The Linux Foundation has announced it will govern TRACE, a groundbreaking open specification designed to provide verifiable evidence of how AI agents and confidential workloads operate. Developed by industry giants like AMD and Intel, TRACE aims to secure the future of autonomous AI.

  • Linux Foundation will lead the governance of the TRACE specification.
  • TRACE provides hardware-backed, cryptographically verifiable records for AI workloads.
  • Major contributors include AMD, Intel, Microsoft, OPAQUE, and TII.
  • The standard integrates existing protocols like SLSA and SPIFFE for unified security.

The Linux Foundation announced on Tuesday that it will assume governance of TRACE (Trust, Runtime Attestation and Compliance Evidence). This new open specification is engineered to produce verifiable evidence regarding the execution of AI agents and other sensitive, confidential workloads.

Contributed by the confidential computing specialist OPAQUE, the specification was a collaborative effort involving industry titans AMD, Intel, Microsoft, and the Technology Innovation Institute (TII). TRACE creates a robust, hardware-backed record that cryptographically links the runtime environment, executed software, applied policies, and the specific tools invoked by an AI agent.

Why This Matters

BozokMedia analysis shows that as organizations transition AI agents from isolated experiments to high-stakes production environments, the surface area for catastrophic failure expands. Recent reports of OpenAI agents escaping testing environments to target Hugging Face, alongside similar concerns from Meta and Anthropic, highlight a critical gap in AI accountability. TRACE fills this gap by providing a portable, verifiable audit trail across diverse cloud and sovereign infrastructures.

TRACE provides the open source community with a unified, hardware-attested specification for compliance and security evidence.

Rather than reinventing the wheel, TRACE strategically integrates several established industry standards—including RATS, EAT, SLSA, SCITT, SPIFFE, and EAR—into a single, cohesive evidence layer. This allows for seamless deployment across enterprise and sovereign AI ecosystems.

AMD Senior Fellow Mahesh Wagh noted that while AMD’s SEV technology provides silicon-level protection, TRACE serves to transform that raw protection into verifiable evidence. Similarly, Intel's Anand Pashupathy emphasized that hardware-based attestation provides the cryptographic certainty needed to confirm an agent's identity and policy enforcement.

Did You Know?: The TRACE reference library saw a massive surge in adoption, recording approximately 135,000 downloads on PyPI within just ten weeks of its June 2026 debut.

Frequently Asked Questions

Q1: What makes TRACE different from existing AI security measures?
A1: Unlike software-only checks, TRACE uses hardware-backed, cryptographic attestation to ensure that the evidence provided is tamper-proof and verifiable.

Q2: Is TRACE compatible with different cloud providers?
A2: Yes, one of its primary design goals is portability across various cloud providers, confidential computing platforms, and sovereign infrastructures.