The convergence of artificial intelligence and post-quantum cryptography has moved from research labs to the boardroom, and it now affects how customer support teams handle data, security, and AI-driven tools. On November 2nd, security leaders and executives will gather at SANS Raleigh to address this dual challenge. For customer support professionals, the stakes are practical: the AI systems you use daily depend on encryption that quantum computers may eventually break, and the governance gaps around AI adoption could expose customer data to legal and reputational damage.
The AI governance gap hits customer operations
AI adoption in customer support has accelerated sharply, bringing new risks: algorithmic bias, data poisoning, model theft, hallucination, and unintended autonomous actions. A chatbot that hallucinates a refund policy or a sentiment analysis tool that misclassifies frustrated customers are not minor glitches - they are liability events. Boards can no longer delegate AI oversight to a single CTO or data science team. Effective governance requires clear policy frameworks, accountability structures, and monitoring mechanisms that span the entire lifecycle of AI systems, from data acquisition and model training to deployment, auditing, and decommissioning.
Without formal governance, organizations expose themselves to legal liability, reputational damage, and operational disruption. The board must ask pointed questions: Who owns AI risk? What are our ethical boundaries? How do we ensure transparency and explainability? And how do we measure the return on AI investment against its inherent risks? For customer support leaders, the practical question is simpler: do you know which AI tools your team uses, what data they consume, and who is accountable when they fail?
The quantum clock is ticking
The quantum computing timeline is accelerating. While fully fault-tolerant quantum computers may be years away, the threat of "harvest now, decrypt later" is real. Adversaries are already collecting encrypted data, waiting for the day they can break RSA, ECC, and other public-key algorithms. The National Institute of Standards and Technology has finalized its post-quantum cryptography standards, but migration is a multi-year, complex process involving hardware, software, protocols, and third-party ecosystems.
Boards must treat PQC migration as a strategic project with clear milestones, budget allocations, and risk assessments - not as an eventual patch. Every system that relies on asymmetric cryptography, from TLS certificates to digital signatures to VPNs, must be inventoried and transitioned. That includes the infrastructure behind customer support platforms, CRM systems, and communication channels that handle sensitive customer information daily.
Why AI and PQC are two sides of the same coin
The intersection of AI and PQC creates a perfect storm. AI systems themselves rely heavily on encryption for data protection, model integrity, and secure communication. If those cryptographic foundations are compromised by quantum attacks, AI models can be manipulated or exfiltrated, leading to cascading failures. Moreover, AI can be used to accelerate the discovery of cryptographic vulnerabilities or to assist in quantum-resistant algorithm development. Boards must therefore view AI and PQC as two sides of the same resilience coin.
Regulators, auditors, and stakeholders are beginning to demand evidence of proactive management in both areas. Frameworks like the NIST AI Risk Management Framework and the Cybersecurity Maturity Model Certification are becoming baseline expectations, not optional best practices. For customer support operations, this means the tools you rely on today may need significant re-architecture in the coming years - and the planning should start now, not after a breach.
The practical path forward
This is not about waiting for perfect solutions. It is about building governance structures that are agile enough to adapt to evolving threats and technologies. Key steps include establishing an AI ethics and risk committee reporting directly to the board, conducting a full cryptographic inventory and creating a migration roadmap, and investing in cryptographic agility - the ability to swap algorithms quickly without redesigning entire systems. Organizations should also engage with industry consortia and government partnerships to stay ahead of regulatory changes, and embed security requirements into every AI procurement and development contract from day one.
For customer support teams specifically, this means asking vendors hard questions about their AI models and encryption standards before signing contracts. It means documenting which AI tools handle customer data and how that data is protected. And it means building skills now: understanding how AI for Customer Support works under the hood, not just how to use the interface. For supervisors managing AI-driven operations, the AI Learning Path for Call Center Supervisors offers a structured way to understand these systems before they become compliance liabilities.
Why this matters for customer support professionals
Customer support is where AI risk becomes visible. When a model fails, a customer sees it. When encryption fails, a customer's data is exposed. The SANS Raleigh session on November 2nd will move beyond theory and provide actionable frameworks for board-level reporting, risk quantification, and implementation roadmaps. Attendees will leave with templates, checklists, and strategic questions to bring directly to their own boardrooms. Whether you are a CISO, a CTO, a compliance officer, or a board advisor, this is the forum to align your AI and post-quantum strategies with corporate governance expectations.
The time to act is now - before the quantum clock strikes and before AI governance gaps become public liabilities. For customer support professionals, the takeaway is concrete: understand which AI tools your team uses, demand transparency from vendors about their security architecture, and build the governance skills that will protect both your customers and your career. Don't let your organization be the cautionary tale.
Your membership also unlocks: