Each step produces a documented audit trail that links a policy clause to a specific test or runtime control, allowing reviewers to trace a live safeguard back to the rule that justified it . Red Hat stated the project aims to cut deployment cycles from months to days
.
The project explicitly maps to NIST AI RMF (Risk Management Framework), OWASP LLM Top 10, and the EU AI Act .
Additional organisations are expected to join as the project matures.
asago is being established under the Apache 2.0 open-source license . The project code is available on GitHub in its formation phase for developers, academic researchers, and enterprise early adopters to review
.
On 4 August 2026, IBM and Red Hat announced that eligible universities, NGOs, and think tanks would receive free access to Lightwell, an AI-powered platform that finds, validates, and repairs vulnerabilities in open-source software packages . Onboarding for eligible institutions began immediately in August 2026
.
Both announcements address a set of interconnected structural risks in the AI era:
Steven Huels, Red Hat's VP of AI Engineering, described the challenge: "As organisations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement" .
These announcements build on the USD 5 billion Project Lightwell commitment announced in May 2026 , the Open Secure AI Alliance (launched by NVIDIA with Red Hat as an inaugural member)
, and broader industry recognition that "no single organisation can tackle [AI safety and security challenges] alone" (Sarah Bird, Microsoft)
.