Skip to main content

Architecting Trust

A ‘Trust by Design Plus’ Framework for Military AI

Author: Branka Marijan

Introduction

Artificial intelligence (AI) is increasingly embedded across military functions, including intelligence analysis, logistics optimisation, targeting support and strike.[1] These technologies promise enhanced speed, precision and decision advantage, while simultaneously introducing new forms of uncertainty, opacity and risk. The increasing reliance on AI in time-sensitive and high-stakes environments raises fundamental questions about how human decision-makers understand, evaluate and rely on machine-generated outputs. Indeed, recent reporting on the February 2026 US attack on Iran, reportedly involving AI-enabled decision-support systems across stages ranging from target identification to legal review and strike launch, has been interpreted as signalling a shift towards increasingly compressed decision-making timelines, raising concerns that human judgement may become progressively marginalised in the use of force.[2]

Within this evolving landscape, trust has emerged as both an operational requirement and a strategic concern. For military organisations, personnel must trust AI-enabled systems sufficiently to be willing to employ them in operational settings, as low levels of trust may significantly constrain the circumstances in which such capabilities are used and, consequently, their operational effectiveness. At the same time, policymakers must ensure that these systems operate in ways consistent with legal and ethical obligations. Beyond the organisational level, states must also interpret and assess each other’s development and deployment of AI-enabled military capabilities, often under conditions of uncertainty and strategic competition.

Trustworthy AI in the military domain has therefore emerged as a shared concern among military practitioners and policymakers. According to a 2025 European Defence Agency white paper:

Trustworthy AI systems in the military domain are designed to inspire confidence among commanders, soldiers, and policymakers by ensuring that AI technologies operate predictably, securely, and ethically in complex and dynamic environments.[3]

In parallel, international discussions on the responsible application of AI in the military domain, including debates on lethal autonomous weapons systems, have increasingly highlighted (dis)trust among states as a central issue.

Despite the growing attention to trust and distrust, the topic remains underexplored in interdisciplinary policy and scholarly literature on military AI.[4] One of the few empirical studies in relation to trust and military attitudes toward AI systems finds that:

service members’ trust in partnering with AI during strategic-level deliberations is based on a tightly calibrated set of considerations, including technical specifications, perceived effectiveness, and international oversight.[5]

This latter point on international oversight is particularly significant, as broader policy discussions are at times described as disconnected from the practical considerations that shape military decision-making.

At the same time, the expanding technical literature on trust and trustworthiness in AI systems has tended to overlook the interstate dynamics that shape how AI is developed, deployed and perceived in international security contexts. Nevertheless, insights from this literature have influenced regulatory discussions on military AI, particularly as technical experts have been increasingly engaged in these processes. Addressing these gaps requires a more integrated understanding of how trust is constructed, operationalised and sustained across multiple levels of analysis in the military AI domain.

This article addresses some of these gaps by advancing three interrelated arguments. First, trust in military AI should be understood as a multi-level construct spanning system, organisational and interstate dimensions. Second, trust is dynamic and must be continuously calibrated across the lifecycle of AI systems, rather than treated as a static design outcome. Third, trust is politically situated and should therefore be calibrated conservatively through demonstrated performance and continuous oversight, rather than maximised as an end in itself. This reflects concerns that claims of ‘trustworthy AI’ may be instrumentalised to legitimise or accelerate the adoption of military AI systems without sufficient scrutiny of their limitations and risks.

Building on these insights, this paper argues that the trust by design (TbD) framework, as conceptualised by Emmanuel A Merchán-Cruz et al. in the context of industrial human–robot collaboration,[6] offers a useful foundation for structuring trust in military AI systems when adapted to account for the socio-technical complexities of international security. By embedding principles such as transparency, human agency and robustness into system design, an expanded ‘trust by design plus’ (TbD+) framework may provide states with more credible and potentially verifiable signals of restraint, while reinforcing human control in the use of force. Rather than seeking to maximise trust, it emphasises the importance of calibrated trust grounded in demonstrable system performance, institutional oversight and adherence to shared norms. Trust, in this sense, is not an input to be engineered but a property that must be continuously earned and validated. It also extends beyond the technical system itself and must account for how users interact with both the system and the operational environment in which it is deployed.[7] This, in turn, requires closer integration between system design and development processes and the ways in which military organisations introduce, govern and employ these capabilities in service. Therefore, the TbD+ framework does not substitute for political and strategic judgement regarding the use of AI-enabled systems in the first place.

Additionally, technical and governance design approaches may still be insufficient to address deeper trust deficits in international security, and notably between major powers such as the United States and China. Accordingly, the paper also identifies a set of complementary confidence-building measures aimed at reducing risks of miscalculation, including commitments to shared principles on human control in the use of force, incident notification protocols, information-sharing on testing and evaluation standards, and capacity-building initiatives within multilateral institutions. Ultimately, this layered approach and expanded understanding of trust by design in the military domain will also require additional research and study, particularly as policies, global dynamics and real-time deployments of technologies continue to develop.

On Trust and Control in Military AI

Trust is often described as a ‘slippery’ term, with multiple meanings and definitions across different fields of study.[8] For the purposes of this discussion, rather than engaging with the extensive literature on the many interpretations of trust, it is more useful to focus on scholarship that examines how trust emerges in relation to new technologies such as AI, particularly within the military domain.

But before discussing some of this literature, it is important to acknowledge that much of the debate on military AI, particularly in discussions on autonomous weapons, has focused on human control. Tim McFarland’s examination of trust and control in the military use of AI highlights a divergence in how these concepts have been treated that is critical to the points made in this paper.[9] Discussions of control have been central in regulatory and policy debates, while AI developers have placed greater emphasis on trust. This dynamic may be partially explained by institutional and commercial incentives. Trust represents a significantly lower threshold for industry to achieve, whereas designing systems that genuinely enable ‘control by design’ often requires substantial state involvement early and throughout the development lifecycle, increasing costs and, in many cases, running up against commercial barriers and procurement rules that limit state capacity to participate in co-design or effectively ‘pick winners’. As a result, the two paradigms have largely evolved in parallel.

In international discussions on lethal autonomous weapons systems, for example, states have emphasised the capacity of humans to exercise control over weapons systems and have outlined measures to ensure that such control is maintained. As McFarland  observes, ‘The idea of relying on ‘trust’ in the system to behave as desired is effectively absent from regulatory discussions’.[10] At the same time, McFarland notes that both trust and control are shaping the application of military. McFarland asks, ‘Might there be a complementary relationship between correctly calibrated trust and “meaningful human control”?’[11]

As debates on lethal autonomous weapons and responsible military AI, particularly through successive Responsible AI in the Military Domain (REAIM) summits, have evolved, it has become increasingly evident that many militaries are seeking to ensure both appropriately calibrated trust in AI systems and the preservation of human judgement.[12] The relationship between trust and human control has become increasingly explicit, including during discussions among military practitioners and academics at the third REAIM Summit, held in Spain in 2026. While the summit’s outcome document uses the term trust only once, it repeatedly emphasises the governance mechanisms that underpin justified trust, including transparency; testing, evaluation, validation and verification (TEVV); accountability, reliability; human oversight; and confidence-building measures. Rather than centring the language of ‘trustworthy AI’, the document places greater emphasis on ensuring that AI-enabled military systems are governable, accountable and verifiable. A similar evolution is evident in the 2026 Policy Settings for Responsible Use of Artificial Intelligence in Defence, released by the Australian Defence Force and Department of Defence, which explicitly link human judgement with ‘trusted autonomy’.[13] Recognising the importance of these concepts, however, is only a starting point. States must still determine how AI-enabled capabilities can be designed, assessed, tested and introduced in ways that meaningfully support human judgement and foster appropriately calibrated trust in operational practice.

Taken together, these developments suggest a shift from the earlier separation identified by McFarland, in which trust and control were treated as largely distinct paradigms. Instead, they are increasingly understood as interdependent: effective human control depends on appropriately calibrated trust in system performance, while such trust, in turn, is shaped by the presence of meaningful human oversight and the ability to exercise judgement. That said, this evolving understanding remains conceptually underdeveloped. Informal discussions at REAIM summits suggest that trust is often assumed rather than clearly defined, with the term used in broad and sometimes ambiguous ways. In particular, equating trust with system reliability alone risks overlooking how AI systems shape human decision-making beyond technical performance alone.[14] A system may be relied upon because it performs well in certain conditions, but trust involves a broader judgement that includes ethical, institutional and contextual factors. In this regard, scholarship on human agency in military AI systems is particularly important.[15] Whether explicitly acknowledged in formal discussions or not, achieving appropriately calibrated levels of trust will be essential for defining and regulating human–machine interaction requirements in practice.

Trust, Trustworthiness and the Politics of Trust

In fact, how control and agency is maintained is going to be shaped in part by the technical architecture of trust. Indeed, trustworthiness has been extensively studied in more technical AI literature, and technical experts have been present in shaping international discussion on lethal autonomous weapons and responsible military AI. In the context of AI systems, trust has often been understood in terms of reliance: whether users choose to depend on system outputs in decision-making processes. In military settings, understanding trust primarily in terms of reliance is appealing, as personnel often have limited choice in whether to use particular systems, either because those are the capabilities available to them or because operational demands create an immediate need for their use. However, this narrow conception has been increasingly challenged by research in human–AI interaction.

Siddharth Mehrotra et al. provide a useful overview of the complexity of different approaches to ensuring appropriate trust in technical literature. From their review of the literature, they note that the approaches focus on confidence scores, explanations, cues, alarms, warning signals and uncertainty communication.[16] Some of the approaches seem particularly relevant for militaries applications of AI. For example, Q Vera Liao and S Shyam Sundar argue (emphasis in original):

Trustworthiness of a technology is not inherently established but communicated through trustworthiness cues, which are embedded in interface features, documentation, and other modes of information, such as speech acts for conversational AI.[17]

These cues are especially relevant in safety-critical contexts as they shape the way in which decisions could be made in time-compressed environments such as conflict zones.

Importantly, Mehrotra et al. point to the fact that recent research on human–AI interaction further complicates the notion of ‘appropriate’ or calibrated trust.[18] Some of the literature has implicitly equated calibration with system accuracy, distinguishing over-trust from under-trust based on whether AI outputs are correct.[19] However, this approach has been increasingly challenged. Trust cannot be reduced to correctness alone; rather, it is shaped by a range of factors, including perceived reliability, transparency, interpretability, prior interactions and users’ cognitive and emotional engagement with the system.[20]

This multi-dimensional understanding of trust has important implications for military AI. In operational contexts characterised by uncertainty, time pressure and adversarial interference, trust is not static but dynamic. It must adapt to changing system performance, environmental conditions and task requirements. A system that performs reliably in one context may degrade in another, requiring operators to continuously recalibrate their expectations and reliance. Yet existing literature provides limited guidance on how such recalibration occurs over time, particularly in long-term or high-stakes deployments.[21]

At the 2024 REAIM Summit in Seoul, experts such as Missy Cummings noted the need for certification and recertification of systems in order to address concerns about using the technology beyond the contexts it has been trained and tested for. Vincent Boulanin and Dustin A Lewis similarly emphasise the importance of ‘responsible reliance’ in ensuring accountability for the use of military AI systems.[22] They argue that states must:

devise and maintain a framework that ensures that natural persons involved in the development and use of a military AI tool can responsibly rely on the tool’s technical aspects, on the other members of the group and on the state itself.[23]

As a result, responsible reliance must be maintained across the lifecycle of AI-enabled capabilities and embedded within the broader organisational and political structures that govern their development, deployment and use.

Moreover, many military decisions are not binary but involve probabilistic assessments, trade-offs and incomplete information. In such cases, identifying over- or under-trust becomes significantly more complex, as there are no clear benchmarks for ‘correct’ reliance. Indeed, in many military contexts it may be neither practical nor desirable to establish these fixed benchmarks. Instead, decisions about whether and how to rely on a particular system are likely to depend on contextual understanding, operational judgement and applicable legal requirements. This underscores the need to move beyond simplified models of trust calibration and towards more context-sensitive approaches that account for the specific characteristics of tasks and decision environments.

These insights reinforce the argument advanced in this article: trust in military AI cannot be treated as a fixed or purely technical attribute. Rather, it is a dynamic, multi-dimensional relationship that must be continuously shaped through system design, organisational practice and broader governance frameworks.

Beyond organisational and technical considerations, trust in military AI must also be understood as a political construct. As Sian Troath (2024) argues, the growing emphasis on ‘trustworthy’ and ‘ethical’ AI in military contexts is not neutral but can function to facilitate the development and adoption of AI-enabled and autonomous systems while deflecting attention from more fundamental political questions. Troath notes that these include who such systems are used against, under what conditions and for what strategic purposes.[24] In this sense, trust operates not only as a relational property between users and systems but also as part of a broader discourse that can legitimise particular forms of technological development and military practice.[25] The coupling of ‘trust’ with ‘ethics’ risks narrowing debate to questions of how systems function, rather than whether their use is justified in specific contexts.

For military AI, this raises an important analytical and normative challenge. Efforts to design for trust must avoid becoming mechanisms that facilitate uncritical adoption or obscure political accountability. Instead, trust should be understood as contingent, limited and subject to ongoing scrutiny. The TbD+ framework is therefore positioned as a means not of maximising trust but of constraining and calibrating it. By embedding mechanisms that expose system limitations, reinforce human agency and support oversight, the framework seeks to ensure that trust remains proportionate to system capabilities and embedded within broader processes of political and legal accountability.

Core Principles of Trust by Design

In order to fully build out the TbD+ framework, it is necessary to understand the conceptualisation by scholars focused on the issue in human–robot industrial research. The framework is particularly useful to military AI applications as it provides a structured approach to embedding trustworthiness into system design.

