Red Hat Launches asago Community to Automate AI Safety and Governance from Policy to Production
New collaborative open source project brings together Red Hat, Alquimia AI, Brave Software, EvalEval coalition, IBM
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
Red Hat, the world’s leading provider of open source solutions, today announced the formation of asago, an open source community project intended to automate how AI governance policies become product-ready, safely-deployed AI systems. asago connects the fragmented steps, tools and requirements of engineer and compliance teams, to create an automated, auditable and traceable workflow. The intent is to help deliver safer, production-ready AI systems that fuel innovation in days, not months or years.
What is asago?
asago (AI Safety And Governance Orchestration) plans to use a standardized open source platform and automated workflow to translate complex corporate and regulatory AI governance policies into actual operational controls. It builds on Red Hat and NVIDIA’s work as members of the Open Secure AI Alliance, and aligns developer flexibility with operator governance across four primary stages:
- Risk mapping: The framework automatically reads and interprets uploaded AI governance policies, mapping an organization’s specific requirements directly to established AI Risk frameworks, ontologies and standards, such as the NIST AI RMF, OWASP LLM Top 10, EU AI Act via the IBM AI Risk Atlas – turning policy language into actionable risk profiles.
- Risk assessment: asago generates and executes use-case specific scenarios for automated safety testing tailored to identified risks, probing for harmful behaviors rather than relying solely on generic benchmarks.
- Risk mitigation: The project then recommends mitigations, including safety guardrails based on testing, creating a clear rationale and audit trail ready for review.
- Production deployment: asago then orchestrates recommended controls into deployment-ready configurations across platforms including hybrid cloud and Kubernetes, eliminating manual infrastructure coding.
Each of these steps will be built to produce a continuous audit trail, tying individual policy clauses directly to tests and runtime controls, enabling reviewers to see exactly what risk each action addresses. This helps to transform AI safety into a more predictable and governed enterprise utility.
Why does asago matter?
Translating abstract policy guidelines into functional software configurations slows AI innovation and introduces further risk from human miscommunication and misunderstandings. Compliance officers require rigorous risk assessments and verifiable evidence, while platform engineers need structured configurations that can be maintained within standard DevOps and GitOps workflows. As wide-ranging regulations like the EU AI Act take effect, organizations cannot risk either stalling innovation in months of manual review or creating unmonitored shadow AI deployments that lack appropriate safety guardrails.
asago intends to resolve this friction by providing a single, open standard that compliance teams, data scientists, and infrastructure administrators can converge upon. By treating every stakeholder as a first-class user, the platform will create safety controls for autonomous AI agents and enterprise large language models (LLMs), without introducing the inconsistencies of manual translation.
What Red Hat is saying
“As organizations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement,” said Steven Huels, vice president, AI Engineering, Red Hat. “Through initiatives like Lightwell, we are working to secure the open source supply chain from AI-driven vulnerabilities. asago complements this effort and takes the next logical step for enterprise AI by automating the link between corporate policy definitions and live production agents. This gives enterprises the end-to-end operational confidence they need to scale trusted AI across the hybrid cloud.”
“The asago project is a true collaborative, open source endeavour bringing together stakeholders from the technology industry, academia and government,” said Stuart Battersby, AI safety and model evaluation architect, Red Hat. “We encourage more collaborators to join this community driven effort, particularly from global jurisdictions, to ensure maximum coverage of AI safety viewpoints.”
Key takeaways
- Automation to cut through policy complexity: Replaces manual interpretation and custom scripts with an integrated orchestration workflow, cutting deployment time from months to days.
- A singular audit trail: Serves policy officers, CIOs, AI developers, platform engineers, and external auditors within a single unified tracing interface.
- Open source and community governance: Released under the Apache License 2.0 to foster open collaboration across the wider AI safety ecosystem.
- Infrastructure-agnostic deployment: Outputs declarative configurations for Kubernetes, Terraform, and Ansible, allowing organizations to maintain consistent safety postures across multiple clouds and on-premises environments.
Deeper details
The asago project unites industry leaders and academic institutions including Red Hat, Brave Software, EvalEval coalition, IBM Research, Interdisciplinary Transformation University Austria, Microsoft, MIT Lincoln Laboratory, North Carolina State University, NVIDIA and The Alan Turing Institute under a multi-organization effort to integrate diverse expertise across AI safety research, enterprise software engineering, adversarial machine learning, and regulatory compliance.
The project will integrate with best-in-class open tools and specifically targets the operational gaps between them. It will aim to provide full, distributed trace capabilities that log evidence bases required by auditors to demonstrate compliance. This enables every control active in a live production environment to be mapped back to its explicit policy justification, establishing continuous verification for enterprise AI portfolios.
What Red Hat’s partners are saying
“At Alquimia we built our agentic platform on a conviction: AI inference must be controlled, explainable, and sovereign by design, not as a compliance afterthought,” said Sebastián Cao, chief executive officer, Alquimia AI. Asago turns that same conviction into an open standard, giving every organization a path from policy to production-ready governance they can actually audit. This is exactly the kind of infrastructure the industry needs, and it’s why through gaussia.ai we’ve been contributing open, scientifically grounded metrics to measure how AI systems actually behave in the real world. Open governance frameworks like Asago make it possible for entire communities, not just vendors, to agree what trustworthy AI looks like in practice.”
“Brave is excited to join the asago Community to help advance the AI safety landscape, as a safer Web is good for everyone,” said Brendan Eich, chief executive officer and co-founder, Brave Software. “Brave has always been open source and we look forward to collaborating with asago to ensure that privacy and security are the foundation of AI tools. Over 120 million users browse and search with Brave, and we hope that our user-first approach will contribute to raising the bar regarding robust AI guardrails.”
“To be trusted in real-world environments, AI needs measurable testing and operational controls. Through the asago community, IBM is contributing our expertise to help bridge the gap between governance frameworks and deployed AI systems,” said Priya Nagpurkar, vice president, AI Platform, IBM Research. “This complements the broader work being done for Project Lightwell, where we are helping clients secure open source vulnerabilities. By bringing together industry, academia, and open source communities, asago can help establish a more transparent and accountable foundation for enterprise AI adoption.”
“Developing trustworthy AI requires more than good intentions. It requires governance that can be implemented, verified and continuously maintained,” said Dr. Ben Wagner, Professor of Human Rights and Technology, IT:U. “asago was designed to help transform high-level policy into practical engineering workflows. IT:U has a strong background in both the technical and organisational governance of AI, which is why we’re grateful for the opportunity to contribute to asago. We hope it empowers organizations to innovate with confidence while making responsible AI development a practical reality.”
“Many of the hardest AI safety and security challenges are still unsolved, and no single organization can tackle them all alone,” said Sarah Bird, chief product officer, Responsible AI, Microsoft. “Open, widely adopted standards can help create more consistent governance across the ecosystem, while the collective ingenuity of the community can accelerate progress on the problems that matter most. We’re excited to join the asago Community and work alongside others to help build AI that is safe, secure, and worthy of people’s trust.”
“Open source collaboration is fundamental to advancing AI safety and security across the entire ecosystem,” said Diane Staheli, chief scientist, AI and Cybersecurity, MIT Lincoln Laboratory. “The asago initiative will incorporate multidisciplinary research to address the critical gap between governance requirements and operational reality. We are excited to contribute to this effort to make AI safety and security tools broadly accessible.”
“Ensuring AI systems are safe and secure is an engineering problem as much as a policy problem, and no single company, lab or university will solve it alone,” said Veena Misra, interim dean, College of Engineering, North Carolina State University. “NC State’s College of Engineering brings deep research strength in AI security to the asago community, along with engineers who graduate ready to build safe, product-ready AI systems on day one. Partnerships like this are how we connect our people and programs directly to what industry needs next.”
“The Open Secure AI Alliance was founded on the principle that open models, open harnesses, and open tooling are the strongest foundation for AI defense — and asago puts that principle into practice,” said Daniel Rohrer, vice president, Software Security, NVIDIA. “By automating the translation of AI governance policy into production-ready controls and audit trails, the asago project demonstrates how Red Hat, NVIDIA and our ecosystem are strengthening agent security with open source tools.”
“No single organisation can make AI safe and governable at scale, it needs open tools, diverse expertise and neutral governance,” said Jason McEwen, chief scientist, The Alan Turing Institute, and Professor at UCL. “That is exactly what makes asago’s community-driven model compelling, and it connects directly to our Trustworthy and Assured AI work within Fundamental Research at the Alan Turing Institute. We’re pleased to join as a founding partner and to help shape the project’s direction alongside the wider community.”
Availability
The asago project is currently in its project formation phase. Developers, academic researchers, and enterprise early adopters can view the repository and participate in project governance via GitHub. Learn more and express interest in collaborating by visiting asago.ai or filling out the community group form.
Learn more
- Read the blog
Connect with Red Hat
- Learn more about Red Hat
- Get more news in the Red Hat newsroom
- Read the Red Hat blog
- Follow Red Hat on X
- Follow Red Hat on Instagram
- Follow Red Hat on LinkedIn
About Red Hat
Red Hat is the open hybrid cloud technology leader, delivering a trusted, consistent and comprehensive foundation for transformative IT innovation and AI applications. Its portfolio of cloud, developer, AI, Linux, automation and application platform technologies enables any application, anywhere—from the datacenter to the edge. As the world’s leading provider of enterprise open source software solutions, Red Hat invests in open ecosystems and communities to solve tomorrow’s IT challenges. Collaborating with partners and customers, Red Hat helps them build, connect, automate, secure and manage their IT environments, supported by consulting services and award-winning training and certification offerings.
Forward-Looking Statements
Except for the historical information and discussions contained herein, statements contained in this press release may constitute forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. Forward-looking statements are based on the company’s current assumptions regarding future business and financial performance. These statements involve a number of risks, uncertainties and other factors that could cause actual results to differ materially. Any forward-looking statement in this press release speaks only as of the date on which it is made. Except as required by law, the company assumes no obligation to update or revise any forward-looking statements.
Red Hat, and the Red Hat logo are trademarks or registered trademarks of Red Hat, LLC or its subsidiaries in the U.S. and other countries. Linux® is the registered trademark of Linus Torvalds in the U.S. and other countries.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260804403325/en/
Media gallery