Advancing Quantum Safe Transitions: Ethical, Legal, Social, and Policy Dimensions
This session focused on advancing quantum-safe transitions by examining the ethical, legal, social, and policy dimensions of quantum information and communications technologies, framing the shift not merely as a technical upgrade but as a broader socio-technical transformation . The discussion drew on a forthcoming ITU Kaleidoscope paper and aimed to contribute to a policy issue brief being developed jointly with UNESCO's Information for All programme and the ITU .
Xianhong Hu from UNESCO highlighted that quantum technologies are rapidly reshaping knowledge societies and that governance must be anticipatory, agile, inclusive, and human-rights-centred, drawing lessons from AI governance . She flagged two critical divides: a human capacity gap, with 43% of countries lacking quantum talent , and a significant gender imbalance, with fewer than 30% of the quantum workforce being female . She also stressed the need to mainstream quantum literacy alongside AI and digital literacy .
Gillian Makamara from the ITU emphasised that international standards, developed by consensus and with multi-stakeholder participation including governments, industry, and academia, are a key mechanism for closing the security divide between nations . She noted that the ITU is actively reviewing foundational Internet security standards, such as X.509, to address emerging quantum vulnerabilities .
Maikki Sipinen argued that the quantum-safe transition must be treated as an ecosystem-wide transformation rather than a purely technical migration, with urgent attention to questions of accountability, risk distribution, and who benefits . She drew parallels with AI governance, recommending that stakeholders learn from that experience while recognising remaining challenges such as unequal global south participation in standard-setting .
Tommaso Calarco outlined Europe's structured approach through initiatives such as the Quantum Act, which establishes three pillars - research, innovation, and strategic security - and extends cooperation beyond EU borders to countries including South Korea, Japan, and African nations . Audience contributions reinforced the need to bring decision-makers into governance discussions, warning that without their engagement, smaller nations risk vendor lock-in and loss of agency as quantum capabilities advance . The session concluded with broad consensus that quantum governance requires genuine multi-stakeholder participation and public quantum literacy to ensure the technology serves the public good .
Overall Purpose
- The discussion aims to examine quantum-safe transitions not merely as a technical cryptographic challenge, but as a broad socio-technical transformation with ethical, legal, social, and policy dimensions. The session also seeks to contribute to a forthcoming UNESCO/ITU policy issue brief and to promote inclusive, multi-stakeholder governance of quantum technologies for the public good. ---
Major Discussion Points
- The quantum divide poses significant risks, particularly around human capacity and gender inequality. Research from UNESCO's Quantum Moment report reveals that 43% of countries lack sufficient human talent to develop quantum technologies, making this the number one barrier to quantum development. Furthermore, women represent less than 30% of the quantum industry workforce, reflecting a deeply gendered divide that mirrors inequalities seen in other technology sectors. The ITU's Global Cybersecurity Index further highlights disparities between countries in cybersecurity readiness, which compounds the threat posed by quantum computing. - International standardisation is a critical but underappreciated tool for ensuring inclusive and secure quantum-safe transitions. The ITU is actively reviewing foundational standards such as X.509 - the basis of current Internet security - to identify vulnerabilities ahead of the quantum threat. Standards development at the ITU operates by consensus and incorporates governments, industry, and academia to ensure multi-stakeholder input. However, achieving genuine inclusivity in standards processes remains difficult, particularly regarding gender representation and participation from developing nations. - Quantum governance must adopt a multi-stakeholder, ecosystem-wide approach, drawing lessons from AI policy. Quantum-safe transitions must not be treated as purely technical migrations; they require simultaneous attention to infrastructure, institutions, standards, and values. Key governance questions - such as who decides timelines, who bears risk, and who is accountable - cannot be answered through technical frameworks alone. Lessons from AI governance suggest that quantum policy must proactively identify the unique qualities of the technology and bring all stakeholder communities together before governance falls behind deployment. - Decision-makers and non-technical actors must be brought into quantum governance conversations urgently, including through procurement policy. Audience contributions highlighted that the political, economic, and social will to deploy security standards is largely absent, and that most organisations deflect responsibility rather than act. A key mechanism for change is requiring "secure by design" principles - including post-quantum cryptography - in government and corporate procurement processes. Framing quantum risks in terms of national security and human agency, rather than technical complexity, was proposed as a way to engage decision-makers before "Q-Day" - the moment a quantum computer could decrypt currently harvested encrypted data - renders inaction catastrophic. - Europe's quantum strategy offers a model for multilateral, inclusive governance, though global cooperation faces geopolitical headwinds. The European Quantum Act is being structured around three pillars - research, innovation and industrialisation, and strategic security - developed jointly between the European Commission and member states. Europe's experience harmonising quantum policy across 27 sovereign states, including efforts to widen participation from less advanced member states and address gender bias, provides a foundation for broader international cooperation. However, it was acknowledged that the era of open multilateralism has stalled, and that international cooperation must now be built pragmatically on mutual interests, including outreach to neighbouring continents such as Africa. ---
Overall Tone
- The overall tone of the discussion is constructive, collaborative, and earnest, with a clear sense of shared urgency. Speakers consistently framed quantum-safe transitions as a collective responsibility rather than a competitive or adversarial challenge. Early contributions from Xianhong Hu and Gillian Makamara were measured and informative, grounding the conversation in existing research and institutional frameworks. Maikki Sipinen and Tommaso Calarco introduced a more forward-looking and slightly cautionary tone, warning against repeating the governance mistakes made with AI and acknowledging geopolitical complications. The audience Q&A introduced a more pressing, even frustrated register, with Wouter Natus pointedly noting the absence of political and economic will to act. This was met with renewed optimism from Xianhong Hu and Tommaso Calarco, who emphasised citizen empowerment and the structural commitments embedded in the Quantum Act. Overall, the tone remained respectful and solution-oriented throughout, though it grew progressively more urgent as the session moved from institutional overviews to practical governance challenges.
Expanded Summary: Advancing Quantum-Safe Transitions — Ethical, Legal, Social, and Policy Dimensions
Session Overview and Objectives
The session, held during AI Digital Week in Geneva as part of the World Summit on the Information Society (WSIS) forum, brought together representatives from UNESCO, the ITU, the private sector, and academia to examine quantum-safe transitions through an ethical, legal, social, and policy lens. Shamira Ahmed, from the Data Economy Policy Hub, opened by framing the session's core premise: that quantum-safe migration should be understood not merely as a technical cryptographic upgrade, but as "a broader socio-technical infrastructure transformation that aims to redistribute trust, responsibility, and risk across institutions, markets, and communities." The discussion was informed by an ITU Kaleidoscope paper entitled An Innovation Ecosystem Ethics Approach for Quantum Safe Transitions, whose conference proceedings were already publicly available at the time of the session.
The session carried two explicit objectives. The first was to present and discuss the research findings of the Kaleidoscope paper. The second was to contribute to the development of a forthcoming policy issue brief being produced jointly by UNESCO's Information for All Programme and the ITU. Ahmed described the overarching mission as promoting information for all while supporting ITU's efforts to foster international cooperation, trusted standards, and inclusive digital transformation through quantum technologies — summarised under the banner of "quantum for good." Speakers included Xianhong Hu from UNESCO's Information for All Programme, Gillian Makamara from the ITU, Maikki Sipinen from Verde, and Professor Tommaso Calarco from the University of Cologne and chair of the Quantum Flagship, who joined online.
UNESCO's Perspective: Human Rights, Anticipatory Governance, and the Quantum Divide
Xianhong Hu situated the discussion within the broader context of the third decade of WSIS, noting that the international community is now grappling not only with the Internet and digital technologies but with a wave of emerging technologies — including AI, quantum, and neuroscience — that are "mushrooming so fast and profoundly impacting the concept and the approach of building knowledge societies." She emphasised that UNESCO's mandate, including its Information for All Programme, is built on the principle of building inclusive futures, and that the Global Digital Compact similarly calls for inclusive digital development.
Hu highlighted two key UNESCO resources relevant to the session. The first was a policy brief co-authored with Shamira Ahmed, previously published, which advocated for human rights-centred governance of quantum technology. She described the brief's approach as deliberately balanced — "neither utopianist nor dystopianist" — recognising that quantum technologies could enhance communication, access to information, and human rights, while also posing significant risks to privacy and encryption. The brief argued that governance must be anticipatory, drawing lessons from AI: "we should really think about this governance issue before the technology is mainstreamed and being applied widely." It also called for governance that is agile, inclusive, and human rights-sensitive.
The second resource Hu referenced was UNESCO's Quantum Moment global report, a comprehensive compilation of more than 100 pages drawing on research, outcomes, and surveys from the whole year-long celebration of the International Year of Quantum in 2025. One of its most significant findings was that the quantum divide is already in place, with the human capacity gap identified as the most pressing barrier: 43% of countries lack sufficient human talent to develop quantum technologies. Hu argued that this necessitates a major expansion of quantum education and capacity building, extending well beyond students and researchers to cover professionals and individuals at all levels. She called explicitly for quantum literacy to be mainstreamed "from now on", noting that it is "so much underdeveloped unlike AI literacy, digital literacy." She also flagged a significant gender imbalance, with fewer than 30% of the quantum industry workforce being female — a divide she described as "nothing new" but nonetheless deeply concerning. Hu further noted that UNESCO has a programme specifically designed to enhance policymakers' capacity to understand new technologies, underscoring the importance of equipping decision-makers — not only citizens — with the tools to engage meaningfully with quantum governance.
ITU's Perspective: Standards as a Mechanism for Closing the Security Divide
Gillian Makamara, introducing herself as "primarily a technical person" and an engineer, acknowledged upfront that "it's very hard to incorporate the ethical dimensions" into engineering, though she noted that more is now being done to address this. Building directly on Hu's concept of the quantum divide, Makamara extended the framework to include a security dimension alongside the human capacity dimension. She referenced the ITU's Global Cybersecurity Index, which is published annually and reveals stark disparities between countries in how they are implementing cybersecurity frameworks. Her assessment was blunt: adding the quantum threat to this already unequal landscape "doesn't look good."
Makamara argued that international standards represent one of the most important mechanisms for closing this gap. She noted that standards "don't make headlines, but they really support our systems today", citing the ITU's X.509 standard as the concrete foundation of all current Internet security. In response to the emerging quantum threat, the ITU is actively reviewing this standard to identify vulnerabilities and gaps, with the aim of ensuring that Internet security infrastructure is as robust as possible before the quantum threat materialises. She used a house-building analogy to explain the philosophy behind standards development: standards should serve as a flexible foundation — determining the structure — while leaving room for customisation in terms of specific implementation, so that they remain applicable across diverse economies and contexts.
On the question of inclusivity in standards development, Makamara described the ITU's consensus-based process, which incorporates governments, industry, and academia to create a genuine multi-stakeholder environment. She acknowledged, however, that demographic diversity and gender representation in standards processes remain significant gaps that she could encourage but not mandate. She called on member delegations to include people from different parts of the world and to improve gender distribution in their participation.
Private Sector and AI Governance Lessons: An Ecosystem-Wide Approach
Maikki Sipinen, bringing an industry perspective and a background in AI policy, presented what she described as the core argument of the Kaleidoscope paper: "we should not let the quantum safe transition stay purely a technical conversation." She argued that an ecosystem-wide transformation approach is needed — one that addresses infrastructure, institutions, standards, and values simultaneously rather than sequentially. The danger of treating the transition as a purely technical migration, she warned, is that it fails to answer the most important governance questions: "who gets to decide on the timelines, who bears the risk of quantum, who benefits and who is then accountable if something goes wrong."
Sipinen drew extensively on the trajectory of AI governance as a cautionary and instructive parallel. She noted that AI governance "started as a technical conversation" and only gradually came to be recognised as encompassing fundamental governance questions about whose values are embedded, who bears risk, and who is at the table. She argued that quantum policy should build on these lessons rather than repeat the same slow evolution. However, she was careful to note that AI governance remains incomplete, with persistent challenges including "unequal participation from the global south in standard setting on AI" and the fact that "AI capacity is on global scale to great extent owned and controlled by only a handful of companies." These failures, she argued, must be actively avoided in quantum governance.
Sipinen also introduced a forward-looking argument about the convergence of AI and quantum technologies. She suggested that governance frameworks should increasingly address both together rather than treating them as entirely separate domains, predicting that "in let's say five years we will have a more solid one joint discussion on AI and quantum not separate topics of different sessions." She emphasised that understanding the unique qualities of quantum as an emerging technology is foundational — and that this understanding must be built not just within the technical community but by bringing all stakeholder communities together. It is also worth noting that Patrick Bell, co-author of the Kaleidoscope paper alongside Sipinen and Shamira Ahmed, was physically present in the building during the session and subsequently contributed from the floor.
Europe's Quantum Strategy: Multilateralism, Inclusivity, and the Quantum Act
Professor Tommaso Calarco, from the University of Cologne and chair of the Quantum Flagship, offered a detailed account of Europe's structured approach to quantum governance. He began by noting that Europe's internal experience of harmonising quantum policy across 27 sovereign member states is itself an exercise in multilateralism, providing "the training to go towards overcoming these obstacles and being able to establish cooperation across and beyond the borders of our own countries." He acknowledged that Europe is not a monolith — member states vary significantly in their levels of investment and advancement in quantum technologies — and that the EU has developed "widening participation" programmes to ensure that less advanced member states can participate in European research and innovation excellence. He also acknowledged that gender bias is "unfortunately very strong" in the quantum field and that European policy measures are in place to address this.
Calarco described the forthcoming Quantum Act as representing the first time the European Commission is giving itself a structured and clear policy for international quantum cooperation. He outlined three pillars that have been recommended to and taken up by the Commission: research and science; innovation and industrialisation; and strategic security and protection, which includes standardisation. He emphasised that this framework will be developed jointly between the Commission and member states and will not be treated as a matter of optional participation.
On international cooperation beyond European borders, Calarco cited the Euro HPC joint undertaking for high-performance computing as an example of an initiative in which non-EU countries — including the UK, South Korea, and Japan — are involved in discussions and in some of these initiatives. He also pointed to growing initiatives towards cooperation with Africa and other neighbouring continents. However, he was candid about the geopolitical constraints on such cooperation, acknowledging that "the era of multilateral cooperation and globalization in the positive sense kind of has come to a halt" in what he described as the current "multi-polar world disorder." He argued that international cooperation must therefore be built pragmatically on mutual interests rather than on naive assumptions about globalisation.
Audience Discussion and Panel Responses
The audience discussion significantly enriched the session by introducing concrete structural and political economy arguments that had been implicit but not yet fully articulated by the panel. Wouter Natus from the BORF, coordinator of an IGF dynamic coalition on the implementation of Internet standards, drew on his coalition's study of the social, economic, and political effects of post-quantum cryptography to make a pointed intervention. He argued that the failure to deploy existing Internet security standards — such as DNS security and RPKI — is not a technical problem but a political, economic, and social one: "the topic is not technical. This topic is about political, economic, social, security will to deploy standards." He observed that "everybody leaves the room as soon as the word Internet standard or post-quantum cryptography is mentioned," and identified two structural barriers: the absence of a level playing field (where investing in security creates a competitive disadvantage relative to non-investing competitors) and the absence of economic incentives because "nobody procures secure by design, almost nobody." His proposed solution was for governments and large organisations to mandate secure-by-design requirements — including post-quantum cryptography — in their ICT procurement processes.
Patrick Bell, co-author of the Kaleidoscope paper, built on Natus's intervention by introducing a structured analytical framework from security studies: the three-layer information environment model comprising the physical layer (hardware), the informational layer (data flows and algorithms), and the cognitive or decisional layer (governments and large corporations as strategic decision-makers). He argued that "almost all the discussion" on quantum stays at the technical layer and "very rarely does it go up to the cognitive or decisional layer." He warned that smaller nations without dedicated quantum budgets "essentially accept whatever the vendor gives them", creating long-term vendor lock-in and path dependence. His proposed remedy was to tell decision-makers directly: "unless you're in the room, things are going to be decided for you" — and that participation does not require a PhD in quantum information systems. He also introduced the concept of "Q-Day" — the moment when a fully operational quantum computer could decrypt currently harvested encrypted data — as a concrete and communicable risk narrative for engaging non-technical decision-makers.
A further audience question from Muganatha from DIMAYA raised the "harvest now, decrypt later" threat — the practice of organisations collecting encrypted data now with the intention of decrypting it once quantum computers become operational. The question was raised but the session moved on without a direct response from the panel, though it reinforced the urgency of the quantum-safe transition and aligned with Bell's Q-Day framing.
Xianhong Hu responded to the broader audience discussion by reaffirming the importance of multi-stakeholder governance and quantum literacy. She acknowledged the challenge that quantum is "very abstract physical concept and theory" and that discussions are sometimes gatekept by demands for technical expertise. She argued against this, asserting that "if technology is going to be so revolutionary... every citizen has a right to know." She emphasised that quantum literacy must extend to government officials and policymakers who need to take decisions about quantum technologies in their procurement, regulation, and policy work.
Tommaso Calarco went further, making a strong democratic empowerment argument: "every citizen has a right to say what they want, to be empowered, to determine the direction of future developments." He drew an explicit analogy with voting — one does not need a PhD to participate in democratic governance — and argued that "it is of paramount importance to get the decision makers not only in the room, but also ready to listen to what society wants." He directly endorsed the Kaleidoscope paper's framing of the problem as an ecosystem governance issue rather than a purely technical or cybersecurity issue, and confirmed that the Quantum Act's three-pillar structure — research, innovation and industrialisation, and strategic security and protection — reflects exactly this integrated ecosystem approach.
Conclusions and Unresolved Challenges
The session concluded with broad consensus across all speakers and audience participants on several foundational principles: that quantum-safe transitions are socio-technical governance challenges requiring genuine multi-stakeholder engagement; that the quantum divide is real, multidimensional, and already in place; that quantum literacy must be mainstreamed across all levels of society; that AI governance offers useful but imperfect lessons; and that international standards, while critical, must be complemented by political will, economic incentives, and inclusive processes.
Nevertheless, the session also surfaced important unresolved tensions. A productive tension existed between Makamara's standards-centred approach and Natus's argument that the real barrier is the absence of political and economic will to deploy standards that already exist. A further tension existed between the aspirational calls for broad citizen empowerment and quantum literacy and the empirical reality that 43% of countries lack even the basic human talent to develop quantum capabilities, and that even professional decision-makers are rarely engaged in quantum governance discussions. The question of how to ensure equitable participation from the Global South — given that similar challenges remain unresolved in AI governance — was raised but not concretely resolved. Similarly, how to build genuine multilateral cooperation in the current multi-polar world disorder, and how to address the immediate "harvest now, decrypt later" threat, were identified as urgent priorities without clear resolution within the session.
The session's two concrete outputs — the publicly available ITU Kaleidoscope paper and the forthcoming UNESCO-ITU policy issue brief — were presented as vehicles through which the community could continue to contribute to these unresolved questions, with participants encouraged to engage with both processes.
UNESCO's mandate for human rights-centred governance of quantum technologies, advocating for a balanced approach that recognises both the benefits and risks of quantum - Quantum governance must be anticipatory, agile, inclusive, and human rights-sensitive, drawing lessons from AI governance
Arg. 1Xianhong Hu argues that UNESCO's approach to quantum governance must be balanced, neither utopian nor dystopian, recognising both the potential benefits of quantum for communication and human rights and the risks to privacy and encryption. She emphasises that governance must be anticipatory — learning from AI governance by thinking about risks before the technology is widely deployed — and must also be agile, inclusive, and human rights-sensitive.
UNESCO published a policy brief co-authored by Shamira that advocates for human rights-centred governance of quantum technology, explicitly recognising that quantum could enhance communication and human rights while also posing risks to privacy and encryption . The brief highlighted the importance of anticipatory governance, drawing lessons from AI to address risks before the technology becomes mainstream .
on: AI governance provides useful but imperfect lessons for quantum policy, and quantum governance should build on these lessons while actively avoiding AI's unresolved problems
A significant human capacity gap exists globally, with 43% of countries lacking quantum talent, making workforce development and quantum literacy a critical priority alongside AI and digital literacy
Arg. 2Hu highlights that the quantum divide is already in place, with the most pressing gap being the lack of human talent in quantum fields. She argues that quantum literacy must be mainstreamed across all levels of society — from students and researchers to professionals, individuals, and policymakers — just as AI and digital literacy have been prioritised.
A survey from UNESCO's global report 'The Quantum Moment', which compiled outcomes from the International Year of Quantum 2025, found that 43% of countries lack the human talent needed to develop quantum capabilities, making this the number one issue for those countries . Hu stressed that quantum literacy is significantly underdeveloped compared to AI and digital literacy and should be mainstreamed from now on .
on: Quantum literacy must be mainstreamed across all levels of society, including citizens, policymakers, and professionals, not just technical experts
A gender gap persists in quantum, with fewer than 30% of the quantum industry workforce being female, mirroring broader gender biases seen in other technology sectors
Arg. 3Hu draws attention to the gender dimension of the quantum divide, noting that the quantum industry is heavily male-dominated. She frames this as a known and persistent problem that must be explicitly addressed as part of any inclusive quantum governance strategy.
Hu cited data indicating that fewer than 30% of the quantum industry workforce is female, describing the quantum divide as 'so much gender biased' . She noted this is consistent with broader gender biases observed across technology sectors .
on: The quantum divide is real, multidimensional, and already in place, encompassing human capacity gaps, security disparities, and gender imbalances
Quantum safe transition should be understood as a broader socio-technical infrastructure transformation that redistributes trust, responsibility, and risk across institutions, markets, and communities, not merely a technical cryptographic upgrade
Arg. 1Shamira Ahmed frames the quantum safe migration not as a narrow technical exercise in cryptographic upgrading but as a wide-ranging transformation of socio-technical infrastructure. This framing implies that the transition has profound implications for how trust, responsibility, and risk are distributed across society, requiring engagement well beyond the technical community.
Ahmed described the paper's main examination as viewing quantum safe migration as 'a broader socio-technical infrastructure transformation that aims to redistribute trust, responsibility, and risk across institutions, markets, and communities' .
on: Quantum safe transition must not be treated as a purely technical issue but requires an ecosystem-wide, multi-stakeholder governance approach
on: Whether the quantum safe transition should be framed primarily as a technical/cryptographic challenge or as a broader socio-technical governance transformation
Every citizen has the right not only to know about quantum technologies but to be empowered to determine the direction of future developments, as governance is fundamentally about what society wants
Arg. 1Calarco argues that quantum governance is not merely a matter of public information but of genuine democratic empowerment, where citizens — without needing technical expertise — should be able to shape the direction of quantum technology development. He draws an analogy with voting, suggesting that just as one does not need a PhD to participate in democracy, one does not need deep technical knowledge to have a say in technology governance.
Calarco stated that 'every citizen has a right to say what they want, to be empowered, to determine the direction of future developments' and drew an analogy with voting, noting that going to vote does not require a PhD . He also compared this to how society engages with mobile phones and AI without understanding their technical workings .
on: Quantum literacy must be mainstreamed across all levels of society, including citizens, policymakers, and professionals, not just technical experts
on: The degree to which citizens and non-technical stakeholders should be empowered in quantum governance versus the practical constraints of technical expertise requirements
Europe already practises inclusivity through its widening participation programmes for less advanced member states and addresses gender bias within its research and innovation frameworks, providing a model for broader international cooperation
Arg. 2Calarco argues that Europe's internal experience of harmonising diverse member states — including through widening participation programmes for less advanced countries and efforts to address gender bias — gives it a strong foundation and set of best practices for extending inclusive cooperation internationally. He presents this internal diversity management as inherently multilateral in character.
Calarco described the EU's 'widening countries' programmes, which aim to widen participation in European research and innovation excellence, as providing habits and best practices for geographic inclusivity . He also noted that gender bias is 'unfortunately very strong' in the quantum field and that Europe is already working to address this within its frameworks .
on: The quantum divide is real, multidimensional, and already in place, encompassing human capacity gaps, security disparities, and gender imbalances
The forthcoming Quantum Act represents the first structured European Commission policy for international quantum cooperation, with three pillars covering research, innovation and industrialisation, and strategic security and protection including standardisation
Arg. 3Calarco explains that the Quantum Act will be the first time the European Commission gives itself a clear, structured policy for international quantum cooperation. The Act is built around three ecosystem pillars — research, innovation and industrialisation, and strategic security and protection — and will be developed jointly with member states, making participation mandatory rather than optional.
Calarco stated that the Quantum Act is 'the first time that the European Commission is going to give itself a structured and very clear policy with very clear initiatives for reaching out and cooperating at international level' in quantum . He outlined the three pillars of the Quantum Act - research, innovation and industrialisation, and strategic security and protection including standardisation - as recommended to and taken up by the European Commission .
Europe's experience of harmonising standards and access across 27 diverse sovereign member states provides inherent training in multilateralism that can be extended to broader international cooperation
Arg. 4Calarco contends that the European Union's process of bringing together 27 sovereign member states under a unified quantum strategy is itself an exercise in multilateralism, providing Europe with practical experience in overcoming the obstacles of harmonising standards and access across diverse national contexts. This internal experience, he argues, is a foundation for extending cooperation beyond European borders.
Calarco noted that harmonising standards and infrastructure access 'presents obstacles and non-trivial aspects even within the European Union', and that the process of doing so gives Europe 'the training to go towards overcoming these obstacles and being able to establish cooperation across and beyond the borders of our own countries' .
International cooperation initiatives such as Euro HPC already involve non-EU countries including the UK, South Korea, and Japan, and there are growing initiatives towards cooperation with neighbouring continents such as Africa
Arg. 5Calarco points to the Euro HPC joint undertaking as a concrete example of quantum-related international cooperation that already extends beyond EU member states to include countries such as the UK, South Korea, and Japan. He also signals growing initiatives towards cooperation with Africa as part of a broader multilateral outreach strategy.
