IoT Gets a Post-Quantum Anchor: WISeKey and OISTE.ORG Build a Root of Trust for Devices and AI Agents
Introduction
The security of the connected world has always rested on a single, quiet assumption: that the keys protecting a device can be trusted, and that the device itself is what it claims to be. For most of the internet's history, that assumption has held because the systems enforcing it were relatively small in number and heavily centralised. The arrival of tens of billions of embedded endpoints, followed by autonomous software agents that act on a device's behalf without a human at the keyboard, is testing that assumption from two directions at once.
On September 25, 2026, WISeKey International Holding Ltd — a Geneva-based company listed on both the SIX Swiss Exchange and Nasdaq that describes itself as a cybersecurity, blockchain, and IoT business — together with the OISTE.ORG Foundation announced a direct answer to that problem. The two organisations are expanding an existing initiative called the Quantum Root Key into a full Post-Quantum Cryptography Root of Trust architecture, one designed explicitly to issue verifiable identities not only to connected devices and human operators, but also to AI models and autonomous agents.
The timing is not accidental. A cryptographically anchored device identity matters more in 2026 than it did in 2020, not only because of the eventual arrival of cryptographically relevant quantum computers, but because the number of entities that need to prove who they are has expanded dramatically. A thermostat, a smart meter, an autonomous procurement agent, and a large language model are all now asked to authenticate themselves to systems they do not own.
Main Content
Why a Root of Trust, and why now
The term "root of trust" comes from the hardware security world. It describes a component whose cryptographic guarantees are taken on faith because verifying them any further would be circular. A secure element, for instance, holds a private key in a tamper-resistant enclosure and performs signing operations internally, so the key never exists in a form an attacker can read. Everything above it — firmware, operating system, applications, cloud services — inherits trust from that anchor.
WISeKey's own framing of the programme traces back to a specific threat. A sufficiently powerful quantum computer, the company argues, would be able to break widely deployed public-key cryptographic systems. RSA and elliptic-curve schemes, which underpin most of the world's secure web, VPN, and device authentication today, are precisely the constructions believed to be vulnerable. Devices with long service lives are the acute problem: an industrial sensor, a smart meter, or a building controller installed today may still be operating in 2040, long after the cryptography that secures it has become trivially breakable by anyone who cares to record encrypted traffic now and decrypt it later.
That harvest-now-decrypt-later dynamic gives the current moment its urgency. An adversary does not need a quantum computer today to start accumulating ciphertext. They only need patience.
The September announcement, however, signals that the partners think the quantum threat is no longer the only one worth designing for. Their stated concern has broadened considerably.
From securing devices to identifying agents
The announcement's framing is notable for the question it foregrounds: how do humans, machines, and other AI systems know that an AI model or AI agent is authentic, authorised, and operating with trusted software, data, and instructions?
This is a departure from classical IoT security thinking. The standard threat model for a connected device assumes the device executes what its owner intends, and that a compromise means an attacker has gained control of the device. With autonomous agents, that assumption breaks. An agent that has been given legitimate credentials and permission to act can be manipulated — through its prompt, its retrieved context, or a poisoned tool result — into taking actions its principal never authorised, while holding entirely valid credentials throughout. Authentication alone does not detect this, because the credential is real.
WISeKey and OISTE propose extending the logic of Public Key Infrastructure, which has authenticated websites, devices, and digital identities for decades, so that it can support machine-verifiable trust for AI systems. Under the described architecture, the joint Root of Trust functions as the cryptographic trust anchor from which identities and credentials are issued to AI models, AI agents, devices, organisations, and authorised human operators.
The result is a proposed chain of trust that the announcement presents explicitly: Post-Quantum Root of Trust, then Organisation, then AI Model, then AI Agent, then Device, then Transaction. Each link in that chain would carry a cryptographically verifiable identity derived from the trusted root. A transaction, in this framing, is not simply authorised by some service that checked a token; it can be traced back through each intervening party to an anchor whose provenance is independently checkable.
What the Root of Trust is intended to support
The partners describe several concrete functions the architecture is meant to enable, and these are the details that determine whether the idea is more than a rebranding.
The first is AI model identity. Under the proposal, models can be issued cryptographic identities, allowing a system to verify which model it is actually communicating with and whether that identity was issued by an authorised organisation. This addresses a problem that has already bitten real deployments: in most current agent frameworks, the model is a name in a configuration file, and a misconfiguration or a substituted endpoint can change what is answering while everything downstream continues to believe it is talking to the intended model.
The second is model integrity and provenance. The announcement states that cryptographic signatures and hashes can help verify that model binaries, model weights, software components, and approved configurations have not been modified since their authorised release. This matters because the supply chain for open-weight models is, for now, largely an act of trust. A checksum published on the same channel as the download proves only that the file you fetched matches the file someone else uploaded.
The third is agent authentication — autonomous agents being able to authenticate themselves before acting. The natural follow-on, which the announcement gestures at, is authorisation scoped to the specific task: an agent issued a credential that permits it to read a shipping schedule should not, on the strength of that same credential, be able to commit a purchase order.
Taken together, these functions describe a system in which trust is not inferred from network position, as it historically was, nor asserted by the party requesting it, as it is when a client declares its own identity. Trust becomes a property that can be checked.
What is genuinely new, and what is not
It would be unfair to present this announcement as though it invented cryptographic device identity. Secure elements, hardware roots of trust, and post-quantum migration plans for connected devices have been commercial products and standards work for years. SEALSQ, for instance, has been building secure-element and onboarding platforms aimed at quantum-resistant IoT deployments, and the post-quantum standardisation work at NIST has been running for long enough to produce actual vetted algorithms rather than theoretical proposals.
