{"slug": "linux-foundation-accepts-opaque-s-trace-standard-for-ai-runtime-evidence", "title": "Linux Foundation accepts OPAQUE's TRACE standard for AI runtime evidence", "summary": "The Linux Foundation accepted OPAQUE's TRACE (Trust, Runtime Attestation and Compliance Evidence) open specification on August 25, aiming to standardize verifiable runtime evidence for AI workloads, with backing from AMD, Intel, Microsoft and the Technology Innovation Institute. TRACE, a developer preview created by OPAQUE chief platform officer Imran Siddique, records which model ran, where, which policy was active, data touched and tools called, and recorded nearly 135,000 PyPI downloads in its first 10 weeks, though governance and core verification work remain unfinished.", "body_md": "# Linux Foundation accepts OPAQUE's TRACE standard for AI runtime evidence\n\n**Imran Siddique's cryptographic receipt format has backing from AMD, Intel and Microsoft, though its governance and core verification work remain unfinished.**\n\nBy [RuntimeWire Staff](/author/runtimewire-staff)\n· Published\n\nPrimary source: [PR Newswire](https://www.prnewswire.com/news-releases/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads-302858923.html)\n\n## Why it matters\n\nOPAQUE is giving away the evidence format while selling the infrastructure that enforces policies and produces the evidence. Linux Foundation governance could turn that strategy into a cross-vendor standard, but TRACE is still a developer preview with unfinished governance and verification work.\n\n[Imran Siddique](https://www.microsoft.com/en-us/research/people/mosiddi/?ref=runtimewire), OPAQUE's chief platform officer, has moved his proposed answer to a difficult AI security question into the Linux Foundation: when an agent touches sensitive data or calls a tool, how can anyone outside its operator verify what actually ran?\n\nThe [Linux Foundation announced on August 25](https://www.linuxfoundation.org/press/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads?ref=runtimewire) that it had accepted TRACE, short for Trust, Runtime Attestation and Compliance Evidence, as an open specification contributed by [OPAQUE](https://www.opaque.co/about?ref=runtimewire). The project was developed with AMD, Intel, Microsoft and the Technology Innovation Institute. The [release published through PR Newswire](https://www.prnewswire.com/news-releases/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads-302858923.html?ref=runtimewire) said the foundation will provide a vendor-neutral home, while technical work will run through the Coalition for Secure AI.\n\nSiddique joined OPAQUE in 2026 after more than 15 years at Microsoft, according to OPAQUE. He previously created Microsoft's Agent Governance Toolkit, an open-source framework for controlling agent identity, permissions and runtime behavior. TRACE extends that work into evidence: a signed record intended to show which model ran, where it ran, which policy was active, what class of data it touched and which tools it called.\n\nOPAQUE is handing the format to a neutral standards organization at a useful moment for its own business. If TRACE becomes a common receipt for agent activity, enterprises will need infrastructure capable of enforcing policies and producing those receipts. OPAQUE is building confidential runtime and governance software aimed at that job.\n\n### A receipt rooted in hardware\n\nThe [TRACE documentation](https://trace.agentrust-io.com/?ref=runtimewire) describes a Trust Record as a portable artifact signed inside a trusted execution environment, or TEE. According to the Linux Foundation, the artifact binds together the runtime environment, software, policies, data classifications and tool usage and is intended to travel across clouds and confidential-computing environments.\n\nThe Linux Foundation says TRACE builds on existing standards, including RATS, EAT, SLSA, SCITT, SPIFFE and EAR, to create a common evidence layer. Its announcement says the open specification, technical documentation and reference implementations are available through the TRACE project site and on [GitHub](https://github.com/agentrust-io/trace-spec?ref=runtimewire).\n\nThat composition reflects Siddique's practical bet. Companies already have security products, cloud attestations and policy engines. A shared evidence format could let those systems exchange records without requiring every cloud, chipmaker or agent framework to accept another vendor's proprietary definition of proof.