09 Trust in Communications, Epilogue: What Changed, What Remains True

What Changed, What Remains True, and Where the Work Goes Next
TRUST IN COMMUNICATIONS · EPILOGUE · ICA AI, Inc. · +Trusted Infrastructure · July 2026

A +Trusted Infrastructure series from ICA AI
Series editor: John Perkins, Chief Executive Officer

This epilogue introduces no new argument and no new evidence. Seven papers and two companions made the case; what is left is to take stock: what the argument changes, what it leaves standing, where it stops, and what it leaves for others to take up. A reader who has followed a long argument is owed that accounting. We would rather say plainly what is established than let the case
overreach on our behalf.

What changed
The series proposes a different engineering model of trust. It does not argue that identity is unimportant; it argues that identity and trust are different engineering objects, and that treating them as the same has constrained how the industry asks its central question.

In practice, in product, and often in policy, the two have been treated as interchangeable: verify the caller, the reasoning goes, and you have settled whether the call can be trusted. But identity is an attribute of a party, and trust is a property of a relationship between two parties. They are held in different places, they are established by different means, and they fail in different ways. That is the change the series is asking for — not that identity matters less, but that it is a different object from trust and cannot be made to stand in for it.

The argument reached that position by elimination rather than accumulation. It asked one question — whether verifying identity is enough to establish trust — and each paper removed a way of answering yes:

Origin is not trust. What authentication establishes is a fact about the call — that it was signed, and how strongly — not a fact about the party behind it. Trust is a property of the relationship — something a single signed call cannot establish.

The relationship layer can stand on its own. It can carry a decision by itself, tested against its hardest case — the compromised account.

Hardening the standard does not close the gap. Coverage divides into two gaps, and only the smaller one is transitional. Signatures stripped in transit recover as the network converts to all-IP — which is what the 2026 recovery in coverage is. The larger gap is untouched at any coverage level: authentication reaches where the economics of signing make it worthwhile, and fraud routes precisely where it doesn’t.

The last three removals were the hardest, each taken on the opposing position’s strongest ground:

Even a flawless rulebook leaves the trust decision unmade. Grant the Proposed FCC Rules full rollout and compliance, and rules that can only prevent and punish still never answer the only question that matters when the phone actually rings — should this call be trusted? Prevention works only in advance, and enforcement only after the fact.

A relationship resists forgery at the scale that makes fraud profitable. The record is held on both sides, and across every counterparty that keeps its own account of it; an attacker controls only their own side — and AI cannot forge records it was never given.

-Even a stolen credential doesn’t beat a layer that keeps checking. A one-time gate is– blind as long as the credential stays valid, which is indefinitely; a layer that keeps checking is blind only until the attacker acts — and the attacker has to act to get any value from it.

What is left standing, after all seven papers, is that the decision requires something present at the moment of the call, specific to the parties on it, and able to weigh behavior rather than only origin.

What remains true
The series spent seven papers on what these tools cannot do. That is not the same as saying they do nothing. Plainly: each of them still does real work.

— Authentication answers a question worth answering, and where it is deployed it has measurably reduced spoofing — a real achievement of the last decade.

-Regulation helps — the Proposed FCC Rules are a real improvement at what they set out to do.

— Enforcement matters, and its slowness is not a defect to be engineered away — it is the cost of doing enforcement fairly, and a cost worth paying.

— Identity has a role the series never disputed: a trust decision has to attach its history to a party, and identity is how a history is indexed.

Indexing the history is not carrying the decision. When the series says authentication is not necessary, it means for carrying the decision, not for filing the history — the relationship record can recognize a counterparty even when no credential arrives with the call. Identity files the history; it does not render the verdict.

None of that is in question. The series denies only that these tools are enough — not that they are worth having. Each does its job. But none of them decides, when the phone rings, whether this particular call should be trusted — and that decision is the one the industry still has to make.

Where the argument stops
Four things the series does not claim:

It is an argument about structure, not a system. Nothing in the series depends on any implementation, and nothing in it should be read as describing one. Where a paper says the relationship layer, it means the property — the thing that is true whether or not anyone ever builds it — not a product.

