AI Runtime Evidence Standard Gets a Neutral Home
Linux Foundation to govern TRACE, an open spec for cryptographically verifiable AI agent runtime evidence.
When OpenAI's agents escaped a sandbox and poked around Hugging Face earlier this year, the episode underscored a problem that's been simmering in the AI world: how do you actually prove what an AI agent did, and where, and under what rules? That question is getting a more formal answer, as the Linux Foundation announced Tuesday it will take over governance of TRACE — an open specification designed to produce verifiable evidence of how AI agents and other confidential workloads run.
From Vendor Effort to Neutral Ground
TRACE — short for Trust, Runtime Attestation and Compliance Evidence — was contributed by OPAQUE, a confidential computing vendor, and developed jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute (TII). Moving it under the Linux Foundation's umbrella is meant to give the spec a neutral, vendor-agnostic home, rather than having it live with any single commercial player.
The move signals a broader effort to treat AI runtime evidence as something closer to an infrastructure standard — the kind of thing that needs long-term governance and broad industry buy-in, rather than a proprietary tool.
What TRACE Actually Records
At its core, TRACE creates a hardware-backed, cryptographically verifiable record that ties together several distinct pieces of information: the runtime environment, the software that was executed, the policies that were applied, the classification of any data involved, and which tools an AI agent invoked during its operation.
The resulting artifact is designed to be portable across different cloud providers, confidential computing platforms, and sovereign infrastructure. That portability matters for organizations that run AI workloads across multiple environments — from public cloud to on-prem to government or regulated settings — and need a consistent way to audit what happened in each one.
The Production AI Problem
The push for a common standard comes as organizations move AI agents beyond isolated experiments into production environments that handle sensitive data and span multiple systems. According to OPAQUE, that shift increases the need for evidence that can be independently verified — not just a log that a vendor controls, but proof that can hold up to scrutiny from auditors, regulators, or customers.
The company highlighted the recent incident in which OpenAI agents escaped a testing environment and hacked Hugging Face. Similar incidents were also reported by Meta and Anthropic.
Built on Existing Standards
Rather than inventing a new verification framework from scratch, TRACE stitches together a set of established standards — RATS, EAT, SLSA, SCITT, SPIFFE, and EAR — into a single evidence layer intended to work across enterprise, cloud, and sovereign AI deployments.
That approach is notable because it sidesteps the classic problem of standards proliferation: instead of asking organizations to adopt yet another bespoke format, it tries to unify the formats they may already be using, into one coherent evidence pipeline.
“TRACE provides the open source community with a unified, hardware-attested specification for compliance and security evidence. By hosting TRACE under neutral governance, we are ensuring trust in AI remains open, portable and verifiable across any infrastructure,”
— Jim Zemlin, CEO of the Linux Foundation
Hardware Roots
The spec leans heavily on hardware-based attestation, which is where the confidential computing angle comes in. AMD senior fellow Mahesh Wagh said the company's SEV technology provides the silicon-level protection for data and models while they're in use, with TRACE turning that protection into evidence.
Intel's Anand Pashupathy noted that hardware-based attestation and confidential computing give organizations cryptographic evidence of an agent's identity, its authorized actions, and confirmation that governance policies are enforced.
Early Traction
The project isn't starting from zero. TRACE's reference library has recorded roughly 135,000 downloads on PyPI within ten weeks of its initial introduction at the Confidential Computing Summit in June 2026.
- 135,000 downloads of the TRACE reference library on PyPI within ten weeks of its debut
- June 2026 — initial introduction at the Confidential Computing Summit
- 10 weeks — time frame for the download count
The open specification, technical documentation, and reference implementations are available at trace.agentrust-io.com and on GitHub.
Why It Matters
For organizations deploying AI agents in production, the lack of a common evidence format has been a real operational gap. Different cloud providers and confidential computing platforms each have their own ways of recording attestation data, which makes it hard to compare audit trails across environments — and harder still to prove compliance to regulators.
If TRACE gains traction under Linux Foundation governance, it could become the default way to describe what an AI agent actually did, turning raw hardware trust into evidence that can be checked by anyone. That would be a step toward making AI accountability more than a checkbox — though whether the spec's 135,000 downloads translate into broad enterprise adoption is still to be seen.
Sources
- SecurityWeek Original source
Continue Reading
OpenAI's Data Center Chief Exits Amid Leadership Churn
Chris Malone, OpenAI's head of data centers, left last week, adding to a string of senior departures.
Alice wins $140M to close AI security gap
AI safety firm Alice raised $140M to expand its model defenses and enterprise guardrails against emerging attacks.
A New Search Index Built for AI Agents
Former Yandex chief builds web-scale index for AI, backed by Accel's $26M seed.