THE LINUX FOUNDATION PROJECTS

Welcome to the August 2026 Newsletter

By September 2, 2026No Comments7 min read

TL;DR | What’s in This Issue?

  • EU Cyber Resilience Act Readiness: ED Mike Bursell details incoming EU CRA reporting rules and requests members disclose if CCC open-source projects are used commercially to assist with LF Stewardship.
  • Securing Agentic AI & AI Identity: Outreach highlights AI Identity as the top security topic for agentic AI, positioning Confidential Computing with attestation as the target enterprise solution.
  • TAC Updates & AI Agent Guidance: The TAC showcases multi-vendor attestation progress via The Certifier Framework and opens contributions for new draft guidance on securing AI Agents.
  • Industry Milestones & News: Google DeepMind pilots double-blind AI evaluations via CC, Forbes covers CC in healthcare AI, and Anjuna Seaglass expands to on-prem AMD SEV data centers.
  • Privacy Research Survey: The Fraunhofer Institute releases an anonymous public survey on PETs adoption challenges to help shape European tech policy.

4 mins read

From the Executive Director 

Hello Community Member,

Although it’s vacation or holiday season for many in the Northern Hemisphere, that doesn’t mean that nothing is happening in the world of security and Confidential Computing. The big news of this month is that part of the EU CRA (Cyber Resilience Act) comes into effect from 2026-09-11, specifically, the reporting part of the Act. The good news is that the requirements on open source software is reduced compared to commercial software, but there is a mechanism by which open source software projects can have a “Steward”, who handles communications with the relevant EU and regional authorities.

The Confidential Computing Consortium, as part of the Linux Foundation, is in the fortunate position of being able to have its projects have the Linux Foundation as the nominated Steward, leading to little overhead. We do, however, need to decide which of our projects need to be included. The key test is whether they are intended for commercial use or are used within software which is commercially available within the European Union. For those that meet one of these criteria, there are a few steps that they need to take, and as Executive Director, I will be working with the maintainers of those projects to help them work through the required actions.

However, it’s vitally important that we, the CCC, know which of our open source projects are used in commercially available products or services. I’d therefore ask you to let me know if your company is using (or planning to use) software from one of our projects in commercially available software. Frankly, this is useful information generally, whether you plan to make it available within the EU or not: understanding how companies (members of the CCC or not) are using our open source projects will allow us to support them – and you – better. If you have information or questions around these, please let me know: I’m always happy to receive communications to mbursell@contractor.linuxfoundation.org.

From the Outreach Committee Chair

At the recent Hot Chips event, security and Confidential Computing continued to be a hot topic, as agentic AI moves into every vertical and is adopted widely at a global level. A recent private review of data pulled from papers, conferences and blogs processing over 4k of data and around 900 mb’s of transcripts uncovered ‘AI identity’ as the number one topic for companies looking across industries for solutions to secure agentic AI.

With AI identity leading discussions today, I believe enterprises are looking for a drop in solution to secure their workloads and Confidential Computing can be the best answer to address their needs – of course, it must be combined with verifiability and attestation. Let me know your thoughts – is your research also pointing to this as the hottest topic today and how is your company helping meet the needs of the enterprise? Do you have any topics you would like us to cover in a tech blog, or address from the Consortium’s perspective?

As always, you can reach out to the Executive Director, the Outreach Chair or Vice Chair (or all three of us!) for more information on plugging in to Outreach.

As a reminder, the Outreach Resources below provide additional opportunities to engage with the CCC: 

From the TAC Chair 

This month we got a great update from The Certifier Framework for Confidential Computing.

The project provides a unified approach to multi-vendor CC deployments. So if you are using a variety of CC capable hardware you can have a common approach to handling attestations.

We also got started on draft guidance for securing AI Agents with Confidential Computing. If you would like to help guide the document feel free to join our next meeting on September 3rd. If you are reading this after the 3rd, know that you can find us alternating Thursdays at 7am pacific time. You can contribute any time in slack or the mail list. You can find the links in the TAC section of the website committees page.

Recent News

  • Google DeepMind is partnering with the Singapore AI Safety Institute, OpenMined, AVERI, and MLCommons, to test a Gemini Flash Lite model against confidential benchmarks in a privacy-preserving environment, increasing evaluation integrity. Learn more.
  • Forbes Article: Why The Future Of Healthcare AI Depends On Confidential Computing Confidential computing enables healthcare organizations to safely scale AI by protecting sensitive patient data while it is actively being processed, allowing secure cross institution collaboration without compromising privacy or regulatory compliance.
  • Anjuna Security has expanded its Anjuna Seaglass confidential computing platform to on-premises data centers powered by AMD SEV on AMD EPYC processors. Learn more.
  • Fraunhofer Institute is a third-party research institute in Germany and is undertaking this survey.The survey is directed at technologists, entrepreneurs, financiers, academics, regulators/policy makers, business managers and others who develop, sell, finance or use PETs. They want to learn about your views on the challenges obstructing PETs adoption, PETs ecosystem and business-model development, and possible solutions for these.
    The survey is anonymous. It will be used for a policy paper directed at European decision-makers, and academic publications. Its results will be made publicly available. If you’re interested, please fill out this Survey on Challenges and Support Measures for the Adoption and Commercialisation of PETs
  • Agents are only as trustworthy as the boundaries around them. At AGNTCon + MCPCon North America (Oct 22-23, San Jose), the security and trust track is stacked with sessions right in CCC’s wheelhouse:
    • Attestation for agent orchestration — Diagrid on durability, guardrails, and attestation in production agent stacksSandbox architecture, rethought — Edera on why today’s agent sandboxes are built backwardsZero-trust identity for autonomous execution — DataRobot and BlueFolders on identity models built for agents, not humansThe Secure Agentic Framework (SAF) — a hands-on workshop from Dell, Microsoft, TestifySec, and The Linux Foundation on securing agentic AI end to end
    If you’re building or evaluating trust infrastructure for AI agents, this is where the conversation is happening. Register now.

Let’s grow our community!  Share this with your network.

Subscribe to CCC Newsletter