Innovation, Quantum-AI Technology & Law

Blog over Kunstmatige Intelligentie, Quantum, Deep Learning, Blockchain en Big Data Law

Blog over juridische, sociale, ethische en policy aspecten van Kunstmatige Intelligentie, Quantum Computing, Sensing & Communication, Augmented Reality en Robotica, Big Data Wetgeving en Machine Learning Regelgeving. Kennisartikelen inzake de EU AI Act, de Data Governance Act, cloud computing, algoritmes, privacy, virtual reality, blockchain, robotlaw, smart contracts, informatierecht, ICT contracten, online platforms, apps en tools. Europese regels, auteursrecht, chipsrecht, databankrechten en juridische diensten AI recht.

EBA, EIOPA en ESMA op 23 september 2026: frontier-AI, quantumcomputing en niet-EU-leveranciers als risico voor banken en verzekeraars. Wat DORA en de AI Act vragen

Wat de Europese toezichthouders op 23 september 2026 publiceerden

EBA, EIOPA en ESMA publiceerden op 23 september 2026 hun gezamenlijke risico-update voor het najaar (JC 2026 29). Het rapport is een samenvatting van de risicobeoordeling die de drie toezichthouders voorleggen aan de Financial Stability Table van het Economisch en Financieel Comité. Het behandelt drie thema's: de afhankelijkheid van de Europese financiële sector van partijen buiten de EU, de samenhang van die afhankelijkheid met cyber- en AI-risico, en private credit. Volgens een enquête van de EBA noemt ongeveer 80 procent van de banken de afhankelijkheid van ICT-dienstverleners buiten de EU/EER de grootste uitdaging. Cloud, software, betalingsverkeer, clearing en kredietbeoordelingen lopen voor een groot deel via ondernemingen buiten de Unie.

Frontier-AI en quantumcomputing als risico voor de financiële sector

De toezichthouders schrijven dat frontier-AI-modellen kwetsbaarheden in IT-systemen met grote snelheid en op grote schaal kunnen vinden en uitbuiten, ook nog onbekende zero-day-lekken. Over quantumcomputing staat er dat een geavanceerde quantumcomputer cryptografie kan ondermijnen die communicatie, transacties, databases en blockchains beveiligt, dat die dreiging zich eerder kan voordoen dan een bruikbare commerciële toepassing, en dat gegevens die vandaag worden onderschept later kunnen worden ontsleuteld. Wie op een klein aantal leveranciers buiten de EU steunt, loopt die risico's via schakels die hij niet zelf beheert. Het artikel legt de verbinding met Herstatt-risico, het afwikkelingsrisico dat zichtbaar werd bij de sluiting van Bankhaus Herstatt op 26 juni 1974: tegenpartijen hadden hun Duitse marken betaald en ontvingen de dollars in New York nooit.

Wat DORA en de AI Act nu al vragen

DORA (Verordening (EU) 2022/2554) geldt sinds 17 januari 2025 en regelt in de artikelen 28 tot en met 31 het beheer van ICT-derdenrisico, concentratierisico, de minimale inhoud van contracten en het Europese toezicht op kritieke ICT-aanbieders. Artikel 6, lid 4, van Gedelegeerde Verordening (EU) 2024/1774 verplicht instellingen om in hun encryptiebeleid op te nemen hoe zij hun cryptografie waar nodig aanpassen op basis van ontwikkelingen in de cryptoanalyse; een vaste overstapdatum voor post-quantumalgoritmen staat er niet in. De AI Act voegt eisen toe aan AI-systemen met een hoog risico (artikel 15) en aan aanbieders van modellen die als model met een systeemrisico zijn geclassificeerd (artikelen 51 en 55), met overgangstermijnen tot 2 augustus 2027 voor modellen die al vóór 2 augustus 2025 in de handel waren. Het artikel eindigt met vijf vragen voor bestuur en inkoop bij een ICT-contract onder DORA, over datalocatie, concentratie, post-quantumcryptografie, AI-componenten en exit, en legt uit waarom dit rapport voor Nederlandse banken, verzekeraars, pensioenfondsen en hun leveranciers een ijkpunt is.

