DEV Community

Cover image for Trustworthy AI: A Complete Guide to Its Principles, Requirements, and Methods
Farzam Kamalpour
Farzam Kamalpour

Posted on

Trustworthy AI: A Complete Guide to Its Principles, Requirements, and Methods

Artificial intelligence is changing how we work, learn, shop, and govern. But the more decisions AI makes about our lives, the more one question matters: can we trust it?

The Ethics Guidelines for Trustworthy AI, published by the European Commission's High-Level Expert Group on Artificial Intelligence (AI HLEG), offer one of the most influential answers. In this guide, we break down everything you need to know about Trustworthy AI: its three core components, the fundamental rights it rests on, its four ethical principles, its seven key requirements, and the technical and non-technical methods organizations can use to put it into practice.

Table of Contents

  1. What Is Trustworthy AI?
  2. Fundamental Rights as the Basis for Trustworthy AI
  3. The 4 Ethical Principles of AI Systems
  4. The 7 Key Requirements of Trustworthy AI
  5. Technical Methods to Achieve Trustworthy AI
  6. Non-Technical Methods to Achieve Trustworthy AI
  7. The Trustworthy AI Assessment List
  8. Frequently Asked Questions (FAQ)
  9. Conclusion

What Is Trustworthy AI?

According to the EU guidelines, Trustworthy AI has three components, and all three should be met throughout the entire life cycle of an AI system, from design to deployment and beyond:

  1. Lawful – The AI system complies with all applicable laws and regulations.
  2. Ethical – The AI system adheres to ethical principles and values.
  3. Robust – The AI system is technically and socially robust, so it does not cause unintentional harm, even with good intentions.

Each component is necessary, but none is sufficient on its own. A system that is legal but unethical, or ethical but technically fragile, cannot be considered trustworthy.


Fundamental Rights as the Basis for Trustworthy AI

Trustworthy AI is built on the foundation of fundamental rights. These rights define what AI systems must protect and respect.

1. Respect for Human Dignity

AI systems should uphold the intrinsic worth of every individual. This means respecting people's physical and mental well-being, their personal identity, and their essential needs. Humans must be treated as subjects, never as mere objects to be sorted, scored, or manipulated.

2. Freedom of the Individual

People should keep their autonomy in decision-making. AI should ensure equal access to benefits and opportunities while safeguarding individuals against coercion, surveillance, deception, and manipulation.

3. Respect for Democracy, Justice, and the Rule of Law

AI systems must not undermine democratic processes. They should respect the plurality of values in society, adhere to legal frameworks, and ensure due process and equality before the law. Crucially, AI must not interfere with democratic voting systems.

4. Equality, Non-Discrimination, and Solidarity

AI must avoid biased outcomes. This requires inclusive and representative training data, along with special protection for vulnerable groups such as workers, women, minorities, and children.

5. Citizens' Rights

AI can make governments more efficient, but it must also safeguard citizens' rights, including the right to vote, access to public services, and good administration. In the EU context, these protections extend to all individuals regardless of nationality or legal status.


The 4 Ethical Principles of AI Systems

Building on fundamental rights, the guidelines define four ethical principles that every AI system should follow.

1. Respect for Human Autonomy

Humans interacting with AI must keep full and effective self-determination. AI should preserve human freedom, support participation in democracy, and leave humans in control of decision-making. Rather than replacing people, AI should empower humans, respect their choices, and support meaningful work.

2. Prevention of Harm

AI systems should not cause or worsen harm to humans. This includes:

  • Protecting human dignity and mental and physical well-being
  • Ensuring safety and security in AI environments
  • Preventing the malicious use of AI
  • Paying special attention to vulnerable individuals
  • Addressing power imbalances and information asymmetries, such as between employers and employees, or governments and citizens
  • Protecting the natural environment and all living beings

3. Fairness

Fairness in AI has two dimensions:

Substantive fairness means:

  • Equal and just distribution of benefits and costs
  • Freedom from unfair bias and discrimination
  • Equal opportunities in access to education, goods, services, and technology
  • No deception or unjustified limitation of freedom of choice
  • Respect for proportionality between means and ends, and a fair balance between competing interests

Procedural fairness means people can contest and seek redress against decisions made by AI systems. This requires that the entity accountable for a decision is identifiable and that decision-making processes are explainable.

