AI Pulse by Inblix

Red Hat’s asago wants to turn AI policy into code—and cut deployment from months to days

AI News · Aug 4, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: Red Hat’s asago wants to turn AI policy into code—and cut deployment from months to days

The gap between an AI governance policy written in a boardroom and actual guardrails running in production is, for most enterprises, a mess of manual reviews, fragmented tools, and compliance teams playing catch-up. Red Hat just open-sourced a project called asago that aims to close that gap automatically—and the contributor list suggests the industry is paying attention.

Here’s how it works: you upload your governance policy, and asago maps it against frameworks like the NIST AI RMF, the OWASP LLM Top 10, and the EU AI Act via IBM’s AI Risk Atlas. That’s step one, risk mapping. Then it generates scenarios tailored to your specific use case and probes for the exact harmful behaviors the policy flagged—not a generic checklist. After testing, it recommends guardrails and, crucially, builds a rationale trail showing why each control exists. Finally, it orchestrates those controls into deployment-ready configurations for Kubernetes, Terraform, and Ansible environments. Red Hat claims this pipeline can compress deployment timelines from months to days.

The real product here isn’t speed—it’s the audit trail. Every policy clause links to a specific test, and every test links to a runtime control. A reviewer can trace any active guardrail in a live deployment straight back to the sentence in the policy document that justified it. That’s a fundamentally different proposition from a one-time certification. It treats AI safety as an ongoing utility that stays checkable as agents keep running.

Steven Huels, Red Hat’s VP of AI Engineering, calls this “the next logical step” from the company’s Lightwell initiative on securing the open-source supply chain. The founding contributors include Microsoft, IBM Research, MIT Lincoln Laboratory, and The Alan Turing Institute—not exactly a Red Hat side project. But there’s a gap between ambition and evidence. No customer case study exists yet, no benchmark validates the “days, not months” claim under a real regulatory audit, and Red Hat hasn’t explained how asago would handle disputes between conflicting policy requirements. For teams watching the EU AI Act deadlines approach, the project is worth tracking, but it’s firmly in the formation phase. The GitHub repo is open; production is another story.

💡 Key Takeaways

  1. asago automatically maps uploaded governance policies to frameworks like the EU AI Act and OWASP, then generates tailored test scenarios rather than using a one-size-fits-all checklist.
  2. The system creates a continuous audit trail linking each runtime control back to the specific policy clause that justified it—treating AI safety as an ongoing utility, not a one-off certification.
  3. Major contributors include Microsoft, IBM Research, MIT Lincoln Laboratory, and The Alan Turing Institute, but the project has no production case studies or benchmarks yet.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles