The Linux Foundation said Tuesday it will take on governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open specification for producing verifiable evidence of how AI agents and other confidential workloads run.
Contributed by confidential computing vendor OPAQUE, the specification was developed jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute (TII).
TRACE creates a hardware-backed, cryptographically verifiable record that ties together the runtime environment, the software executed, the policies applied, the classification of any data involved, and which tools an AI agent invoked.
The resulting artifact is designed to be portable across different cloud providers, confidential computing platforms, and sovereign infrastructure.
The push for a common standard comes as organizations move AI agents beyond isolated experiments into production environments that handle sensitive data and span multiple systems, a shift OPAQUE said increases the need for evidence that can be independently verified.
The company highlighted the recent incident in which OpenAI agents escaped a testing environment and hacked Hugging Face. Similar incidents were also reported by Meta and Anthropic.
Rather than building a new verification framework from scratch, TRACE combines a set of existing, established standards — RATS, EAT, SLSA, SCITT, SPIFFE and EAR — into a single evidence layer intended to work across enterprise, cloud and sovereign AI deployments.
“TRACE provides the open source community with a unified, hardware-attested specification for compliance and security evidence. By hosting TRACE under neutral governance, we are ensuring trust in AI remains open, portable and verifiable across any infrastructure,” said Jim Zemlin, CEO of the Linux Foundation.
AMD senior fellow Mahesh Wagh said the company’s SEV technology provides the silicon-level protection for data and models while they’re in use, with TRACE turning that protection into evidence.
Intel’s Anand Pashupathy noted that hardware-based attestation and confidential computing give organizations cryptographic evidence of an agent’s identity, its authorized actions, and confirmation that governance policies are enforced.
TRACE’s reference library has recorded roughly 135,000 downloads on PyPI within ten weeks of its initial introduction at the Confidential Computing Summit in June 2026. The open specification, technical documentation, and reference implementations are available at trace.agentrust-io.com and on GitHub.
Related: Anthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source Fund
Related: OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
Related: Irregular Details How a Naming Error Let AI Models Attack a Real Company
Related: Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware

