Compliance Becomes Code: An Open-Source Consortium Moves to Keep AI Governance Out of Proprietary Hands
Red Hat, joined by NVIDIA, IBM Research, Microsoft, Brave Software, MIT Lincoln Laboratory, The Alan Turing Institute and others, has launched asago, an open-source project that converts written AI governance policy into deployable, auditable controls.

Red Hat, joined by NVIDIA, IBM Research, Microsoft, Brave Software, MIT Lincoln Laboratory, The Alan Turing Institute and others, has launched asago, an open-source project that converts written AI governance policy into deployable, auditable controls. The move signals that the compliance layer of the AI stack, the connective tissue between regulation and running systems, is now contested ground that organisations can choose to own rather than rent.
A Consortium Turns Policy Into Production Controls
Announced on August 4 in a Red Hat press release, asago (AI Safety And Governance Orchestration) is an Apache 2.0 licensed community project, with code hosted on GitHub. It structures governance work into four automated stages: reading an organisation's policies and mapping their requirements to established frameworks (the NIST AI RMF, the OWASP Top 10 for LLM applications, and the EU AI Act via IBM's AI Risk Atlas); generating safety testing scenarios tailored to the identified risks; recommending guardrails; and orchestrating the resulting controls into deployment-ready configurations for hybrid cloud and Kubernetes environments. Each stage produces a continuous audit trail that links specific policy clauses to the tests and runtime controls that enforce them.
The founding roster spans commercial and research institutions: Red Hat, Alquimia AI, Brave Software, the EvalEval coalition, IBM Research, the Interdisciplinary Transformation University Austria, Microsoft, MIT Lincoln Laboratory, North Carolina State University, NVIDIA, and The Alan Turing Institute.
The Timing Is the Message
The launch landed two days after the European Commission's AI Office activated its enforcement powers over general-purpose AI model providers on August 2, with authority to demand documentation, evaluate models, order corrective measures, and levy fines of up to 15 million euros or 3 percent of worldwide annual turnover. Governance obligations are no longer aspirational text; they are enforceable requirements that must be demonstrated in running systems. That shift converts the translation of policy into technical controls from a consulting exercise into core infrastructure. Whoever supplies that translation layer holds durable leverage over how organisations deploy AI.
Governance Tooling Is the Next Layer of Lock-In
The market had been drifting toward proprietary answers: closed compliance SaaS platforms that ingest an organisation's policies, risk registers, and audit evidence, and hold them in someone else's cloud. For organisations that care about data control, that is an uncomfortable trade: the record of how you govern your most sensitive systems becomes itself a dependency on an external vendor. An Apache-licensed, self-hostable alternative changes the calculus. Policy logic, test suites, and audit trails can remain inside an organisation's own infrastructure, inspectable line by line, portable across clouds, and free of per-seat rent. There is also a broader strategic upside: if a shared open scaffolding for governance takes hold across vendors, it could do for compliance what Kubernetes did for orchestration, establishing a common substrate that no single supplier controls, and lowering the cost of demonstrable compliance for everyone, including smaller sovereign deployments that cannot afford enterprise GRC contracts.
Adopt the Direction, Not Yet the Dependency
The caveats are real. Nothing about asago is production-tested. Independent coverage notes there are no deployed customer case studies, no performance benchmarks under an actual regulatory audit, and no established mechanism for resolving disputes among contributing organisations. The project is in its formation phase. The practical posture for technical and compliance teams is engagement without dependency: evaluate the code, trial the policy-to-framework mapping against your own governance documents, and contribute where your regulatory context is under-represented. Keep audit evidence in portable formats regardless of tooling. For organisations facing the EU AI Act's enforcement regime, the ability to show a traceable line from policy clause to runtime control is precisely what regulators will ask for; building that muscle on open infrastructure preserves the option to switch or self-host later.
Own the Rulebook, Own the Runtime
Regulation has made AI governance mandatory; asago is a bid to make it open. Organisations that treat the compliance layer as strategic infrastructure, and keep it on ground they control, will meet their regulators without surrendering their independence to a new class of vendor.
Sources: Red Hat press release (primary): https://www.redhat.com/en/about/press-releases/red-hat-launches-asago-community-automate-ai-safety-and-governance-policy-production | AI News: https://www.artificialintelligence-news.com/news/red-hat-nvidia-ibm-back-project-turning-ai-policy-into-code/ | European Commission, AI Act regulatory framework: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai | Wilson Sonsini, EU AI Act Enforcement Phase Begins: https://www.wsgr.com/en/insights/eu-ai-act-enforcement-phase-begins.html | Verified: launch date (August 4, 2026) and consortium membership confirmed against the primary press release; EU AI Act enforcement timeline confirmed against the European Commission's official page; the production-readiness caveat is drawn from independent reporting.
Source: Red Hat