Thought Leaders
Your AI Budget Is Writing Checks Your Cryptography Can’t Cash

The signs are everywhere. Moody’s, Google, Cloudflare, and the White House are all sounding the alarm. So why are CISOs still treating quantum as a “later” problem?
Ask any CISO where their discretionary budget went this year, and you’ll hear the same answer: AI. The market has decided that artificial intelligence is the defining security challenge of our era, and the money has followed.
There is just one problem. While your organization has been building AI pipelines, someone may already be quietly stealing your most sensitive, encrypted data and waiting for a quantum computer to arrive to decrypt it.
That is not a hypothetical scenario. It is a documented collection posture known as “harvest now, decrypt later,” and it is precisely why Moody’s Ratings (the credit agency whose opinions move sovereign bond markets) has issued a stark warning that slow post-quantum cryptography (PQC) adoption could represent a material credit risk for organizations across finance, healthcare, and critical infrastructure, and the White House recently mandated accelerated PQC adoption for federal agencies and contractors
The Timeline Just Got Significantly Shorter
For years, the standard reassurance offered to boards reluctant to spend on quantum preparedness was simple: we have until at least 2035. That was the US government’s own target for migrating national security systems to post-quantum cryptography and this was distant enough horizon to feel comfortable deprioritizing, for now. However, that has changed. On June 22, 2026, the White House unveiled not one but two Executive Orders which mandated timelines for federal agencies to migrate to post-quantum cryptographic solutions. Taken together, these Executive Orders recognize that advancing quantum computing and defending against its security implications are now inseparable national priorities. One order accelerates quantum innovation; the other accelerates the operational readiness required to protect critical systems in the quantum era.
Until recently, the consensus held that breaking today’s encryption would require millions of qubits, a capability still years away. New research, including work cited by Google’s own Quantum AI team, suggests that approximately 10,000 qubits may be sufficient to run Shor’s Algorithm against current standards. Around 26,000 qubits could potentially crack P-256, the elliptic curve algorithm underpinning vast swathes of financial services and government systems. Google’s own research points to a roughly 20-fold reduction in the computing resources needed to attack secure elliptic curve cryptography compared with earlier estimates
In March 2026, Google announced it was accelerating its internal PQC migration target to 2029. Cloudflare followed in April with the same target. Most recently, at the end of June, Microsoft brought forward its PQC transition target from 2033 to 2029. The US regulatory posture on PQC has also shifted meaningfully in the past eighteen months. The NSA now expects vendors of network equipment to support and prefer CNSA 2.0 algorithms by 2026, and the recent executive order directed federal agencies to transition high-value assets and high-impact systems to PQC by 2030.
In the EU, the European Commission’s messaging is clear: start transitioning by the end of 2026, and complete protection of critical infrastructures no later than the end of 2030.
The combined effect of these developments is that the “later” timeline most organizations are operating against is no longer valid. The question is not whether regulatory pressure on quantum cryptography will arrive. It is whether your organization will be caught scrambling to comply when it does, or whether it will have built the foundation already.
The Budget Trap: Why AI Always Wins and Why That’s a Problem
Here is the uncomfortable dynamic that plays out in IT budget meetings every quarter. AI investment has a story. It generates leads, cuts costs, accelerates analysts, and produces outputs that executives can see and touch. An AI-powered SOC tool will show you a dashboard on day one. A PQC migration program will show you a cryptographic inventory of problems you didn’t know you had, and no discernible change to the user experience.
Moody’s has identified this tension explicitly, noting that PQC spending will “compete directly with AI investment” because it delivers no immediate revenue uplift or productivity gain. It is the kind of spending that is very easy to defer and very hard to justify until something goes catastrophically wrong.
That deferred cost, however, is not free. Moody’s projects that organizations starting PQC migration now should expect it to represent around 2.5% of annual IT budgets. Those who delay until 2030 could be looking at double that, and a much more compressed, chaotic migration under regulatory pressure. The White House has already estimated that migrating federal systems alone will cost approximately $7.1 billion over a decade. That is for a single government. Multiply that logic across the enterprise market and the numbers become difficult to ignore.
What the Smartest Operators Are Already Doing
The fact that Google, Cloudflare and Microsoft are ahead of the curve is notable, but it should also be instructive. These companies have concluded that cryptographic migration is not a compliance exercise to be completed on a government timetable. It is a competitive infrastructure decision that needs to be made now, while there is still time to do it properly.
Their approach centers on two principles that should inform enterprise strategy broadly.
The first is cryptographic agility: building systems where the underlying algorithms can be swapped out cleanly, without a rip-and-replace, as the PQC landscape continues to evolve. NIST’s finalization of ML-KEM and ML-DSA as its primary post-quantum standards in 2024 was a major milestone, but the algorithm landscape will keep shifting. Several strong candidates have already been broken during the standardization process. Organizations that hard-code today’s PQC algorithms with the same rigidity they applied to RSA will face the same painful rip-and-replace cycle all over again in five years.
The second is visibility. You cannot migrate cryptography you cannot see, and most enterprises have no coherent picture of where public-key cryptography lives across their estate. Not just in their own applications, but in third-party integrations, vendor-managed platforms, IoT devices, operational technology, and legacy systems that have not been patched in years.
Both these capabilities: agility and visibility, require investment. Dedicated spend on cryptographic inventory, orchestration, and migration tooling. That spend needs to be carved out now, before the window to act affordably closes.
The Question Boards Need to Ask
There is a version of this story that ends badly and is entirely predictable. Organizations continue to funnel discretionary security budget into AI tooling through 2027 and 2028. Quantum computing capability advances faster than expected. Regulators begin mandating PQC compliance with short lead times. Organizations scramble to migrate critical cryptographic infrastructure under time pressure, at double the cost, while simultaneously managing whatever AI-related incidents are dominating the headlines that year.
That is not a quantum threat. That is a planning failure.
The smarter version of this story looks different. It starts with boards asking their CISOs a straightforward question: where is our public-key cryptography, what would it cost to migrate it, and when do we need to start? It continues with IT leadership recognizing that a portion of the AI security budget, even a modest one, should be redirected toward building the cryptographic foundation that every other investment depends on.
AI and PQC are not actually competing priorities. Every AI system an organization deploys, every model it trains on sensitive data, every API it exposes, relies on the cryptographic infrastructure beneath it. If that infrastructure is broken by a quantum adversary, the AI security tooling sitting on top of it doesn’t matter.
The case for moving some of your AI budget toward quantum cryptography preparedness is not really a technical argument. It is a financial one.
Early movers will build cryptographic agility into new systems at marginal cost. They will negotiate PQC readiness requirements into vendor contracts before those requirements become industry standard and vendors raise their prices accordingly. They will spread migration costs over several years rather than compressing them into a panicked, regulator-driven sprint.
Late movers will pay twice as much, migrate under pressure, and explain to their boards why they read the EOs, saw Moody’s warning, watched Google, Cloudflare and Microsoft move their timelines to 2029, and still didn’t act.












