The Linux Foundation announced the contribution of TRACE, which stands for Trust, Runtime Attestation and Compliance Evidence, from OPAQUE on August 25, 2026. According to the foundation’s release, the specification creates a standardized, hardware-backed record that documents the runtime environment, applied policies, data classifications and tool usage for AI agents in a portable format. The evidence artifact travels with workloads across different cloud providers, confidential computing platforms and sovereign infrastructure while remaining cryptographically verifiable. TRACE integrates multiple established protocols rather than introducing an entirely new framework.
Founding collaborators on the project include AMD, Intel, Microsoft and OPAQUE, with the Technology Innovation Institute positioned as the anchor for sovereign AI deployments, a joint statement said. TII contributed post-quantum cryptography capabilities to protect attestation records against future decryption threats from quantum computers. Dr. Najwa Aaraj, CEO of TII, said, “Sovereignty in the age of AI is defined by the ability to verify, not trust. Open, transparent standards give organizations and nations the confidence to independently validate how AI systems are governed, while post-quantum cryptography preserves the confidence against the security challenges of the future.” The institute’s participation aligns with broader UAE national strategies for technology leadership.
A corporate filing by Trust Stamp indicated that the sovereign-AI market could exceed 48 billion dollars in 2026, underscoring demand for reliable verification tools as adoption scales. The Linux Foundation reported that TRACE builds on standards including RATS, EAT, SLSA, SCITT, SPIFFE and EAR to form a consistent evidence layer. This composition ensures interoperability without compromising the hardware-enforced protections required for sensitive AI operations, according to the project description.
Jim Zemlin, CEO of the Linux Foundation, said in the announcement, “TRACE provides the open source community with a unified, hardware-attested specification for compliance and security evidence.” He added that neutral governance under the foundation keeps trust in AI open, portable and verifiable across any infrastructure. OPAQUE’s Chief Platform Officer Imran Siddique led development of the specification alongside the company’s CEO and CTO, the release stated.
OPAQUE’s assessment in the announcement highlighted how enterprise AI has shifted from experimental models to autonomous agents handling sensitive data across multiple environments. The company pointed to recent incidents in which AI agents escaped testing environments as examples of governance gaps that standardized evidence can address. TRACE delivers independently auditable proof of execution behavior, policy adherence and data handling that any authorized party can validate, according to the collaborators.
The standard focuses on binding together runtime details, software provenance and compliance evidence into a single artifact that supports both enterprise and national AI programs, the Linux Foundation reported. Microsoft and the hardware providers supplied input on attestation and confidential computing elements while TII emphasized long-term cryptographic resilience for sovereign use cases. This collaborative approach aims to accelerate safe deployment of AI agents without requiring organizations to rely on proprietary verification systems.


