Yes. Even before a European Quantum Act is in place, Article 32 of the General Data Protection Regulation (GDPR) and Article 30 of the Belgian NIS2Act of April 26, 2024, require companies to align their security measures with the state of the art, and the European roadmap of June 23, 2025, calls for the transition to post-quantum cryptography to begin by the end of 2026. The quantum computer capable of breaking today’s encryption does not yet exist. However, the legal obligation to prepare for it already exists.
In short:
- In its Quantum Europe Strategy of July 2, 2025, the European Commission promised a Quantum Act for the second quarter of 2026; that deadline passed without a proposal, and in early September 2026, the Commission itself mentioned the end of 2026 or 2027 as the target date for a law that primarily organizes cooperation and does not impose any obligations.
- On June 23, 2025, the member states set three deadlines for the transition to post-quantum cryptography: begin by the end of 2026, have critical systems ready by the end of 2030, and have the rest ready by the end of 2035.
- For anyone who processes personal data or is subject to the NIS2 Act, outdated encryption is already a security vulnerability today: under Article 59 of that law, a major entity risks a fine of up to 7,000,000 euros or 1.4 percent of its global annual revenue.
What Makes a Quantum Computer Different
A quantum computer is a computer that performs calculations using qubits instead of bits. A classical bit is either 0 or 1. A qubit, as long as it is not measured, can take on both values at the same time. This property is called superposition. Furthermore, two qubits can become entangled, so that the state of one immediately determines that of the other, regardless of the distance between them. For certain mathematical problems, this results in a level of computational power that no classical supercomputer can match.
Three areas of application recur throughout the policy documents: quantum sensors that measure mass, time, or light with unprecedented precision; quantum computers that solve optimization and simulation problems; and quantum communication that transmits information via entangled particles and immediately reveals any eavesdropping. The promises are concrete: new medicines, better batteries, and faster logistics.
At the same time, the technology is fragile. Qubits lose their state at the slightest disturbance from the environment, a phenomenon known as decoherence. That is why current machines operate at temperatures close to absolute zero and rely on robust error correction. This explains the high cost, and it explains why the major players are primarily American and Chinese companies.
Europe is opting for a strategy—and will soon adopt a law
On July 2, 2025, the European Commission published its Quantum Europe Strategy (COM(2025) 363 final), with the goal of making Europe a global leader in quantum technology by 2030. The strategy focuses on five areas: research and innovation, quantum infrastructure, strengthening the ecosystem, space and dual-use applications, and skills. It also announced a Quantum Act, scheduled for the second quarter of 2026.
That timeline was not met. The strategy set the proposal for the second quarter of 2026, as did the joint roadmap One Europe, One Market The process involving the Parliament, the Council, and the Commission, which began in the spring of 2026, continued throughout that quarter, with the goal of reaching a political agreement in the third quarter of 2027. As of today, nothing is on the table. On September 3, 2026, the Deputy Director-General of DG CNECT stated that the proposal could be presented later this year, but that internal procedures could push it back to 2027, as reported by MLex. A draft text does not yet exist, Techzine confirmed a few days later.
Will the Quantum Act become a second AI Act?
There are calls to regulate quantum technology based on the model of the AI Act, Regulation (EU) 2024/1689, which classifies artificial intelligence according to risk. The reasoning is tempting. Quantum computing and artificial intelligence reinforce each other, and the risks are the same: infringement of fundamental rights, concentration of the technology in the hands of a few large companies, and criminal and military abuses. Anyone familiar with the AI Act’s risk pyramid will immediately see the similarity.
Yet the Commission itself is pointing in a different direction. According to the same director-general, unlike the AI Act, the Quantum Act should not primarily impose rules and obligations, but rather provide a framework within which the European quantum sector can collaborate more effectively and achieve greater scale. Furthermore, the law will not have its own budget: unlike the Regulation (EU) 2023/1781 According to the Commission, the Quantum Act—which follows the September 13, 2023, legislation (the Chips Act), which included its own investment component—is primarily intended to encourage the sector to collaborate and scale up using existing resources, such as Horizon Europe and the EuroHPC Joint Undertaking.
This choice is justifiable. The AI Act demonstrates how a risk-based approach becomes an all-or-nothing system in practice, as we analyzed earlier in our blog Is the AI Act really risk-based? A sector with 78 European startups and virtually no large-scale production has little to gain from such a system. The risk posed by quantum computing also lies not in the product itself, but in how it affects existing security measures. That problem does not require new legislation, as it is already covered by existing laws.
Why Your Current Encryption Has an Expiration Date
Almost all of the encryption that secures the internet today relies on mathematical problems that a classical computer cannot solve within a reasonable amount of time: factoring very large numbers into prime factors, or computing discrete logarithms. RSA, the most widely used method for key exchange and digital signatures, works this way. In 1994, mathematician Peter Shor demonstrated that a sufficiently powerful quantum computer can solve these problems in polynomial time; his detailed paper appeared in 1997 in the SIAM Journal on Computing. So the algorithm is thirty years old. All that's missing is the machine.
That doesn’t mean the threat is something for the future. Anyone who intercepts and stores encrypted traffic today can decrypt it later, as soon as the technology becomes available. For data that must remain confidential for ten years—such as medical records, contracts, or source code—this vulnerability is already a reality.
Post-quantum cryptography is a form of encryption based on mathematical problems that even a quantum computer cannot solve quickly. The U.S. National Institute of Standards and Technology (NIST) published on August 13, 2024 the first three final standards (FIPS 203, 204, and 205). The European Commission asked the member states in Recommendation (EU) 2024/1101 dated April 11, 2024, regarding a coordinated transition. The member states responded on June 23, 2025, with a joint roadmap which specifies three dates: by the end of 2026, all member states will begin developing national plans and inventories; by the end of 2030, critical systems and high-risk applications will have been transitioned; and by the end of 2035, the rest will follow where feasible.
Is post-quantum cryptography already mandatory today?
No Belgian or European law currently mandates a specific algorithm. The requirement runs deeper: it lies in the open standards that existing laws impose on security.
Article 32 of the General Data Protection Regulation (GDPR) requires the controller and the processor to implement technical measures that ensure a level of security appropriate to the risk, taking into account the state of the art. The state of the art is constantly evolving. Once post-quantum algorithms are standardized and available—which they have been since August 2024—it becomes more difficult to justify encryption that is known to be breakable in the long term. The GDPR adds a second consideration to this. In practice, pseudonymization relies on the encryption or hashing of identifying data. Anyone who breaks through that layer makes the data subject identifiable again, with all the consequences that entails for the classification as personal data, as we explained earlier in our blog When is pseudonymized data still considered personal data?
For the entities covered by the NIS2 law In such cases, the standard is even more explicit. Article 30, § 2 of the Act of April 26, 2024, establishing a framework for the cybersecurity of network and information systems of general interest to public safety (NIS2 Act) requires measures that take into account the state of the art as well as European and international standards. Article 30, § 3, 8° expressly mentions a policy and procedures regarding the use of cryptography and encryption. An entity that does not maintain an inventory of its cryptography or have a migration plan will find it difficult to comply with this provision. The penalty is set forth in Article 59: for a significant entity, an administrative fine of 500 to 7,000,000 euros or 1.4 percent of global annual revenue; for an essential entity, up to 10,000,000 euros or 2 percent.
There is a third rule that is rarely mentioned. Article XI.291 of the Code of Economic Law (CEL), that Article 6 of the directive 2001/29/EC Revenue protects technical measures on copyrighted works against circumvention. That protection applies only to effective measures—that is, measures that actually achieve the intended protection. Our interpretation is that encryption that a quantum computer routinely breaks can no longer be considered effective, meaning that the rights holder loses protection against circumvention. There is no case law on this matter in Belgium yet. Nevertheless, for publishers, streaming services, and software companies, this is a reason to update their security measures—and not just for security reasons.
Who owns a quantum algorithm?
A quantum algorithm is, at its core, a mathematical method. Article XI.4 of the WER and Article 52, paragraph 2, of the European Patent Convention exclude mathematical methods and computer programs as such from patentability. However, the exclusion applies only to the method as such. As soon as the algorithm solves a technical problem—for example, correcting decoherence in a specific quantum processor—there is a technical contribution that may indeed be patentable. The patent law This does allow for some flexibility, but the patent application must be based on the technical effect rather than the mathematics. The United States is more flexible in this regard than Europe, and that difference matters for those operating in both markets.
Hardware is better protected than software. In Recital 17, the Chips Act explicitly mentions quantum chips and pilot lines for their production as part of the European semiconductor policy. Anyone investing in quantum hardware is therefore covered by a policy that already exists.
The question of the output remains. A quantum computer combined with a generative model produces text, music, or designs on a scale that is unimaginable today. Since the ruling, the Court of Justice has required, for copyright protection, that Infopaq (ECJ, July 16, 2009, C-5/08) an intellectual creation of the author, and since the judgment Painer (ECJ, December 1, 2011, C-145/10) free and creative choices that reflect the author’s personality. A machine does not make choices in that sense. The question that remains is whether the person who writes the prompts and selects from the variants makes enough independent choices to be considered the author. For quantum AI, this question is the same as for classical AI.
Quantum Computers as Military Assets
A dual-use item is a good, software, or technology that can be used for both civilian and military purposes and whose export is therefore subject to a license. The Regulation (EU) 2021/821 Dated May 20, 2021, it establishes those controls for the entire Union and lists in Annex I which products are subject to authorization.
Quantum computers have been on that list since November 15, 2025. The Delegated Regulation (EU) No. 2025/2003 The regulation of September 8, 2025, added quantum computers, along with the components that make them work: electronics that operate at cryogenic temperatures, parametric signal amplifiers, cooling systems, and low-temperature wafer testers. A Belgian company that supplies such components outside the Union therefore needs an export license from the regional authority responsible for strategic goods. Technical assistance and brokering are also covered by the regulation.
There is a downside to these controls. Export controls protect national security, but they also protect domestic industries from foreign competition. In a sector where the United States and China together hold the lion’s share of patents, the line between security policy and protectionism is not always clear-cut. A European startup that sources its components from Asia experiences this from both sides.
Specifically, what does this mean?
For executives and security officers of NIS2 entities. The first step is not a purchase but an assessment: which systems use which encryption, which data must remain confidential and for how long, and which vendors manage those keys. Based on this, a migration plan will be developed with a timeline that follows the roadmap set for June 23, 2025. If you’re unsure whether your current cryptography policy complies with Article 30 of the NIS2 Act, that’s the first thing we’ll check for you.
For data controllers. Include post-quantum cryptography in the periodic evaluation of security measures under Article 32 of the GDPR, and specify in the data processor agreements when the data processor will update its encryption. Anyone who shares pseudonymized data should reassess whether that pseudonymization will still be valid in ten years.
For technology companies and research institutions. Anyone developing a quantum algorithm or a component should decide early on between confidentiality and a patent, and base the application on the technical effect. Anyone manufacturing components should review their product catalog against Annex I of Regulation (EU) 2021/821, as amended in November 2025. For both of these matters, you would be well advised to seek assistance from a lawyer specialized in patent law with experience in software and export controls.
Frequently asked questions (FAQ)
Is post-quantum cryptography already mandatory in Belgium?
No law currently prescribes a specific algorithm. However, Article 32 of the GDPR and Article 30 of the NIS2 Act require security measures that are in line with the state of the art, and as of August 2024, that state of the art includes standardized post-quantum algorithms. The European roadmap of June 23, 2025, expects member states and critical sectors to begin the transition by the end of 2026 and to complete it by the end of 2030. For high-risk systems, a wait-and-see approach is therefore difficult to justify.
As an SME, do I need to replace all my encryption right now?
Not necessarily right away, but it is planned. The question is how long your data needs to remain confidential. Data that will still be sensitive in five to ten years could be intercepted today and decrypted later. Start by taking stock of your encryption and the vendors who manage it, and ask them about their timeline. If your company is subject to the NIS2 regulation, a cryptography policy is already a legal requirement.
Can I patent a quantum algorithm?
Not as a purely mathematical method: Article XI.4 of the Economic Law Code and Article 52 of the European Patent Convention exclude such methods. However, it is patentable if the algorithm solves a technical problem, such as error correction in a specific quantum processor. The patent application must then be drafted to describe that technical effect. Alternatively, protection as a trade secret remains possible, provided that reasonable confidentiality measures are in place.
Conclusion
The United Nations declared 2025 to be International Year of Quantum Science and Technology (Resolution A/RES/78/287 of June 7, 2024), and Europe aims to be a global leader by 2030. The Quantum Act intended to support this is not yet in place and will not be a second AI Act. For Belgian companies, this changes little in terms of their obligations: the GDPR and the NIS2 Act already require them to align their encryption with a state-of-the-art standard that incorporates post-post-quantum cryptography is available; export controls have also applied to quantum hardware since November 2025; and patent law rewards only those who can formulate their algorithm as a technical solution. Anyone in Belgium waiting for the quantum computer to take action will be too late.
ICT Rechtswijzer is the knowledge platform of the Intellectual Property, IT Law, AI Law, Data Protection, and Media Law department at Everest Advocaten, led by Joris Deene, Esq. Our attorneys assist companies in assessing the compliance of their cryptography policies with the GDPR and the NIS2 Directive, in protecting quantum algorithms and hardware, and in meeting licensing requirements for the export of dual-use products.


