positions asago as a natural evolution, automating the crucial link between corporate policy definitions and live production AI systems, and complementing Red Hat’s Lightwell initiative which focuses on securing the open-source AI supply chain.
Stuart Battersby, Red Hat’s AI Safety and Model Evaluation Architect, underscores the project’s collaborative nature. He encourages broader participation from the technology industry, academia, and government to ensure comprehensive coverage of AI safety perspectives and regulatory landscapes across global jurisdictions.
A Collaborative Effort, Not a Single-Vendor Solution
The founding contributors to asago extend beyond Red Hat and NVIDIA, including prominent organizations such as Brave Software, IBM Research, Microsoft, MIT Lincoln Laboratory, North Carolina State University, and The Alan Turing Institute. The EvalEval coalition and Austria’s Interdisciplinary Transformation University (IT:U) are also involved, alongside partner Alquimia AI. This diverse group reflects a shared understanding that tackling complex AI safety challenges requires collective expertise.
Sarah Bird, Chief Product Officer for Responsible AI at Microsoft, articulates this sentiment, stating that many of the most challenging AI safety and security issues remain unsolved, necessitating collaborative efforts where no single organization can provide all the answers.
Academic contributors echo this perspective. Veena Misra, Interim Dean of the College of Engineering at NC State, views AI safety as an equally critical engineering and policy problem, highlighting the need for practical, implementable solutions.
A significant technical advantage of asago is its intended infrastructure-agnostic nature. The project aims to produce declarative configurations compatible with popular tools like Kubernetes, Terraform, and Ansible. This flexibility means that a safety posture established in one cloud environment can be deployed across others without extensive re-engineering.
It is important to note that asago is currently in its nascent stages. Red Hat’s announcement does not include any production-tested examples, customer case studies, or benchmarks validating the claimed reduction in deployment times. Furthermore, mechanisms for resolving potential disputes over risk-mapping standards among contributing organizations as the project matures are yet to be fully defined.
For now, asago exists as an open repository and a governance framework on GitHub, inviting developers, researchers, and enterprise teams to actively contribute and build alongside a growing list of collaborators, rather than adopting a fully realized product. This community-driven evolution is central to asago’s development strategy.
Original article, Author: Samuel Thompson. If you wish to reprint this article, please indicate the source:https://aicnbc.com/24397.html