Innovation, Quantum-AI Technology & Law

Blog over Kunstmatige Intelligentie, Quantum, Deep Learning, Blockchain en Big Data Law

Blog over juridische, sociale, ethische en policy aspecten van Kunstmatige Intelligentie, Quantum Computing, Sensing & Communication, Augmented Reality en Robotica, Big Data Wetgeving en Machine Learning Regelgeving. Kennisartikelen inzake de EU AI Act, de Data Governance Act, cloud computing, algoritmes, privacy, virtual reality, blockchain, robotlaw, smart contracts, informatierecht, ICT contracten, online platforms, apps en tools. Europese regels, auteursrecht, chipsrecht, databankrechten en juridische diensten AI recht.

Quantum and the End of Privacy: Harvest-Now-Decrypt-Later, Quantum Sensing, and Forward-Dated Data Protection Law

By our Editor

Privacy law has always been, at bottom, a law of time. Medical files, genomic profiles, financial records, diplomatic cables, the intimate archive of a life: what we protect is information whose sensitivity persists across decades. Quantum technology attacks that temporal dimension, and it attacks it twice. Once through cryptanalysis, which quietly stamps an expiry date on everything encrypted today, and once through quantum sensing, which promises to measure what law has long treated as unmeasurable: the inside of buildings, the ground beneath cities, eventually the working brain. Both threats were central to Mauritz Kop’s Oxford University lecture on quantum threats, and both are moving faster than most privacy frameworks were designed to absorb.

Whether this amounts to "the end of privacy" is a governance choice, and physics will not make it for us. Like most governance choices in emerging technology, it is being made right now, largely by default, while attention is consumed by AI. Artificial intelligence and quantum capabilities compound each other: machine-learning models are precisely the tools that turn raw quantum measurements and decrypted archives into usable inference.

Harvest-now-decrypt-later: encrypted archives collected today can be opened once a large quantum computer exists.


How harvest-now-decrypt-later puts an expiry date on today's secrets

The first attack runs through mathematics. A sufficiently large, error-corrected quantum computer running Shor's algorithm would break the RSA and elliptic-curve cryptography that secures most internet traffic, financial messaging, and government communication. No such machine exists today. That is cold comfort, because the attack does not need to wait for the machine. In a harvest-now-decrypt-later strategy, an adversary records encrypted traffic in bulk today and stores it until cryptanalytically relevant quantum computers arrive. Security authorities such as the NSA and CISA warn that adversaries may already be collecting encrypted traffic for exactly this purpose.

The consequence inverts the logic of data protection. Encryption has been treated as a durable wall. It is a wall with a demolition date. Any data whose confidentiality horizon is longer than the time to quantum decryption, including health and genomic data, sexual orientation, political affiliation, whistleblower communications, trade secrets, and state secrets, is already exposed to harvest-now-decrypt-later risk. Where ciphertext has been intercepted and retained, disclosure can follow years later, once decryption becomes feasible. In that scenario, victims may never learn that communications they sent in 2026 were read in 2036, which leaves redress, the backbone of privacy enforcement, out of reach.


The migration deadlines governments have set: 2030, 2033, 2035

Governments treat this as a scheduled risk. In August 2024, the U.S. National Institute of Standards and Technology finalized its first three post-quantum cryptography standards, FIPS 203, 204 and 205, built on the ML-KEM, ML-DSA and SLH-DSA algorithms, and urged immediate adoption. The NSA's Commercial National Security Algorithm Suite 2.0, announced in 2022, sets phased deadlines that run to 2033 for U.S. national security systems. In June 2025, the European Commission and Member States published a coordinated implementation roadmap for the transition to post-quantum cryptography: national transition plans under way by the end of 2026, critical infrastructure migrated no later than 2030, and the remainder by 2035.

For privacy lawyers the important move is to read these timelines through the GDPR. Article 32 requires security "appropriate to the risk," taking into account the state of the art. Once standardized quantum-resistant algorithms exist and public authorities on both sides of the Atlantic have declared the threat actionable, the state of the art arguably includes post-quantum readiness for data with a long sensitivity horizon, today, well before Q-day. The practical first step is the one supervisors are beginning to demand of boards: a complete cryptographic inventory that maps which systems protect which data with which algorithms for how long, a governance exercise we examined in our analysis of the cryptographic inventory as a board-level file.


How quantum sensing intrudes without intercepting any data

The second attack on privacy's temporal dimension touches no data at all. Quantum sensing exploits quantum effects to measure gravity, magnetic fields, and electromagnetic signals, and particular devices now surpass their classical counterparts in sensitivity, stability, or operating conditions. In 2022, researchers at the University of Birmingham demonstrated a cold-atom quantum gravity gradiometer that located a buried utility tunnel beneath a real road, the first such survey to succeed outside laboratory conditions. Scaled into arrays on vehicles, drones, or satellites, gravimetric and magnetometric sensing could, in constrained settings, render parts of the built environment effectively transparent. Interior voids, underground shelters, and the layout of private facilities become reconstructable from outside the property line, without entry, without line of sight, and without a single byte intercepted.

The maturity picture deserves the same precision. Quantum radar remains largely a laboratory demonstration, and no sensor reads thoughts. Privacy law should nonetheless register what the trajectory does to its own foundations. Surveillance doctrine distinguishes what is visible from a public vantage point from what requires physical intrusion, and human-rights instruments such as Article 17 ICCPR protect the home on the assumption that walls and ground provide practical obscurity. Remote quantum measurement dissolves that assumption. Nothing is hacked; something is measured. Data-protection law can engage once measurements relating to an identifiable person are recorded or inferred, but the physical obscurity on which home and surveillance law rely has by then already been bypassed.

Quantum gravimetry and magnetometry could map the built environment from the street without entering any property.


Why wearable brain sensors make neurorights an early model for quantum-sensing law

The most intimate sensing frontier is the brain. Optically pumped magnetometers have made magnetoencephalography wearable: helmet-based systems now record brain activity while the subject moves naturally, and nitrogen-vacancy centers in diamond can detect the faint magnetic signatures of neural activity in laboratory settings. The physics does not permit cinematic mind-reading. Combined with task-specific models and artificial intelligence trained on large neuroimaging datasets, it does support limited inferences about particular cognitive or affective correlates, such as attention or recognition, without giving general access to mental states. The temptations are easy to foresee: attention monitoring in workplaces and schools, "intention screening" at borders, crowd-arousal measurement at protests. These themes also surfaced in the NATO StratCom workshop on quantum and cognitive sovereignty.

Law is beginning to respond. Chile amended its constitution in 2021 to protect mental integrity and brain-derived information, and in 2023 its Supreme Court applied that protection in a ruling on neural data involving a consumer EEG headset. In November 2025, UNESCO's General Conference adopted the first global standard on the ethics of neurotechnology, extending its scope to inferred mental states and warning against workplace neuro-monitoring. The neurorights debate is often filed under biotech ethics. It is better understood as an early model for quantum-sensing governance, because it protects a signal close to the point of measurement instead of only at the point of processing.

Wearable quantum magnetometers move neural measurement, and the neurorights debate, out of the laboratory.


What forward-dated privacy law would require of regulators

The cryptanalytic and sensing threats share one effect: each defeats privacy law's implicit present tense. Consent, purpose limitation, and security measures are all assessed at the moment of collection, and quantum capabilities re-price that moment years later. The intelligence-law insight of the mosaic theory, that innocuous fragments aggregate into revealing wholes, acquires a fourth dimension. Fragments harvested or measured across decades can be assembled retroactively by whoever first commands the decryption and sensing advantage. That asymmetry between early quantum haves and have-nots is itself a privacy problem, with consequences for surveillance, market power, and democratic oversight explored in Ethics in the Quantum Age.

The remedy is to make privacy law forward-dated, which forces an explicit comparison between two lifetimes that regulation has never had to compare before. Every dataset has a sensitivity lifetime. Every cryptographic system has a security lifetime. Wherever the first exceeds the second, today's compliance is tomorrow's breach. Concretely, this means post-quantum migration obligations calibrated to data-sensitivity horizons instead of uniform deadlines; retention rules that treat long-stored encrypted data as a liability; warrant and proportionality standards that treat high-resolution remote sensing as the search it functionally is; and purpose limitation and licensing for quantum-derived inference, with neural data in the highest protection tier. None of this requires new physics. It requires the recognition, developed across the Quantum ELSPI research agenda, that these are governance design problems to be engaged while the technology is still malleable. The stakes extend beyond confidentiality to the integrity of records themselves, a theme of the Stanford talk on quantum technology and the end of stable records delivered by Professor Mauritz Kop.

The compact version for lawmakers: quantum computing has already changed the legal meaning of "secure," and quantum sensing is about to change the legal meaning of "private." Regulators who date-stamp their privacy frameworks, asking "protected until when, and against whom?", can keep the end of privacy where it belongs, as a scenario and never a schedule.

Last updated: September 3, 2026