7 views
17 minutes ago

TII joins AMD, Intel and Microsoft on a standard built to prove what an AI agent actually did

The Technology Innovation Institute has signed on as a founding collaborator in TRACE, an open standard that generates portable, hardware-attested evidence of what an AI system ran, which policies were enforced while it ran, and which data classifications it touched.

The Abu Dhabi research body announced its participation on 26 August 2026, alongside AMD, Intel and OPAQUE, with support from Microsoft.

The specification, short for Trust, Runtime Attestation, and Compliance Evidence, has been contributed to the Linux Foundation for vendor-neutral governance, with the technical workstream hosted by the Coalition for Secure AI.

TII, the applied research pillar of Abu Dhabi’s Advanced Technology Research Council, has taken on a role that extends past drafting. It will operate as the reference deployment environment for TRACE, running the standard against live sovereign AI requirements and returning those findings to the specification.

The problem the standard targets has widened as governments and large enterprises move from isolated model deployments to agentic systems that reach across sensitive data stores and call external tools. Running a model on infrastructure an organisation owns settles where computation happened. It leaves open what actually executed once the system reached production, whether the approved model and its policies stayed in force, and how an agent behaved towards the data it was handed.

For sovereign AI programmes in the Gulf, that gap has procurement consequences. National-scale deployment has largely been discussed in terms of domestic data centres and domestically trained models. TRACE adds a third condition: a record that a regulator, an auditor or a partner government can verify without having to trust whoever operates the system.

TII is contributing across three areas of institutional expertise, covering cryptography-based confidential computing, post-quantum cryptography, and identity and authentication. Its teams are engaged in drafting the specification, in protocol design, and in integrating sovereign components aligned to the standard.

The post-quantum element addresses retention. Attestation records generated today may need to survive scrutiny years into the future, by which point the cryptography protecting them could no longer hold.

Dr Najwa Aaraj, Chief Executive Officer at TII, said: “Evidence that cannot be independently verified is not evidence, and evidence that expires when cryptography moves on is not durable. TII is contributing the foundations that address both: confidential computing rooted in cryptography, post-quantum protection so that attestation records remain trustworthy over their full retention period, and the identity and authentication layer that supports verification of which agent acted and the authority context under which it operated.”

Hosting the specification at the Linux Foundation is intended to keep the resulting evidence readable across competing silicon and cloud platforms, a question that matters when AMD and Intel are both at the founding table.

Jim Zemlin, Chief Executive Officer at the Linux Foundation, said: “The widespread adoption of autonomous systems requires independent, cross-platform proof of operational integrity. TRACE provides the open-source community with a unified, hardware-attested specification for compliance and security evidence. By hosting TRACE under neutral governance, we are ensuring trust in AI remains open, portable and verifiable across any infrastructure.”

TRACE was originated by OPAQUE, whose chief executive argues the window for agreeing a shared format is closing while vendors are still willing to converge on one.

Aaron Fulkerson, Chief Executive Officer at OPAQUE, said: “The models and agents we deploy five years from now will be far more powerful than the ones we’re deploying today. We may not always be able to predict how they reason, but we can control what they’re allowed to do and prove what they actually did. TRACE creates a tamper-evident record of what ran, which policies were enforced, what data was involved, and which tools an agent invoked.”

“That proof holds whether you’re running an open-weight model today or a much more capable system tomorrow. The industry needs that evidence to be portable and independently viable before the market hardens around incompatible vendor trust systems.”

TII has said it intends to hold the reference environment role beyond this specification, across technologies where sovereignty and privacy set the governing constraints. For CIOs in Abu Dhabi and Riyadh already writing attestation language into AI tenders, the practical test will be whether TRACE evidence produced on one vendor’s silicon still verifies on another’s.

Leave a Reply

Don't Miss

$915 million for speed: inside Dynatrace’s Arize acquisition

Dynatrace signed a definitive agreement on 13 August to acquire AI observability
Simon Howells, General Manager, GCG Enterprise Solutions

Why AI and ERP investments underperform without clean processes

By Simon Howells, General Manager, GCG Enterprise Solutions The most costly realisation

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy