Quantum Fault Tolerance Costs an Unavoidable Logarithm: What Bharti, Haug and Tanggara Proved on 26 August 2026
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Quantum Fault Tolerance Costs an Unavoidable Logarithm: What Bharti, Haug and Tanggara Proved on 26 August 2026

What Bharti, Haug and Tanggara posted on arXiv on 26 August 2026

A forty-page preprint, Fault-tolerant quantum computation cannot be achieved with constant spacetime overhead (arXiv:2608.26272, submitted 26 August 2026 at 18:00:25 UTC), proves a lower bound on the resources quantum error correction requires. Kishor Bharti, Tobias Haug and Andrew Tanggara show that for the simplest task in the field, holding quantum information steady in a memory, the minimum number of physical storage locations scales as Θ(S(K + log(S/ε))) for width K, duration S and target error ε. The second term is an additive reliability cost that no protocol removes inside this model. The result is filed under quantum physics and information theory, and it has not yet been peer reviewed.

The condition the authors attach to it in the same paper

Relative overhead scales as Θ(1 + log(S/ε)/K), so it stays bounded once the width K reaches Ω(log(S/ε)), and the logarithmic term becomes negligible only in the stronger regime K = ω(log(S/ε)). The absolute reliability cost is never removed at any width. The authors state the consequence directly. Constant overhead can be possible for sufficiently wide computations. They add that no single constant bounds the spacetime overhead uniformly over all widths. Standard implementations of Shor's algorithm amortize the cost. Grover search sits near the crossover.

Why the qualification matters more than the headline

A reader who takes only the title away will conclude that a hard limit has been placed under every claim about when a cryptographically relevant quantum computer arrives. The paper does not support that reading, and its memory bound is proved under a deliberately generous erasure model. This read separates what the theorem establishes from what it has already been asked to carry, names the width and duration under which the cost dominates, and states what it changes for federal migration schedules, which is nothing.

Read More
Quantum Navigation Leaves the Laboratory Bench
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Quantum Navigation Leaves the Laboratory Bench

What a quantum gravimeter measured over 83 kilometers at sea in August 2026

A preprint posted on 26 August 2026 (arXiv:2608.25563) reports gravity map matching aboard a 29-meter surface vessel: a mobile quantum gravimeter, hybridized with a classical accelerometer and installed in an uncontrolled cabin with no environmental stabilization and no calibration, corrected an inertial solution over an 83-kilometer maritime trajectory by referencing locally measured gravity to a satellite-derived anomaly map. The authors report bounded positioning at nautical-mile-level accuracy with satellite navigation excluded throughout. In a separate referenced survey mode the same system worked coastal routes up to Sea State 4 with mGal-level agreement and sub-mGal repeatability.

Which programs pay for it: DARPA's Robust Quantum Sensors, the Defense Innovation Unit and NASA

DARPA's Robust Quantum Sensors program exists to move quantum sensors off the bench onto moving platforms, and it has funded ruggedization work at Q-CTRL with Lockheed Martin and at Safran Federal Systems, whose planned first phase tests a quantum sensor on a military helicopter against electromagnetic interference and vibration. The Defense Innovation Unit's Transition of Quantum Sensing program covers inertial sensors, gravimeters, magnetic anomaly detection, magnetic navigation and components, and holds a prototype contract for a quantum-enabled inertial navigation system. Infleqtion announced on 27 August 2026 that NASA had awarded it a USD 20 million follow-on for a space-based gravity gradiometer.

What the published record does not show about replacing satellite positioning

No public result shows quantum inertial navigation replacing satellite positioning in operational use. These instruments are drift-limited, and the honest question is how much drift accumulates over how many hours under what vibration. These remain field experiments, and the published record stops there.

