News

TII Joins TRACE Initiative to Build Open Standard for Verifiable AI

The Technology Innovation Institute (TII), the applied research pillar of Abu Dhabi’s Advanced Technology Research Council (ATRC), has announced its role as a founding collaborator in TRACE (Trust, Runtime Attestation, and Compliance Evidence), an open standard designed to provide portable and verifiable evidence of how AI systems operate.

Developed by AMD, Intel, OPAQUE and TII, with support from Microsoft, TRACE aims to establish a common approach for producing hardware-attested evidence showing what software or AI models ran, which policies were applied and what data classifications were involved.

The specification has been contributed to the Linux Foundation for vendor-neutral governance, while the technical workstream is hosted by the Coalition for Secure AI (CoSAI). The initiative addresses growing concerns around trust and accountability as organisations move from standalone AI models towards agentic systems that can independently interact with enterprise data, applications and tools.

Controlling the infrastructure on which an AI model runs does not necessarily provide proof of what happened after deployment. An organisation may know where its AI computation took place, but still lack independent evidence showing whether the approved model was used, whether security policies remained active or what data an autonomous agent accessed. TRACE is intended to address that gap by creating portable runtime evidence that can be independently verified.

This is particularly relevant to sovereign AI, where governments and organisations require greater control over their data, infrastructure and AI systems. According to TII, sovereignty requires more than operating AI on domestic infrastructure or using locally developed models; it also requires independently verifiable evidence about how those systems operate.

TII’s contribution to TRACE focuses on three areas: cryptography-based confidential computing, post-quantum cryptography, and identity and authentication. The institute is participating in the drafting of the specification and protocol design, while also working on the integration of sovereign components aligned with the standard.

Dr. Najwa Aaraj, Chief Executive Officer, TII, said, “Evidence that cannot be independently verified is not evidence, and evidence that expires when cryptography moves on is not durable. TII is contributing the foundations that address both: confidential computing rooted in cryptography, post-quantum protection so that attestation records remain trustworthy over their full retention period, and the identity and authentication layer that supports verification of which agent acted and the authority context under which it operated.”

TII will also operate TRACE as a reference deployment environment, testing the standard against real-world sovereign AI requirements. Findings from those deployments will then be fed back into the specification. The move to the Linux Foundation is intended to prevent TRACE from becoming tied to a particular vendor or technology ecosystem.

Jim Zemlin, CEO, Linux Foundation, said, “The widespread adoption of autonomous systems requires independent, cross-platform proof of operational integrity. TRACE provides the open-source community with a unified, hardware-attested specification for compliance and security evidence. By hosting TRACE under neutral governance, we are ensuring trust in AI remains open, portable and verifiable across any infrastructure.”

For AI developers and enterprises, portability could become increasingly important as AI systems span different cloud environments, processors, models and software stacks. TRACE was originated by OPAQUE, which says the need for verifiable runtime evidence will increase as AI systems become more autonomous and capable.

Aaron Fulkerson, CEO, OPAQUE, said, “The models and agents we deploy five years from now will be far more powerful than the ones we’re deploying today. We may not always be able to predict how they reason, but we can control what they’re allowed to do and prove what they actually did. TRACE creates a tamper-evident record of what ran, which policies were enforced, what data was involved, and which tools an agent invoked. That proof holds whether you’re running an open-weight model today or a much more capable system tomorrow. The industry needs that evidence to be portable and independently viable before the market hardens around incompatible vendor trust systems.”

The approach is particularly relevant to AI agents, which can perform actions across multiple systems and interact with sensitive information without necessarily following a predictable sequence of operations. By linking runtime evidence to identity, policies and data classifications, TRACE is intended to provide organisations with a way to establish not only where an AI system ran, but also what it did and under what authority.

TRACE is currently available as an open specification, alongside reference implementations and documentation. The initiative is inviting developers, cloud providers, silicon manufacturers and standards organisations to review and contribute to the technical work.

For TII, its participation also extends Abu Dhabi’s growing focus on sovereign AI infrastructure and security, positioning the institute within an international effort to establish common technical foundations for trustworthy and independently verifiable AI systems.

Show More

Chris Fernando

Chris N. Fernando is an experienced media professional with over two decades of journalistic experience. He is the Editor of Arabian Reseller magazine, the authoritative guide to the regional IT industry. Follow him on Twitter (@chris508) and Instagram (@chris2508).

Related Articles

Back to top button