up:: The Human & Organizational Side MOC
Security Works on What It Can See
AI is tangible. You can open it, demo it, watch it do something wrong, and put a screenshot of that in front of a board. Quantum is theoretical. The machine that breaks your encryption does not exist, nobody has seen it, and the harm it does is invisible while it happens. Organizations work on the first kind of problem and defer the second, and that sorting is doing more damage than any disagreement about timelines.
It helps to be clear about what this is not. The security leaders I talk to are not skeptical about the quantum threat, which would at least mean they had read something and formed a view. They have simply put it in the category of things that are not real yet, and nothing in a working week ever pulls it back out.
The flaw in that sorting shows up twice in 2026. Both times something concrete and dated happened to cryptography, and both times it was skipped, because it arrived filed under the theoretical heading.
In July, an AI model found a hidden mathematical structure inside a cryptographic algorithm that had been under public expert review for 3 years, and it killed the algorithm in a day. The algorithm was HAWK, one of 9 candidates left in the third round of NIST’s competition to select additional digital signature algorithms, and the specialists reviewing it were people whose whole job was finding exactly this kind of flaw. The model found it instead. Another cryptographer confirmed the result within hours, the submission team withdrew HAWK the next day, and NIST updated its project page to record that the scheme was gone. The work cost about 60 hours of machine time and roughly $100,000, according to Anthropic, which built the model and is reporting its own result.
Nothing in production was affected, and that part matters. HAWK was a competition candidate, so no product ever shipped it, and Anthropic states the attack “is specific to HAWK and does not impact other NIST post-quantum signature candidates or lattice-based cryptography in general.” This is a selection process catching a weak candidate before anyone deployed it, which is the process working as designed.
4 months earlier, physicists published a new estimate of what it would take to break the cryptography behind most of the web, and the number came down hard, from millions of qubits to roughly 10,000 on a newer and far more efficient hardware design. Part of that improvement came from a machine. The paper says so in its own methods, crediting the error-correction scheme it depends on to an “LLM-assisted heuristic computer search.” Cloudflare cited that paper 8 days later and set its own target for being fully protected at 2029, against the 2035-and-later timelines the field had been working to.
2 AI stories about cryptography, both filed under quantum, both missed by an industry that thinks of itself as paying close attention to AI.
Tangible beats theoretical, every time
It is not stupidity and it is not denial. The 2 subjects present themselves in completely different forms, and organizations are built to act on only one of them.
Everything about AI is visible. A board member has used it personally. A vendor can demo it in the room. An incident produces a screenshot, a log line, a thing that happened on a date. It runs on equipment you already own, it produces results inside a quarter, and every question about it has someone waiting on an answer. Work like that gets staffed because the cost of ignoring it is something you can point at.
Nothing about the cryptographic transition looks like that. The machine is a paper estimate. The adversary copying your traffic today leaves no trace and triggers no alert. The cryptography itself worked silently for 30 years, which is exactly why almost nobody was ever made responsible for it, and it cuts across applications, infrastructure, vendor products and identity at once, so it falls into the gaps between teams. Nothing about it ever interrupts anyone, and “we know where all our cryptography is” appears on no scorecard anywhere.
So it gets sorted as theoretical and set down, and the sort is not irrational. It is just wrong about which part is theoretical.
The deadlines are the part that is not theoretical
Start with something happening now that your vendors will not raise with you.
A separate study published in July, benchmarking frontier models across 191 cryptanalysis problems, had a model expose a mistake in an algorithm’s published security proof that nobody had reported before. That changes a conversation security leaders have constantly, because a formal proof is now exactly the kind of artifact these tools audit well, and the auditing is affordable. A vendor telling you their cryptography is “provably secure” has quietly become weaker evidence than “this survived a decade of people trying to break it.”
The same study is careful about its limits, and so should anyone quoting it be. The models re-derived known attacks far more often than they found new ones, the novel results landed on competition submissions rather than anything deployed, and no deployed full-strength standard fell anywhere in the benchmark.
Then there are the dates, which are already written down and do not care whether anyone read the papers. An executive order signed in June 2026 requires the government’s most sensitive systems to move to post-quantum key establishment by the end of 2030 and to post-quantum signatures by the end of 2031, and it directs a rule be proposed holding federal contractors to the same standards by that first date. A NIST transition document deprecates RSA-2048 and the standard elliptic curve after 2030 and disallows the old public-key cryptography outright after 2035, though that one remains an initial public draft, so it reads as intent rather than as settled rule. Cloudflare’s 2029 sits ahead of all of them, chosen by a company that read the papers.
None of those dates is a prediction about when a quantum computer shows up. They are obligations with years attached, and they arrive whether or not the machine does. That is the piece the sorting gets wrong: the computer is theoretical, and the deadline is a date on a calendar, as concrete as anything on your roadmap.
The work in front of that deadline is concrete too, and it is dull. Find out where your cryptography lives. My read, from the rooms I work in, is that most security teams could not currently say which of their systems use RSA or elliptic curve at all, and that inventory is the slowest part of the whole transition. It has nothing to do with quantum physics and everything to do with a spreadsheet nobody owns.
One risk announces itself, the other never will
The AI work is earned, and none of this is an argument against it. Model risk, data governance and AI-enabled attacks are present-tense problems with present-tense consequences, and a program ignoring them would be negligent. The argument is about what happens to the work that never presents itself at all.
The cryptography research deserves the same skepticism, too. Those qubit estimates are theoretical, describing machines nobody has built at that size. The March paper’s authors hold shares in the company whose hardware design it favors, the machine-assisted search behind its key result is credited to a companion paper still in preparation, and Cloudflare noted that both results behind its own decision were deliberately incomplete. Nobody has demonstrated a quantum computer that can break real-world cryptography, and no credible source puts a date on when one will.
What survives is narrower and harder to wave off. The cost of breaking today’s cryptography keeps falling on better mathematics rather than better hardware, that mathematics is now partly being done by machines, and one of the largest operators on the public web has already repriced its own timeline on it.
So the 2 risks are not competing for the same slot, and treating them as if they were is the mistake the budget process pushes you into. AI risk is visible and operational, it changes month to month, and you know when it goes wrong because something happens and you respond to it. Cryptographic risk produces no event at all: no alert when your traffic is copied for later, no incident report when 2030 arrives with the inventory unstarted. Nothing about it will ever raise its hand.
Which is why it has to be scheduled rather than prioritized. Prioritizing means putting it in a queue against work that will always look more real, and it loses there every time, forever. Scheduling means someone owns a dull inventory question and a date by which it is answered, and that survives a busy quarter because it was never competing in the first place.
Final thoughts
An AI model ended a cryptographic algorithm in a day this July, and the people whose whole job is watching AI missed it, because it wore a label that means not real yet.
The machine is still theoretical, and it may stay that way for a decade. The deadline is not, the inventory is not, and neither of them needs a physicist. Find out which of your systems use RSA and elliptic-curve cryptography, and which of your data has to stay confidential past 2030. Both are questions about your own estate, both are answerable this quarter, and until they are answered every other decision here is guesswork.
The map is free, and the execution is the work I do at LaMarr Labs.
Last verified 2026-09-02 · Maintained by Addie LaMarr, LaMarr Labs.