Strategy

Apache projects are adopting AI the way everyone else is: quickly, and one account at a time. A committer signs up with a provider, pays out of pocket or through an employer, and wires the result into a project workflow. That works for one project. At the scale of hundreds of projects it leaves the Foundation with no view of what is being spent, no shared catalog of what is approved, and no way to extend a donated pool of tokens across communities fairly.

The Responsible AI initiative is building a Foundation-managed alternative. Committers remain free to use whatever tools they like; this is the path the ASF runs and can account for.

Free to projects

A project draws on a budget the Foundation allocates, rather than a personal account or an employer's.

Governed by default

Every call is matched to a committer, metered, and charged to their project.

Private where it matters

Sensitive work runs on models the Foundation hosts itself, so the content never leaves ASF infrastructure.

How the pieces fit together

The work divides into four layers. A project asks for work; agents do it; shared services run those agents and govern every model call; models answer.

WORKLOADSAGENTS SERVICESMODELS define · schedule · report runs security scansissue triageCI/CD review what projects build agent workbench build and run agents MCP federation governed tool access llm.apache.org metered model access advisor cost · quality · policy frontier providersenterprise termsASF-hosted models

Workloads is what a project asks for: which job to run, on what schedule, reported where. Agents are the implementations that do the work, and the layer where projects contribute their own. Services are the shared infrastructure the Foundation builds and operates. Models are the classes of model available behind the gateway.

The dividing line matters. Projects contribute at the agents layer; the Foundation is responsible for keeping the services underneath them running.

One governed path to models

llm.apache.org is the address AI calls go to. It matches the caller to an Apache committer and their project, then picks a model that fits the job, metering the call against that project's budget. Some of those models run on the Foundation's own hardware, so sensitive material need never leave ASF infrastructure.

PROJECTS CI pipelines committer tools agents committees one address llm.apache.org Apache identityper-project budget metered & attributedrouted to best fit MODELS frontier providers best capability enterprise terms not used for training ASF-hosted models never leaves our infrastructure

The three classes differ in what happens to a prompt: frontier providers offer the most capability but the prompt leaves ASF control; enterprise terms keep it from being used to train a provider's models; Foundation-hosted models never see it leave our infrastructure at all.

Tokens reach that pool from several directions: providers donate them, the Foundation procures capacity, and we run open-weight models on our own rented hardware. A project asks for what it needs; the Foundation decides where it comes from.

Where this is going

The initiative is early, and this page describes direction rather than finished work.

Running now Automated security scanning across Apache projects, with findings delivered to maintainers through the Foundation's standard disclosure process
In development The model gateway at llm.apache.org, and the agent workbench the scanning pipelines already run on
In design Tool federation, and the advisor layer that tracks cost, quality, and routing policy
Ahead Self-serve access for any project that wants it, and open-weight models the Foundation controls

Each piece is being built in the open. As they land, this page will say so.

Take part

The initiative works in public on the discussion list, and welcomes participation from any Apache committer — on the technical work, on policy, or on the questions projects are facing right now.

This page describes work in progress and will be updated as the work develops.