Quantum disentangled #5: Quantum and IP & AI – Protecting innovation in a post-quantum world
Quantum computing is set to change how businesses protect and commercialise certain IP assets, such as data, proprietary or confidential business information, including, e.g., AI models. A pharmaceutical company’s most valuable compound formula. A financial institution’s proprietary trading algorithm. The weights of a foundation AI model that took hundreds of millions of dollars to train. These assets share two characteristics: they are unregistered IP that derive their commercial value primarily from secrecy, and they are protected, in large part, by encryption.
The question is therefore no longer just whether data “in transit” is secure, but whether the intangible assets that define a company’s competitive position can survive a post-quantum world intact. The assets most affected are those whose protection depends on assumptions – about the durability of encryption, the intractability of reverse-engineering, the adequacy of contractual security obligations – that quantum computing is poised to invalidate. Businesses that act now by auditing their intangible assets for quantum exposure, reassessing protection strategies, and future-proofing their commercial agreements will be better placed to preserve the value of their innovations as the threat matures.
Intangible assets: highly exposed to quantum threats
We already covered the threat of “Harvest Now, Decrypt Later” (HNDL) attacks in previous blogposts of this series (see e.g. here). Now we would like to take a closer look at the intangible assets which derive their legal enforceability and commercial value from secrecy. Unlike a registered patent, which survives public disclosure by design, a trade secret exists only as long as it remains secret, i.e. the damage is “done” once it is exposed. For instance, a foundation model’s trained weights, its architecture, and the curated datasets used to train it are typically protected through secrecy rather than patents, or potential copyrights (which would in any case only protect original human expression, and not extend to the underlying information, ideas, procedures, methods of operation or mathematical concepts as such). Public disclosure would not only surrender competitive advantage but potentially invite replication at a fraction of the original investment. These assets are, in economic terms, likely one of the most consequential HNDL targets a technology company holds.
If the encryption underpinning the confidentiality may not survive the commercial life of the innovation, the expected value of secrecy-based protection declines relative to registration of a patent or other formal IP right (although not every trade secret is eligible for patent, trademark or design registration). For innovations eligible for a patent which have a long commercial horizon (e.g. a pharmaceutical process, a materials science breakthrough or a core machine learning technique) the decision whether to file and, in case of filing, earlier filing may therefore offer more durable protection despite the disclosure cost. In addition, for intangible assets that are not eligible for formal IP registration, copyright and related rights – such as database rights – may become the primary form of legal protection.
Legal pressure points
Existing legal frameworks do not yet address quantum risk explicitly, but several create obligations that will increasingly come into focus as the threat matures and countermeasures become available.
- “Reasonable measures” and trade secret protection. Under both the EU Trade Secrets Directive and the U.S. Defend Trade Secrets Act, legal protection requires the holder of a trade secret to take “reasonable measures” to maintain secrecy. That standard is dynamic. It evolves with available technology and recognised threats. With NIST’s post-quantum cryptography standards (PQC) now finalised and the EU’s “Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography” published last year, a failure to adopt quantum-resilient protections will become increasingly difficult to defend as “reasonable”. A company that suffers trade secret loss through quantum decryption may find that a court assesses its security posture against the standards available at the time the data was exfiltrated, not at the time it was decrypted. This stresses that companies need to think ahead already now.
- AI regulation and moving security baselines. The EU AI Act requires providers of high-risk AI systems to ensure appropriate cybersecurity. NIST’s AI Risk Management Framework ties AI security to the resilience of underlying technical controls. Neither mandates specific cryptographic standards today, but both establish obligations that will sharpen as PQC becomes the recognised baseline. For providers of high-risk AI systems, this creates a direct IP commercialisation risk: an AI system that fails to meet evolving security requirements could lose its conformity assessment and/or market access in regulated sectors – potentially rendering the underlying model and its associated IP effectively uncommercial, regardless of its technical quality. In addition, the powers of EU and Member State market surveillance authorities to access an AI system’s source code and model weights under the EU AI Act may expose providers’ most valuable intangible assets to quantum threats directed at the authorities obtaining such protected information and data. It is therefore particularly important that these authorities migrate to PQC as well and exercise their access rights only where strictly necessary for the performance of their regulatory tasks.
- The temporal adequacy gap in licensing agreements. IP and AI licensing agreements routinely frame security obligations around present-day standards (e.g. “industry-standard encryption” or “commercially reasonable measures”). These formulations could create a gap: the contractual obligation may be satisfied at signing but inadequate within the contract term. For example, a licensor that grants access to proprietary AI model weights under an AI system development agreement requiring “industry-standard encryption” may find that a third party’s ability to decrypt those weights changes fundamentally within the contract term due to heightened quantum computing exposure. Crypto-agility clauses, PQC migration covenants, ratchet provisions tied to evolving benchmarks, and termination rights triggered by material changes in cryptographic risk can help closing this gap, but only if negotiated before execution.
What businesses should do now
Businesses that treat quantum as an IP strategy question, not just a cybersecurity question, will be better positioned to protect and monetise their innovations in the years ahead. In practice, this means:
- Audit IP and AI assets for quantum exposure. Go beyond the standard cryptographic inventory. Identify which assets depend on secrecy for their legal protection or commercial value, and assess the confidentiality lifespan of each. The critical question is not just “is this data encrypted?” but “does this asset lose its legal protection or its competitive value if decrypted?”
- Reassess IP protection strategies. For innovations currently protected as trade secrets, evaluate whether the expected durability of that protection justifies the risk, or whether formal IP filings offer a more resilient alternative. For assets that must remain secret (e.g. training data, model weights, source code) prioritise PQC migration.
- Future-proof commercial agreements. Review IP licensing, AI licensing, and data sharing agreements for temporal adequacy. Introduce provisions that anticipate changes in cryptographic risk rather than anchoring security obligations to today’s threat environment.
- Integrate quantum resilience into innovation governance. Embed PQC requirements into research & development collaboration agreements, joint venture structures, and supply chain contracts. Every partner, vendor, and collaborator with access to sensitive IP or AI assets is a potential point of quantum risk exposure. Factor in export control and investment screening constraints where quantum-related IP is developed, transferred, or commercialised across borders.
