Paper · 7 September 2026

Trust and Proof

The interesting question is not whether a system is trustless. It is where the trust has gone.

Abstract

Trust and proof are often spoken of as if they were one relation. Four claims get run together: that they are the same thing, that trust depends on proof, that proof depends on trust, and that proof can stand in for trust. None of them holds in every case. Trust is a relational attitude toward an agent, institution, method, or machine. Proof is used broadly here to mean an inspectable evidentiary object supporting a proposition: a formal derivation, cryptographic proof, certificate, or test result. The label “trustless” then treats the remaining demand for trust as a Boolean property of a system. This paper argues that it is not. Where trust remains can only be judged relative to a proof boundary: what has actually been proved, and relative to which assumptions and dependencies.

Write P(x | A) for the required property of x established relative to assumptions and dependencies A, and Need(T, x | A) for the remaining demand to trust x given that boundary. Where proof successfully substitutes for trust, the substitution is local: P(x | A) → ¬ Need(T, x | A). That claim can be true. Zero-knowledge proofs, formal verification and cryptography can discharge particular trust relations. What they do not entail is the elimination of every remaining trust relation.

The trust residue R(A) is the subset of A whose members still require trust relative to the rest of the boundary. The Trust Displacement Result states that local discharge does not entail global elimination:

P(x | A) ∧ ¬ Need(T, x | A) ⇏ R(A) = ∅

Architectures that establish the same property of x can be compared by residue: A2 trust-dominates A1 when R(A2) is a proper subset of R(A1). “More trustless” then means a strictly smaller trust residue, not the absence of trust. A proof claim that does not expose its material A is an incomplete engineering claim. The Ethereum Foundation Proximity Prize illustrates the engineering consequence: disproved conjectures invalidated part of the assumed proof boundary, rather than demonstrating a failed implementation.

Governance of autonomous action is not the accumulation of logs or proof objects. It is explicit management of proof boundaries and their residues, including when A changes while the observable action does not. The interesting question is not whether a system is trustless. It is where the trust has gone.

Keywords: trust; proof; trust residue; trustless systems; formal verification; cryptographic assumptions; governance; philosophy of trust

Cite

Betts, R. (2026) ‘Trust and Proof’. Riley Betts Ltd. Available at: https://rileybetts.ai/papers/trust-and-proof