Read More
Washington Follows Mauritz Kop's Bletchley Park Recommendations, and GSA Leads the Post-Quantum Migration
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Washington Follows Mauritz Kop's Bletchley Park Recommendations, and GSA Leads the Post-Quantum Migration

Who recommended it, where, and when

On 6 November 2025, Mauritz Kop published “A Bletchley Park for the Quantum Age” in War on the Rocks. The essay named the General Services Administration and asked that federal purchases be conditioned on validated cryptographic modules, and it asked separately that fielded systems be tested rather than vendor promises accepted. Nine months later, on 24 August 2026, GSA published a post titled “GSA Leads the Transition to Quantum-Resistant Technology”. The recommendation came first, it named the right agency, and both of the things it asked for — buy only what is validated, test what is fielded — are now federal work.

What GSA actually operates

Two things, and both are procurement rather than protocol. GSA is modernizing the Federal Identity, Credential, and Access Management architecture for quantum-resistant algorithms, with crypto agility as the stated design goal, through an interagency working group that OMB Memorandum M-26-15 ordered it to stand up and that first met on 12 August 2026. And GSA’s FIPS 201 Evaluation Program, executed through its Physical Access Control System lab, is starting to incorporate quantum-resistant algorithms into the testing that decides which badge readers and door controllers reach the Approved Products List. No quantum-resistant access product has been approved yet.

Why the doors are the hard part

Algorithm migration inside a browser handshake can often be delivered through software updates. Credentials and readers run on hardware-refresh cycles measured in a decade, which is why M-26-15 puts access control built on public-key infrastructure in its priority tier. Put quantum-resistant algorithms inside the FIPS 201 test suite and covered identity and access purchases start inheriting the requirement from the buying rule rather than from a new mandate.

Read More
Princeton's New Quantum Institute Is Aimed at the Junction Inside Superconducting Qubits
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Princeton's New Quantum Institute Is Aimed at the Junction Inside Superconducting Qubits

A $290 million announcement, read against its own awards

On 25 August 2026 the US National Science Foundation announced more than $290 million across eight Quantum Leap Challenge Institutes — $28 million to $37.5 million each over five years, three of them new and five renewed, spanning 36 higher-education institutions in 19 states with the Department of Energy national laboratories, NIST and the Department of War as federal collaborators and more than 30 companies alongside. The number travelled as a marker in the quantum computing race. The award titles read differently.

What the money is actually aimed at

Princeton's new institute, MARQUIS, receives $27.9 million over five years to reinvent one component: the Josephson junction, two superconducting electrodes separated by an oxidized insulating barrier only a few atoms thick, whose dominant construction — aluminum with an aluminum oxide barrier — Princeton describes as essentially unchanged for more than 25 years. Yale's PRACTIQAL takes practical error correction. Chicago's QuBBE takes quantum sensing for biophysics. Colorado's Q-SEnSE takes $37.5 million for atomic clocks, the most stable lasers in the world, and sensors that read disease in a patient's breath. Not one of the eight is denominated in qubit count.

Two states, one week, opposite ends of the curve

In the same week India's C-DOT unveiled fourteen indigenous quantum-secure products, which its chief executive characterized as production-grade with revenue already booked. One state announced a product line; the other funded the layer underneath it. Both answers are defensible and they are answers to different questions — and only one of them has products to point at this year.

Read More
Network Monitoring Learned the Cryptography That Is Being Replaced
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Network Monitoring Learned the Cryptography That Is Being Replaced

A change underneath the measurement

Encrypted-traffic classifiers read the outside of a connection — packet sizes, directions, timings — and infer what is inside without decrypting it. A preprint posted to arXiv on 24 August 2026 by Bingzhen Li and eight co-authors asks what happens to those models when TLS moves to hybrid post-quantum key establishment. Using the deployed group X25519MLKEM768, which pairs the classical X25519 exchange with ML-KEM-768 from FIPS 203, the authors show that the larger post-quantum handshake reshapes observable traffic while leaving the application above it and its label untouched. They name the effect PQC-induced protocol drift, and they put numbers on it.

Relocated, not removed

Across five representative classifiers and three experimental settings, the result holds: the signal survives the migration but moves, and models that score well under matched conditions lose reliability once the cryptographic domain shifts beneath them. The mixed period — part traditional traffic, part hybrid, in proportions that change every month — lasts as long as both domains share the same wire, and it is precisely the condition the field's benchmarks are not built to measure. The measured scope is narrow and is stated as such: closed-world website fingerprinting, one deployed hybrid group, one purpose-built benchmark.

Why the loss has no owner

In the same week, the US Treasury launched its Quantum-Readiness Task Force under Executive Order 14412, with third-party and vendor readiness as one of three workstreams. Migration is becoming procurement. Procurement asks whether a supplier supports the new algorithm, and has no natural place to record that switching it on ages a detection baseline owned by a different team. This piece reads the paper closely and follows that seam into the operational and civic consequences, including a temporary privacy dividend that nobody planned and nobody owns.

Read More
Windows Dated Post-Quantum Signing and Left the Algorithm Open
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Windows Dated Post-Quantum Signing and Left the Algorithm Open

A date, and no algorithm

Microsoft's guidance of 20 August 2026 sets three steps for the chain of trust that decides which software a Windows machine will accept. The Microsoft Windows Production PCA 2011 expires on 19 October 2026, with a replacement authority already rolling out. Signing moves to RSA-3072 and SHA-384 by the end of 2026. And in 2027, Windows signing transitions to post-quantum signing, which Microsoft says might use hybrid signature constructions. The guidance commits to a date and a direction while naming no post-quantum algorithm at all.

The bench that is supposed to answer

NIST's additional-signatures on-ramp exists chiefly to diversify beyond structured-lattice signatures, and secondarily to find short signatures and fast verification for applications that need them. Nine candidates advanced to its third round on 14 May 2026; on 29 July the HAWK team withdrew, and eight remain. Cloudflare's July analysis walked the same bench and concluded that none of the compact candidates is ready to carry the first migration, committing instead to ML-DSA on a 2029 target.

Deployment pressure, not a verdict

A vendor calendar fixed to 2027 without an algorithm. A programme built to diversify, one candidate lighter. An infrastructure provider settling on the general-purpose standard because it is finished. And a cross-regional pilot announced on 24 August that will put financial supervisors inside a live ML-DSA-65 test as observers. Microsoft selects nothing; only the last two actually pick a scheme. What they share is narrower than a verdict and still worth acting on: near-term deployment pressure is settling on ML-DSA while the alternatives mature, in a layer of the stack almost nobody outside cryptography can see.

Read More
€1.05 Billion, and the IP Has to Stay in Romania
IP & Competition Henry Quentir IP & Competition Henry Quentir

€1.05 Billion, and the IP Has to Stay in Romania

A member state acts while the union schedules

On 20 August 2026 the Romanian Government approved TechUp România, a state-aid scheme with a maximum budget of 5.313 billion lei — about 1.05 billion euro — created under the economic-relaunch package in Emergency Ordinance 8/2026. The eligible-technology list is unusually explicit for an ordinary industrial instrument: alongside artificial intelligence, ASIC and FPGA chip design, integrated photonics and 5G/6G, it names quantum computing and post-quantum cryptography outright. Financing agreements may be issued between 2026 and 2032; the payments run through to 2041.

The condition attached to the money

The scheme will not pay for research standing on its own. A qualifying project carries between 5 and 50 million lei of eligible costs, of which at least 2 million must be research and at least 3 million must be a follow-on investment in production or service-provision capacity. Beneficiaries provide at least 25 percent from non-public sources, their own or private external finance. The capacity has to keep operating in its region for five years, the aided jobs have to last as long, and the intellectual property has to be held through the investment period. The reason given is blunt: Romanian firms currently buy research services in Germany, France and Israel at high cost, and risk the know-how, trade secrets and rights that result staying captive abroad.