Calarco cited Euro HPC as a joint undertaking for high-performance computing that incorporates quantum activities and already involves non-EU countries such as the UK, South Korea, and Japan in discussions on international cooperation . He also mentioned a series of initiatives with Africa that Europe intends to strengthen as part of broader international cooperation .
Genuine multilateral cooperation must be pursued pragmatically, acknowledging the current multi-polar world disorder and building progressively on mutual interests rather than naive assumptions about globalisation
Arg. 6Calarco acknowledges that the era of straightforward multilateral cooperation and globalisation has come to a halt, describing the current situation as a 'multi-polar world disorder'. He argues that international quantum cooperation must therefore be built progressively and pragmatically on the basis of mutual interests rather than idealistic assumptions.
Calarco explicitly stated that 'the era of multilateral cooperation and globalization in the positive sense kind of has come to a halt' and described the current context as a 'multi-polar world disorder', arguing that cooperation must be built 'progressively based on mutual interests' .
The quantum divide has both a human capacity dimension and a security dimension, as existing disparities in cybersecurity posture between countries are compounded by the emerging quantum threat
Arg. 1Makamara extends the concept of the quantum divide beyond human capacity to include a security dimension, arguing that countries already differ significantly in their cybersecurity frameworks and readiness. She warns that adding the quantum threat to this already unequal landscape makes the situation considerably more serious.
Makamara referenced the ITU's annual Global Cybersecurity Index as evidence of existing disparities between countries in implementing cybersecurity frameworks, noting that 'already we do have this divide' before the quantum threat is even factored in . She framed the combination of the existing cybersecurity gap and the emerging quantum threat as a compounded challenge .
on: The quantum divide is real, multidimensional, and already in place, encompassing human capacity gaps, security disparities, and gender imbalances
International standards, developed through consensus-based multi-stakeholder processes involving governments, industry, and academia, are a key mechanism for closing the quantum security gap and ensuring global applicability
Arg. 2Makamara argues that international standards are a critical but often overlooked tool for addressing the quantum security divide, particularly for countries with fewer resources. She emphasises that the ITU's consensus-based, multi-stakeholder approach to standards development — involving governments, industry, and academia — is essential for ensuring that standards are globally applicable and not tailored only to well-resourced economies.
Makamara described the ITU's standardisation process as operating by consensus rather than voting, and as incorporating diverse stakeholders including governments, industry, and academia to create a 'multi-stakeholder environment for standards development' . She cited the X.509 standard as an example of an ITU standard that currently underpins all Internet security .
on: International standards are a critical but insufficient mechanism for closing the quantum security gap, requiring complementary political will, inclusive processes, and diverse stakeholder participation
on: The degree to which citizens and non-technical stakeholders should be empowered in quantum governance versus the practical constraints of technical expertise requirements
The ITU is reviewing foundational standards such as X.509 to identify vulnerabilities ahead of the quantum threat, ensuring that the Internet's security infrastructure is as robust as possible
Arg. 3Makamara explains that the ITU is proactively reviewing the X.509 standard — the foundational standard for Internet security — to identify vulnerabilities that could be exploited by quantum computers. This forward-looking review is intended to ensure that the Internet's security infrastructure is as resilient as possible before the quantum threat materialises.
Makamara stated that the ITU is 'taking that standard [X.509], reviewing it, and trying to identify what vulnerabilities and gaps there exist on that standard so that by the time we have this quantum threat coming in, we are at least confident that the Internet that we rely on today is as secure as we can hope for it to be' .
Standards should serve as flexible foundations rather than overly prescriptive rules, allowing for customisation and inclusivity across diverse economies and contexts
Arg. 4Makamara argues that for standards to be genuinely inclusive and globally applicable, they must be designed as flexible foundations rather than rigid, highly specific rules. Using the analogy of building a house on a foundation, she explains that standards should set the base requirements while allowing for customisation to suit different national contexts, resource levels, and needs.
Makamara used the analogy of building a house, explaining that standards are like a foundation upon which different countries can decide 'how high you want your walls' and 'what kind of windows you would like', meaning they should not be 'so specific that they fit into a very, very specific domain without room for customization' .
on: International standards are a critical but insufficient mechanism for closing the quantum security gap, requiring complementary political will, inclusive processes, and diverse stakeholder participation
The deployment of post-quantum cryptography standards requires political, economic, and social will, not just technical solutions, and procurement processes should mandate secure-by-design requirements to create the necessary economic incentives
Arg. 1The audience speaker (Wouter Natus) argues that the failure to deploy existing Internet security standards is not a technical problem but a political, economic, and social one, driven by a lack of will and misaligned incentives. He proposes that governments and large organisations should mandate secure-by-design requirements in their ICT procurement processes to create the economic incentives needed to drive adoption of post-quantum cryptography.
Natus noted that when organisations are asked why they are not deploying security standards, they typically blame others, but the underlying causes are a lack of a level playing field - where investing in security puts a company at a competitive disadvantage - and the absence of economic incentives because secure-by-design is rarely required in procurement . He argued that 'totally different people' need to be in the room and that procurement mandates for secure-by-design would change the dynamic .
on: International standards are a critical but insufficient mechanism for closing the quantum security gap, requiring complementary political will, inclusive processes, and diverse stakeholder participation
on: Whether technical standards are sufficient to address the quantum security divide, or whether political, economic, and social will is the primary missing ingredient
Decision makers at the cognitive and decisional layer are rarely included in quantum discussions, yet unless they are brought into the room, strategic decisions will be made for them, resulting in loss of agency and vendor lock-in
Arg. 2Patrick Bell argues that quantum discussions almost always remain at the technical or informational layer, rarely reaching the cognitive and decisional layer where governments and large corporations make strategic decisions. He warns that if decision makers are not actively included, they will lose agency over quantum-related choices and become subject to vendor lock-in and path dependence.
Bell described a three-layer framework from security studies - physical, informational, and cognitive/decisional - and observed that 'almost all the discussion' on quantum stays at the technical layer and 'very rarely does it go up to the cognitive or decisional layer' . He introduced the concept of 'vendor lock-in' and 'path dependence', warning that small nations without dedicated quantum resources 'essentially accept whatever the vendor gives them' , and argued that decision makers must be told 'unless you're in the room, things are going to be decided for you' .
on: Quantum literacy must be mainstreamed across all levels of society, including citizens, policymakers, and professionals, not just technical experts
The 'harvest now, decrypt later' threat — where encrypted data is being collected now for future decryption by quantum computers — is a concrete risk that can be used to engage decision makers on the urgency of quantum safe transitions
Arg. 3An audience member (Muganatha) raises the 'harvest now, decrypt later' threat as a concrete and immediate risk, noting that organisations are already collecting encrypted data with the intention of decrypting it once sufficiently powerful quantum computers become available. This threat is presented as a tangible way to communicate urgency to decision makers who may not otherwise engage with abstract quantum security discussions.
The audience member asked speakers to comment on the practice of organisations 'simply collecting encrypted data at this point so that they can be later decrypted' . Patrick Bell had also referenced this concept, describing 'Q-Day' as the day when a fully operational quantum computer can decrypt data that 'is being harvested right now' .
Quantum safe transition must not remain a purely technical conversation; an ecosystem-wide transformation approach is needed that simultaneously addresses infrastructure, institutions, standards, and values
Arg. 1Sipinen argues that the core risk in quantum safe transition is treating it as a purely technical migration question, which would leave the most important governance questions unanswered. She calls for an ecosystem-wide transformation approach that addresses infrastructure, institutions, standards, and values simultaneously rather than sequentially.
Sipinen stated that 'the core argument and the result of our work in drafting the paper was that we should not let the quantum safe transition stay purely a technical conversation' and that 'an ecosystem-wide transformation approach is needed' covering infrastructure, institutions, standards, and values all at the same time . She warned that treating the transition as only a technical migration question 'doesn't really get us answers' to the most important governance questions .
on: Quantum safe transition must not be treated as a purely technical issue but requires an ecosystem-wide, multi-stakeholder governance approach
on: Whether the quantum safe transition should be framed primarily as a technical/cryptographic challenge or as a broader socio-technical governance transformation
Critical governance questions — such as who decides on timelines, who bears the risk, who benefits, and who is accountable — cannot be answered through technical processes alone and require genuine multi-stakeholder engagement
Arg. 2Sipinen identifies a set of fundamental governance questions that technical processes are inherently unable to answer: who decides on transition timelines, who bears the risk of quantum threats, who benefits from quantum technologies, and who is accountable when things go wrong. She argues that only genuine multi-stakeholder engagement — covering ethical, legal, social, and political dimensions simultaneously — can address these questions.
Sipinen explicitly listed the key governance questions as 'who gets to decide on the timelines, who bears the risk of quantum, who benefits and who is then accountable if something goes wrong' , and stated that this 'definitely needs to be a multi-stakeholder discussion and process' to cover 'ethical, legal, social, political dimensions all at the same time' .
on: Quantum safe transition must not be treated as a purely technical issue but requires an ecosystem-wide, multi-stakeholder governance approach
AI governance has followed a trajectory from purely technical discussion to broader governance recognition, and quantum policy should build on these lessons rather than repeat the same slow evolution
Arg. 3Sipinen draws on her background in AI policy to argue that AI governance went through a recognisable arc — starting as a technical conversation before gradually becoming understood as a governance challenge — and that quantum policy should learn from this trajectory rather than repeat it from scratch. She frames AI governance as being 'further along' in this process and therefore a useful reference point for quantum.
Sipinen described how AI governance 'started as a technical conversation' and 'little by little, it got more clear that many of those important questions are actually governance questions, not just technical ones' , and argued that quantum policy should 'build on those lessons learned' from AI governance .
on: AI governance provides useful but imperfect lessons for quantum policy, and quantum governance should build on these lessons while actively avoiding AI's unresolved problems
Persistent challenges from AI governance, such as unequal participation from the Global South in standard setting and concentration of AI capacity among a handful of companies, must be actively avoided in quantum governance
Arg. 4Sipinen cautions that while AI governance offers useful lessons, it also presents unresolved problems that quantum governance must actively work to avoid. She specifically highlights the unequal participation of the Global South in AI standard setting and the concentration of AI capacity among a small number of companies as critical pitfalls.
Sipinen noted that 'there remain big questions, such as the unequal participation from the global south in standard setting on AI' and that 'the AI capacity is on global scale to great extent owned and controlled by only a handful of companies', describing these as 'important work and big challenges on the AI side too' that quantum governance should seek to avoid .
on: AI governance provides useful but imperfect lessons for quantum policy, and quantum governance should build on these lessons while actively avoiding AI's unresolved problems
Understanding the unique qualities that make quantum a genuinely emerging technology is foundational for all stakeholder communities before more concrete governance structures can be successfully developed
Arg. 5Sipinen argues that before governance structures for quantum can be effectively built, all stakeholder communities — not just the technical community — must invest time in understanding what makes quantum technology genuinely novel and different from previous technologies. She frames this foundational understanding as the prerequisite for meaningful governance dialogue.
Sipinen stated that 'the most important thing' when governing new technologies is 'to take time to understand what is the uniqueness, what is the quality in this new technology that actually makes it an emerging technology' , and emphasised that this understanding must be built 'not just in the technical community but bringing all the communities together' .
The convergence of AI and quantum technologies means that governance frameworks should increasingly address both together rather than treating them as entirely separate domains
Arg. 6Sipinen argues that AI and quantum are not entirely separate technologies and that their convergence will become an increasingly important topic. She suggests that in the near future, governance discussions will need to address AI and quantum jointly rather than in separate silos.
Sipinen stated that 'AI and quantum are not two separate technologies completely' and predicted that 'the discussion will probably also move more towards the convergence on AI and quantum and what those can do together', suggesting that in five years there may be 'a more solid one joint discussion on AI and quantum not separate topics of different sessions' .
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Shamira Ahmed framed the session's core premise as viewing quantum safe migration as 'a broader socio-technical infrastructure transformation that aims to redistribute trust, responsibility, and risk across institutions, markets, and communities' . Sipinen reinforced this, stating that 'the core argument and the result of our work in drafting the paper was that we should not let the quantum safe transition stay purely a technical conversation' and that 'an ecosystem-wide transformation approach is needed' . Hu argued that governance must be 'anticipatory, agile, inclusive, and human rights-sensitive' . Calarco extended this by asserting that 'every citizen has a right to say what they want, to be empowered, to determine the direction of future developments' . Audience member Wouter Natus argued that 'the topic is not technical' but rather 'about political, economic, social, security will to deploy standards' , while Patrick Bell warned that 'almost all the discussion' stays at the technical layer and 'very rarely does it go up to the cognitive or decisional layer' .
Quantum safe transition should be understood as a broader socio-technical infrastructure transformation that redistributes trust, responsibility, and risk across institutions, markets, and communities, not merely a technical cryptographic upgrade
Quantum safe transition must not remain a purely technical conversation; an ecosystem-wide transformation approach is needed that simultaneously addresses infrastructure, institutions, standards, and values
Critical governance questions — such as who decides on timelines, who bears the risk, who benefits, and who is accountable — cannot be answered through technical processes alone and require genuine multi-stakeholder engagement
UNESCO's mandate for human rights-centred governance of quantum technologies, advocating for a balanced approach that recognises both the benefits and risks of quantum - Quantum governance must be anticipatory, agile, inclusive, and human rights-sensitive, drawing lessons from AI governance
Every citizen has the right not only to know about quantum technologies but to be empowered to determine the direction of future developments, as governance is fundamentally about what society wants
The deployment of post-quantum cryptography standards requires political, economic, and social will, not just technical solutions, and procurement processes should mandate secure-by-design requirements to create the necessary economic incentives
Decision makers at the cognitive and decisional layer are rarely included in quantum discussions, yet unless they are brought into the room, strategic decisions will be made for them, resulting in loss of agency and vendor lock-in
Hu highlighted that 'the quantum divide is already in place', with a survey from UNESCO's global report finding that '43% of the country are a lack of the human talents' , and that 'there are less than 30% of workforce female in the quantum industry' . Makamara built on this, extending the concept of the quantum divide to include a security dimension, referencing the ITU's Global Cybersecurity Index as evidence of 'disparities between different countries in how they're implementing cybersecurity frameworks' , and warning that adding the quantum threat to this already unequal landscape 'doesn't look good' . Calarco also acknowledged that 'gender bias is unfortunately very strong' in the quantum field and that Europe is working to address this .
A significant human capacity gap exists globally, with 43% of countries lacking quantum talent, making workforce development and quantum literacy a critical priority alongside AI and digital literacy
A gender gap persists in quantum, with fewer than 30% of the quantum industry workforce being female, mirroring broader gender biases seen in other technology sectors
The quantum divide has both a human capacity dimension and a security dimension, as existing disparities in cybersecurity posture between countries are compounded by the emerging quantum threat
Europe already practises inclusivity through its widening participation programmes for less advanced member states and addresses gender bias within its research and innovation frameworks, providing a model for broader international cooperation
Hu argued that 'quantum literacy should also be mainstreamed from now on' and that capacity building should 'really go beyond the students and researchers and cover professionals and individuals' . She also noted that UNESCO has a programme to 'enhance the policymakers' capacity to understand new technology' . Calarco went further, arguing that citizens should be 'empowered to determine the direction of future developments' and that 'to go to vote, you don't have to have a PhD' . Patrick Bell reinforced this from the audience, noting that 'it doesn't mean you need a PhD in quantum information systems' to participate in governance discussions , and that decision makers must be told 'unless you're in the room, things are going to be decided for you' .
A significant human capacity gap exists globally, with 43% of countries lacking quantum talent, making workforce development and quantum literacy a critical priority alongside AI and digital literacy
Every citizen has the right not only to know about quantum technologies but to be empowered to determine the direction of future developments, as governance is fundamentally about what society wants
Decision makers at the cognitive and decisional layer are rarely included in quantum discussions, yet unless they are brought into the room, strategic decisions will be made for them, resulting in loss of agency and vendor lock-in
Sipinen described how AI governance 'started as a technical conversation' and 'little by little, it got more clear that many of those important questions are actually governance questions, not just technical ones' , arguing that quantum policy should 'build on those lessons learned' . However, she also cautioned that 'there remain big questions, such as the unequal participation from the global south in standard setting on AI' and that 'the AI capacity is on global scale to great extent owned and controlled by only a handful of companies' . Hu similarly argued that governance must be 'anticipatory - meaning we do draw a lesson from AI and we should really think about this governance issue before the technology is mainstreamed' .
AI governance has followed a trajectory from purely technical discussion to broader governance recognition, and quantum policy should build on these lessons rather than repeat the same slow evolution
Persistent challenges from AI governance, such as unequal participation from the Global South in standard setting and concentration of AI capacity among a handful of companies, must be actively avoided in quantum governance
UNESCO's mandate for human rights-centred governance of quantum technologies, advocating for a balanced approach that recognises both the benefits and risks of quantum - Quantum governance must be anticipatory, agile, inclusive, and human rights-sensitive, drawing lessons from AI governance
Makamara argued that standards 'are not very interesting for most people' but 'really support our systems today' , and that the ITU's consensus-based, multi-stakeholder approach involving governments, industry, and academia creates a 'multi-stakeholder environment for standards development' . She also argued that standards should be 'flexible foundations' rather than overly specific rules . However, audience member Wouter Natus highlighted that the failure to deploy existing Internet security standards is not a technical problem but a political and economic one, driven by a lack of a level playing field and absent economic incentives , arguing that procurement mandates for secure-by-design would change the dynamic .
International standards, developed through consensus-based multi-stakeholder processes involving governments, industry, and academia, are a key mechanism for closing the quantum security gap and ensuring global applicability
Standards should serve as flexible foundations rather than overly prescriptive rules, allowing for customisation and inclusivity across diverse economies and contexts
The deployment of post-quantum cryptography standards requires political, economic, and social will, not just technical solutions, and procurement processes should mandate secure-by-design requirements to create the necessary economic incentives
Both Sipinen and Calarco emphasised the need for an ecosystem-wide approach to quantum governance that integrates multiple dimensions simultaneously. Sipinen argued that 'these questions touch the infrastructure, institutions, standards, values, and they should all be addressed simultaneously' , while Calarco described the Quantum Act's three pillars — research, innovation and industrialisation, and strategic security and protection — as reflecting exactly this kind of integrated ecosystem approach . Sipinen also predicted that 'the discussion will probably also move more towards the convergence on AI and quantum' , a view consistent with Calarco's framing of quantum governance as inherently connected to broader digital technology governance. All three speakers acknowledged the gender gap in quantum as a serious and persistent problem. Hu cited data showing 'less than 30% of workforce female in the quantum industry' . Makamara noted that 'good gender distribution' is 'something that we are really missing in the standards process' . Calarco acknowledged that 'gender bias is unfortunately very strong in our field' and that Europe is working to address this within its frameworks . All three framed gender inclusivity as an integral part of addressing the broader quantum divide. Patrick Bell from the audience, Sipinen, and Calarco all converged on the view that non-technical decision makers must be actively brought into quantum governance discussions. Bell warned that 'almost all the discussion' stays at the technical layer and 'very rarely does it go up to the cognitive or decisional layer' , and that small nations 'essentially accept whatever the vendor gives them' . Sipinen identified the key unanswered governance questions as 'who gets to decide on the timelines, who bears the risk of quantum, who benefits and who is then accountable' . Calarco argued that 'it is of paramount importance to get the decision makers not only in the room, but also ready to listen to what society wants' . Both Hu and Sipinen stressed the importance of anticipatory, proactive governance that understands the unique nature of quantum technology before it becomes mainstream. Hu argued that governance must be 'anticipatory — meaning we do draw a lesson from AI and we should really think about this governance issue before the technology is mainstreamed and being applied widely' . Sipinen similarly argued that 'the most important thing' when governing new technologies is 'to take time to understand what is the uniqueness, what is the quality in this new technology that actually makes it an emerging technology' , and that this understanding must be built 'not just in the technical community but bringing all the communities together' . Both Calarco and Makamara emphasised the importance of inclusive, multi-stakeholder processes in developing standards and governance frameworks that are genuinely global in applicability. Makamara described the ITU's consensus-based process involving governments, industry, and academia , while Calarco described how Europe's experience of harmonising 27 diverse member states gives it 'the training to go towards overcoming these obstacles and being able to establish cooperation across and beyond the borders of our own countries' . Both framed inclusive process design as foundational to achieving globally applicable outcomes.
It was somewhat unexpected that Makamara, who self-identified as 'primarily a technical person' and an engineer , acknowledged that 'it's very hard to incorporate the ethical dimensions' in engineering and that standards development requires diverse stakeholder voices including governments, industry, and academia . This aligned closely with audience member Wouter Natus's argument that 'the topic is not technical' but rather 'about political, economic, social, security will to deploy standards' . The convergence between a technical standards expert and a policy-focused audience member on the primacy of non-technical factors was a notable area of unexpected agreement.
Sipinen, coming from an AI policy background in the private sector, predicted that 'the discussion will probably also move more towards the convergence on AI and quantum and what those can do together' , suggesting a joint governance discussion in five years . Calarco, a quantum physicist and academic, independently reinforced the need for integrated governance approaches through his description of the Quantum Act's ecosystem pillars and his framing of citizen empowerment as central to technology governance . The alignment between an AI policy practitioner and a quantum scientist on the need for integrated, citizen-centred governance was unexpected given their different disciplinary starting points.
The audience member Muganatha from DIMAYA raised the 'harvest now, decrypt later' threat , which Patrick Bell had also referenced as 'Q-Day' - 'the day in which you get a fully operational quantum computer that can actually decrypt the data that we're kind of like it's being harvested right now' . This concrete, immediate threat resonated with Makamara's proactive review of the X.509 standard and Sipinen's call for urgent ecosystem-wide action . The unexpected consensus here was that an audience member from a developing country context independently identified the same urgent threat that the panel had been building towards, suggesting that awareness of this risk is more widespread than the panel may have anticipated.
There was a remarkably high level of consensus across all speakers and audience participants on several foundational principles: that quantum safe transition is a socio-technical governance challenge requiring multi-stakeholder engagement ; that the quantum divide is real and multidimensional, encompassing human capacity, security, and gender gaps ; that quantum literacy must be mainstreamed across all levels of society ; that AI governance offers useful but imperfect lessons for quantum policy ; and that international standards, while critical, must be complemented by political will and inclusive processes . The panel also converged on the urgency of engaging non-technical decision makers before quantum technologies become mainstream . Minor differences in emphasis existed - for example, Makamara focused more on the technical standards dimension while Sipinen and Hu emphasised governance frameworks - but these were complementary rather than contradictory.
Makamara argued that international standards are a key mechanism for closing the quantum security gap, emphasising the ITU's consensus-based, multi-stakeholder standardisation process as the primary vehicle for ensuring global applicability . By contrast, audience member Wouter Natus argued that the failure to deploy existing Internet security standards is fundamentally not a technical problem but a political, economic, and social one . He pointed out that organisations already fail to deploy second-generation Internet standards such as DNS security and RPKI, not because of technical barriers but because of misaligned economic incentives and a lack of a level playing field . He proposed that procurement mandates for secure-by-design requirements are the missing lever , implying that standards alone - however well-designed - are insufficient without the political and economic will to implement them.
International standards, developed through consensus-based multi-stakeholder processes involving governments, industry, and academia, are a key mechanism for closing the quantum security gap and ensuring global applicability
The deployment of post-quantum cryptography standards requires political, economic, and social will, not just technical solutions, and procurement processes should mandate secure-by-design requirements to create the necessary economic incentives
Makamara, as a self-described engineer, approached the quantum safe transition primarily through the lens of technical standards and cybersecurity frameworks , focusing on the ITU's review of the X.509 standard and the role of standardisation in closing the security divide . Ahmed and Sipinen, however, explicitly framed the transition as a broader socio-technical infrastructure transformation that redistributes trust, responsibility, and risk , with Sipinen warning that treating it as a purely technical migration question 'doesn't really get us answers' to the most important governance questions . Sipinen argued that an ecosystem-wide approach addressing infrastructure, institutions, standards, and values simultaneously is required , representing a fundamentally different framing from Makamara's standards-centred view.
International standards, developed through consensus-based multi-stakeholder processes involving governments, industry, and academia, are a key mechanism for closing the quantum security gap and ensuring global applicability
Quantum safe transition must not remain a purely technical conversation; an ecosystem-wide transformation approach is needed that simultaneously addresses infrastructure, institutions, standards, and values
Quantum safe transition should be understood as a broader socio-technical infrastructure transformation that redistributes trust, responsibility, and risk across institutions, markets, and communities, not merely a technical cryptographic upgrade
Calarco made a strong democratic empowerment argument, stating that 'every citizen has a right to say what they want, to be empowered, to determine the direction of future developments' and drawing an analogy with voting - one does not need a PhD to participate in democracy . He explicitly pushed back against the notion that quantum governance requires deep technical expertise . Makamara, by contrast, acknowledged the difficulty of incorporating ethical dimensions into engineering and focused her multi-stakeholder framing on governments, industry, and academia - a narrower set of actors than Calarco's vision of broad citizen empowerment. Makamara also noted that demographic diversity and gender distribution in standards processes are areas she cannot directly control , implying structural limits to the inclusivity she can advocate for within her institutional role.
Every citizen has the right not only to know about quantum technologies but to be empowered to determine the direction of future developments, as governance is fundamentally about what society wants
International standards, developed through consensus-based multi-stakeholder processes involving governments, industry, and academia, are a key mechanism for closing the quantum security gap and ensuring global applicability
It was unexpected that an audience member would implicitly challenge the framing of the ITU's own representative. Makamara, as an ITU engineer, presented standards as the key mechanism for closing the quantum divide , and described the ITU's consensus-based process as ensuring inclusivity . However, Natus directly challenged this framing by pointing out that existing Internet security standards - which are also ITU and IETF products - are widely not deployed, not because of technical deficiencies but because of misaligned economic incentives and lack of political will . He observed that 'everybody leaves the room as soon as the word Internet standard or post-quantum cryptography is mentioned' , implying that the technical community's framing of these issues as standards problems is itself a barrier to engagement. This was an unexpected moment of tension given that Makamara was presenting the ITU's standardisation work as a solution, while Natus was effectively arguing that the same type of work has already failed to produce deployment in analogous cases.
It was somewhat unexpected that Calarco, while presenting Europe as a model of inclusive multilateralism , simultaneously acknowledged that 'the era of multilateral cooperation and globalization in the positive sense kind of has come to a halt' and described the current context as a 'multi-polar world disorder' . This created an internal tension in his argument: Europe is presented as a best-practice model for inclusive cooperation, yet the broader international environment in which this model is supposed to be extended is characterised as fundamentally hostile to such cooperation. Sipinen's warning about unequal Global South participation in AI standard setting and concentration of capacity among a handful of companies implicitly raised the question of whether European-led quantum governance initiatives might replicate these same power asymmetries, even if unintentionally - a challenge that Calarco's optimistic framing of European values and widening participation programmes did not fully address.
There was an unexpected implicit tension between Hu's and Calarco's calls for broad quantum literacy and citizen empowerment and the practical reality described by Hu herself - that 43% of countries lack even the basic human talent to develop quantum capabilities - and by Ahmed, who noted that quantum discussions often prompt the response 'are you having a PhD in physics? If not maybe you just shut up' . Audience member Bell's observation that quantum discussions almost never reach the cognitive and decisional layer further underscored the gap between the aspiration of broad citizen empowerment and the current reality where even professional decision makers are not engaged. This created an unexpected tension between the normative goal of quantum literacy for all and the empirical evidence of how far current reality falls short, without any speaker offering a concrete pathway to bridge this gap.
The discussion revealed a broadly collaborative atmosphere with shared goals around inclusive, anticipatory, and multi-stakeholder quantum governance. However, substantive tensions emerged in three main areas: (1) whether technical standards or political/economic will is the primary lever for quantum safe transitions ; (2) whether the transition should be framed as a technical/cryptographic challenge or a broader socio-technical governance transformation ; and (3) whether citizen empowerment and quantum literacy are realistic near-term goals given the acknowledged scale of the human capacity gap . A further tension existed between Europe's self-presentation as a model of inclusive multilateralism and the acknowledged reality of a multi-polar world disorder and persistent Global South exclusion from standard-setting processes . The most concrete disagreement was between Makamara's standards-centred approach and Natus's argument that the real barrier is the absence of political and economic will to deploy standards that already exist .
All speakers agreed that quantum governance must be multi-stakeholder and cannot remain purely technical. Hu emphasised anticipatory, agile, inclusive, and human rights-sensitive governance ; Makamara highlighted the need for diverse voices including governments, industry, and academia in standards processes ; Sipinen called for an ecosystem-wide transformation approach ; Calarco argued for citizen empowerment in determining the direction of quantum development ; and audience member Bell argued that decision makers at the cognitive and decisional layer must be brought into the room . However, they diverged on the primary mechanism: Makamara focused on standards , Sipinen on ecosystem governance frameworks , Hu on anticipatory policy and literacy , Calarco on democratic empowerment and the Quantum Act , and Bell on engaging strategic decision makers through framing quantum as a national security and human problem .
UNESCO's mandate for human rights-centred governance of quantum technologies, advocating for a balanced approach that recognises both the benefits and risks of quantum - Quantum governance must be anticipatory, agile, inclusive, and human rights-sensitive, drawing lessons from AI governance The quantum divide has both a human capacity dimension and a security dimension, as existing disparities in cybersecurity posture between countries are compounded by the emerging quantum threat Quantum safe transition must not remain a purely technical conversation; an ecosystem-wide transformation approach is needed that simultaneously addresses infrastructure, institutions, standards, and values Every citizen has the right not only to know about quantum technologies but to be empowered to determine the direction of future developments, as governance is fundamentally about what society wants Decision makers at the cognitive and decisional layer are rarely included in quantum discussions, yet unless they are brought into the room, strategic decisions will be made for them, resulting in loss of agency and vendor lock-in
Hu, Makamara, and Calarco all acknowledged the gender gap in quantum as a serious problem. Hu cited data showing fewer than 30% of the quantum workforce is female ; Makamara stated that good gender distribution is 'something that we are really missing in the standards process' ; and Calarco noted that gender bias is 'unfortunately very strong' in the quantum field and that Europe is working to address it . However, they differed on what can be done: Makamara acknowledged she could only encourage member delegations to improve gender distribution but could not mandate it , while Calarco pointed to European policy measures as providing structural mechanisms , and Hu called for mainstreaming quantum literacy across all levels including addressing gender gaps .
A gender gap persists in quantum, with fewer than 30% of the quantum industry workforce being female, mirroring broader gender biases seen in other technology sectors International standards, developed through consensus-based multi-stakeholder processes involving governments, industry, and academia, are a key mechanism for closing the quantum security gap and ensuring global applicability Europe already practises inclusivity through its widening participation programmes for less advanced member states and addresses gender bias within its research and innovation frameworks, providing a model for broader international cooperation
Sipinen, Hu, and Calarco all agreed that quantum governance should learn from AI governance and act in an anticipatory manner rather than waiting for the technology to be widely deployed. Hu explicitly stated that governance should be anticipatory, 'drawing a lesson from AI' to address risks before the technology becomes mainstream . Sipinen argued that AI governance is 'further along' and that quantum policy should 'build on those lessons learned' . Calarco endorsed the paper's ecosystem governance framing as the right approach . However, Sipinen also cautioned that AI governance has unresolved problems — including unequal Global South participation in standard setting and concentration of AI capacity among a handful of companies — that quantum governance must actively avoid, introducing a note of caution about uncritically importing AI governance models that Hu and Calarco did not explicitly address.
AI governance has followed a trajectory from purely technical discussion to broader governance recognition, and quantum policy should build on these lessons rather than repeat the same slow evolution UNESCO's mandate for human rights-centred governance of quantum technologies, advocating for a balanced approach that recognises both the benefits and risks of quantum - Quantum governance must be anticipatory, agile, inclusive, and human rights-sensitive, drawing lessons from AI governance Every citizen has the right not only to know about quantum technologies but to be empowered to determine the direction of future developments, as governance is fundamentally about what society wants
Both Makamara and audience member Natus agreed that the quantum security divide is a serious and compounded problem that requires urgent attention. Makamara used the ITU's Global Cybersecurity Index to demonstrate existing disparities between countries and acknowledged that adding the quantum threat 'doesn't look good' . Natus similarly warned that without action, 'we'll be discussing we haven't lost everything when that first computer comes on' . However, they diverged sharply on the solution: Makamara focused on standards as the primary mechanism , while Natus argued that the real barrier is the absence of political, economic, and social will to deploy standards that already exist, and that procurement mandates are the necessary lever .
The quantum divide has both a human capacity dimension and a security dimension, as existing disparities in cybersecurity posture between countries are compounded by the emerging quantum threat The deployment of post-quantum cryptography standards requires political, economic, and social will, not just technical solutions, and procurement processes should mandate secure-by-design requirements to create the necessary economic incentives
- Quantum safe transition must be understood as a broader socio-technical infrastructure transformation that redistributes trust, responsibility, and risk across institutions, markets, and communities, not merely a technical cryptographic upgrade.
- Quantum governance must be anticipatory, agile, inclusive, and human rights-sensitive, drawing explicit lessons from the trajectory of AI governance to avoid repeating the same slow evolution from technical to broader governance recognition.
- A significant global human capacity gap exists, with 43% of countries lacking quantum talent; quantum literacy must be mainstreamed alongside AI and digital literacy for citizens, professionals, and policymakers alike.
- A persistent gender gap in quantum persists, with fewer than 30% of the quantum industry workforce being female, mirroring broader gender biases seen across technology sectors.
- The quantum divide has both a human capacity dimension and a security dimension, as existing disparities in cybersecurity posture between countries are compounded by the emerging quantum threat.
- International standards, developed through consensus-based multi-stakeholder processes involving governments, industry, and academia, are a critical mechanism for closing the quantum security gap and ensuring global applicability across diverse economies.
- The ITU is reviewing foundational standards such as X.509 to identify vulnerabilities ahead of the quantum threat, ensuring that the Internet's security infrastructure is as robust as possible before the threat materialises.
