Banking Law And Hybrid Classical-Quantum Finance Systems Spain .
Banking Law and Hybrid Classical–Quantum Finance Systems in Spain
1. Introduction
Hybrid classical–quantum finance systems refer to financial systems in which conventional classical computing infrastructure—servers, databases, algorithms, cloud systems and traditional cryptography—is combined with quantum computing or quantum-safe technologies.
Spain does not currently have a separate banking statute called a “Hybrid Classical–Quantum Finance Act.” Instead, such systems would operate within the existing framework of Spanish banking law, EU financial-services regulation, cybersecurity rules, data-protection law, consumer protection, payment law and securities regulation.
This distinction is important: quantum computing is an emerging technological capability, while the legal obligations of a Spanish bank already arise from the regulated financial activity being performed.
The Banco de España has specifically examined quantum computing's opportunities and risks for finance, including the threat that sufficiently powerful quantum computers could undermine some existing cryptographic systems.
2. Meaning of a Hybrid Classical–Quantum Finance System
A hybrid system may operate approximately as follows:
Traditional banking infrastructure
→ customer accounts
→ payment systems
→ databases
→ conventional risk engines
→ classical cybersecurity
combined with:
Quantum component
→ quantum optimisation
→ quantum-assisted portfolio analysis
→ quantum risk modelling
→ quantum machine learning
→ quantum-resistant cryptography
The quantum computer does not necessarily replace the ordinary banking system.
Instead, it may function as a specialised computational component.
Example
A Spanish bank could use:
- classical computers for customer-account management;
- classical databases for transaction records;
- quantum processors for optimisation of investment portfolios;
- classical systems for execution of trades;
- post-quantum cryptography for protecting communications.
Therefore, the system is hybrid rather than purely quantum.
3. Legal Position in Spain
Spanish financial regulation is strongly integrated with EU law.
Important institutions include:
| Institution | Main function |
|---|---|
| Banco de España | Banking supervision and financial stability |
| CNMV | Securities and investment-market supervision |
| European Central Bank | Banking supervision within the Single Supervisory Mechanism |
| European Banking Authority | EU banking regulatory standards |
| European Commission | EU financial and digital legislation |
| AEPD | Data protection |
Spain's Law 6/2023 on Securities Markets and Investment Services regulates financial instruments, investment services, trading systems, clearing and settlement, and supervision by the CNMV. It also expressly accommodates technological systems based on distributed-ledger technology.
The important legal principle is therefore:
The use of quantum technology does not remove a bank's existing regulatory obligations.
4. Classical Computing + Quantum Computing
A hybrid financial architecture can be divided into four layers.
Layer 1 – Classical banking infrastructure
This includes:
- core banking;
- customer accounts;
- payment processing;
- ATMs;
- databases;
- conventional servers;
- loan-management systems.
Layer 2 – Quantum processing
Possible applications include:
- portfolio optimisation;
- derivatives pricing;
- fraud-pattern analysis;
- credit-risk modelling;
- liquidity optimisation;
- stress testing.
Layer 3 – Cybersecurity
This becomes particularly important because quantum computing may threaten some currently used public-key cryptographic techniques.
Banco de España's 2024 study specifically identifies the implications of quantum computing for financial-sector cryptography and discusses the development of cryptographic resilience.
Layer 4 – Regulatory controls
The institution must still satisfy:
- capital requirements;
- governance requirements;
- cybersecurity requirements;
- operational resilience;
- consumer protection;
- AML/CFT requirements;
- data protection;
- auditability;
- record keeping.
5. DORA and Quantum Financial Systems
One of the most important modern regulatory frameworks is the Digital Operational Resilience Act (DORA).
DORA entered into force in 2023 and has applied from 17 January 2025. Its purpose is to strengthen the digital operational resilience of financial entities and regulate risks arising from ICT services and third-party technology providers.
This is highly relevant to quantum finance.
Suppose a Spanish bank obtains quantum-computing capacity from an external technology provider.
The bank cannot simply argue:
“The quantum calculation was performed by our technology supplier.”
The bank remains subject to applicable operational-risk and ICT governance requirements.
Quantum-related DORA concerns
Potential issues include:
- quantum-computing provider failure;
- incorrect quantum calculations;
- loss of data;
- cyberattack;
- migration failure;
- dependency on a single technology provider;
- insufficient auditability;
- inadequate disaster recovery;
- incompatibility between quantum and classical systems.
6. Quantum Cybersecurity
This is arguably one of the most important legal issues.
Traditional banking systems rely heavily upon cryptographic protection.
A sufficiently capable quantum computer could threaten some existing cryptographic mechanisms.
Consequently, banks may need to adopt:
Post-quantum cryptography
This involves cryptographic algorithms designed to resist attacks from quantum computers.
