PQC and AI: a perfect storm for cyber readiness?

Artificial intelligence and post-quantum cryptography are often discussed as separate cybersecurity challenges.

One is immediate, visible and accelerating rapidly. The other feels more strategic, technical and distant. But for those responsible for protecting sensitive data, digital services and customer trust, the two are starting to collide.

AI is changing the speed and scale of cyber risk. Quantum computing is changing the long-term assumptions behind encryption. Together, they create a new readiness challenge: not simply defending against today’s attacks, but preparing for a future where trust, identity, data protection and cryptography all need to become more agile.

That future is not theoretical. The NCSC has already set out a UK migration roadmap for post-quantum cryptography, with organisations expected to identify cryptographic services and build migration plans by 2028, execute high-priority upgrades between 2028 and 2031, and complete migration by 2035.

At the same time, AI is being adopted across business workflows, software development, customer service, security operations and data analysis. The question is no longer whether either shift matters, but whether organisations are ready for both at once.

cloud with AI and quantum imagery

What is post-quantum cryptography? 

Post-quantum cryptography, or PQC, refers to cryptographic algorithms designed to resist attacks from future quantum computers. 

Much of today’s digital infrastructure still relies on public-key cryptography that could be vulnerable to a sufficiently capable quantum computer. This includes the cryptographic mechanisms used to secure TLS, VPNs, digital certificates, software signing, identity systems and encrypted communications. 

In August 2024, NIST released its first three finalised post-quantum encryption standards, giving organisations a clearer foundation for migration. But for many, PQC readiness will not start with replacing algorithms, but with understanding where cryptography exists in the first place. 

That means finding certificates, keys, protocols, applications, devices, suppliers and systems that rely on vulnerable cryptography. For large organisations, this is not a spreadsheet exercise. It is a discovery, governance and automation problem.

 

Why does AI make PQC readiness more urgent? 

New AI-enabled services may connect to data stores, APIs, identity platforms, internal tools and third-party applications at a pace traditional governance models struggle to match. That matters because cryptography is often embedded deep inside the systems AI now depends on. 

If you do not understand where sensitive data flows, how systems authenticate, which certificates secure which services, or how machine identities are managed, then AI adoption can expand the attack surface faster than security teams can map it. 

This is where the “perfect storm” begins to form. 

 

The hidden risk: harvest now, decrypt later 

One of the most important PQC risks is “harvest now, decrypt later”. 

This is the idea that attackers can steal encrypted data today and store it until quantum capabilities mature enough to decrypt it in the future. That is particularly concerning for data with a long shelf life, such as government records, healthcare information, intellectual property, financial data, legal documents and sensitive personal information. 

AI adds another dimension. As organisations use AI to process, summarise, classify and move large volumes of information, they need to think carefully about where that information goes, how it is protected, and how long it needs to remain confidential. 

For CISOs and IT leaders, this creates a practical question: can you identify which systems process long-life sensitive data, which cryptographic protections they rely on, and whether those protections can be changed without disrupting the service? 

The overlap between AI data governance and PQC planning is becoming harder to ignore. 

The overlap between AI data governance and PQC planning is becoming harder to ignore. 

What does good cyber readiness look like?

Good readiness is not about waiting for quantum computers to become a mainstream threat, or blocking AI adoption until every risk is solved. It is about building the ability to adapt.

For PQC, you need:

  • cryptographic discovery across applications, infrastructure, cloud services and third-party suppliers
  • visibility of certificates, keys, protocols and machine identities
  • clear ownership of cryptographic assets and dependencies
  • automation and certificate lifecycle management
  • a migration roadmap aligned to government guidance

 

For AI, you need to understand:

  • where AI is being used across the business
  • what data AI tools can access, process or generate
  • what actions AI-enabled systems can take
  • which controls exist around prompts, outputs, permissions and identities
  • whether AI is moving into agentic workflows that can query systems, trigger actions and interact with live business data

 

Across both PQC and AI, the goal is the same: to move away from static, manual security models towards continuous visibility and governed change.

Organisations should be asking:

  • do we know where cryptography is used?
  • are certificates and machine identities managed centrally?
  • can cryptographic assets be rotated or replaced quickly?
  • are AI tools interacting with sensitive or business-critical systems?
  • do we have the visibility and governance needed to change safely?

These aren’t separate workstreams, but part of the same conversation.

 

The strategic point: agility is now a security control

Those best prepared for PQC and AI will not necessarily be the ones with the most tools. They will be the ones with the clearest visibility, strongest governance and fastest ability to make controlled change.

That is what crypto-agility means in practice. It is the ability to understand, update and replace cryptographic systems without creating disruption. In an AI-enabled environment, that agility becomes even more important because systems, workflows and data pathways are changing faster.

Those that act early will have time to discover, plan, test and migrate in a controlled way. Those that wait may find themselves trying to solve two major transformation challenges at once, under pressure, with incomplete visibility.

That is the real perfect storm.

Those best prepared for PQC and AI will not necessarily be the ones with the most tools. They will be the ones with the clearest visibility, strongest governance and fastest ability to make controlled change.

FAQs: PQC, AI and cyber readiness

What is the connection between PQC and AI?

PQC and AI are different challenges, but they both increase the need for better cyber visibility and control. PQC requires organisations to understand where cryptography is used and how it can be migrated. AI increases the speed at which data, applications and workflows are connected. Together, they make cyber readiness more urgent.

 

Why should organisations start preparing for PQC now?

PQC migration will take years for many organisations, especially those with complex estates, legacy systems, cloud environments and third-party dependencies. Starting now gives security teams time to discover cryptographic assets, prioritise high-risk systems, test migration paths and reduce disruption.

 

Does AI make quantum risk worse?

AI does not directly create the quantum threat. However, it can increase the complexity of the environment organisations need to protect. As AI tools interact with more data, systems and applications, organisations need stronger governance over where sensitive information goes, how it is secured, and which controls are in place.

 

What is “harvest now, decrypt later”?

“Harvest now, decrypt later” describes the risk of attackers stealing encrypted data today and storing it until future quantum computers are capable of breaking current encryption. This is especially important for data that needs to remain confidential for many years, such as healthcare records, government information, financial data and intellectual property.

 

What is crypto-agility?

Crypto-agility is the ability to identify, manage and change cryptographic systems quickly and safely. This includes knowing where certificates, keys, algorithms and protocols are used, and being able to update them without disrupting critical services.

 

Where should organisations begin?

A practical first step is discovery. Organisations need to understand where cryptography is used, which systems protect long-life sensitive data, how certificates are managed, and where AI is already interacting with business-critical information. From there, they can build a roadmap for automation, governance and migration.

About the Author

Ewan Ferguson
Chief Executive Officer
FullProxy’s CEO and a passionate web application guru with 25 years’ experience safeguarding networks for organisations of all sizes.
Resilience resized

The Power of 10: Why Agility, Expertise and Resilience will define the next decade of cyber defence

Ten years is a long time in cyber security. When FullProxy launched in 2016, the world looked very different. Cloud adoption was still gathering pace. Hybrid working wasn’t yet mainstream. AI was nowhere near today’s agenda. Ransomware was growing, but hadn’t yet become the industrial-scale threat it is now.
F5 iSeries upgrade

Your options to replace F5 iSeries (before end of support forces your hand)

The F5 iSeries has been dependable infrastructure for years. Stable. Predictable. Deeply embedded in production. But as F5 iSeries approaches end of support (EOS) at the end of the year, this stops being a lifecycle milestone and becomes a strategic decision point.
PQC timeline roadmap graphic

PQC Timeline: do I really need to start now?

The NCSC has published its Post-Quantum Cryptography timeline. Learn why 2028 isn’t as far away as it looks and what steps to take now to prepare.

From our experts to your inbox

Sign up to our monthly newsletter for trends, technology updates and exclusive content from our senior consultants.