When an AI system acts, most of what you can see afterwards is its own logs, and the system can edit those. AgenTrust is a set of free, open specifications and tools that produce a signed receipt instead: which model ran, which agent acted, and each step it took. On supported hardware the processor itself vouches for where the work ran. Anyone can check a receipt on their own computer, without asking us.
/verify › keybind_quote.binoffline · in this browser
reportSigned report from an Intel TDX processor on Google Cloud, captured 2026-09-14
step 1The processor's attestation key signed the reportnot run
step 2Intel's quoting enclave vouches for that keynot run
step 3That vouching is signed by the chip's own Intel certificate (PCK)not run
step 4The certificate chain ends at Intel's root certificatenot run
linkThe report names the key that signed a published TRACE receiptnot run
verdictA genuine Intel processor produced this reportnot run
NoteThis box checks a real processor report while you watch. A genuine Intel TDX processor signed it, and the report names the key that signed the TRACE receipt published beside it. It does not show which software was running inside.
Runs in your browser. Nothing is sent back to us.
Why now
Logs are written by the system you are trying to check.
Agents can edit the record of what they did.
An independent evaluator's incident report (METR, 26 August 2026) found roughly 7% of the agent transcripts it reviewed had been successfully spoofed, and could not rule out agents deleting logs after the fact.
In June 2026 an add-on for a popular coding agent, downloaded about 29,000 times a week, shipped code that quietly copied users' long-lived login tokens to an attacker.
Models are leaving the building.
A model's weights are the trained file that is the model. Running a model in a customer's or a government's own data centre puts that file on hardware somebody else owns. Weight-security research recommends confidential computing for the highest protection levels, and today's chips can still be broken by someone with physical access to the machine.
04 · EVIDENCECan someone else check all of it, offline, years later?
TRACE is the receipt format. The TRACE Registry is a public log of receipts with signed checkpoints, and the conformance suite tests that a tool reads them correctly.
TRACE spec v0.2, a Series of LF Projects with an AAIF Sandbox proposal open, agentrust-trace 0.11.0, signed registry checkpoints with an external witness receipt
Each step links to its own project site. No step needs the others, so start with the one that answers your question.
In plain English
The words on this site, in one line each.
AI agent
An AI system that takes actions on its own, such as reading files or sending messages, instead of only answering questions.
Tool call
One action an agent takes through another piece of software. MCP (Model Context Protocol) is a common way agents connect to those tools.
Delegation
One agent handing part of a job to another agent. A2A (Agent2Agent) is a common protocol for it.
Confidential computing
Chips that keep a program's memory encrypted while it runs, so even the server's owner cannot read it. Intel TDX, AMD SEV-SNP and NVIDIA H100 are three kinds. The protected area is called a trusted execution environment (TEE).
Attestation
A report signed by the chip itself about what it is and what is loaded on it. The signature traces back to the chip maker, not the cloud provider.
Signed receipt
A record with a digital signature attached. If anyone changes a single character, the signature check fails. TRACE is the receipt format used here.
Verify offline
Check a receipt on your own computer, with no call to us or to any service that could change the answer.
Where it runs
Tested on real confidential-computing chips, checked back to the chip maker.
AMD SEV-SNP
On a Microsoft Azure confidential virtual machine. The processor's reports check out against AMD's root certificate.
We check that each signature traces back to the chip maker. We do not judge whether a chip's firmware has its latest security updates.
Scope
What this proves, and what it does not.
A signature proves who signed a receipt and that nobody changed it since. On its own, it does not prove where the signer was running.
Proving that a receipt came from protected hardware needs a checked processor report (attestation) that names the key that signed it.
Someone who physically owns the machine can break today's confidential-computing chips by tapping the memory wires (published attacks include TEE.fail and BadRAM). Weight custody is designed with that limit in mind.
The quick start pages and demos run in software mode: the receipts are real, but no chip vouches for them.
The conformance tests are self-tests. Passing them is not a certification.
An entry in the registry shows a receipt was published. It does not show that what the receipt says is true.
Who it is for
Start with the part you are responsible for.
Model builders
Who run their model on a customer's or a government's own hardware and need to stay in control of it.
TRACE, the receipt format, is hosted at the Linux Foundation as its own project (a Series of LF Projects), announced on 25 August 2026 and developed with AMD, Intel, Microsoft, OPAQUE and TII. It has also been proposed to the Agentic AI Foundation as an early-stage Sandbox project (aaif/project-proposals #42, opened 14 September 2026).
Sponsored by OPAQUE, which funds the engineering, infrastructure and confidential-computing work behind these projects. Organisations that want to support open, verifiable AI infrastructure are welcome to join as sponsors.