Red Hat, NVIDIA, and IBM: Transforming AI Governance into Code

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Red Hat, NVIDIA, and IBM Join Forces for asago
Red Hat recently unveiled asago, an open-source community project aimed at transforming AI governance into ready-to-deploy code. This project presents itself as an automated and auditable workflow, designed to bridge the gaps between the often fragmented stages, tools, and requirements of engineering and compliance teams. With regulations like the EU AI Act coming into effect, Red Hat highlights the dilemma organizations face: either slow down AI innovation through manual checks or risk allowing unregulated agents to operate unchecked.
asago is based on the joint efforts of Red Hat and NVIDIA within the Open Secure AI Alliance. Distributed under the Apache License 2.0, the project is currently in its initial development phase, with an open repository on GitHub. This allows developers, academic researchers, and early enterprise users to participate in shaping governance.
From Policy to Operational: A Four-Step Process
The workflow proposed by Red Hat breaks down into four distinct steps. The first step is risk mapping. The system reads the governance policy provided by an organization and aligns its specific requirements with established frameworks, such as the NIST AI RMF, the OWASP LLM Top 10, and the EU AI Act, as listed in IBM's AI Risk Atlas. This process automatically transforms the language of the policy into a risk profile, eliminating the need for manual cross-referencing by the compliance team.
The second step is risk assessment. asago generates and executes scenarios tailored to the specific use case, examining potentially harmful behaviors identified during the risk mapping, rather than relying on a simple standard checklist. Next comes risk mitigation, where the system proposes safeguards based on test results and establishes a rational traceability capable of withstanding external scrutiny.
Finally, asago orchestrates the recommended controls into deployment-ready configurations for hybrid environments and Kubernetes. This eliminates the need for manual coding of the infrastructure, which would otherwise be required between a mitigation recommendation and an operational control. Red Hat aims to reduce deployment timelines from several months to just a few days with this approach.
Comprehensive Traceability for Ongoing Security
Each step of the process feeds into a continuous audit trail. Each policy clause is linked to a specific test, and each test is associated with an execution control. In theory, an auditor can trace any active control in a live deployment back to the policy line that motivated it.
This traceability is one of the project's main selling points. Red Hat presents AI security not as a one-time certification but as an ongoing enterprise utility, meaning a verifiable process as long as agents are active, and not just at the time of their initial approval.
Steven Huels, Vice President of AI Engineering at Red Hat, emphasizes the importance of this approach: “As organizations transition from experimental pilot projects to long-term autonomous agents, establishing clear operational safeguards becomes a critical infrastructure requirement.”
Huels also connects asago to Red Hat's Lightwell initiative, which aims to secure the open-source supply chain against AI-related vulnerabilities. He describes asago as a “logical next step for enterprise AI by automating the link between enterprise policy definitions and live production agents.”
Stuart Battersby, AI Security Architect at Red Hat, is more direct about the collaborative nature of the project: “The asago project is a true collaborative and open-source effort bringing together stakeholders from the tech industry, academia, and government.”
He encourages more contributors to join this community effort, particularly from global jurisdictions, to ensure maximum coverage of perspectives on AI security.
An International Collaboration for an Ambitious Project
The list of contributors to asago extends well beyond Red Hat and NVIDIA. Organizations such as Brave Software, IBM Research, Microsoft, MIT Lincoln Laboratory, North Carolina State University, and The Alan Turing Institute are also involved. The coalition EvalEval and the Interdisciplinary Transformation University (IT:U) of Austria are also among the contributors. Alquimia AI, a partner rather than a founding research institution, is also mentioned.
Sarah Bird, Head of Responsible AI Products at Microsoft, highlights the ongoing challenges in AI security and safety, stating that no organization can solve them alone.
Academic voices share this vision. Veena Misra, Interim Dean of the College of Engineering at NC State, views AI security as an “engineering problem as much as a policy issue.”
The outcomes of asago are designed to be infrastructure-agnostic, with declarative configurations for Kubernetes, Terraform, and Ansible, according to Red Hat. This means that a security posture defined in one cloud does not need to be re-engineered in another.
For now, the project has not yet been tested in production. There are no client case studies deployed in Red Hat's announcement, nor any reference demonstrating that the promise of “days, not months” holds up under live regulatory audit. Additionally, no indication is given on how disputes between contributing organizations regarding risk mapping standards will be resolved once the code moves past the training phase.
Currently, the project exists as a repository and governance structure on GitHub, open to developers, researchers, and enterprise teams eager to build alongside a list of contributors rather than adopting a finished product.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.