An AI agent approves an action, queries a database and calls another tool. Six months later, an auditor asks a basic question: what actually ran?
Abu Dhabi’s Technology Innovation Institute is helping build TRACE, an open specification intended to produce hardware-attested evidence of AI runtime, policy and data conditions. TII is a founding collaborator with AMD, Intel and OPAQUE, while Microsoft supports the initiative and the Linux Foundation now hosts it under vendor-neutral governance.
As AI agents gain permission to touch sensitive data and tools, organizations need evidence of what actually ran, not only policies describing what should have happened.
UAE government teams, banks, critical-infrastructure operators, cloud buyers, AI platform teams, auditors, regulators, and enterprises deploying autonomous agents.
A common evidence format could make AI governance more portable across sovereign, enterprise and cloud environments instead of trapping proof inside one vendor’s logs.
TRACE is still an early specification; hardware attestation can prove aspects of execution, but it does not prove that a model’s reasoning or output was correct.
The meaningful milestone is production adoption: stable specifications, conformance tooling, real deployments, and evidence that auditors or regulators can use across vendors.
Ask AI vendors how they prove which model, policy, data boundary and tool permissions were active when an agent took an action.
Organizations that need portable proof of runtime identity, policy enforcement, data classification and tool use across different infrastructure providers.
TRACE is an open specification with public technical documentation and reference implementations for developers, infrastructure vendors and standards contributors.
Watch specification maturity, production references, cross-cloud interoperability, post-quantum protections, regulator interest, and whether major AI platforms expose TRACE-compatible evidence.
The idea is powerful because AI governance is moving beyond model cards and written policies. But TRACE is still an emerging standard, not a finished guarantee of trustworthy AI.
The Problem Starts After the Agent Gets Permission
An AI agent can be authorized to query a database, call an external tool and move information between systems. Months later, an auditor may need to answer a simple question: what actually ran when that action happened?
That is a harder problem than writing a policy. Robius has already documented how AI agents can cross boundaries that look obvious to humans. Once systems can act, governance needs evidence tied to the execution itself.
TRACE is designed for that layer. The Linux Foundation describes it as an open specification for hardware-attested runtime and compliance evidence for AI agents and confidential workloads.
What TRACE Actually Tries to Prove
The specification is intended to bind several facts into one portable, cryptographically verifiable record: the runtime environment, software, active policies, data classifications and tool usage. TII describes the goal more simply as evidence of what ran, under which policies and which data classifications were involved.
That is different from a normal application log. A log is useful, but the system that created it may also control the evidence. Hardware attestation is meant to anchor part of the record below the application layer so another party can verify the execution environment.
TRACE also builds on existing security and identity standards rather than trying to replace every layer of enterprise security. The Linux Foundation names RATS, EAT, SLSA, SCITT, SPIFFE and EAR among the foundations it composes.
Why Abu Dhabi’s Role Matters
TII says it is a founding collaborator alongside AMD, Intel and OPAQUE, with Microsoft supporting the work. The specification has been contributed to the Linux Foundation for vendor-neutral governance.
TII is also positioning itself as a reference environment for sovereign AI deployment. That connects directly with a question Robius has raised before: sovereign AI is not the same as manufacturing every component at home. Control can also come from verifiable execution, local policy and independently checkable evidence.
TII says its contribution includes expertise in confidential computing, post-quantum cryptography, identity and authentication. Those are useful building blocks if a trust record needs to remain verifiable long after the original workload ran.
The Standard Is Not Finished
This is where the announcement needs restraint. An open specification is not the same as a production standard used across the AI industry. TRACE still has to prove interoperability, durability and operational usefulness outside its founding group.
The Linux Foundation says TRACE recorded nearly 135,000 PyPI downloads within ten weeks of its initial introduction. That is a signal of developer attention, not proof of production adoption or regulatory acceptance.
The same caution applies to all AI control layers. Our analysis of AI sandbox failures made the same distinction: a control is meaningful only when the architecture and enforcement actually hold under pressure.
A Receipt Does Not Prove the Decision Was Good
Runtime evidence can help establish which software ran, which policies were active and which tools or data classes were involved. It cannot by itself prove that the model made a correct decision, interpreted a rule correctly or produced a safe outcome.
That boundary matters. A cryptographically verified mistake is still a mistake. TRACE is best understood as an evidence layer for governance and audit, not a substitute for model evaluation, authorization design, human oversight or incident response.
That becomes even more important at scale, where thousands of interacting agents create a different control problem than a single assistant.
The Robius Layer
The agentic AI conversation has focused on capability: what agents can automate, how many tools they can use and how much work they can complete. TRACE points at the less glamorous requirement that follows capability into real systems: proof.
If AI is going to act inside government, finance and critical enterprise workflows, “trust us” will not be enough. The useful standard will be the one that lets another party verify what happened without depending entirely on the vendor that ran the system. TRACE is an early attempt to make that evidence portable.
Sources
- Technology Innovation Institute: TII’s 26 August 2026 announcement of its founding role in TRACE and sovereign-AI reference environment – https://www.tii.ae/news/tii-announces-its-founding-role-trace-open-standard-verifiable-ai-contributing-cryptography
- Linux Foundation: 25 August 2026 contribution of TRACE, runtime-evidence scope, founding collaborators, underlying standards and download figure – https://www.linuxfoundation.org/press/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads?hs_amp=true
- TRACE: Public technical documentation and reference material for the open specification – https://trace.agentrust-io.com/
Robius.news — Dubai, UAE — 2026 | Built to be first. Built to be trusted.



