Analyzing critical legal trends and developments across data, cyber, AI and digital regulations from around the world and beyond borders

In brief

With the rapid deployment of AI in recent years, most in-house attorneys will appreciate the impact of technological advances on legal risk to their organizations. Although a commercially viable and scalable quantum computer does not currently exist, the legal regime related to this transformative technology is already under development, and the potential risks and legal issues are already apparent. This post is a primer on the legal issues and risks every in-house lawyer should keep in mind as quantum moves out of the lab and into the mainstream.

What is quantum?

Quantum computing uses the principles of quantum mechanics to process complex information exponentially faster than classical computers. Instead of using standard binary bits (0s and 1s), it relies on qubits, which can exist as both 0 and 1 simultaneously (superposition) and interact instantly across vast distances (entanglement). Quantum computers are still in their early stages. Potential applications include a machine that can design powerful new drugs by simulating the behavior of individual molecules, or optimize complex supply chains by helping companies get the parts they need and assemble them in the most efficient way possible. With the potential technological advances, however, come technological risks. Quantum computers could break the encryption that safeguards your private information on the internet. Further, the opportunities for harvest-now-decrypt-later (HNDL) expose multinationals to an exponential increase in harm from security incidents and new potential threat vectors in a way that significantly changes the cybersecurity and risk landscape for multinationals.

There are numerous signals that quantum is moving from a purely research-based field to a commercially viable industry, with the development of new infrastructure, significant capital investment and growing adoption:

  • The Chicago region has established itself as a leading quantum ecosystem, including the establishment of the Illinois Quantum and Microelectronics Park, major commitments from PsiQuantum to build a large-scale quantum computer in Illinois, and significant support from the State of Illinois, the University of Chicago, Argonne National Laboratory, Fermilab, the federal US National Quantum Initiative and private actors.[1]
  • Multinationals are beginning to announce their use of quantum in business applications:
    • BMW has publicly partnered with several quantum providers to optimize manufacturing processes, supply-chain logistics and vehicle production planning.[2]
    • Roche has announced collaboration with quantum computing companies for drug discovery, molecular modeling and biomedical research.[3]
    • JPMorgan has announced partnerships with quantum companies for portfolio optimization, risk analysis, derivatives pricing and cybersecurity.[4]
  • Quantum companies are raising large amounts of capital:
    • Quantinuum’s June 2026 $1.68 billion IPO represents the first traditional quantum IPO, and it is now the largest pure-play quantum computing company.
    • PsiQuantum, IonQ, D-Wave, Rigetti, QuEra, Alice & Bob and SandboxAQ have continued to announce significant recent capital raises.
  • Quantum companies are now center stage in M&A:
    • D-Wave Quantum Inc. (NYSE: QBTS) acquired Quantum Circuits Inc. for $550 million.
    • European quantum leader IQM agreed to a combination with Real Asset Acquisition Corp.
    • Quantum Computing Inc. (NASDAQ: QUBT) acquired NHanced Semiconductors for $73.1 million and Luminar Semiconductor for $110 million.

This is also a fast-moving and rapidly evolving space, and that dynamism is reflected in the deal market and capital markets. Alongside this initial activity, we are likely to see a steady increase in M&A, strategic investment, and partnership activity across the quantum stack, creating both competitive pressure and meaningful opportunities for organizations that position themselves early. These same dynamics sharpen the diligence and integration considerations discussed in point 7 (M&A diligence and cross-border reorganizations) below.

Concurrently with the increased interest in and financing of quantum, regulators in the United States, European Union, United Kingdom, and Asia-Pacific have begun publishing concrete timelines and non-binding proposed controls:

  • NIST has finalized its first post-quantum cryptography (PQC) standards (FIPS 203 ML-KEM; FIPS 204 ML-DSA; FIPS 205 SLH-DSA).
  • The June 22, 2026, US Executive Order on Securing the Nation Against Advanced Cryptographic Attacks sets December 31, 2030, for Key Encapsulation Mechanisms (KEM) migration and 2031 for signatures in federal systems and directs FAR amendments to flow PQC obligations to covered contractors.
  • Parallel work is underway in the EU (Quantum Europe Strategy, planned Quantum Act, ENISA’s draft Agreed Cryptographic Mechanisms v3) and the UK (NCSC roadmap to 2035).

For multinationals, the practical effect is that the “state of the art” and “reasonable security” standards in existing laws are starting to be informed by published government mandates, even before those mandates apply directly to private actors.

Practical Issues for In-House Attorneys

As these standards develop and broaden, in-house attorneys need to stay ahead of the regulatory and risk curve. For many in-house teams, the muscle built out for AI governance (cross-functional intake, board reporting, vendor questionnaires, disclosure calibration) is the same muscle that will carry quantum readiness across legal teams, including privacy, IP, technology, trade, M&A and investigations.

Below are ten key legal issues to track as quantum computing takes hold.

1. Cryptographic inventory and program governance

A defensible post-quantum cryptography (PQC) posture starts with knowing where cryptography lives, on what data, and with what lifetimes.

2. Vendor, cloud, and IT contracting

This is the operational lever in-house teams will be asked about first. Market practice is still forming. We are not yet seeing a consistent set of PQC clauses across enterprise procurement. The near-term ask is visibility, understanding which vendors have PQC roadmaps and how that maps to the customer’s own data and obligations, rather than needing to update all template agreements right now. Long-dated commitments made today (e.g., multi-year vendor contracts, data licenses, product roadmaps, and M&A undertakings) will need to work in a post-quantum environment, so quantum considerations are entering current transactions even where Q-Day timing remains uncertain.

