Red Hat Launches asago AI Governance Project
A multi-organisation effort to automate policy-to-control traceability could reduce manual compliance translation work for agencies deploying AI - but it is not yet a deployable tool.
Key points
- Red Hat launched asago, an open-source project linking AI governance policy text to risk tests and deployment controls.
- The planned workflow maps policies to NIST AI RMF, OWASP LLM Top 10, and EU AI Act via IBM's AI Risk Atlas.
- Asago is in formation phase only - no production release, timeline, or independent validation has been announced.
Implications for Australian agencies
- Monitor AI governance practitioners may want to monitor asago's development on GitHub, particularly whether its policy-to-control traceability model matures into a deployable tool applicable to APS compliance workflows.
- Consider Agencies developing AI governance frameworks could consider whether asago's approach of linking policy clauses to risk assessments and runtime controls aligns with their own audit and assurance requirements.
Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.
View original source
Copied.
Appeared in:
Weekly digest, 3 August 2026
"Red Hat Launches asago AI Governance Project"
Source: Let's Data Science – AI Governance
Published: 4 August 2026
URL: https://letsdatascience.com/news/red-hat-launches-asago-ai-governance-project-fb36091a
Red Hat announced asago (AI Safety and Governance Orchestration) on 4 August 2026, an open-source project designed to translate written AI governance policies into risk tests, recommended safeguards, and deployment configurations for platforms such as Kubernetes, Terraform, and Ansible. The planned four-stage workflow would map organisational policies to established frameworks including the NIST AI Risk Management Framework and EU AI Act, generate use-case-specific safety tests, and preserve an audit trail from policy clause to runtime control. The project involves IBM Research, Microsoft, MIT Lincoln Laboratory, Nvidia, the Alan Turing Institute, and others. However, asago remains in its formation phase with no generally available release or independent validation published.
Implications for Australian agencies:
- [Monitor] AI governance practitioners may want to monitor asago's development on GitHub, particularly whether its policy-to-control traceability model matures into a deployable tool applicable to APS compliance workflows.
- [Consider] Agencies developing AI governance frameworks could consider whether asago's approach of linking policy clauses to risk assessments and runtime controls aligns with their own audit and assurance requirements.
Retrieved from SIMS, 16 September 2026.