WISeKey and OISTE extend post-quantum root of trust to AI agents

WISeKey and OISTE.ORG are expanding their quantum-safe PKI architecture to issue cryptographic identities to AI models, agents and devices.

A large, multi-layered brass and copper cryogenic device stands prominently in a bright, white-walled laboratory surrounded by racks of electronic equipment, workbenches with scientific instruments, and windows.

WISeKey International Holding and the OISTE.ORG Foundation have announced an expansion of their existing Quantum Root Key initiative into a Post-Quantum Cryptography (PQC) Root of Trust architecture designed to assign verifiable cryptographic identities to AI models, autonomous agents, connected devices and human operators. The announcement, made on 25 September 2026, positions the joint initiative as foundational infrastructure for what the partners call the "intelligent internet."

The core proposition is a trust chain running from a post-quantum root certificate authority down through organisations, AI models, AI agents and individual devices to signed transactions. Rather than relying on a model or agent declaring its own identity, downstream systems would cryptographically verify that identity against credentials issued from the OISTE/WISeKey root. The architecture incorporates NIST-standardised PQC algorithms ML-DSA and ML-KEM, and extends into hardware via Hardware Security Modules, Trusted Platform Modules and WISeKey's subsidiary SEALSQ Corp's secure semiconductor elements.

Carlos Moreira, founder and chief executive of WISeKey, said: "AI should not have to be blindly trusted. AI should be cryptographically verifiable. By combining OISTE's global Root of Trust, WISeKey's PKI infrastructure and SEALSQ's secure semiconductor technologies, we believe we can extend digital trust from humans and connected devices to AI models and autonomous agents."

What the architecture covers

Beyond model identity, the release describes several functions the architecture is designed to support. These include model integrity verification through cryptographic hashes of weights and binaries; AI-to-AI authentication before agents exchange data or execute transactions; human-to-AI authorisation certificates governing who may instruct or terminate an agent; and tamper-evident audit trails of signed AI actions. The partners frame this as a shift from "trust me" AI, where users accept a model's claimed identity at face value, to "verify me" AI backed by a traceable certificate chain.

WISeKey also references an emerging HUMAN-AI-T supervisory framework in which a designated AI supervisor, carrying its own independently verifiable identity, could monitor subordinate models while preserving human override capability. The release does not detail how the supervisory AI's own trustworthiness is established beyond the cryptographic identity layer.

Market context and standards alignment

The announcement lands at a commercially sensitive moment for post-quantum cryptography. NIST finalised its first PQC standards in August 2024, and the US Office of Management and Budget has directed federal agencies to begin migration planning. The EU's NIS2 Directive and the forthcoming Cyber Resilience Act are also pushing critical-infrastructure operators to document their cryptographic agility roadmaps. WISeKey's use of ML-DSA and ML-KEM puts it in line with the NIST-approved algorithm set, which is likely to matter for procurement decisions in regulated sectors such as financial services, defence and energy.

The broader AI identity space is attracting growing attention. The EU AI Act's requirements for transparency and traceability of high-risk AI systems create a natural demand for exactly the kind of provenance and audit-trail capabilities WISeKey describes. However, no commercial customers, pilot programmes or certification milestones are named in the release, and performance benchmarks for the PQC platform are absent. The company also did not disclose pricing, deployment timelines or integration partnerships beyond the existing SEALSQ semiconductor relationship.

WISeKey carries listings on both SIX Swiss Exchange and NASDAQ and has reported deploying over 1.6 billion microchips across IoT sectors, giving it a hardware distribution base that could accelerate edge deployment of the PQC root infrastructure. Investors and enterprise buyers will be watching for named customer wins and independent certification of the PQC implementation as indicators that the architecture moves from design to production adoption.