OPAQUE’s Open Source Approach to Verifiable AI Nears Half a Million Downloads as Community Code Contributions Grow More Than Tenfold
OPAQUE’s Open Source Approach to Verifiable AI Nears Half a Million Downloads as Community Code Contributions Grow More Than Tenfold
Three months after AgenTrust’s public launch, outside vendors and projects have contributed 15 integrations and five community maintainers who now share responsibility for its specifications and runtimes
SAN FRANCISCO (September 25, 2026). OPAQUE, the Confidential AI company, today reported that its open source approach to verifiable AI is gaining fast developer adoption, reflecting growing demand for practical AI governance and security. AgenTrust, OPAQUE’s open source initiative for verifiable AI, has recorded close to half a million package downloads since its packages were first published in June. Community developers merged 140 code contributions in September, up from 11 in June, and outside vendors and projects now account for 15 entries in the AgenTrust integration catalog, a 50% increase since September 1.
Adoption is still accelerating. AgenTrust packages were downloaded nearly 144,000 times in the 30 days ending September 23, more than in June and July combined, and agentrust-io.com now draws more than 25,000 unique visitors a month. Across AgenTrust’s 14 public repositories, 95 contributors have had pull requests merged, and five community maintainers have authored 149 merged pull requests between them.
As enterprises give AI agents access to sensitive data and business systems, security and governance teams want evidence they can check for themselves: which agent ran, under what policy, on which hardware, and what it did. Verifiable AI provides that evidence as signed records that any party can inspect, whoever built the system and wherever it runs. AgenTrust publishes the specifications, runtimes and test suites that produce and check those records, so organizations can adopt verifiable AI without depending on a single vendor.
“Every company putting AI agents into production is asking how to prove what those agents did, and the answer can’t be a proprietary black box. In three months developers have downloaded AgenTrust close to half a million times, outside companies have built products and integrations on it, and community members now maintain parts of the code. That is what demand for verifiable AI looks like, and it is why we built it in the open,” said Aaron Fulkerson, CEO of OPAQUE.
What the community is saying
At least ten outside open source projects now declare AgenTrust packages as dependencies, and TRACE’s Python package ranked among the 10,300 most-downloaded of PyPI’s more than 900,000 projects in early September.
“A security team can’t grade what it can’t see. TRACE gives us a signed record of what an agent actually did, and the Agentic Trust Framework turns that record into a judgment about how much autonomy the agent has earned. We ran it live on September 7. When someone changed the grade in the token by hand from Senior to Principal, a resource OPAQUE doesn’t operate refused it,” said Josh Woodruff, Founding Chair, Agentic Trust Framework, CSAI Foundation.
“Banks, energy companies and many regulated enterprises in the Kingdom are asking for AI they can audit against regulatory requirements. With AgenTrust, every agent that connects to our GRC platform produces evidence that auditors and regulators can check for themselves, which gives Saudi enterprises the confidence to bring AI into their governance, risk and compliance programs,” said Faisal Alshinaifi, Founder of Odystra AI.
"Authorization is a decision made on signals. For regulated industries, verifiable evidence of where and how an agent ran is one of the signals that decides whether it gets access at all. AAuth carries that evidence to the policy enforcement point, so a resource can require it before it says yes," said Dick Hardt, creator of AAuth and OAuth 2.0, and founder and CEO of Hellō.
“The registry became checkable the day it started signing checkpoints anyone can verify offline. AgenTrust merging that layer from an outside contributor, and then letting an outside witness stamp it, is demonstration of ‘open’ in action,” said Steven Mih, Founder and CEO, Action State Group.
“A run record is evidence only when someone who does not trust the producer can check it with a verifier the producer did not write. That is why Bernstein publishes TRACE records to the public registry and runs an independent verifier against them. The spec’s rulings are argued in the open and pinned by test vectors, so an outside project can build on it without asking permission,” said Alex Chernysh, creator and maintainer of Bernstein.
“Access is not authority. When agents act across systems that do not share one trust model, authority has to stay bounded and the evidence has to survive the boundary. TRACE makes that runtime evidence inspectable outside the system that produced it, so the other side does not have to take the first system at its word,” said Tymofii Pidlisnyi, author of the Agent Passport System.
The Janssen Project develops community-governed identity and access management infrastructure. The Janssen team has proposed extending the "Lock Server" component to collect signed evidence under the TRACE standard. By linking human authentication events to an agent’s authorization, actions, and the effects of the capability exercised, Lock Server creates a verifiable execution history that helps organizations detect unexpected behavior and prioritize risk management and accountability.
Community developers take on maintenance
In June, 95% of human-authored pull requests merged across AgenTrust came from OPAQUE staff. By September, community developers were merging an average of six changes a day across specifications, runtimes, test suites and integrations. Community members now hold maintainer roles across Agent Manifest, Confidential MCP, Confidential A2A and TRACE, and the maintainer group is growing as repeat contributors take on review responsibility.
“Downloads tell you people are trying it. Merged pull requests and maintainer roles tell you they are staying. In June almost every change came from our team; in September community developers merged 140, and five of them now review and maintain the specifications and runtimes. Publishing the code, the tests and the known limits is what makes that possible, because a contributor can check our work before building on it,” said Imran Siddique, Chief Platform Officer at OPAQUE.
Developers can explore the projects and contribution opportunities at agentrust-io.com and the AgenTrust GitHub organization. The integration catalog links to implementation code, documentation and testing status.
About OPAQUE
OPAQUE develops Confidential AI technology for organizations working with sensitive data and proprietary models. Originating in UC Berkeley’s RISELab, the company combines confidential computing with evidence of runtime policy enforcement to support enterprise AI workloads. Learn more at opaque.co.
Media contact
Inkhouse for OPAQUE
opaquesystems@inkhouse.com
press@opaque.co