All updates
Research

The Trust Problem Nobody Wants to Name

Blanco-style line drawing of Daniel Glinz smiling, in a light beige blazer and open-collar shirt with a conference lanyard, holding a certificate that reads Best Paper Award, The Architecture of Digital Trust, on a clean white ground.Hover for the original photo

Everybody is spending money on AI. Almost nobody can say what they got back. The distance between what AI promises and what it actually delivers inside a working organisation has a name in a new paper by Daniel Glinz: the AI value gap. The paper won the Best Paper Award at the 2026 IEEE Swiss Conference on Data Science and AI, and its central claim is uncomfortable in a precise way. For a decade the gap has been handed to engineering to close. It was never engineering’s to close. It is a trust deficit wearing a technical costume.

Executive summary

A prize is a weak proxy for whether an idea survives contact with practice, and the paper says as much about its own framework, which it calls a starting point rather than a verdict. What the award signals is narrower and more useful: a room full of practitioners recognised the problem on sight. For years the value gap was treated as a technical shortfall, on the assumption that better models and cleaner pipelines would eventually close it. The paper’s argument is that the largest part of the gap was never technical. Systems do not fail because they cannot perform; they fail because no one is willing to lean on them.

There is a historical rhyme worth stating up front. General-purpose technologies have always front-loaded infrastructure and back-loaded productivity, and economic analysis suggests AI’s near-term contribution is still largely infrastructural, with durable gains lagging adoption by years. So some of the value gap is simply time, and that part closes on its own. The trust deficit is the part that will not. What follows is the paper’s account of it: the seven mechanisms that widen the gap, the four-layer architecture and the iceberg beneath it, three paradoxes that do not resolve, and five design principles that follow from all of it. It ends where the work does, with what an organisation can actually do on Monday morning.

At the 2026 IEEE Swiss Conference on Data Science and AI in Zurich.

A vote that had nothing to do with the technology

Switzerland once put an electronic identity system to a national vote. On the technical merits there was little to argue with. The architecture was sound, privacy had been designed for rather than bolted on, and by any reasonable engineering standard the system worked. Voters rejected it anyway.

What they could not be talked into was not whether the system was safe today, but whether it would still be safe in fifteen years, under a different government, with different commercial partners, under pressures no one had yet imagined. The question was never “does this work.” It was “who controls this later, and what stops them changing it.”

The paper gives that reflex a name: anticipatory distrust. It is the cleanest possible illustration of the central point, because there was no defect to fix. No bug report, no failed audit, no incident to write up. The engineering was fine. The trust was not there, and no additional engineering would have put it there. That is the whole subject of the paper: not systems that cannot perform, but systems no one is willing to depend on.

The unease, in numbers

The survey evidence should give any product team pause. Across studies in the United States, the United Kingdom and Germany, roughly one in five consumers say they trust companies that use AI. One in five. And when Swiss financial institutions were asked what actually stops them scaling AI past the prototype, they did not point to technical readiness or a weak business case. They pointed to data quality, privacy and regulatory compliance. Organisational resistance barely registered. The people are willing; the governance is not there yet.

Seven mechanisms, not one

Before it builds anything, the paper takes the value gap apart. It identifies seven distinct structural mechanisms, and naming them separately matters, because most organisations suffer from two or three of them, not all seven, and the remedy depends on which.

MechanismWhat actually breaks
Governance-AI mismatchRisk and compliance frameworks built for deterministic systems are pointed at probabilistic ones with emergent behaviour.
Research-practice gapFairness metrics and explainability methods that work beautifully in a paper resist being operationalised at enterprise scale.
Principle-action gapEthical-AI commitments stay aspirational because no one translated them into enforceable technical controls.
Investment-ROI gapCapability scales faster than the organisation’s ability to absorb and govern it.
Compliance-trust gapBeing fully compliant does not, on its own, make anyone trust you.
The quality paradoxAI output matches human quality and is still judged inauthentic.
The flooding problemThe sheer volume of AI content degrades trust in all digital content, including the honest parts.
The value gap is not one failure but seven. Organisations usually carry two or three, and the fix depends on which.

The last of these is a collective-action problem, and no single organisation can solve it alone. That limitation returns near the end, when the paper turns to shared infrastructure.

Four layers, and the iceberg beneath them

The framework is built from a 56-source interdisciplinary review spanning organisational psychology, information systems, economics, AI governance and ethics, human-computer interaction, complexity science and law, with a trust-dynamics thread running through all of them. The method is a hybrid of Design Science Research and a grounded-theory literature review, coded through open, axial and selective phases. What comes out is an architecture of four layers, ten constructs and 127 individual trust cues.

  1. 01

    Agency, the human layer

    How people read intention, competence and accountability. We judge machines with mental models built for judging people, and trust drops when those signals are weak, whatever the system’s real performance.

  2. 02

    Engineering, where trust becomes measurable

    Identity assurance, provenance, cryptographic integrity, adversarial testing, controlled failure. Modern failure modes (hallucination, drift, prompt injection) need continuous evaluation, not a one-time certificate.

  3. 03

    Governance, the organisational layer

    Adaptive governance that evolves with the risk, resilience that absorbs disruption without collapse, and live evidence that systems behave as intended. Periodic oversight of stable processes does not fit AI.

  4. 04

    Institutional, the macro layer

    Law, regulation, standards bodies, certification, public infrastructure. This layer exists so trust does not rest on the goodwill of private companies alone.

The foundation — bias precedes everything above it

The iceberg is where the framework earns its keep. The cues an organisation chooses to show the world are the visible tip: certifications, transparency reports, privacy notices. Below the waterline sit the structures no marketing team can reach, disposition to trust, institution-based trust, prior beliefs, the accumulated residue of every earlier digital disappointment. You cannot campaign your way past what sits below the waterline, which is exactly why treating trust as a communications exercise fails so reliably.

The framework as an iceberg: the cues shown above the waterline, and the four structural layers that hold trust up beneath it.

Three paradoxes that will not resolve

The most interesting section is the one that refuses to offer clean answers. Three tensions are, on the paper’s account, structural features of human-AI interaction. You manage them. You do not solve them.

The authorship effect

Label identical content “AI-generated” rather than “human-made” and people rate it less trustworthy, less persuasive, less emotionally engaging. The quality does not change; the judgement does. Human authorship carries a symbolic charge, craftsmanship, care, moral accountability, and machine authorship reads instead as cost-cutting or indifference.

The real-world version ran in public. Coca-Cola’s AI-driven holiday campaign was called soulless and visually incoherent despite a large budget, and drew boycott calls. Apple’s Apple TV+ sequence showed the handcrafted process behind a logo animation and was widely praised. Similar ambitions, opposite receptions, and the difference was who audiences believed had made the thing. Note the trap this sets: disclosing AI involvement is the transparent thing to do, and here transparency can reduce trust rather than build it, especially where trust is already low. That is a genuine bind, not a messaging failure.

The intimacy paradox

The classic privacy paradox is the gap between what people say about privacy and what they actually do. Generative AI widens it. Conversational systems are patient, responsive, never judgemental, always available, and they create what Sherry Turkle calls an illusion of dialogue, one that lowers the barrier to disclosure. So people tell these systems things they would never put in a form, and the same people, asked directly, say they do not trust the companies running them. The interface feels like a private room; it is a pipeline processing input at scale. The gap between felt safety and real exposure is likely to widen as free AI tools drift toward advertising-supported models, where the conversation itself becomes behavioural data.

The agency paradox

We want the cognitive load taken off our hands, and we resent it when the thing taken is something we consider ours: our judgement, our writing, our professional identity. Helga Nowotny’s observation is that AI lets us see further ahead, but if we start to believe the predicted future is the only possible one, we quietly close off the alternatives. The features that make AI appealing are the same ones that make it feel threatening. That is not a flaw in the design. It is the design.