Where the top rates point

Under the current regional-aid map, intensity reaches up to 70 percent in four counties — Galați, Prahova, Dolj and Gorj. Those are the steel, oil-refining, car-making and lignite counties, rather than Romania's leading research hubs. Arad and Timiș, the west's industrial success story, get up to 30. The rates are horizontal, applying to any eligible project rather than to cryptography specifically, and the hierarchy is not fixed for the scheme's whole life: intensities for 2028 to 2032 fall to be set under new Commission-approved maps. Read as a map rather than a table, though, they mean a qualifying post-quantum or photonics project would draw its strongest support in the places with the most to lose when the old industrial base closes.

Read More
Why the New Attack Estimate Did Not Move a Single Deadline
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Why the New Attack Estimate Did Not Move a Single Deadline

A twentyfold-lower estimate, now through review

In a Perspective accepted by PRX Quantum on 6 July 2026, Ryan Babbush and colleagues — a Google-led multi-institution team including Craig Gidney, Adam Zalcman, Tanuj Khattar, Justin Drake and Dan Boneh — put the quantum cost of breaking elliptic-curve cryptography at about 1,200 logical qubits and 90 million Toffoli gates in one configuration, or 1,450 logical qubits and 70 million in another, mapping to fewer than 500,000 physical qubits: roughly twenty times below the prior physical-qubit estimate for the same task. Run straight through, those circuits take 23 or 18 minutes. Only a primed attack, with the precomputation already done, falls to about 12 or 9 minutes, which is the variant that draws level with the window in which a transaction sits on a public network with its key exposed.

The deadlines that stayed where they were

None of the migration dates examined here moved. Executive Order 14412 still sets 31 December 2030 for post-quantum key establishment across federal high-value and high-impact systems and 31 December 2031 for signatures; the European roadmap still runs to 2030 for critical infrastructure; the ICAO passport standard is still expected around the middle of 2027. The US order was signed after the preprint of 30 March 2026; the European roadmap and the ICAO target both predate it. A search of official communications on 22 August 2026 found no US, EU or ICAO statement revising any of them in light of the work.

Why that is mostly defensible

Those deadlines were never derived from a resource estimate. They are procurement calendars, keyed to certification and product queues that no executive order can shorten, and a co-author of the paper has cautioned that a rushed transition is the likelier catastrophe. The reasoning holds wherever a secret can be rotated. Where something has already been captured and cannot be reissued — a biometric, an archive, a public key long since published — harvest now, decrypt later means the useful deadline for that particular record has already gone, whatever date the instrument carries.

Read More
Five Days to Four Kelvin: Reading IBM's Modular Cryogenics Milestone
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Five Days to Four Kelvin: Reading IBM's Modular Cryogenics Milestone

A refrigerator result, precisely dated

On 19 August 2026 IBM said it had connected and cooled its first two modular cryogenic systems into a single environment. Assembled, the two box-shaped modules stand more than eight feet tall and eight feet wide. They reached 4 kelvin in under five days and then went below 15 millikelvin, and each module’s vacuum enclosure offers up to twelve times more wiring space than IBM’s most widely used quantum systems — room sized for the chip-to-chip connections its L-coupler interconnect is meant to carry.

What was not announced

IBM reports no installed processor and no qubit result for this test. The release carries no qubit counts, no fidelities and no error-correction figures for the coupled pair, and IBM Quantum Nighthawk processors are due to go into the cells later in 2026 for operational testing. Filed accurately, this is a cryogenics and packaging result under a fault-tolerance roadmap, and it sits at the layer where long roadmaps either hold their dates or quietly slip.

The calendar it runs beside

IBM’s stated targets are L-coupler-linked processors totaling at least 1,000 programmable qubits by 2027 and Starling, billed as the first fault-tolerant quantum computer, in 2029. Beside those company dates runs a standards calendar that moves with neither: NIST’s draft transition report IR 8547 deprecates classical public-key algorithms at 112-bit security strength after 2030 and disallows them after 2035. Reading the two together is where quantum readiness stops being a posture and becomes a schedule with dates on it.

Read More
The Export Control That Fits Inside a Passport
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

The Export Control That Fits Inside a Passport

Two governments, one control point

On 31 July 2026 China’s State Council published the Exit and Entry Administration Provisions, nineteen articles that take effect on 15 September. One of them lets competent State Council departments bar a citizen from leaving the country where that person violates export control or technology import/export rules in a way that “may endanger national industrial or technological security.” Seventeen days later, on 17 August, the Office of the Under Secretary of War for Research and Engineering notified thirty American universities to audit their institutional ties to foreign entities listed under Section 1286 of the fiscal 2019 defense authorization, with mitigation — up to terminating the partnership — reported by 31 August or future federal research funding is at risk. The same day, the White House published a national security science and technology strategy whose protected-technology list names quantum information technologies.

Why the wording matters

American law has treated a person as a channel for export since the deemed-export rule, so the direction is not new; a fundamental-research carve-out has kept university science largely outside it. What is changing sits at the edges of that carve-out. One instrument conditions a university’s research funding on the foreign affiliations in its own files; the other attaches an exit consequence to an individual on a forward-looking standard, with no fixed time limit where other categories of Chinese exit ban run six months to three years.

An unusually legible test case

Neither measure singles out quantum: the strategy lists it as one of fourteen protected areas, and the Chinese trigger is written around export control generally. Quantum research is simply where the change is easiest to observe, because the field is small, concentrated in a countable number of laboratories, and heavily co-authored across borders. A collaboration agreement signed in 2024 now carries exposure on both ends, and an affiliation cannot be recalled the way a shipment can.

Read More
Korea Funded a Quantum Drug Program That Plans to Make the Molecule
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Korea Funded a Quantum Drug Program That Plans to Make the Molecule

A program that publishes its verification loop

On 19 August 2026 Korean industry press reported that Baobab AiBIO had been named lead research institution of a Ministry of Science and ICT / National Research Foundation program applying quantum computing to targeted protein degradation, with LigaChem Biosciences, Yonsei University and the Institute of Molecular Design as co-institutions. The part worth reading twice is the workflow the program describes: design, then synthesis and evaluation, then Cryo-EM structural work, then redesign. Quantum-assisted molecular design is being pointed at a wet lab instead of at a benchmark table.

What that does and does not settle

Taking predictions into synthesis is not the same as demonstrating quantum advantage. That claim would additionally need a declared classical comparator, a stated endpoint and a resource comparison, and none of those is public yet. Nor is wet-lab work unprecedented here: a 2025 Nature Biotechnology paper reported fifteen molecules designed with a quantum-classical generative model, synthesized and assayed, two of them promising against KRAS. The Korean program adds public money on the testing half of the loop and a named synthesis partner.

The infrastructure running alongside

IBM joined and cooled its first two modular cryogenic units below 15 millikelvin the same week, on a roadmap to at least a thousand programmable qubits in 2027. That is parallel context and not a dependency: the Korean work names Yonsei's existing IBM QPU environment. For any reader judging a quantum-medicine claim, the useful test is whether a check has been scheduled.

Read More
Two Auditors Found the Reversed Step Inside an AI-Generated Proof
AI Governance Henry Quentir AI Governance Henry Quentir

Two Auditors Found the Reversed Step Inside an AI-Generated Proof

A correction, published with its own author list

On 3 August 2026 two auditors posted a note on Chapter 6 of OpenAI's Ten Advances in Mathematics and Theoretical Computer Science. The chapter claims an exponential parallel-repetition theorem for all finite two-player, one-round entangled games. Its quantitative greedy conditioning lemma is correctly stated and, as printed, incorrectly proved: the continuation test is written in terms of average success where the next step needs a large conditional failure probability. The note supplies a counterexample and a complete repair — and declines to call that repair an independent verification of the theorem.