A hybrid Spanish banking system could therefore operate:
Classical banking system
Quantum-resistant encryption
Quantum computing for selected financial calculations
This creates a form of quantum-resilient banking architecture.
Banco de España has specifically identified cryptographic resilience as an important financial-sector issue arising from quantum computing.
7. Quantum Risk Management
Quantum computing could potentially change the way banks calculate risk.
For example, a bank could theoretically use quantum-assisted algorithms for:
- credit-risk simulations;
- market-risk calculations;
- liquidity modelling;
- portfolio optimisation;
- stress testing.
But legally, the bank cannot simply rely upon a technologically sophisticated model.
It must be able to demonstrate:
- model governance;
- reliability;
- validation;
- explainability where required;
- appropriate human oversight;
- accurate records;
- regulatory compliance.
This creates an important legal principle:
Technological complexity does not reduce the bank's legal responsibility.
8. Consumer Protection
Quantum technology may be invisible to consumers.
For example, a customer might receive a mortgage whose interest rate has been determined using a quantum-assisted risk model.
The customer still benefits from existing consumer-protection law.
The bank cannot argue:
“The decision was produced by a quantum algorithm, therefore ordinary consumer law does not apply.”
Spanish and EU case law demonstrates the importance courts attach to transparency and fairness in banking contracts.
9. Case Law
Because direct Spanish judicial decisions specifically concerning quantum-computing banking systems are presently very limited, the most useful authorities are existing Spanish/EU banking cases establishing principles that would apply when quantum technology is introduced into banking.
Below are 8 important cases.
Case 1 – Banco Español de Crédito v Calderón Camino
C-618/10, 14 June 2012
This case concerned an unfair term in a consumer credit agreement.
The CJEU held that where a national court identifies an unfair contractual term, it cannot simply rewrite the term to preserve the contract; the unfair term must generally be left unapplied.
Relevance to quantum finance
Suppose a quantum-assisted system automatically generates loan terms.
The technological origin of the term does not change consumer-protection obligations.
The bank remains responsible for ensuring that contractual terms comply with applicable law.
Principle
Automated financial contracting remains subject to consumer law.
Case 2 – Aziz v Caixa d'Estalvis de Catalunya, Tarragona i Manresa
C-415/11, 14 March 2013
Mohamed Aziz concerned Spanish mortgage enforcement and unfair contractual terms.
The CJEU found that the Spanish procedural framework did not adequately allow consumers to obtain effective judicial protection against potentially unfair mortgage terms.
Relevance
A hybrid quantum system could be used for:
- mortgage underwriting;
- valuation;
- credit scoring;
- default prediction.
But automated or quantum-assisted decision-making cannot eliminate effective legal remedies.
Principle
Technological automation must remain compatible with effective judicial protection.
Case 3 – Bankia v Marí Merino
C-109/17, 19 September 2018
The case concerned mortgage enforcement and unfair commercial practices.
The CJEU considered whether Spanish procedural mechanisms provided adequate and effective means of combating unfair commercial practices in mortgage lending.
Relevance
If quantum-assisted technology is used to determine:
- property values;
- creditworthiness;
- mortgage risk;
- auction values,
the technology must operate within consumer-protection requirements.
Principle
Financial technology cannot circumvent substantive consumer protection through procedural automation.
Case 4 – Gómez del Moral Guasch v Bankia
C-125/18, 3 March 2020
This case concerned a mortgage with an interest rate linked to the Spanish savings-bank reference index.
The CJEU held that the relevant contractual term was subject to the Unfair Terms Directive and that national courts had to examine whether it was sufficiently clear and intelligible.
Quantum-finance relevance
Imagine a bank uses a sophisticated quantum model to determine a variable interest rate.
The bank cannot merely say:
“The model is mathematically too complex for the customer to understand.”
The underlying contractual arrangement must still satisfy applicable transparency requirements.
Principle
Technological or mathematical complexity cannot automatically excuse inadequate contractual transparency.
Case 5 – Caixabank, C-484/21
Judgment of 25 April 2024
This case concerned unfair terms in a mortgage agreement and limitation periods for recovering amounts paid under an unfair term.
The CJEU examined when the limitation period could begin in circumstances involving judicial findings concerning unfair contractual terms.
Relevance
Quantum-enabled financial systems will generate large amounts of:
- transaction data;
- model outputs;
- automated decisions;
- customer records.
Banks therefore need reliable records capable of demonstrating what happened and when.
Principle
Digital sophistication does not eliminate legal obligations concerning restitution, limitation and evidentiary records.
Case 6 – Bankia v Marí Merino and others
C-109/17
This case is particularly relevant to automated financial valuation because the dispute involved revaluation of immovable property before mortgage auction.
Quantum relevance
A future quantum-assisted valuation engine might generate property valuations more rapidly or use complex optimisation.