3. Data

Data, especially regulated or sensitive data (e.g., health, genomic, financial, defense-adjacent, trade secrets), is the data most exposed to the HNDL theory. Protecting data is already central to organizations and this technological evolution will further increase the need to focus on legal mechanisms for protecting data.

4. Privacy and data protection

Global privacy laws require security “appropriate to the risk” measured against the state of the art. As regulators publish PQC timelines, that benchmark may begin to shift. California’s new CCPA cybersecurity audit and risk-assessment regulations expressly assess encryption at rest and in transit, which is a natural place for PQC readiness to surface in the audit cycle.

5. IP strategy

For quantum developers, patent strategy, freedom-to-operate, and standards-essential patent exposure will be active questions as PQC algorithms enter implementation standards. All companies will need to focus on trade secrets. Export-controlled know-how sits at the intersection of IP and trade controls (see #6), and adoption of open-source PQC libraries and reference implementations raises the usual third-party code diligence and license-compliance questions.

6. Export controls, sanctions, and investment screening

The US BIS Interim Final Rule (September 2024) added quantum computers, components, materials, software, and related technology to the Commerce Control List, with allied coordination. The June 2026 EO directs further harmonization with allied investment-screening and research-security regimes and signals additional controls to follow. Multinationals with quantum-adjacent R&D, joint ventures, university collaborations, or supply chains touching countries of concern should treat this as a live trade-controls file.

7. M&A diligence and cross-border reorganizations

In technology, life-sciences, financial-services, and defense-adjacent deals, cryptographic posture, quantum-related IP, export-control exposure, research-security commitments, and key-personnel concentration are increasingly diligence items. Ownership of underlying IP is far from settled in the industry, and like artificial intelligence, we expect the transactions to precede settlement of IP ownership. Cross-border reorganizations should re-examine intra-group data flows and licensing arrangements with similar considerations.

8. Product counseling and AI/quantum convergence

For developers of AI, quantum-enabled, or “quantum-inspired” products, marketing claims attract regulator attention, both FTC-style deception concerns (“quantum-washing”) and EU AI Act transparency expectations where AI and quantum capabilities are bundled, though this remains a forward-looking issue.

9. Disclosure, board oversight, and securities

The SEC cybersecurity rules require registrants to describe processes for assessing material cyber risk and board oversight of those processes, which extends naturally to cryptographic risk. NIS2 and DORA in the EU and other cybersecurity regulations apply parallel expectations. Boards will likely start to ask for a quantum-readiness briefing.

10. Global investigations and incident response

When an incident is investigated months or years after exfiltration, HNDL is a foreseeable theory of harm. Incident-response playbooks, retention of forensic artifacts, breach-notification analyses, and cross-border evidence-preservation protocols are key to managing the possibility that data exfiltrated today may be decrypted later.

Outlook

The next twelve months are likely to bring implementing rules under the June 2026 US EOs, including FAR amendments and CISA critical-infrastructure guidance; further movement on a final EU Quantum Act and successor measures under the Quantum Europe Strategy; the finalized ENISA ACM v3; and continued BIS and allied trade-control activity. We will continue to track these developments.

This post is a companion to our recent alert on the June 22, 2026, US Executive Orders on quantum innovation and cryptographic security and to our Canada chapter in Global Legal Insights: Quantum Computing 2026. It is also no coincidence that the post authors are in Chicago, which is vying to become a global capital of quantum with significant public and private investment in the region.

Key takeaways

  • Quantum is commercializing. Capital, infrastructure, and enterprise adoption are all accelerating, and rising M&A and investment activity is reshaping the competitive landscape.
  • The risk is present now, not just at “Q-Day.” Under the harvest-now-decrypt-later (HNDL) theory, sensitive data with a long shelf life that is exfiltrated today can be decrypted later.
  • Regulators are setting the pace. NIST’s PQC standards, the June 2026 US Executive Order migration deadlines (2030/2031), and parallel EU and UK efforts are beginning to inform “reasonable security” and “state of the art” benchmarks.
  •  
  • This will be the first of many looks at this issue as we expect quantum technology to be one of the major technical legal themes, particularly given the need for additional computing technology for artificial intelligence.

[1] Illinois Quantum & Microelectronics Park announcements; State of Illinois economic development materials; University of Chicago and P33 quantum ecosystem publications.

[2] https://www.bmwgroup.com/en/news/general/2025/quantum-computing.html

[3] https://fortune.com/2021/01/28/roche-to-use-quantum-computing-for-drug-discovery/

[4] https://www.jpmorganchase.com/about/technology/blog/oqc-jpmc-amd-quantum-ai-platform

Author

Adam Aft helps global companies navigate the complex issues regarding intellectual property, data, and technology in product counseling, technology, and M&A transactions. He leads the Firm's North America Technology Transactions group and co-leads the group globally. Adam regularly advises a range of clients on transformational activities, including the intellectual property, data and data privacy, and technology aspects of mergers and acquisitions, new product and service initiatives, and new trends driving business such as platform development, data monetization, and artificial intelligence.

Author

Author

Bill assists global clients with transformational domestic and international mergers and acquisitions. He also leads Baker McKenzie’s North American corporate knowledge and training development program and has been an Illinois Super Lawyers Rising Star in Mergers and Acquisitions every year since 2012.