Anina Steele | Senior PR Manager
More About This Author >
Anina Steele | Senior PR Manager
More About This Author >
Artificial intelligence and quantum computing are often discussed as separate technology trends. But fresh findings from the Thales Quantum and AI Threat Report suggest that treating them as separate problems is a mistake we can’t really afford right now.
Based on responses from 3,120 security and technology professionals across 20 countries, the report reveals a common theme running through both technologies: they are converging on the same target - enterprise data. So, how should we go about protecting data at the crossroads of two revolutions?
AI doesn’t take away the need to prepare for quantum — it makes that need more urgent. AI can make attacks happen faster, while we depend more and more on encryption to keep things safe.
Going back to the report, the vast majority (98%) of respondents said they are considering how AI and quantum computing interact. The conversation has already moved past viewing these technologies in isolation. While AI and quantum operate on different timelines, both are creating pressure on the same security foundations, including data discovery, classification, encryption, key management, and cloud security. The organizations making progress in one area are often further ahead in the other.
That concern is not only defensive. According to 451 Research's VoTE Digital Pulse Quantum Computing study, 36% of organizations expect quantum computing to deliver material business value within one to three years, and 52% cite competitive advantage as the main driver of investment.
Unlike quantum computing, AI security is not a concern for some future date.
Organizations are already increasing spending on AI initiatives. 25% ranked AI security as the second-highest security spending category, after cloud. 30% reported significant increases in AI-specific security budgets.
At the same time, security teams are finding themselves under pressure to support AI programs where speed and innovation often take precedence. Security ranked second from the bottom among reported AI project success criteria at just 35%, suggesting that many organizations still see it as a supporting function rather than a primary objective.
The major hurdles to AI implementation also relate to data. The top inhibitors to AI adoption were data quality and governance (65%) and data exposure (61%).
The report also highlights how quickly AI-generated risks have become part of everyday security operations.
Only 3% of respondents reported experiencing no harm or damage from AI-generated threats. Human error is the leading cause of breaches, but deepfakes emerged as the leading AI-related concern. 59% of respondents reported experiencing deepfake attacks, while 48% reported reputational damage linked to AI-generated threats, reflecting the growing sophistication of AI-enabled social engineering.
The growing adoption of agentic AI and autonomous systems within organizations is driving a surge in the volume and velocity of data use. As such, cybersecurity professionals are under pressure to control data access and understand where the data resides, how it is used, and whether it is adequately protected as it is used in complex AI workflows.
If AI is today's pressure, quantum computing is tomorrow's deadline.
The report shows that organizations are already adjusting their security priorities in response. Harvest-Now, Decrypt-Later (HNDL) attacks are now the leading quantum-related concern, cited by 61% of respondents.
In a harvest now, decrypt later attack, adversaries collect encrypted data today and store it to decrypt in the future, once quantum computers can break the encryption that protects it. The concern is straightforward. Sensitive data stolen today could be retained and decrypted years later once sufficiently powerful quantum systems become available.
A significant portion of organizations are already preparing. Nearly a third (32%) are either experimenting with or surveying quantum computing initiatives, while 59% plan to prototype or evaluate post-quantum cryptography (PQC) algorithms within the next 18 to 24 months.
Current trends reveal that discussions about timing are becoming pressing. A recent preprint (not yet peer-reviewed) from a Caltech-led research team found that Shor’s algorithm could run at cryptographically relevant scales with as few as 10,000 reconfigurable atomic qubits — dramatically fewer than earlier estimates for attacks on schemes such as 256-bit elliptic curve cryptography.
The timing of when a true "Q-Day" will arrive remains contested, but some estimates say it could be as early as 2030. Irrespective of whether that timeline is right, transitioning to quantum-resistant security controls will take years, so preparation must start as soon as possible.
The report also compared technology leaders and laggards.
AI security leaders were defined as organizations that have invested in AI-specific security and consider themselves ahead of peers in AI adoption. Quantum leaders were organizations actively experimenting with or surveying quantum computing opportunities.
Across both groups, stronger data security fundamentals consistently appeared alongside greater readiness for emerging technologies.
Among AI leaders, 36% reported complete knowledge of where their data is stored, compared with 28% of laggards. 43% reported being able to fully classify their data, compared with 35% among laggards.
The relationship also works in the other direction. AI leaders are further along in their quantum journey, with 33% actively experimenting with or surveying quantum projects compared with 22% of laggards. Meanwhile, 89% of quantum leaders have invested in AI-specific security compared with 80% of quantum laggards.
The implication is difficult to ignore. Organizations that build stronger foundations around data security appear better positioned to adapt to both technological shifts.
The report also reinforces the central role cloud environments play in modern security risk.
According to 451 Research's VoTE Digital Pulse Quantum Computing, cloud security has been the leading enterprise security pain point every year since 2021.
That trend appears throughout the report's findings. The three most frequently targeted assets are all cloud-related: cloud storage (35%), cloud applications (34%), and cloud management infrastructure (32%).
The average organization now uses 2.3 cloud providers, while 39% use more than three. As AI initiatives depend on cloud infrastructure for training, inference, and data storage, the attack surface continues to widen.
For security teams, visibility becomes increasingly important as environments become more distributed and data moves across multiple platforms, providers, and AI services. The leader/laggard split in the report suggests that organizations investing in data fundamentals now are not just managing today's AI risk. They are also narrowing their exposure to a quantum threat that will not announce itself in advance.
Harvest now, decrypt later (HNDL) is an attack strategy in which adversaries steal and store encrypted data today so they can decrypt it later, once quantum computers are powerful enough to break current encryption. In the Thales 2026 Quantum & AI Threat Report, 61% of respondents named HNDL their top quantum-related concern.
Yes. Large-scale quantum computers are expected to break the public-key encryption — such as RSA and elliptic curve cryptography — that protects most data in transit and at rest. The most immediate risk is harvest now, decrypt later, where data stolen today is decrypted once that capability exists.
“Q-Day” is the point at which a quantum computer can break today’s encryption. Estimates vary and remain contested, but some place it as early as 2030. Because migrating to quantum-resistant controls takes years, most experts advise starting preparation now.
The report points to strong data security fundamentals: knowing where data lives, classifying it, and protecting it with encryption and key management. Practical first steps include building crypto-agility and evaluating post-quantum cryptography, and using data security posture management to discover and protect sensitive data across cloud and hybrid environments.
Download the full Thales Quantum and AI Threat Report to explore the complete findings and recommendations.