The Linux Foundation said Tuesday it will take over management of TRACE (Trust, Runtime Authentication, and Evidence of Conformance), a new open specification for creating verifiable evidence of how AI agents and other confidential workloads work.
Brought to you by proprietary computing vendor OPAQUE, the specification was developed in collaboration with AMD, Intel, Microsoft and the Technology Innovation Institute (TII).
TRACE creates a hardware-backed, cryptographically verifiable record that correlates the execution environment, the software being run, the policies applied, the classification of any data involved, and which tools an AI agent invoked.
The resulting artifact is designed to be portable between different cloud providers, private computing platforms, and sovereign infrastructure.
The push for a common standard comes as organizations move AI agents beyond isolated experiments into production environments that process sensitive data and span multiple systems, a shift OPAQUE says increases the need for evidence that can be independently verified.
The company highlighted the recent incident where OpenAI agents escaped from a testing environment and hacked Hugging Face. Similar incidents were also reported by Meta and Anthropic.
Rather than building a new verification framework from scratch, TRACE combines a set of existing, established standards—RATS, EAT, SLSA, SCITT, SPIFFE, and EAR—into a single evidence layer designed to work across enterprise, cloud, and sovereign AI deployments.
“TRACE provides the open source community with a unified, hardware-authenticated conformance specification and proof of security. By hosting TRACE under neutral governance, we ensure that trust in AI remains open, portable and verifiable across any infrastructure,” said Jim Zemlin, CEO of the Linux Foundation.
AMD Senior Associate Mahesh Wagh said the company’s SEV technology provides silicon-level protection for data and models while in use, with TRACE turning that protection into evidence.
Intel’s Anand Pashupati noted that hardware-based attestation and confidential computing give organizations cryptographic proof of an agent’s identity, its authorized actions, and confirmation that management policies are being enforced.
The TRACE Reference Library has recorded approximately 135,000 downloads of PyPI within ten weeks of its initial presentation at the June 2026 Confidential Computing Summit. The open specification, technical documentation, and reference implementations are available at trace.agentrust-io.com and on GitHub.
Connected: Anthropic expands access to Mythos 5 to more defenders, reveals $35M open source fund
Connected: OpenAI repairs model security with a test environment, 30-minute warnings and training breaks
Connected: Random details how a naming error allows AI models to attack a real company
Connected: Conflicting test goals prompted Claude Agents to deploy self-replicating malware