Q-Day will come. Ready or not?

IBM Quantum Loon chip (Credit: IBM)

A note on AI use: My posts are written by me. I use AI to check grammar and spelling, generate images and charts, and analyse data or large amounts of text. I also use it to review my writing and get feedback, which I decide whether to use.

Every now and then there is a technology that actually shifts the paradigm. No, I am not talking about the marketing BS where every new thing is a paradigm shift! The internet shifted the paradigm of how information is exchanged. Newtonian’s classical physics was challenged by Einstein’s Theory of Relativity. Classical computing will be changed by quantum computing. Yeah…, we have been hearing it for a while. It appears on all the big tech predictions every year, but so does every other hype. For the last twenty-odd years, we have been five years away from quantum. But something has changed in the last few years, especially 2024 to 2026.

What has changed?

What changed in the last two years? Error correction. If you noted in the sidebar “What is Quantum Computing?”, qubits are the key to quantum computing. The more qubits are added; one expects a better result. However, until recently, more qubits meant more noise and poorer result.

Let’s understand the challenge. Classical computing is deterministic. Given the same inputs, you will get the same result however many numbers of times you try. In a spreadsheet, you will get the same results for the calculations unless you change anything. The world of quantum computing is not deterministic, it is probabilistic and is prone to change due to any change in the environment, yes including temperature. Error correction takes up most of the compute resources in quantum computing. In classical computing, we have algorithms, a set of instructions that can be followed. Apart from a few quantum algorithms, there aren’t many.

Willow, Google’s latest quantum chip has proven to reduce the error correction rate below threshold. (Source: Meet Willow, our state-of-the-art quantum chip). IBM announced Loon, an all-hardware fault tolerant chip. (Source: IBM Delivers New Quantum Processors, Software, and Algorithm Breakthroughs on Path to Advantage and Fault Tolerance). The days of fault tolerant quantum computing are coming.

Classical computers rely on bits and bytes to store data. A bit represents either a zero or a one. Computers process data sequentially using these binary states. Quantum computing introduces qubits. Qubits exist in multiple states simultaneously, not just 1s and 0s. This property allows systems to calculate complex data combinations at the same time.

The underlying physics involves complex quantum mechanics. There are architectural and security implications. This technology augments and challenges classical high-performance infrastructure.

Check out Quantum Explainer – MIT for explainer videos on quantum computing.


The timelines without the hype

Like AI, quantum computing is not new. A lot of research and work has gone into it before the real useful aspects emerge. A lot of it has been just PR. This reminds me of a quote from the one and only Richard Feynman.

“For a successful technology, reality must take precedence over public relations, for Nature cannot be fooled.”

– Richard Feynman, in his report on Challenger disaster
A bit of history

Pre-2024 it was primarily about getting concept of the basic quantum computer working. This was the time when the more qubits are added, the noisier it got, or more errors. Fault-tolerant general-purpose quantum computing is 3 to 7 years away. The cybersecurity risk is already here.

Click on the time periods to see the developments and key moments.

Foundations 1980 – 1985 5 milestones
1980
Paul Benioff: quantum Turing machine
Argonne National Laboratory
1980
Paul Benioff: quantum Turing machine
Argonne National Laboratory

Benioff publishes the first quantum mechanical model of a Turing machine, proving computation could work under quantum mechanics. The field’s quiet origin, largely unnoticed outside physics circles at the time.

1981
Richard Feynman: the rallying cry Key moment
“Nature isn’t classical, dammit”
1981
Richard Feynman: the rallying cry
Caltech keynote

Feynman’s Caltech keynote proposes that only a quantum computer can properly simulate quantum nature. The quote and the idea launched a field. Published formally in 1982 as “Simulating Physics with Computers.”

1982
No-cloning theorem
Wootters & Zurek
1982
No-cloning theorem
Wootters & Zurek

Quantum states cannot be copied. This constraint is foundational to quantum cryptography: any eavesdropper on a quantum channel disturbs the signal and is therefore detectable.

1984
BB84 protocol
Bennett & Brassard: quantum cryptography concept
1984
BB84 protocol
Bennett & Brassard

The first quantum key distribution protocol. Two parties can share a secret key over a quantum channel: any eavesdropping is mathematically detectable. Quantum cryptography as a working concept, before any hardware existed to run it.

1985
David Deutsch: universal quantum computer formalised
Oxford University
1985
David Deutsch: universal quantum computer formalised
Oxford University

Deutsch gives quantum computing a rigorous mathematical definition: the universal quantum Turing machine. Quantum computing becomes a proper research programme, not just a physics thought experiment. Asher Peres also identifies in the same year that error correction will eventually be needed.

Algorithms era 1994 – 1998 3 milestones
1994
Shor’s algorithm: RSA is threatened Cybersecurity
Peter Shor, Bell Labs
1994
Shor’s algorithm: RSA is threatened
Peter Shor, Bell Labs

Shor proves a quantum computer can factor large numbers in polynomial time, directly breaking RSA, ECC, and all public-key cryptography. The moment quantum computing becomes a national security concern: nine years before any hardware could run it.

1996
Grover’s algorithm: quantum search
Lov Grover, Bell Labs
1996
Grover’s algorithm: quantum search
Lov Grover, Bell Labs

Quantum search of an unstructured database in √N queries vs N classical: a quadratic speedup. Less devastating than Shor’s for encryption (AES-256 effectively becomes AES-128 strength), but meaningful. Doubles as an early proof that quantum algorithms have real-world applications beyond cryptography.

1998
First working qubits
Oxford & MIT: NMR 2-qubit machines
1998
First working qubits
Oxford & MIT

Oxford and MIT run the first quantum algorithms on 2-qubit NMR machines. The computations are trivial: but theory meets hardware for the first time. A seventeen-year gap between Feynman’s 1981 vision and the first physical demonstration.

First hardware 2001 – 2016 5 milestones
2001
IBM 7-qubit processor: Shor’s runs on hardware
IBM Research
2001
IBM 7-qubit processor: Shor’s runs on hardware
IBM Research

IBM runs Shor’s algorithm on a 7-qubit processor and factors 15 into 3×5. The answer was known. The achievement was doing it on actual quantum hardware: seven years after Shor published the algorithm.

2007
D-Wave One: first commercial quantum annealer
D-Wave Systems
2007
D-Wave One: first commercial quantum annealer
D-Wave Systems

D-Wave launches a 28-qubit quantum annealer: optimisation-focused, not general purpose. Sparks years of debate about whether it is “really” quantum computing. Regardless, it is the first commercial product in the category and the first signal that someone was willing to pay for this.

2011
Lockheed Martin buys a D-Wave system
First commercial sale: approx. $10M
2011
Lockheed Martin buys a D-Wave system
First commercial sale

D-Wave’s 128-qubit system sold to Lockheed Martin. Quantum computing crosses from academia into enterprise procurement. Google and NASA follow with a joint purchase in 2013.

2014
NSA sounds the alarm Cybersecurity
Harvest-now-decrypt-later threat named publicly
2014
NSA sounds the alarm
US National Security Agency

NSA publicly warns it is planning migration to quantum-resistant algorithms. The first time a major government body names harvest-now-decrypt-later as a present-tense threat. Adversaries are collecting encrypted data now to decrypt later. This is when the cybersecurity timeline starts. Not 2024.

2016
IBM Quantum Experience: public cloud access
5-qubit quantum computer, free via browser
2016
IBM Quantum Experience: public cloud access
IBM Research

IBM puts a 5-qubit quantum computer on the cloud, free to anyone with a browser. Within months, researchers worldwide are writing quantum code. The field opens beyond specialist labs: the same democratisation moment that cloud computing had a decade earlier.

Supremacy race 2019 – 2023 3 milestones
2019
Google Sycamore: “quantum supremacy” Key moment
53 qubits, task completed in 200 seconds
2019
Google Sycamore: “quantum supremacy”
Google Quantum AI

Google’s 53-qubit Sycamore processor completes a specific sampling task in 200 seconds: claimed to take classical supercomputers 10,000 years. IBM disputes the benchmark. The debate is productive, forcing the field to define what “quantum advantage” actually means and on what problems.

2022
IBM Osprey: 433 qubits
Largest superconducting processor at the time
2022
IBM Osprey: 433 qubits
IBM Research

IBM’s Osprey reaches 433 physical qubits. A scale milestone, but qubit count without error correction is still insufficient for practically useful tasks. This era teaches the field a hard lesson: raw qubit count is the wrong metric. Quality, coherence time, and error rates matter more.

2023
IBM demonstrates utility-scale quantum advantage
Google achieves below-threshold on Milestone 2
2023
IBM demonstrates utility-scale quantum advantage
IBM & Google

IBM demonstrates utility-scale computing on real-world problems. Google hits its Milestone 2 on its 6-milestone roadmap: below-threshold error rates at a physically relevant scale. The industry begins treating error correction as an engineering problem, not a theoretical one.

Error correction era 2024 – present 5 milestones
Aug 2024
NIST finalises post-quantum standards Cybersecurity
Three PQC standards replace RSA and ECC
2024
NIST finalises post-quantum standards
US National Institute of Standards and Technology

NIST finalises three post-quantum cryptographic standards. NSA’s CNSA 2.0 requires all new national security systems to be quantum-safe by January 2027. Phase out quantum-vulnerable algorithms after 2030, disallow after 2035. The regulatory clock has started.

Dec 2024
Google Willow: below-threshold error correction Key moment
More qubits now improve results
2024
Google Willow: below-threshold error correction
Google Quantum AI

The inflection point. Willow demonstrates that adding more qubits now reduces rather than amplifies errors: the threshold the field spent 40 years trying to cross. Claims a 5-minute task would take a classical supercomputer 10²⁴ years. Peer-reviewed and published in Nature.

Jan 2025
QuEra: 96 logical qubits (Nature)
448 physical atoms, 4.7:1 encoding ratio
2025
QuEra: 96 logical qubits
QuEra Computing & Harvard

QuEra (with Harvard) encodes 96 logical qubits from 448 physical atoms using high-rate quantum error correction codes: a 4.7:1 ratio. Below-threshold error suppression confirmed. Demonstrates that the overhead cost of error correction is falling faster than expected.

Early 2025
Microsoft Majorana 1: topological qubits
A different hardware bet
2025
Microsoft Majorana 1: topological qubits
Microsoft Research

Microsoft announces a topological qubit chip using a “new form of matter”: theoretically more stable than superconducting or trapped ion qubits. Early stage, but represents a fundamentally different hardware architecture. If it scales, it could outpace current approaches.

June 2026
Microsoft Majorana 2: 2x gap, 1000x reliability
Developed with agentic AI
2026
Microsoft Majorana 2: 2x gap, 1000x reliability
Microsoft Research

Updated material stack increases the critical topological gap by over 2x, delivering a 20-second parity lifetime and 1000x improvement in switching reliability. The fact that agentic AI assisted the hardware design is itself a signal of where the quantum-AI intersection is heading.

In the last two years there have been significant changes that are crucial for quantum computing to be a reality in the future. How long in the future? I reckon 2030 could be an interesting year, especially in algorithm and research space.


Creative Destruction: What gets disrupted?

I don’t claim to be a futurist or a crystal ball gazer. What I know is that quantum computing is not for solving every type of problem. These are the quantum algorithms that are already shaping up and will disrupt the status quo.

  • Drug discovery and materials science: simulating molecular behaviour at quantum level. This is where the clearest near-term advantage sits.
  • Financial optimisation: portfolio optimisation, risk modelling, fraud detection at scale (longer term) that classical machines cannot match.
  • Logistics and supply chain: problems that are computationally intractable today become solvable.
  • AI training: quantum-classical hybrid models could accelerate specific ML workloads. This is where quantum could meet AI.
  • Cryptography infrastructure: everything changes. This is where my interest lies and I am sure many of my peer technology leaders are already thinking about it.

The Cybersecurity Implications

Two acronyms worth knowing: PQC and QKD.

PQC or Post Quantum Cryptography are set of new encryption standards believed to be resistant to quantum attacks, including those using Shor’s algorithm. BTW, they also need to run on the existing computers!

Computer communications are secured using a public and private key based encryption method. Data encrypted (e.g. passwords stored in systems, when you sign up for a website) using these algorithms today are secure. In 1994, Peter Shor identified a quantum algorithm that can decrypt data using current encryption methods, specifically RSA, DSA, ECC, DH. I told you we are so good at acronyms.

QKD or Quantum Key Distribution is an evolving method of encrypting information using quantum mechanics. There have been many bold claims made such as:

The NSA (National Security Agency) is more direct about the limits:

“Quantum key distribution and Quantum cryptography vendors—and the media—occasionally state bold claims based on theory—e.g., that this technology offers “guaranteed” security based on the laws of physics. Communications needs and security requirements physically conflict in the use of QKD/QC, and the engineering required to balance these fundamental issues has extremely low tolerance for error. Thus, security of QKD and QC is highly implementation-dependent rather than assured by laws of physics. Although we refer to QKD only to simplify discussion below, similar statements can be made for QC.”

In summary, NSA views quantum-resistant (or post-quantum) cryptography as a more cost effective and easily maintained solution than quantum key distribution. For all of these reasons, NSA does not support the usage of QKD or QC to protect communications in National Security Systems, and does not anticipate certifying or approving any QKD or QC security products for usage by NSS customers unless these limitations are overcome. (Source: National Security Agency/Central Security Service > Cybersecurity > Quantum Key Distribution (QKD) and Quantum Cryptography QC)

The theoretical security claims are real and grounded in physics. The implementation is where complexity creeps in. Trusted nodes, hardware side-channels, detector loopholes, supply chain risk. QKD is a serious and valuable tool for specific high-value links, but “unbreakable” appears to be marketing BS. Post quantum cryptography, which NIST has standardised and which runs on existing infrastructure, is the more practical near-term migration path for most organisations.

“Extraordinary claims require extraordinary evidence.”

– Carl Sagan, Cosmos

What should we be doing?

Security is all about risk management, mostly. A key question, boards and execs need to be asking, without going into the nitty-gritty of the encryption, is that how long are we storing encrypted data for? If you are protecting long term data using a vulnerable algorithm, well, there will be trouble. Medical data, private information, financial records that must be kept for ten years or longer.

Data already stolen, protected by current public-key encryption methods, will be able to be decrypted, even if it is not possible to do it now. It is called “Harvest now, decrypt later”. (Even this has an acronym – HNDL, seriously!) Protect your data against being stolen now, even if it is encrypted to the toughest standards that cannot be broken today.

The NIST standards are already available. Do a cryptographic inventory now, start migration planning) even years away), and check your third-party vendors.


Quantum and AI

So where does AI, which is at the top of the hype-cycle now, fit into the quantum story?

AI and quantum are complementary at different layers. Current AI runs on classical hardware. Quantum will not replace GPUs anytime soon. But for specific optimisation problems inside ML pipelines, for searching enormous solution spaces, quantum offers genuine advantage.

Another possibility is quantum-enhanced AI. Quantum algorithms for faster sampling, better reinforcement learning, and molecular simulation to discover better materials for chip fabrication (which then runs better classical AI). The feedback loop could be real.

Here is an interesting feedback loop: Software engineers built AI tools to write code faster. AI wrote code faster. Now the people who paid for it think they no longer need software engineers.

My honest assessment is that most organisations should focus on AI now and treat quantum as a 3 to 5 year horizon. But the security piece does not get that luxury.


C’mon, is this really going to happen or is it a YAH?

Back to the theme of acronyms, there are a lot of YA{X} style IT acronyms, where YA stands for Yet Another {Something}. So, is quantum computing Yet Another Hype (YAH)? Like any other technology, it will go through the standard hype cycle. It is still in its infancy. It has been five years away for the last twenty years. It needs a lot of investment to make it “production ready”.

Here is my take on it:

  • It will not replace classical computers, and we will not have laptops and phones running on quantum chips, in the near future. The overhead for error correction remains enormous. Today’s quantum processors are still characterised by high error rates and limited scalability. They are not poised to replace classical computing for most business operations anytime soon
  • The quantum advantage currently only works for quantum only problem and not general-purpose problem. It is still a long while for the general-purpose problem solving to benefit from quantum computing.
  • There is a pattern in emerging technology markets. Investors price in a future that may be a decade away. Quantum is doing this at an unusual scale. At the end of 2025, the four main pure-play quantum stocks carried price-to-sales ratios of 141x (IonQ), 856x (Rigetti), 315x (D-Wave), and 2,760x (Quantum Computing Inc.). To put that in context, the median public SaaS company trades at around 5 to 6x revenue. Even cloud security companies, one of the most richly valued niches in tech, average around 21x. Quantum pure-plays are on a different planet. History suggests the planet eventually moves closer to Earth.

The lingering question!

The question this leaves me with is: If your data has a 7 to 10 year confidentiality horizon, is it quantum-safe today?


Sources and Further Reading

This post needed a bit of quantum reading to do, and it has been interesting research. I come from a classical computing background and with a very limited and peripheral knowledge of quantum physics. I am surely watching this space, and every tech leader should do so as well. Here is what I found useful:

Don’t want to miss latest posts?

Subscribe Here


Discover more from Sid Kumar

Subscribe to get the latest posts to your email.

Or follow me on

Discover more from Sid Kumar

Subscribe now to keep reading and get access to the full archive.

Continue reading