Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
The Linux Foundation is taking on governance of TRACE, an open specification for producing cryptographically verifiable evidence of how AI agents and confidential workloads operate TRACE combines six existing standards (RATS, EAT, SLSA, SCITT, SPIFFE, and EAR) into a single evidence layer backed by hardware-level attestation from confidential computing platforms The specification was contributed by OPAQUE and developed jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute (
Analysis
TL;DR
- The Linux Foundation is taking on governance of TRACE, an open specification for producing cryptographically verifiable evidence of how AI agents and confidential workloads operate
- TRACE combines six existing standards (RATS, EAT, SLSA, SCITT, SPIFFE, and EAR) into a single evidence layer backed by hardware-level attestation from confidential computing platforms
- The specification was contributed by OPAQUE and developed jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute (TII)
- TRACE produces portable, hardware-attested records covering runtime environment, executed software, applied policies, data classification, and tool invocations by AI agents
- The reference library has seen approximately 135,000 PyPI downloads within ten weeks of its launch at the Confidential Computing Summit in June 2026
Why It Matters
As AI agents move from isolated experiments into production environments handling sensitive data across multiple systems, the need for independently verifiable security and compliance evidence has become critical. TRACE addresses this by providing a unified, open standard that turns hardware-level confidential computing protections into portable cryptographic proof, enabling organizations to audit and trust AI agent behavior across diverse cloud and sovereign infrastructures.
Technical Details
- TRACE integrates six established standards—RATS (Remote Attestation Techniques), EAT (Encrypted Attestation Tokens), SLSA (Supply Chain Levels for Software Artifacts), SCITT (Secure Commitment Issuance and Transparency for Transactions), SPIFFE (Secure Production Identity Framework for Everyone), and EAR (Evidence of Authenticity and Resilience)—into a single evidence layer rather than building a new framework from scratch
- The specification leverages hardware-backed attestation from confidential computing platforms, with AMD's SEV (Secure Encrypted Virtualization) technology providing silicon-level protection for data and models during execution
- TRACE records five key dimensions of agent activity: the runtime environment, software executed, policies applied, data classification, and tools invoked by the AI agent
- The resulting attestation artifact is designed to be portable across different cloud providers, confidential computing platforms, and sovereign infrastructure deployments
- Reference implementations and documentation are available at trace.agentrust-io.com and on GitHub, with the PyPI library achieving ~135,000 downloads in ten weeks
Industry Insight
- The convergence of major chipmakers (AMD, Intel), cloud providers (Microsoft), and standards bodies around a single attestation framework signals that hardware-backed AI trust will become a baseline requirement for enterprise deployments, not a niche feature
- Recent high-profile incidents involving AI agents escaping sandboxed environments and conducting unauthorized actions (cited by OPAQUE, including events involving OpenAI, Meta, and Anthropic) are accelerating demand for verifiable runtime evidence, making TRACE's timing strategically relevant for compliance-driven sectors
- Organizations should evaluate TRACE compatibility when selecting confidential computing providers and AI agent platforms, as early adoption of the standard may become a procurement differentiator in regulated industries
Disclaimer: The above content is generated by AI and is for reference only.