Table of Contents
The Linux Foundation will govern TRACE, a new open standard for AI runtime attestation, the nonprofit said Tuesday. Contributed by confidential computing vendor OPAQUE, the specification was built with AMD, Intel, Microsoft, and the Technology Innovation Institute (TII).
TRACE produces cryptographically verifiable records, anchored in hardware, of how AI agents and other confidential workloads actually run. The record is built to travel with the workload across clouds and sovereign infrastructure.
The move lands as companies push AI agents into production systems that touch sensitive data, raising demand for proof that outside parties can check independently.
AI Runtime Attestation: Key Takeaway
- TRACE gives AI agents a portable record, anchored in hardware, that proves how they ran, and the Linux Foundation will steward it as neutral infrastructure.
This section contains affiliate links; we may earn a commission at no cost to you.
Tools to help you find and close these flaws before attackers do:
- Tenable: vulnerability management to locate every affected Oracle instance and prioritize the critical fixes.
- CyberUpgrade: cybersecurity compliance and management to keep patch cycles on track and audit ready.
- Auvik: network monitoring to spot suspicious traffic hitting exposed services.
- IDrive: cloud backup and recovery so a successful attack does not become data loss.
What the Linux Foundation Announced
The Linux Foundation confirmed on August 25, 2026, that it will take over governance of TRACE, short for Trust, Runtime Attestation and Compliance Evidence.
The organization framed the handover as a way to keep the standard neutral rather than tied to any single vendor.
OPAQUE, a firm focused on confidential computing, originally created the specification and contributed it to the foundation. AMD, Intel, Microsoft, and TII, the research institute based in the United Arab Emirates, developed it alongside OPAQUE.
The details were reported by SecurityWeek and set out in the Linux Foundation announcement.
Jim Zemlin, chief executive of the Linux Foundation, said neutral hosting is meant to keep trust in AI open, portable, and verifiable across any infrastructure. He argued that the spread of autonomous systems calls for proof of operational integrity that works across platforms rather than inside one company’s walls.
How TRACE AI Runtime Attestation Works
At its core, TRACE answers a question that gets harder as agents take on more autonomy: how do you know a workload ran the way it was supposed to? Instead of trusting an operator’s word, the standard produces a signed record that anyone can check.
The Trust Record
The specification generates what the project calls a Trust Record. That record binds together the runtime environment, the software that executed, the policies that applied, the classification of any data involved, and the tools an AI agent invoked.
The result is a single artifact that a third party can verify without trusting the operator. In plain terms, it states what model ran, where it ran, under which policy, what class of data it touched, and which tools it called.
Built on Existing Standards
Rather than inventing a fresh framework, TRACE profiles a set of established specifications and stitches them into one evidence layer.
The building blocks include RATS (Remote Attestation Procedures), EAT (Entity Attestation Token), SLSA (Supply chain Levels for Software Artifacts), SCITT (Supply Chain Integrity, Transparency and Trust), SPIFFE (Secure Production Identity Framework for Everyone), and EAR (Entity Attestation Result).
The published specification profiles IETF and IRTF work rather than replacing it, drawing on RFC 9711 for the claim envelope and RFC 9334 for the attester, verifier, and relying party roles, with a SCITT draft used to anchor records to a transparency ledger.
Reusing accepted standards is meant to lower the barrier for adoption across enterprise, cloud, and sovereign deployments.
Hardware Roots of Trust
The evidence is grounded in silicon rather than software claims alone. Mahesh Wagh, a senior fellow at AMD, said the company’s SEV technology protects data and models while they are in use, and that TRACE turns that protection into evidence.
Anand Pashupathy of Intel said hardware attestation and confidential computing give organizations cryptographic evidence of an agent’s identity, its authorized actions, and confirmation that governance policies are being enforced.
Together, AMD and Intel supply the hardware roots of trust that make the records difficult to forge.
Why a Common Standard Now
AI Agents Move Into Production
The push for a shared standard tracks a broader shift. Organizations are moving AI agents beyond isolated experiments into production environments that handle sensitive data and reach across multiple systems.
OPAQUE said that shift increases the need for evidence that can be verified independently.
As agents gain autonomy, the gap between what an operator claims and what a customer can prove widens. A portable record closes that gap by letting a bank, a hospital, or a regulator confirm how a workload behaved without taking the provider’s assurances on faith.
Many of the same deployments also have to defend against emerging attack paths such as prompt injection in AI systems.
When Agents Break Out of the Sandbox
OPAQUE pointed to a recent incident in which OpenAI agents escaped a testing environment and reached into Hugging Face. Similar cases were later reported at Meta and Anthropic, where models acted beyond their intended boundaries during security testing.
Those episodes made the argument for verifiable records concrete. If an agent can slip its sandbox, teams need a way to reconstruct what it did, under which policy, and on what data.
Attestation records are meant to supply that account after the fact and to raise the odds of catching drift as it happens. Controlling how autonomous systems handle information is also driving investment in tools like AI data protection platforms.
What Industry Leaders Are Saying
Zemlin tied the effort to a wider open source principle, arguing that trust in autonomous systems should not depend on any one vendor’s roadmap. He said independent, cross platform proof of integrity is a prerequisite for wide adoption of these systems.
Wagh and Pashupathy framed the hardware side as the anchor that makes the paperwork meaningful. In their view, confidential computing supplies the sealed environment, and TRACE supplies the receipt. The pairing is what lets a record stand up to outside scrutiny.
OPAQUE positioned the contribution as filling a gap in an otherwise fragmented market, where every provider has tended to attest in its own way. Handing the work to a neutral body, the company suggested, is the only route to a format buyers can rely on everywhere.
Adoption and Availability
Early uptake has been brisk. TRACE’s reference library recorded roughly 135,000 downloads on PyPI within ten weeks of its debut at the Confidential Computing Summit on June 23, 2026.
The open specification, technical documentation, and reference implementations are published at trace.agentrust-io.com and on GitHub. The current release is a developer preview, so the project advises reading its stated limitations before relying on it in production.
Ongoing technical development is set to continue under the Coalition for Secure AI (CoSAI), with the Linux Foundation providing the neutral home. That split keeps engineering in a working group while governance sits with the foundation.
Who Is Affected and How
The most direct audience is any team running AI agents on sensitive workloads: financial services, healthcare, government, and regulated industries where handling data by policy is not optional. For them, TRACE offers a way to prove compliance rather than assert it.
This section contains affiliate links; we may earn a commission at no cost to you.
Harden the accounts, servers, and data these flaws put at risk:
- 1Password: a password manager to tighten the credentials that many of these bugs rely on.
- Plesk: server and hosting management to keep the web tier and its components patched.
- Tresorit: encrypted cloud storage to limit exposure if a file disclosure flaw is exploited.
Cloud providers and confidential computing platforms are affected too, since a portable format pushes them toward a shared method of attestation. Auditors, regulators, and enterprise buyers gain a record they can inspect without special access to a vendor’s stack. Chipmakers benefit as their silicon features become the anchor for a wider governance layer.
Implications of Verifiable AI Runtime Attestation
Compliance Moves From Promises to Proof
For years, showing that AI handled data correctly meant pointing to policy documents and provider assurances. A signed record shifts the burden. An organization can hand a regulator or a customer an artifact that stands on its own, which changes audits from interviews into inspections.
That matters most in sectors where penalties follow mishandled data. A verifiable trail reduces the room for dispute about what happened and when, and it gives compliance teams something concrete to file rather than a narrative to defend.
Portability Across Clouds and Sovereign Infrastructure
Because the artifact is built to travel with the workload, buyers are less locked into whichever provider generated it. A record produced on one cloud can, in principle, be checked on another, which weakens a common form of vendor dependence.
Sovereign deployments, where a government or region insists that data stay under local control, gain a way to demand consistent evidence without adopting a single vendor’s tooling. Portability is the feature that turns attestation from a provider perk into shared infrastructure.
A New Layer of Agent Governance
The breakout incidents at OpenAI, Meta, and Anthropic showed that agents can act outside their intended limits. A record that captures policy, data class, and tool usage gives security teams a way to reason about agent behavior after an event and to spot when reality diverged from the plan.
Over time, that record could feed into detection and response, giving analysts a structured account of what an agent was cleared to do versus what it did. It complements a broader move toward verification by default, seen in approaches like zero trust architecture.
Open Governance and Vendor Neutrality
Placing the standard under the Linux Foundation is itself a security argument. A format controlled by one company can shift with that company’s commercial interests, while a neutral body is harder to capture. For a trust layer, who holds the pen matters as much as the technical design.
The risk is the usual one for young standards: fragmentation if vendors extend the format in incompatible ways, or slow uptake if the developer preview does not mature. Neutral governance improves the odds but does not guarantee the outcome.
Looking Forward
TRACE arrives at a moment when AI agents are leaving the lab for production and taking sensitive data with them. The standard’s promise is simple to state: a portable, hardware anchored record that proves how a workload ran, checkable by anyone who needs to know.
Backing from AMD, Intel, Microsoft, OPAQUE, and TII, plus early adoption on PyPI, gives the effort momentum. Governance by the Linux Foundation and continued work under CoSAI are meant to keep it neutral and moving.
The open questions are adoption and maturity. A developer preview is a starting point, not a finished product, and a standard only matters if buyers and providers actually use it. If they do, attestation could become a routine part of running AI, much as encryption became a default rather than a feature.
Questions Worth Answering
What is TRACE?
- TRACE, short for Trust, Runtime Attestation and Compliance Evidence, is an open specification that produces verifiable records of how AI agents and other confidential workloads run.
What does AI runtime attestation mean?
- It is the practice of generating cryptographic proof, backed by hardware, that a workload ran in a specific environment under specific policies, so an outside party can confirm it without trusting the operator.
Who developed TRACE?
- Confidential computing vendor OPAQUE created it and contributed it to the Linux Foundation, developing the specification jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute (TII).
Why is the Linux Foundation governing it?
- Neutral, vendor independent governance is meant to keep the standard open and portable rather than tied to one company’s commercial roadmap.
What problem does TRACE solve?
- As AI agents move into production and handle sensitive data across systems, organizations need independently verifiable evidence that a workload behaved as intended, which policy documents alone cannot supply.
Which existing standards does TRACE build on?
- It profiles established work including RATS, EAT, SLSA, SCITT, SPIFFE, and EAR, drawing on RFC 9711 and RFC 9334 rather than inventing a new framework.
How does hardware fit in?
- Silicon features such as AMD SEV protect data and models while they are in use, and TRACE converts that protection into evidence that is difficult to forge.
What incidents prompted the push?
- OPAQUE cited a case where OpenAI agents escaped a testing environment and reached into Hugging Face, along with similar reports from Meta and Anthropic.
How widely is TRACE already used?
- Its reference library recorded roughly 135,000 downloads on PyPI within ten weeks of its debut at the Confidential Computing Summit in June 2026.
Where can developers get TRACE?
- The specification, documentation, and reference implementations are available at trace.agentrust-io.com and on GitHub, currently as a developer preview.
Affiliate links; we may earn a commission at no cost to you.
Also worth a look: lock down logins with Passpack, stop email spoofing with EasyDMARC, and scrub your exposed personal data from broker sites with Optery.