IQN (NewsDesk): Geneva-based cybersecurity firm WISeKey, working with the OISTE.ORG Foundation, has expanded its Quantum Root Key initiative into a broader post-quantum cryptography (PQC) framework designed to give AI models, autonomous agents, connected devices, and human operators verifiable digital identities.
From Securing Devices to Verifying AI
The original Quantum Root Key was built to address a well-known long-term threat: that sufficiently powerful quantum computers could eventually break the public-key cryptography that underpins most of today’s secure communications and digital identity systems. WISeKey’s expansion reframes that same cryptographic foundation around a newer problem, verifying whether an AI model or autonomous agent claiming to be legitimate actually is.
The company frames the challenge directly: as AI systems become more autonomous, how do humans, machines, and other AI systems know that a given model or agent is authentic, properly authorized, and running trusted software, data, and instructions? WISeKey and OISTE argue the answer starts with a cryptographically verifiable root of trust, built on the same public key infrastructure principles that have authenticated websites and devices for decades, but extended to make AI systems machine-verifiable too.
A Chain of Custody From Root Key to AI Action
Under the new architecture, the OISTE/WISeKey root of trust acts as the top-level cryptographic anchor from which identities and credentials can be issued down a chain: from the root, to an organization, to a specific AI model, to an AI agent operating on that model’s behalf, to a device, and finally to an individual transaction. Each link in that chain can carry its own independently verifiable cryptographic identity, rather than systems simply trusting an AI because it claims a particular identity.
The framework leans on NIST-standardized post-quantum algorithms, including ML-DSA and ML-KEM, and preserves familiar public key infrastructure mechanisms such as certificate revocation lists and root and intermediate certificate authorities, while swapping in quantum-resistant cryptography underneath.
Part of a Larger Human-AI Oversight Model
WISeKey positions the root of trust as a foundational piece of what it calls its HUMAN-AI-T framework, a proposed safety architecture in which specialized supervisory AI systems monitor the actions of other AI systems while preserving ultimate human control. In that model, a supervisory AI wouldn’t simply watch another model from the outside. Both the supervisor and the supervised system would carry independently verifiable cryptographic identities, and the overall setup would include an authenticated AI supervisor, authenticated models and agents, cryptographically authorized actions, a tamper-evident audit trail, and a defined path for human escalation or intervention.
WISeKey noted that its semiconductor subsidiary, SEALSQ, could extend the root of trust further into secure hardware elements, potentially embedding this identity verification directly into chips rather than leaving it purely at the software layer.