WISeKey expands its Quantum Root Key to protect AI

WISeKey International Holding Ltd and OISTE. ORG are extending their initiative to establish a cryptographically verifiable Root of Trust for artificial intelligence systems.

The collaboration aims to address a growing challenge: verifying that AI models and agents are “authentic, authorized and operating with trusted software, data and instructions.” This builds on existing Public Key Infrastructure, the system used to authenticate websites, but applies it to AI, creating a potential chain of trust from a “Post-Quantum Root of Trust” to every AI transaction. WISeKey and OISTE believe that “every AI should have an identity” and every action should be verifiable.

Post-Quantum Root of Trust Secures AI Model Identity & Provenance

WISeKey’s semiconductor technology, through its subsidiary SEALSQ Corp, extends the reach of this Root of Trust into secure elements, TPMs, and post-quantum semiconductor architectures. This integration allows an AI workload, whether running on a server, robot, or embedded device, to establish a cryptographically verifiable link between hardware, firmware, operating environment, the AI model itself, the AI agent controlling it, and the authorized user. Such hardware-backed attestation significantly complicates attempts to impersonate legitimate AI agents or surreptitiously replace authorized software and models.

The architecture supports critical functions for trusted AI, beginning with AI model identity; systems can verify the origin of an AI and confirm authorization through cryptographic identities issued to AI models. Cryptographic signatures and hashes further verify the integrity of model binaries, weights, software components, and configurations, ensuring they haven’t been altered post-release.

Beyond model verification, the system authenticates AI agents before they access systems, APIs, financial services, IoT infrastructure, or other AI agents, establishing a secure chain of trust. Human-to-AI authorization is also addressed, allowing trusted digital identities and certificates to confirm who is authorized to instruct, modify, deploy, or terminate an AI agent. As autonomous agents interact more frequently, cryptographic credentials will enable one agent to verify the identity and authorization of another before exchanging information or executing transactions.

High-impact AI actions can be digitally signed, creating an auditable record of the initiating agent, its identity, and authorization. These signed events can then be recorded in tamper-evident or immutable audit systems, providing traceability throughout the AI lifecycle. This approach fundamentally shifts the paradigm from trusting AI based on claims to verifying its authenticity and authorization.

Every critical AI interaction should be verifiable. The Root of Trust uses NIST-standardized Post-Quantum Cryptography algorithms, including ML-DSA and ML-KEM, alongside other quantum-resistant cryptographic technologies. These technologies integrate with WISeKey’s trusted infrastructure and Post-Quantum PKI platform, anchoring cryptographic operations within tamper-resistant environments like Hardware Security Modules and Trusted Platform Modules. This ensures the identity infrastructure securing future AI systems remains resilient against both conventional and quantum computing attacks.

The architecture also supports a supervising AI model, a potential safety measure where a specialized AI oversees the actions of another, preserving ultimate human governance. Within this framework, both the supervisory and monitored AI possess independently verifiable cryptographic identities. The system operates with the OISTE Post-Quantum Root of Trust anchoring trusted human governance, an authenticated AI supervisor, authenticated AI models and agents, cryptographically authorized actions, a tamper-evident audit trail, and a pathway for human escalation or intervention.

“Instead, it provides something more fundamental: verifiable identity, integrity, authorization and accountability,” explains the company. “These mechanisms can complement model-level AI safety controls by providing a security layer underneath them.” The implications extend to sectors where autonomous AI decisions have significant consequences, including financial services, healthcare, defense, energy, and critical infrastructure. Post-Quantum certificates issued through the platform adhere to conventional PKI principles, Root and Intermediate Certificate Authorities, defined Key Usages, Certificate Revocation Lists, while incorporating quantum-resistant algorithms.

Carlos Moreira, Founder and CEO of WISeKey, emphasizes the shift occurring in AI. “AI is rapidly moving from generating information to taking autonomous actions.

In that environment, identity becomes fundamental. Before an AI agent can access infrastructure, communicate with another AI or execute a transaction, we need to know cryptographically who that agent is, who authorized it and whether it has been modified. Our Post-Quantum Root of Trust creates the foundation for this new trust architecture.” The objective, he states, is to move beyond simply trusting AI to cryptographically verifying it.

AI is rapidly moving from generating information to taking autonomous actions. In that environment, identity becomes fundamental. Before an AI agent can access infrastructure, communicate with another AI or execute a transaction, we need to know cryptographically who that agent is, who authorized it and whether it has been modified. Our Post-Quantum Root of Trust creates the foundation for this new trust architecture. The objective is simple: AI should not have to be blindly trusted. AI should be cryptographically verifiable.

Intelligent Internet Carlos Moreira, Founder and CEO of WISeKey
Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Ivy Delaney

Ivy Delaney

Ivy Delaney has been working with neural networks and machine learning since the mid-nineties, back when a couple of hidden layers and a long afternoon of training counted as ambitious. She has watched the field go from academic curiosity to the thing quietly running underneath everything, and she brings that long view to quantum computing. For Quantum Zeitgeist she covers the ground where the two fields meet. That means quantum machine learning and the variational algorithms it leans on, and it also means the less glamorous but more interesting story of classical machine learning already doing real work inside quantum machines, decoding error-correcting codes, calibrating noisy hardware and learning the error models that simulators depend on. She writes about the hardware those algorithms have to run on too, and about the post-quantum cryptography scramble that the same hardware has set off. Her stories typically start with the paper, whether that is peer-reviewed work, conference proceedings or an arXiv preprint, with the source linked so you can hold a claim up against the research it came from. She is unimpressed by benchmarks that will not say what they beat, and by demonstrations that only work in the press release.

Latest Posts by Ivy Delaney: