
The August 2024 publication of NIST’s first post-quantum cryptography (PQC) standards marks a critical milestone in preparing for quantum-resilient cybersecurity, yet significant gaps persist between technical standardization and practical implementation. This paper examines the policy-practice divide through a comprehensive analysis of federal frameworks (NSM-10, QCCP Act), international coordination efforts, and organizational readiness across sectors. Our research reveals that, although technical standards are mature, implementation faces critical barriers: 89% of federal cyber experts lack dedicated PQC budgets, organizational cryptographic discovery capabilities remain limited, with 43% unable to inventory assets, and estimated migration costs for federal agencies alone reach $7.1 billion through 2035. We analyze coordination mechanisms across the EU, NATO, and Five Eyes alliance, finding the EU’s coordinated 2030 critical infrastructure timeline represents the most comprehensive policy approach, while US federal agencies demonstrate stronger government-industry partnerships. Through synthesis of 30 recent academic sources and economic analysis indicating explosive market growth from $302M to $21B by 2034, we identify five critical implementation gaps: cryptographic asset discovery limitations, workforce expertise shortages, vendor ecosystem maturity delays, interoperability challenges during hybrid deployments, and insufficient automated migration tools. Our analysis provides a novel framework for policy-practice alignment, including phased migration strategies, public-private coordination mechanisms, and economic incentive structures. Key contributions include the identification of optimal timing strategies that balance the costs of premature migration against the urgency of quantum threats, the development of sectoral readiness assessment criteria, and policy recommendations to accelerate practical adoption while maintaining security assurance.

We introduce an initial framework for content traceability in AI-generated media, aligning with the objectives of the EU AI Act. The rapid advancements in generative AI (genAI) necessitate the development of reliable mechanisms for identifying and tracking AI-generated content to ensure transparency, trust and regulatory compliance. To address these challenges, we propose a conceptual infrastructure that facilitates media content registration for AI companies, artists and institutions. It enables provenance tracking and content authentication. Importantly, the proposed system is applicable not only to AI-generated content but also to non-AI-generated media. This dual functionality enhances trust beyond the requirements set forth in the EU AI Act by ensuring the identification of both authentic and synthetic content. The framework incorporates robust hashing techniques, digital signatures, and a database to mitigate the spread of media with uncertain provenance while adhering to regulatory guidelines. A key component of this approach is the adoption of the ISO-standardized International Standard Content Code (ISCC) as a robust hashing method. The ISCC’s decentralized architecture allows for independent implementation without legal constraints, and its adaptability ensures compatibility across various content formats. However, maintaining the flexibility to update hashing algorithms remains essential to address evolving technological advancements and adversarial manipulations.