At its core, the TbD framework conceived by Merchán-Cruz et al. for industrial human–robot collaboration identifies several interrelated design logics that are particularly salient when adapted to military AI. First, it foregrounds human agency and empowerment, ensuring that AI systems augment rather than replace human judgement. This includes preserving the capacity for operators to interrogate, adjust and override system outputs, particularly in high-stakes contexts involving the use of force. Second, it emphasises transparency and interpretability not as abstract principles but as functional requirements that allow users to understand system behaviour, assess uncertainty and anticipate outcomes. Third, it highlights the importance of robustness and safety, including fail-safe mechanisms, predictable performance and the visibility of system limitations under varying conditions.

In addition, the framework incorporates accountability and traceability, ensuring that decisions and actions can be reconstructed and evaluated, as well as data governance and fairness, addressing the ethical implications of data use and potential bias. Finally, it underscores the role of user integration and training, recognising that trust is shaped through repeated interaction, organisational context and user competence, rather than design alone. Yet, within military contexts the challenge is not simply articulating such principles but determining how they are operationalised across the lifecycle of capabilities. Human agency, transparency and accountability must therefore be translated into concrete practices of testing, validation, oversight, doctrine and operational governance if they are to shape the use of AI systems in practice rather than remaining aspirational design goals.

Trust by Design Plus (TbD+)

The trust by design plus (TbD+) framework builds on the above work while addressing its limitations in military contexts. While frameworks such as the European Commission’s Ethics Guidelines for Trustworthy AI and related defence policy documents emphasise principles such as transparency, accountability and human oversight, they often treat trustworthiness as a set of desirable system attributes rather than as a dynamic and relational condition. TbD+ extends these approaches by integrating technical, organisational and political dimensions of trust, recognising that trust in military AI is constructed across multiple levels of interaction and shaped by broader strategic contexts.

The framework is guided by principles across three levels: systems level, organisational level and interstate level. At the system level, the framework focuses on the design features and technical characteristics that condition human interaction with AI systems. Drawing on the TbD literature, this includes human agency and empowerment, transparency and interpretability, and robustness and safety. In military contexts, these elements take on heightened significance: systems must not only perform reliably but also make their limitations visible, support operator understanding under time pressure and enable meaningful human intervention in high-stakes decisions. Crucially, these features do not produce trust directly. Rather, they shape the conditions under which users form expectations, assess uncertainty and adjust reliance.

At the organisational level, TbD+ extends beyond system design to consider the institutional context in which AI systems are deployed. Here trust is shaped by doctrine, training, oversight mechanisms and professional norms that structure human–machine interaction. Organisational practices determine how responsibility is allocated, how uncertainty is managed and how human agency is preserved or eroded in operational settings. This dimension is particularly important in mitigating well-documented risks such as automation bias, over-reliance and the diffusion of responsibility in complex socio-technical systems.

The organisational dimension raises a broader set of institutional questions that military organisations must address if trust in AI-enabled capabilities is to be appropriately calibrated in practice. These include how operational responsibility and accountability are distributed across chains of command; how professional military judgement is maintained under conditions of increasing automation and compressed decision-making timelines; and how doctrine, procurement and capability development processes shape the integration of AI into operational environments.[26] TbD+ also raises questions regarding how organisations identify where human agency remains essential, how operators are trained to understand system limitations and uncertainty and how institutional incentives may encourage either excessive reliance on or resistance to AI-enabled systems.

Additional organisational challenges include ensuring interoperability and shared understandings of trust across different services, commands and allied forces; integrating civilian and military oversight mechanisms; managing adaptation as systems evolve over time; and determining how lessons from operational use, failure and near misses are incorporated back into training, testing and governance processes. In this sense, trust at the organisational level is a matter not simply of user confidence but of institutional capacity to govern human–machine interaction responsibly across the lifecycle of AI-enabled capabilities.

At the interstate level, the framework situates trust within broader strategic and political dynamics. In this domain, claims of ‘trustworthy AI’ function as signals that are interpreted by other states under conditions of uncertainty. Realising this dimension of TbD+ in practice requires far deeper integration between international policy discussions, capability development processes and the operational governance of AI-enabled systems than currently exists. This includes linking emerging norms and political commitments to concrete practices of testing, evaluation, doctrine, procurement and operational oversight across the lifecycle of capabilities. Given current geopolitical tensions, this may be the most difficult element of TbD+ to operationalise, yet it is also increasingly important both for enabling interoperability and shared understandings among allies and for reducing risks of miscalculation and escalation with adversarial states.

Trust is not directly observable but is inferred through practices such as transparency measures, information-sharing and adherence to emerging norms. At the same time, these signals are inherently ambiguous and subject to contestation. As a result, trust in military AI is not only a technical or organisational matter, but also a political one, shaped by strategic incentives, competing narratives and the risk of misinterpretation. Importantly, these principles across the three levels are not intended to generate trust in any straightforward sense. Rather, they function as constraints that define the conditions under which trust may be considered warranted. This distinction is critical in light of concerns that trust can be instrumentalised as a means of facilitating the adoption of AI systems without adequately addressing their risks or broader implications.

TbD+ therefore reframes trust not as an output of system design but as a condition of use that must be governed across time, context and interaction. It emphasises that trust cannot be calibrated solely through system accuracy or static design features. Instead, trust must be continuously evaluated and, where necessary, recalibrated based on system performance, user experience, organisational practice and the evolving strategic environment. In this sense, TbD+ aligns with a broader shift away from technocratic understandings of trust towards an approach that recognises its dynamic, relational and inherently political character.

A Lifecycle Approach: Operationalising Trust by Design Plus

For the TbD+ framework to be operationally useful, it must be implemented alongside a lifecycle approach to military AI governance. Lifecycle governance has become increasingly prominent in discussions on responsible military AI and autonomous weapons because it recognises that issues of human control, judgement and agency cannot be addressed at a single point in the development process but must instead be considered throughout the evolution of an AI-enabled capability.[27] Reflecting this shift, the Institute of Electrical and Electronics Engineers (IEEE) 2024 White Paper on Military Autonomous and Intelligent Systems (AIS) identifies nine interconnected stages spanning the capability lifecycle, from pre-development planning and system requirements through research and development, procurement, TEVV, human–system integration, operational employment, and ultimately review, reuse, or retirement.[28]

This lifecycle perspective reinforces a central premise of TbD+: trust is not an inherent property of an AI system; nor is it established at a single point in time. Rather, appropriately calibrated trust is constructed, assessed, maintained and, where necessary, recalibrated throughout the lifecycle as systems are designed, tested, integrated, deployed, operated, adapted and ultimately retired. During the early stages of capability development, this includes identifying legal, ethical, and operational risks, defining intended use and incorporating user-centred design principles. During TEVV, it involves evaluating not only technical performance but also human–machine interaction, operator understanding, and the calibration of reliance under realistic operational conditions. Deployment and operational use require appropriate training, doctrine, leadership and continuous monitoring of both system performance and human behaviour, while review and retirement provide opportunities to capture lessons learned and feed them back into future capability development and governance.

This lifecycle perspective also recognises that trust is dynamic rather than static. It may increase, decrease or fluctuate depending on system performance, operational context and organisational practice. Systems that perform reliably in one environment may perform differently in another, requiring operators and organisations to continually reassess and recalibrate their reliance. Appropriately calibrated trust therefore depends not only on technical design but also on institutional arrangements, including doctrine, oversight, professional education and mechanisms for organisational learning.

Table 1 outlines selected considerations for implementing the TbD+ framework across the IEEE military AI lifecycle. Given the diversity of state requirements, operational contexts and approaches to military AI governance, it is intended as an illustrative guide rather than a comprehensive or prescriptive checklist.

Table 1. Implementing TbD+ across the IEEE military AI lifecycle
IEEE military AI lifecycle stage System level Organisational level Interstate level
Requirements Define intended use, human decision points and acceptable limits of autonomy. Establish operational need, allocate responsibilities and identify risks to human judgement. Align with international commitments and interoperability objectives.
Design and development Build transparency, interpretability, robustness and fail-safe mechanisms into the system. Set procurement criteria, involve users in design reviews, and plan training and change management. Design for compatibility with allies and consider export controls and responsible transfer.
TEVV Test technical performance, safety and limitations; evaluate human–machine interaction and calibration. Conduct human–machine teaming exercises, assess operator performance and document lessons. Use agreed testing approaches; share non-sensitive methodologies and results where appropriate.
Integration Ensure usable interfaces, human override and integration with existing systems. Deliver training; update doctrine, roles and authorities. Ensure interoperability and shared understandings with allied forces.
Deployment Confirm system readiness and operational safeguards. Certify operators; establish rules of engagement and command responsibilities. Communicate capability intent and appropriate use; support confidence-building.
Operations Monitor performance in context; communicate uncertainty and support operator calibration. Monitor use, collect feedback, manage risks (e.g. automation bias, over-reliance) and adapt training. Engage in information sharing where appropriate; maintain strategic signalling and stability.
Maintenance and updates Update models and data; re-test and validate changes. Manage configuration control; update doctrine and training; ensure oversight of updates. Notify allies/partners of significant changes where appropriate.
Incident review and learning Conduct technical root-cause analysis; identify contributing factors. Conduct accountability review; capture lessons from incidents and near misses. Share lessons and best practices; contribute to norm development where appropriate.
Retirement/disposal Securely decommission systems and preserve audit trails. Capture knowledge and documentation; manage workforce transition. Provide transparency on retirement/disposal where appropriate.
Across all stages Apply human agency, transparency, robustness, safety and accountability principles. Maintain governance, oversight, training and institutional learning. Support international law, interoperability and confidence-building measures.

