Red Hat、NVIDIA、IBM が AI ポリシーをコード化するプロジェクト「Asago」を支援
本文の状態
日本語全文を表示中
詳細モードで約7分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
AI News
Red Hat は NVIDIA や IBM と連携し、AI ガバナンスポリシーを自動でデプロイ可能なコードに変換するオープンソースプロジェクト「asago」を開始した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月7日 22:41
AI深層分析
キーポイント
政策からコードへの変換自動化
Red Hat は asago プロジェクトを通じて、組織のガバナンスポリシーを NIST AI RMF や EU AI Act などのフレームワークと照合し、リスクプロファイルを自動生成する仕組みを提供する。
4 つの段階によるワークフロー
このプロジェクトはリスクマッピング、リスク評価、緩和策の提案、そしてハイブリッドクラウド環境向けのデプロイ構成へのオーケストレーションという 4 つの段階で動作する。
継続的な監査証跡の構築
各ポリシー条項が特定のテストと実行時制御に紐付けられ、運用中のエージェントの挙動を常にポリシー根拠から追跡可能な監査証跡を生成する。
開発者コミュニティへの公開
Red Hat と NVIDIA が Open Secure AI Alliance で進めてきた取り組みに基づき、Apache License 2.0 の元で GitHub リポジトリが公開され、開発者や研究者の参加を呼びかけている。
多様なステークホルダーによる共同プロジェクト
Red Hat や NVIDIA のみならず、Microsoft、IBM、MIT、NC State など技術業界、学界、政府から多数の組織が参加するオープンソース協働 initiative である。
重要な引用
As organisations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement.
"The asago project is a true collaborative, open-source endeavour bringing together stakeholders from the technology industry, academia, and government."
"Many of the hardest AI safety and security challenges are still unsolved, and no single organisation can tackle them all alone."
The post Red Hat, NVIDIA, IBM back project turning AI policy into code appeared first on AI News.
編集コメントを表示
編集コメント
AI ガバナンスの実装を自動化するツールがオープンソースとして登場したことは、規制対応の負担軽減において大きな一歩となる。企業は自社のポリシーとこのツールの適合性を確認し、導入による開発プロセスの変化を評価すべきである。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Red Hat は、AI ガバナンスポリシーを実際の運用環境で使えるデプロイコードに変換することを目指すオープンソースコミュニティプロジェクト「asago」を立ち上げました。
このプロジェクトは、エンジニアリングチームとコンプライアンスチームが直面する「断片化された手順、ツール、要件」をつなぐ自動化可能かつ監査可能なワークフローとして位置づけられています。EU AI 法(EU AI Act)などの規制が施行される中、Red Hat は組織が直面する選択を以下のように定義しています。手動レビューによって AI の革新性を削ぎ落とすか、それともポリシーへの適合性を確認もせず管理されていないエージェントを生産環境で走らせるかです。
asago は、Red Hat と NVIDIA が「Open Secure AI Alliance」内で進めてきた取り組みを基盤としています。Apache License 2.0 の下で公開され、現在は形成フェーズにあります。GitHub リポジトリは開発者、学術研究者、そしてガバナンスへの早期導入を検討する企業向けにオープンされており、レビューや貢献を受け付けています。
ポリシー記述から実行中の制御まで、4 つの段階
Red Hat が説明するワークフローは 4 つのステージを通じて進行します。最初のステップはリスクマッピングです。このフレームワークは組織がアップロードしたガバナンスポリシーを読み込み、NIST AI RMF や OWASP LLM Top 10、そして IBM の AI Risk Atlas を通じてカタログ化された EU AI 法など、確立された枠組みに対して特定の要件をマッピングします。これにより、コンプライアンスチームによる手動での照合ではなく、ポリシー記述が自動的にリスクプロファイルへと変換されます。
そこから、asago はリスク評価フェーズへと移行します。このプロジェクトは、特定のユースケースに合わせてシナリオを生成・実行し、標準的なチェックリストに基づくテストではなく、リスクマップで特定された有害な行動を検出するよう設計されています。