- Deployment of post-quantum cryptography standards requires political, economic, and social will, not just technical solutions; procurement processes should mandate secure-by-design requirements to create the necessary economic incentives and a level playing field.
- Critical governance questions — such as who decides on timelines, who bears the risk, who benefits, and who is accountable — cannot be answered through technical processes alone and require genuine multi-stakeholder engagement at the cognitive and decisional layer.
- The 'harvest now, decrypt later' threat — where encrypted data is being collected now for future decryption by quantum computers on Q-Day — is a concrete and urgent risk that can be used to engage decision makers on the necessity of quantum safe transitions.
- Decision makers at the strategic and governmental level are rarely included in quantum discussions; unless they are brought into the room, strategic decisions will be made for them, resulting in loss of agency and vendor lock-in, particularly for smaller nations.
- Persistent challenges from AI governance, such as unequal participation from the Global South in standard setting and concentration of capacity among a handful of companies, must be actively avoided in quantum governance.
- The convergence of AI and quantum technologies means that governance frameworks should increasingly address both together rather than treating them as entirely separate domains.
- Europe's forthcoming Quantum Act represents the first structured European Commission policy for international quantum cooperation, built on three pillars: research, innovation and industrialisation, and strategic security and protection including standardisation.
- Europe's experience of harmonising standards and access across 27 diverse sovereign member states provides inherent training in multilateralism that can serve as a model for broader international cooperation, including with Africa and other regions.
- Every citizen has the right not only to know about quantum technologies but to be empowered to determine the direction of future developments, as governance is fundamentally about what society wants, not about possessing technical expertise.
“The quantum divide is already in place. One of the most important divides is on the human capacity gap — 43% of countries lack human talent. Additionally, less than 30% of the quantum industry workforce is female, signalling a significant gender bias in quantum development.”
“I like to think of the quantum divide in two ways — both from the human perspective, but then also the security divide in itself. The ITU's Global Cybersecurity Index already reveals stark disparities between countries. Now add the quantum threat into the mix — it doesn't look good.”
“We should not let the quantum safe transition stay purely a technical conversation. An ecosystem-wide transformation approach is needed. The danger is that if we treat this transition as a technical migration question only, it doesn't get us close to the most important questions: who gets to decide on the timelines, who bears the risk, who benefits, and who is accountable if something goes wrong?”
“The topic is not technical. This topic is about the political, economic, social, and security will to deploy standards. We need totally different people in the room. Large organisations and governments should be demanding secure-by-design in their procurement processes — including post-quantum cryptography. If we don't, there are two problems: a lack of a level playing field (investing in security means earning less than a competitor who doesn't), and no economic incentive because nobody procures secure by design.”
“Almost all the discussion I've seen goes to the technical layer. Very rarely does it go up to the cognitive or decisional layer — where governments and large corporations are the strategic decision-makers. When you include them and tell them 'this is not just an IT problem, this is a national security problem, but more importantly, a human problem' — and specifically, if you have a very small nation that doesn't have money to dedicate to quantum, they just accept whatever the vendor gives them. Unless you're in the room, things are going to be decided for you, and you'll lose any agency in your decision-making.”
“Every citizen has a right not just to know, but to be empowered — to determine the direction of future developments. To go to vote, you don't have to have a PhD. Society wants to be able to say which direction this should take. The paper rightly frames the problem not as a technical issue or a cybersecurity aspect, but as an ecosystem governance aspect. In the Quantum Act, we have three pillars: research and science, innovation and industrialisation, and strategic security and protection — which includes standardisation. This will not be optional for member states.”
How can quantum literacy be mainstreamed for citizens, policymakers, and professionals, similar to AI literacy and digital literacy?
The discussion highlighted that quantum literacy is significantly underdeveloped compared to AI and digital literacy. Given that quantum technologies will profoundly impact society, ensuring broad understanding across all levels — from individual citizens to government decision-makers — is critical for inclusive and informed governance.
How can the gender gap in the quantum workforce (currently less than 30% female) be addressed, and what specific policy measures can close this divide?
Multiple speakers flagged the significant gender bias in the quantum industry and in standards development processes. Further research is needed into targeted interventions, policy measures, and best practices that can improve gender representation across the quantum ecosystem.
How can developing countries and low-resource nations be meaningfully included in quantum safe transition processes, given the existing cybersecurity divide and human capacity gaps?
The discussion identified that a quantum divide already exists, particularly in terms of human capacity and cybersecurity readiness. Further research is needed on how international standardisation, capacity building, and governance frameworks can be designed to be genuinely inclusive of developing nations rather than leaving them dependent on vendor-driven solutions.
How can procurement processes be reformed so that governments and large organisations require 'secure by design' ICT, including post-quantum cryptography, as a standard requirement?
The speaker highlighted that the absence of procurement-driven demand for secure-by-design systems creates a negative incentive structure where organisations have little economic motivation to deploy post-quantum standards. Research into procurement policy reform could be a key lever for accelerating adoption.
How can decision-makers at the cognitive and decisional level (governments, large corporations) be brought into quantum governance discussions, given that most discourse remains at the technical layer?
Several speakers noted that quantum discussions rarely reach the level of strategic decision-makers. Further research is needed on communication strategies, governance frameworks, and engagement models that can effectively translate technical quantum risks into actionable policy and organisational decisions.
What are the implications of 'harvest now, decrypt later' strategies, where organisations are currently collecting encrypted data to decrypt once quantum computers become operational?
This question was raised but not fully addressed during the session. It represents a critical and immediate security threat that warrants further research into the scale of such data harvesting activities, which organisations are involved, and what policy and technical responses are available.
How can the governance lessons learned from AI policy be systematically applied to quantum governance to avoid repeating the same mistakes, particularly regarding unequal participation from the Global South and market concentration?
The speaker drew parallels between AI and quantum governance trajectories, noting that AI governance remains incomplete, with significant challenges around Global South participation and concentration of capabilities in a handful of companies. Structured comparative research could help identify transferable lessons and avoid replicating these inequities in quantum governance.
How will the convergence of AI and quantum technologies create new governance challenges, and how should multi-stakeholder frameworks evolve to address these jointly?
The speaker suggested that AI and quantum are not entirely separate technologies and that their convergence will likely become a central governance challenge. Further research is needed to anticipate the combined risks and opportunities of AI-quantum convergence and to develop governance frameworks that address both simultaneously.
What specific governance safeguards are being embedded within Europe's quantum initiatives (Quantum Act, Euro HPC, IRIS²) to ensure equitable participation and benefit-sharing beyond European borders, particularly with Africa and the Global South?
While Tommaso outlined Europe's intentions for international cooperation, the specific mechanisms and safeguards for ensuring equitable participation by non-European countries remain underspecified. Further research and policy development is needed to translate these intentions into concrete, accountable frameworks.
How can the 'vendor lock-in' and 'path dependence' risks in quantum safe transitions be mitigated, particularly for smaller nations with limited resources?
The speaker highlighted that smaller nations without dedicated quantum budgets are likely to simply accept whatever vendors provide, creating long-term dependency and loss of agency. Research into policy tools, open standards, and multilateral support mechanisms that can reduce vendor lock-in is critically needed.
How should the concept of 'Q-Day' (the day a fully operational quantum computer capable of breaking current encryption becomes available) be communicated to decision-makers to drive timely action?
The speaker introduced Q-Day as a concrete framing tool for engaging decision-makers, but the question of how best to communicate this risk — and translate it into organisational and policy action — remains open. Further research into risk communication strategies tailored to non-technical audiences is needed.
How can international standardisation processes be made more agile and inclusive to accommodate diverse stakeholder voices, particularly from developing countries, while still achieving the consensus needed for global interoperability?
The tension between the need for consensus-based, inclusive standards development and the urgency of the quantum threat was highlighted. Further research is needed on governance models for standardisation that can balance speed, inclusivity, and technical rigour.
What anticipatory governance mechanisms can be developed for quantum technologies to ensure risks are identified and mitigated before the technology is widely deployed, drawing on lessons from AI governance?
The speaker emphasised the importance of anticipatory governance for quantum, noting that AI governance was largely reactive. Research into foresight methodologies, early warning systems, and proactive regulatory frameworks specifically designed for quantum technologies would be highly valuable.
How can the multi-stakeholder ecosystem approach proposed in the ITU Kaleidoscope paper be operationalised across different institutional, national, and sectoral contexts to ensure ethical, legal, social, and policy dimensions are addressed simultaneously?
The paper presented at the conference proposes an innovation ecosystem ethics approach, but the practical operationalisation of this framework across diverse contexts remains an open research and policy question. Further work is needed to develop implementation guidance, pilot frameworks, and evaluation mechanisms.
