Skip to content

The Devolution of Trust: Have We Opened Pandora’s Box?

Bill Nelson Sep 22, 2026

Trust is a fascinating thing. It takes years to build, seconds to destroy, and sometimes a lifetime to restore.

Throughout human history, trust has been fundamental to our survival. It has enabled us to form communities, establish relationships, conduct business, and build civilizations. Without trust, cooperation becomes difficult, commerce becomes risky, and society itself begins to fracture.

Yet, when I look at the world today, I find myself asking a rather uncomfortable question. Have we become so focused on making life easier that we have inadvertently made it harder to trust anyone or anything?

Technology has given us extraordinary capabilities. We can communicate with someone on the other side of the planet in seconds, transfer millions of dollars with a few keystrokes, and access virtually all of humanity's accumulated knowledge from a device in our pocket. We have never been more connected.

But are we any more trusting? I would argue that, in many ways, the opposite is true.

And to understand how we got here, we need to look at how trust itself has evolved.

In the beginning, trust was personal

Imagine a time before written contracts, financial institutions, governments, or even established currencies.

Human beings lived in relatively small communities where survival depended on cooperation. Trust was established through personal relationships, shared experiences, and reputation. You knew the people you depended on. You understood their behavior because you had observed it firsthand.

If someone promised to help you hunt, share food, or protect your family, you had a reasonable basis for deciding whether to believe them. Their actions established their reputation.

And because communities were small, violating that trust could have significant consequences. A person who repeatedly deceived others might find themselves excluded from the very relationships they needed to survive.

Of course, this was hardly a perfect system. Deception, betrayal, and exploitation have existed for as long as humanity itself. But trust had something that we seem to be losing today. It had a direct connection to personal accountability.

You knew who you were dealing with, and they knew that their actions could affect their standing in the community.

As civilization grew, trust became institutional

As communities expanded into towns, cities, and eventually nations, personal relationships were no longer sufficient. We needed ways to establish trust between people who had never met.

We developed currencies, contracts, laws, courts, banking systems, and governments. Rather than personally knowing everyone with whom we conducted business, we began relying on institutions to establish and enforce trust.

Consider the simple act of depositing money in a bank. You hand over something of value in exchange for a promise that it will be there when you need it. You trust the bank to protect your money. You trust regulators to oversee the bank. You trust the legal system to provide recourse if something goes wrong.

Trust was no longer simply a relationship between two individuals. It became a relationship between individuals and the institutions responsible for protecting their interests. This allowed commerce and society to grow on an extraordinary scale.

But it also introduced a new vulnerability. What happens when the institutions we depend on fail to honor that trust? And what happens when the people responsible for holding those institutions accountable are themselves no longer trusted?

Then came the digital revolution

The digital revolution fundamentally changed the way we live and conduct business.

We no longer needed to visit a bank to transfer money, walk into a store to purchase something, or sit across from someone to establish a business relationship. The internet removed geographical barriers and introduced an entirely new level of convenience. We could transact with people and organizations we had never met, in places we had never visited, at virtually any time of the day.

From a business perspective, the benefits were enormous. Organizations could reach global markets, automate processes, reduce operating costs, and deliver services at a scale that previous generations could scarcely have imagined.

And as consumers, we embraced it. Why wouldn't we? Convenience is a powerful motivator.

But something interesting happened along the way. We began replacing personal and institutional trust with technological mechanisms designed to simulate it.

Passwords, digital certificates, encryption, identity verification, authentication systems, and access controls became the mechanisms through which we established whether someone or something should be trusted. We no longer needed to know the person on the other end of a transaction. We simply needed the technology to tell us that the transaction was legitimate.

And for a while, that seemed like a reasonable trade. Until we began discovering just how easily those mechanisms could be exploited.

The erosion of trust in a digital world

Think about how we interact with the world today.

We receive an email from our bank asking us to verify a transaction. Is it legitimate, or is someone trying to steal our credentials? We receive a text message from a delivery service asking us to update our address. Is there actually a package waiting for us?

Our phone rings, and the caller ID displays the name of someone we know. Can we trust that the person calling is actually who they claim to be?

We watch a video of a public figure making a controversial statement. Did they actually say it, or was the video manipulated? We read an article published by a seemingly reputable organization. Is the information accurate, selectively presented, or entirely fabricated?

The unfortunate reality is that we can no longer take many of these things at face value.

And the irony is difficult to ignore. We developed technology to simplify our lives, yet we now spend an extraordinary amount of time trying to determine whether the technology we are using can be trusted.

We have introduced multifactor authentication, fraud detection, identity verification, digital signatures, and increasingly sophisticated cybersecurity systems. Each new layer of protection addresses a legitimate problem. But each also reminds us that the previous layer of trust was insufficient.

We have reached a point where the simple act of answering a telephone call from an unfamiliar number can require a conscious decision about whether we are exposing ourselves to fraud.

How did we get here? And perhaps more importantly, have we accepted this as the new normal?

When convenience becomes a substitute for trust

I have spent much of my professional career working with organizations to establish and manage digital identities. At its core, identity and access management is about answering some very fundamental questions.

Who are you? How do I know you are who you claim to be? What should you be allowed to do? And how can I be confident that you will only do what you are authorized to do?

These questions are not new. Human beings have been asking variations of them for thousands of years. What has changed is the environment in which we must answer them.

Historically, we could establish trust through personal relationships, physical presence, and institutional accountability. Today, we often attempt to establish that same trust through a collection of digital attributes, credentials, and automated decisions.

We authenticate someone using a password, a biometric characteristic, or a cryptographic credential. We authorize their access based on a collection of roles, policies, and entitlements. We monitor their activities to identify potentially suspicious behavior.

And we call this security. But security and trust are not necessarily the same thing.

A system can successfully authenticate an individual without establishing that the individual is trustworthy.

A legitimate employee can misuse authorized access. A compromised account can satisfy certain authentication requirements. A perfectly valid digital identity can be used to carry out an entirely illegitimate transaction.

Technology can help us establish identity, evaluate risk, and enforce accountability. But it cannot eliminate the human element of trust.

And I wonder whether, in our enthusiasm to digitize everything, we have gradually lost sight of that distinction.

Artificial intelligence changes the equation

Just when we thought we were beginning to understand the challenges of establishing trust in a digital world, artificial intelligence arrived and introduced an entirely new dimension.

For most of human history, we have relied on our senses and our ability to reason to determine whether something is real. We could listen to someone's voice, look at a photograph, watch a video, or read a document and make a reasonable judgment about its authenticity. Those methods were never infallible, but they provided a foundation upon which we could form opinions and make decisions.

Artificial intelligence is challenging that foundation.

Today, technology can generate remarkably convincing images, videos, audio recordings, and written content. It can imitate someone's voice, reproduce their appearance, and generate statements they never made. It can produce a convincing explanation of an event that never occurred. And it can do so at a speed and scale that would have been unimaginable just a few years ago.

Consider the implications for executive leadership.

Imagine receiving a video message from your CEO directing you to authorize a significant financial transaction. The individual looks like your CEO. The voice sounds like your CEO. The message references legitimate business activities.

But the person in the video is not your CEO. How do you establish trust?

Now extend that question beyond financial transactions.

What happens when we can no longer distinguish between an authentic historical recording and an artificially generated one? What happens when a fabricated statement can be attributed to someone who never made it? What happens when the information we use to make decisions has been selectively altered, intentionally manipulated, or generated entirely by a machine? George Orwell imagined a version of this in 1984, where the historical record could be continuously rewritten until yesterday’s truth simply became today’s fiction. The difference is that Orwell needed a Ministry of Truth to accomplish it. Today, we may only need an algorithm. 

We are entering a world in which seeing is no longer necessarily believing. And that should concern all of us.

When the truth itself becomes negotiable

There is another dimension to this discussion that I believe deserves considerably more attention.

Trust depends on our ability to establish a common understanding of reality. We do not necessarily need to agree on the interpretation of every fact. In fact, questioning established beliefs and challenging conventional wisdom are essential to human progress. But there is an important distinction between questioning our understanding of the facts and deliberately manipulating the facts themselves.

Throughout history, individuals and institutions have attempted to influence how events are recorded, interpreted, and remembered. That is nothing new.

What is new is the extraordinary ability of digital technology to modify, distribute, and reinforce information at a global scale.

Consider how much of our understanding of the world now comes from digital sources. Our news, historical records, educational materials, scientific research, financial information, and even personal memories increasingly exist in digital form.

We rely on search engines, social media platforms, online publications, and now artificial intelligence to help us understand what is happening around us. But who controls the information these systems present? Who determines which information is relevant? Who decides which sources are credible?

And how do we distinguish between information that has been verified, information that is generally accepted, and information that has simply been repeated so often that we have come to believe it?

There is a fundamental difference between a fact, an interpretation of that fact, and an opinion based on that interpretation. Yet, in our digital world, those distinctions can become increasingly difficult to recognize.

Algorithms can reinforce our existing beliefs by continually presenting information that aligns with our interests and perspectives. Artificial intelligence can produce convincing answers without necessarily providing the evidence needed to establish their accuracy.

And when an incorrect statement is repeated across enough digital sources, it can begin to acquire the appearance of credibility.

The danger is not simply that we might believe something that is untrue. It is that we may gradually lose confidence in our ability to determine what is true in the first place.

If we can no longer agree on the underlying facts, how can we establish the trust necessary to make informed decisions?

This is not just a technological problem. It is a societal problem. And it is a leadership problem.

The paradox of Zero Trust

There is an interesting parallel between this broader erosion of trust and the direction in which cybersecurity has evolved.

For years, organizations operated under a relatively simple security model. Once an individual had successfully authenticated and gained access to the corporate network, they were often granted a level of implicit trust.

We eventually recognized the limitations of that approach. A person who was trustworthy yesterday might have their credentials compromised today. A device that was secure this morning might become vulnerable this afternoon.

As a result, the industry began adopting what we now call Zero Trust.

The fundamental principle is that access should not be granted solely because an individual or device is already inside a trusted environment. Instead, identity, authorization, device posture, and other relevant signals should be evaluated continually and according to the risk associated with the requested activity.

From a cybersecurity perspective, this is a logical evolution. But consider the broader implications.

We have developed a security philosophy built around the idea that implicit trust is no longer sufficient. And in many ways, that same philosophy is beginning to influence how we interact with the world around us.

We question the authenticity of our communications. We question the accuracy of the information we consume. We question whether the person on the other end of a digital interaction is actually who they claim to be.

We are increasingly being asked to verify everything.

But there is a significant difference between applying Zero Trust principles to a computer system and attempting to live in a society where nobody trusts anybody.

A computer system can evaluate credentials, policies, and risk signals. Human relationships require something more.

They require honesty, accountability, consistency, and a willingness to act in the interests of others. We cannot simply deploy another authentication mechanism and expect those qualities to emerge.

What does this mean for executive leadership?

For those of us responsible for leading organizations, I believe the implications extend far beyond cybersecurity.

Trust is fundamental to virtually every aspect of business. Our customers must trust us with their personal information, financial transactions, and business relationships. Our employees must trust that leadership will communicate honestly, make informed decisions, and act with integrity.

Our business partners must trust that we will honor our commitments. And our shareholders must trust that the information we provide accurately represents the state of the organization.

Technology can support each of these relationships. But technology alone cannot establish them.

As we continue investing in digital transformation and artificial intelligence, perhaps we should begin asking some different questions.

Questions worth asking

1. Are we making it easier to do business with our organization, or are we simply transferring the burden of establishing trust to our customers?

2. When we introduce a new digital capability, do we evaluate its impact on trust with the same rigor that we evaluate its financial return?

3. Can we demonstrate the authenticity and integrity of the information upon which our most important business decisions depend?

4. As we delegate more decisions to artificial intelligence, who remains accountable when those decisions are wrong?

5. Are we building systems that help people make informed decisions, or are we gradually conditioning them to accept whatever the technology tells them?

6. If our customers, employees, or business partners lose confidence in our digital systems, what mechanisms do we have to restore that confidence?

These are not questions that can be answered exclusively by the CIO, CISO, or technology organization. They are questions that require the attention of the entire executive leadership team.

Because while cybersecurity can help protect an organization from a breach, restoring trust after it has been lost is an entirely different challenge.

Can we put the genie back in the bottle?

I sometimes wonder whether we have reached a point where the very technologies that have made our lives easier have fundamentally changed our relationship with trust.

We have willingly traded personal interactions for digital convenience. We have delegated decisions to systems we do not fully understand. We have entrusted our personal information to organizations we have never visited and individuals we have never met.

And we are now beginning to entrust our understanding of reality to artificial intelligence.

I am not suggesting that we abandon technology or attempt to return to a world that no longer exists. The benefits of digital transformation are undeniable, and artificial intelligence has the potential to deliver extraordinary advances in virtually every industry.

But progress should not require us to surrender our ability to establish what is real, determine who is accountable, or make informed decisions for ourselves.

Perhaps restoring trust begins with recognizing that it cannot be reduced to a technological problem.

We need systems that provide transparency and verifiable evidence. We need organizations that accept responsibility for the decisions made by the technologies they deploy. We need individuals who are willing to question information, including information that reinforces their existing beliefs.

And we need leaders who recognize that trust is not something that can simply be purchased, automated, or delegated. It must be earned.

But I am left with a more fundamental question.

Have we already opened Pandora's box?

As artificial intelligence becomes increasingly capable of generating convincing representations of reality, will we eventually reach a point where we can no longer reliably distinguish between what is authentic and what has been manufactured?

Will future generations accept a world in which every interaction, every communication, and every piece of information must be independently verified? Will the very concept of trust evolve into something entirely different from what humanity has understood for thousands of years?

Or is there an opportunity for us to use the same technological ingenuity that created these challenges to establish a new foundation of trust?

Perhaps the answer lies somewhere between the two.

We may never return to a world where a handshake and someone's word are sufficient to establish trust in every situation. But that does not mean we should accept a world where trust has become obsolete.

The question is whether we are willing to make restoring it a priority.

Because in our pursuit of convenience, efficiency, and technological advancement, we may have overlooked something far more valuable.

We have spent thousands of years developing ways to trust people we do not know. Are we now entering an era where we can no longer trust even the people we think we know?

I would be interested in hearing how other executives view this challenge.

Is the erosion of trust an unavoidable consequence of digital progress, or have we simply failed to give trust the same attention that we give innovation?

And if we have opened Pandora's box, what responsibility do we have as leaders to address what has been released?

Leave a Comment