WISeKey International Holding Ltd and OISTE. ORG are extending their initiative to establish a cryptographically verifiable Root of Trust for artificial intelligence systems.
The collaboration aims to address a growing challenge: verifying that AI models and agents are “authentic, authorized and operating with trusted software, data and instructions.” This builds on existing Public Key Infrastructure, the system used to authenticate websites, but applies it to AI, creating a potential chain of trust from a “Post-Quantum Root of Trust” to every AI transaction. WISeKey and OISTE believe that “every AI should have an identity” and every action should be verifiable.
Post-Quantum Root of Trust Secures AI Model Identity & Provenance
WISeKey’s semiconductor technology, through its subsidiary SEALSQ Corp, extends the reach of this Root of Trust into secure elements, TPMs, and post-quantum semiconductor architectures. This integration allows an AI workload, whether running on a server, robot, or embedded device, to establish a cryptographically verifiable link between hardware, firmware, operating environment, the AI model itself, the AI agent controlling it, and the authorized user. Such hardware-backed attestation significantly complicates attempts to impersonate legitimate AI agents or surreptitiously replace authorized software and models.
The architecture supports critical functions for trusted AI, beginning with AI model identity; systems can verify the origin of an AI and confirm authorization through cryptographic identities issued to AI models. Cryptographic signatures and hashes further verify the integrity of model binaries, weights, software components, and configurations, ensuring they haven’t been altered post-release.
Beyond model verification, the system authenticates AI agents before they access systems, APIs, financial services, IoT infrastructure, or other AI agents, establishing a secure chain of trust. Human-to-AI authorization is also addressed, allowing trusted digital identities and certificates to confirm who is authorized to instruct, modify, deploy, or terminate an AI agent. As autonomous agents interact more frequently, cryptographic credentials will enable one agent to verify the identity and authorization of another before exchanging information or executing transactions.
High-impact AI actions can be digitally signed, creating an auditable record of the initiating agent, its identity, and authorization. These signed events can then be recorded in tamper-evident or immutable audit systems, providing traceability throughout the AI lifecycle. This approach fundamentally shifts the paradigm from trusting AI based on claims to verifying its authenticity and authorization.
Every critical AI interaction should be verifiable. The Root of Trust uses NIST-standardized Post-Quantum Cryptography algorithms, including ML-DSA and ML-KEM, alongside other quantum-resistant cryptographic technologies. These technologies integrate with WISeKey’s trusted infrastructure and Post-Quantum PKI platform, anchoring cryptographic operations within tamper-resistant environments like Hardware Security Modules and Trusted Platform Modules. This ensures the identity infrastructure securing future AI systems remains resilient against both conventional and quantum computing attacks.
The architecture also supports a supervising AI model, a potential safety measure where a specialized AI oversees the actions of another, preserving ultimate human governance. Within this framework, both the supervisory and monitored AI possess independently verifiable cryptographic identities. The system operates with the OISTE Post-Quantum Root of Trust anchoring trusted human governance, an authenticated AI supervisor, authenticated AI models and agents, cryptographically authorized actions, a tamper-evident audit trail, and a pathway for human escalation or intervention.
“Instead, it provides something more fundamental: verifiable identity, integrity, authorization and accountability,” explains the company. “These mechanisms can complement model-level AI safety controls by providing a security layer underneath them.” The implications extend to sectors where autonomous AI decisions have significant consequences, including financial services, healthcare, defense, energy, and critical infrastructure. Post-Quantum certificates issued through the platform adhere to conventional PKI principles, Root and Intermediate Certificate Authorities, defined Key Usages, Certificate Revocation Lists, while incorporating quantum-resistant algorithms.
Carlos Moreira, Founder and CEO of WISeKey, emphasizes the shift occurring in AI. “AI is rapidly moving from generating information to taking autonomous actions.
In that environment, identity becomes fundamental. Before an AI agent can access infrastructure, communicate with another AI or execute a transaction, we need to know cryptographically who that agent is, who authorized it and whether it has been modified. Our Post-Quantum Root of Trust creates the foundation for this new trust architecture.” The objective, he states, is to move beyond simply trusting AI to cryptographically verifying it.
AI is rapidly moving from generating information to taking autonomous actions. In that environment, identity becomes fundamental. Before an AI agent can access infrastructure, communicate with another AI or execute a transaction, we need to know cryptographically who that agent is, who authorized it and whether it has been modified. Our Post-Quantum Root of Trust creates the foundation for this new trust architecture. The objective is simple: AI should not have to be blindly trusted. AI should be cryptographically verifiable.
Intelligent Internet Carlos Moreira, Founder and CEO of WISeKey




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
