Open specifications for verifiable AI

Prove what your AI ran, and what it did.

When an AI system acts, most of what you can see afterwards is its own logs, and the system can edit those. AgenTrust is a set of free, open specifications and tools that produce a signed receipt instead: which model ran, which agent acted, and each step it took. On supported hardware the processor itself vouches for where the work ran. Anyone can check a receipt on their own computer, without asking us.

/verify › keybind_quote.binoffline · in this browser
  1. reportSigned report from an Intel TDX processor on Google Cloud, captured 2026-09-14
  2. step 1The processor's attestation key signed the reportnot run
  3. step 2Intel's quoting enclave vouches for that keynot run
  4. step 3That vouching is signed by the chip's own Intel certificate (PCK)not run
  5. step 4The certificate chain ends at Intel's root certificatenot run
  6. linkThe report names the key that signed a published TRACE receiptnot run
  7. verdictA genuine Intel processor produced this reportnot run

NoteThis box checks a real processor report while you watch. A genuine Intel TDX processor signed it, and the report names the key that signed the TRACE receipt published beside it. It does not show which software was running inside.

Runs in your browser. Nothing is sent back to us.

Logs are written by the system you are trying to check.

Agents can edit the record of what they did.

An independent evaluator's incident report (METR, 26 August 2026) found roughly 7% of the agent transcripts it reviewed had been successfully spoofed, and could not rule out agents deleting logs after the fact.

Read the incident report ↗

The tooling around agents is the attack surface.

In June 2026 an add-on for a popular coding agent, downloaded about 29,000 times a week, shipped code that quietly copied users' long-lived login tokens to an attacker.

Models are leaving the building.

A model's weights are the trained file that is the model. Running a model in a customer's or a government's own data centre puts that file on hardware somebody else owns. Weight-security research recommends confidential computing for the highest protection levels, and today's chips can still be broken by someone with physical access to the machine.

Read the weight-security research ↗

Four questions, each with evidence a stranger can check.

01 · WEIGHTS Is this the model that was released, and who may release its key?

Weight Custody Manifest: a signed record of exactly which model file this is, and the rules for who may release the key that decrypts it.

Spec pre-1.0, SDK 0.30.0, 97 portable conformance vectors
02 · AGENT What is this agent, and what is it allowed to do?

Agent Manifest: a signed ID card for an agent, listing what it is and what it may touch.

SDK 0.15.0, proposed to CoSAI WS4 (RFC #149)
03 · ACTIONS Was each action the agent took, and each job it handed to another agent, checked against the rules?

cMCP checks every tool an agent uses, such as sending an email or querying a database. cA2A does the same when one agent hands work to another.

cmcp-runtime 0.7.0; ca2a-runtime 0.4.0 developer preview
04 · EVIDENCE Can someone else check all of it, offline, years later?

TRACE is the receipt format. The TRACE Registry is a public log of receipts with signed checkpoints, and the conformance suite tests that a tool reads them correctly.

TRACE spec v0.2, a Series of LF Projects with an AAIF Sandbox proposal open, agentrust-trace 0.11.0, signed registry checkpoints with an external witness receipt

Each step links to its own project site. No step needs the others, so start with the one that answers your question.


The words on this site, in one line each.

AI agent
An AI system that takes actions on its own, such as reading files or sending messages, instead of only answering questions.
Tool call
One action an agent takes through another piece of software. MCP (Model Context Protocol) is a common way agents connect to those tools.
Delegation
One agent handing part of a job to another agent. A2A (Agent2Agent) is a common protocol for it.
Confidential computing
Chips that keep a program's memory encrypted while it runs, so even the server's owner cannot read it. Intel TDX, AMD SEV-SNP and NVIDIA H100 are three kinds. The protected area is called a trusted execution environment (TEE).
Attestation
A report signed by the chip itself about what it is and what is loaded on it. The signature traces back to the chip maker, not the cloud provider.
Signed receipt
A record with a digital signature attached. If anyone changes a single character, the signature check fails. TRACE is the receipt format used here.
Verify offline
Check a receipt on your own computer, with no call to us or to any service that could change the answer.

Tested on real confidential-computing chips, checked back to the chip maker.

We check that each signature traces back to the chip maker. We do not judge whether a chip's firmware has its latest security updates.


What this proves, and what it does not.


Start with the part you are responsible for.


Anyone can read it, run it and check it.

TRACE, the receipt format, is hosted at the Linux Foundation as its own project (a Series of LF Projects), announced on 25 August 2026 and developed with AMD, Intel, Microsoft, OPAQUE and TII. It has also been proposed to the Agentic AI Foundation as an early-stage Sandbox project (aaif/project-proposals #42, opened 14 September 2026).

The Linux Foundation AMD Intel Microsoft Technology Innovation Institute OPAQUE
Read the Linux Foundation announcement ↗
OPAQUE
Sponsor

Sponsored by OPAQUE, which funds the engineering, infrastructure and confidential-computing work behind these projects. Organisations that want to support open, verifiable AI infrastructure are welcome to join as sponsors.

Talk to us about sponsoring →
Every project is open source. Licences vary by project and are listed on each site.
10 project repositories hold an OpenSSF Best Practices passing badge, an independent checklist for how open source projects are run.
The software rule-checking builds on the Microsoft Agent Governance Toolkit.