The GSMA Open Gateway initiative is a working example of what a trust exchange looks like in practice. Network APIs — Number Verification, SIM Swap, KYC Match, device information, location verification — are usually described simply as APIs. Underneath them is a bigger idea: they are mechanisms for moving trusted outcomes between organisations.
What crosses the boundary
The organisation exposing the API does not disclose everything it knows. It answers a specific question within the area where it is authoritative. The underlying data remains with the organisation that has the legitimate relationship and authority to hold it; the trusted outcome is what gets consumed by the other organisation. A bank does not need a copy of a mobile network's customer database — it may simply need to know whether the person requesting a transaction controls the number associated with the account.
Interoperability and network effects
What makes this a trust exchange, rather than a single point-to-point integration, is that the same trusted outcome can in principle be reused across multiple consuming organisations under appropriate governance, without the authoritative organisation repeatedly exposing the underlying data to each one individually.