NIST takes identity post quantum. Audit records must follow
Audit records need post-quantum protection for the same reason identity credentials do: both must still be provable on the day quantum computers arrive.

Audit records need post-quantum cryptography for the same reason identity credentials do: both must still be trustworthy on the day a capable quantum computer arrives, not just on the day they are created. In June 2026 NIST released initial working drafts of post-quantum updates to the Personal Identity Verification standards, setting out how the ML-DSA signature algorithm and the ML-KEM key encapsulation mechanism will be used in federal identity credentials. We read the drafts as more than an identity refresh: classical public-key cryptography is entering managed retirement, and every regulated organisation must ask which of its long-lived digital artefacts needs to be believed in the 2030s. Identity is the first front. The evidence layer, the logs and audit trails that prove what systems and people actually did, is the next one.
What did NIST publish in June 2026 and why does it matter?
NIST published initial working drafts that update the Personal Identity Verification standards, the specifications behind US federal workforce credentials, to use post-quantum algorithms. The drafts describe ML-DSA for digital signatures and ML-KEM for key establishment, both finalised in NIST's post-quantum standardisation programme in 2024. Working drafts are not final rules, but the direction is unambiguous.
It matters because PIV is one of the most widely implemented identity frameworks in the world, so when NIST changes how a federal credential is signed, vendors and allied governments adjust their roadmaps. The migration will take years, which is the point: credentials issued today may still be in circulation when the quantum threat matures, and cryptography must be replaced before it fails, not after.
Why do audit records face the same quantum threat as identity credentials?
Because both depend on digital signatures whose security collapses if a capable quantum computer can break the underlying mathematics. For audit records the threat has two halves. The first is the pattern called harvest now, decrypt later, where an adversary collects encrypted material today and waits until quantum capability lets them read it. Logs of what an organisation's AI systems were asked, and what they answered, are exactly the kind of corpus worth harvesting. The second half is forgery. A classically signed audit trail stops being proof the moment signatures of that type can be fabricated, because a forger can rewrite history or let a bad actor repudiate actions that really happened.
The uncomfortable part is timing. An identity credential can be revoked and reissued under a new algorithm. An audit record cannot be re-witnessed. If a regulator or court in 2035 asks what your systems did in 2026, the only evidence available is whatever record was created at the time, protected with whatever cryptography was chosen then. That asymmetry is why we argue the evidence layer deserves quantum-resistant protection from the outset, not as an afterthought scheduled behind the identity migration.
How does the Open Audit Record apply post-quantum signing today?
Every action taken inside our operating system is signed into the Open Audit Record with post-quantum cryptography at the moment it happens. Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on-premise and air-gapped where the environment demands it. The Open Audit Record is the subsystem that turns that operation into evidence: each action is cryptographically signed, the chain is tamper-evident, and the record can be verified offline, with no dependency on us, a network connection, or any third party being available or honest. Signing keys sit under a hardware-held root of trust rather than in software an intruder could lift.
The record is only half of the control. Before a sensitive action runs, our cooperative multi-model consensus substrate requires specialist sovereign models to agree, and voice-biometric gating binds the authorisation to a person rather than a password. All of that, the proposal, the consensus, the authorisation, and the outcome, lands in the same signed record. The NIST drafts apply to credentials the same logic we apply to actions: bind trust to mathematics expected to survive the quantum transition, and anchor it in hardware.
“An audit record you cannot still verify in ten years was never evidence, it was decoration. We sign every action so that the proof outlives the machine, the vendor, and the arrival of quantum computing.”
What should regulated organisations do before the standards are final?
Start a cryptographic inventory now, because the slowest part of any post-quantum migration is discovering where the old cryptography lives. The drafts give security teams a planning anchor, and long-lived evidence deserves the same urgency as identity. In practice that means five things.
- Inventory every place a digital signature protects a long-lived artefact, including audit logs, signed documents, timestamps, and archives, not just certificates and credentials.
- Classify records by how long they must remain provable, because a log that must stand up in 2036 needs quantum-resistant protection in 2026.
- Ask every vendor which NIST-finalised post-quantum algorithms they use today, and reject vague commitments to add them later.
- Prefer systems that are crypto-agile, so signature schemes can be rotated without invalidating the historical chain of evidence.
- Treat AI action logs as regulated evidence rather than operational exhaust, and hold them on infrastructure you control.
We built for this posture from the start. Our operating system offers 87 studios, with ten production-ready at launch and 77 in development, and all of them are built to write to the same post-quantum signed Open Audit Record. The engineering behind that record sits within 104 filed UK patent applications spanning 2,340 claims, filed rather than granted, a foundation rather than a headline. What matters to a compliance officer is simpler: the evidence of what your AI did is created once, at the moment of action, and it either survives the next decade of cryptanalysis or it does not.
Frequently asked questions
What are ML-DSA and ML-KEM?
ML-DSA and ML-KEM are the post-quantum algorithms NIST standardised in 2024, with ML-DSA providing digital signatures and ML-KEM providing key encapsulation for establishing shared secrets. The June 2026 working drafts describe how both will be used in the Personal Identity Verification standards for US federal identity credentials.
Do the NIST PIV drafts apply outside the US federal government?
Not directly, but their influence will reach far beyond it. PIV shapes the products of card manufacturers, middleware vendors, and identity providers worldwide, so the drafts signal the direction of travel for any organisation, including UK and EU regulated bodies, planning a post-quantum migration.
Why can audit logs not simply be re-signed later?
Because re-signing only proves a record existed at the moment of re-signing, not that it was genuine when the action happened. If the original scheme is broken before you migrate, an attacker could have altered the record, and the new signature would faithfully preserve the forgery. Quantum-resistant signing at the moment of action keeps the chain of evidence intact from the start.
Does an air-gapped system still need post-quantum cryptography?
Yes, because its records do not stay sealed forever. Audit extracts are handed to regulators, shared in litigation, and archived for years, and the Open Audit Record is designed to be verifiable offline by third parties, which only means something if the signatures still resist attack on the day someone checks them.
What is MICKAI?
Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs entirely on the customer's own hardware, on-premise and air-gapped, so sensitive data never leaves the organisation. Every action is cryptographically signed into the Open Audit Record, which is post-quantum secure, tamper-evident, and verifiable offline. The operating system offers 87 studios, with ten production-ready at launch and 77 in development, and is supported by 104 filed UK patent applications across 2,340 claims, filed rather than granted.