Together, these dimensions help AI contribute positively to a fairer society while keeping accountability and transparency in place.

4. Explicability

Explicability is essential for building and maintaining trust in AI. It involves:

  • Transparent processes
  • Open communication about the capabilities and purpose of AI systems
  • Decisions that are explainable to those directly and indirectly affected, as far as possible

Without this information, a decision cannot be properly contested. For so-called "black box" algorithms, where explanations are not always possible, alternative measures such as traceability, auditability, and transparent communication about system capabilities may be required, provided fundamental rights are respected. The degree of explicability needed depends on the context and on how severe the consequences of an incorrect output would be.


The 7 Key Requirements of Trustworthy AI

The guidelines translate the ethical principles into seven concrete requirements. Let's look at each in detail.

Requirement 1: Human Agency and Oversight

Including fundamental rights, human agency, and human oversight.

Human agency: Users should have the knowledge and tools to understand and interact with AI systems, so they can make informed decisions and challenge the system when needed. AI should help people reach their goals, not manipulate or unfairly influence their behavior. User autonomy is central, including the right not to be subject to a decision based solely on automated processing when it significantly affects them.

Human oversight: Oversight ensures that AI does not undermine human autonomy or cause adverse effects. Three governance approaches are commonly used:

Approach What It Means
Human-in-the-Loop (HITL) A human can intervene in every decision cycle of the system.
Human-on-the-Loop (HOTL) A human intervenes during the design cycle and monitors the system's operation.
Human-in-Command (HIC) A human oversees the overall activity and impact of the AI system and decides when and how to use it.

Public enforcers should also be able to exercise oversight in line with their mandate. The level of oversight needed depends on the application area and the potential risk. The less oversight a human can exercise, the more extensive testing and stricter governance are required.

Requirement 2: Technical Robustness and Safety

Including resilience to attack and security, fallback plans and general safety, accuracy, reliability, and reproducibility.

Resilience to attack and security: Like any software, AI systems must be protected against vulnerabilities that attackers could exploit. Attacks can target:

  • The data (data poisoning)
  • The model (model leakage)
  • The underlying infrastructure (software and hardware)

Adversarial attacks can change a system's behavior or data, leading to different decisions or even a shutdown. Malicious intent or unexpected situations can corrupt systems and data, and weak security processes can cause wrong decisions or even physical harm. Secure AI systems must consider potential unintended uses and abuse by malicious actors, with measures to prevent and mitigate these risks.

Fallback plan and general safety: AI systems should include safeguards that trigger a fallback plan when problems occur, such as switching from a statistical to a rule-based procedure or asking a human operator to step in. Systems should do what they are meant to do without harming living beings or the environment, while minimizing unintended consequences and errors. Organizations should establish processes to identify and assess risks across application areas. Safety measures should be proportionate to the level of risk, and should be developed and tested proactively, especially for systems with foreseeable high risks.

Accuracy: Accuracy is an AI system's ability to make correct judgments, such as classifying information correctly or making accurate predictions, recommendations, or decisions. A strong development and evaluation process helps identify and reduce risks from inaccurate predictions. When errors can't be avoided, the system should indicate how likely they are. High accuracy is especially important when AI directly affects human lives.

Reliability and reproducibility:

  • A reliable AI system works correctly across a range of inputs and situations, which makes it possible to scrutinize the system and prevent unintended harm.
  • Reproducibility means an AI experiment produces the same behavior when repeated under the same conditions. This lets scientists and policymakers accurately describe what AI systems do. Replication files help test and reproduce behaviors, strengthening transparency and accountability.

Requirement 3: Privacy and Data Governance

Including respect for privacy, quality and integrity of data, and access to data.

Privacy and data protection: AI systems must guarantee privacy and data protection throughout their life cycle. This covers both the information users provide and the data generated about them through their interaction with the system. Strong protection prevents data from being used to unlawfully or unfairly discriminate based on inferred characteristics such as sexual orientation, age, gender, or political views. People will only trust data collection if they are confident their data won't be misused.

