Pull to refresh
Logo
Traefik Labs launches verifiable evidence system for AI agent actions

Traefik Labs launches verifiable evidence system for AI agent actions

New Capabilities

Sovereign Trust Plane ties identity, policy, and tamper-evident logging into one gateway

Today: Sovereign Trust Plane introduced

Overview

Updated 3 hours ago

AI agents now issue refunds, read customer data, and change business records. When a regulator asks 18 months later who authorized an action and which policy governed it, a standard log entry is not evidence: anyone with access could have edited it.

On September 15, Traefik Labs introduced the Sovereign Trust Plane (STP) for its Traefik Hub gateway. It connects three functions: delegated access through the customer's identity provider, policy enforcement through the organization's policy engine, and an append-only transparency log that records every approval and refusal.

An independent witness cosigns each checkpoint, so verifying the record means checking proofs and signatures, not taking Traefik's word. The stack runs on customer-controlled infrastructure and can operate air-gapped with zero egress, with no SaaS control plane on the request path.

Why it matters

When an AI agent moves money or changes data, companies must prove who authorized it and which controls fired. That evidence must survive independent review.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

3
Governance capabilities in STP
Delegate (identity), Authorize (policy), Prove (transparency log).
September 30, 2026
General availability target
Initial evidence capability is live; full GA planned for this date.
December 2027
EU AI Act Article 12 effective date
The EU's record-keeping requirement was delayed to this month, shaping the regulatory deadline.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

January 2015 September 2026

2 events Latest: Today
  1. Sovereign Trust Plane introduced

    Today Product launch

    STP launched in Traefik Hub with live evidence capability; GA planned September 30. Verified with Okta, OpenFGA, and Cerbos.

  2. Traefik Labs founded

    Founding

    Company founded as Containous; Traefik reverse proxy released.

Scenarios

1

STP reaches general availability, regulated industries lead adoption

Likely Resolves by End of 2026

Discussed by: Help Net Security's coverage emphasizes CISO and compliance use cases across banking, insurance, and healthcare.

General availability lands September 30 as planned. Adoption leads in sectors that already face audit requirements, because STP converts questions like 'who authorized this?' into a verifiable record. The pre-verified Okta, OpenFGA, and Cerbos integrations keep the stack on customer-controlled infrastructure, which suits regulated environments. A public Traefik-operated witness covers smaller customers; larger ones self-host.

2

GA slips, adoption stays confined to early adopters

Possible Resolves by Q1 2027

Discussed by: The EU AI Act Article 12 delay to December 2027 removes near-term regulatory pressure, which may let companies defer the investment.

General availability pushes past September 30. Without a binding regulatory deadline until late 2027, most companies treat tamper-evident agent records as optional. Adoption stays with security-conscious early adopters and the few sectors already under audit obligation. The market waits for regulators to force the issue.

3

Rival gateways replicate the transparency model before EU rules bind

Uncertain Resolves by End of 2027

Discussed by: EU AI Act Article 12's December 2027 record-keeping requirement creates a market for verifiable evidence.

Competing API and AI gateway vendors ship their own tamper-evident evidence features before the December 2027 EU deadline. The approach becomes table stakes, and Traefik's first-mover edge narrows to its pre-verified identity and policy integrations. Regulators get multiple vendors offering similar evidence, slowing any single-vendor standard.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

July 2002

Sarbanes-Oxley Act (2002)

After Enron and WorldCom collapsed on misstated financials, Congress passed Sarbanes-Oxley. Section 404 forced public companies to document and attest that internal controls over financial reporting actually worked, not just report the numbers.

Then

Compliance costs rose sharply as companies built internal control evidence trails.

Now

It created a lasting expectation that executives prove controls operated, and became the template for 'prove the controls fired' regulation.

Why this matters now

STP applies the same idea to AI agents: regulators want to know not only what happened, but what the agent was prevented from doing and which policy produced each decision.

March 2013

Certificate Transparency (2013)

Google began requiring Certificate Transparency for new HTTPS certificates. Every certificate had to be logged in public append-only ledgers where anyone could audit entries and detect fraudulent issuance.

Then

Fraudulent and misissued certificates became detectable and publicly auditable; browsers began refusing unlogged certificates.

Now

The model, independent verifiers checking append-only logs without trusting the issuer, became a template for building auditable infrastructure.

Why this matters now

STP applies the same pattern to AI agent actions: an append-only transparency log plus an independent witness, so customers verify without trusting Traefik's signature alone.

June 2021

SLSA software provenance framework (2021)

Google and the Open Source Security Foundation introduced SLSA, a framework requiring cryptographically signed provenance for software builds so a binary could be traced to the exact source and build process that produced it.

Then

Major cloud platforms adopted signed provenance and attestation for build pipelines.

Now

Verifying software's origin moved from an audit niche to a default expectation in supply chain security.

Why this matters now

STP extends the same 'prove the provenance' standard from software artifacts to agent decisions, recording where authority came from and which policy decided each action.

Sources

(5)