Post-Quantum Cryptography
New encryption that even quantum computers cannot break: NIST standards since 2024, migration underway from 2025/26.
Open in the interactive tree →Lattice-based schemes such as ML-KEM and ML-DSA replace RSA and elliptic curves, which Shor’s algorithm would break. It is urgent already today because of “harvest now, decrypt later”: attackers store encrypted data to decrypt it later. The migration affects every piece of software, every certificate and every chip.
As of October 2026
NIST published FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) in August 2024 and selected HQC as a backup key mechanism in March 2025 (final standard expected 2027); FIPS 206 (FN-DSA/Falcon) is still in development. NIST’s transition plan (draft IR 8547) would deprecate RSA and elliptic curves after 2030 and disallow them after 2035, and the EU roadmap asks member states to begin migrating by the end of 2026 and protect high-risk uses by 2030. Cloudflare reported in October 2025 that the majority of human web traffic through its network already uses post-quantum key exchange, while only about 3.7% of origin servers supported it.
Open steps
- Finding every place old crypto hides High AI leverageOrganisations do not know which code, devices and certificates use RSA or elliptic curves; a complete inventory is the first step of any migration.
- Compact post-quantum certificates Medium AI leveragePost-quantum signatures are about 20 times larger than ECDSA; web certificates need new designs such as Merkle Tree Certificates before logins can go post-quantum.
- Side-channel-safe implementations Medium AI leverageLattice schemes can leak secrets through timing and power on small devices; verified constant-time code and hardened chips are needed.
- Upgrading devices that cannot be updated Low AI leverageSmart cards, cars, meters and satellites live for years with little memory and need post-quantum firmware or hardware roots of trust, often not field-updatable.
Where AI could help
Medium AI leverage. AI can find and rewrite cryptography in code at scale and test implementations; devices, certificates and standards pace the migration.
- Inventory cryptographic use across codebases and binaries
- Draft and test code migrations to ML-KEM and ML-DSA libraries
- Fuzz and verify implementations for side-channel and memory bugs
- Prioritize which systems to move first by data lifetime
Shown so far
- In January 2025 Google reported in an experience paper that language models can significantly cut the time needed for large internal code migrations. source
Prerequisites
- Abstract Algebra (Noether)1921-1931ML-KEM and ML-DSA are lattice schemes over polynomial rings and modules
- Public-Key Cryptography1976
- Quantum Algorithms (Shor)1994