Quality and integrity of data: Dataset quality is critical for AI performance. Data may contain social biases, inaccuracies, and errors that need to be addressed before training. Data integrity also matters, because malicious data can change the behavior of AI systems, especially self-learning ones. Processes and datasets should be tested and documented at every stage, including planning, training, testing, and deployment. This applies even to AI systems acquired from external providers.

Access to data: Organizations that handle personal data should have clear data access protocols that define who may access data and under what circumstances. Only qualified personnel with a legitimate need should have access to individuals' data.

Requirement 4: Transparency

Including traceability, explainability, and communication.

Traceability: The data sets and processes behind an AI system, including data gathering, data labeling, and the algorithms used, should be documented. The same applies to the decisions the system makes. Traceability helps identify why an AI decision went wrong and prevent future mistakes. It also enables auditability and explainability.

Explainability: Explainability means being able to understand both the technical processes of an AI system and the human decisions connected to it. Technical explainability ensures that AI decisions can be understood and traced by humans. There can be a trade-off between explainability and accuracy: making a system more explainable may reduce its accuracy, and vice versa. When an AI system significantly affects people's lives, they should be able to request a suitable explanation, adapted to their level of expertise. Organizations should also be transparent about their business models, design choices, and the reasons for deploying the system.

Communication: AI systems should not present themselves as human. Users have the right to know when they are interacting with AI, and where needed, they should have the option of interacting with a human instead. The capabilities and limitations of the AI system, including its accuracy level, should be communicated clearly to practitioners and end users in a way that fits the use case.

Requirement 5: Diversity, Non-Discrimination, and Fairness

Including the avoidance of unfair bias, accessibility and universal design, and stakeholder participation.

Avoidance of unfair bias: Datasets may contain historic bias, gaps, and flawed governance models, which can lead to prejudice and discrimination. Deliberately exploiting consumer biases can harm people and create unfair competition. Identifiable bias should be removed during data collection where possible, and oversight processes should address bias transparently throughout development. Hiring diverse teams brings different perspectives and helps reduce bias.

Accessibility and universal design: Particularly in business-to-consumer settings, AI systems should be user-centric and accessible to everyone, regardless of age, gender, abilities, or other characteristics. Accessibility for persons with disabilities deserves special attention, following Universal Design principles and relevant accessibility standards. This ensures fair access and active participation for all users.

Stakeholder participation: To build trustworthy AI, stakeholders affected by the system should be consulted throughout its life cycle. Feedback should be collected regularly, including after deployment, with long-term mechanisms for participation. This includes informing, consulting, and involving workers when AI systems are introduced in organizations.

Requirement 6: Societal and Environmental Well-Being

Including sustainability and environmental friendliness, social impact, society, and democracy.

Sustainable and environmentally friendly AI: AI should help address societal challenges while being environmentally responsible. The development, deployment, and supply chain of AI systems should be assessed for resource use and energy consumption, favoring environmentally friendly options throughout.

Social impact: Social AI systems are becoming present in many areas of life. They may change how we understand social agency and affect our relationships and attachments. While they can help build social skills, they can also weaken them, with possible effects on physical and mental well-being. These effects need continuous monitoring.

Society and democracy: Beyond individual impact, AI's effects on institutions, democracy, and society as a whole should be assessed. Particular care is needed when AI is used in democratic processes, including political decision-making and elections.

Requirement 7: Accountability

Including auditability, minimization and reporting of negative impacts, trade-offs, and redress.

Auditability: Auditability means algorithms, data, and design processes can be assessed. This doesn't always require disclosing business models or intellectual property. Evaluations by internal and external auditors, and the availability of their reports, strengthen trust. For applications that affect fundamental rights, including safety-critical ones, independent audits should be possible.

Minimization and reporting of negative impacts: Organizations should be able to report on the actions and decisions that led to an outcome and respond to the consequences. Negative impacts should be identified, assessed, documented, and minimized, especially for those directly affected. Whistle-blowers, NGOs, trade unions, and others who raise legitimate concerns must be protected. Tools such as red teaming and Algorithmic Impact Assessments help reduce negative impacts and should be proportionate to the risks involved.

Trade-offs: Implementing these requirements can create tensions between them. Such trade-offs should be handled methodically: identify the relevant interests and values, acknowledge the conflicts, and evaluate the risks they pose to ethical principles and fundamental rights. If no ethically acceptable trade-off can be found, the AI system should not be developed, deployed, or used in that form. Trade-off decisions must be reasoned, documented, and accountable, and should be reviewed continuously.