Meer lezen
Quantum-AI: Nondeterministic Computing and the Exponential-Speedup Claim, Audited

Every technology cycle has its incantation, and quantum computing's is "exponentially faster." The phrase is true just often enough to be dangerous. Quantum algorithms hold a superpolynomial advantage over the best known classical methods for factoring, may deliver substantial advantages on specific quantum-simulation problems, and have provable speedups on a handful of engineered learning problems; none of that establishes a general exponential speedup, and for most workloads the advantage is unproven. This analysis audits the exponential speedup claim against the mathematical results and asks what remains for boards, courts, and regulators once the slogan is stripped away.

Where the proven speedups are, and where they are missing

The scoreboard is more precise than the headlines. Shor's algorithm genuinely threatens public-key cryptography. Grover's algorithm delivers a quadratic gain. Quantum computers are not known to solve NP-complete problems efficiently: the machine does not "try all answers at once," it choreographs interference. We walk through the fine print that separates proven quantum advantage from investor prose, including the caveats attached to famous algorithms for linear algebra and machine learning.

How a bank-backed research collaboration demonstrated certified quantum randomness in 2025

A quantum state evolves deterministically between measurements, but the measurement that ends a computation is probabilistic: the same circuit, run twice, may return different answers, and correctness is a property of distributions. This nondeterministic behavior is physical randomness, distinct from the nondeterministic machines of complexity theory. That is comfortable for machine learning and uncomfortable for verification, audit, and liability. The strangeness is already monetizable. In 2025 a commercial trapped-ion processor produced certifiably random bits, converting physical indeterminacy into a compliance-grade evidentiary object. Meanwhile the reverse direction matured quietly: artificial intelligence now designs error-correction decoders and calibrates quantum hardware, closing a loop in which each field accelerates the other.

What the EU AI Act needs before quantum-AI systems reach the market

The governance stakes do not wait for quantum advantage. The EU AI Act imposes accuracy, robustness, and testing duties without requiring deterministic outputs, and hybrid quantum-classical pipelines will need validation suited to probabilistic behavior. They demand conformity assessment that samples and bounds distributions, plus technical documentation covering two failure surfaces at once, statistical learning and hardware noise. Transparency-first instruments are already the trend in AI regulation, as we analyzed for California's frontier-model disclosure regime in the Daiki SB-53 recipe for frontier AI transparency. Quantum-AI extends that logic to the physics itself.

The full analysis separates the three real speedup regimes, explains barren plateaus and dequantization in plain language, and closes with a concrete agenda for governing quantum technology before the inflection point: distributional testing, dual technical files, and certified entropy standards.

Meer lezen
Musical Interludes at the 2nd Annual Stanford Responsible Quantum Technology Conference

A quantum governance conference with a concert program sounds like an ornament until you sit through one. At the second annual Stanford gathering on responsible quantum technology, held on May 20, 2024, the musical interludes were scheduled with the same care as the keynotes, and they earned their place in the day.

What standing waves in a piano teach a policy audience about qubits

Many acoustic instruments produce standing waves: strings and air columns vibrate in superposed overtones, and their interference decides what the ear hears. That is a genuine classical analogue of the wave interference at the heart of quantum computation, which is why a live performance can hand a policy audience a physical intuition that no diagram delivers.

The program: from Chopin to Schubert and Schoenberg, performed by the conference community

The day's music ran from Chopin's Grande Polonaise Brillante to Schubert's Der Hirt auf dem Felsen and Schoenberg's Opus 11, a wide arc from tonal to atonal, performed by musicians from within the conference's own community. The Stanford Law School stage has form here. The same campus culture that staged operetta with the Stanford Light Opera Company, see Johann Strauss' Die Fledermaus, treats performance as part of intellectual life.

Why shared music builds the trust an interdisciplinary field runs on

Interdisciplinary fields fail socially before they fail intellectually. Physicists, lawyers, ethicists, and diplomats arrive with different vocabularies and different status games, and a shared aesthetic experience is one of the few fast ways to make one community out of four professions. Twenty minutes of Chopin does more for cross-disciplinary candor than any icebreaker, because it asks nothing of anyone except attention. The interludes rehearsed the very trust that responsible quantum governance, and responsible artificial intelligence before it, depend on.

The full post reconstructs the program of May 20, 2024, names the performers who carried it, and explains why the arts-science bridge works as a governance tool, with the conference summary archived at Stanford for readers who want the substance behind the songs.

