- 6G security decisions are being made now inside 3GPP and the ITU, years ahead of any live network
- EU-funded research such as Hexa-X has shaped much of the early zero trust and slicing security thinking now feeding into 3GPP
- The near-term UAE risk is inherited: weak segmentation and classical cryptography that will not hold up once 6G's timeline meets a quantum-capable adversary
- Operators and enterprises that fix zero trust and key management on their current 5G and cloud stack now will be the ones actually ready in 2030
Most of what gets written about 6G security describes a network that does not exist yet. That is not a criticism, it is the point: standards bodies write security requirements before vendors build hardware, so the architecture does not have to be patched after deployment the way 4G and 5G were. What is worth understanding now is what is actually being decided, who is deciding it, and what UAE operators and enterprises should be doing in the meantime rather than waiting for a finished spec.
Where 6G security standards actually stand right now
There is no 6G network to secure yet. The ITU-R published its IMT-2030 framework recommendation in 2023, setting the vision for what comes after 5G: ubiquitous connectivity, integrated AI, integrated sensing and communication, and connectivity for non-terrestrial platforms alongside terrestrial ones. 3GPP is expected to open formal 6G study and work items around Release 20, with a first full specification targeted for roughly Release 21, and commercial deployment realistically sitting around 2030. Those dates move as they always do with mobile generations, but the sequencing matters: security requirements are being scoped as part of the standard, not added afterward.
That is the genuine difference from 5G, whose security was largely retrofitted onto an architecture already fixed on performance and cost grounds. The IMT-2030 framework treats trustworthiness, including security, privacy and resilience, as a named design goal from the start. Whether that survives contact with real vendor implementations and cost pressure is a separate question, and history says it will not survive intact. Standards define a floor, not the security of any given deployment.
What the EU's 6G research is actually contributing
The EU's lead here is real but specific: a research and standards-contribution lead, not a finished-product one. Horizon Europe funded projects, most visibly Hexa-X and its successor Hexa-X-II, alongside the Smart Networks and Services Joint Undertaking, have produced a large share of the early published architecture work on 6G, including security-by-design proposals: zero trust as a default assumption for network functions rather than a perimeter control added at the edge, and identity built into the network layer itself instead of bolted onto the applications running over it. That research feeds into 3GPP and ETSI working groups, where it competes with proposals from other regions before anything becomes a mandatory requirement.
That gives UAE operators something to track, not a finished product to adopt: which of these security-by-design proposals actually survive into ratified 3GPP requirements, rather than architecting around research papers that may never make it into the standard.
The attack surface 6G adds on top of 5G
6G does not remove 5G's problems. It adds new ones on top, in four areas that matter for planning now.
Network slicing that finally gets tested properly
5G introduced network slicing in principle; most deployments have not stress-tested slice isolation under real attack conditions. 6G leans on slicing more heavily, so slice-to-slice isolation failures, already a weak point that penetration testing engagements flag in mature 5G cores, become a bigger problem, not a smaller one.
AI built into the radio network, not added on top
6G specifications assume AI-native radio access and orchestration: the network itself uses machine learning to manage spectrum, routing and resource allocation. That turns the network's own models into an asset that needs defending. Poisoned training data or adversarial input against the network's AI becomes a network security problem, not just an application-layer one, and most telecom security teams have not built the tooling to test model integrity the way they test firewalls.
Non-terrestrial links and continued interface disaggregation
6G formally integrates satellite and high-altitude platform links alongside terrestrial towers, and continues the trend toward disaggregated, multi-vendor radio access networks that started with Open RAN. Both extend the network's footprint into segments with weaker physical security and more vendor interfaces, meaning more places where a standards-compliant component is not actually a secure one.
The quantum problem arrives before 6G does
This is the one operators most often underweight. 6G's realistic commercial timeline sits past the point most cryptographers expect classical public-key algorithms to be unsafe against a sufficiently capable quantum adversary. Traffic and key exchanges captured today can be decrypted later once that capability exists, so harvest-now-decrypt-later collection against current 5G signalling and backhaul is a live reason to plan a post-quantum migration now. NIST finalised its first post-quantum cryptography standards in 2024, and telecom equipment refresh cycles run long enough that decisions made this year will still be in production when 6G arrives.
Is 6G actually more secure than 5G
Not automatically, and treating it as if it will be is the mistake to avoid. Trustworthiness is a named design goal in the IMT-2030 framework, a genuine improvement over 5G's security being bolted on after the performance architecture was already fixed. But a design goal is not the same as secure behaviour in a shipped product. Every previous mobile generation shipped with the security features the standard specified and was still misconfigured, under-segmented and poorly monitored in production. 6G will be judged on implementation and operational discipline, not on what the specification promised.
What UAE operators and enterprises should actually do before 2030
Waiting for the specification to finalise is not a plan, because the gaps that will matter most in 2030 are the same ones that matter in a 5G and cloud stack today.
- Move network management planes and virtualised network functions onto a zero trust architecture rather than a flat trusted core, so slice and function compromise does not automatically mean lateral access.
- Treat segmentation between network segments as a tested control, not a diagram, with the same rigour applied to core network functions as to enterprise IT.
- Start a post-quantum cryptography migration plan for anything with a long key or certificate lifetime, since equipment bought this year will still be running when the quantum timeline and the 6G timeline meet.
- Extend existing log collection and monitoring to cover network function and orchestration layers now, so the operational visibility 6G will require is not something a team is building from scratch when it arrives.