The Shrinking Timeline for Cryptographic Resilience

By
Dr. Michele Mosca, Marco Piani
June 25, 2026
The Shrinking Timeline for Cryptographic Resilience

New advances in AI and quantum computing are accelerating the need for resilient cryptographic infrastructure

Anthropic’s April announcement that it was restricting access to Claude Mythos due to cybersecurity concerns was significant for a couple of reasons. Not only did it signal another leap forward in AI but also — and maybe more importantly — it highlighted the fact that any sufficiently powerful have potential to seriously disrupt the cybersecurity status quo.

Given today’s intense interest in AI, that story got mainstream media coverage. Google’s similar decision to withhold technical details on how a quantum computer could use Shor’s algorithm to break 256-bit elliptic curve cryptography was mostly confined to industry press and analyst blogs — but was no less consequential.

Drastically different degrees of risk

The risk posed by Claude Mythos is that bad actors might use it to discover and exploit previously unknown vulnerabilities in some of the most commonly relied-on software platforms around the world.

With quantum computing,cryptography itself becomes a point of vulnerability, exposing even the most highly sensitive and protected data and systems to potential compromise.

Given current progress in quantum computing, organizations face the hard fact that “collapse time” —the time to a cryptographically relevant quantum computer (CRQC) that can break conventional cryptography — may be shorter than the time available to migrate to post-quantum cybersecurity. Even organizations on track to meet jurisdictional migration targets by 2030 or 2031 could still be caught short if a CRQC emerges before then.

A shrinking threat timeline

Our new 2025 Quantum Threat Timeline co-published with the Global Risk Institute (GRI) touches on many of the advances accelerating the quantum threat today. Testament to the pace of research and development, even more examples have surfaced since we released this year’s edition. Among them:

- New papers from Google and Oratomic — a quantum company fresh out of stealth mode — indicate substantially improved resource estimates for quantum cryptanalysis.

- Australia’s Iceberg Quantum unveiled its Pinnacle Architecture, which could reduce the number of physical qubits needed to breakRSA 2048 by an order of magnitude (read more about that in our brief.)

- Google recently indicated a shift in its hardware strategy, including developing a neutral-atom quantum computing platform alongside its superconducting one, and set an ambitious deadline of 2029 for post-quantum cryptography (PQC) migration.

- NVIDIA announced Ising, the world’s first family of open-source quantum AI models to help researchers and enterprises build quantum processors capable of running useful applications.

While none of these announcements on its own represents an unequivocal breakthrough, the proliferation of developments in and around quantum computing can only be taken as a signal that the field is “getting real” for the biggest technology players in the world.

Ever-mounting risks

Advances in AI and quantum computing both pose cryptographic threats that organizations need to be aware of and ready for today.

AI-enabled attack automation could eliminate much of the advance notice organizations depend on to manage cryptographic vulnerabilities. Organizations need the ability to respond instantly to emerging cryptographic risks by rapidly transitioning to alternative cryptographic protections and, in some cases, relying on layered protections established in advance.

Even without a CRQC to break encryption, flawed implementations or poor algorithmic choices could force organizations to scramble in the face of a cybersecurity threat. Conventional approaches are not designed to remediate these vulnerabilities rapidly or at scale.

What’s needed is cryptographic resilience:the ability to sustain security even as threats evolve and underlying cryptographic assumptions fail. Given the current pace of CRQC development,this resilience becomes increasingly critical.

No time to waste

Much of the discussion around quantum risk has focused on harvest-now, decrypt-later scenarios — that data compromised today will be stored away for decryption and exploitation as soon as a CRQC becomes available.

That remains a real threat, but quantum risk has grown even bigger with the advances being made. And what’s at risk goes far beyond data confidentiality. If cryptographic systems cannot be migrated before current cryptography becomes untrustworthy, the integrity,availability and control of critical systems, digital infrastructure, and automated systems and agents that rely on trusted digital interactions could asll be compromised.

Even so, there are steps that can be taken immediately to start building cryptographic resilience and shore up defenses against the coming tide of next-generation threats.

You can download the full briefing on these latest developments here.

And if you’re ready to talk about increasing your cryptographic resilience today, don’t hesitate to reach out. At evolutionQ, we believe cryptographic risk can be managed through resilient architectures and operational readiness. Our focus is on helping organizations build cryptographic infrastructures that can adapt as technologies, threats, and trust assumptions evolve.