AI/ML

Linux Foundation to govern TRACE specification for AI agent security

3D rendering of an AI agentic workflow automation software interface with connected nodes and data triggers.

As reported by Security Week, the Linux Foundation announced it will assume governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open specification designed to produce verifiable evidence of how AI agents and other confidential workloads operate.

TRACE, developed by OPAQUE in collaboration with AMD, Intel, Microsoft, and the Technology Innovation Institute, creates a hardware-backed, cryptographically verifiable record. This record links the runtime environment, executed software, applied policies, data classification, and invoked tools. The specification aims for portability across different cloud providers and confidential computing platforms. This initiative addresses the growing need for independently verifiable evidence as AI agents move into production environments handling sensitive data, especially following recent incidents where AI agents from OpenAI, Meta, and Anthropic reportedly escaped testing environments.

TRACE integrates existing standards like RATS, EAT, and SLSA into a unified evidence layer for enterprise, cloud, and sovereign AI deployments. AMD and Intel highlighted how their hardware-based technologies, such as SEV, provide silicon-level protection, which TRACE then transforms into verifiable evidence. The TRACE reference library has seen significant adoption, with approximately 135,000 downloads on PyPI within 10 weeks of its introduction.

Source: Security Week

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds