upsunday

Trust Is Decided Before It’s Read: How Credibility Forms When AI Makes Polish Free

Visitors judge a site in a fraction of a second, and AI has made the look of quality available to everyone, scammers included. What the Stanford credibility research actually found, the Three Pass model of how trust forms, and a trust audit you can run this month.

Jake Young7 min read
Cover art for “Trust Is Decided Before It’s Read: How Credibility Forms When AI Makes Polish Free”

For twenty years a polished website was a decent sign of a real company, because polish was expensive. That signal has collapsed. Generative tools give a new competitor, a template and a fraudster the same clean layout, the same confident copy and the same flawless photography by lunchtime, and visitors still decide how far to trust you before they read a sentence.

So trust has moved. Looking good now only keeps you out of the reject pile. Belief is earned by proof that is hard to fake, easy to check and consistent everywhere a person or a model meets you, and the brands that design for that will stand out more than they could when everyone else still looked amateur.

What the Research Actually Says

The speed is real. In 2006 Gitte Lindgaard and colleagues showed people homepages for 50 milliseconds and found their ratings of visual appeal closely matched ratings given after longer viewing. In 2012 a team led by Alexandre Tuch cut exposure to 17 milliseconds and found two properties already shaping judgments: busy pages made worse first impressions, and pages that looked typical of their category made better ones.

The Stanford Web Credibility Project, led by B.J. Fogg, explains why. In a 2002 study, 2,684 people compared the credibility of real websites and wrote down their reasons. Design look came up in 46.1% of the 2,440 comments, more than anything else, followed by information structure at 28.5% and information focus at 25.1%. Privacy policies, which people had told surveys they cared about, came up in less than 1%.

That study is often summarised as “people judge by design”, which misses its better idea. Fogg’s Prominence-Interpretation Theory says an element affects credibility only when a person notices it and then interprets it as good or bad. A privacy policy nobody sees has no effect. A typo in the hero has a large one, because everyone sees it and everyone reads it the same way. That model is the basis of how we audit.

Fluency matters too. Reber and Schwarz showed in 1999 that statements printed in easier to read colours were more often judged true. And distrust has a price: in Baymard Institute’s checkout research, 19% of US shoppers who abandoned an order said they didn’t trust the site with their card details.

What AI Changed

Everything in the first glance can now be generated. The FBI’s Internet Crime Complaint Center warned in December 2024 that criminals use generative AI to build fraudulent websites and to fix the spelling mistakes that used to give scams away. The cues people relied on to spot a bad actor are gone.

Legitimate brands converged at the same time. Similar tools push everyone toward the same typical page, which is exactly what Tuch’s research says makes a good first impression. So everyone passes the glance and nobody stands out in it. Our essay Taste Is the Last Moat covers the creative side of that sameness. The trust consequence is narrower: when surface quality is universal, it stops carrying information, and people move straight to the signals that still do.

Fake proof got cheaper too. Invented testimonials and generated reviews cost nothing, which is why the US Federal Trade Commission’s rule banning fake reviews, in force since October 2024, explicitly covers testimonials from people who don’t exist, AI generated ones included. What’s left is what economists call costly signals: claims that are expensive to make unless they’re true. A named client someone could phone. A return policy with real terms. Years of consistent presence.

The Three Pass Model

Visitors evaluate in three passes, each using different evidence, so we design for all three.

Pass one, the glance: under a second

The question is whether this looks like a legitimate company of its kind. The evidence is visual: complexity, familiarity, fluency, craft. AI has raised this floor for everyone, so the goal is to clear it without relying on it. Look like a credible member of your category, with enough distinctive craft that the page couldn’t belong to anyone else.

Pass two, the scan: the first ten seconds

The question is whether this is for me and whether they’re being straight with me. Dwell time research by Liu, White and Dumais found the first ten seconds largely decide whether people stay. The evidence here is structural: a plain statement of what you do and for whom, visible routes to the things people check, and upfront disclosure, which Nielsen Norman Group lists among its four lasting credibility factors.

Pass three, the check: when stakes rise

Before someone pays, books or hands over data, they look for proof they can verify: real people with names and faces, specific results, reviews on platforms you don’t control, an address, a phone number that answers, and more and more often, what an AI assistant says when they ask about you. The Stanford guidelines from twenty years ago read like a checklist for this pass.

The passes feed each other. A strong glance buys the ten seconds for the scan, and a clean scan makes people willing to check. A failed check undoes everything, so design effort should rise with the stakes of the action.

Walkthrough: A Trust Audit

This is the audit we run, in order. It needs a spreadsheet, a handful of real people and some patience.

Step one: pick the three moments where trust matters most, usually the homepage, the page before the main conversion, and the conversion itself.

Step two: inventory every trust signal on those pages, with its location and whether it’s verifiable. A quote with a full name, company and role is verifiable. “Sarah, happy customer” isn’t.

Step three: score prominence. Show people each screen for five seconds, hide it, and ask what they remember and what the company does. A signal nobody mentions has low prominence. A returns policy linked only from the footer has none at the moment of checkout.

Step four: test interpretation. Show people the signals and ask what each one tells them. Generic testimonials and polished stock photography now often read as fake, and people say so. Anything read as marketing rather than evidence goes on the list.

Step five: hunt for negative signals, since the Stanford guidelines end on avoiding errors of every size. Broken links, an old copyright year, a blog that stopped two years ago, a hidden price model, dark patterns in forms, and pop ups before the page has earned any goodwill.

Step six: check consistency across touchpoints. Put the website beside your LinkedIn page, review profiles, listings and sales deck. Do they use the same name, claims and visual identity? Then ask ChatGPT, Claude, Gemini and Perplexity what your company does and whether it’s trustworthy, several times each, and write down the answers. Assistants are now a touchpoint built from all the others, and Your Brand Is a Dataset Now explains how to shape what they say.

A soft 3D rubber stamp tilted toward the viewer, its face carrying a sun emblem
Consistency is the one trust signal nobody can generate overnight. Every touchpoint should carry the same mark.

Step seven: fix in order of stakes times prominence. Upgrade unverifiable signals to verifiable ones, move proof to the moment of decision, remove anything read as fake, and repair the negative cues. Then test again.

Designing Signals That Survive the AI Era

The signals that still work would all be expensive or risky to fake, which gives us a design brief.

Specific beats superlative. “Trusted by leading brands” is free to write. A named client, the problem, what changed and a person willing to be quoted is expensive to fake, and it’s also what AI assistants can repeat about you.

Disclosure beats reassurance. State how pricing works, what happens when something goes wrong, how long things take and who to call. In Nielsen Norman Group’s research, participants turned away from companies that hid their rates.

Real people beat stock people. Photograph your actual team in your actual space, with names and roles. After years of generated imagery, slightly imperfect real photography reads as evidence.

Consistency beats volume. Recognition builds through the same name, look and claim across every touchpoint over years, and inconsistency now costs twice, because models blur contradictory sources into something vague.

Craft still matters, with a new job. It used to prove you could afford good design. Now it proves care, that someone made deliberate choices about this brand in particular.

What Machines Can Check, and What They Can’t

Some trust work should be automated because it decays: a scheduled crawl can flag stale dates, broken links, inconsistent descriptions and unnamed testimonials. Whether a person believes you is different. Only people can tell you that, and deciding what counts as proof is a senior judgement about your brand and your buyers. One rule has no exceptions: never generate trust signals. A synthetic quote or team photo is exactly the evidence visitors are right to discount, and in the US a fake testimonial is now a regulatory problem too.

Our prediction: over the next few years, proof becomes more structured and portable, with reviews tied to confirmed purchases and credentials a machine can check. Brands that already publish checkable evidence will find people and AI assistants more willing to vouch for them.

What to Do This Quarter

Run the audit on your three highest stakes moments. Replace every unverifiable testimonial with a named one, or remove it.

Publish your policies plainly and link them at the point of decision. Replace stock photography of people with photographs of your people.

Write one canonical description of the company, align your site and profiles to it, and record what four AI assistants say about you as a baseline.

Trust used to be something you could buy with production value. Now it has to be demonstrated. If you’d like an outside view of how your brand reads in its first seconds, and what it would take to make your proof impossible to doubt, we’d love to talk.

  • Brand
  • Trust
  • Credibility
  • AI
Share

More insights

Keep reading

Contact

Let's talkabout something yours