Importantly, TbD+ does not resolve the broader political question of whether and under what conditions military AI should be deployed. Rather, it operates within these constraints, recognising that technical and governance interventions cannot substitute for political judgement. At the same time, the framework is intended to help inform such judgements by providing a structured approach for assessing where human agency is essential, how trust can be appropriately calibrated and what forms of testing, oversight and organisational governance are required across the lifecycle of AI-enabled capabilities. In this sense, TbD+ seeks not to legitimise the expansion of AI-enabled warfare but to govern and constrain the conditions under which such systems may be considered appropriate for use.

Trust and Confidence Building at the Interstate Level

Trust in military AI extends beyond technical and organisational dimensions to encompass interstate dynamics and broader political considerations. As Troath observes, the logic of ‘trust but verify’ captures a defining feature of international security and arms control: trust must be grounded in observable practices rather than rhetorical commitments.[29] Dialogue and information-sharing are therefore not neutral confidence-building exercises but mechanisms through which states seek to produce, interpret and contest evidence about each other’s behaviour.

This dynamic reflects core insights from international relations theory, where trust is not assumed but inferred through signalling, interpretation and repeated interaction under conditions of uncertainty, as outlined by Andrew Kydd.[30] From this perspective, claims of ‘trustworthy AI’ are not simply technical descriptors but strategic interventions that can shape expectations, frame acceptable uses of technology and potentially narrow political debate. As such, they must be approached with caution: rather than serving as straightforward indicators of responsible behaviour, they are themselves subject to interpretation, contestation and, at times, instrumentalisation.

Building on this understanding, confidence-building measures remain an important, if inherently limited, mechanism for managing uncertainty and mitigating risks of miscalculation in the development and deployment of military AI.[31] Such measures may include mutual declarations in which states affirm shared principles, such as the maintenance of human control in the use of force; the establishment of incident notification protocols or dedicated communication channels to clarify AI-related errors or unintended behaviour before they escalate; and the development of joint or comparable approaches to testing and evaluation standards, aimed at reducing the risks associated with system brittleness or unpredictability.[32] At the same time, declarations alone are insufficient to establish trust. Their credibility ultimately depends on whether subsequent state practice consistently reflects and reinforces the commitments being made. In this sense, confidence-building measures should be understood less as guarantees of responsible behaviour than as mechanisms through which states generate evidence, signal intentions and enable ongoing assessment of whether stated commitments are borne out in practice.

In addition, capacity-sharing initiatives may support the development of responsible governance frameworks across a wider range of states, helping to reduce asymmetries that could otherwise contribute to instability. Michael Horowitz notes that at least some of these measures might be achievable. Horowitz points out:

The military AI areas most likely to generate agreements, on average, will be those where international cooperation can reduce accidents, inadvertent escalation and miscalculation involving military applications of AI, since these are in the interest of all or nearly all countries.[33]

However, consistent with the analysis above, these measures should not be understood as generating trust in any straightforward sense. Rather, they function as mechanisms for structuring expectations, enabling interpretation and constraining uncertainty within an inherently competitive and politically contested environment. As a result, their effectiveness will depend not only on their design but on the extent to which they are embedded in sustained practices of engagement and subject to ongoing scrutiny. It is also worth recognising that poorly designed or implemented confidence-building measures may unintentionally undermine trust by creating ambiguity, unrealistic expectations or strategic suspicion among states.

Conclusion

This article makes a conceptual contribution by reframing trust in military AI as neither a purely technical property nor a stable relational outcome but as a dynamic and politically situated process. Existing approaches often treat trust as something to be engineered through system design or measured through user reliance. By contrast, this article argues that an architecture of trust is multi-dimensional, context dependent and continuously evolving across human–machine interaction, organisational practice and interstate dynamics. Building on this insight, the proposed TbD+ framework shifts the focus from maximising trust to constraining and calibrating it. In doing so, it brings together technical, organisational and political perspectives demonstrating that trust in military AI must be governed as an ongoing condition of use rather than assumed as a prerequisite for adoption. Additional research and study is needed to examine the proposed framework.

