The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Identity Thread by Entrust
The Identity Thread by Entrust artwork

Inside A Quantum Computer - The Race AI Is Speeding Up

The Identity Thread by Entrust · 2026-06-25 · 43 min

0:00--:--

Key moments - from our scoring

Substance score

53 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality10 / 20
Guest Caliber12 / 20
Specificity & Evidence13 / 20
Conversational Craft7 / 20

The quantum computing timeline is compressing faster than expected, driven by algorithmic breakthroughs and AI-accelerated research. Google and Caltech recently reduced the qubit requirement for breaking modern encryption from 1 million to 10,000 qubits through algorithmic optimization - shifting cryptographic vulnerability from a decade away to potentially the early 2030s. Michael Kleiman (Entrust) and Haran Gharibian (Blue Cubit CEO, quantum physicist from Stanford) explain how AI is amplifying this acceleration: AI workflows automate quantum algorithm design, researchers have already reverse-engineered Google's improved Shor's algorithm circuit using AI agents, and large language models are proving hard mathematical conjectures at superhuman speed. Simultaneously, organizations rushing to deploy autonomous agentic AI systems face expanding attack surfaces, identity management designed for static human users, and adversaries using AI to discover zero-day vulnerabilities at scale. The episode targets enterprise leaders and security teams who must understand the interconnected risks: post-quantum cryptography adoption timelines (NIST says 2030, Google says 2029, expected White House executive orders will accelerate further) and the immediate need to secure AI agents operating in production environments.

Key takeaways

  • →Google's recent algorithmic improvements have compressed the timeline for cryptographically relevant quantum computers from 10+ years to potentially 2029-2030, with AI playing a key role in this acceleration.
  • →Organizations must transition to post-quantum cryptography for key exchange and digital signatures by 2029 (per Google's timeline) or 2030 (per NIST guidance), with expected federal executive orders mandating faster adoption for government agencies and suppliers.
  • →AI is being actively used to reverse-engineer and improve quantum algorithms, with researchers using AI agents to improve Google's Shor's algorithm circuit further within weeks of its theoretical publication.
  • →The deployment of autonomous agentic AI in enterprises requires fundamental rethinking of identity and access control systems beyond traditional static security models to handle ephemeral, conditional, and policy-driven access.
  • →The convergence of AI and quantum creates a dual threat where AI accelerates both offensive vulnerability discovery and quantum computing advancement, intensifying the cybersecurity threat landscape simultaneously.

In this episode

  1. 1The Quantum Computing Landscape and Recent Advances
  2. 2How AI is Accelerating Quantum Development and Algorithm Design
  3. 3Timeline Compression: From Theory to Cryptographically Relevant Quantum Computers
  4. 4Post-Quantum Cryptography and the Race Against the Timeline
  5. 5AI-Driven Cybersecurity Threats and the Evolving Threat Landscape
  6. 6Identity and Access Management in an AI and Quantum Era

Mentioned

EntrustBlue CubitGoogleIBMQuantinuumMicrosoftAmazonOpenAINISTStanfordAnthropicShor's algorithm

Guests

Michael KleimanHaran Gharibian

Topics in this episode

Agentic AIZero-knowledge proofsPost-quantum cryptographyRSA encryptionShor's AlgorithmElliptic Curve Cryptography (ECC)IBM quantum computingGoogle WillowQuantinuumBlue Cubit

Questions this episode answers

How much closer is a cryptographically relevant quantum computer now compared to previous estimates?

Recent algorithmic improvements by Google and Caltech reduced the qubit requirement for breaking RSA and ECC encryption from 1 million qubits to 10,000 qubits. While cryptographically relevant quantum computers don't yet exist, they are now expected in the early 2030s rather than 10+ years away, compressing the timeline substantially.

What is post-quantum cryptography and what are the adoption deadlines?

Post-quantum cryptography uses quantum-resistant algorithms to replace RSA and ECC before quantum computers can break them. NIST guidance calls for transitioning by 2030; Google accelerated this to 2029. A White House executive order expected in summer 2024 will likely push federal agencies and suppliers to transition even faster, particularly for key exchange and digital signature systems.

How is AI speeding up quantum computing development?

AI automates quantum algorithm design and optimization through agentic workflows, reducing what takes human researchers months into days. AI agents have already reverse-engineered Google's quantum Shor's circuit and improved it further. Large language models are also solving hard mathematical conjectures needed to discover new quantum algorithms, lowering barriers to quantum research participation.

What cybersecurity risks come from deploying autonomous AI agents in enterprises?

Agentic AI expands attack surfaces and requires dynamic, conditional identity and access controls instead of static systems built for human users. Identity systems today lack visibility and scale for ephemeral agent identities. Concurrently, adversaries use AI to discover zero-days and build exploits at scale, creating an AI-driven security arms race.

What are the two ways cryptography is used in the systems affected by post-quantum transition?

Key exchange (like securing credit card data in transit on Amazon using RSA or ECC) and digital signatures (used in DocuSign, identity cards, code signing for software like Microsoft PowerPoint, and verifying software authenticity). The expected executive order targets both for faster transition in high-assurance systems.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

Gharibian delivers several genuinely useful insights - qubit reduction from 1M to 10K, AI agents reverse-engineering unpublished quantum circuits, and a concrete 6-month AI capability leap on an in-house benchmark - but Kleiman's contributions are largely framework-level repetition and the host generates filler throughout.

going from million qubits, requiring only 10,000 qubits, that is, has been quite a big deal in the media. But we don't have really quantum computer even with 10,000 qubits. But uh, but those are computers we can actually see how to build in the next few years
Group of researchers with uh, AI agents actually reverse engineered the circuit and then published it. And in fact they kept running the AI workflow and improved the circuit even more

Originality

10 / 20

The AI-accelerating-quantum-algorithms angle and the specific anecdote of AI agents improving an unpublished Google circuit are genuinely fresh; however, the cybersecurity half of the episode recycles standard zero-trust framing and well-worn 'cryptographic agility' talking points without adding new angles.

Group of researchers with uh, AI agents actually reverse engineered the circuit and then published it. And in fact they kept running the AI workflow and improved the circuit even more so like the depth of the circuit resource requirements, they were even further improved
AI workflow. I think one of the technical terms is auto research coined by Kurt Pathy

Guest Caliber

12 / 20

Gharibian is a legitimate practitioner - Stanford quantum PhD, active Blue Cubit research published alongside Google and Quantinuum teams, working hands-on with the best available hardware - but Kleiman is an internal Entrust employee functioning as a vendor spokesperson rather than an independent practitioner, dragging the overall caliber down.

a theoretical physicist by training who earned his PhD from Stanford where he specialized in quantum computing and black hole physics
we published an article last year along with teams from Google, Continuum and others of this like class of solutions called scientific quantum advantage claims

Specificity & Evidence

13 / 20

Gharibian provides concrete numbers (1M vs 10K qubits, IBM's $10B over 5 years, NIST 2030 vs Google's 2029 deadline, named algorithms ML-DSA/ML-KEM/SLH-DSA) and a verifiable AI circuit-reversal anecdote; Kleiman's portions are less evidenced, relying on illustrative analogies rather than data.

going from million qubits, requiring only 10,000 qubits
the NIST standardization of the first three post quantum algorithms, mldsa, ML, Chem and slhtsa, that happened um almost two Years ago

Conversational Craft

7 / 20

The host asks broad, open-ended questions and adds little intellectual pressure; there is no meaningful pushback on any claim, no probing of timelines or uncertainty estimates, and the wrap-up is purely affirmatory - Kleiman as an internal guest makes the format closer to a branded explainer than an interview.

Can you talk a little bit, just a little bit about what your company's doing
Well, yeah, it seems like, you know, maybe it sounds crass in this conversation, but it's a budget problem, right?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B49%
  • Speaker C37%
  • Speaker A15%

Most-used words

quantum107algorithms33systems23computers21post19organizations18cryptography17today16cryptographic14problems14important12computing12computer12google12cryptographically12infrastructure12

Episode notes

In this episode, Hrant Gharibyan, CEO and Co-founder of BlueQubit, and Michael Klieman, Global VP of Product at Entrust, explore what it really takes to build a quantum computer, how AI is compressing the timeline, and why organizations must rethink trust, identity, and post-quantum cryptography now. Because as AI accelerates, so does the need for quantum-safe foundations.

Full transcript

43 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: For years, cryptography has been at the foundation of digital trust, protecting everything from email to data to devices, talking to each other. AI doesn't change that. In fact, it makes cryptography strategy more important than ever. That foundation is now under pressure and you know what comes next. Let's say it together. Quantum computers are going to break traditional encryption in the next five to 10 years. You've probably heard that one before, right? But here's what's new. AI is accelerating, getting more capable and more autonomous. And it's being deployed in more innovative ways, like accelerating progress in quantum computing and compressing the timeline to that future where today's encryption may no longer hold. In other words, AI innovation is helping to break the cryptographic systems that enable trust in AI systems. So it's time for every leader to get a handle on the fast approach and reality of quantum computer advancement. And what does it mean for the way we secure AI driven systems? Hi, I'm Ken Cadet and this is the identity thread. Today we're joined by Michael Kleiman from Entrust, one of our leading experts on AI security and post quantum cryptography solutions. Welcome back to the podcast, Michael.

Speaker B: Great to be back Ken.

Speaker A: Thanks. And we are pleased to welcome a special guest today, Haran Gharibian, CEO and co founder of Blue Cubit. Harry Harant is a theoretical physicist by training who earned his PhD from Stanford where he specialized in quantum computing and black hole physics. At ah, Blue Qubit, he is helping customers envision how to map real world enterprise problems into the quantum paradigm, pushing the boundaries of what today's quantum hardware can solve. So hrat, welcome to the podcast. We're really happy to have you here.

Speaker C: Thank you Ken. It's super exciting to be here and looking forward to the conversation.

Speaker A: Well, thanks, uh, same here. Um, so let's try to set the scene. Um, there's a lot of talk about quantum computing, maybe not as much understanding. Um, uh, Mike, uh, we're getting a lot of signals from out in the market. What's going on right now, Michael, uh, help us set the scene and level set on what's happening in quantum today.

Speaker B: The thing that's in the news a lot is advances by Google, um, the investment by the U.S. federal government, uh, into quantum computing. I think a $2 billion investment. A billion just uh, I.B. um, uh, quantinium is going public. Uh, so I think Harad, what's behind all that?

Speaker C: Yeah, I'm happy to share a bit about the progress. I think there's like to make quantum computing like a trillion dollar Industry.

Speaker A: Right.

Speaker C: That's relevant for enterprises. There are two aspects. One is to build quantum computers and second to figure out how things we're going to be running on quantum computers. Um, one of the very famous algorithms that we already know for a few decades is Shor's algorithm that for breaking cryptography. I think there has been some uh, progress recently that got a lot of publicity from Google team and Caltech team. Actually two separate papers in terms of reducing the algorithmic requirements for breaking modern encryption. Uh, just purely uh, from algorithmic optimization point of view, going from million qubits, requiring only 10,000 qubits, that is, has been quite a big deal in the media. But we don't have really quantum computer even with 10,000 qubits. But uh, but those are computers we can actually see how to build in the next few years. So I think that that has created a lot of uh, worry from cybersecurity point of view because we thought like 1 million quantum computers that will be cryptographically relevant are like 10 years away now. I think that timeline has been moved substantially. We still can't exactly predict it. Right. Because there's competition, there's some enterprises building it, there's like university teams building quantum computers. But the capabilities of quantum computers are also advancing quite rapidly. And um, that is the part that I think people who are afraid of the cryptographic risk, um, um, have trouble following because there's a lot of nuance. Uh, there's various modalities of different ways to build a quantum computer. Like superconductors that Google and IBM build like neutral atoms and trapped ions is like how we use atoms with lasers and make qubits out of them. Uh, but the field is steadily progressing and indeed government investment is a big push as well. Recently announced to some of the top quantum companies. IBM. Actually I was at an IBM event in Madrid last week giving a talk about some work we do with them. They announced 10 billion investment in the next five years. So they're really serious about scaling up the infrastructure and fabrication for quantum. And um, to add to all of this is AI helping scientific research. Quantum computing is probably one of the most important scientific areas that's going to have biggest disruption uh, to tech and compute. And that timelines indeed are affected by the ability of AI models to uh, improve quantum systems like from calibration to design of those quantum systems, all the way to like optimization and algorithms, like coming up with the good algorithms that run on quantum computers. Yeah, so there are a lot of moving pieces, but there is a Like a lot of top teams in the world are building consensus that there's a very like, like high chance we will have large scale quantum computers like um, in the, in the early 2000-30s and that is really uh, important for various use cases. We're running quantum computers as well as cryptographic risks that comes with.

Speaker A: Your company's really working on making um, creating the ability to use quantum computers when they're here or when they're here in a production scale way. A ah, practical reality. Can you talk a little bit, just a little bit about what your company's doing and um, what's driving your optimism that this is going to be a big deal? Um, uh, relatively.

Speaker C: Yeah, a great question. So we are focusing on the two problems. One is to build the right scale quantum computer and figure out what we're going to run on those computers. Uh, and we are focused on the second one. So we are like a frontier lab, like looking at quantum algorithms, testing those algorithms in best quantum computers in the world such as IBM systems, Quantinium systems, um, QRS systems which are like different modalities of quantum computers that are the best systems in the western hemisphere in terms of capabilities of quantum computers. And one of the specific things we work on is quantum uh, advantage. So like we are in the search of problems where quantum computer can solve a problem within hours that even largest classical supercomputers that are worth like 100 times more money, like consume a lot more energy, cannot solve even if let it run like many years. So we published an article last year along with teams from Google, Continuum and others of this like class of solutions called scientific quantum advantage claims where we identify interesting problems where we solve with a quantum computer and there's no known classical way to solve it even with AI and largest supercomputers in the world like Frontier or Colossus. And that is a very new frontier, uh, where we show that quantum computers have uh, some strong power relative to classical computers for certain problems. And you know, cryptographic problems are one of those classes actually. Shor's algorithm has been known for a very long time. We have proposed a much more near term like cryptographic Anzas, that even current quantum computers can actually show this big gap, quantum versus classical to find the secret key. And um, yeah that is what our focus in and our team is composed of primarily like PhDs and quantum algorithms and engineers who build all the software infrastructure to like test and benchmark these algorithms.