Redress: When unjust adverse impacts occur, accessible mechanisms for redress must be available. Knowing that redress is possible when things go wrong is key to trust. Particular attention should be given to vulnerable persons and groups.


Technical Methods to Achieve Trustworthy AI

These methods can be built into the design, development, and use phases of an AI system. They vary in maturity.

Architectures for Trustworthy AI

Requirements must be turned into procedures anchored in the system's architecture. This can include:

  • White-list rules: behaviors or states the system should always follow
  • Black-list restrictions: behaviors or states the system should never show
  • Provable guarantees about system behavior

Monitoring compliance with these restrictions should be handled as a separate process.

Ethics and Rule of Law by Design (X-by-Design)

Values-by-design requires clear links between abstract principles and specific implementation decisions. Compliance with norms should be built into the design itself. Companies should identify potential impacts and relevant norms from the very start. Established concepts like privacy-by-design and security-by-design serve as models. Trustworthy AI must be secure, robust, and resilient against attacks, with fail-safe shutdown mechanisms that allow operation to resume after a forced shutdown.

Explanation Methods (Explainable AI / XAI)

Understanding why an AI system behaves the way it does is central to trust, which is why Explainable AI (XAI) is an active research field. Neural networks are especially challenging because their parameters are hard to link to outcomes. Small changes in input data can drastically change the output, causing a system to confuse one object for another. Attackers can exploit this weakness. XAI methods aim to explain system behavior so users can understand it and deploy it reliably.

Testing and Validating

Because AI systems are non-deterministic and context-specific, traditional testing is not enough. Key practices include:

  • Monitoring the model's stability, robustness, and predictable operation during both training and deployment
  • Testing early in the life cycle, covering all components: data, pre-trained models, environments, and overall system behavior
  • Having diverse groups design and run tests, using multiple metrics to cover different perspectives
  • Using adversarial testing by trusted "red teams" and bug bounties to uncover vulnerabilities
  • Making sure outputs and actions align with predefined policies

Quality of Service Indicators

Quality of service indicators help confirm that AI systems were built and tested with security and safety in mind. They include measures for testing and training algorithms, as well as traditional software metrics such as functionality, performance, usability, reliability, security, and maintainability.


Non-Technical Methods to Achieve Trustworthy AI

Technical tools are only half the picture. The following non-technical methods also play a valuable role and should be evaluated on an ongoing basis.

Regulation

Existing regulation, such as product safety laws and liability frameworks, already supports trustworthy AI. Where new or revised rules are needed, the AI HLEG addressed them in its second deliverable, the AI Policy and Investment Recommendations.

Codes of Conduct

Organizations can adopt the guidelines and embed Trustworthy AI into their corporate responsibility charters, KPIs, codes of conduct, and internal policies. They can document their intentions and align them with standards focused on fundamental rights, transparency, and harm avoidance.

Standardization

Standards act as a quality management system for AI users, organizations, and governments, promoting ethical conduct and informing purchasing decisions. Co-regulatory approaches like accreditation systems and professional codes of ethics complement traditional standards. Examples include ISO standards and the IEEE P7000 series. A future "Trustworthy AI" label could confirm that a system meets safety, robustness, and transparency standards.

Certification

Certification by trusted organizations can reassure the public that an AI system is transparent, accountable, and fair, using standards adapted to specific domains and techniques. However, certification should complement, not replace, responsibility, and should come with accountability frameworks including disclaimers and review and redress mechanisms.

Accountability via Governance Frameworks

Organizations should create internal and external governance frameworks for the ethical aspects of AI development, deployment, and use. Options include:

  • Appointing an ethics officer
  • Establishing an ethics panel or board for oversight and advice
  • Working with certification bodies
  • Opening communication channels with industry and public oversight groups to share best practices and discuss emerging concerns

These mechanisms cannot replace legal oversight, such as the appointment of a data protection officer required under data protection law.

Education and Awareness to Foster an Ethical Mindset

Trustworthy AI depends on the informed participation of all stakeholders. Communication, education, and training help spread knowledge about AI's potential impact and empower people to shape how society develops. Stakeholders include designers, developers, users, affected groups, and society at large. Basic AI literacy should be promoted, and ethicists working in this field need proper skills and training.