What the WISeKey and OISTE announcement contributes is a claim about scope and sequencing. Rather than treating post-quantum cryptography as a device-hardening problem to be solved one product line at a time, the partners position the Root of Trust as a common substrate, and then extend that substrate to entities — models and agents — that had no presence in the original threat model. If an agent is going to act on a device's behalf, the argument goes, then the identity of the agent deserves the same cryptographic guarantees as the device itself.
It is a different approach from the one taken by Semtech's pairing of AirLink routers with the Palo Alto Networks industrial IoT security stack, which secures the network perimeter the devices sit on rather than the identity of the devices themselves.
There is also a governance dimension worth watching. A Root of Trust is only as credible as the process that anchors it, and anchoring infrastructure is precisely the kind of asset that invites concentration. WISeKey has previously described its Quantum Root Key as hardware-based, designed to resist quantum decryption attacks by securing key generation and storage within the device. Extending such a scheme to cover AI systems introduces a question that public key infrastructure has spent decades negotiating: who operates the anchor, who audits it, and what happens to trust when the operator is not the party being protected.
For the wider IoT industry, the practical test will be adoption rather than architecture. The number of connected endpoints already in the field runs into the tens of billions, and the overwhelming majority are cheap, low-power devices with decade-plus service lives and no realistic path to a firmware update. Any post-quantum architecture that requires per-device intervention will not reach them. Architecture that can be inherited passively, or delivered through the same provisioning path a device already uses, has a chance. The proposal's usefulness will be decided by that question and not by the elegance of the trust chain it describes.
Where this fits against regulation
The announcement arrives against a regulatory backdrop that has recently become considerably less theoretical in Europe. The EU Cyber Resilience Act's vulnerability and incident reporting obligations became live on September 11, 2026, requiring manufacturers of products with digital elements — ranging from consumer smart home products to industrial IoT equipment — to report actively exploited vulnerabilities to ENISA, alongside the broader security and support obligations the Act imposes. Recent law-firm briefings have focused on the practical mechanics of those reporting duties.
A post-quantum Root of Trust is not a substitute for any of that. The Cyber Resilience Act is about vulnerability handling and support periods, not about cryptographic agility. But the two trends reinforce each other. Regulators are already asking manufacturers to demonstrate ongoing security competence for the devices they ship. A credible answer to "how will you keep this device secure for the next fifteen years" increasingly includes an answer for "what happens to your cryptography when the primitives underneath it weaken," and the honest answer to that question is migration planning, not optimism.
The combination of regulatory pressure and cryptographic migration is what turns a research-adjacent announcement into something with a commercial half-life. Devices designed today without a path to post-quantum key exchange are devices that will need to be replaced, not patched, once the relevant thresholds are crossed.
Conclusion
WISeKey and OISTE.ORG's expansion of the Quantum Root Key into a post-quantum architecture covering devices, models, agents, and transactions is an ambitious framing of a problem that IoT has been deferring for a decade. The core insight is sound: as connected devices give way to a mix of hardware and autonomous software acting on their behalf, the set of things that need verifiable identity grows, and public key infrastructure is the mechanism already proven to do that job at scale.
Whether the architecture survives contact with the field is a different question. Anchors in hardware are expensive, which is precisely why the multi-billion endpoints that most need quantum resistance are the least able to carry it. The proposal's credibility will rest on whether verification can be made passive and cheap enough to deploy on a three-dollar sensor, and on whether the governance of the anchor itself withstands scrutiny from the parties whose security depends on it.
What the announcement does establish is that the conversation has moved. The question is no longer whether connected devices will need to be cryptographically anchored against a future quantum threat. It is who anchors them, what else gets anchored alongside them, and how much of the existing installed base will still be running when the threat arrives.
Images

![]()
![]()
References
- WISeKey International Holding Ltd, "WISeKey and OISTE.ORG Expand Post-Quantum Root of Trust to Secure the Quantum and AI Era," press release, September 25, 2026. https://www.wisekey.com/press/wisekey-and-oiste-org-expand-post-quantum-root-of-trust-to-secure-the-quantum-and-ai-era
- WISeKey International Holding Ltd, "WISeKey and OISTE.ORG Expand Post-Quantum Root of Trust to Secure the Quantum and AI Era," via Yahoo Finance, September 25, 2026. https://uk.finance.yahoo.com/news/wisekey-oiste-org-expand-post-050000356.html
- Simply Wall St, "WISeKey International Holding," company analysis describing the Quantum Root Key as hardware-based root-of-trust technology for resisting quantum decryption attacks. https://simplywall.st/stocks/us/semiconductors/nasdaq-wkey/wisekey-international-holding
- Travers Smith, "The EU Cyber Resilience Act's vulnerability and incident reporting requirements are now live," September 11, 2026. https://www.traverssmith.com/knowledge/knowledge-container/the-eu-cyber-residence-acts-vulnerability-and-incident-reporting-requirements-are-now-live/
- Kirkland & Ellis, "The EU Cyber Resilience Act: Preparing for the New Reporting Requirements," September 2026. https://www.kirkland.com/publications/kirkland-alert/2026/09/the-eu-cyber-resilience-act
- Wikipedia Commons, "RouterBOARD RB14e, close-up," and "Circuit Board," retrieved September 26, 2026.