Several months ago, a risk committee chair for a client of mine asked a question that I have not been able to shake: “An agenda item on our next board meeting is to address digital trust now that we are enabled by AI. How do we do that?”
Notice what she was not asking. She was not asking whether the controls passed. She had a report for that, and it was green. She was asking whether the organization could still be relied on by the people who have a choice and those who do not. And the reason it landed on her agenda at all was that the organization had started putting AI in front of customers.
I hear a version of that question every month now, and it usually arrives with the wrong diagnosis attached. AI and digital trust are being discussed as if the first is destroying the second. It is not. In most organizations, digital trust was never built. It was assumed. It sat in policies nobody read, in vendor attestations nobody re-checked, in “we’ve never had an incident” statements that were true only because nobody was looking. AI did not erode that trust. It put weight on it for the first time and it gave way.
Digital trust was an assumption, not an asset. Here is the trap most enterprises walked into. Security, privacy, resilience, quality, compliance…these are inputs. You manage them, you invest in them, you get audited on them. Trust is the outcome. It is what other people decide about you. You cannot buy it, install it, or assign it to a team, and having every input in place does not hand it to you.
AI changes the playing field. Traditional assurance assumed the system is inspectable and evidence is generated internally. It now faces outputs from a model nobody in the building can open, behavior that drifts between assessments, and evidence held by a vendor’s vendor. Procurement transfers the capability. It never transfers the answer you owe a regulator or a customer. Trust that was only ever assumed has no way to survive that.
Assumed trust and earned trust look identical until something happens. Both have a green dashboard, and every claim on it can be true and signed off by somebody competent. It is the same distinction I keep coming back to: governance is either load-bearing or decorative, and a green dashboard cannot tell you which. Assumed trust is what decorative governance produces.
Green does not just report comfort. It manufactures it. When confidence is high, scrutiny declines and the questions stop. When did anyone in your organization last challenge a green indicator? Not a red one. A green one.
So here is the diagnosis. Strong control performance and falling confidence is not a technology failure. It is a governance failure, and it is diagnosable. If your controls are working and trust is still declining, you are measuring the wrong thing, not managing the wrong system. ISACA’s Digital Trust Ecosystem Framework (DTEF) is my reference here because it does not score the boxes. It looks at what happens between them.
Nobody can measure trust directly. Every attempt ends in a survey. What you can measure is the distance between three things you already observe. The claim: what you tell interested parties. “Your data is safe.” “A human reviews every decision.” The evidence: what you can prove today, and how well. I grade it on a five-rung ladder…asserted (rung one, someone said so), documented, verified, tested, and monitored (rung five, continuously observed with a named response when it drifts). The experience: what people encounter. Not their opinion. What they do, wait for, escalate, or abandon.
Two gaps do the work. Claim minus evidence is what you promise that you cannot yet prove. That is your exposure, and it belongs to governance. Evidence minus experience is what you can prove that people still do not feel. That is a communication failure, and it belongs to leadership. For AI, those three pieces line up with three altitudes.
Strategic altitude: are we trusted by the people who matter most? This is where the board lives, and it is where the claims get made. The website, the app, the regulatory filing. “Customers are treated fairly.” “A person reviews every decline.” Ask a board which of those claims they would personally defend to a regulator. If the answer is a list of vendors rather than a list of judgments, the claim was never decided. It was purchased.
A board approves an AI assistant for customer service on the strength of a vendor demo and a slide that says “human in the loop.” Eighteen months later a regulator asks which director decided the assistant could quote policy terms to customers. Nobody did. The trust was purchased with the license, and it expires the first time the assistant is wrong in public.
Tactical altitude: are our trust-building efforts being implemented? Management’s altitude, where evidence lives. Earned trust here means the people accountable for an AI system can answer, without calling the vendor, how it is monitored, what triggers a human review, and how they would know it had drifted. A claim you make publicly should never sit more than one rung below the confidence with which you make it. Most of the AI claims I see sit on rung one, asserted: someone said so. Usually a vendor. Usually in a slide.
We settled this for identity a decade ago with zero trust. Never trust, always verify. Nobody would accept a one-time credential check and call the session safe all day. An annual vendor attestation for a model that retrains monthly is exactly that check.
The vendor updates the model behind your eligibility decisions. Nothing breaks, so nothing is logged, and the annual attestation predates the update. Six weeks later a customer segment is being declined in a pattern nobody designed, and the only evidence you hold is a certificate describing a model you are no longer running.
Operational altitude: is trust being delivered in the daily details? This is ground level, where experience lives and where nobody at the top can fake it. Operational trust is transitive. It flows from the two altitudes above it.
A financial services provider scores transactions for fraud with a third-party model, declines are automatic, and the dashboard has been green for three quarters. Meanwhile, agents in three districts are reporting repeat declines on the same customers, and none of it reaches a risk register, because agents raise it to operations. The signal existed and it was traveling. It just never met the dashboard.
The three altitudes have to agree. Put them side by side and the contrast is hard to miss.
| Altitude | The question | What lives here | Assumed trust looks like | Earned trust looks like |
|---|---|---|---|---|
| Strategic | Are we trusted by the people who matter most? | The claim | A list of vendors | A claim someone decided to make and would defend |
| Tactical | Are our trust-building efforts being implemented? | The evidence | Rung one, asserted: someone said so, usually a vendor | Rungs four and five, tested or monitored, with a named response |
| Operational | Is trust being delivered in the daily details? | The experience | A green dashboard while agents complain to operations | Signals that reach the risk register before the headline does |
Earned trust is the opposite. Each altitude can produce evidence the others can inspect. The board can point to the claim it decided to make. Management can point to the rung the evidence sits on. Operations can point to what customers experience. That chain is what DTEF means by an ecosystem, and it is what a regulator, an auditor, or an angry customer will eventually ask you to walk them through.
Final Thoughts
AI did not create your trust problem. It revealed it. Revealed problems can be fixed. Assumed ones cannot. Just do not build a trust program to fix them. A parallel trust program will be defunded within eighteen months. An extension of a governance system that already has a budget will not.
1. Stop saying “rebuild.” You cannot rebuild what was never built. Try this: pick one AI-enabled process and write down, at each altitude, what evidence exists. The blank spaces are your answer.
2. Grade your five loudest claims. The promises on your website, in your app, in your filings. Try this: put each one on the ladder: asserted, documented, verified, tested, monitored. It takes an afternoon. You may not like the answer.
3. Add one indicator that can disagree with your dashboard. If your confidence measures always agree with your control measures, they are restating the controls in different words. Try this: beside each control metric you already report, add one indicator capable of contradicting it. Same page, same meeting. Replace nothing.
4. Challenge a green indicator. Green is where the questions stopped. Try this: in your next governance meeting, pick the greenest item on the page and ask which evidence rung it sits on.
5. Give the gap a name and a date. Not a working group. A person, and a date. Try this: take the claim with the largest gap and put an owner and a review date beside it before the meeting ends.
You can build world-class controls and invest millions in AI. But if customers do not believe your intent and regulators do not trust your governance, your models are just technology, your frameworks are just paper, and your strategy is just noise and hope.
So here is my question for you: if a regulator, an auditor, or your largest customer asked you to walk them through the trust chain for one AI system, at which altitude would you have to start improvising?

