Most companies have an AI policy document sitting somewhere in a shared drive. Few have a reliable way to ensure their AI systems actually follow it.
That's the problem a new open-source project aims to solve, and it has attracted backing from three enterprise AI heavyweights: Red Hat, IBM and NVIDIA.
The initiative focuses on translating written AI governance policies, the kind lawyers and compliance teams create for regulators and internal risk committees, into machine-readable code that software can check and enforce automatically.
Instead of existing as a paragraph buried inside a PDF, a policy becomes something an AI system can evaluate in real time.
That distinction matters more than it might first appear.
Why policy has been stuck on paper
AI governance has become a boardroom priority over the past two years.
Executives want assurance. Regulators want documentation. Customers want transparency.
Yet most governance remains a manual process.
Someone writes a policy. Someone else audits whether systems comply. The two rarely connect in real time.
That approach doesn't scale.
A company operating dozens of AI models across multiple business units can't rely on compliance officers manually checking every deployment whenever a model changes or new data is introduced.
Turning policy into code changes the process entirely.
Rules covering data handling, transparency, model testing or bias can be expressed as machine-readable logic, allowing systems to verify compliance continuously rather than through occasional audits.
"Policy should be executable, not just readable."
Why Red Hat, IBM and NVIDIA are involved
The involvement of Red Hat and IBM makes strategic sense.
Both companies have spent years positioning themselves as trusted enterprise infrastructure providers, helping large organisations adopt emerging technologies while meeting strict governance requirements.
For NVIDIA, the project fits a broader strategy.
The company increasingly wants to provide every layer of the AI stack, from chips and software frameworks to the governance tools enterprises need before deploying AI into production.
The open-source approach also sends an important signal.
Rather than allowing a single vendor to define AI compliance standards, the three companies are backing a shared framework that organisations can inspect, adapt and improve collectively.
That could reduce fragmentation and lower the cost of compliance, particularly for organisations without large legal or AI safety teams.
The bigger signal
This project reflects a broader shift happening across enterprise AI.
The conversation has moved beyond, "Can we build powerful AI?" to, "Can we prove it's behaving the way we claim?"
Regulation is helping drive that change.
The EU AI Act, sector-specific rules in finance and healthcare, and increasingly demanding enterprise procurement processes all require companies to demonstrate compliance rather than simply promise it.
Machine-readable policy offers one practical solution.
It turns governance from a static document into an operational system that can be tested, versioned and audited just like software.
Whether this project becomes an industry standard remains uncertain.
Open-source governance initiatives often take years to achieve widespread enterprise adoption, particularly if cloud providers and AI platform vendors need to build support into their own products.
Even so, the direction of travel is becoming clear.
Compliance is evolving into core infrastructure rather than an administrative exercise.
What This Means for Miami
Miami's AI ecosystem spans highly regulated industries including fintech, healthcare and logistics, where compliance is increasingly becoming a competitive advantage.
Machine-readable policy frameworks could give South Florida startups a faster and more affordable path to AI governance without requiring large legal or compliance teams, an important benefit for venture-backed companies scaling quickly.
Enterprise customers across Miami, including banks, healthcare providers and large corporations, are also likely to place greater emphasis on automated policy enforcement when evaluating AI vendors.
For local developers building on Red Hat or NVIDIA infrastructure, governance capabilities may soon become standard features rather than optional add-ons, making compliance part of the development process instead of an afterthought.
