A new arXiv preprint published on 20 July argues that companies investing seriously in AI safety and oversight cannot consistently prove to consumers or regulators that their systems go beyond bare-minimum compliance [S1]. The paper calls this a structural "trust gap", and the fix it proposes would reshape how AI systems are bought and sold. Whether that fix can actually work is the question the paper leaves hanging.

The gap nobody can see across

The core distinction the authors draw is between "responsible AI" and "trustworthy AI". Responsible AI is internal process: the policies and audits a company runs inside its own walls. Trustworthy AI is something different: independently verifiable evidence that a deployed system actually produces good outcomes in the real world [S1].

The problem is that the first does not automatically produce the second. A company can have excellent internal practices and still have no way to show the outside world that its systems are safer or fairer than a competitor's [S1]. The paper identifies three compounding failures that keep this gap open:

  • The market cannot distinguish trustworthy systems from imitations. A firm that invests heavily in safety looks identical, from the outside, to one that does the bare minimum.
  • Evaluation targets models and outputs rather than the full deployed system. A model that performs well on a benchmark may behave differently once wrapped in an application, connected to live data, and put in front of users.
  • The measurement ecosystem is oriented toward avoiding harm rather than demonstrating benefit. Most AI assessment asks whether a system caused damage, not whether it produced a good outcome [S1].

This matters because the current wave of AI governance is still finding its feet. Tools and frameworks are multiplying but none of them, the authors argue, integrate three things at once: a governance baseline, independently verified positive-outcome evidence, and market signaling in a single framework [S1].

What other sectors did

The paper compares AI governance to certification regimes in healthcare and security. The authors do not name specific regimes in the abstract, but the logic is familiar. In healthcare, drugs and devices clear independent trials before reaching patients. In sustainability, certification bodies verify environmental claims that companies cannot make on their own. In security, independent audits attest to system integrity [S1].

AI has nothing equivalent. The closest things in the open-source world are repositories like NVIDIA's Trustworthy-AI toolkit [P3], created in October 2024, and AOSSIE-Org's OpenVerifiableLLM project [P2], created in February 2026. Both are tools for building and checking AI systems. Neither functions as an independent certifier that can vouch for outcomes to a third party.

What it means

The paper's proposal is independent, outcome-oriented certification as a "connective layer" between regulation and internal governance [S1]. The idea is that certification would make trustworthiness something buyers can measure and reward commercially. A company that invests in safety could point to a certificate. A buyer could compare certificates. A regulator could set certification as a condition of market access.

The mechanism is straightforward in principle. Regulation sets the floor. Internal governance builds the practices. Certification provides the signal that the practices actually produce results. The gap the paper identifies is that the signal layer is missing, and without it, good actors and bad actors look the same from the outside [S1].

For a reader with no background in AI policy, the analogy is simple. Think of food labelling. A company can claim its product is organic, but the label only means something because an independent body verifies it. Without that verification, the claim is just marketing. The paper argues AI is in the pre-labelling stage: companies make trust claims, but nobody is checking.

What it means for business

For a two-person firm building AI tools for clients, the trust gap cuts both ways. If the firm invests in testing and fairness, it has no way to prove that to a prospective client who is comparing it against a cheaper competitor making the same claims. Certification, if it existed, would let the firm point to a verifiable signal instead of a slide deck.

For a larger company buying AI systems, the gap means due diligence is harder. A procurement team can read a vendor's safety policy, but it cannot independently verify that the policy translates into better outcomes. The paper's argument is that this is where a certification layer would change purchasing decisions: it would give buyers something concrete to compare [S1].

For a suburban agency deploying AI for customer service or content generation, the practical question is whether the tools they adopt have been independently assessed. Today, the answer is almost always no. The paper does not claim any certification body currently exists [S1], and the proposal is normative rather than descriptive. What changes on the desk this quarter is nothing yet. What changes if the proposal gains traction is that procurement could eventually include a line item for certified systems.

What we don't know yet

The paper is a preprint, version 1, and has not been peer reviewed [S1]. Its diagnosis of the trust gap and its three compounding failures are analytical claims, not empirically tested findings. The authors do not provide survey data or market measurements about consumer trust or corporate AI investment.

The proposal for independent certification is aspirational. No regulator or government has endorsed it. No certification body exists to implement it. The paper does not name the specific regimes in healthcare and security that it references, so the comparisons remain at a conceptual level [S1].

What to watch next is whether the paper's framing gains traction in policy circles, and whether any existing AI governance body moves toward outcome-oriented certification. The closest existing projects, like NVIDIA's Trustworthy-AI repository [P3] and the OpenVerifiableLLM effort [P2], are tools, not certifiers. The distance between tooling and certification is exactly the gap the paper describes.

If this piece sharpened your thinking on AI governance, subscribe to keep reading. The next development worth watching is whether peer review strengthens or challenges the trust-gap diagnosis.

Sources

More from Not A Tech Guy


Generated from an audited evidence pack with primary-source research. Social-media items are discussion signals, not verified facts. Nothing here is financial, legal or medical advice.