Red Hat has launched an open-source community project called Asago (AI Safety and Governance Orchestration) that automatically converts AI governance policies into operational controls. SiliconANGLE reported on Aug. 4 that Asago focuses on linking policy requirements to deployment configurations that can be applied to AI systems.
Asago brings into a single flow work that had been split among compliance teams, data scientists and infrastructure managers. It automates policy interpretation, risk assessment, safeguard recommendations and deployment configuration creation, and it also leaves an audit trail that allows users to trace which controls are based on which policy requirements.
Red Hat said such a system has become necessary as companies move beyond the experimental phase of generative AI to adopt long-running systems and autonomous agents. It said translating governance requirements into the tests, guardrails and infrastructure configurations engineers actually need is becoming increasingly difficult.
Red Hat said manually interpreting policies and producing custom scripts can slow deployments and increase errors.
Asago operates through a four-step standard platform and workflow. It first interprets an organisation's governance policies, then maps them to standards such as the U.S. National Institute of Standards and Technology AI Risk Management Framework, the Open Worldwide Application Security Project Large Language Model Applications Top 10 and the European Union AI Act. IBM AI Risk Atlas is used in this process.
It then generates and runs safety tests tailored to the risk of a specific use case. Based on the results, it recommends mitigation measures and guardrails and records the rationale. Finally, it converts controls into deployment configurations that can be applied directly to hybrid cloud and Kubernetes environments. Outputs include artefacts for Kubernetes, Terraform and Ansible.
Priya Nagpurkar (프리야 나그푸르카르), vice president of the IBM Research AI platform, said AI needs measurable tests and operational controls to earn trust in real-world environments. IBM is contributing expertise through the Asago community to narrow the gap between governance frameworks and AI systems deployed in practice, she added.
Participants in Asago include Red Hat, Alquimia AI, Brave Software, the IvelIvel Consortium, IBM Research, the Austrian Interdisciplinary Transformation University, Microsoft, the MIT Lincoln Laboratory, North Carolina State University, Nvidia and the Alan Turing Institute. The project is based on work Red Hat and Nvidia have carried out through the Open Secure AI Alliance. The software is released under the Apache License 2.0 and is currently in the project formation stage.