⚡ Quick Summary
Published by the UC Berkeley Center for Long-Term Cybersecurity (CLTC), this white paper introduces a taxonomy of trustworthiness for artificial intelligence intended to complement and support use of the NIST AI Risk Management Framework. Authored by Jessica Newman and dated January 2023, it sets out 150 properties of trustworthiness, each building on one of NIST's seven characteristics of trustworthiness — valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed — plus an eighth crosscutting characteristic the paper adds, "Responsible Practice and Use."
Each property is tagged to one of the seven AI lifecycle stages defined in the NIST AI RMF (Plan and Design, Collect and Process Data, Build and Use Model, Verify and Validate, Deploy and Use, Operate and Monitor, and Use or Impacted By) and paired with future-oriented guiding questions and a list of the most relevant NIST AI RMF core subcategories. The paper reviews four government-led frameworks — the High-Level Expert Group on AI's assessment list (ALTAI), the EU AI Act, the White House Blueprint for an AI Bill of Rights, and the NIST AI RMF — and argues that trustworthiness should not be limited to high-risk or human-facing applications. Two appendices map the characteristics to international AI standards and restate the properties without lifecycle segmentation.
🧩 What’s Covered
The paper runs from an introduction and five key findings through four analytical chapters, a taxonomy presented as tables, and two appendices.
- Introduction and key findings: frames trustworthy AI as a contested term, states the aim of complementing the NIST AI RMF, and lists five findings, including that trustworthiness should be considered before development, that many properties matter regardless of whether a system is "high risk," and that some are less relevant for non-human-facing systems.
- Trustworthy AI: reviews definitions from the NIST Framework for Cyber-Physical Systems, the Oxford English Dictionary and the OECD, notes criticism of the term, and states that the paper uses it for "an aspiration and an ongoing process."
- Existing frameworks: surveys ISO, IEEE, ITU and other standards work, then examines four government-led efforts in detail: the High-Level Expert Group on AI's Ethics Guidelines and ALTAI, the EU AI Act and its high-risk categories, the White House Blueprint for an AI Bill of Rights and its five principles, and the NIST AI RMF with its govern, map, measure and manage functions.
- Properties of trustworthiness: explains holistic consideration of the 150 properties, interdependencies and tensions (for example between explainability and security), the additional characteristic "Responsible Practice and Use," and the uneven availability of metrics, benchmarks and standards.
- Spectrum of human-AI engagement: offers three questions on human data, human users or operators, and informing human decision-making, and explains the asterisk marking properties likely to be less relevant to non-human-facing systems.
- Taxonomy: presents each lifecycle stage with tables listing the characteristic, property, guiding question and relevant NIST AI RMF subcategories, with one or two subcategories bolded as starting points.
- Implications, further research and conclusion: restates the findings, discusses which properties remain relevant across the spectrum of human engagement, and calls for piloting the framework and developing case studies.
- Appendices: Appendix I maps characteristics of trustworthiness to international standards from the OECD, European Commission, NIST, ISO, IEEE, ITU-T and ETSI; Appendix II restates the properties without lifecycle segmentation.
💡 Why it matters?
The taxonomy gives teams a concrete bridge between the abstract characteristics of trustworthy AI and the working parts of a risk management process. Because every property is tagged to NIST AI RMF subcategories and to a lifecycle stage, it can be used to locate where a given concern should be addressed and which part of the framework to read next. It also extends consideration beyond high-risk and human-facing systems, which is directly relevant to organisations whose applications fall outside the EU AI Act's pre-listed areas or the ALTAI's user-facing focus.
❓ What’s Missing
The paper acknowledges that the list of properties "should not be assumed to be fully comprehensive," that much of the source literature originated in western democratic nations and may not capture global variation in values, and that it does not incorporate regional regulations or guarantee compliance with any of them. Some properties lack established standards, metrics or benchmarks, and the authors note that quantification methods in those areas are likely to change. It also concedes that trustworthiness is not tied only to a product lifecycle, since many properties concern people and organisations rather than products, and it offers no prioritisation method beyond context, no worked examples, and no discrete definitions of points along the spectrum of human-AI engagement.
👥 Best For
AI governance and risk leads using the NIST AI RMF who need to translate its characteristics into stage-by-stage questions; compliance and audit teams mapping internal practice to NIST subcategories; product, security and data teams assigning ownership of specific properties; and standards, policy or civil society analysts reviewing how trustworthiness guidance addresses non-human-facing systems.
📄 Source Details
A Taxonomy of Trustworthiness for Artificial Intelligence: Connecting Properties of Trustworthiness with Risk Management and the AI Lifecycle, by Jessica Newman, published by the Center for Long-Term Cybersecurity (CLTC), UC Berkeley, in the CLTC White Paper Series and dated January 2023. The extraction covers all 78 pages, including cover, contents, the numbered chapters and taxonomy tables, two appendices, acknowledgments and author biography. No URL for the document itself is printed in the text.