
Proving that an AI agent actually did what it claimed, on the hardware it claimed to use, has become one of the trickiest problems in enterprise computing. The Linux Foundation is stepping in to solve it, announcing it will govern TRACE, an open specification for AI runtime attestation that turns hardware-level proof into a verifiable receipt for AI workloads. The move signals that trust in AI systems is shifting from marketing promises to something you can actually check with cryptography.
Key takeaways
- The Linux Foundation now governs TRACE, an open standard for AI runtime attestation that generates hardware-backed, cryptographically verifiable proof of AI workload execution.
- TRACE stands for Trust, Runtime Attestation and Compliance Evidence, and it was originally built by OPAQUE alongside AMD, Intel, Microsoft, and the Technology Innovation Institute.
- The standard relies on silicon-level hardware attestation from AMD SEV and Intel TDX to produce what the project calls Trust Records.
- In the roughly ten weeks after its June 23, 2026 debut, TRACE’s reference implementation was downloaded about 135,000 times on PyPI.
- Ongoing technical development will continue under the Coalition for Secure AI (CoSAI), with Linux Foundation CEO Jim Zemlin stressing the need for neutral oversight.
Linux Foundation Takes Over Governance of the TRACE Standard for AI Runtime Attestation
TRACE gives organizations a standardized way to answer a question that has become harder to ignore as AI agents take on more autonomous, sensitive tasks: how do you know a workload actually ran the way it was supposed to? The acronym stands for Trust, Runtime Attestation and Compliance Evidence, and the specification generates hardware-attested, cryptographically verifiable records of AI agent and confidential workload execution. It works something like a tamper-proof receipt for every AI operation, one a third party can check without simply trusting the operator’s word.
The specification wasn’t built inside the Linux Foundation from scratch. It was originally developed by OPAQUE, a confidential computing firm, working in collaboration with AMD, Intel, Microsoft, and the Technology Innovation Institute. That consortium brought together the pieces needed to make attestation practical at scale: AMD and Intel supplying the hardware roots of trust, Microsoft contributing its Azure confidential computing stack, and TII, based in the UAE, adding further technical input. Handing governance to the Linux Foundation is meant to keep the standard neutral rather than tied to any single vendor’s roadmap.
How TRACE Verifies AI Workloads Through Hardware Attestation
TRACE’s core function is producing records that prove an AI workload ran as promised, and it does this by anchoring verification in silicon rather than software claims alone. Instead of inventing an entirely new trust framework, the specification integrates a set of already-established standards, including RATS, EAT, SLSA, SCITT, SPIFFE, and EAR, to keep it interoperable across different cloud platforms and secure computing environments. That interoperability matters because most large organizations run workloads across multiple providers, and a standard that only worked on one platform would defeat the purpose.
Trust Records and Cryptographic Verification
The output of all this is what the project calls Trust Records. These documents capture operational details such as l’ambiente di esecuzione, il software che è stato lanciato, le classificazioni dei dati e le normative applicate during a given AI operation. Every one of those details is secured by silicon attestation mechanisms, meaning the proof is rooted in hardware rather than resting on an operator’s assurances. In practice, TRACE leverages hardware attestation technologies like AMD SEV and Intel TDX, giving those existing confidential computing capabilities a standardized language specifically for AI workloads.
Early Adoption and the Road Ahead Under CoSAI
Adoption numbers suggest developers didn’t wait long to start testing TRACE. The specification was first presented publicly at the Confidential Computing Summit on June 23, 2026, and in the roughly ten weeks that followed, its reference implementation was downloaded approximately 135,000 times on PyPI, the Python package repository. That kind of early uptake, before formal governance was even finalized, points to real demand for a standardized way to verify AI runtime behavior rather than a purely theoretical exercise.
Neutral Governance Takes Center Stage
Jim Zemlin, CEO of the Linux Foundation, emphasized the importance of neutral governance for producing AI trust records that organizations across industries can actually rely on. Going forward, ongoing technical development of TRACE will continue under the Coalition for Secure AI, known as CoSAI, which will steer the specification’s evolution rather than leaving it in the hands of any one founding company. This matters for adoption: standards that stay locked to a single vendor’s incentives tend to struggle for broad industry buy-in, while foundation-governed specifications, like other Linux Foundation projects, have a track record of becoming shared infrastructure across competitors.
The Trust Problem TRACE Aims to Solve
As organizations deploy increasingly autonomous AI agents to handle sensitive workloads across infrastructure they don’t fully control, a fundamental trust gap opens up. A regulated bank needs to confermare che il suo modello di intelligenza artificiale sia stato eseguito all’interno di un’enclave protetta presso uno specifico fornitore di servizi cloud. A healthcare company has to prove to auditors that patient data was processed according to policy. Any organization running workloads on someone else’s hardware eventually has to demonstrate compliance without simply asking auditors to take its word for it.
TRACE flips that model. Because the attestation originates from the hardware itself rather than from the operator’s own logs, i Registri di Fiducia risultanti possono essere convalidati da qualsiasi soggetto terzo che disponga dell’accesso alle specifiche. That’s the key distinction from most existing compliance documentation: the cryptographic verification confirms how a workload ran without requiring the verifier to see what data it actually processed, which matters in regulated sectors where privacy and auditability often pull in opposite directions.
Whether TRACE becomes the default language for AI runtime attestation across cloud providers will likely depend on how quickly major platforms beyond the founding consortium choose to support it. With CoSAI now steering the technical roadmap and the Linux Foundation holding governance, the standard has cleared its first hurdle, but broad, cross-industry adoption is the test that’s still ahead.
FAQ
What is TRACE and why is it important?
TRACE is an open AI runtime attestation standard that produces cryptographically verifiable records proving AI workloads ran as promised, with the proof rooted in hardware attestation rather than software claims.
Who governs the TRACE standard?
The Linux Foundation governs TRACE, providing neutral oversight intended to support the creation of verifiable AI trust records across the industry.
Which technologies back the hardware attestation in TRACE?
TRACE leverages AMD SEV and Intel TDX hardware attestation technologies to secure the Trust Records it generates.
How does TRACE improve trust in AI workload execution?
TRACE generates Trust Records secured by silicon attestation, letting third parties cryptographically verify how an AI workload executed without needing to trust the operator’s word or expose the underlying data.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

1 hour ago
16









English (US) ·