Red Hat maps asago’s path from AI policy to deployable controls
The early architecture links policy extraction, risk mapping, red-team scenarios and Kubernetes-ready mitigations, but much of the workflow remains a roadmap.
Red Hat has published an initial technical architecture for asago, an open source project intended to connect enterprise AI policy with testing and deployable runtime controls. The useful distinction is that asago is not another guardrail or evaluation library: Red Hat describes it as an orchestration layer that should join existing safety tools and fill gaps between them.
From prose to test scenarios
The proposed first half of the workflow starts with policy documents. A policy mapper extracts risks and maps them to the IBM AI Risk Atlas, producing risk cards that can be narrowed to the technical risks relevant to a particular agent. A scenario generator then combines those risks with the agent’s deployment context to produce tests and supporting data.
That sequence addresses a practical platform-engineering problem: policy owners, application teams and security engineers often work with different artifacts. In Red Hat’s design, the trace begins with a policy clause rather than with a generic benchmark, so an eventual test should retain a reason for existing.
From failed tests to platform configuration
The second half is an iterative loop. Scenarios are converted into run artifacts for evaluation and red-team frameworks, executed through EvalHub, and passed to a recommender that proposes mitigations. Red Hat says those mitigations are intended to become deployable resources such as Kubernetes custom resources or ConfigMaps, after which the agent can be tested again.
The broader project announcement also names Terraform and Ansible outputs as goals. If implemented, that would make AI-safety decisions fit normal GitOps review and change-control paths instead of ending as a separate compliance report.
What exists now
The implementation is earlier than the architecture diagram may suggest. Red Hat says the community is still in project formation, while the available code currently includes policy-mapping work, examples and midojo, a framework for testing agents against indirect prompt injection. The complete policy-to-production loop remains a planned system, not a finished platform.
That maturity gap matters. The project’s value will depend on whether it preserves useful provenance across policy parsing, scenario generation, third-party test runners and generated mitigations without turning uncertain model judgments into apparently authoritative controls.
The community starts with contributors from Red Hat, Alquimia AI, Brave, IBM Research, Microsoft, MIT Lincoln Laboratory, NVIDIA, North Carolina State University, The Alan Turing Institute and others. Its Apache-2.0 approach gives platform teams a concrete upstream to inspect, but the immediate opportunity is architectural review and experimentation—not production adoption.
sources
comments · 0