Reflection
Trust is becoming an engineering discipline
For years we treated trust as the consequence of good governance: write the policy, run the audit, produce the certificate, and trust follows as a downstream consequential effect. That model made sense when the things being trusted were slow-moving....a process, a department, an annual filing.
I increasingly think we have that backwards.
In organisations where AI systems and autonomous agents are doing an increasingly larger share of the actual work, annual compliance may not fit the bill. Trust, therefore, must be architected into the system itself: who can act, under what conditions, with what evidence left behind, and what happens automatically when something goes outside the expected pattern.
That is a different discipline from governance as we have practiced it. Governance asks "did we follow the process." Engineered trust asks "can the system demonstrate, continuously and on its own, that it is behaving as intended", and if the system cannot demonstrate that, does it fail safely rather than fail invisibly.
None of this replaces governance. It gives governance something to point at other than a policy document: instrumentation, logging, attestations, real-time controls that are load-bearing rather than decorative. Organizations that get comfortable with this shift early will find that trust becomes something they can show, not just something they can claim.
I don't think this is fully worked out yet, even in my own head. But the direction feels right: less "trust us because we followed the rules," more "trust the system because you can see it proving itself."
Personal reflection. Views are my own and not those of my employer.