Red Hat has launched asago, an open-source project designed to transform artificial intelligence governance policies into operational technical controls. Supported by organisations including NVIDIA and IBM Research, the initiative aims to close the persistent gap between the rules companies write and the systems their engineers must build.
Closing the policy-to-production gap
AI governance commonly begins with policies written by legal, compliance and risk teams. These documents may establish which data a model can access, when human approval is required and how an AI system should be monitored. Converting those requirements into reliable software controls, however, remains largely a manual process.
Asago is intended to make policies machine-readable so that they can be tested, versioned and deployed in a similar way to software code. Its contributors hope this approach will reduce inconsistent interpretations, implementation errors and the time between approving a policy and enforcing it across an organisation’s technology infrastructure.
The project could also provide evidence showing how a policy has been implemented. This may help companies demonstrate compliance to auditors and regulators while allowing technical teams to identify which control is responsible for a particular restriction.
Built through open collaboration
Red Hat is leading the project alongside technology companies, researchers and universities. Participants and supporters include NVIDIA, Microsoft and IBM Research. Asago also builds on earlier work conducted by Red Hat and NVIDIA through the Open Secure AI Alliance.
The software is being released under the Apache 2.0 licence, allowing organisations to use, modify and distribute it with relatively few restrictions. Developers, academic researchers and enterprise users have been invited to review the project and contribute to its development.
Asago remains in its formation stage. It should therefore be regarded as an emerging framework rather than a mature product ready for widespread production deployment.
Why businesses are paying attention
The initiative may prove particularly relevant to financial services, healthcare, government and other regulated sectors. These organisations increasingly use AI while facing strict requirements governing data protection, accountability and operational risk.
A shared policy-as-code system could make controls more consistent across data centres, public clouds and hybrid environments. Instead of recreating rules separately for every application, businesses could potentially manage them through a common governance layer.
This may also improve communication between compliance specialists and software engineers. Policy changes could become traceable technical updates, making it easier to determine when a rule changed, who approved it and which systems were affected.
Human oversight remains essential
Automating governance does not eliminate the need for legal interpretation or human judgement. Regulations can be ambiguous, differ between jurisdictions and change over time. A poorly interpreted policy converted into code could enforce the wrong decision consistently and at considerable scale.
Companies adopting such technology would still require review processes, testing, exception handling and clear accountability. Asago must also attract a broad contributor community and demonstrate that it can integrate with the diverse AI platforms already used by businesses.
Nevertheless, the project reflects a wider shift in AI governance, from policies existing mainly as documents towards rules that operate directly within technical systems. Its eventual influence will depend on whether companies and regulators accept policy as code as a practical foundation for responsible AI.
Newshub Editorial in North America – 5 August 2026

Ask NF GPT
If you have an account with ChatGPT you get deeper explanations,
background and context related to what you are reading.

Recent Comments