In February 2022, a team at the University of Birmingham published a result in Nature that almost no privacy officer read. Using a quantum gravity gradiometer, an instrument that measures the difference in gravitational pull between two clouds of cold atoms in free fall, they located a utility tunnel roughly two meters across, buried about half a meter beneath a road. Nothing was excavated. Nothing was transmitted. The instrument sat on the surface and inferred the void below from a difference in weight that no other field-deployable device can reliably resolve.
The result was reported as a milestone for civil engineering, and it is one. Buried services, sinkholes, and archaeological features are expensive to find and expensive to miss. Now ask a different question. If an instrument can characterize what sits under a road without emitting anything and without touching it, which of your organization’s policies governs pointing that instrument at a building?
In most compliance programs, the honest answer isn’t any of them by name. That’s the problem this article is about, and it is a narrower and more tractable problem than the surveillance-dystopia framing that usually surrounds quantum sensing. Quantum sensors are not creating a new category of privacy harm. They are walking through a gap that already exists in how privacy law is drafted, and the same gap that commodity radio hardware walked through five years earlier. We can describe that gap precisely, and once it is described, a governance function can close it locally without waiting for a legislature.
What these instruments actually measure
Four families matter for governance purposes, and the differences between them determine which of your policies should apply.
Magnetometers. An optically pumped magnetometer is a small cell of alkali vapor whose optical response shifts in proportion to the magnetic field passing through it. Nitrogen-vacancy diamond sensors work on a different mechanism and serve a similar role. Commercial units reach sensitivities in the tens of femtotesla per root hertz. For scale, Earth’s magnetic field is around 50 microtesla, roughly a billion times larger, and the magnetic field of a beating heart measured at the chest surface is around 50 picotesla. Brain signals measured at the scalp are hundreds of times weaker again.
Those numbers are why magnetocardiography works and why through-the-wall cardiac monitoring is much harder than the popular coverage suggests. A dipole field falls off with the cube of distance, so doubling the standoff cuts the signal by a factor of eight. The honest position is that a magnetometer sensitive enough to read a heartbeat across a room would also be reading the elevator motor, the air handling unit, and every laptop on the floor, all of them far louder. Sensitivity is real. Selectivity at distance is the engineering problem, and it is mostly a problem of shielding, gradiometry, and signal processing rather than raw sensor performance.
Gravimeters and gradiometers. Atom interferometers drop or launch cold atoms and read the phase difference accumulated under gravity. A gradiometer runs two such measurements at different heights and subtracts them, which cancels the vibration common to both and leaves the local mass distribution. These instruments detect voids, dense objects, and fluid movement below the surface. They emit nothing at all, which is exactly why they fall outside statutes written around transmission and interception.
Radio-frequency receivers. A Rydberg atom sensor uses atoms excited into states with very high principal quantum numbers, which gives them enormous electric dipole moments and makes them responsive to radio-frequency fields across a wide band. One physically small device can cover a spectrum that would otherwise need a rack of tuned antennas, and its response is referenced to atomic constants rather than to a calibration table. The governance-relevant property is bandwidth: a receiver that covers everything picks up everything, including unintended emissions from equipment that was never meant to transmit.
Quantum illumination and quantum radar. In 2020, a group at IST Austria demonstrated microwave quantum illumination, using entangled photon pairs to detect a low-reflectivity object at room temperature. The demonstrated advantage over the best classical protocol exists in a narrow regime of very low signal power, and entanglement degrades quickly in any realistic environment. Claims that quantum radar defeats stealth aircraft have circulated for years without published evidence. Treat operational quantum radar as unproven, and treat vendor claims about it as a procurement red flag rather than a capability to plan around.
For a fuller technical treatment of these families, PostQuantum.com maintains an introduction and taxonomy of quantum sensing.
Why the rulebook does not name them
Privacy law is keyed to two things: named modalities and identification purposes. Quantum sensors fit neither cleanly.
Take the modality side first. In Kyllo v. United States, decided in 2001, the Supreme Court held that pointing a thermal imager at a home was a search requiring a warrant, reasoning that the device was not in general public use and revealed details of the interior. The holding is powerful and it is also tightly bound to the home. Step outside the curtilage and its force drops sharply. A Tenth Circuit panel reviewing law enforcement use of a handheld Doppler radar capable of detecting movement and breathing through walls (United States v. Denson, 775 F.3d 1214 (10th Cir. 2014)) flagged serious constitutional concerns, while resolving the case on independent grounds. Deployment had preceded the judicial commentary by some years: courts rule on a capability after agencies have already fielded it.
State biometric statutes are narrower still. The Illinois Biometric Information Privacy Act, usually called BIPA, defines biometric identifiers as a closed list: retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry. A cardiac magnetic signature is not on that list. Neither is a gait signature derived from floor vibration. The statute is one of the strictest biometric regimes in the United States, and a heartbeat measured at three meters falls outside it.
Now the identification side. The EU General Data Protection Regulation, or GDPR, treats biometric data as a special category only where it is processed for the purpose of uniquely identifying a natural person. A magnetic time series recorded in an occupied room is personal data if it relates to an identified or identifiable person, and it may be nothing at all if it does not. The trigger is your documented purpose and the practical possibility of attribution, not the physics of the sensor. California’s approach is broader in one useful respect, since its definition of biometric information reaches sleep, health, and exercise data that contain identifying information, but it remains anchored to identification.
Communications law does not help either. The US Electronic Communications Privacy Act governs the interception of the contents of communications. Detecting an unintended electromagnetic emanation from a device is not interception of contents in the ordinary sense, which is precisely why emanation security has always been an engineering discipline rather than a legal one.
Export control is the one regime that already touches these instruments directly. Magnetometers and gravity gradiometers above certain performance thresholds have long been controlled under Category 6 of the US Commerce Control List, and a 2024 Commerce rule added quantum-specific classifications. That control surface is about strategic capability rather than privacy, but it gives a compliance function something concrete to attach to during procurement.
Put the pieces together and the shape of the gap is clear. Statutes enumerate cameras, microphones, wiretaps, and a short list of biometric identifiers. Quantum sensors produce physical measurements that appear on no such list and that are frequently not identifying at the moment of collection. They become identifying downstream, after processing and after joining against something else.
Quantum sensing is not the first through this gap
The gap is not new, and quantum hardware is not what opened it. Commodity Wi-Fi radios already compute channel state information, the per-subcarrier amplitude and phase measurements a receiver uses to equalize a link. Those measurements change when a body moves through the propagation path. Published research has used them for presence detection, coarse localization, and respiration monitoring, through interior walls, on hardware that costs tens of dollars. IEEE 802.11bf, which formalizes sensing as a WLAN function, was approved in 2024, and vendors are now working it into shipping firmware.
Millimeter-wave automotive radar tells a similar story. Chips designed for parking assistance have been repurposed for vital-sign monitoring and occupancy sensing, and they are now appearing in consumer devices.
The parallel matters for two reasons. It sets expectations honestly, because the through-wall capability your general counsel is worried about mostly exists already and mostly doesn’t require quantum anything. And it tells us what happens next, because the regulatory response to Wi-Fi sensing has been close to silent. A governance program that waits for a quantum-specific statute will wait a long time, and will spend that time not covering a class of instruments that is already installed in its own facilities under an equipment monitoring budget line.
Where the law already reaches
Three developments cut the other way, and they share a structure worth copying.
The EU AI Act prohibits inferring emotions from biometric data in workplace and educational settings, with narrow exceptions for safety and medical purposes, and restricts real-time remote biometric identification in publicly accessible spaces. The prohibitions became applicable in February 2025. Critically, the drafting is technology-neutral. It regulates the inference, not the instrument. A magnetometer array feeding a stress-classification model in a factory is inside that prohibition regardless of how exotic the sensor is.
Neural data legislation follows the same pattern. Chile amended its constitution in 2021 under Law 21,383 to protect mental integrity against technological intrusion. California added neural data to the sensitive personal information category under its privacy statute in 2024, and Colorado amended its own act to cover biological and neural data in the same year. These instruments are drafted around a class of signal rather than around a device.
GDPR’s purpose test, read carefully, belongs in the same group. It is inference-keyed rather than modality-keyed, which is why it ages better than an enumerated list.
The pattern is the answer. Where regulators have written modality-neutral rules about what may be inferred, quantum sensing is already covered. Where they have written device lists, it is not, and it never will be, because device lists can’t be maintained at the speed instruments are invented.
The control point is inference, not collection
Here is a worked case, assembled from the shape of real deployments rather than from any single one.
A pharmaceutical manufacturer installs an array of optically pumped magnetometers across a production hall. The stated purpose is motor and pump condition monitoring: bearing wear and winding faults show up in magnetic emissions well before they show up in vibration. Procurement classifies the purchase as industrial instrumentation. No personal data assessment is triggered, and on the facts as stated, none is required.
Three things then happen over eighteen months, none of them a decision anybody would recognize as a privacy decision.
The integrator moves several sensor heads closer to the line for better signal, which puts them within a meter or two of standing operators. The sampling configuration is left at the vendor default, which covers the sub-100 hertz band, and that band carries cardiac and respiratory signal along with everything mechanical. And the vendor ships an analytics update adding occupancy-aware anomaly detection, trained in part on when the hall is staffed.
At no point did anyone acquire a biometric device. At the end, the plant holds a continuous physiological record of identifiable individuals, because shift rosters and badge logs make attribution trivial, and it holds that record without a lawful basis, without an impact assessment, and without anyone in the compliance function knowing it exists.
The lesson generalizes into a test. Ask whether the pipeline, as configured, produces or enables an output attributable to an identified or identifiable person. Three factors decide it:
- Resolution against standoff distance. What is the smallest human-scale signal this configuration can resolve at the distance it is actually mounted? Not in the datasheet’s best case. In this room.
- Correlation surface. What other data can these measurements be joined against, and who holds the join key? Badge systems, shift rosters, and camera timestamps convert anonymous physical data into attributed physical data in a single query.
- Retention of raw traces. Aggregated equipment health metrics carry little inference risk. Retained raw waveforms carry all of it, because any future model can be run against them.
An inventory that records capability
Most sensor inventories record the label on the box: what the device is for, who owns it, where it sits. Almost none record what it can resolve, and vendors have no commercial incentive to volunteer that information. Closing this gap is the single highest-value change available to a governance function this year, and it costs nothing but the discipline of asking five questions per instrument.
- What physical quantity does it measure, at what sensitivity, at what standoff distance as installed?
- What is the smallest human-scale signal this configuration could resolve, if someone tried?
- What data can these measurements be joined against, and who controls that join?
- Are raw traces retained, in what form, and for how long?
- What does the vendor’s analytics do with the data, where does it run, and what happens when the model is updated?
The output of those questions is a capability envelope: what the deployment can resolve, at what range, in what frequency band. Record that alongside the stated purpose. When the two drift apart, as they did in the case above, you’ll see it.
Controls that hold up
Once the envelope is documented, the control set is unremarkable, which is the point.
Filter at the edge. The strongest privacy-by-design control available for magnetic and vibration sensing is a bandwidth restriction implemented in the sensor head, before any data is stored. Equipment health signatures and human physiological signals occupy largely different bands. Where the application does not need the physiological band, filter it out in hardware or firmware and document the filter. A control that removes the data is auditable in a way that a policy forbidding its use is not.
Site deliberately. Standoff distance is a control. Mounting decisions made for signal quality quietly change the privacy posture of a deployment, and they are made by integrators who have never seen the impact assessment.
Separate the join keys. Where raw sensor data must be retained, hold it under different access controls from badge logs, rosters, and video. Attribution should require a decision by a named person, logged.
Log analytics runs. Every model executed against retained sensor data, with the purpose and the requester recorded. Model updates from a vendor are a change of purpose until proven otherwise.
Write purpose into the deployment record. Not the procurement record. The deployment record, held where the operations team can see it, so that the next reconfiguration has a stated purpose to be checked against.
Procurement questions worth asking
Contract language does work here that policy cannot, because it reaches the party that knows the capability.
Ask the supplier to state the sensitivity and bandwidth of the delivered configuration, not the product family. Ask for a written statement of the export control classification number under which the item ships, which is both a compliance requirement and a fast proxy for how capable the device actually is. Require notification before any analytics or firmware update that changes what the system infers. Require disclosure of where vendor-side processing occurs. And require a warranty that the delivered system does not perform biometric or emotion inference, with the definitions drawn from the AI Act rather than from marketing copy.
A supplier who can’t answer the first question is usually reselling hardware it doesn’t understand, which is grounds to disqualify the bid.
What to do this quarter
Four steps, in order, none of which requires a physics team.
Find the instruments you already have. Search asset registers for magnetometers, vibration and acoustic arrays, millimeter-wave radar, and any Wi-Fi infrastructure with sensing features enabled. Most organizations find more than they expect, and almost all of it was bought as facilities equipment.
Record the capability envelope for anything installed within a few meters of occupied space, using the five questions above.
Run one impact assessment on the deployment with the widest envelope. Under GDPR, a data protection impact assessment is the formal analysis required before high-risk processing, and the exercise is valuable even in jurisdictions that do not mandate it, because it forces the purpose and the capability onto the same page.
Add the capability-envelope questions to the standard procurement questionnaire, so the next sensor arrives already classified.
Where the skills gap sits
Nothing above is exotic compliance work. It’s ordinary classification, applied to a class of device that the compliance function has never been asked to classify, using a small amount of physics that determines the answer. Whether a magnetometer at four meters can resolve a cardiac signal isn’t a legal question. It decides the legal question, and someone has to be able to answer it.
That is the practical shape of the quantum sensing problem for governance teams. Not a coming wave of mind-reading devices, but a steady arrival of instruments whose capability is invisible on a purchase order and whose regulatory status depends on a number nobody in the approval chain can read.
We built our training around exactly that kind of gap: enough physics to ask the right question of a vendor, enough governance structure to record the answer where it will be found again. If your program is being asked about quantum sensing and the honest answer so far has been that nobody knows, Quantum Academy is where to start closing it.