The Trust Code, Reviewed: When AI Deserves Our Confidence

In The Trust Code, Tiffany Xingyu Wang describes a practice at Siemens Energy that deserves more attention than another impressive AI demonstration. New systems run alongside established processes while operators compare their predictions with what actually happens. Existing methods remain available as a fallback. Decisions involving competing human needs, such as how to allocate power outages, remain with people.

The work is in the comparison, the fallback, and the authority to intervene. Those details help explain why a system might deserve reliance. A convincing demonstration alone cannot.

That is the question at the center of The Trust Code: How to Unlock AI’s Promise Without Losing Humanity. Wang asks what happens when machines become remarkably good at eliciting our confidence, while the conditions that would justify that confidence remain harder to see. Her answer brings together psychology, technological history, interviews, and practical questions about how we use AI. The book is most useful when it turns trust into something we can examine in a particular situation, including the people and institutions surrounding the technology.

Tiffany is my friend, and I genuinely respect her work. We are both members of the Young Global Leaders alumni community. She provided me with a free advance copy of the book.

Purple cover of The Trust Code: How to Unlock AI’s Promise Without Losing Humanity by Tiffany Xingyu Wang, photographed on a wooden surface.
The Trust Code. Photograph supplied by the author.

My interest in her argument is also practical. Much of my writing about human-AI collaboration concerns how to benefit from capable systems while retaining the ability to understand, question, and direct their work. Wang approaches that problem through trust. I approach it through the design of work. The meeting point is consequential: a person can remain formally responsible for a decision while having very little opportunity to make it well.

What confidence cannot tell us

The book’s foundational distinction is between trustworthiness, trust, and calibration. Trustworthiness concerns what a system and its deployment deserve. Trust concerns our willingness to rely on them. Calibration concerns whether that willingness fits the evidence and the situation.

This distinction changes the purpose of the discussion. Greater trust is not automatically progress. Someone can be appropriately unwilling to rely on an unreliable system. Someone else can miss a useful opportunity because their distrust extends beyond what the evidence warrants. The aim is a better fit between reliance and what deserves it.

Consider a hypothetical use of an AI assistant. I might accept its suggestions for rearranging a paragraph after reading the result. Giving that assistant authority to send a consequential message creates a different vulnerability. The language model could be identical. What changed is the action, the opportunity to review it, the people affected, and the difficulty of undoing an error. A reputation for writing well does not settle the second decision.

Wang gives this reasoning a structure she calls the Trust Print. It asks us to examine the source of trust, its prerequisites, its behavioral expression, and the influences we may not notice. Who appears to be speaking? Who actually sets the objectives and defaults? What would count as competence here? What are we disclosing or delegating? Which social cues are doing more persuasive work than we recognize?

A fluent interface makes those questions easy to collapse. We encounter one apparent conversational partner, while responsibility is distributed across the organizations choosing data, incentives, product design, deployment conditions, and safeguards. Wang repeatedly brings that responsibility back into view. A model’s agreeable tone tells us little about which interests the surrounding system serves.

I also appreciate her distinction between trusting someone’s character and trusting their competence in a particular domain. Confidence in a person or institution does not automatically travel into every adjacent task. That is a useful discipline for a review of a friend’s book, too. Affection explains a relationship; the argument still has to earn its conclusions.

The underlying questions have a substantial intellectual history. Wang’s notes draw on organizational trust research and work connecting trust to trustworthiness. Her contribution is an accessible synthesis directed at the particular confusions AI creates. She gives readers a way to notice when a judgment about one property has quietly become permission for something else.

The institutions inside an ordinary act of trust

One of the book’s more revealing scenes concerns Wang riding in a driverless car with her toddler. The encounter feels immediate and personal. The conditions behind it include engineering, operating procedures, safety arrangements, and regulation. The passenger experiences a ride; trust depends on much that the passenger cannot inspect from the seat.

Wang uses a tour through earlier technologies to develop this point. Printing changed source authority. Industrial machinery raised questions about labor and the distribution of benefits. Electricity made people dependent on invisible systems and specialist knowledge. Automobiles distributed dangerous capabilities among strangers. Each required arrangements through which people could live with consequences they could not individually evaluate in full.

She describes a Trust Cycle moving from wonder through exposure to harm, the creation of trust mechanisms, and eventual normalization. Its value is in directing attention to what gets built around a technology. Safety practices, professional responsibilities, enforceable rules, and reliable interfaces are part of technological adoption itself. Trust is not simply the public becoming accustomed to novelty.

I would treat this cycle as an interpretive model rather than a law of history. Normalization can contain several things at once: improved safeguards, habit, necessity, unequal bargaining power, and harms that some people continue to bear.

Widespread use does not establish that everyone using a system has a meaningful alternative.

Wang’s own account of trust under constrained choice gives us grounds for this qualification.

That qualification matters for AI. A person may use an automated system because it is the only route to a service, or because an employer has selected it. Calling that use trust can conceal the question of consent. An adoption chart cannot tell us whether the people counted in it have confidence, tolerate the arrangement, or feel unable to refuse it.

The book is similarly careful at an important point in its discussion of inevitability. Continued scientific development is one proposition; the inevitability of current business models, deployment choices, and governance arrangements is another. Wang separates them. Her account of scientific curiosity, commercial incentives, and geopolitical fear explains pressures toward speed without making every decision taken under that pressure unavoidable.

This creates room for a more useful argument than a general vote for or against AI. Which capabilities should we pursue? Under what conditions should we use them? Who gets to set those conditions, and who lives with the consequences?

Where the book makes trust concrete

The chapter on AI that operates largely outside public attention is among the book’s strongest. Its examples concern the less theatrical work of keeping systems dependable: domain knowledge, sustained observation, constraints, fallback, and clear responsibility.

The Siemens Energy account makes a distinction I want more leaders to understand. Comparing a new system’s recommendations with outcomes over time produces a different kind of evidence from admiring a demonstration. Keeping an established process available changes what happens when that evidence is disappointing. Retaining human authority over value-laden decisions recognizes that technical competence does not determine whose interests should prevail.

These practices are Wang’s reported account of the organization, not an independent audit supplied by this review. That distinction is part of taking her argument seriously. An interview can illuminate how a control is intended to work. Judging its effectiveness across deployments requires evidence about how it performs, including when something goes wrong.

The book’s discussions of payment systems and enterprise software add another useful distinction: trust in a familiar institution cannot substitute for limits on a particular action. A payment agent’s permissions can be bounded by who it acts for, where it can transact, and what it can spend. Grounding an answer in relevant information, keeping records, and creating checkpoints make a workflow more inspectable. None of these practices makes error impossible. Their value is in changing the conditions under which error is detected, contained, and corrected.

The strongest part of these examples is the mechanism. Longevity and brand reputation are less decisive. An established company still needs to earn trust for a new use; a newer organization can adopt serious operational discipline. I would carry the book’s task-specific standard into every company case it presents.

I recognized a version of this problem in an upgrade of my own AI collaboration tools. A safety control had passed its tests but had never been activated on the machine it was meant to protect. The tests showed that the control worked when configured. They did not show that it was operating. An independent review found the gap. After activation, the control rejected a commit from the very session that had switched it on.

That refusal was useful evidence. It demonstrated a boundary being enforced in the environment where I needed it. It did not prove that every control worked or every future action would be safe. My confidence became better grounded because I knew something more specific than I had known before.

This is one reason I find Wang’s emphasis on earned, contextual trust persuasive. It gives language to a recurring engineering problem: evidence from one stage of work is easily mistaken for evidence about another. A working component, an activated safeguard, and an effective operating practice are related achievements, but each needs to be examined.

Different dangers require different responses

Wang’s mirror, weapon, and ghost categories offer a practical way to distinguish sources of AI risk. She presents them as an aid to sensemaking, not a complete technical taxonomy.

The mirror category concerns the human failures AI inherits and scales. Data can reflect institutional choices, exclusions, and incentives. Making a system more effective at reproducing a pattern does not establish that the pattern deserves to continue. The reader’s attention belongs upstream as well as at the output: what is being optimized, and why was it treated as a suitable representation of the goal?

Weapon risks arise when people use capabilities to deceive, exploit, or harm. Here Wang is particularly useful when she moves beyond advising individuals to be more vigilant. Verification needs usable channels. An employee cannot be expected to distinguish every convincing impersonation without a reliable way to confirm a consequential request. Procedures for independent confirmation, limits on authority, and deliberate pauses can matter more than another reminder to be careful.

Ghost risks concern failures that emerge through optimization, misleading outputs, and our adaptation to systems that appear increasingly competent. A system need not have a human intention to produce an answer that induces misplaced confidence. Nor does every damaging dependency begin with a dramatic mistake. It can develop when the convenient answer becomes the answer we stop examining.

The categories overlap. A harmful incentive can shape training data, create an opportunity for abuse, and encourage dependence at the same time. I see their usefulness in the different questions they prompt, rather than in assigning each incident to exactly one box. Repairing an inherited institutional failure, defending against an adversary, and preserving the user’s capacity to judge call for different interventions.

The chapter’s title, “The Defeatable,” could suggest a stronger promise than its argument makes. Wang explicitly explains that she means establishing boundaries rather than eliminating every danger. That qualification is essential. We can reduce exposure and improve our response without pretending to have settled the entire problem.

Her discussion of cognitive dependence raises a concern I share, though I would be more cautious about how far particular studies take us. The essay-writing study she cites involved 54 participants across its first three sessions, with 18 completing a fourth. Its findings about engagement, recall, and ownership of work are reasons to investigate how assistance changes learning. They cannot, by themselves, establish a general or permanent loss of human capacity from using AI.

The practical question remains valuable without that extrapolation: which parts of a task must people continue to practice if they are to judge the result later? Faster production can be beneficial while leaving that question unresolved. A good workflow should make room for learning as well as completion.

Human judgment needs an intelligible choice

Wang’s positive account of AI gives judgment something to do. Her discussion of creative work describes an hourglass: AI can help with research inputs and production, while human insight, taste, intention, and care occupy the narrow middle. The value of the work depends on what passes through that middle, not merely on the volume of material produced around it.