リスク軽減の段階では、システムがテスト結果に基づいてガードレール(安全装置)を推奨し、審査官の厳格な scrutiny に耐えうる根拠の追跡経路を構築します。
Red Hat によると、asago はこれらの推奨制御をハイブリッドクラウドおよび Kubernetes 環境向けのデプロイ済み構成としてオーケストレーションします。これにより、リスク軽減の提案と実際の制御の実行の間に存在する手動インフラコードが不要となり、Red Hat が掲げる目標である「数ヶ月かかっていたデプロイ期間を数日に短縮」を実現します。
監査証跡のプロダクト化
各工程は、単一の継続的な監査証跡に情報を提供することを意図しています。各ポリシー条項は特定のテストと紐付けられ、各テストはランタイム制御と紐付けられます。原則として、審査官は稼働中のデプロイにある任意の制御を、それを正当化したポリシーの行まで遡って追跡することが可能です。
このトレーサビリティこそが、本プロジェクトの実質的な売り込みポイントです。Red Hat の公式な見解では、AI セーフティは一度きりの認証作業ではなく、エージェントが稼働し続ける限り常にチェック可能な状態を維持する「継続的なエンタープライズユースケース」として位置づけられています。
Red Hat の AI エンジニアリング担当バイスプレジデント、スティーブン・ヒュールズ氏はこう述べています。「組織が実験的な AI パイロットから、長期間稼働する自律型エージェントへと移行する中で、明確な運用上のガードレールを確立することは、極めて重要なインフラ要件となっています。」
ヒュールズ氏は、このプロジェクト「asago」を Red Hat の別の取り組みである Lightwell イニシアチブとも関連付けています。Lightwell は AI に起因する脆弱性からオープンソースサプライチェーンを守ることに焦点を当てていますが、ヒュールズ氏によれば asago は「企業ポリシーの定義と実際の生産環境にあるエージェントとのリンクを自動化することで、エンタープライズ AI における次の論理的なステップとなる」とのことです。
Red Hat の AI セーフティおよびモデル評価アーキテクトであるスチュアート・バタースビー氏は、プロジェクトが目指す姿についてより直接的に語っています。「asago プロジェクトは、技術業界、学界、政府からステークホルダーを集めた、真の協力的かつオープンソースな取り組みです。」
「私たちは、AI セーフティに関する多様な視点を最大限にカバーするために、特に世界各国の管轄区域からのより多くの協力者をこのコミュニティ主導の取り組みに参加するよう呼びかけています。」
単一のベンダーではない、主要な貢献者リスト
asago の創設メンバーは Red Hat と NVIDIA に限定されません。Brave Software、IBM Research、Microsoft、MIT リンカーン研究所、ノースカロライナ州立大学、そして The Alan Turing Institute が貢献者として名を連ねています。これらに加え、EvalEval コアリションやオーストリアの学際的変革大学(IT:U)も参加しています。また、創設研究機関ではなくパートナーである Alquimia AI も名前が挙げられています。
マイクロソフトの責任ある AI 担当チーフプロダクトオフィサー、サラ・バード氏は「AI の安全性やセキュリティにおける最も困難な課題の多くはまだ解決されておらず、単一の組織がこれらすべてを一人で抱え込むことはできない」と述べています。
学界からも異なる視点から同様の意見が上がっています。ノースカロライナ州立大学の工程学院 interim デーン(学長代行)を務めるヴィーナ・ミスラ氏は、AI の安全性は「政策上の問題であると同時に、エンジニアリング上の課題でもある」と指摘しています。
asago の出力は、Red Hat によるとインフラに依存しない設計となっています。Kubernetes、Terraform、Ansible 向けの宣言型構成を提供するため、あるクラウドで設定したセキュリティ姿勢を別のクラウドへ移行する際にも再設計は不要です。
しかし、このプロジェクトはまだ本番環境でのテストが行われていません。Red Hat の発表にはデプロイ済み顧客の事例研究はなく、「数ヶ月ではなく数日で」という主張が実際の規制監査の下でも成立することを示すベンチマークもありません。また、コードが形成段階を超えた後に、貢献する各組織間でリスクマッピング基準を巡って紛争が生じた場合、それをどう解決するかという指針も示されていません。
現時点では、このプロジェクトは GitHub 上のリポジトリとガバナンス構造として存在しており、完成した製品を導入するのではなく、貢献者リストと共に開発に取り組むことを望む開発者、研究者、企業チームに対してオープンになっています。
関連記事:OpenAI が EU AI 法(GPAI コード)に準拠した安全性対策を調整

本記事「Red Hat、NVIDIA、IBM が AI ポリシーをコード化するプロジェクトを支援」は、AI News に最初に掲載されました。
原文を表示
Red Hat has launched asago, an open-source community project that aims to turn AI governance policy into production-ready deployment code.