\n\nThe Linux Foundation said TRACE recorded [nearly 135,000 PyPI downloads in the 10 weeks after its introduction](https://www.prnewswire.com/news-releases/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads-302858923.html?ref=runtimewire) at the Confidential Computing Summit in June. That is a company-reported package count, rather than evidence of production adoption. The [PyPI package](https://pypi.org/project/agentrust-trace/?ref=runtimewire) identifies TRACE as a developer preview.\n\n### The Berkeley team behind the standard\n\nOPAQUE grew from confidential-computing research at UC Berkeley's RISELab. [OPAQUE says](https://www.opaque.co/about?ref=runtimewire) its research team built a system in 2017 for running analytics over data that remained encrypted during computation. Co-founder and CTO Rishabh Poddar helped develop that research. His co-founders include UC Berkeley professor Raluca Ada Popa, Databricks and Anyscale co-founder Ion Stoica, Wenting Zheng and Chester Leung.\n\nAaron Fulkerson joined OPAQUE as CEO in October 2023 to turn that research into an enterprise business. Fulkerson previously co-founded the open-source knowledge software company MindTouch and later led new businesses at ServiceNow. In [his account of joining OPAQUE](https://www.opaque.co/resources/articles/honored-to-join-opaque-systems-as-ceo?ref=runtimewire), he said ServiceNow Impact had signed more than 1,500 customers in under two years.\n\nOPAQUE has capital to pursue the commercial side of the standards push. In February, OPAQUE [announced a $24 million Series B](https://www.opaque.co/resources/articles/opaque-raises-24m-series-b-at-300m-valuation-to-advance-confidential-ai-for-the-enterprise?ref=runtimewire) led by Walden Catalyst, with Intel Capital, Race Capital, Storm Ventures, Thomvest and the Advanced Technology Research Council participating. OPAQUE said the financing brought its total funding to $55.5 million and valued it at about $300 million post-money.\n\n### Neutral governance is still being built\n\nThe Linux Foundation contribution gives TRACE institutional credibility, but the project documents show that the handoff is not complete. The [technical charter](https://trace.agentrust-io.com/CHARTER/?ref=runtimewire) remains a working draft, and its proposed governance, intellectual-property rules and conformance-mark ownership are not final. The charter says external users should not base production systems on those governance commitments before v1.0 ratification.\n\nTRACE's technical claims also have defined boundaries. Its [limitations document](https://trace.agentrust-io.com/LIMITATIONS/?ref=runtimewire) says a record can prove that a particular policy hash was active without proving that the policy was well designed. TRACE does not capture a model's internal reasoning, prevent hardware side-channel attacks or make a software-only Level 0 record trustworthy against a privileged operator.\n\nThe project's [roadmap](https://trace.agentrust-io.com/ROADMAP/?ref=runtimewire) targets a v1.0 standard in 2027 and lists core verification work among its remaining priorities.\n\nThose caveats make the Linux Foundation's role consequential. TRACE needs participation from cloud providers, chipmakers, agent platforms and regulated businesses before it can function as a cross-vendor standard. OPAQUE can write the first format and reference code. It cannot credibly serve as the sole judge of whether competing infrastructure has produced valid evidence.\n\nThe Linux Foundation now has to convert corporate endorsements into an open technical process, while OPAQUE has to show that a standard born inside its product strategy can work across infrastructure it does not control. If that happens, AI governance may gain something enterprise software has repeatedly promised and rarely supplied: a receipt that another party can independently check.", "url": "https://wpnews.pro/news/linux-foundation-accepts-opaque-s-trace-standard-for-ai-runtime-evidence", "canonical_source": "https://runtimewire.com/article/linux-foundation-accepts-opaque-trace-ai-runtime-evidence", "published_at": "2026-08-26 20:20:35+00:00", "updated_at": "2026-08-26 20:49:19.397148+00:00", "lang": "en", "topics": ["ai-policy", "ai-infrastructure", "ai-safety"], "entities": ["Linux Foundation", "OPAQUE", "AMD", "Intel", "Microsoft", "Technology Innovation Institute", "Imran Siddique", "Coalition for Secure AI"], "alternates": {"html": "https://wpnews.pro/news/linux-foundation-accepts-opaque-s-trace-standard-for-ai-runtime-evidence", "markdown": "https://wpnews.pro/news/linux-foundation-accepts-opaque-s-trace-standard-for-ai-runtime-evidence.md", "text": "https://wpnews.pro/news/linux-foundation-accepts-opaque-s-trace-standard-for-ai-runtime-evidence.txt", "jsonld": "https://wpnews.pro/news/linux-foundation-accepts-opaque-s-trace-standard-for-ai-runtime-evidence.jsonld"}}