Product of the Day
ASAGO turns AI rules into safeguards
An open-source framework from Red Hat aims to link governance requirements with safety tests and traceable audit evidence.
A new initiative intends to automate the conversion of AI governance policies into operational controls for production systems. The open-source community project, called ASAGO (AI Safety and Governance Orchestration), has been formed by Red Hat.
ASAGO aims to connect compliance teams, AI engineers and infrastructure operators through a standardised workflow.
According to Red Hat, translating abstract policy guidelines into functional software configurations slows AI innovation and introduces further risk from human miscommunication and misunderstandings. The company says compliance officers require rigorous risk assessments and verifiable evidence, while platform engineers need structured configurations that can be maintained within standard DevOps and GitOps workflows.
The challenge is becoming more pressing as regulations such as the EU AI Act take effect. Lengthy manual reviews can slow AI deployments, while inadequate oversight can result in shadow AI deployments without appropriate guardrails, according to the company.
ASAGO proposes a single open standard for compliance teams, data scientists and infrastructure administrators. The framework would support safety controls for autonomous AI agents and enterprise large language models.
Red Hat says the proposed process would cover the following four stages:
- Risk mapping: The framework automatically reads and interprets uploaded AI governance policies, mapping an organisation’s specific requirements directly to established AI Risk frameworks, ontologies and standards, such as the NIST AI RMF, OWASP LLM Top 10, EU AI Act via the IBM AI Risk Atlas – turning policy language into actionable risk profiles.
- Risk assessment: ASAGO generates and executes use-case specific scenarios for automated safety testing tailored to identified risks, probing for harmful behaviours rather than relying solely on generic benchmarks.
- Risk mitigation: The project then recommends mitigations, including safety guardrails based on testing, creating a clear rationale and audit trail ready for review.
- Production deployment: ASAGO then orchestrates recommended controls into deployment-ready configurations across platforms including hybrid cloud and Kubernetes, eliminating manual infrastructure coding.
The project plans to output declarative configurations for Kubernetes, Terraform and Ansible. This infrastructure-independent approach would support consistent safety controls across multiple clouds and on-premises environments.
ASAGO would integrate existing open tools rather than replace established AI safety technologies. The focus is on orchestrating the operational gaps between those tools.

Each stage would contribute to a continuous audit trail. Individual policy clauses could be linked directly to tests and controls operating in production. Reviewers would then be able to identify the specific risk addressed by each action.
The framework aims to provide distributed tracing that records the evidence required by auditors. Each live control could therefore be mapped back to the policy requirement behind the decision.
Red Hat says this approach could support continuous verification across an organisation’s AI portfolio. Policy officers, CIOs, AI developers, platform engineers and external auditors would use a unified tracing interface.
“As organisations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement,” says Steven Huels, Red Hat VP of AI engineering.
“Through initiatives like Lightwell, we are working to secure the open source supply chain from AI-driven vulnerabilities. ASAGO complements this effort and takes the next logical step for enterprise AI by automating the link between corporate policy definitions and live production agents. This gives enterprises the end-to-end operational confidence they need to scale trusted AI across the hybrid cloud.”
According to the company, replacing manual policy interpretation and custom scripts with an integrated orchestration workflow could reduce deployment times from months to days. The project builds on Red Hat and Nvidia’s work as members of the Open Secure AI Alliance.
Daniel Rohrer, Nvidia VP of software security, says: “The Open Secure AI Alliance was founded on the principle that open models, open harnesses, and open tooling are the strongest foundation for AI defence — and ASAGO puts that principle into practice.”
“By automating the translation of AI governance policy into production-ready controls and audit trails, the ASAGO project demonstrates how Red Hat, Nvidia and our ecosystem are strengthening agent security with open source tools.”
The wider collaboration supports expertise in AI safety research, enterprise software engineering, adversarial machine learning and regulatory compliance.
Participants include Alquimia AI, Brave Software, the EvalEval coalition, IBM Research and Interdisciplinary Transformation University Austria. Microsoft, MIT Lincoln Laboratory, North Carolina State University and The Alan Turing Institute are also involved.
Red Hat AI safety and model evaluation architect Stuart Battersby says the community wants participation from additional global jurisdictions to expand the range of AI safety perspectives represented within the project.
ASAGO is planned for release under the Apache License 2.0. The community-governance model is intended to encourage collaboration across the AI safety ecosystem. The project remains in the formation phase. Developers, academic researchers and enterprise early adopters can view the repository and participate in project governance through GitHub.
* Visit the ASAGO website here.



