AI Didn’t Wait for Quantum Computers to Shorten the Cryptography Deadline – The AI Journal
In late March 2026, Google’s Quantum AI team published a result that rewrote a multi-billion-dollar industry’s homework.
Researchers used AI-assisted algorithm design to attack the elliptic-curve cryptography (ECC) that protects most internet authentication and cryptocurrency. They showed it could take far fewer quantum resources to break than anyone had estimated.
Days later, a separate team, Oratomic, published a resource estimate suggesting the same class of attack might need as few as 10,000 qubits on a neutral-atom quantum computer. One of the researchers behind the work said that AI had played a decisive role in getting there.
Within days, Google moved its internal quantum-safe migration deadline to 2029, six years ahead of the US National Institute of Standards and Technology’s 2035 target.
Cloudflare soon followed suit. It cited the same two papers and said the new research meant the deadline was arriving much sooner than expected. Both companies pointed to the same root cause.
AI hadn’t just helped build better quantum hardware. It had helped find smarter ways to attack the cryptography the rest of us depend on every day.
That one episode captures most of what you need to know about where AI and quantum computing now intersect. The conversation about post-quantum readiness has changed. It’s no longer a niche cryptography topic. It’s an AI strategy one, and there are three stories tangled up inside it, but most organisations are only paying attention to one.
For years the working assumption was that a quantum computer capable of breaking RSA or ECC encryption, what researchers call a cryptographically relevant quantum computer, was a problem for the 2030s at the earliest.
The Global Risk Institute’s annual survey of quantum experts has tracked that estimate creeping forward. It’s 2024 survey of 47 experts put the probability of a machine existing by 2034 at 34%, roughly double the 17% the same survey found just two years earlier. That isn’t a stable forecast holding steady while we wait. It’s accelerating faster than the calendar.
AI is a meaningful part of why. Researchers are using machine learning in two ways. One is to optimise quantum error correction, long considered the field’s hardest engineering problem. The other, as the Oratomic episode shows, it’s helping discover more efficient quantum algorithms that could perform tasks such as breaking encryption with less quantum hardware than was previously believed necessary.
None of this requires AI to “solve” quantum computing outright. It only needs to keep shaving years off the runway, much as it already has in drug discovery and materials science.
This matters even if a fully working quantum computer never arrives this decade. Adversaries don’t need one today to start causing damage tomorrow. They only need to believe one is coming.
That belief alone makes “harvest now, decrypt later” worthwhile: collecting encrypted data today, on the best that it can be unlocked in five or 10 years. Anything with a long shelf life is exposed under this model right now, such as financial records, health data, legal contracts, and government communications.
It doesn’t matter when the quantum computer actually shows up. AI hasn’t created that risk. It has made the bet considerably more rational.
Here’s the part of the story that gets less attention. While AI is shortening the runway on one side, it is dramatically lengthening it on the other.
Every AI agent that books a meeting, queries a database, or moves money between systems needs an identity (a certificate, key, or token) to prove it is allowed to do what it is doing. Those identities are multiplying at a pace security teams have never had to plan for.
Palo Alto Networks’ 2026 Identity Security Landscape report found organisations now manage an average of 109 machine identities for every human one. AI agent identities alone are expected to grow 85% over the next year.
CyberArk’s 2025 State of Machine Identity Security Report puts that ratio at 82:1 and found 79% of organisations expect machine identities to grow by as much as 150% over the next year.
KPMG’s 2026 Cybersecurity Considerations report goes further. Drawing on interviews with security leaders at Google, Microsoft, Palo Alto Networks and ServiceNow, it names managing non-human identities as one of its eight top priorities for CISOs this year. The reasoning is simple: identity governance built for humans doesn’t survive at that scale.
Almost all those machine identities are secure the same way human ones have been for two decades: with RSA- or ECC-based certificates and keys. That matters, because the exact cryptography AI’s algorithmic breakthroughs are weakening is the same cryptography now authenticating an exploding population of autonomous software that no one fully governs yet.
Microsoft has been building out a dedicated identity system for AI agents, Entra Agent ID. It moved from preview in mid-2025, through expansion at the company’s Ignite conference that November, to general availability in 2026. The rollout amounts to a tacit admission: identity models built for people who get onboarded and offboarded by a manager don’t fit machines that spin up, act and persist indefinitely.
Gartner has gone as far as predicting that a quarter of enterprise breaches by 2028 will trace back to AI agent abuse.
Put the two trends side by side and the picture sharpens. AI is making the lock weaker and putting more doors behind it, at the same time.
Here’s where the story stops being purely alarming. AI is useful for compressing quantum timelines because of two traits: pattern recognition at scale and automation of tedious search problems. Those same two traits make it one of the more practical tools for getting organisations quantum ready.
The first step in any post-quantum migration is knowing where cryptography actually lives across an organisation’s systems, which applications, certificates, libraries, and protocols use which algorithms (and where). Done manually, that inventory can take large enterprises 12 to 24 months.
That’s exactly the kind of high-volume, pattern-matching task AI is well suited to. A growing set of tools is already doing it, from dedicated cryptographic discovery platforms to AI features built into security copilots. They scan codebases and network traffic to flag where RSA, ECC or other vulnerable algorithms are doing work no one remembers configuring.
That same logic applies downstream. Deciding which systems to migrate first means weighing data sensitivity, retention periods, and regulatory exposure across thousands of systems at once. That’sanother task better suited to automation than spreadsheets.
Migrating to post-quantum cryptography isn’t a one-off project either. It’s an ongoing discipline. NIST’s own guidance treats cryptographic discovery as a permanent programme, not a single exercise, since new algorithms are likely to keep emerging over the next decade or two.
That makes AI-assisted monitoring arguably the only realistic way to keep an inventory current as systems, vendors and standards keep shifting underneath it.
None of this is a reason to panic, but it isn’t a reason to wait either. The uncomfortable middle ground is where most organisations currently sit.
DigiCert’s research found that 69% of organisations believe quantum computers will break encryption within five years. Yet only 5% have actually implemented quantum-safe encryption.
A separate academic survey found fewer than 5% of enterprises have a formal quantum-transition plan of any kind. The awareness is there. The action mostly isn’t.
If there’s one option worth pushing back on, it’s the idea that this can be scheduled for “later” because the threat is uncertain. The uncertainty is precisely the point. No one can promise ten years of runway, and “harvest now, decrypt later” means the clock may already be running on data created years ago.
A more useful frame is to treat AI governance and quantum readiness as a single programme, not two unrelated ones, and it’s one that regulators are increasingly converging on:
The most important shift here isn’t technical. It’s that AI has merged two roadmaps that most boards still budget for separately. Fewer organisations will get caught out for simply ignoring quantum computing outright. Far more will get caught out for running “AI strategy” and “quantum readiness” as two separate meetings on the calendar, owned by teams who never compare notes.
source
This is a newsfeed from leading technology publications. No additional editorial review has been performed before posting.
Turn insight into action with CDO TIMES.
CDO TIMES helps executives move from AI awareness to AI execution through practical frameworks, tools, executive research, and advisory support.
Explore the Frameworks
Continue with Enterprise AI 2030, HI + AI = ECI, AI Governance, and executive playbooks.
Explore Enterprise AI 2030 →Use the Free Tools
Assess readiness, estimate AI ROI, model AI costs, and prioritize AI initiatives.
Open Executive Tools →Read the Book
Explore the HI + AI = ECI leadership model in The AI-Ready Leader.
Order The AI-Ready Leader →Go deeper with CDO TIMES Pro.
Unlock premium research, executive playbooks, templates, advanced tools, and member-only briefings.
Need executive help?
Explore advisory, workshops, fractional CIO/CDO/CISO/CAIO support, and AI operating model design.
Explore Advisory →Attend executive events
Join leadership forums, executive dinners, webinars, and strategic AI briefings.
View Events →Build AI capability
Use CDO TIMES Academy for executive learning, AI leadership development, and implementation training.
Explore Academy →