The project describes itself as an automated, auditable workflow that connects the “fragmented steps, tools, and requirements” of engineering and compliance teams. With regulation such as the EU AI Act now taking effect, Red Hat frames the choice facing organisations as: either grind AI innovation down through manual review, or let ungoverned agents run in production without anyone checking their behaviour against policy.
asago builds on Red Hat and NVIDIA’s work inside the Open Secure AI Alliance. It is being released under the Apache License 2.0, and the project is currently in its formation phase, with a repository open on GitHub for developers, academic researchers, and enterprise early adopters to review and contribute to governance.
Four stages from policy text to running controls
The workflow Red Hat describes runs across four stages. Risk mapping comes first: the framework reads an organisation’s uploaded governance policy and maps its specific requirements against established frameworks, including the NIST AI RMF, the OWASP LLM Top 10, and the EU AI Act as catalogued via IBM’s AI Risk Atlas. Policy language becomes a risk profile automatically, rather than through a compliance team’s manual cross-referencing.
From there, asago moves into risk assessment. The project generates and runs scenarios tailored to the specific use case, probing for the harmful behaviours that its risk mapping flagged rather than testing against a standard checklist. Risk mitigation follows: the system recommends guardrails based on what the testing surfaced, and builds a rationale trail meant to survive a reviewer’s scrutiny.
asago orchestrates the recommended controls into deployment-ready configurations for hybrid cloud and Kubernetes environments, according to Red Hat, cutting out the manual infrastructure coding that would otherwise sit between a mitigation recommendation and a running control. Red Hat’s stated aim is to cut deployment timelines from months to days.
Audit-trail-as-a-product
Every stage is meant to feed a single, continuous audit trail. Each policy clause ties to a specific test, and each test ties to a runtime control. A reviewer, in principle, can trace any active control in a live deployment straight back to the policy line that justified it.
That traceability is the actual selling point. Red Hat’s own framing treats AI safety less as a one-off certification exercise and more as an ongoing enterprise utility (i.e. something that stays checkable as agents keep running, not just at the point they’re first approved.)
Steven Huels, Red Hat’s VP of AI Engineering, says: “As organisations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement.”
Huels connects asago to Red Hat’s separate Lightwell initiative, which focuses on securing the open-source supply chain from AI-driven vulnerabilities, calling asago “the next logical step for enterprise AI by automating the link between corporate policy definitions and live production agents.”
Stuart Battersby, Red Hat’s AI safety and model evaluation architect, is more direct about the project’s intended shape: “The asago project is a true collaborative, open-source endeavour bringing together stakeholders from the technology industry, academia, and government.
“We encourage more collaborators to join this community-driven effort, particularly from global jurisdictions, to ensure maximum coverage of AI safety viewpoints.”
A roster of major contributors, not a single vendor
The founding list runs far wider than Red Hat and NVIDIA. Brave Software, IBM Research, Microsoft, MIT Lincoln Laboratory, North Carolina State University, and The Alan Turing Institute all appear as contributors, alongside the EvalEval coalition and Austria’s Interdisciplinary Transformation University (IT:U). Alquimia AI, a partner rather than a founding research institution, is also named.
Sarah Bird, Chief Product Officer for Responsible AI at Microsoft, comments: “Many of the hardest AI safety and security challenges are still unsolved, and no single organisation can tackle them all alone.”
Academic voices push a similar line from a different angle. NC State’s Veena Misra, Interim Dean of the College of Engineering, calls AI safety “an engineering problem as much as a policy problem.”
asago’s outputs are meant to be infrastructure-agnostic: declarative configurations for Kubernetes, Terraform, and Ansible, according to Red Hat, so a safety posture set in one cloud doesn’t need re-engineering in another.
Nothing about the project is production-tested yet. There’s no deployed customer case study in Red Hat’s announcement, no benchmark showing the “days, not months” claim holding up under a live regulatory audit, and no indication of how disputes between contributing organisations over risk-mapping standards get resolved once the code moves past formation.
For now, the project exists as a repository and a governance structure on GitHub, open to developers, researchers, and enterprise teams willing to build alongside a list of contributors rather than adopt a finished product.
See also: OpenAI aligns safety practices with EU AI Act’s GPAI Code

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.
AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
The post Red Hat, NVIDIA, IBM back project turning AI policy into code appeared first on AI News.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み