cybersecurity

Linux Foundation Welcomes TRACE to Bring Verifiable Runtime Evidence to AI Workloads

The Linux Foundation has accepted TRACE, an open specification designed to provide portable, hardware-attested runtime and compliance evidence for AI agents and confidential workloads across clouds and infrastructure.

Xcademia Team

Xcademia Research Team

Aug 26, 20267 min read5 views
Share:
Linux Foundation Welcomes TRACE to Bring Verifiable Runtime Evidence to AI Workloads

Linux Foundation Introduces Vendor-Neutral Governance for TRACE

The Linux Foundation has announced the contribution of TRACE, short for Trust, Runtime Attestation and Compliance Evidence, as an open specification for hardware-attested runtime and compliance evidence.

Developed collaboratively by AMD, Intel, Microsoft, OPAQUE and the Technology Innovation Institute (TII), TRACE is designed to address a growing challenge in enterprise AI: how organisations can independently verify what an AI workload did, which policies were applied and how sensitive data was handled.

The project will operate under Linux Foundation governance, while its technical workstream will be hosted by the Coalition for Secure AI (CoSAI).

The announcement positions TRACE as an evidence layer rather than a completely new security framework.

Why Runtime Evidence Matters for AI Agents

AI agents are increasingly designed to operate with greater autonomy. They can interact with data, use tools, execute tasks and potentially delegate actions to other systems.

That creates a governance challenge.

Traditional security controls can help establish who has access to a system, but organisations may also need evidence about what happened during execution.

TRACE is designed to address this by connecting information about:

  • The runtime environment

  • Software running in the environment

  • Security and governance policies

  • Data classifications

  • Tool usage

  • Agent identity and authority context

The resulting record is intended to be portable and cryptographically verifiable, allowing evidence to travel with a workload across different clouds and confidential computing environments.

This approach is particularly relevant to organisations handling sensitive information where proving compliance can be as important as enforcing a policy.

info-1

TRACE Builds on Existing Industry Standards

According to the Linux Foundation, TRACE is not intended to replace established security frameworks.

Instead, it composes existing standards into a common evidence layer.

The announcement specifically references:

  • RATS

  • EAT

  • SLSA

  • SCITT

  • SPIFFE

  • EAR

The objective is to create a consistent approach for trusted AI execution while maintaining interoperability across enterprise, cloud and sovereign AI infrastructure.

This distinction is important. Rather than creating another isolated security ecosystem, TRACE is positioned as a way to connect established technologies and standards around a common evidence model.

The initial specification focuses on current AI agent architectures, while the Linux Foundation says it is designed to provide a foundation that can evolve towards future multi-agent and confidential computing deployments.

Hardware Attestation Forms a Key Part of the Model

Hardware-based attestation is central to TRACE's approach.

The concept allows systems to provide evidence about the environment in which a workload is executing. TRACE then builds on that foundation to create an evidence record that can be independently verified.

AMD highlighted its SEV confidential computing technology as a hardware foundation for protecting data and models while they are in use.

Intel similarly pointed to hardware-based attestation and confidential computing as mechanisms for establishing evidence around an AI agent's identity, authorisation, execution environment and policy enforcement.

The Linux Foundation announcement does not provide a complete implementation guide for every hardware platform.

Additional details were not disclosed in the announcement.

info-2

Open Governance Is a Central Part of TRACE

The Linux Foundation says vendor-neutral governance is intended to support the long-term sustainability and adoption of TRACE.

That matters because runtime evidence becomes more useful when organisations can verify it independently rather than relying solely on evidence generated and controlled by one technology provider.

OPAQUE's contribution of TRACE to the Linux Foundation is therefore positioned as an effort to give the specification a neutral home where different industry participants can contribute to its development.

The technical work will be hosted by CoSAI, adding an open industry collaboration layer around the project.

For enterprises, this could mean a more standardised approach to evaluating AI workloads that operate across multiple infrastructure environments.

Early Adoption Signals

The Linux Foundation says TRACE recorded nearly 135,000 PyPI downloads within 10 weeks of its initial introduction at the Confidential Computing Summit in June 2026.

This figure was provided in the announcement and represents early interest in the project. It should not, by itself, be interpreted as proof of production adoption or enterprise deployment.

The specification, technical documentation and reference implementations are available through the project's online resources and GitHub repository.

Post-Quantum Protection and Long-Term Evidence

TII also highlighted another issue: evidence needs to remain trustworthy for as long as organisations are required to retain it.

Its contribution to the project includes work around confidential computing, cryptographic protection, post-quantum considerations, identity and authentication.

The broader issue is important for compliance systems. A governance record may need to remain verifiable well beyond the moment when it was originally generated.

TRACE therefore addresses not only the creation of runtime evidence but also the broader question of how that evidence can support independent verification over time.

The announcement does not provide specific technical details about the implementation of post-quantum protection within TRACE.

What TRACE Could Mean for Enterprise AI

The development reflects a broader industry shift toward verifiable AI operations.

As AI systems become more autonomous, organisations may need to demonstrate more than simply whether an agent was authorised to perform an action. They may also need evidence showing the environment in which it operated, the policies applied to it and how it interacted with sensitive information.

TRACE's proposed model brings these elements together into a portable evidence layer.

For enterprises, this could mean a path towards more consistent governance when AI workloads operate across different infrastructure providers.

For cloud and confidential computing environments, interoperability could become increasingly important as organisations avoid locking their AI governance processes to one platform.

For regulators and auditors, independently verifiable evidence could potentially make it easier to assess whether specific controls were applied during workload execution.

These are potential implications of the architecture. The Linux Foundation announcement does not claim that TRACE by itself resolves all AI governance or compliance challenges.

info-3

Why the Linux Foundation's Role Matters

TRACE enters a technology landscape where AI security, confidential computing, identity and compliance standards often exist across separate ecosystems.

The Linux Foundation's role could provide a neutral governance structure for bringing these areas together.

The announcement highlights a broader industry shift toward portable and independently verifiable evidence for AI workloads, rather than relying exclusively on provider-specific security claims or controls.

Whether TRACE becomes a widely adopted industry standard will depend on implementation, interoperability and participation across the ecosystem. The announcement does not provide specific adoption targets or future deployment commitments.

Bottom Line

TRACE is an open specification designed to give organisations a consistent way to create and verify runtime and compliance evidence for AI agents and confidential workloads.

Its approach combines hardware attestation with existing standards covering areas such as identity, software supply chains, evidence and trusted execution.

With the Linux Foundation providing vendor-neutral governance and CoSAI hosting the technical workstream, TRACE aims to create a portable evidence layer that can work across different clouds and infrastructure environments.

As AI agents gain greater access to sensitive data and enterprise tools, the ability to prove what happened during execution is becoming an important part of AI security and governance.

#AI#AIAgents#Cybersecurity#ConfidentialComputing#RuntimeAttestation#AICompliance#LinuxFoundation#TrustedAI

About the Author

X
Xcademia Team
Xcademia Research Team
Share:
Learn to stop attacks like this oneCybersecurity Engineer Bootcamp: live cohorts enrolling now, Career+ support included.