Machine-checked file, human-read chapter

The same result ships with a Lean 4 formalization whose manifest records zero unfinished steps. Both facts hold at once, because a machine-checked formalization certifies the Lean file and not the prose a reader actually reads. A second audit, published 17 August, rigorized three of the four lemmas in the Dihedral Coset Problem preprint that connects, through a chain of reductions, to the lattice problems behind post-quantum cryptography. It corrected several of them and isolated a surviving hypothesis the algorithm's own rule does not supply, while leaving the parameter gap to ML-KEM exactly where it was.

And in code, a dispute about what was read

In the same week a disclosed GitHub Actions injection in Snowflake's connector repository left Wiz and GitHub publicly at odds over whether an automated review had examined the vulnerable code at all. Authorship of the line is on the record and belongs to a named engineer. What the squash-merge co-author field cannot establish is which lines any machine review actually read. Three cases, one pattern: production of plausible argument is scaling and the reading is not.

Read More
Sunlight Replaced the Pump Laser in an Outdoor Entanglement Source
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Sunlight Replaced the Pump Laser in an Outdoor Entanglement Source

A four-year objection, answered outdoors

On 6 August 2026 Optica published a result whose lead author, Cheng Li, says has “met with repeated doubt and pushback” since the project began: polarization-entangled photon pairs generated with natural sunlight as the pump, measured outdoors, at a Bell-state fidelity of 0.939 and a CHSH value of 2.5408 against the classical bound of 2. The apparatus is a Fresnel collector about the size of a household window, a custom all-glass concentrator cone, a fiber about as wide as a human hair, and a ppKTP crystal at the end of it. The same lead author had shown in 2022 that an incoherent LED could pump weak entanglement; a Xiamen group showed in 2025 that sunlight could drive down-conversion at all. This joins those two records.

A substitution, not yet a subtraction

The energy overhead of the pump laser is the motivation the authors name, and running a source on light that is already falling on the instrument is attractive for exactly that reason. What the experiment swaps in, though, is a collector, a tracking mount, spectral filtering, a custom concentrator and crystal temperature control, and no published comparison yet shows that trade winning on total mass, power, thermal load or reliability.

What is not yet on the record

The preprint reports roughly 1,600 pairs per second per milliwatt, comparable to laser-pumped setups once normalized for effective phase-matching bandwidth. What is missing is mission-level throughput, a secure key rate, a sustained duty cycle across sky conditions, and an independent replication. Those are the numbers to watch before anyone writes a passive entanglement source into a space-segment work package.

Read More
The A-Share Market's First Quantum Measurement Stock Is a Scientific-Instruments Business
IP & Competition Henry Quentir IP & Competition Henry Quentir

The A-Share Market's First Quantum Measurement Stock Is a Scientific-Instruments Business

A listing that does not match its label

On 11 August 2026 CIQTEK closed its first session on Shanghai's STAR Market at RMB 110.23 against an offer price of RMB 21.22, a gain of 419.46 percent and a market capitalization near RMB 44.1 billion. Chinese financial coverage called it the A-share market's first quantum precision measurement stock. The catalog underneath that label is electron microscopes, nuclear magnetic resonance and electron paramagnetic resonance spectrometers, scanning nitrogen-vacancy microscopes and gas adsorption analyzers, sold to universities, national academies and manufacturers.

Why measurement ships before computation

Part of the catalog is not quantum technology at all — electron microscopes and gas adsorption analyzers are conventional laboratory instruments. The spin-resonance line is where the physics matters. A quantum computer has to protect coherence across an entire algorithm, which is why error correction dominates its cost. Many present-day spin sensors hold a state only for a single short interrogation, read out a field-induced phase or resonance shift, and recover precision by repeating and averaging, which is why the products shipping today carry no fault-tolerance layer.

Where the public instruments reach, and where they thin out

Most of what governments issued this year points at computation or at defence timing: the US Commerce letters of intent in May, DARPA's optical clock award in August, the Royal Navy's cold-atom timing trial. Brussels and London have funded quantum sensing and metrology tooling too. What stays thin is the ordinary laboratory instrument park — the spectrometers, microscopes and adsorption analyzers that qualify materials for every industry, still classified under scientific-equipment rules that predate the quantum label. This post reads the listing closely and asks what concentration in that supply would mean for anyone who has to verify a battery, a wafer or a drug.

Read More
Copy-Based Resilience Is the One Habit This Signature Scheme Cannot Allow
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Copy-Based Resilience Is the One Habit This Signature Scheme Cannot Allow

One key, one place, one number

Stateful hash-based signatures are the one post-quantum family that behaves like a book of numbered receipts: every leaf may be used exactly once, and the count of what has already been spent is part of the secret. NIST's 2020 recommendation for those schemes holds the line with two plain conformance clauses. The cryptographic module may not export private keying material, even in encrypted form, and it may not use a one-time key more than once. Sign twice at the same index and, in NIST's words, it becomes computationally feasible for an attacker holding both signatures to forge further ones.

Where it meets the recovery plan

Ordinary resilience engineering runs on the opposite reflex. Many conventional copy-based designs duplicate the signing environment or roll it back in time, and where they do, both faults land in the same place: an index issued twice. Safer state-aware mechanisms exist and have been catalogued at the IETF; they are simply not what most recovery machinery does by default. The problem is well enough known to have its own engineering literature at the IETF, and it reached the banking press this week through a Swiss custody bank explaining why Ethereum's post-quantum roadmap is already an operational question. Switzerland's supervisor had reached an adjacent finding in July, reporting that in most cases among the sixty institutions it surveyed there was "a lack of a clear roadmap and sufficiently forward-looking planning" for the migration.

What the standard proposed instead

The interesting part sits in the recommendation itself. NIST anticipated module failure in 2020, refused the copy, and gave over a whole section to two architectures in its place — several independent keys across several modules, or one multi-tree key whose subtrees are generated on separate hardware. That is redundancy without duplication, and it has to be chosen at the key-generation ceremony, years before anyone reaches the migration deadline written in the plan.

Read More
Washington Would Take Equity in Nine Quantum Firms. One Prospectus Shows What That Means.
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Washington Would Take Equity in Nine Quantum Firms. One Prospectus Shows What That Means.

Nine non-binding letters, not nine closed deals

On 21 May 2026 the US Department of Commerce announced nine letters of intent worth $2.013 billion in CHIPS incentives across the American quantum computing industry — $1 billion to IBM for a 300-millimetre quantum wafer foundry in Albany, $375 million to GlobalFoundries, and $100 million each to Atom Computing, D-Wave, Infleqtion, PsiQuantum, Quantinuum and Rigetti, with up to $38 million to Diraq. Attached to each is a condition that changes the instrument: in exchange for the award, each recipient would issue equity securities to the Department. The letters are non-binding, and the definitive documents are still unsigned.

What one filing answers

Commerce described every stake as minority and non-controlling, and said little more. Several recipients have since added something of their own — D-Wave that it would issue $100 million in common stock, GlobalFoundries that the Department's position is about one per cent. Quantinuum's prospectus goes furthest by a distance, describing securities that would be non-voting so far as the law permits and freely transferable, carrying anti-dilution, registration, redemption, exchange, conversion, participation, tag-along and information rights, with funding released against named milestones across a five-year performance period. For that one company the control question is largely designed out. The custody question is not, and no recipient has answered it.

Own, screen, or buy

Three governments reached for three different instruments this season. Washington moved toward ownership. Brussels chose control over ownership: Regulation (EU) 2026/1386 puts quantum technologies into the mandatory screening scope of all 27 Member States for the first time. Israel chose procurement, tendering a sovereign quantum computer in August. Ownership is the instrument whose internal governance is least visible, and it is the one the United States picked in a field whose cost assumptions moved again in July.