Stakeholder Participation and Social Dialogue

Making AI benefit everyone requires open discussion involving social partners, stakeholders, and the general public. Many organizations already use stakeholder panels made up of legal experts, technical experts, ethicists, consumer representatives, and workers to discuss AI and data analytics. Actively seeking participation and dialogue helps evaluate results and approaches, especially in complex cases.

Diversity and Inclusive Design Teams

Teams that design, develop, test, maintain, deploy, and procure AI systems should reflect the diversity of users and society. This brings objectivity and ensures different perspectives, needs, and goals are considered. Ideal teams are diverse in gender, culture, age, professional background, and skill sets.


The Trustworthy AI Assessment List

The guidelines also include a Trustworthy AI assessment list to put the key requirements into practice, mainly for AI systems that interact directly with users. It is designed for developers and deployers of AI.

Key points about the assessment list:

  • It must be tailored to the specific use case and context.
  • A governance structure is recommended for implementing it, involving both operational and top management levels. Research shows that top-level management attention is essential for real change, and involving all stakeholders increases acceptance and relevance.
  • It was piloted with stakeholders from the public and private sectors, with feedback gathered through qualitative and quantitative processes, leading to a revised version.
  • It can be integrated into existing governance mechanisms or run through new processes, depending on an organization's structure and resources.
  • Hard questions matter too. Organizations should not only address clear areas of concern but also acknowledge questions without easy answers. For example, if the team building and testing an AI system lacks diversity, stakeholders from inside or outside the organization may need to be involved.
  • Document everything, both technically and managerially, so that results are understood at every level of the governance structure.
  • It raises questions rather than giving concrete answers, encouraging reflection on how to operationalize Trustworthy AI and suggesting possible next steps.

Important: Following the assessment list does not guarantee legal compliance, nor does it give guidance on complying with specific laws. Some laws already require specific processes or prohibit certain outcomes. For example, data protection laws set legal requirements for collecting and processing personal data. Since Trustworthy AI also requires ethical data handling, internal procedures for data protection compliance can support both ethical practice and legal obligations. Many practitioners already use assessment tools and development processes for non-legal standards, so the assessment list doesn't need to be a standalone exercise and can be built into existing practices.


Frequently Asked Questions (FAQ)

What are the three components of Trustworthy AI?

Trustworthy AI must be lawful (compliant with laws), ethical (aligned with ethical principles and values), and robust (technically and socially reliable). All three should be met throughout the AI system's entire life cycle.

What are the 7 key requirements of Trustworthy AI?

  1. Human agency and oversight
  2. Technical robustness and safety
  3. Privacy and data governance
  4. Transparency
  5. Diversity, non-discrimination, and fairness
  6. Societal and environmental well-being
  7. Accountability

What are the 4 ethical principles for AI?

Respect for human autonomy, prevention of harm, fairness, and explicability.

What is the difference between HITL, HOTL, and HIC?

Human-in-the-loop (HITL) means a human can intervene in every decision cycle. Human-on-the-loop (HOTL) means a human intervenes during design and monitors operation. Human-in-command (HIC) means a human oversees the overall activity and impact of the AI system and decides when and how to use it.

Does following the Trustworthy AI assessment list guarantee legal compliance?

No. The assessment list supports ethical and robust AI, but it does not guarantee compliance with applicable laws or give legal guidance.

Who created the Ethics Guidelines for Trustworthy AI?

They were developed by the High-Level Expert Group on Artificial Intelligence (AI HLEG), set up by the European Commission, and published in April 2019. They have strongly influenced later European AI policy, including the EU AI Act.


Conclusion

Trustworthy AI isn't just a technical goal. It's a commitment to building AI that respects human dignity, protects rights, and serves society. By combining the three components (lawful, ethical, robust), the four ethical principles, and the seven key requirements with practical technical and non-technical methods, organizations can develop AI systems that people can genuinely rely on.

Whether you're a developer, business leader, policymaker, or simply curious about the future of AI, understanding these principles is the first step toward a more responsible and human-centric digital future.


Found this guide helpful? Share it with your team and colleagues working on AI projects.

Top comments (0)