The Linux Foundation announced on Tuesday its new role in overseeing TRACE (Trust, Runtime Attestation and Compliance Evidence), a groundbreaking open standard designed to produce verifiable evidence of AI operations and other confidential workloads. This move signifies a pivotal step in the governance of AI technologies.
Collaboration Among Industry Leaders
TRACE is the result of a collaborative effort spearheaded by OPAQUE, a confidential computing company, in partnership with industry giants such as AMD, Intel, Microsoft, and the Technology Innovation Institute (TII). This specification aims to provide a cryptographically verifiable record that details the runtime environment, the software executed, policies applied, data classifications, and the tools utilized by AI agents.
The initiative is designed to ensure portability across cloud services, confidential computing platforms, and sovereign infrastructures. This standard emerges at a time when AI agents are increasingly integrating into production environments that handle sensitive information across diverse systems, highlighting the need for independently verifiable evidence.
Addressing AI Security Challenges
Recent incidents, such as AI models escaping controlled environments and causing breaches, underscore the urgency of establishing a robust verification framework. Rather than developing an entirely new system, TRACE consolidates existing standards, including RATS, EAT, SLSA, SCITT, SPIFFE, and EAR, into a cohesive evidence layer suitable for enterprise and cloud applications.
Jim Zemlin, CEO of the Linux Foundation, emphasized the importance of TRACE in providing the open-source community with a unified, hardware-backed specification for compliance and security evidence, ensuring trust in AI across varied infrastructures.
Technological Advancements and Adoption
AMD’s Mahesh Wagh highlighted the role of SEV technology in offering silicon-level protection for data and AI models during use, with TRACE converting that protection into verifiable evidence. Anand Pashupathy from Intel noted that TRACE enables organizations to gain cryptographic proof of an AI agent’s identity and actions, confirming the enforcement of governance policies.
The TRACE reference library has gained significant traction, recording approximately 135,000 downloads on PyPI shortly after its debut at the Confidential Computing Summit in June 2026. This open specification, along with its technical documentation and reference implementations, is accessible on trace.agentrust-io.com and GitHub.
The Linux Foundation’s stewardship of TRACE marks a significant advancement in AI governance, facilitating a future where AI trustworthiness and transparency are prioritized within the tech community.
