AI Trust and Control Canvas
See whether a person can sensibly decide how much to rely on one AI output, and what they can do when it is wrong.
When to use the canvas
Use the canvas for any AI output that changes a record, a decision, a message or a commitment. Fill one canvas per output type.
It is for product designers and product managers designing a consequential AI interaction.
You need one specific output, not the feature. Allow enough time to work through it with someone who understands the consequence.
The canvas blocks
- 01
The output
Write the actual thing the AI produces, as the user sees it. One sentence. If you cannot, the interaction is not defined yet.
- 02
The consequence
Identify what changes in the world if the user accepts the output: money moves, a message sends, a record closes, a person is scheduled, or a claim is assessed. Then answer whether it is reversible, and by whom.
This block sets the budget for everything below. Low consequence and reversible earns a light interaction. High consequence and irreversible earns friction.
- 03
The basis
Name the specific sources the output is built from: which records, which documents, which prior behaviour, which model knowledge. Then answer which of these the user can actually see at the moment of deciding.
- 04
Confidence
Be concrete about how the user distinguishes a well-supported output from a thin one. A number nobody understands is not an answer, and neither is a uniformly confident tone.
If the system cannot tell the difference internally, that is the finding. Say so here.
- 05
Inspection
Define what the user can open, expand or check before accepting. At minimum, this includes the sources from block 3. Better inspection includes the reasoning, the alternatives considered, and the record that triggered it.
- 06
Control
List what the user can do instead of accepting.
- Edit before committing
- Reject and choose an alternative
- Ask for a different basis
- Escalate to someone with more authority
- Do it manually
If the honest list is "accept or ignore", write that down and look at it next to block 2.
- 07
Recovery
Assume the output was wrong and the user accepted it. Then answer how it is discovered, who is told, what undoes it, how long that stays possible, and what happens to things that already depend on it.
- 08
The record
Define what is retained about the interaction: what the AI proposed, what the person did, what changed, when, and who. This is what allows anyone to review the decision later, and it is usually designed last and regretted first.
Reading your canvas
- 01
Block 2 severe, blocks 5 and 6 thin
The interaction is asking for trust it has not earned. Add inspection and control before shipping.
- 02
Blocks 5 and 6 heavy, block 2 mild
The interaction is over-engineered. Users will click through the friction and learn to ignore all of it, including the parts that matter later.
- 03
Block 4 empty
Everything will arrive with the same authority. Users will calibrate to the worst output they ever saw.
- 04
Block 7 empty
The product works only when the AI is right, which is not a product.
- 05
Block 8 empty
Nobody will be able to reconstruct what happened, including you.
What this does not tell you
The canvas covers one output. It does not assess model performance, cover regulatory obligations, or replace testing with real users.
What to do next
Tcules' article on calibrated trust in AI interfaces explains why maximum transparency is not the goal. Trust, Control and Recovery is the service; the BuildTwin case shows the pattern in a real accountable workflow.
If the canvas raised more questions than it settled, the AI Product UX Readiness Assessment starts with a free audit on one interaction.
Use the canvas on one interaction
If the canvas raised more questions than it settled, the AI Product UX Readiness Assessment starts with a free audit on one interaction.