The claim is that divergence surfaces, not that it is detected. Behavioral divergence from an established, bidirectional pattern is designed to surface as a mismatch or anomaly. It does not claim detection, and it does not claim that surfacing is the same as certainty. A signal that gets weighed is not a verdict that gets pronounced, and staying honest about the claim means never letting the first pass for the second.

The forgery claim is only about scale. A single relationship can be mimicked by a determined attacker with enough reconnaissance, and the mimicry can work for a time. But fraud is a volume business, and a forgery that does not repeat is not a fraud operation.

The window on a compromised account closes — just not instantly. That it closes at all is the property a one-time gate structurally lacks, and the series claims nothing more.

Where the work goes from here
If the series is right that trust is relational, there is real work still to do. The following are research and engineering questions that need to be answered:

How should a relationship be represented? The series argues that relationships are load bearing without settling what counts as an interaction of record, how much history is required before a relationship signal can carry weight, or how a relationship that has gone quiet should be treated. Until these are settled, there is no common object to build on or to measure.

Where should the evidence live, and what privacy must it guarantee? The barrier in Paper 6 depends on records reflecting what each party independently holds — and wherever that evidence lives, the privacy properties it must guarantee are a real and open question.

What happens before a relationship exists? Every relationship has a first interaction, and at that moment there is nothing to read. The series’ answer is to screen that first contact and let its outcome become the first entry in the record. What remains open is narrower: how much history counts as enough before a relationship signal can carry weight.

How much does behavior have to break pattern before it counts — and what does gtting it wrong cost? Surfacing a divergence is not the same as acting on one. Thresholds, the cost of a false positive against a false negative, and what a system may do with aweighed signal are live questions — and they are the ones on which operator adoption will actually turn.

How would anyone measure whether any of this works? Today the industry measures authentication — signing rates, attestation levels, database compliance — and those process metrics are the ones it relies on. Nobody measures whether the person receiving the call was protected. Roughly 48.8% of calls were signed at termination as of June 2026 — a twenty-month high, and still short of half after five years of the mandate — and of the calls signed at origin, fewer than half arrive with the signature intact; reported fraud losses hit a record of roughly $16 billion in 2025. The first two numbers describe a mechanism, the third an outcome — and no one has an accepted way to connect them. No approach to trust, this one included, can be judged against a benchmark that does not exist.

The question changes
If the arguments in this series are substantially correct, then the industry’s central research question changes. It is no longer how do we strengthen identity. It is how do we responsibly operationalize relationship.

That work is the domain of +Trusted Infrastructure — ICA AI’s layer built for precisely the characteristic that authentication does not have: the relationship.

This series does not claim to have answered that question. It claims to have changed it. The answer belongs to those who would build it — to the operators who would carry it, the researchers who would measure it, and the standards bodies who would have to agree on what is being measured. Seven papers asked whether verifying identity is enough to establish trust, and the answer, tested from every direction this series could find, is that it is not. That finding does not close the matter. The work it opens is a research program, and it belongs to the people who will build the answer, not to this series.

About this series
Trust in Communications is a seven-part white-paper series, with two companion volumes and a concluding epilogue, examining one question: whether verifying identity is enough to establish trust in voice communications. The list below is in reading order — the companions sit where they are best read, not at the end.

  1. What Trust Actually Is
    ◇ Companion — Voice Fraud: The Evidence
  2. The Role of Caller Authentication in Establishing Trust
  3. The One Layer That Can Stand Alone
  4. The Permanent Coverage Gap
  5. Even If the Proposed FCC Rules Work Perfectly, Will They Be Enough?
    ◇ Companion — The Proposed FCC Rules
  6. Why a Relationship Cannot Be Faked at Scale
  7. The Compromised Account
    Epilogue — What Changed, What Remains True (this document)
    Read the full series at ICATrusted.ai.

    Drafted with AI assistance; all analysis, claims, and conclusions rest with the series editor.