EU-UK Spotlight: Renewables, trade, and the global supply chain
Quantum computing is an emerging but foreseeable risk for insurers because it may undermine the encryption that protects policyholder, claims and financial data over time.
Regulators in the UK and EU are not yet mandating “quantum‑safe” solutions, but they increasingly expect insurers to show forward‑looking planning and governance around long‑term cyber and resilience risks. Quantum risk is not just a technology issue: it affects data protection, outsourcing and cloud contracts, operational resilience, and board‑level oversight
Insurers should use 2026 to embed proportionate quantum risk awareness into data retention, contracting and enterprise risk management frameworks, rather than waiting for regulatory or operational pressure to escalate.
As insurers move further into 2026 and beyond, emerging technology risks are no longer just theoretical issues for future planning. Increasingly, they are matters that require attention from legal, risk, compliance, and senior management teams today. One such risk is quantum computing, not because it is already widely used, but because of the scale of disruption it may eventually cause. In this article we look at why quantum computing matters for insurers including data protection, operational risk and regulatory/governance risks.
Quantum computing is a new type of computing that works very differently from the computers we use today. Traditional computers process information in a simple on‑off way (using 0s and 1s). Quantum computers use qubits, which can exist in more than one state at the same time. This means they may, in future, be able to solve certain problems far more quickly than current computers.
Why does this matter for insurers? Because many of the digital protections we rely on today, such as encryption used to protect customer data, claims information and financial transactions are based on mathematical problems that quantum computers are expected to solve much faster. Over time, this could weaken the security of systems that insurers depend on every day.
Although large scale quantum computing is still developing, regulators and market participants are increasingly focused on the long term risk it creates now. Decisions insurers make today about data storage, encryption, outsourcing, and operational resilience are being taken with the growing understanding that existing security methods may not last indefinitely.
For insurance legal, compliance and risk teams, the challenge is therefore not to predict exactly when quantum computing will become mainstream, but to show that the organisation is thinking ahead and managing the risk sensibly and proportionately.
The main legal concern linked to quantum computing is its potential impact on the encryption that keeps digital information secure. This encryption underpins:
For insurers, this creates risk in three key areas:
Quantum risk is therefore not just a technology issue. It affects contracts, outsourcing decisions, regulatory compliance, and board oversight.
As awareness of quantum related risk increases, insurers in the UK and EU should keep a close eye on the following areas:
UK and EU data protection laws require insurers to put in place security measures that reflect current risks and available technology. While regulators are not yet requiring “quantum safe” encryption, they are increasingly interested in whether firms are planning ahead in a reasonable way.
For insurers, this affects data retention policies, encryption practices, supplier contracts, and incident response planning. Firms holding large volumes of sensitive or long term data may face particular scrutiny if future risks are not considered.
Quantum computing also highlights weaknesses in long term technology and outsourcing contracts. Many agreements assume today’s security methods will continue indefinitely. Insurers are therefore beginning to review whether contracts:
These issues are especially important for core systems, cloud platforms and claims infrastructure.
As part of 2026 risk planning, insurers may wish to ask:
For insurers, quantum computing represents a slow burning but potentially significant risk. While the technology itself is still evolving, expectations around preparedness, governance and resilience are already taking shape in the UK and EU.
The key challenge in 2026 is to engage with quantum risk early and sensibly, building it into data protection, contracting and governance frameworks now, rather than reacting later under regulatory or operational pressure.
Authored by Karishma Paroha.