Speaker A: So um, how do you guys look at um, the cybersecurity implications of that so obviously there's insanely important work going on with um, that's going to be happening on quantum computers. Um we know that, we know that there may, that the quantum computers may be breaking today's encryption. There's a transition, I think everybody acknowledges it has to happen at some point soon. Um, but maybe talk about like how the, how these things work together.

Speaker B: Yeah, the interesting thing is where uh, where we're seeing in the market um, uh acceleration of investment in quantum. Sorry Haran, you said um, uh how much was IBM uh investing in quantum?

Speaker C: 10 billion in next five years.

Speaker B: That was 10 billion in the next five years. Right. A billion of that's coming from the US federal government. And um, uh we've got the uh, others that we just talked about. Um at the same time the expectations um, of advancing in quantum computing uh has a direct implication on um, the cyber security expectations as well. And so just not to take it for granted, the expectation is that um, uh eventually we will get to a point where there is what's called a cryptographically relevant quantum computer and that is a quantum computer that is sufficiently powerful to execute algorithms that can break today's conventional cryptography. RSA and ECC being the algorithms in particular that are most at risk and um, upon which all of global infrastructure depends uh, today. Right. And so the notion of shifting to quantum resistant algorithms or post quantum cryptography is the, is the offshoot of that um, the, the expectation that organizations, I think that um, the organizations that are at ah, the head of the quantum development end of things are saying is there is progress here towards a cryptographically relevant quantum computer that is faster than what we thought before. And so there have been a couple of things that have happened just in the last couple of months. Um, Google um, has uh, in parallel with um, a number of announcements that they put out related to their advances in quantum computing have also put out um, essentially their call to the industry to say um, bring in the timeline from what NIST established and what um uh what NSA had established, uh at least in the US markets um for when organizations should make the uh, make the shift to post quantum. The core timeline is really starting in 2030 is when uh, the NIST guidance basically uh says organizations um should be making the uh, they should have made the shift to post quantum cryptography for new applications uh and starting the transition of um, cryptosystems to post quantum algorithms uh in that timeframe. With Google's announcement earlier in the year of their advances in quantum, they've basically said um get it all done by 2029. Right. And that's what they are trying to do. And uh, and Google doing that is is pretty uh massive because Google operates a huge portion of the Internet. Uh they're massive technology influencer, um uh where they're not just a vendor, right they are at the core of um uh core Internet technology that we all depend on. The other uh recent uh announcement is this uh isn't finalized yet but uh um there is an expectation that there will be a new executive order put out by the White House uh this summer, uh that accelerates the timelines and the requirements of agencies across the federal government uh and their suppliers to make the transition to post quantum sooner than the NIST guidance. Um that was just published uh 18 months ago. Uh and that takes a couple of different forms. There are two basic uh ways in which uh cryptography is used um that are relevant to um the shift to post quantum. The first is key exchange. When you're going uh to Amazon, uh uh to buy something uh from Amazon you want your credit card information uh secured in transit. Um the way in which that is protected is with essentially a first step and that is exchanging cryptographic keys. That first step is secured with RSA or ecc. Um so the first thing is making the transition of those systems to using uh post quantum algorithms. The other uh is for digital signatures. Digital signatures are used all over the place. It is what it sounds like. Digital signatures can be used um for example with DocuSign or with applications that involve um a uh contract of some sort. Um but this is also what underpins ah an individual identity. If you have a um, uh cryptographically based access card, uh that has a digital signature in it that says hey it's Ken Cadet who's uh swiping into the building. Uh that's a technology that's used extensively um in high security environments. Um uh digital signatures are also used to secure code. Um so when uh um Microsoft uh publishes uh the next version of PowerPoint, uh and they make that available for download, um uh that application um is protected with a digital signature so that everybody who's installing uh a copy of UH PowerPoint, UH can actually cryptographically verify that it is the legit version and not a hacked version of uh that application. Those two um uses uh, of cryptography, key exchange and um digital signature basically are the subject of the executive order that's expected to come out and essentially say uh for high assurance systems, uh um make that shift faster. Um for uh the scope of Organizations that are subject to the executive order, it is not just the agencies of the federal government but any of their suppliers. That will be a huge change uh, if that executive order comes down. That is really being driven by acceleration in quantum. We're seeing uh, progress um, in quantum computing. Uh, and I think part uh, of this conversation and where it gets super complicated and where all of these technologies are coming together at the same time is the advancement in AI, right? Because I think, and I think it's harad you can talk about it better than I can. But um, how is AI being used in quantum systems to accelerate? That second thing that you said two things right, was one is uh, building the systems for themselves and the second is building the algorithms that sit on those systems. On that second piece, AI can be used to accelerate and improve the algorithms themselves. And that's where there's increasing concern I believe on um, that technology scaling up as well to um, improve and shorten the timeframe by when um, uh, cryptographically relevant quantum computer that's executing Shorj or another algorithm, uh, can break current cryptography.