Meer lezen
Genesis Q (DOE, 17 september 2026): 215 miljoen dollar, in fase II pas bij 100 aangetoonde logische qubits. Wat dit betekent voor Europese quantuminkoop onder Richtlijn 2014/24/EU

Wat het DOE op 17 september 2026 uitzette

Het Amerikaanse Department of Energy kondigde op 17 september 2026 de Quantum Genesis Q Competition aan: tot 215 miljoen dollar, met in fase I vaste bedragen tot 1,5 miljoen dollar per deelnemer voor vroege mijlpalen en in fase II een pot van 100 miljoen dollar voor wie een foutbestendige quantumcomputer met ten minste 100 logische qubits demonstreert, plus bonuspotten van 50 miljoen dollar voor 150 en 200 logische qubits. Aanvragen sluiten op 19 oktober 2026. Van het bedrag is in 2026 slechts 2,5 miljoen dollar beschikbaar; de rest hangt af van het Congres. Naast de prijs financiert het DOE een apart keuringstestbed van 45 miljoen dollar bij de nationale laboratoria, los van de prijzenpot. In het rapport van de SCAC Quantum Subcommittee van september 2026 bepleiten geïnterviewde partijen onafhankelijke, reproduceerbare benchmarks die steeds tegen de beste klassieke methode worden afgezet, en inkoop op basis van aangetoonde prestaties in plaats van alleen roadmaps van leveranciers.

Waarom de definitie van een logische qubit het prijzengeld verdeelt

Een logische qubit is een prestatieclaim die afhangt van de foutcorrectiecode, de codeafstand, de decoder en het foutmodel. Twee leveranciers kunnen met dezelfde fysieke qubits tot verschillende aantallen komen. Wie de definitie in de stukken schrijft, bepaalt wie wint. Het artikel legt de constructie naast de Longitude Act van 1714, waarin het Britse parlement een prijs uitloofde die pas na een proefvaart en een oordeel van de Board of Longitude werd uitbetaald, en laat zien dat het conflict tussen Harrison en de Board over de acceptatievoorwaarden de waarschuwing is die in 2026 nog geldt.

Wat Europese en Nederlandse inkopers hiermee kunnen

Richtlijn 2014/24/EU kent met het innovatiepartnerschap van artikel 31 en de prestatiegerichte specificaties van artikel 42 de instrumenten om betaling aan een gedemonstreerd resultaat te koppelen; de Aanbestedingswet 2012 neemt ze over in de artikelen 2.31a, 2.75 en 2.76. Het gelijkheids- en transparantiebeginsel eisen dan wel dat de meetmethode vooraf vastligt en niet tijdens de rit wordt bijgesteld; de keurende partij vooraf benoemen is een praktische aanbeveling om belangenconflicten te vermijden. De Quantum Europe Strategy van 2 juli 2025 beloofde een Quantum Act die de gemeenschappelijke benchmark zou kunnen dragen; die verordening is er nog niet. Het Nationaal Groeifonds werkt bij Quantum Delta NL al met fasen van 54, 228 en 333 miljoen euro en met mijlpalen als subsidieverplichting in de beschikking van 18 december 2025; die gepubliceerde beschikking noemt zelf geen door een onafhankelijk laboratorium bevestigd aantal logische qubits als betalingsvoorwaarde. Het artikel sluit af met vijf vragen die elke Europese quantuminkoper of subsidiegever nu in de stukken moet zetten, van de codeafstand tot de eigendom van de meetdata.

Meer lezen
Statute-Led Quantum Governance: A Legislative Blueprint for the United States

On June 22, 2026, the White House signed two quantum executive orders in one afternoon: a national push toward a science-enabling quantum computer, and an accelerated federal migration to post-quantum cryptography. The orders are far-reaching and structurally fragile. A later administration can amend or revoke executive action far more easily than Congress can repeal a statute, and executive action cannot appropriate a dollar or settle the values by which quantum technology will be governed. That work belongs to Congress.

What Congress has in motion in 2026 and why it is still revocable

The 2026 federal landscape is busy and brittle. The National Quantum Initiative reauthorization is moving through both chambers after its predecessor died with the 118th Congress, a $2.5 billion Department of Energy quantum bill waits alongside it, and export controls on quantum computing arrived by interim rule in 2024. Every instrument is revocable, expirable, or reversible. The United States has quantum legislation in the National Quantum Initiative Act and still lacks a comprehensive quantum statute. Governing by summit communiqué instead of binding rule is a wider habit, as our analysis From Kananaskis to Évian shows for the G7.

Why statutes serve foundational technologies better than accreted guidance

Foundational technologies mature on timescales longer than administrations, cut across agency jurisdictions, and allocate power in ways that deserve democratic sanction. The artificial intelligence precedent is cautionary: congressional silence produced a state patchwork in which Colorado's pioneering AI statute was rewritten before it ever took effect. A quantum statute with values-based guardrails, from risk tiers to trials pathways and access equity, is innovation policy in its own right. It gives investors, allies, and the public reasons to trust the ecosystem being built.

The eight-part blueprint for a United States quantum act

The full analysis lays out an eight-part legislative blueprint: capability-based definitions that survive hardware generations, risk-tiered obligations, statutory post-quantum cryptography deadlines, a standing standards mandate for NIST, regulatory sandboxes, calibrated research security, national quantum-advantage missions with a software institute, and workforce plus allied coordination. It merges the reauthorization bills, the DOE act, and the executive orders into one coherent act of Congress.

Europe's Quantum Act proposal is expected in 2026, and the EU has made statute-led governance its brand, from the AI Act's risk tiers to the Quantum Europe Strategy. America's answer should be transatlantic interoperability: shared risk concepts, mutual recognition, aligned export regimes. The reauthorization vehicles moving through both chambers this session give Congress a rare moment when legislative ambition costs little more than drafting. Read the full analysis for the blueprint and the case for using that moment.

Meer lezen
Mag een pacing-afspraak tussen AI-labs onder artikel 101 VWEU? Fergusons waarschuwing van 15 september 2026, het AdBlue-kartelbesluit van 8 juli 2021 en de route van artikel 56 AI Act

Op 8 juli 2021 beboette de Europese Commissie BMW en de Volkswagen-groep voor 875 miljoen euro omdat zij met Daimler hadden afgesproken hoe groot de AdBlue-tank in hun dieselauto's zou zijn. Niemand had prijzen afgesproken; de fabrikanten hadden afgesproken om niet te wedijveren op schoner rijden dan de wet eiste. Het was het eerste kartelbesluit dat uitsluitend rustte op een beperking van de technische ontwikkeling, het verbod uit artikel 101, lid 1, onder b, VWEU. Dit artikel legt dat besluit naast wat Dario Amodei op 12 september 2026 aan de Amerikaanse overheid vroeg: een smalle antitrustvrijstelling zodat AI-laboratoria samen het tempo van hun ontwikkeling kunnen afspreken.

Wat Ferguson op 15 september 2026 zei en wat Khan twee dagen eerder schreef

FTC-voorzitter Andrew Ferguson zei op 15 september 2026 dat iedereen "deeply suspicious" moet zijn van AI-bedrijven die om antitrustvrijstellingen vragen terwijl ze tegelijk lobbyen voor nieuwe regels. Oud-voorzitter Lina Khan bracht op 13 september het spiegelbeeld naar voren: er bestaat volgens haar geen AI-uitzondering op bestaande wetten, en zij wees op FTC v. Keppel uit 1934 als mogelijk aanknopingspunt voor een lab dat onveilige systemen uitbrengt en concurrenten zo onder druk zet. In vier dagen kreeg de Amerikaanse discussie zo twee vragen: mag men samen vertragen, en wat gebeurt er als één partij alleen versnelt.

Welke ruimte de Horizontale Richtsnoeren van 2023 en de ACM-beleidsregel bieden

In de EU bestaat geen individuele ontheffing meer; partijen beoordelen zelf of hun afspraak aan artikel 101, lid 3, voldoet. Hoofdstuk 9 van de Richtsnoeren inzake horizontale samenwerkingsovereenkomsten van 21 juli 2023 geeft in punt 549 zes cumulatieve voorwaarden voor duurzaamheidsnormeringsafspraken tussen concurrenten, en de ACM-beleidsregel van oktober 2023 volgt die aanpak; wie erbuiten valt, krijgt een individuele beoordeling. Het artikel houdt drie soorten afspraken uit elkaar: een gezamenlijke veiligheidsnorm, een gezamenlijke afspraak om een model niet uit te brengen, en een gezamenlijk plafond aan trainingsrekenkracht. De laatste is in de vergelijking de omvang van de tank, en de vier voorwaarden van artikel 101, lid 3, worden per stuk nagelopen.

Waarom artikel 56 AI Act een nalevingskanaal is en geen antwoord op de tempovraag

Amodei vraagt om een forum waarin de overheid het gesprek mogelijk maakt zonder mee te praten. In de EU bestaat zo'n forum met een beperkter doel: artikel 56 van de AI-verordening draagt het AI-bureau op praktijkcodes voor AI-modellen voor algemene doeleinden te faciliteren, en de code van 10 juli 2025 biedt een aanbieder van een model met systeemrisico een manier om zijn eigen naleving jegens de toezichthouder aan te tonen. Zij is vrijwillig, legt geen gezamenlijk ontwikkelingstempo vast en spreekt niet over rekenkracht; punt 597 van de richtsnoeren maakt bovendien duidelijk dat betrokkenheid van een overheid een afspraak niet aan artikel 101 onttrekt. Het artikel sluit af met vijf toetsvragen voor een onderneming die overweegt aan een veiligheidsafspraak met concurrenten mee te doen, en met wat dit betekent voor Nederlandse afnemers van frontier-modellen en voor de rol van de ACM.

Meer lezen
Quantum and the End of Privacy: Harvest-Now-Decrypt-Later, Quantum Sensing, and Forward-Dated Data Protection Law

Every privacy regime ever written shares one silent assumption: protection assessed today stays valid tomorrow. Quantum technology breaks that assumption twice, once by putting an expiry date on modern encryption and once by making the physically hidden measurable. This analysis maps both fronts and asks what a forward-dated privacy law would look like.

Two quantum clocks: decryption deadlines and quantum sensors

The first clock is cryptanalytic. Adversaries are recording encrypted traffic now, betting that future quantum computers will unlock it. This harvest-now-decrypt-later strategy has pushed NIST, the NSA, and the European Commission to set migration deadlines running from 2026 to 2035. Any data that must stay confidential longer than the migration takes is already exposed to that risk; if the ciphertext has been retained, only the disclosure date is open.

The second clock is metrological. Quantum gravimeters have located tunnels under real roads, and wearable magnetometers read the brain's faint magnetic signals while the wearer moves freely. This is quantum sensing: privacy intrusion without interception, where nothing is hacked because something is measured, and the physical obscurity that home and surveillance law rely on is gone before any legal safeguard applies.

How fragments collected over decades become one retroactive picture

Between these clocks sits an uncomfortable synthesis. Fragments harvested or measured across decades can be assembled retroactively by whoever gains the quantum edge first: the mosaic theory of intelligence law, extended into the future tense. The asymmetry between early quantum haves and have-nots becomes a fundamental-rights question, first examined when Mauritz Kop advised Yale Law School's Lowenstein Human Rights Project on quantum technology.

What forward-dated data protection law would change in practice

The governance proposal is concrete. Compare every dataset's sensitivity lifetime against its cryptosystem's security lifetime, and treat any mismatch as a present-day compliance gap under the GDPR's state-of-the-art standard. Calibrate post-quantum migration duties to data horizons, treat long-retained encrypted archives as liabilities, and regulate high-resolution remote sensing as the search it functionally is.

Chile's constitutional neurorights, UNESCO's 2025 neurotechnology recommendation, and the EU's coordinated post-quantum roadmap show that the pieces already exist. What is missing is the temporal frame that connects quantum computing, artificial intelligence, and privacy into a single question for regulators: protected until when, and against whom? The full analysis sets out the timelines, the case law, and the policy blueprint.

Meer lezen
Quantum ELSA and ELSPI in North America: Mauritz Kop Co-Authors a UNESCO International Year of Quantum Book Chapter

One hundred years after quantum mechanics upended physics, the United Nations proclaimed 2025 the International Year of Quantum Science and Technology and asked what the next hundred should look like. A new chapter co-authored by Mauritz Kop for a volume in the Year's scholarly program answers for one region, mapping the quantum ELSPI, the ethical, legal, social, and policy implications, of quantum technologies across the United States and Canada.

Where North American quantum governance is actually decided

The chapter's premise is practical. North America's quantum economy runs through cloud platforms and proprietary toolchains, which means the consequential governance decisions are being made in standards bodies, procurement offices, and competition policy, long before any parliament passes a dedicated quantum law. Providers of quantum hardware, benchmarks, and developer tooling shape access conditions and technical practice alongside formal regulators and standards bodies.

That reframing matters for the security agenda too. The migration to post-quantum cryptography is the region's major near-term quantum security program, driven by the prospect that future quantum computers could break today's public-key encryption, and by adversaries harvesting encrypted data now in order to decrypt it later.

How the ELSA lens widened into ELSPI

Behind the chapter stands a research field with a Stanford pedigree. Quantum ELSPI widens the classic ethical-legal-social lens to include policy, market structure, intellectual property, and national security, treating ethics as an operating model to be executed, audited, and improved. The chapter applies the same operational turn that artificial intelligence governance took when principles were translated into controls, documentation, and assurance.

The author team mirrors that ambition: quantum physicist Shohini Ghose, security scholar Lindsay Rand, legal scholar Mauritz Kop, Bruna Shinohara de Mendonça, and Karl Thibault, a multidisciplinary blend Kop has brought into international institutions before, including his work consulting UNESCO and the OECD on quantum ethics and technology policy.

What the chapter forecasts for the next five to ten years

The chapter closes with a five-to-ten-year outlook on how North American quantum technology governance is likely to evolve, from supply-chain chokepoints and export controls to sector-by-sector assurance regimes, grounded in how the ecosystem is actually structured.

For readers in government, industry, or research management, it doubles as a checklist: if your organization touches quantum systems, your cryptographic inventory, procurement clauses, and standards participation are where responsible quantum begins. The full announcement explains what the chapter argues, who wrote it, and why the UNESCO-led Year gives it unusual reach.

Meer lezen
Ingebedde AI-evaluatoren bij Anthropic en OpenAI: wat de beloften van 12 september 2026, het Senaatsontwerp van Thune, Cruz en Klobuchar en artikel 55 en 92 AI Act voor Nederlandse afnemers betekenen

Op 12 september 2026 beloofde Dario Amodei in het essay We Must Pace the Frontier dat Anthropic een team externe evaluatoren permanent in huis gaat halen, met bureaus, toegangspassen en het recht om bevindingen te publiceren zonder redactionele controle. Sam Altman zegde dezelfde dag op X toe dat OpenAI hetzelfde doet. Een dag eerder, op 11 september, meldde Politico dat senatoren Thune, Cruz en Klobuchar werken aan een wet die gevaarlijke capaciteiten vóór de release aan het Department of Commerce laat melden, met een injunction als stok achter de deur. Dit artikel legt beide ontwikkelingen naast de architectuur die de EU al heeft: artikel 55 en 92 van de AI-verordening.

Wat de belofte van 12 september 2026 inhoudt

De ingebedde evaluatoren van Anthropic beoordelen afgeronde modellen én de trainingspijplijn waarin die ontstaan, melden incidenten en mogen openbaar zeggen wanneer een schrapping door het bedrijf iets wezenlijks heeft weggenomen. Dat verschilt van het programma dat OpenAI in november 2025 beschreef, waarin externe beoordelaars een geheimhoudingsovereenkomst tekenden en OpenAI publicaties vooraf goedkeurde. De opening ligt bij het Nederlandse Stoomwezen (keuringsvoorschriften 1824, Dienst 1855, Stoomwet 1869): de keurmeester die door het mangat de ketel in kroop.

Wat artikel 55 AI Act eist sinds 2 augustus 2025, en artikel 92 sinds 2 augustus 2026

Hoofdstuk V van Verordening (EU) 2024/1689 verplicht aanbieders van modellen met systeemrisico tot evaluatie met adversariële tests, risicobeperking, incidentmelding aan het AI-bureau en cyberbeveiliging. Artikel 92 geeft de Commissie sinds 2 augustus 2026 de bevoegdheid om, na raadpleging van de AI-board, zelf een model te evalueren wanneer de informatie over de naleving tekortschiet of bij een onderzoek naar systeemrisico's, met toegang tot API's en broncode, en sinds diezelfde dag gelden de boetes van artikel 101: tot 15 miljoen euro of 3 procent van de wereldwijde jaaromzet, naargelang welk bedrag hoger is. Het stuk legt uit waarom een evaluatie door het AI-bureau iets anders is dan een evaluator die permanent binnen zit, en welke drie elementen bepalen of zo'n toezegging iets waard is: reikwijdte van de toegang, publicatierecht en de vraag wie de evaluator betaalt.

Wat een Nederlandse afnemer hiermee doet

Voor bedrijven, ziekenhuizen en gemeenten die een frontier-model inbouwen, verschuift de vraag van beleid naar contract. Artikel 53 geeft integrerende aanbieders recht op documentatie, artikel 25 maakt een afnemer soms zelf aanbieder, en voor software die na 9 december 2026 in de handel komt telt de nieuwe productaansprakelijkheid mee. Het artikel sluit af met vijf vragen aan uw leverancier over externe evaluatie, van de omschrijving van de toegang tot een opschortingsrecht als het lab zijn toezegging intrekt.

Meer lezen
The Quantum Internet: Teleportation, Entanglement, QKD, PQC and Hybrid Security Strategies

The quantum internet will do something classical networks cannot do at all: distribute entanglement between cities, teleport quantum states, and detect interception at the protocol level. This explainer walks the whole stack for a legal and policy audience: teleportation, quantum key distribution over fiber and satellite, the NIST post-quantum standards, and the hybrid strategies that boards and ministries must adopt long before the network itself matures. The physics is subtle. The policy consequences are concrete and come with deadlines.

What Delft, The Hague and the Micius satellite have already demonstrated

The milestones are no longer thought experiments. In 2024, researchers entangled quantum processors in Delft and The Hague over 25 kilometers of ordinary underground telecom fiber, a genuine metropolitan quantum network link. China's Micius satellite has distributed quantum keys between ground stations 7,600 kilometers apart, securing a videoconference between Beijing and Vienna. The strategic significance of who builds and controls these networks is examined in the CNAS Entanglement Edge quantum networking report. Teleportation itself is routinely misread: it transfers a quantum state using entanglement plus a classical signal. No matter moves, nothing exceeds light speed, and the original state is destroyed.

Why the post-quantum deadlines exist years before the hardware

The urgency is cryptographic. A future quantum computer running Shor's algorithm breaks RSA and elliptic-curve encryption, and adversaries are already recording traffic to decrypt later, the harvest-now-decrypt-later attack. NIST answered in August 2024 with its first finalized post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) and selected the code-based HQC in March 2025 as a future backup. Migration timelines from U.S. and European authorities cluster around 2030 to 2035. For long-lived data, interception already creates the confidentiality risk, because retained ciphertext may become readable later.

How layered security replaces the search for a single quantum fix

The central argument is architectural. Security in the quantum transition comes from hybrid strategies: classical plus post-quantum key establishment, AES-256 payload encryption, QKD only on high-value links where its trusted-node risks are consciously accepted, and crypto-agility as the governing design principle. The analysis closes with a concrete sequence for enterprises and governments: build the cryptographic inventory, triage data by confidentiality lifetime, write post-quantum requirements into procurement and audits, and run quantum-network pilots with candid trusted-node risk assessments. Read on to see how physics, standards, and statecraft interlock, and why the migration calendar is an obligation of today.

Meer lezen
FIPS 140-2 wordt na 21 september 2026 historisch: gevolgen voor inkoopeisen, de zorgplicht uit de Cyberbeveiligingswet en de PQC-routekaart bij Aanbeveling (EU) 2024/1101

Amerikaanse en Canadese federale instanties mogen onder FIPS 140-2 gevalideerde modules tot en met 21 september 2026 voor nieuwe systemen accepteren; daarna verliezen de resterende validaties hun actieve CMVP-status en verhuizen zij naar de historische lijst. Er gaat geen apparaat uit en geen sleutel wordt zwakker. Wat verandert is de status van een label dat in Nederlandse hostingcontracten, leveranciersbijlagen en specificaties voor sleutelbeheer al vijftien jaar als vast ijkpunt wordt gebruikt, zonder dat het hier ooit een juridische grondslag had.

Drie lezingen van dezelfde contractzin

De zin "de module is FIPS 140-2 Level 3 gevalideerd" laat zich vanaf 22 september 2026 op drie manieren lezen, met drie verschillende uitkomsten. Als doorlopende eis dat de module een geldig certificaat draagt, levert het verlies van de actieve status een tekortkoming op zonder dat er iets aan het product mankeert, waarna pas de vraag komt of er ook verzuim intreedt. Als momentopname bij contractsluiting is de bepaling formeel intact en materieel leeg. Als gelijkwaardigheidsnorm verschuift de vraag naar wat gelijkwaardig heet, en daar zwijgt het contract meestal over. Voor aanbestedende diensten komen daar de artikelen 2.76, 2.77 en 2.78b Aanbestedingswet 2012 bij, die inschrijvers ruimte geven om gelijkwaardigheid aan te tonen met certificaten of testverslagen; een exclusieve FIPS-eis wordt pas echt problematisch wanneer zij gelijkwaardig bewijs afsnijdt. Europa heeft inmiddels een eigen route: het EUCC-schema uit Uitvoeringsverordening (EU) 2024/482, van toepassing sinds 27 februari 2025 en gebouwd op Common Criteria.

