US AI Congress Quantum Computing Panel Recap
- Mike J. Walker

- Jun 23
- 4 min read
Updated: 3 days ago

At the US AI Congress, I joined a discussion that covered quantum computing, artificial intelligence, cybersecurity, national defense, and the future of enterprise technology.
It reinforced something I’ve believed for a while, “AI, cybersecurity, and quantum computing can no longer be managed as separate technology domains. They are converging into one enterprise trust problem.”
What stood out to me is this, these aren’t separate challenges anymore. AI is accelerating everything, quantum is extending risk further into the future, and most organizations are trying to manage both with systems that weren’t built for either.
That’s why I keep coming back to a simple idea, this isn’t just a cybersecurity issue. It’s a trust issue.
If AI can act on your behalf, quantum computing can eventually weaken the cryptography that proves identity and integrity. Then the real question becomes whether your organization can still trust who or what is taking action and whether you can adapt quickly when that trust is compromised.
When will Q-Day Arrive is the Wrong Question
A lot of the conversation around quantum security focuses on “Q-Day,” the point when a quantum computer can break widely used public-key cryptography.
Naturally, executives want a timeline. Is it 2029? 2035? Twenty years from now? The reality is that no one knows, yet.
Quantum progress depends on many variables that include hardware design, error rates, correction methods, algorithm improvements, and how much effort an attacker is willing to invest. Those variables are still evolving.
Recent research has lowered some estimates for the resources needed to break RSA-2048, but that doesn’t mean today’s machines can do it. They can’t. What it does mean is that relying on a fixed timeline or vendor roadmap as a risk indicator is overly simplistic.
What Quantum Computing Actually Threatens
It’s important to be precise. Quantum computing mainly threatens public-key cryptography systems like RSA and elliptic-curve cryptography that support identity, secure communication, and digital signatures.
Symmetric encryption and hashing are affected differently. While quantum algorithms can reduce their strength, properly sized symmetric systems remain viable.
Public-key cryptography underpins trust in the digital world. It tells us:
Whether a website is legitimate
Whether software is authentic
Whether a communication partner is real
Whether a signature is valid
So the issue isn’t just confidentiality, it’s about the authenticity and integrity of digital systems.
Three Viewpoints Every Leader Should Understand & Take Action
#1 The Attacker Viewpoiont
AI is speeding up the entire attack lifecycle. This isn’t theoretical anymore. Threat intelligence teams are seeing attackers use AI for reconnaissance, vulnerability discovery, social engineering, credential theft, malware development, and more.
In June 2026, Anthropic reported on 832 accounts linked to malicious cyber activity, mapping over 13,000 techniques to the MITRE ATT&CK framework. Google and Microsoft have also noted that attackers are moving from experimentation to real operational use of AI. That shift matters.
AI doesn’t need to create entirely new types of attacks to change the landscape. It just needs to make existing ones:
Faster
Cheaper
More targeted
More scalable
More adaptable
Easier to execute
The real impact of AI isn’t just about smarter attackers, it’s about higher volume. On the panel I had communicated that, “AI isn’t just increasing attacker intelligence. It’s increasing attacker throughput.” I see that attackers are not inventing new methods of attack but rather being more efficient with the existing methods.
#2 The Data Viewpoint
Some data loses value quickly. Other data stays sensitive for decades. This is where “harvest now, decrypt later” comes in. An attacker doesn’t need a quantum computer today. They can collect encrypted data now and wait until they have the capability to decrypt it.
So the real risk depends on two things:
How long the data needs to stay confidential
How long it will take to upgrade the systems protecting it
Examples of long-lived sensitive data include:
National security information
Defense system designs
Health and genomic data
Pharmaceutical research
Manufacturing processes
Intellectual property
Infrastructure designs
Strategic business plans
Some of this data remains valuable for decades. That’s why quantum risk isn’t just a future issue. The breach can happen today. The decryption can come later.
#3. The Migration Viewpoint
Cryptography is everywhere in an organization. It’s embedded in applications, operating systems, hardware, certificates, APIs, VPNs, identity systems, firmware, cloud services, and third-party products. Most organizations don’t have full visibility into where it’s used.
Replacing cryptography isn’t like applying a patch. It often involves:
Finding hidden dependencies
Updating software and protocols
Reissuing certificates
Replacing hardware
Testing performance impacts
Revalidating regulated systems
Coordinating with partners
Maintaining compatibility during transition
In industries like healthcare, manufacturing, and defense, these challenges are even greater due to long system lifecycles and strict validation requirements.
NIST has finalized three key post-quantum standards:
ML-KEM (FIPS 203) for key exchange
ML-DSA (FIPS 204) for digital signatures
SLH-DSA (FIPS 205) as an alternative signature method
NIST recommends starting migration now, with vulnerable algorithms phased out by 2035.
That’s not a deadline to wait for it’s a signal of how long this will take.
Regulated Industries Face Greater Exposure
In regulated industries, trust has to be proven, not assumed.
Organizations must show who did what, why, and whether the data and systems involved can be trusted.
This makes AI governance, cybersecurity, and quantum readiness tightly connected.
You can’t:
Build reliable AI on untrusted data
Maintain trusted data without strong identity
Safely automate decisions without clear authority
Achieve quantum readiness without adaptable systems
For these organizations, the goal isn’t just being “quantum-safe.”
It’s becoming continuously verifiable.
Call to Action for Leaders
There’s a risk this becomes just another compliance exercise. That would miss the bigger picture. Preparing for quantum threats can uncover hidden systems, outdated technology, weak controls, and governance gaps.
Done well, it leads to an organization that is:
Easier to manage
Faster to adapt
More resilient
More transparent
More secure
No one can give a precise date for Q-Day.




Comments