AgenTrust Fellowship 2026: applications closed early #23
Replies: 7 comments 5 replies
|
This is a really cool initiative @imran-siddique. I'm planning to apply for the fellowship and want to work on cmcp and AGT. Been reading through the attestation flow in cmcp, curious about the mutual attestation gap mentioned for cA2A, is there any early design thinking on bidirectional verification at the gateway boundary, or would that be starting fresh? Also wondering how the Azure TDX case factors in since it can't produce a signed DCAP quote offline. Looking forward to digging into this more. |
|
@imran-siddique As someone working closely with AI-enabled platforms, I find the focus on verifiable AI agents, attestation, and trust infrastructure especially interesting. Building open, interoperable standards for agent governance feels like an important step toward making AI systems more trustworthy, auditable, and enterprise-ready. Looking forward to following the outcomes from this fellowship. |
|
Hi Imran. I am applying for the Agent Manifest home track. I have been building persistent agent memory and a retrieval-regression harness. The gap I am proposing to work on is narrow: a memory checkpoint can be authentic, fresh, and a valid append-only advance while still changing retrieval in a way the deploying organization would reject. I am keeping the first contribution outside normative text: an external I opened the gap report here: agentrust-io/agent-manifest#298 My public implementation base is: One design question before I submit the application: would you prefer this appraisal to remain an external artifact referenced beside checkpoint evidence, or do you see a possible future integration point near the memory checkpoint binding after the tooling has produced evidence? |
|
Thanks all — closing the response gap here with concrete direction. @qubeena07: mutual cA2A attestation is not a blank-sheet design. The existing The Azure TDX premise has also moved since this announcement. Hardware validation is now complete in cmcp#409 and agent-manifest#228. The important design boundary remains: Azure's path is vTPM/paravisor-rooted and must not be treated as equivalent to a guest-controlled direct DCAP quote. Model backend capabilities explicitly and test the binding each backend actually provides. @nikshil: keep @zoheb341: thank you. The outcome we want is exactly what you described—interoperable trust evidence that can be independently verified rather than accepted as an operator assertion. |
|
Hi @imran-siddique, after agentrust-io/integrations#128 was merged, I am planning to use agentrust-io/integrations#96 as the base for my fellowship proposal. I do not want the scope to be just adding more adapters. The gap I want to work on is evidence fidelity across released runtimes: a portable conformance profile with small framework drivers, an independent ground-truth ledger, and adversarial scenarios that test what each adapter can honestly claim across errors, retries, cancellation, concurrent calls, ambiguous identity, payload exclusion, and SDK drift. OpenAI's TracingProcessor would be the next implementation, with ADK and LangGraph as the initial verification surfaces. A key acceptance criterion would be that an adapter author can run the same corpus and get comparable machine-readable results without changing the conformance core. I am scoping that as the six-month extension of #96. The one repository question I would like to settle before locking the milestones is whether this shared conformance surface should live in integrations or in a separate repository. |
|
Hi @imran-siddique, AGT's NIST AI RMF alignment identifies fairness evaluation as a Priority 1 gap. The narrower gap I am interested in is what happens after the evaluation: how externally produced fairness evidence should become a machine readable governance signal for policy decisions, human review, restricted actions, or compliance escalation. I am considering a small I also noticed that TRACE v0.2 has a Public implementation base: |
|
Applications closed early on August 26 because the response exceeded what we can responsibly review. Existing applications remain under consideration, and selected candidates will be contacted directly. Thank you to everyone who applied or contributed to the discussion. |
Uh oh!
There was an error while loading. Please reload this page.
Applications for the AgenTrust Fellowship 2026 open on 1 August and close on 29 August. Three to five fellows, six months, part-time at 20 hours a week, paid.
Read the announcement
Who funds it, and who you would be working for
Stating this plainly because it matters here. OPAQUE funds the fellowship and is the employer. The work is in these open repositories, under their existing licences and governance, and the point of the programme is to put more hands on the open specifications rather than on a product. If that distinction is important to you, it should be, and it is the reason it is spelled out rather than left as an inference.
Who it is for
Security engineers, distributed systems researchers, AI governance and compliance professionals, and Ph.D. students interested in trustworthy AI standards. You do not need all of those. The stack spans hardware attestation, policy engines, transparency logs, and standards drafting, and very few people arrive strong in more than one of those.
What you would actually do
Contribute code and specifications across the AgenTrust projects, and complete a public technical artifact: a paper, a conference talk, or something comparable that is yours and carries your name.
Selection is based on a technical proposal, so the most useful preparation is to look at the work rather than the programme description. These are open right now and labelled
fellowship:These are real open items, not exercises invented for candidates. A proposal that engages with one of them concretely, or that argues something in the specs is wrong, will read better than a general statement of interest.
Some honest context about the state of the work
If you are deciding whether this is interesting, the gaps are more informative than the achievements:
Mentored by Imran Siddique (@imran-siddique), Chief Platform Officer at OPAQUE and creator of the Agent Governance Toolkit.
Applications go through the OPAQUE Greenhouse board, linked from the announcement. Cohort starts September 2026. Questions about the technical work are welcome in this thread, and asking one before you apply is a reasonable use of it.
All reactions