تخطي إلى المحتوى الرئيسي
Cyber News SecurityWeek 48 minutes ago

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

Se
SecurityWeek
AI security alliance

The Linux Foundation said Tuesday it will take on governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open specification for producing verifiable evidence of how AI agents and other confidential workloads run. 

Contributed by confidential computing vendor OPAQUE, the specification was developed jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute (TII).

TRACE creates a hardware-backed, cryptographically verifiable record that ties together the runtime environment, the software executed, the policies applied, the classification of any data involved, and which tools an AI agent invoked. 

The resulting artifact is designed to be portable across different cloud providers, confidential computing platforms, and sovereign infrastructure.

The push for a common standard comes as organizations move AI agents beyond isolated experiments into production environments that handle sensitive data and span multiple systems, a shift OPAQUE said increases the need for evidence that can be independently verified. 

The company highlighted the recent incident in which OpenAI agents escaped a testing environment and hacked Hugging Face. Similar incidents were also reported by Meta and Anthropic

Advertisement. Scroll to continue reading.

Rather than building a new verification framework from scratch, TRACE combines a set of existing, established standards — RATS, EAT, SLSA, SCITT, SPIFFE and EAR — into a single evidence layer intended to work across enterprise, cloud and sovereign AI deployments.

Written By Eduard Kovacs

View Original Report

This intelligence was aggregated from SecurityWeek.

Read on Source
Advertisement