How AI Can Help Defend Against Future Quantum Attacks
Ali El Kaafarani is founder and CEO of PQShield, a British cybersecurity startup specializing in quantum-secure solutions.
gettyAI is now a core part of the cybersecurity conversation for every government and business. Not only do agencies and boardrooms need to make sure they are prepared for AI-powered attacks, but they are now being asked how AI is involved in their defense preparations, as well.
The cutting edge of this debate is happening in cryptography, where AI has completely changed popular understandings of trust and assurance.
The cyber community has quickly come to understand that AI models are capable of finding security flaws at a staggering scale. The first line of defense against this has been urgent security patches to fix those software flaws that had not been exploited in the pre-AI world. On many occasions, these vulnerabilities were years-old, zero-day flaws that bad actors didn’t have the means to attack.
As these surface-level patches are being rolled out, attention has turned to the cryptographic standards beneath them: the rigorously tested and globally trusted mathematical encryption algorithms that protect the world’s data. In the age of AI, how can we be assured that these standards are still up to snuff? It’s no longer good enough to assume that an algorithm is watertight or that long-reliable implementations can be trusted as usual.
The bar for trustworthy cryptography has been raised, and it won’t come back down. AI systems are already finding vulnerabilities in some digital signatures and cryptographic implementations, and this means that cryptographers no longer have the luxury of “assumed” security.
The good news is that cyber defenders have access to AI, not just attackers. This means that cryptographers now have a new, incredibly powerful tool for testing the strength of these algorithms.
Cryptanalysis is a crucial process for global cybersecurity. By stress-testing encryption systems, cryptographers can put themselves in an attacker’s shoes and “red-team” their own products to understand how well they will withstand a real-life attack.
While AI accelerates attackers’ movements, it also means that this process of cryptographic review is only becoming faster, more iterative and more demanding. The bar for trusted, assured security is rising, but AI-powered cryptanalysis is helping the cyber community to meet it.
Utilizing specialized AI models, cryptography experts can analyze encryption systems and validate the security of a specific cryptographic implementation. Vulnerability discovery can be automated, keys can be tested en masse and patterns in data can be spotted faster.
Cryptographers were of course carrying out these tests to a high level before new AI tools emerged. Now, with AI, they can accelerate efforts and build renewed trust in encryption algorithms that undergird software, hardware and firmware globally.
This new, narrower threshold for trusted cryptography needs to be met with greater collaboration across the supply chain, especially between private vendors and government-level standard-setters. By setting official encryption standards, government agencies like NIST in the U.S. and NCSC in the UK play a major role in building public trust in cryptography. These agencies now need to work with cryptanalysis experts to ensure that standardized algorithms are continually tested against the latest AI attack vectors.
This shift in trust comes at an inflection point for cryptography: The world is in the middle of a transition to new post-quantum cryptography (PQC) standards, which have been designed to protect data and critical national infrastructure from quantum-powered attacks in the future.
This migration to PQC is well underway. The U.S. government is mandating total adoption of quantum-proof encryption by 2035, while hyperscalers and tech giants like Google and Cloudflare have announced plans for total quantum readiness by 2029.
Naturally, as the world prepares for one existential cyber threat, the emergence of AI attacks could seem like a distraction. Even before AI threats, the transition to PQC was becoming one of the most complicated and risk-laden global cybersecurity upgrades in history. Poor-quality implementations of even the strongest new PQC standards could create devastating vulnerabilities across hardware, software, cloud and critical systems.
The reality is that AI presents a major opportunity for the post-quantum transition. Post-quantum security is not just about hypothetical quantum attacks; it’s a broader security modernization effort. As new PQC algorithms move from standards into production at scale, AI-powered cryptanalysis can help manufacturers test this brand-new technology as robustly as possible and bake in the highest level of trust.
Right now, government security ministers and Fortune 500 CISOs are trying to make the most informed decisions around how best to implement PQC standards into their systems. Verified, trusted implementations will win out.
In other words, AI can help the global transition to quantum-proof cybersecurity become more efficient and help develop a new gold standard for security: trusted, continuously tested and secure implementations of standardized security algorithms.
The organizations that want to succeed must combine strong standards, expert implementation and AI-assisted validation to improve how cryptography is selected, deployed and maintained.
AI and quantum are both emerging technologies, and are both challenging established cyber benchmarks daily. The threat landscape is changing rapidly, and this means that one of the most important things an organization can do is stay agile: being as adaptable and resourceful as possible to maintain trust.
The mission to standardize PQC algorithms has shown that the cryptography community, working together with the public and private sector, can improve the security of the entire supply chain.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