However:
quantum-generated valuation ≠ legally unquestionable valuation.
The affected party must still have access to legally appropriate remedies and procedures.
Case 7 – Banco Santander v ECB
T-610/24, with appeal C-560/26 P pending
This is a contemporary banking-supervision dispute involving Banco Santander and the ECB. As of September 2026, the ECB has appealed concerning the General Court's treatment of whether a contested email produced legal effects.
Relevance
The case illustrates a broader issue important for technology-driven banking:
Which supervisory communications or technological actions produce legally relevant effects?
In a hybrid quantum banking environment, this could become significant where:
- automated supervisory systems are used;
- algorithmic risk notifications are issued;
- model outputs trigger regulatory action;
- banks challenge supervisory decisions.
Principle
The legal effects of supervisory actions remain a matter of administrative and banking law even where digital technology is involved.
Status: the 2026 appeal means the matter should not be treated as finally settled on the appealed issue.
Case 8 – Banco Español de Crédito and the Automated-Banking Principle
The significance of C-618/10 extends beyond traditional paper contracts.
The case demonstrates an important principle for modern automated banking:
A bank's technological process cannot displace mandatory legal rules protecting consumers.
The more automated the system becomes, the more important it becomes to ensure that legal controls are built into the architecture.
10. Spanish Securities Law and Quantum Finance
Spain's Law 6/2023 on Securities Markets and Investment Services is especially relevant to quantum-assisted investment systems.
The law regulates:
- financial instruments;
- investment services;
- trading;
- clearing;
- settlement;
- investment firms;
- data-service providers;
- supervision and sanctions.
It also contains provisions concerning systems using distributed-ledger technology.
Therefore, a quantum-assisted trading platform would still need to satisfy the relevant securities-market rules.
Example
Suppose an investment firm uses a quantum algorithm to optimise trading.
The fact that the algorithm is quantum-assisted does not exempt the firm from:
- market-conduct rules;
- investor protection;
- organisational requirements;
- record keeping;
- supervision;
- applicable prudential requirements.
11. Hybrid Quantum Lending
A possible future Spanish lending system could work like this:
Customer application
↓
Classical database
↓
AI/credit analysis
↓
Quantum optimisation
↓
Risk score
↓
Human/compliance review
↓
Loan approval
This creates several legal questions.
Question 1 – Who is responsible?
Normally, the regulated financial institution remains responsible for its activities.
Question 2 – Can the customer challenge the decision?
Applicable consumer, data-protection and financial-services remedies remain relevant.
Question 3 – Can the bank use opaque quantum calculations?
The bank would need to comply with applicable transparency, governance and risk-management requirements.
Question 4 – What happens if the quantum provider fails?
Operational-resilience and ICT-risk controls become relevant.
12. Quantum Fraud Detection
Quantum computing could potentially be used for advanced pattern analysis.
For example:
10 million transactions
↓
classical preprocessing
↓
quantum optimisation/analysis
↓
potentially suspicious transaction patterns
↓
human/compliance investigation
This could support:
- fraud detection;
- AML monitoring;
- transaction monitoring;
- anomaly detection.
However, the system should not be treated as infallible.
A quantum-generated result is still a model output, not automatically proof of wrongdoing.
13. Data Protection
Financial institutions process extremely large amounts of personal data.
A quantum system could potentially process:
- income information;
- transaction history;
- credit information;
- investment behaviour;
- customer profiles.
Therefore, data-protection requirements remain relevant.
A hybrid architecture should incorporate:
- data minimisation;
- purpose limitation;
- access controls;
- secure storage;
- appropriate retention;
- security safeguards;
- lawful processing.
14. Algorithmic Accountability
Quantum algorithms may be considerably more complicated than traditional algorithms.
This creates an accountability problem.
Suppose:
Quantum model → rejects mortgage application.
The customer may ask:
“Why was my application rejected?”
The legal question is not simply whether the computer produced the answer.
The bank should have appropriate governance explaining:
- what data was used;
- what decision process was followed;
- what risk factors mattered;
- whether human review occurred;
- whether the decision complied with applicable law.
15. Quantum Finance and Financial Stability
Quantum computing could eventually affect systemic financial risk.
If many banks depend upon the same quantum infrastructure, a common technological failure could affect multiple institutions simultaneously.
This creates concentration risk.
Example
Bank A → Quantum Provider X
Bank B → Quantum Provider X
Bank C → Quantum Provider X
Bank D → Quantum Provider X
If Provider X experiences a major failure:
A + B + C + D → simultaneous disruption
This makes third-party technology governance particularly important.
DORA's operational-resilience framework is therefore highly relevant to this emerging model.