At the same time, the political dimensions of trust extend beyond interstate dynamics alone. The broader ‘trust ecosystem’ surrounding military AI includes relationships between industry, military organisations, governments, academia, civil society and the public, as well as differing layers of trust within military institutions themselves, including between services and between military and civilian elements. These relationships shape how AI-enabled capabilities are developed, interpreted, adopted and contested across the lifecycle of use. Future research should therefore examine how the TbD+ framework and its lifecycle approach may assist both researchers and practitioners in navigating this wider trust ecosystem, including how trust is negotiated, maintained and challenged across institutional, societal and strategic contexts over time.

In addition, the maintenance of human agency is critical to ensuring appropriately calibrated trust, avoiding both over-reliance on AI-enabled systems and susceptibility to automation bias or related cognitive effects in AI-supported decision-making. This requires militaries to first identify where and how human agency is currently exercised, and where it remains essential, before effective safeguards can be designed to preserve it. Existing command-and-control structures often implicitly assume full human participation across intelligence, decision-making and teaming functions, an assumption that may be increasingly challenged as AI systems take on more operational and cognitive tasks. This is particularly relevant given the growing role of AI decision-support systems and recognition of the impact on human roles and responsibilities in human-machine teaming.[34]

Ultimately, the challenge is to determine when, to what extent and under what conditions specific AI-enabled systems should be trusted in particular operational contexts. By reframing trust as a dynamic, constrained and politically situated relationship, this article contributes to a growing body of work that seeks to move beyond technocratic optimism towards a more grounded understanding of AI in military contexts.[35] In doing so, it highlights that the governance of military AI is a question not only of capability but of judgement, restraint and responsibility. As contemporary cases of AI-enabled warfare are demonstrating, there is a pressing need to consider the purposes and consequences of using AI-enabled systems.

Endnotes

[1] Michael C Horowitz, Artificial Intelligence, the Future of War and International Politics, CIGI Papers No. 345 (CIGI, 2026).

[2] Robert Booth and Dan Milmo, ‘Iran War Heralds Era of AI-Powered Bombing Quicker than “Speed of Thought”’, The Guardian, 3 March 2026.

[3] European Defence Agency, Trustworthiness for AI in Defence: Developing Responsible, Ethical, and Trustworthy AI Systems for European Defence (European Defence Agency, 2025), pp. 12–13).

[4] Roff, Heather M., and David Danks. 2018. “‘Trust but Verify’: The Difficulty of Trusting Autonomous Weapons Systems.” Journal of Military Ethics 17 (1): 2–20. doi:10.1080/15027570.2018.1481907.; Tim McFarland, ‘Reconciling Trust and Control in the Military Use of Artificial Intelligence’, International Journal of Law and Information Technology 30, no. 4 (2022): 472–483; Sian Troath, ‘Trusting Technology to Wage War: The Politics of Trust and Ethics in the Development of Robotics, Autonomous Systems, and Artificial Intelligence’, Critical Military Studies 11, no. 1 (2025): 59–77; Branka Marijan, Trust by Design? AI in Military Applications, CIGI Policy Brief no. 218 (CIGI, 2025); Paul Lushenko, ‘AI, Trust, and the War Room: Evidence from a Conjoint Experiment in the US Military’, Cambridge Forum on AI: Law and Governance 1: e52 (2025).

[5] Lushenko, ‘AI, Trust, and the War Room’, p. 2.

[6] Emmanuel A Merchán-Cruz, Ioseb Gabelaia, Mihails Savrasovs, Mark F Hansen, Shwe Soe, Ricardo G Rodriguez- Cañizo and Gerardo Aragón-Camarasa, ‘Trust by Design: An Ethical Framework for Collaborative Intelligence Systems in Industry 5.0’, Electronics 14, no. 10 (2025): 1952.

[7] Ingvild Bode and Katherine Chandler, ‘Re-Thinking Human–Machine Interaction and the Governance of AI in the Military Domain’, Nature Machine Intelligence 8 (2026).

[8] S Krüger and C Wilson, ‘The Problem with Trust: On the Discursive Commodification of Trust in AI’, AI & Society 38 (2023): 1753–1761; Roy Lindelauf and Herwin Meerveld, ‘Building Trust in Military AI Starts with Opening the Black Box’, War on the Rocks, at: https://warontherocks.com/2025/08/buildingtrust-in-military-ai-starts-with-opening-the-black-box.

[9] McFarland, ‘Reconciling Trust and Control in the Military Use of Artificial Intelligence’.

[10] Ibid., p. 477.

[11] Ibid., p. 480

[12] Lindelauf and Meerveld, ‘Building Trust in Military AI Starts with Opening the Black Box’.

[13] Australian Defence Force and Department of Defence, Policy Settings for Responsible Use of Artificial Intelligence in Defence: Responsible Use of AI at All Stages of the Technology Lifecycle (Canberra: Commonwealth of Australia, 2026), p. 5.

[14] Alon Jacovi, Ana Marasović, Tim Miller and Yoav Goldberg, ‘Formalizing Trust in Artificial Intelligence: Prerequisites, Causes and Goals of Human Trust in AI’, in Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency (Association for Computing Machinery, 2021), pp. 624–35.

[15] Ingvild Bode, Human-Machine Interaction and Human Agency in the Military Domain, CIGI Policy Brief no. 193 (Waterloo ON: CIGI, 2025).

[16] Siddharth Mehrotra, Chadha Degachi, Oleksandra Vereschak, Catholijn M Jonker and Myrthe L Tielman, ‘A Systematic Review on Fostering Appropriate Trust in Human-AI Interaction: Trends, Opportunities and Challenges’, ACM Journal on Responsible Computing 1, no. 4, article 26 (2024), p. 4.

[17] Q Vera Liao and S Shyam Sundar, ‘Designing for Responsible Trust in AI Systems: A Communication Perspective’, in Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency (Association for Computing Machinery, 2022), pp. 1257–1268.

[18] Mehrotra et al., ‘A Systematic Review on Fostering Appropriate Trust in Human-AI Interaction’.

[19] Lee, John D., and Katrina A. See. 2004. “Trust in Automation: Designing for Appropriate Reliance.” Human Factors 46 (1): 50–80. https://doi.org/10.1518/hfes.46.1.50_30392

[20] Liao and Sundar, ‘Designing for Responsible Trust in AI Systems’.

[21] Mehrotra et al., ‘A Systematic Review on Fostering Appropriate Trust in Human-AI Interaction’.

[22] Vincent Boulanin and Dustin A Lewis, ‘Responsible Reliance Concerning Development and Use of AI in the Military Domain’, Ethics and Information Technology 25, no. 8 (2023).

[23] Ibid.

[24] Troath, ‘Trusting Technology to Wage War’.

[25] Daniel Møller Ølgaard, ‘The New Technopolitics of War: (Re)imagining Agency and Authority in Military Affairs’, Global Policy 16, no. 3 (2025).

[26] Netta Goussac, ‘Responsible Behaviour in Military AI Starts with Responsible Procurement’, SIPRI (website), at: www.sipri.org/commentary/essay/2025/military-ai-responsible-procurement.

[27] Zena Assaad and Jessica Dorsey, ‘Designing Lawful Military AI: Technical and Legal Reflections on Decision-Support and Autonomous Weapon Systems’, Perry World House (website), at: https://perryworldhouse.upenn.edu/news-and-insight/designing-lawful-military-ai-technical-and-legal-reflections-on-decision-support-and-autonomous-weapon-systems.

[28] IEEE SA Research Group on Issues of Autonomy and AI in Defense Systems, A Framework for Human Decision Making Through the Lifecycle of Autonomous and Intelligent Systems in Defense Applications (New York NY: IEEE SA, 2024).

[29] Troath, ‘Trusting Technology to Wage War’.

[30] Kydd, Andrew H. 2005. Trust and Mistrust in International Relations. Princeton, NJ: Princeton University Press.

[31] Michael C Horowitz, Lauren Kahn and Casey Mahoney, ‘The Future of Military Applications of Artificial Intelligence: A Role for Confidence-Building Measures?’, Orbis 64, no. 4 (2020): 528–543.

[32] Ioana Puscas, Confidence-Building Measures for Artificial Intelligence: A Framing Paper (Geneva: United Nations Institute for Disarmament Research, 2022).

[33] Horowitz, Artificial Intelligence, the Future of War and International Politics, p. 2.

[34] Jessica Dorsey and Marta Bo. ‘AI-Enabled Decision-Support Systems in the Joint Targeting Cycle: Legal Challenges, Risks, and the Human (e) Dimension’, International Law Studies 106 (2025); Zena Assaad, ‘A Risk-Based Trust Framework for Assuring the Humans in Human-Machine Teaming’, TAS ‘24: Proceedings of the Second International Symposium on Trustworthy Autonomous Systems, no. 3 (New York NY: Association for Computing Machinery, 2024): pp. 1–9.

[35] Neil Renic and Elke Schwarz, ‘Crimes of Dispassion: Autonomous Weapons and the Moral Challenge of Systematic Killing’, Ethics & International Affairs 37, no. 3 (2023): 321–343.