Wat wel bindt, en wat deze week alleen advies was

De Cyberbeveiligingswet geldt sinds 15 augustus 2026 en artikel 21 lid 2 onder h van de NIS2-richtlijn vraagt om beleid en procedures voor cryptografie. Artikel 32 AVG vraagt om passende maatregelen, uitdrukkelijk rekening houdend met de stand van de techniek. Beide normen zijn techniekneutraal en beide binden nu al. Daartegenover leverde de eerste week van september drie Europese signalen op die geen van alle verplichtingen scheppen: de enquêteresultaten en de FAQ van DG CNECT bij de gecoördineerde PQC-routekaart van 2 september, de oproep van de G7 Cybersecurity Working Group van 3 september die het ANSSI opstelde en die post-quantumcryptografie in overheidsinkoop wil verankeren, en het uitblijven van een gepubliceerde ontwerptekst voor de aangekondigde Quantum Act.

Het cijfer, de mijlpalen en de bewaartermijn

Op 8 september 2026 publiceerde IonQ een resource-schatting voor het breken van 256-bits handtekeningen op elliptische krommen: 25,7 dagen met 19.397 fysieke en 1.457 logische qubits. Google Quantum AI kwam eerder op ongeveer 1.200 logische qubits voor dezelfde curve, al gaan beide studies uit van andere hardware-architecturen en aannames en toont geen van beide een bestaande machine — met de kanttekening dat IonQ zelf post-quantumdiensten verkoopt. De routekaart van de NIS-samenwerkingsgroep begint eind 2026 met nationale routekaarten, inventarisatie en pilots, en houdt daarna eind 2030 aan voor toepassingen met een hoog risico en 2035 voor systemen met een middelhoog of lager risico. Een medisch dossier moet twintig jaar bewaard blijven en een notariële akte veel langer, zodat de vertrouwelijkheidshorizon van die gegevens voorbij elke mijlpaal loopt. Het artikel eindigt met zes vragen voor de eerstvolgende contractronde.

Meer lezen
Quantum Computing Use Cases in 2026: Simulation, Optimization, Machine Learning, and Cryptanalysis Ranked by Maturity

Every technology wave reaches the moment when the buyer's question changes from "what is it?" to "what is it for?" Quantum computing reached that moment between Google's below-threshold error-correction result of December 2024 and the first error-corrected chemistry calculation of 2025. The answer has four parts, simulation, optimization, machine learning, and cryptanalysis, and they are far from equally ripe. This analysis maps all four families and separates demonstrated results from projections, because that separation is where sound strategy and sound regulation both begin.

Four use-case families at four levels of maturity

Simulating molecules and materials is the application nature itself argues for: chemistry is quantum-mechanical, so quantum simulation attacks the problem in its native language. Drug discovery, battery chemistry, and catalysts carry the largest societal upside and a strong theoretical case for quantum advantage on selected problems, with practical advantage still to be demonstrated. Optimization is the family where marketing runs furthest ahead of evidence; 2025 benchmarks show classical solvers still winning on portfolio and logistics problems. Quantum machine learning sits at the frontier where artificial intelligence meets quantum hardware, promising and unproven in equal measure.

Why cryptanalysis is a use case with a compliance deadline

Cryptanalysis is different in kind. Shor's algorithm makes today's public-key encryption mortal, and the harvest-now-decrypt-later strategy means long-lived secrets are already at risk, because adversaries can record ciphertext today and decrypt it when the hardware arrives. With NIST's post-quantum cryptography standards finalized in August 2024, migration has become a concrete security and governance obligation, and in a growing number of sectors and jurisdictions a binding legal one. This is the one quantum use case with a date attached, and it is the reason cryptographic inventories are climbing onto board agendas across regulated sectors.

How each family lands in a different regulatory lane

Simulation walks into healthcare regulation, optimization into financial supervision, quantum machine learning into AI governance, and cryptanalysis into export controls. Getting the maturity story right therefore determines which rules bind, when, and whom. The framework for that kind of disciplined, values-based assessment is set out in the Stanford RQT framework and its ten principles, which anchor this analysis.

The full article walks through the demonstrated results per family, from logical qubits and benchmark studies to barren plateaus and FIPS standards, and closes with a governance map that policymakers, general counsel, and quantum technology strategists can put to work today.

Meer lezen