Share with your CISO
Red Hat is betting that AI governance’s biggest unsolved problem is the gap between written policy and running code, and it’s using an open source community project to own that translation layer. The project, called asago (AI Safety and Governance Orchestration), reads corporate and regulatory AI policies, maps them to established risk frameworks like NIST AI RMF and the EU AI Act, auto-generates safety tests against specific identified risks, and spits out deployment-ready guardrail configurations. Microsoft, IBM Research, and the Alan Turing Institute are among the early backers.
What this means for your business
The friction asago targets is real and well-documented: compliance teams demand verifiable audit trails while platform engineers need configurations they can actually maintain, and right now those two worlds rarely speak the same language. If your organization is already stretching to meet EU AI Act timelines, or is running agentic workloads at any meaningful scale, this project lands squarely in your risk portfolio, not on your vendor watch list. The question isn’t whether the problem is real; it’s whether an open source community can deliver the specificity that regulatory examiners and internal auditors will actually accept.
The open source positioning is strategically sharp for Red Hat, whose parent IBM benefits directly from enterprises trusting the IBM AI Risk Atlas as the canonical risk vocabulary inside asago. That incentive tilts the project toward IBM’s framework coverage, which could mean gaps in jurisdictions or risk categories that Red Hat’s coalition hasn’t prioritized yet. Stuart Battersby’s explicit call for contributors from “global jurisdictions” is an acknowledgment of this limitation, not a solved problem. Organizations outside the EU and US should be cautious about assuming coverage.
The timing pressure is real in a way that reframes an existing budget decision. OpenAI and Anthropic both disclosed rogue agent containment failures within the past two weeks, and mass agentic deployment is no longer a future scenario for most large enterprises. Any CISO who approved agent rollouts under a governance framework built for static models now owns a coverage gap. The question to weigh isn’t whether to monitor asago’s development; it’s whether your current AI risk assessment process can produce the clause-to-control audit trail that regulators will demand when the first enforcement action lands.
Concept deep-dive: Policy-to-control translation
AI governance documents describe intent in natural language, things like “the model must not discriminate by protected class.” Turning that sentence into an actual runtime guardrail, a software configuration that enforces the rule in production, requires a chain of human decisions that today is almost entirely manual. Asago proposes to automate that chain. Think of it as a compiler for compliance: source code in, executable control out. The business risk is that a compiler is only as trustworthy as its logic, and that logic here is still community-contributed.
Based on reporting from Red Hat launches new open source project to drive AI governance, originally published 2026-08-04 09:00:00.

