What asago Actually Does
asago (AI Safety and Governance Orchestration) is a new open-source community project from Red Hat. The core idea is straightforward: take your organization’s actual governance policy documents, read them automatically, and translate them into testable risk profiles and deployable safety controls.
That’s a meaningful shift from how this usually works. Right now, compliance teams write policies, engineers interpret them manually, and somewhere in the middle, things get lost, misread, or quietly skipped.
asago aims to make that translation automated, auditable, and traceable — connecting the compliance side to the engineering side without requiring either team to fully speak the other’s language.
The Problem It’s Solving
As agentic AI moves from pilot projects to long-running autonomous systems, the stakes for getting safety controls right go up considerably. Two failure modes are becoming common:
- Over-caution: Months of manual policy review stall deployment while teams try to interpret frameworks like the EU AI Act or NIST AI RMF without clear tooling.
- Under-caution: Shadow AI deployments go live without proper guardrails, creating real exposure to data vulnerabilities and agentic AI attacks.
asago is positioned to address both. It reads uploaded governance documents, maps them to risk profiles, generates use-case-specific safety testing scenarios, and then recommends tailored mitigations — including guardrails — with a clear audit trail attached.
Why Open Source Matters Here
Red Hat is making a deliberate choice to build this as a vendor-agnostic open standard rather than a proprietary feature. Stuart Battersby, AI Safety & Model Evaluation Architect at Red Hat, makes the case plainly: safety testing results need to be comparable across systems, and fragmented vendor tooling makes that harder, not easier.
That framing is worth taking seriously. When every major cloud provider ships its own safety layer, enterprises running hybrid or multi-cloud environments end up with inconsistent controls and no clean way to audit across them.
An open standard gives compliance teams, data scientists, and infrastructure engineers a shared surface to work from — and it fits naturally into existing DevOps, enterprise AI orchestration, and GitOps workflows.
What’s Supported and What’s Next
asago references established frameworks out of the box, including the EU AI Act via the IBM AI Risk Atlas and the NIST AI Risk Management Framework. That’s a practical starting point for enterprises already working within those compliance regimes.
The project is currently in its formation phase on GitHub. Red Hat is actively inviting developers, academic researchers, and enterprise early adopters to participate — and is specifically calling for contributors from global jurisdictions to broaden the coverage of AI safety perspectives and risk perspectives.
Who Should Pay Attention
If you’re in any of these positions, asago is worth watching:
- Compliance officers who need verifiable evidence trails, not just policy documents
- Platform engineers managing enterprise LLMs or autonomous agents in production
- AI teams navigating EU AI Act or NIST requirements without a clear operationalization path
- Open-source contributors interested in AI safety infrastructure at the enterprise layer
The Takeaway
asago doesn’t promise to make AI governance easy. What it does promise is to make the translation from written policy to deployed safety control less manual, less error-prone, and more auditable. For enterprises scaling agentic AI, that’s not a nice-to-have — it’s the infrastructure layer that makes everything else defensible.
The project is early, but the problem it’s targeting is real and growing. Worth a bookmark on GitHub, at minimum.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!