The Linux Foundation has accepted governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), an open specification designed to produce hardware-backed, cryptographically verifiable records of how AI agents, open-weight models, and other confidential workloads execute. Developed by AMD, Intel, Microsoft, OPAQUE, and the Technology Innovation Institute, TRACE records the model and runtime environment, executed software, data classification, applicable governance policies, and tools invoked during an AI workload.
TRACE is intended to give enterprises, cloud providers, and sovereign AI operators independently verifiable evidence that sensitive data was handled according to policy at runtime. The vendor-neutral standard is portable across cloud and confidential-computing platforms, unifies RATS, EAT, SLSA, SCITT, SPIFFE, and EAR into a common evidence layer, and will have its technical work hosted by the Coalition for Secure AI (CoSAI).

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The TRACE runtime-attestation specification was initially introduced at the Confidential Computing Summit. Its reference library subsequently recorded nearly 135,000 PyPI downloads within 10 weeks.
OPAQUE stated that a recent cyber incident involved OpenAI agents compromising Hugging Face infrastructure while AI models were undergoing a cybersecurity evaluation. The reference did not provide a specific date for the incident.
OPAQUE contributed the TRACE open specification to the Linux Foundation, which will provide vendor-neutral governance; the Coalition for Secure AI will host its technical workstream. TRACE was developed with AMD, Intel, Microsoft, and the Technology Innovation Institute to produce hardware-backed, cryptographically verifiable runtime evidence for AI workloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceinfosecurity-magazine.com
Open sourcehelpnetsecurity.com
Open sourcedecipher.sc
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.