Utimaco Warns AI Security Must Adapt for Quantum Computing Threats
A new eBook from Utimaco outlines how the rise of quantum computing could expose AI systems to unprecedented security threats. The report emphasizes the urgent need for organisations to adopt quantum-resistant cryptography and hardware-based trust mechanisms to protect data used in AI development and deployment.
Organisations face mounting security risks in the development and deployment of artificial intelligence (AI) systems, a concern set to intensify with the advent of quantum computing, according to a recent eBook published by cybersecurity firm Utimaco. The report, titled “AI Quantum Resilience,” identifies security as the primary barrier to effective AI adoption, especially concerning the protection of sensitive data used in AI model training and inference.
AI’s practical value depends heavily on the data organisations possess. However, this dependency introduces vulnerabilities at multiple stages—from the potential manipulation of training data to risks of intellectual property theft and exposure of sensitive information during AI processes.
Utimaco's analysis highlights three core threat areas: the risk of malicious actors tampering with training data (which can degrade model performance in ways that are difficult to detect), the illicit copying or extraction of AI models (compromising intellectual property), and the unintended disclosure of sensitive data both during training and at the point of inference.
Looking ahead, the report underscores a growing, yet less-publicized, threat: the prospect of quantum computing enabling the decryption of data that is currently considered secure. Public key cryptography, widely used to protect data today, may be rendered obsolete within the next decade as quantum systems mature. The concern is further compounded by indications that some groups are already collecting encrypted data with the intention of decrypting it once quantum capabilities become available.
To address these evolving risks, the report advocates prompt migration to quantum-resistant cryptographic methods. Utimaco argues that such a transition impacts not only the cryptographic algorithms used but also protocols for key management, system interoperability, and overall performance—making it a complex, multi-year process.
A key concept introduced is 'crypto-agility', which refers to the ability to switch cryptographic algorithms without a need to redesign entire systems. This commonly involves hybrid cryptography, which layers established algorithms with new post-quantum techniques such as those recommended by the US National Institute of Standards and Technology (NIST).
The authors also caution that cryptography alone is insufficient for comprehensive security. They recommend broader adoption of hardware-based trust devices, such as secure hardware modules and encrypted enclaves, to isolate cryptographic keys and sensitive operations from the general IT environment. These hardware-based enclaves can prevent even privileged system administrators from accessing data during processing and can perform external attestation to ensure the integrity of the processing environment—a concept known as a 'chain of trust'.
Importantly, these measures should be implemented throughout the AI lifecycle, from initial data ingestion and model training, to deployment and ongoing inference. Hardware-driven key management also generates tamper-resistant logs, which are vital for compliance with regulatory frameworks like the EU AI Act.
While many current risks—such as data leaks and model theft—are well known in the AI security community, the looming threat of quantum-powered decryption introduces new urgency. The report concludes by recommending the enhancement of security controls across all AI phases, embracing crypto-agility for post-quantum readiness, and instituting hardware-based trust solutions for high-value assets.
Related Posts
Publishers Gain Right to Opt Out of AI Search Following New Regulation
New regulation grants publishers the ability to opt out of having their content indexed or used by AI-powered search engines. This policy shift is expected to reshape the relationship between content creators and major AI platforms. Industry observers note the potential for significant impact on access to information and copyright enforcement.
Mathematicians Raise Concerns Over AI’s Impact on Mathematical Research
A group of mathematicians has issued a declaration highlighting threats posed by artificial intelligence to the integrity and future of mathematical research. The Leiden Declaration, developed over several months and endorsed by the International Mathematical Union, expresses concerns about increasing industry influence and recent AI-driven advances such as disproving longstanding conjectures.
Google Introduces Fake Call Detection to Counter AI Deepfake Scams
Google has rolled out a new fake call detection feature designed to protect users from AI-powered deepfake impersonation scams. The capability aims to identify and flag suspicious calls, leveraging advances in artificial intelligence. This move responds to rising concerns over the misuse of generative AI for realistic voice fraud.