What happened
On August 25, 2026, OPAQUE contributed TRACE — an open specification for hardware-attested runtime and compliance evidence for AI agents and confidential workloads — to the Linux Foundation, which will provide vendor-neutral governance while the Coalition for Secure AI (CoSAI) hosts the technical workstream. TRACE was collaboratively developed by AMD, Intel, Microsoft, OPAQUE, and the Technology Innovation Institute (TII). Rather than creating a new framework from scratch, TRACE composes six existing standards (RATS/RFC 9334, EAT/RFC 9711, SLSA, SCITT, SPIFFE, EAR) into a common evidence layer that binds the runtime environment, executed software, applied policies, data classifications, and tool usage into a portable, cryptographically verifiable artifact using hardware-based confidential computing (e.g., AMD SEV). The reference implementation recorded ~135,000 PyPI downloads within 10 weeks of its initial June 2026 introduction at the Confidential Computing Summit, and the specification, docs, and reference code are publicly available on GitHub (agentrust-io/trace-spec).
Why it matters
This directly targets a governance gap highlighted by the July 2026 OpenAI/Hugging Face incident: documented policies and sandbox configs don't prove which controls were actually enforced or what an agent did during execution. TRACE gives enterprises, cloud providers, and regulators an independently verifiable, tamper-resistant runtime record for AI agents — portable across clouds and confidential-computing environments. Because it's now under Linux Foundation vendor-neutral governance with CoSAI driving the technical workstream, it has a credible path to broad multi-vendor adoption (AMD, Intel, Microsoft, TII, OPAQUE already participating), positioning it as a de facto interoperability standard for agentic AI runtime attestation and compliance evidence.
Action needed
Security and platform teams deploying agentic AI or confidential-computing workloads should evaluate TRACE's reference implementation and evidence schema, track its evolution under CoSAI/Linux Foundation governance, and consider piloting TRACE-based attestation for high-risk agent deployments (especially those handling sensitive data or requiring regulator-facing compliance evidence).