Five principles, and what they demand

From the architecture the paper derives five design principles, each mapped to a specific interaction between the layers.

PrincipleWhat it demandsPriority
Layered architectureCoherent alignment across all four layers, not excellence in one. Minimum viable capability everywhere before optimisation anywhere.Foundation
Forward-looking trustCredible constraint: architectural limits, enforceable deletion, usage restrictions that outlast acquisitions and political cycles, built in rather than promised.Critical
Productive frictionDeliberate pauses, confirmations, visible reasoning and human checkpoints where a fluent wrong answer would cost the most.High
Paradox managementDesign with the three paradoxes in view. Minimise collection precisely because AI is so good at eliciting disclosure; keep stakeholder dialogue running.Ongoing
Ecosystem integrationBuild on shared foundations (decentralised identifiers, verifiable credentials, C2PA provenance, the Trust over IP stack) before they harden into requirements.Strategic
Five principles, each tied to a specific interaction between layers and each with a different urgency.

Two of them carry most of the weight. Forward-looking trust is the principle the e-ID vote was really about: users judge a system not only on what it does now but on what it could become under different ownership. The answer is not a promise about intent but a credible constraint, an architectural limit or an enforceable deletion guarantee that still holds when intent changes, and such constraints are far more believable built in than retrofitted. Productive friction runs against the industry’s instinct to treat every pause as a defect. When a system produces fluent, confident output with no signal of its own uncertainty and then turns out to be wrong, people feel betrayed rather than warned. The paper calls the frictionless interface an unearned smoothness that hides hallucination. In healthcare, criminal justice and financial services, deliberate friction is what makes trust calibrated rather than blind.

From reputation to proof

Underneath all of this runs a quieter argument about where trust now lives. Traditional digital trust rested on implicit signals: brand recognition, platform dominance, the general sense that a large company probably will not defraud you. In a world of synthetic identity, generated content and convincing deepfakes, those signals stop carrying weight. Entrust’s 2025 identity-fraud report recorded a deepfake attempt roughly every five minutes in 2024, with deepfakes making up about 40 percent of all biometric fraud and national identity cards the single most-targeted document. The attack has moved to the foundations.

What replaces implicit trust is explicit, machine-verifiable guarantee: self-sovereign identity that puts credentials in the person’s hands through decentralised identifiers; verifiable credentials that can be checked without calling the issuer; content provenance bound cryptographically at the moment of creation; delegation frameworks that let a person grant an AI agent limited, revocable, auditable authority; proof-of-personhood that establishes someone is human without exposing who they are. The shift is from trust as reputation to trust as a system property, from something you claim to something you can demonstrate.

The part worth sitting with

The paper is candid about its limits, and the candour is part of why it reads as credible rather than promotional. The constructs and cues were derived by a single coder, so inter-rater reliability has not been formally assessed. The framework is conceptual and still awaits independent empirical validation. Trust also varies by culture, markedly higher in China than across Western countries, so a single architecture may not travel unchanged. None of that dislodges the central claim.

Trust has been handled as a communications function, something addressed with the right message after the product ships. The paper argues it is a system property, built in or absent, and it gives organisations something to act on: a way to assess maturity across four layers, work out which of the seven mechanisms is actually hurting them, and prioritise from there. The path forward is not to scale AI faster, but to scale it responsibly. A less exciting line for a board deck, and a considerably more useful one.

“Trust has been treated as a message you send after the product ships. It is a property you build in, or it is absent. You cannot campaign your way past what sits below the waterline.”

The Architecture of Digital Trust

Read the paper

The full paper, “The Architecture of Digital Trust: A Multi-Level Framework for Bridging the AI Value Gap,” appears in the proceedings of the 2026 IEEE Swiss Conference on Data Science and AI and is available on IEEE Xplore. Read or download it here. The framework and its trust cues are maintained at iceberg.digital.

The paper on IEEE Xplore, DOI 10.1109/SDS70563.2026.00016.

The talk

The framework was presented as a conference talk at SDS 2026, moving from the Swiss e-ID vote through the value gap and the three paradoxes to the grounded-theory method, the iceberg and the four layers. The full slide deck is available to download. Download the talk slides (PDF).

The opening slide of the SDS 2026 talk; the full deck is linked above.

Where validant.ai stands

We build the instrument the paper describes. If trust is a system property that has to be measured rather than asserted, then someone has to do the measuring, independently of the vendor whose system is under test. That is the whole of what validant.ai is for. The paper is the theory; the platform is where an organisation sees it applied to its own systems.

What the paper arguesLayer of the architectureThe validant.ai answerStatus
Trust is a system property, built in or absent, not a message added after shipThe architecture as a wholeIndependent, continuous assessment of digital trust via the iceberg.digital trust signalClosed beta, Q3 2026
Only outside measurement separates safety from safety marketingEngineering, the modelAI Fairness and Explainability: Pulse, Navigator and the open-source vfairness libraryClosed beta, Q3 2026
Authority that lives in a service agreement can be revoked by someone elseAgency, the personSelf-Sovereign Identity: verifiable credentials and signed agent mandatesPlanned
The paper’s thesis mapped onto the three bodies validant.ai assesses, and where each stands today.

The through-line is independence. validant.ai does not run your models, hold your identity, or sell you the system it evaluates. We are closer to a ratings agency than to a vendor grading its own homework, and we hand the same evidence to every stakeholder so each can decide on their own measurements rather than on anyone’s word.

Trust is assessed, not asserted. If your organisation deploys AI and wants its trust posture measured by an independent party, across fairness, explainability and governance, rather than asserted by a vendor, our closed beta opens to a small group in Q3 2026. Read the award-winning paper for the framework, then let us run it against your own systems. Write to hello@validant.ai with the subject “Closed Beta,” or request a demo. Seats are limited and assigned in order of fit, not order of arrival.

Read the peer-reviewed framework at iceberg.digital

In one line

Everybody is spending on AI and almost nobody can say what they got back, because the missing piece was never engineering. It was trust, and trust is a property you build into a system across four layers, not a message you attach to it afterwards. The award-winning paper names the gap; validant.ai measures it.

Sources and further reading

Share this post
Read next
Fine grey-blue technical drawing on warm paper of a single rack-mounted frontier-AI model unit gone dark, beside a large knife-blade breaker switch thrown to off and actuated by a sealed letter, with dashed data lines to small client terminals and a faint world map all cut by break-marks, one teal switch lever, a soft coral wash and a small human figure for scale.ResearchOpen to read
14 June 2026

When a Model Becomes a Munition

A frontier AI model was switched off worldwide by a single government letter. Reading the June 2026 shutdown through the three-body picture of digital trust: how the kill switch stopped being a metaphor, why the most governable lab was governed least carefully of all, and what single-vendor, single-jurisdiction dependence now costs a board.

Read
Blanco-style technical line drawing of three spheres of different sizes held in balance by interlacing elliptical orbits, with soft coral washes, on a white ground.ResearchOpen to read
5 June 2026

Digital Trust Is an Orbit, Not a Pillar

Trust is not one more pillar to stack. It is the orbit three bodies trace together: the model, the person and the organisation. Why the three-body problem is the honest metaphor for trustworthy AI, and how to tell where you are in the orbit.

Read
Fine grey-blue technical drawing of an orrery: a heavy central sphere in a teal gimbal mount, encircled by calibrated elliptical orbit rings with two smaller spheres captured close, a key hanging as a credential, on a precision base with a small figure for scale and a soft coral wash, on warm paper.ResearchOpen to read
11 June 2026

Agents Will Act for Us. Who Vouches for Them?

When agents start acting for us, trust moves from outputs to actors. Reading Michael Casey’s case for proof of control alongside our three-body picture of digital trust: where convenience quietly pulls authority toward a few global platforms, how validant.ai answers it, and a closed beta for scientific validation opening in Q3 2026.

Read