Speaker A: What are you seeing in that space, in that space of AI driving quantum development?

Speaker C: Yeah, yeah, it is actually super exciting area like uh, BlueCubit has several projects uh, in this area as well that will put out those papers soon. And essentially one of the key things, there's a lot of automation of research that AI can do and that will really speed up of a lot of heuristic design of new novel algorithms, testing of those algorithms. So something that would take you like a um, normal group of researchers like six months to test and come up with the idea AI workflow. I think one of the technical terms is auto research coined by Kurt Pathy. Uh, he is um, essentially a lot of research problems that are heuristic can be accelerated with the right agentic workflow. And we are actually doing a lot of testing and seeing some great results in terms of like speeding a lot of innovation. On algorithm side, there's one example actually publicly known that is an interesting example related to the Google's paper. So when Google published their um, improvement to uh, quantum Shor's algorithm that breaks cryptography, they didn't actually publish the full quantum circuit because of security reasons. They used what's known as zero knowledge proof so they can like validate to the community that they have it, but they don't actually publish the circuit. Group of researchers with uh, AI agents actually reverse engineered the circuit and then published it. And in fact they kept running the AI workflow and improved the circuit even more so like the depth of the circuit resource requirements, they were even further improved. This happened in the past few weeks and uh, we're going to see more and more of this. I think that is the part that is kind of uh, uh, worrisome that people who are in the field are also are not very good at predicting exact timelines. Like things in progress happen faster than we anticipate because of the non trivial ways AI is being used. One of them is this heuristics, uh, designs of algorithms like compiling of quantum circuit which is uh, very similar to a lot of other problems that AI is good at like protein folding where you look at a lot of pattern and make good guesses. And then there's another dimension of solving mathematical problems with AI. There was a big um, quite important problem recently being solved by OpenAI's latest model. I think that is creating a lot of consensus from serious mathematicians that AI is becoming remarkably good at proving uh, really hard mathematical claims and conjectures or proving and disproving. I think the next problem people are going after like new types of quantum algorithms. So we have a list of quantum algorithms that like for optimization, for cryptography, for others. But it's still, it's in infancy in terms of scale. I think AI is going to speed it up. You will need just fewer researchers and AI, uh, assistants to find new types of algorithms. So I expect to see more of that as well. Some of it probably from our team, others from IBMs and Googles and academic teams. Uh, it is actually a really exciting time for the AI for science and quantum is one of the most important scientific areas and specifically in the mathematical aspects like algorithms, heuristics. Uh, I think there's going to be a lot of progress and we see the first signals in the past few months. Uh, but I think there's going to be more of that. And it's really hard to predict exact timelines as AI models are also improving in parallel. So their capabilities like you know for one of our algorithmic challenges we tried it with one of the standard AI like reasoning models and it was really bad. At six months later it like outperformed a human solution. So we like clearly see it just crossed within the six months to a regime where it's really doing better than like the, the best researchers are. I think it's going to continue this trend. Um, and yeah in algorithms I think it's ready to go. Right. Like a lot of teams, including this team who reverse engineers Google circuit, um, can right away. Those are open reasoning models. They're not open source, but they're open to any users who has the budget for using them. Um, uh, and I think that's going to actually enable a lot of people to be at the frontier of research where in the past you needed to have this body of knowledge, like Learned and doing PhD. I think like AI is kind of removing a barrier to innovation. Um, and that's, I think is going to draw more people into like many scientific fields, including quantum, like algorithms, quantum computing research.

Speaker A: Yeah, yeah, it definitely makes sense. And I know certainly across organizations, enterprises, um, the drive to adopt AI and adopt, um, agentic, more autonomous agentic AI, um, is just, you know, expanding dramatically. Maybe not quite as complex as some of the mathematical things you're talking about, but the drive is there all over the place. Um, uh, Michael, as this happens, um, obviously two massive things happening kind of, kind of in parallel, but kind of, you know, crossing the streams, um, as well. Why should we think about AI and quantum together? Uh, is it, you know, is it a little bit from the security standpoint? It's a little bit from the sort of, you know, developing the, developing the enterprise standpoint. How do you, how do you see it?

Speaker B: First off, I love the crossing the streams for those of us who's always welcome. Exactly, who remember it when it came out in the theaters. The reality is there there are multiple streams that are going on at the same time. Right. Um, so, uh, take what you just said, Ken, which is organizations adopting agentic AI faster. Um, what are the implications of that? Uh, and this is not in the quantum space. This is just in general is, um, twofold. One is, uh, you have to ask the question of how do I secure the agents inside my environment? Um, you have to ask the question of how do I actually get a handle on, uh, ensuring that the um, that the attack surface that is being created by deploying agents, uh, is also secure. Right. Uh, and then that gets to do. I understand where all the agents are and how they're being secured and what the policies are associated with that. Um, I think we're seeing, um, uh, we're seeing with uh, those problems, um, the weaknesses in the current cybersecurity infrastructure, um, that everybody, you know, relies on today. Right. And that is, um, the identity systems that exist today, um, they are more static, uh, in terms of how they operate in general than how they really need to with agents. Particularly if you imagine an agent that has, uh, autonomous capabilities and is um, able to discern and determine. Here's the next resource that I need to get access to authorization decisions, um, access decisions are no longer static, things that are determined up front. We're talking about conditional access and policy driven access which um, requires a rethink around how do I do security in the first place? Um, organizations need um, greater visibility into here's where all of these identities and where the agents uh, are operating, uh, inside their environment as well. And for the most part the systems that have been built today to secure human identities weren't necessarily built to scale, uh, to handle uh, the scope of um, both a much larger base of agents plus the notion that identity um, is ephemeral, it is limited and it's temporal, um, uh, it's conditional. Um, those systems um, uh, weren't built to deal with um, that complexity. At the same time it's not just about uh, the agents themselves. Uh, it is the attack surface. Uh, and the threat landscape has changed massively because of the introduction of AI. And this is where Anthropics, uh, Mythos and Project Glasswing have come into play. And that is hey, we can take uh, AI, uh to um, apply it to the problem of can I detect vulnerabilities in software that's been deployed, um, that have been previously undetected. Now they have set after that problem, um, from the standpoint of essentially a white hat hacker. Uh, and that is to identify those vulnerabilities, those zero days and to inform uh, the publishers uh, of that software. Hey, here's the vulnerability that we found. Go and look into it, validate it and then go and put out a fix for that as quickly as possible. Um, that's the good news. The bad news is bad guys are doing the same thing, right? And bad guys can do, where they use AI um to uncover uh, as of yet undetected vulnerability, uh to build up at scale the set of 0 days and then to use AI to build the exploits, um, what's the malware that uh, um, is published in order to take advantage of that vulnerability that they found and to commercialize it, to put it out into the dark web to sell those, you know, to sell those exploits to make money off of the execution of those exploits. Um, that's what uh, that's what the bad actors are doing. And that's a, that's an AI driven arms race, right? And that's uh, what, what's the implication of that for um, uh, for organizations everywhere is the threat landscape is intensifying, right? And the, whatever security controls you've put in place, you have to Take a look and say, hey, um, are they built for today's landscape? And you know, the notion of shifting to zero trust, um, has been around for many years. And that is, you know, the tagline is uh, uh, uh, never trust, always verify. Right? And um, that takes a couple of forms, right? That is, um, uh, have strongest, you know, your strongest identity and your strongest level of data protection. How you know, what's the gold standard in both of those is using cryptography, right? Is, uh, encrypt your data, encrypted at rest, encrypted in motion, encrypted in use and use cryptographically based identities, um, that are um, much harder to uh, compromise, um, by taking those couple of steps and it's much more complicated than two things and then you're done, right? That is across every application that you've got and all of your infrastructure and all of your users, um, machines and humans, um, when you take those steps, you're better positioned securely for dealing with the uh, threat landscape at any time. But particularly now, um, as you have agent and AI based attacks occurring, um, the shift to cryptographically based data protection, cryptographically based identity, um, is much more of a necessity than it's ever been. Now couple that with. Okay, do I have a handle on where all of those cryptographic uh, assets are? Uh, just like I have the problem around where all the agents inside my environment, environment and where we started the conversation, the fact that uh, we're at a point in time where the timelines for shifting, what are the cryptosystems that you're using are accelerating to say, hey, I've got to make the shift to post quantum, uh, sooner rather than later. This is a very complicated area for organizations, uh, to figure out. How do I juggle all of those balls at the same time?

Speaker A: Well, yeah, it seems like, you know, maybe it sounds crass in this conversation, but it's a budget problem, right? I mean you're putting all this money into AI. You can't use cryptographic identity. That's going to be out of date in a couple years.

Speaker B: Well that's absolutely right.

Speaker C: To add kind of to your point, Ken and Michael is like, also the timing is great. We're building all this AI infrastructure from scratch and I think being uh, like mindful of what kind of security and PQC algorithms, uh, like cryptographic primitives we want to use because in some fields there's like a whole infrastructure that needs to be rebuilt. Here we're building from scratch and actually being quantum aware With a few year time horizon versus a decade I think is pretty important and the timing might be good for that. I think uh, the fact that Google is spearheading it and they have a big influence in tech I think is encouraging that others will follow suit um, in this direction, um, and actually build AI infrastructure that uses cryptographic primitives that are quantum post quantum secure. And luckily NIST has standardized this from 2024 already. We have uh, for various use cases, uh, standard primitives that are quite reliable and well uh, tested through NIST process. Um, and yeah, it was actually great to hear from um, Michael. There's a announcement to accelerate requirement to transition which is I think quite important since last one was two years ago and it's outdated with the recent scientific progress in quantum hardware and both algorithmically and hardware scale.

Speaker A: Maybe just to summarize a little bit like what does a modern quantum ready trust architecture actually look like from your point of view?

Speaker C: I think in terms of quantum uh, readiness. Yeah, like great question. I think like luckily many organizations are moving in that direction and there are two aspects. One like being aware of quantum hardware's progress and capabilities currently and roadmaps to the next capabilities in the next few years. So for that you need to have a quantum team that's working on a frontier of algorithms, collaborating and partnering with the best vendors in this area. And there are organizations like in financial institutions, in pharmaceuticals, in defense already building up quantum capabilities to understand what are the high value applications, what is the stock, what kind of hardware they will need and um, is current hardware most for research, what kind of hardware will be needed to actually solve mission critical or uh, commercially high value problems. And those are kind of quantum applications teams within those um, enterprises. And then the other side, if you are bullish about the capabilities of quantum progressing and taking advantage of that is the cybersecurity preparation. Because I think that starts to pose a lot of commercial. The scale where commercial applications of quantum computers become viable is around the time that they also start to become cryptographically relevant. So you have to revisit what kind of risks this opens for you in terms of like cybersecurity and infrastructure that you rely on and you assume it's safe. I think Michael perhaps can address that better than I do.

Speaker B: No, I think you hit the nail on the head and uh, I'll maybe hit it from a just slightly different angle and you brought it up Ken. And that is um, this is about budgeting, right? And this is about what are the priorities that you've got related to cybersecurity. And I think when you take a look at the threat landscape is increasing, um organizations are racing to figure out how do they transform themselves and stay competitive in a world where everybody's looking at how can I use uh agentic AI effectively to transform my organization. And that creates a whole new set of um requirements related to security. And at the same time you've got an accelerating timeline related to uh advances in quantum computing and advances um for all the reasons that we just talked about in the algorithm development of um, what can potentially break uh, and what will eventually break today's conventional cryptography. Like the, the priority that organizations really need to um ask themselves and that where do they put their money when it comes to their cyber defenses is do you have the right um, do you have the right um, uh amount of focus and the right uh cryptographic and not just cryptographic but the right trust foundation and right trust fabric that underpins your cybersecurity strategy? Right now you definitely hear from me and uh, uh I believe it is the use of cryptography is 1 uh in each one of the use cases that we've talked about. This is the gold standard in terms of um, here's how you deploy uh, the best crypto defense or the best cybersecurity defenses inside of your organization. So uh, the reality is that organizations in my experience have not writ large and this is not true for certain sectors and for certain individual companies but writ large organizations haven't taken a uh first principles look at what is most important in terms of my cybersecurity foundation because if they did decisions around use of cryptography would not be distributed to an individual development team, uh to an individual marketing team that's spinning up a server, uh to um, here's an infrastructure team in terms of uh how they are choosing to architect their systems. You would have an intentional view of I want to apply cryptography first. Uh, I want to apply that zero trust uh architecture um and that is uh around encrypting data and that is making um my identities uh cryptographically based. When you start to think about that organization wide that that's about your trust fabric. Right? And uh, that also incorporates the you know the notion of uh agility and um, how easy or how hard is it for me to update those systems as the algorithms uh and as the requirements change. Harad said it, you know the nist, um uh the NIST standardization of the first three post quantum algorithms, mldsa, ML, Chem and slhtsa, that happened um almost two Years ago. Uh, there are two others in the pipeline and there is a whole other um, uh, series of algorithms that are being tested today. Because the reality is um, the approved algorithms are ones that have been undergoing cryptanalysis for the last eight to 10 years, unlike RSA and ECC which have been in practice for 50 years. And they have stood the test of time and they have stood the test of cryptanalysis over that time frame. These new algorithms, uh, they are the best ones that uh, the world has come up with um, to defend against uh, future uh, cryptographically relevant quantum computer. But um, the, the expectation that organizations should have is what's my post post Quantum uh, algorithm strategy, uh, and that gets to cryptographic agility and what is that trust fabric that I've got underpinning my organization?

Speaker A: Absolutely. So you're going to have to do it once and you may have to do it a couple more times after that.

Speaker B: We take anything out of what we're seeing is the pace of change. Ah, and the advances in technology are so great, it's happening so fast that if you think that you know, here's the thing that I'm putting in place and it is going to last me forever, you know, that that is definitely uh, uh, I think a bad assumption. And uh, assuming that I've got to make change, assuming that I've got to strengthen my security um, at all times, like how do I do that? What is the gold standard? Because I'm going to keep pushing uh, harder and harder towards that as um, the attacks get worse and as the requirements start to increase. I think that's the reality that organizations need to address.

Speaker A: We'll just wrap up with one last question. So if for some reason they put me in charge of driving change, in driving uh, our quantum transition, um, as well as in charge of let's say accelerating our AI adoption, um, what should I be doing? What's one thing I should be doing differently? Karat, let's start with you.

Speaker C: Yeah, I think the main thing is to have a plan like at least for the next five years, uh, like hopefully longer. I think having a strategy like assuming the current development proceeds with the current pace of quantum devices. I think understanding what are the high value problems that's going to be completely disrupted by quantum computing. I think it's one of the most important question because in some industries those problems are not very many of them and or they're not very high value in others it will completely change the way they do R and D, or completely change how they design and Test their products uh using quantum simulation or quantum optimization. So having a good understanding of those problems and having a strategy around how we're going to be ready for that moment where quantum computer is announced by uh Quantinium. The next device will have this capabilities. And then the way to do it is to have a quantum team internally or working with the partners who are at the frontier, right? Quantum hardware players, quantum algorithm players who work with the most capable systems, who understand limitations and uh, opportunities different platforms bring. Um, and that's kind of quantum readiness for algorithmic point of view. I think uh, it's super important. And then attached to it is understanding the risks to cybersecurity and probably having a timeline to comply uh with the transition, uh, maybe soon there'll be actually a requirement, uh but even before it is a requirement, I think understanding uh, what it will take to transition, I think it's not an easy task. Uh in each industry, in each infrastructure it's a unique challenges that it comes

Speaker A: a lot of prioritization, a uh, lot of focus needed and Michael, I'll give you the last word.

Speaker B: The place where I would start is the following is um, you know, in, in the context of the shift to post quantum, one of the first things that uh has been recommended, and you won't get any argument from me, that discovery of where uh, what are all the cryptographic assets that I've got inside my environment, make sure I understand what they are. Then I can develop a strategy to uh, address them and then I can start implementing that strategy and then I can rinse, wash, repeat, um uh across my whole infrastructure. I think that general guidance is good. However um, uh, that guidance has been around for many years and I think we're at a stage where starting um to make the shift today uh to post quantum, where I can is the um. That is the most important thing and that um. That can take a couple of different uh, forms.

Speaker A: Right.

Speaker B: One is as I am introducing new systems and this was the. By the way, the, the guidance from NIST to begin with is hey, by 2030 any new system that comes online should be uh, using post quantum algorithms and then a longer time frame to replace all of the existing systems that are using RSA and ecc, um with post quantum algorithms. Uh, the one thing that I would advise uh, any organization is start doing that today. Right. Um, start, you know, uh, uh, don't wait on spinning up your post quantum pkis and uh, and start um applying post uh quantum algorithms to new applications. Your most uh, obvious new application that you're rolling out is going to be, where am I using agentic AI? What are the systems that they are, uh, attaching to start to build from there so that you are not sitting on a whole bunch of, um, cybersecurity debt as, uh, things proceed a whole lot faster? Um, that's where I would start to begin with.

Speaker A: Sounds like you've got my marching orders. And, uh, they are big. Uh, uh, but it sounds doable and it sounds like there's sort of an action plan in place, um, that folks should start to implement. So thank you. I appreciate it. It's a really interesting conversation, Ron. Really. Um, many thanks for being here, Michael. Uh, thanks for being here again, of course. Um, and, um, thank you all for listening to the Identity thread by Entrust. You can Explore more@ntrust.com Identity thread or search for that on the Internet. Um, subscribe for ongoing episodes and perspectives from leaders across the industry. And of course, reach out to us@identitythreadtrust.com, we'd love to hear from you. Our podcast was produced by Megan Gable and Stephen Damone. And if you like what you hear, I do encourage you to rate and review this podcast on Spotify, Apple Podcasts, wherever you get your podcasts. And do, um, check us out on YouTube as well. You can watch us have, uh, this conversation live as well. And thank you for listening. We'll see you next time.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Decision Logic: The Difference Between an Answer and a DecisionThe AI Forecast · on Agentic AI87 / 100
  • KYA Won't Always Protect You. The Real Risk Is the Swarm!Fintech Conversations & Insights with Efi Pylarinou · on Agentic AI86 / 100
  • Agentic AI in Sales: What Business Leaders Need to KnowScaling with AI · on Agentic AI86 / 100
  • EP284 Closest Alligator to the Canoe: How Transforming SOC Became P0 for Lloyds BankCloud Security Podcast by Google · on Agentic AI85 / 100
  • AI Is Ready for Government. Is Government Ready?The So What from BCG · on Agentic AI84 / 100
  • Beyond the Simplistic Narrative that AI will Replace Software with Mahesh RajasekharanSaaS Scaled · on Agentic AI83 / 100

More from The Identity Thread by Entrust

All episodes →
  • Modernizing PKI for the Agentic Enterprise
  • From Discovery to Deployment: Solving the PQ Timeline Compression Challenge
  • Know Your Employee: Securing the Workforce Against Fraud, Impersonation & Insider Threats
  • Why Identity Centric Security Is Essential
  • The Quantum Countdown and the Future of Encryption
Explore the best B2B Engineering & DevTools podcasts →
All The Identity Thread by Entrust episodes →