Linux Foundation to govern TRACE AI runtime attestation

The Linux Foundation will govern TRACE, an open specification that creates hardware-backed cryptographic records of how AI agents and confidential workloads run.

The Linux Foundation will assume governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), an open specification that produces hardware-backed, cryptographic evidence of how AI agents and other confidential workloads run. TRACE was contributed by confidential computing vendor OPAQUE and developed with AMD, Intel, Microsoft and the Technology Innovation Institute. The specification defines a verifiable record linking the runtime environment, the software executed, applied policies, classifications of involved data and which tools an AI agent invoked. The artifact is designed to be portable across cloud providers, confidential computing platforms and sovereign infrastructure. The specification, technical documentation and reference code are available at trace.agentrust-io.com and on GitHub.

Project leaders described TRACE as a response to the expanding use of AI agents in production settings that handle sensitive information and span multiple systems, where organizations require independently verifiable proof of how workloads operated. OPAQUE and partners pointed to incidents in which AI agents left test environments and accessed external systems, including a case that affected Hugging Face and reports involving other major AI developers.

Rather than building a verification framework from scratch, TRACE combines established standards into a single evidence layer. The specification integrates components from RATS, EAT, SLSA, SCITT, SPIFFE and EAR to produce a consistent attestation artifact for enterprise, cloud and sovereign AI deployments. The project publishes technical documentation, a reference library and sample implementations.

The TRACE reference library has recorded about 135,000 downloads on PyPI since it was shown at the Confidential Computing Summit in June 2026. The code and examples are available for developers and operators to inspect and deploy.

Jim Zemlin, chief executive of the Linux Foundation, described TRACE as “a unified, hardware-attested specification for compliance and security evidence.” Mahesh Wagh, an AMD senior fellow, highlighted that SEV technology protects data and models at the silicon level while they run and that TRACE can turn that protection into tamper-evident records. Anand Pashupathy of Intel noted that hardware-based attestation and confidential computing provide cryptographic proof of an agent’s identity, the authorized actions it performed and confirmation that governance policies were enforced.

TRACE provides a method for enterprises and cloud operators to collect and verify runtime evidence by tying together environment details, code provenance, applied policies and data labels into a single signed artifact, which can be used in compliance checks and operational investigations across diverse infrastructure setups.

Articles by this author