16. Classical–Quantum Hybrid vs Pure Quantum Finance
| Issue | Classical finance | Hybrid classical–quantum finance | Pure quantum concept |
|---|---|---|---|
| Core banking | Classical | Classical | Quantum theoretically |
| Data storage | Classical | Mostly classical | Quantum/classical |
| Risk calculation | Classical | Classical + quantum | Quantum |
| Cybersecurity | Conventional cryptography | Post-quantum migration possible | Quantum-safe required |
| Regulation | Existing financial law | Existing financial law + technology controls | Future regulatory adaptation |
| Consumer protection | Applicable | Applicable | Applicable |
| DORA | Applicable | Highly relevant | Highly relevant |
| Human oversight | Important | Very important | Essential |
| Legal responsibility | Bank/regulated entity | Bank/regulated entity | Bank/regulated entity |
17. Major Legal Risks
1. Model risk
A quantum algorithm may produce incorrect or unsuitable outputs.
2. Cybersecurity risk
Existing cryptographic infrastructure may become vulnerable to future quantum attacks.
3. Third-party risk
Banks may depend upon specialist quantum-computing providers.
4. Explainability risk
Quantum calculations may be difficult to explain to customers or supervisors.
5. Data-protection risk
Sensitive financial data may be processed by complex computational infrastructure.
6. Liability risk
Errors could produce:
- incorrect credit decisions;
- inappropriate investment decisions;
- financial losses;
- incorrect fraud alerts.
7. Operational risk
Failure of quantum infrastructure could interrupt financial services.
8. Regulatory risk
Existing financial rules may not expressly address every new quantum application.
18. Important Legal Principle
The Spanish regulatory approach can be understood through the following proposition:
“Technology-neutral regulation with technology-specific risk management.”
In other words:
The law does not necessarily need a completely separate legal regime merely because a bank uses quantum computing.
Instead:
Banking activity
→ existing banking regulation
Quantum technology
→ additional technological, operational and cybersecurity risks
Consumer interaction
→ consumer-protection rules
Personal data
→ data-protection requirements
ICT dependency
→ operational-resilience requirements.
19. Role of Banco de España
Banco de España has already considered quantum technology from the perspective of financial-sector opportunities and cybersecurity risks.
Its 2024 publication discusses quantum computing's potential applications in finance while highlighting limitations and the implications for current cryptographic systems.
This is significant because it indicates that quantum finance is not merely a theoretical computer-science question; it has become relevant to financial-sector risk management and regulatory preparedness.
20. Future Regulatory Framework
Spain and the EU may increasingly need rules addressing:
- quantum-risk assessments;
- post-quantum cryptography;
- quantum technology outsourcing;
- quantum-model validation;
- audit trails;
- algorithmic accountability;
- quantum incident reporting;
- financial-sector quantum standards;
- cross-border quantum infrastructure;
- supervisory access to quantum models.
21. Conclusion
Hybrid classical–quantum finance systems in Spain are best understood as an emerging technological layer operating inside an already-established banking and financial regulatory framework.
The principal legal framework comes from Spanish and EU banking, securities, consumer-protection, data-protection and digital-resilience law rather than from a dedicated “quantum banking law.”
The most important legal consequences are:
- quantum technology does not remove banking regulation;
- banks remain responsible for regulated financial activities;
- consumer-protection principles continue to apply to automated and technologically complex contracts;
- DORA makes digital operational resilience particularly important;
- quantum computing creates a significant future cryptographic-security issue;
- post-quantum cryptographic migration may become an important compliance issue;
- quantum-assisted risk and credit models require appropriate governance and validation;
- third-party quantum providers can create concentration and outsourcing risks;
- Spanish securities law already demonstrates a willingness to accommodate emerging technologies within the financial regulatory framework.
Key Case Laws at a Glance
| Case | Year | Main legal principle |
|---|---|---|
| Banco Español de Crédito v Calderón Camino, C-618/10 | 2012 | Unfair bank terms must not simply be rewritten by courts |
| Aziz v CatalunyaCaixa, C-415/11 | 2013 | Effective judicial protection in mortgage enforcement |
| Bankia v Marí Merino, C-109/17 | 2018 | Effective protection against unfair banking practices |
| Gómez del Moral Guasch v Bankia, C-125/18 | 2020 | Transparency of variable mortgage-interest terms |
| Caixabank, C-484/21 | 2024 | Restitution and limitation following unfair terms |
| Banco Santander v ECB, T-610/24 / C-560/26 P | 2026 | Legal effects and judicial review of ECB supervisory action |
| Bankia, C-109/17 | 2018 | Mortgage valuation and procedural protection |
| Banco Español de Crédito, C-618/10 | 2012 | Consumer protection limits automated/standardised banking contracting |
These cases do not establish a special body of “quantum banking law”; rather, they provide existing banking-law principles that would remain relevant when quantum or hybrid computational systems are deploy

comments