TLDRocket
Sign in

Red Hat leads open-source project to automate AI governance

SiliconANGLE Paul Gillin

Red Hat just launched asago, an open-source project to turn AI compliance rules into actual deployment code. Basically it's trying to stop compliance teams and engineers from playing telephone with AI regulations.

Based on reporting by SiliconANGLE, Paul Gillin — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Red Hat wants to solve a problem that's been quietly slowing down enterprise AI for years: the gap between what a compliance team writes in a policy document and what actually gets configured on a server. Today the company announced asago, short for AI Safety and Governance Orchestration, an open-source project meant to automate that translation process from end to end.

The pitch is straightforward once you strip away the acronyms. Right now, when a company wants to deploy an AI system, someone has to read through frameworks like NIST's AI Risk Management Framework, OWASP's Top 10 for LLM Applications, or the EU AI Act, figure out what they actually require, and then hand that off to engineers who write custom scripts to enforce it. That handoff is slow, error-prone, and nearly impossible to audit months later. Asago tries to replace it with a four-stage pipeline: map policy to standards using IBM's AI Risk Atlas, generate and run safety tests specific to the use case, recommend guardrails with documented reasoning, and spit out ready-to-deploy Kubernetes, Terraform, and Ansible configurations.

Red Hat frames this as increasingly urgent because generative AI is no longer a sandbox experiment at most large companies. Agents and models are staying in production for months or years, which means governance can't be a one-time checklist before launch — it has to be something that persists and gets audited continuously. The promise here is traceability: an auditor should be able to point to a live control running in production and trace it directly back to a specific clause in a policy document, complete with the test evidence that justified it.

The roster of contributors is notable for how competitive it is on paper. IBM Research, Nvidia, Microsoft, Brave Software, MIT Lincoln Laboratory, North Carolina State University, the Alan Turing Institute, and the EvalEval coalition are all listed alongside Red Hat as founding participants, building on groundwork laid by the Open Secure AI Alliance that Red Hat and Nvidia started earlier. Getting rivals like Microsoft and Nvidia into the same open-source tent suggests there's real appetite across the industry for a shared governance layer rather than everyone building bespoke compliance tooling in isolation.

For now, asago is still in its formation phase, released under Apache 2.0, with the code sitting on GitHub waiting for developers and early enterprise adopters to actually kick the tires. Ambitious governance frameworks have a habit of looking great in press releases and then stalling once real companies try to bolt them onto messy, existing infrastructure. Whether asago becomes a genuine standard or just another well-intentioned specification depends entirely on what happens over the next year of actual adoption.

My take — AI-written commentary, not fact-checked reporting

Handing AI governance to a fresh crop of open-source tooling backed by Nvidia, Microsoft, and IBM sounds sensible right up until someone asks why the checklist mapped to the EU AI Act still needs a human to sign off on anything meaningful — automation is great at generating configs, less great at deciding what 'acceptable risk' means. Worth watching whether regulators treat asago-style audit trails as genuine compliance evidence or just a fancier paper trail; until then, this is infrastructure vendors selling shovels during a gold rush they helped create.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.