The science examples make a related distinction between generating a promising possibility and validating it. The energy discussion brings questions of infrastructure and the distribution of costs and benefits into view. These discussions keep the book from becoming a catalog of hazards. They also support its central claim: useful capability depends on the human practices and institutions surrounding it.

My own experience has made me wary of the phrase “human in the loop” when it is used without explanation. I once had an approval interface that worked mechanically and failed as a means of making decisions. It presented fifteen choices in language intelligible to the system that produced them, but not to me. The controls worked. I made no decisions.

I described that experience in my essay on decision packets. Rewriting the choices and their consequences in language I could understand made the packet usable. I also chose to show recommendations without preselecting them, and to record bulk acceptance differently from individual decisions.

A click still cannot prove comprehension. Those choices address narrower problems: an unread recommendation should not arrive in the record as an agreement, and accepting a batch should not masquerade as examining every item.

Meaningful human responsibility requires a truthful account of what the person was asked, could understand, and actually decided.

This is the practical substance behind what I call human architectural authority in synthesis coding: people retain authority over consequential commitments while AI contributes substantial work. Authority requires enough understanding to evaluate those commitments. A final approval button cannot supply understanding that the preceding workflow failed to develop.

Wang’s argument helps broaden this beyond software. A patient, employee, student, or customer may be nominally consulted and still lack the information or alternatives needed to exercise judgment. The quality of the human role depends on how the surrounding system treats that person.

A framework to use, and conditions it needs

The book closes with CALIBRATE, a framework for making trust a recurring practice of judgment. It helps readers examine whether their reliance on AI fits the situation and reconsider that reliance as circumstances change. The value lies in working through those judgments with the book’s explanations and examples.

Wang is clear that this practice complements institutional safeguards; it does not replace regulation, risk standards, or compliance. She also provides a shorter approach for everyday use. Her public essay on the human layer of AI governance introduces the thinking behind this part of the book.

The framework is useful as a discipline of inquiry. I would not treat completing it as certification that a deployment deserves trust. The quality of the answers matters, along with who can test them and what happens when an answer is unsatisfactory.

This is where I wanted the book to go further. Wang recognizes institutional responsibility, unequal power, and the need for recourse. The remaining difficulty is making those commitments exercisable. An employee may know the right question but lack authority to pause a rollout. A customer may understand the risk but have no alternative service. An operator may be told to oversee a system without being given the time, evidence, or practice required to challenge it.

Organizations using the framework should therefore make its consequences explicit. What finding stops a deployment? Who can invoke that stop? How does a person challenge a decision that affects them? Which skills will the organization protect through continued practice? Questions about trust become operational when someone must answer them and act on the answer.

Continuity matters here as well. In synthesis project management, I keep decisions, evidence, and project history in durable records that can survive the conversation that produced them. This supports a continuing examination of work: what was decided, why, what was verified, and what remains uncertain. A confident account from the current AI session is insufficient if the underlying record tells a different story.

I have also written about keeping that accumulated work under human control when AI tools change. The ability to inspect records and continue in another environment can make dependence more voluntary. It does not make every transition effortless. It gives the person a stronger position from which to decide whether continued reliance is justified.

These are connections I draw from my work, rather than practices Wang endorses. They are examples of the next step her argument invites: translating a principle of agency into something a person can actually exercise.

Who benefits from reading it

The Trust Code belongs in a conversation that extends beyond technology specialists. Its central distinctions are useful to leaders deciding how to organize work, practitioners designing AI-assisted processes, and readers trying to understand what they are delegating. Technical readers will find more value in its synthesis of human and institutional questions than in treating it as a technical reference. Readers seeking an audited comparison of vendors or a finished governance specification will need other resources alongside it.

I thought about two earlier books while considering where this one fits. In my review of Trailblazer, I considered values as a basis for business decisions. Wang brings a more granular question into view: what would make reliance justified in this particular interaction? A declared value such as trust needs expression in boundaries, evidence, and responsibility.

Michele Wucker’s You Are What You Risk, which I reviewed here, emphasizes how differently people experience and interpret risk. That perspective adds something to trust calibration. The person who benefits from speed may not be the person who bears an error. Disagreement about whether to trust a system can reflect different stakes, rather than a simple divide between people who understand technology and people who fear it.

Wang’s book gives those conversations a useful shared vocabulary. Its best passages move between personal judgment and the arrangements that make judgment possible. Its broadest claims deserve the same care about evidence that it asks readers to bring to AI. I find that a reason to engage closely with the book: its own central distinction helps us assess both its examples and the systems around us.

The Siemens Energy example stays with me because the alternative remains available and the comparison continues. Trust has conditions. People can learn whether those conditions are being met and retain some ability to respond when they are not.

That is the standard I would take from The Trust Code into my own work. Before granting a system more authority, I want to know what supports the decision, who can challenge it, and what happens if that challenge is right.

Edition note: This review is based on an advance, uncorrected galley. References to the book describe that edition; pagination and wording may differ in the published book.

Rajiv Pant and Tiffany Xingyu Wang standing side by side indoors.
With Tiffany Xingyu Wang in Manhattan, November 30, 2023.