Innovation, Quantum-AI Technology & Law

Blog over Kunstmatige Intelligentie, Quantum, Deep Learning, Blockchain en Big Data Law

Blog over juridische, sociale, ethische en policy aspecten van Kunstmatige Intelligentie, Quantum Computing, Sensing & Communication, Augmented Reality en Robotica, Big Data Wetgeving en Machine Learning Regelgeving. Kennisartikelen inzake de EU AI Act, de Data Governance Act, cloud computing, algoritmes, privacy, virtual reality, blockchain, robotlaw, smart contracts, informatierecht, ICT contracten, online platforms, apps en tools. Europese regels, auteursrecht, chipsrecht, databankrechten en juridische diensten AI recht.

Berichten in Cybersecurity
Na 17.000 machinehandelingen begint het juridische incidentdossier

Een aanval die bleef doorwerken

Hugging Face meldde op 16 juli 2026 een cyberincident dat volgens het bedrijf van begin tot eind door een autonoom agentsysteem werd uitgevoerd. Een kwaadaardige dataset misbruikte twee code-executiepaden in de dataverwerking. Daarna volgden toegang op nodeniveau, het verzamelen van credentials en laterale beweging door interne clusters. Het bedrijf reconstrueerde meer dan 17.000 gebeurtenissen uit de aanvallerslog. Hugging Face vond geen aanwijzingen dat openbare modellen, datasets, Spaces of de software supply chain waren gemanipuleerd.

De melding laat één belangrijk gat open: het gebruikte taalmodel is niet bekend. Dat is juridisch gezond. Een autonome campagne bestaat uit een model, een uitvoeringsharnas, tools, accounts, kwetsbare software en toegekende bevoegdheden. Wie meteen een modelmerk aanwijst, slaat de causale keten over. De verdedigende kant gebruikte eveneens AI: Hugging Face analyseerde de logs lokaal met een open-weight model, omdat commerciële API's echte aanvalspayloads blokkeerden en omdat credentials en aanvallersdata zo binnen de eigen omgeving bleven.

Vier routes, vier verschillende vragen

Het label AI-incident bepaalt nog geen meldplicht. Artikel 55 AI Act richt zich op aanbieders van general-purpose AI-modellen met systeemrisico en noemt adversarial testing, risicobeheersing, incidentdocumentatie en cyberbeveiliging. Artikel 73 ziet op aanbieders van high-risk AI-systemen en koppelt melding aan wettelijk omschreven ernstige gevolgen. Wanneer een onderzoeksingreep het systeem zo zou wijzigen dat latere oorzaakevaluatie wordt beïnvloed, moet de aanbieder de bevoegde autoriteiten daar vooraf over informeren; deze regel blokkeert onmiddellijke containment of noodzakelijke correctie niet.

NIS2 beoordeelt significante incidenten bij entiteiten die binnen haar sectorale scope vallen. De Nederlandse Cyberbeveiligingswet is inmiddels gepubliceerd en treedt op 15 augustus 2026 in werking; zij vervangt dan de Wbni. De AVG kijkt naar een inbreuk in verband met persoonsgegevens en het risico voor betrokkenen. Contracten kunnen al bij gestolen credentials of ongeautoriseerde toegang een melding eisen. Eén technisch incident kan daardoor verschillende klokken starten, met andere adressaten en drempels. De gedeelde tijdlijn moet vastleggen wanneer een team iets zag, wat het toen wist en waarom een route wel of niet is geactiveerd.

Van actielog naar controleerbaar bewijs

Een machine kan duizenden gebeurtenissen snel samenvatten. Een toezichthouder heeft daarnaast bronlogs, tijdstempels, systeem- en modelversies, accountrechten, beslissingen en resterende onzekerheden nodig. De ruwe feiten en de interpretatie horen in afzonderlijke lagen. Wie alleen de door een model geschreven tijdlijn bewaart, kan later niet meer aantonen welke gebeurtenis is weggelaten of verkeerd verbonden. Forensisch bewijsbehoud omvat daarom ook de versie en configuratie van het verdedigende model.

Een overdraagbaar incidentdossier verbindt per gebeurtenis de actor, bevoegdheid, getroffen component, bronlog, impact, juridische route, maatregel en externe melding. Die structuur maakt onderscheid tussen de aanvallende agent, het verdedigende analysemodel en een eventueel getroffen AI-product. Zij maakt ook zichtbaar wie een agent kon stilzetten en welke leverancier toegang tot de relevante logs had. De juridische arbeid begint dus op het moment dat de technische reconstructie snel genoeg lijkt.

Meer lezen
CNAS Interviews Mauritz Kop for The Entanglement Edge Quantum Networking Report

The Center for a New American Security has published The Entanglement Edge: U.S. Strategic Priorities in Quantum Networking—and Mauritz Kop briefed the CNAS research team on quantum networking and cybersecurity in November 2025, as part of the expert interviews behind it.

The entanglement edge, soberly measured

The report by Constanza M. Vidal Bustamante and Morgan Peirce declines the hype on both sides. Quantum key distribution is a niche complement, not a replacement, for post-quantum cryptography; China's 10,000-kilometer QKD network is real infrastructure but not next-generation readiness; and America's task is to fund what compounds—interconnects, benchmarks, supply chains, PQC migration—while declining to subsidize theater.

Where Kop's briefing landed

Kop gave the researchers an administrable rule: "PQC by default"—QKD only where incremental assurance can be proven over cost and complexity, quantum random-number generators widely for stronger entropy. His briefing pressed the shift from guidance to verifiable outcomes: a federal transition lead with a public dashboard, procurement requiring validated FIPS 203/204/205 modules, crypto-agility drills, and allied "one test, many markets" certification so the coalition's cryptographic baseline cannot fracture into a quantum splinternet. It is the operational sequel to the positions he brought to the U.S. Department of State on quantum technology and foreign policy.

What planners should take away

The harvest-now, decrypt-later campaigns are already running; the contest that decides their outcome is over verification—whose security architecture can be tested, certified, and trusted across an alliance. Reports built on dozens of expert interviews, rather than vendor decks, are how that architecture gets designed before the deadline arrives.

Meer lezen
GARP Interviews Mauritz Kop on Quantum Governance Strategies for Risk Professionals

The Global Association of Risk Professionals (GARP) interviewed Mauritz Kop for David Weldon's article Full-Scale Quantum Computing May Be Years Away. Risk Mitigation Can't Wait.—bringing quantum governance to the desks of risk professionals worldwide.

Q-Day is the wrong question

Kop's message to the risk profession inverts the usual timeline anxiety. The immediate danger is not a cinematic moment when encryption falls; it is the quiet accumulation of harvested data—financial records, identity data, health and government archives—collected today for decryption tomorrow, compounded by weak vendor oversight and a lack of crypto-agility. Records that outlive their cryptography may already face that exposure, whatever the hardware roadmaps say.

Five must-haves for a quantum governance strategy

The strategy Kop laid out is deliberately operational: a PQC migration roadmap anchored in asset classification and harvest-now-decrypt-later exposure; board-level ownership; integration with existing cyber, model, and operational risk frameworks; vendor due diligence on quantum-safety claims; and independent testing and benchmarking instead of marketing trust. Layered across architecture, algorithms, and operations, it treats quantum as an extension of disciplines risk professionals already command—the same principles-to-practice arc as the global quantum policy brief he co-authored at CIGI.

From the trading floor to the boardroom

Quantum, Kop argues, is both threat and tool for finance: it endangers the confidentiality of everything archived, and it is being explored for better simulation, optimization, and risk discovery. His benchmark for the U.S.: core post-quantum migration substantially done before 2030 for long-lived data and critical systems. The institutions that will meet that deadline are the ones whose boards treat quantum readiness as governance, not as someone else's research project.

Meer lezen
Cyber Week 2021 Tel Aviv University Israel

AIRecht Director Mauritz Kop will speak at Cyber Week 2021 Tel Aviv University Israel, and participate in the Panel 'Debating Collective Cyber Defense for Democracies'. He will present his Stanford essay ‘Democratic Countries Should Form a Strategic Tech Alliance’ on July 22nd at 20:00 Israel time, see: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3814409

Cyber Week 2021 hosts a range of distinguished speakers from across the globe, including the Prime Minister of Israel Naftali Bennett, see: https://cw2021.b2b-wizard.com/expo/speakers

Debating Collective Cyber Defense for Democracies

Line-up and speakers of the ‘Debating Collective Cyber Defense for Democracies’ panel (notice the strong Dutch@Stanford representation):

Keynote: Ambassador Heli Tiirmaa-Klaar, Ambassador-at-Large for Cyber Diplomacy at the Estonian Ministry of Foreign Affairs

Lectures by:

Prof. Chris Demchak, Strategic and Operational Research Department, U.S. Naval War College

Lior Tabansky, Ph.D., (Moderator), Head of Research Development, Blavatnik Interdisciplinary Cyber Research Center, Tel Aviv University

Mauritz Kop, Stanford Law School TTLF Fellow, Founder of MusicaJuridica, and Strategic Intellectual Property Lawyer at AIRecht

Marietje Schaake, International Policy Director at the Cyber Policy Center; International Policy Fellow at the Institute for Human-Centered Artificial Intelligence, Stanford University

See the complete agenda at: https://cw2021.b2b-wizard.com/expo/agenda

Democratic Countries Should Form a Strategic Tech Alliance

Kop’s essay titled ‘Democratic Countries Should Form a Strategic Tech Alliance’ concludes that to prevent authoritarianism from gaining ground, democratic governments should do four things: (1) inaugurate a Strategic Tech Alliance, (2) set worldwide core rules, interoperability & conformity standards for key 4IR technologies such as AI, quantum, 6G and Virtual Reality (VR), (3) win the race for 4IR technology supremacy, and (4) actively embed our common democratic norms, principles and values into the architecture and infrastructure of our technology.

REGISTER for the conference following the link: https://cw2021.b2b-wizard.com/expo/home

Meer lezen