SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
Red Hat launches asago to turn AI policy into code

Red Hat launches asago to turn AI policy into code

Wed, 5th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Red Hat has launched asago, an open source community project that automates the translation of AI governance policies into production controls. The project brings together companies, research institutions and universities, including NVIDIA, Microsoft and IBM Research.

The launch places Red Hat at the centre of a growing debate over how organisations can turn broad AI rules into systems engineers can deploy and auditors can verify. The project is intended to connect compliance and engineering teams through a single workflow that records how policy requirements map to tests and operational controls.

Asago, short for AI Safety And Governance Orchestration, is being established as an Apache 2.0 open source project. It is intended to cut the time needed to put safety controls in place from months to days by replacing manual interpretation of policy documents with automated processes.

The software is designed to support several stages of AI oversight. These include reading governance policies, mapping them to existing risk frameworks, generating safety tests linked to identified risks, recommending mitigations, and converting those recommendations into deployment-ready configurations for tools such as Kubernetes, Terraform and Ansible.

The approach targets a persistent problem for companies adopting AI systems in regulated or risk-sensitive settings. Compliance officers often need documented evidence that an AI application meets internal or external rules, while engineering teams need configurations that fit established DevOps and GitOps workflows.

Each step in the process is meant to create an audit trail linking policy clauses to testing and runtime controls. In practice, that would allow reviewers to trace a live safeguard back to the rule or risk assessment that justified it.

The project also reflects wider industry efforts to build open tools for AI oversight rather than rely on proprietary systems. The work builds on activity linked to the Open Secure AI Alliance, a group launched by NVIDIA that focuses on open approaches to AI safety and security.

Broad group

Founding participants include Alquimia AI, Brave Software, EvalEval coalition, IBM Research, Interdisciplinary Transformation University Austria, Microsoft, MIT Lincoln Labouratory, North Carolina State University, NVIDIA and The Alan Turing Institute. The line-up spans commercial software groups, academic researchers and public-interest AI specialists, underlining how governance questions now cut across several parts of the sector.

Some members framed the effort as a response to the difficulty of making high-level AI principles enforceable in day-to-day operations. Others pointed to the need for open standards that can be inspected and adapted by a wider community.

Steven Huels, Vice President, AI Engineering, Red Hat, described the operational problem the project aims to address.

"As organisations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement," said Steven Huels, Vice President, AI Engineering, Red Hat. "Through initiatives like Lightwell, we are working to secure the open source supply chain from AI-driven vulnerabilities. asago complements this effort and takes the next logical step for enterprise AI by automating the link between corporate policy definitions and live production agents. This gives enterprises the end-to-end operational confidence they need to scale trusted AI across the hybrid cloud."

Stuart Battersby, AI Safety and Model Evaluation Architect, Red Hat, said the project depends on outside input.

"The asago project is a true collaborative, open source endeavour bringing together stakeholders from the technology industry, academia and government," said Stuart Battersby, AI Safety and Model Evaluation Architect, Red Hat. "We encourage more collaborators to join this community-driven effort, particularly from global jurisdictions, to ensure maximum coverage of AI safety viewpoints."

Policy to code

One of the clearest practical goals is to convert written policy into controls that can be deployed without teams having to hand-code each step. The system is intended to map rules to recognised frameworks such as the NIST AI RMF, OWASP LLM Top 10 and the EU AI Act through the IBM AI Risk Atlas.

That may appeal to organisations trying to reconcile internal governance standards with emerging regulation. The issue has become more pressing as businesses move from experimental pilots to AI agents and large language model-based applications that interact with customers, staff and critical systems.

Partners also used the launch to argue for shared infrastructure. Priya Nagpurkar, Vice President, AI Platform, IBM Research, said the work centred on measurable controls.

"To be trusted in real-world environments, AI needs measurable testing and operational controls. Through the asago community, IBM is contributing our expertise to help bridge the gap between governance frameworks and deployed AI systems," said Priya Nagpurkar, Vice President, AI Platform, IBM Research. "This complements the broader work being done for Project Lightwell, where we are helping clients secure open source vulnerabilities. By bringing together industry, academia and open source communities, asago can help establish a more transparent and accountable foundation for enterprise AI adoption."

Microsoft also stressed the limits of any one group setting the agenda for AI safety alone.

"Many of the hardest AI safety and security challenges are still unsolved, and no single organisation can tackle them all alone," said Sarah Bird, Chief Product Officer, Responsible AI, Microsoft. "Open, widely adopted standards can help create more consistent governance across the ecosystem, while the collective ingenuity of the community can accelerate progress on the problems that matter most. We're excited to join the asago community and work alongside others to help build AI that is safe, secure and worthy of people's trust."

The project is currently in its formation phase, with Red Hat positioning it as a community-led effort rather than a finished product.

"The Open Secure AI Alliance was founded on the principle that open models, open harnesses and open tooling are the strongest foundation for AI defense - and asago puts that principle into practice," said Daniel Rohrer, Vice President, Software Security, NVIDIA. "By automating the translation of AI governance policy into production-ready controls and audit trails, the asago project demonstrates how Red Hat, NVIDIA and our ecosystem are strengthening agent security with open source tools."