As companies give AI agents greater access to sensitive data, software and business systems, customers need reliable ways to verify what those agents did.
AMD, Intel, Microsoft, OPAQUE and the Technology Innovation Institute introduced TRACE — Trust, Runtime Attestation and Compliance Evidence — at the Confidential Computing Summit in June 2026. The open specification creates a common format for producing verifiable governance records about AI agents and other confidential workloads.
The Linux Foundation has now taken stewardship of TRACE to support vendor-neutral development. For channel partners, the specification could provide a common foundation for building AI governance, confidential computing and compliance services across different vendors’ infrastructure.
“Contributing TRACE to the Linux Foundation gives that work the vendor-neutral home it needs, where the industry can shape a common, interoperable standard and no single company gets to define what counts as proof,” said Imran Siddique, chief platform officer at OPAQUE.
What TRACE brings
TRACE is designed to help organizations verify whether an AI workload operated under specified policies and controls, including when handling data in a regulated environment.
A TRACE implementation can record which model ran, its execution environment, the policies applied, data classifications and tool usage.
TRACE records are designed to be independently verifiable without relying solely on the operator’s claims. Evidence generated through a Trusted Execution Environment can be cryptographically signed, allowing a third party to detect subsequent alterations.
This evidence can verify that a specified workload ran under recorded conditions. It does not prove that the model’s decisions were correct, safe or legally compliant.
How TRACE fits into the security landscape
TRACE builds on existing standards and frameworks, including Supply-chain Levels for Software Artifacts (SLSA), Supply Chain Integrity, Transparency, and Trust (SCITT), and Entity Attestation Token (EAT).
Building on established attestation and supply-chain frameworks could make TRACE easier for cloud providers, security vendors and integrators to incorporate into existing governance and compliance services.
TRACE also has defined limits. According to the project documentation, it does not protect a TEE against side-channel attacks or record a model’s internal chain of thought.
The project documents these boundaries and advises implementers to use TRACE as one layer within a broader security architecture.
It also includes post-quantum security contributed by TII, intended to help its attestation records remain trustworthy as organizations prepare for future quantum threats.
“Evidence that cannot be independently verified is not evidence, and evidence that expires when cryptography moves on is not durable,” said Najwa Aaraj, CEO of TII.
For enterprises and their technology partners, TRACE offers a possible way to produce stronger evidence of how AI workloads operated inside confidential computing environments. Its value will depend on adoption by cloud platforms, AI vendors and compliance tools, but a vendor-neutral specification could help channel partners build governance services that work across multiple technology stacks.





