Nobody can agree on when a quantum computer will break today’s encryption. Everyone agrees the migration away from it takes about a decade. And meanwhile, your engineers’ source code is already leaving the building through the front door.
The UK’s National Cyber Security Centre has published a timeline for moving the country off today’s encryption standards: discover and plan by 2028, migrate the highest-priority systems by 2031, complete the whole job by 2035. Tucked inside that guidance is a warning most boards haven’t fully absorbed. The NCSC advises organisations to assume that sensitive, encrypted data is already being collected today, for decryption later, once a sufficiently powerful quantum computer exists to do it. Security people call this harvest now, decrypt later. It’s the harvest part that matters right now, years before decryption becomes possible at all.
An honest disagreement about the threat date
Nobody actually knows when a cryptographically relevant quantum computer, one capable of breaking the encryption protecting most of the internet, will exist, and it’s worth being upfront about that rather than glossing over it. A 2024 survey of 47 experts by the Global Risk Institute put the odds at roughly one in four by 2030, rising to about one in two by 2035. Some in the field think even that’s too aggressive. The venture firm a16z’s crypto team has argued publicly that we are nowhere near a machine capable of this, pointing out that breaking RSA-2048 would need hundreds of thousands, plausibly millions, of highquality physical qubits sustained across extremely long computations, several orders of magnitude beyond anything in a lab today, and that raw qubit counts thrown around in press releases are a poor proxy for that kind of sustained, fault-tolerant computation.
Both sides make a fair point. Progress has been faster than sceptics expected in places: Google’s own research in 2025 cut its estimate of the qubits needed to break RSA-2048 by roughly twentyfold, and the company has since moved its internal migration deadline forward to 2029 as a result. IBM is targeting a machine with more than a thousand logical qubits in the early 2030s. None of that amounts to proof the threat is imminent. It’s evidence the estimate keeps moving in one direction, and rarely the reassuring one.
The part that isn’t up for debate
But the disagreement above matters less than it first looks. Whatever year a working quantum computer eventually arrives, everybody, sceptics included, agrees that migrating a large organisation’s cryptography away from vulnerable algorithms takes something in the region of five to ten years. New standards need adopting, systems need inventorying, vendors need to catch up, and testing has to happen without breaking things that currently work. That migration runway is fixed regardless of which side of the quantum debate turns out to be right. If the threat arrives in 2030, an organisation that starts migrating in 2026 is in reasonable shape. An organisation waiting for certainty before acting isn’t, because certainty was never going to arrive before the runway ran out.
That’s why the NCSC’s phased approach doesn’t hinge on predicting Q-Day at all. It’s a migration plan with a fixed multi-year duration, backed into a target date that leaves enough room for standards, tooling and vendor support to mature properly rather than being rushed. Most of the CTOs and CISOs I talk to treat quantum as a problem for some future version of themselves to worry about. The organisations already moving, and it’s genuinely the more cautious institutions leading here, aren’t betting on a specific arrival date at all. The G7 published a coordinated roadmap for the financial sector at the start of 2026. The Bank of Israel has told its banks and payment providers to submit formal quantum-transition plans. The EU’s own coordinated roadmap requires national inventories of vulnerable systems by the end of this year and full migration by 2035. These aren’t organisations known for chasing speculative technology trends. They’ve simply done the arithmetic on how long migration takes and worked backwards from a deadline they’d rather not test.
On the harvesting question itself, I want to be careful not to overstate the evidence. There is no public, confirmed case of an intelligence agency or criminal group successfully decrypting old stolen ciphertext using a quantum computer, because no such computer yet exists to do it, and passive interception of encrypted traffic leaves no log for anyone to later discover. What is documented is the infrastructure such an operation would require. Bulk interception programmes tapping transatlantic fibre have existed and been publicly disclosed for over a decade. Largescale rerouting of major internet traffic through third countries, the kind of event that would let an adversary copy encrypted data in transit, has been observed more than once in the past several years, entirely separate from any quantum motive. That doesn’t prove harvest-now-decrypt-later is already happening at scale. It does show the mechanism for it exists and has been used for other things, which is why the NCSC treats the assumption as a prudent one rather than a speculative one, particularly for any organisation holding data that needs to stay confidential for a decade or longer: health records, long-term contracts, defence and financial information.
The second clock, running in plain sight
If quantum risk is a slow-burning, debated future threat, the second clock worth your attention is neither slow nor debated. It’s happening on your network right now.
Verizon’s 2026 Data Breach Investigations Report, one of the industry’s most rigorously assembled annual studies, found that the share of employees regularly using AI tools on corporate devices tripled in a single year, from 15% to 45%. Two-thirds of that usage runs through personal accounts, entirely outside anything a security team can see or govern. Across the hundreds of thousands of AI-related data-loss events the report analysed, the single most common category of information uploaded to unauthorised AI tools wasn’t customer records or marketing copy. It was source code.
Nobody involved in that statistic thinks they’re doing anything wrong. An engineer pasting a function into a free AI assistant to debug it faster isn’t trying to leak intellectual property. They’re trying to finish a task before lunch. The effect on the business is identical either way: proprietary code, the thing that in many organisations is the actual product, leaves the building through a channel nobody approved, monitored, or even necessarily knew existed. It’s the same mechanism that made the 2023 Samsung incident, in which engineers repeatedly pasted confidential source code into a public AI tool, a cautionary tale rather than an isolated mistake. It has simply become far more common since.
Outright AI bans don’t really solve this. They mostly just push the same behaviour onto personal devices nobody can see at all. What actually works is building a genuine inventory of who’s using what, for which categories of data, and putting fast, sanctioned alternatives in front of people before they reach for their own. Some evidence suggests unsanctioned use falls sharply once a good, approved option exists. That’s a far more tractable problem than quantum computing. It just needs someone to decide it’s worth solving before the next Samsung moment happens on their own systems.
Two very different clocks, the same lesson
Quantum risk and shadow AI could hardly be more different in character. One is a slow, genuinely uncertain, long-horizon threat that rewards patient, structured migration planning. The other is an immediate, entirely mundane behavioural problem that rewards fast, practical governance. What they share is this: not knowing exactly when either one becomes a crisis is not a reason to wait. Neither clock is going to pause while you make up your mind.
Arik Fletcher is a fractional vCTO, vCISO and vCIO working with organisations across financial services, healthcare, manufacturing and hospitality.
Sources: National Cyber Security Centre, Timelines for migration to post-quantum cryptography, March 2025; Global Risk Institute, expert survey on quantum computing timelines, 2024; a16z crypto, public commentary on quantum computing progress and cryptographic risk; Google Quantum AI, research on RSA-2048 resource estimates, 2025; G7 and European Union, coordinated post-quantum migration roadmaps, 2025 and 2026; Verizon, 2026 Data Breach Investigations Report, published May 2026; reporting on the 2023 Samsung source-code data-loss incident.