Read More
The Post-Quantum Handshake That Delivered a Windows Zero-Day
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

The Post-Quantum Handshake That Delivered a Windows Zero-Day

What the report describes

On August 11, 2026, Check Point Research published an account of an Operation Dream Job intrusion chain aimed at defense and aerospace staff in France, Germany, India and Brazil. The lure was a recruiter approach. The payload was a use-after-free race in the Windows socket driver AFD.sys, tracked as CVE-2026-68820, giving local escalation to SYSTEM. Microsoft received the report on July 28, assigned the identifier on August 5, and patched on August 11. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, with a federal remediation date of August 25.

The detail that matters

Before the exploit moved, the privilege-escalation loader carried out post-quantum key establishment with its server: it took server public keys, generated fresh key material with Kyber/ML-KEM, returned the encapsulated result, and only then requested the zero-day. The report places this inside that loader's exchange, not across the campaign's wider command infrastructure. A second cipher layer sat on top of the existing AES transport, using a randomly generated 16-byte session key prepended to each packet. The rootkit that followed blinded 94 event-tracing providers and tampered with Smart App Control.

Why it reads as an organizational story

As a general matter, a classical ephemeral exchange offers comparable protection against later decryption, so a post-quantum primitive is not by itself a new offensive capability. What the case shows is speed. NIST finalized ML-KEM in August 2024; it appeared here in an ordinary tooling update, integrated by a team with no inventory to survey and no supplier to wait for. Enterprises measure the same transition in years because their constraint was never the mathematics. That asymmetry, not the handshake, is what inspection-based defense now has to plan around.

Read More
The Vulnerability Database Is Being Rebuilt Without a Word About Cryptography
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

The Vulnerability Database Is Being Rebuilt Without a Word About Cryptography

A consultation with one word missing

On August 12, 2026, NIST opened a public consultation on rebuilding the National Vulnerability Database for an era of AI-assisted attack and machine-readable security data. The notice runs to seven groups of questions, from automation of the vulnerability lifecycle through to the standards that govern vulnerability data and a five-year vision for the database itself. Comments close on October 13, 2026. The word cryptography does not appear anywhere in it.

Why the omission matters

Two years after the first post-quantum standards were finalized, European rules now require entities in scope to hold policies on the use of cryptography, and the Dutch implementing statute takes effect three days after this notice published. No instrument orders anyone to keep a cryptographic inventory — but a policy that cannot be checked against deployed systems is not one an auditor can test. The database ingests vulnerability records within about an hour of publication, so speed was never the binding constraint. The constraint is structural: a register answers only the questions its schema anticipated, and a flaw record was never built to describe a key exchange or a signing algorithm.

Who this decides for

Cryptographic discovery is already procurable by anyone with a budget, and no central record could replace it: what a given operator has configured is local knowledge that has to be found locally. What a public record could supply is the reference layer underneath — what a product version implements — so that local discovery resolves against something instead of being re-derived by everyone independently. Whether that layer acquires a cryptographic dimension will shape the real pace of migration among smaller operators more than any further deadline, and it is being settled on an open docket rather than in an instrument.

Read More
DARPA Is Buying the Copies, Not the Discovery
Standards Henry Quentir Standards Henry Quentir

DARPA Is Buying the Copies, Not the Discovery

A program bought units, not a demonstration

On August 6, 2026 the Defense Advanced Research Projects Agency announced It's About Time, a program whose stated aim is a pilot manufacturing pipeline for tactical-grade optical clocks. On the same day IonQ said it had received a $28 million contract extension covering manufacturing development and 25 Evergreen-05 optical atomic clocks, with an unexercised $30 million option for a further 100 units, and that it would add $15 million of its own capital for production space, equipment and staff. A facility is expected to open by mid-2027.

Timing is the capability arriving first

The Evergreen-05 sits in a five-liter enclosure, roughly one seventy-fifth the volume of an active hydrogen maser, and is specified at 50 femtoseconds of stability at one second with nanosecond-level holdover across ten days. Holdover is the number that matters operationally: it describes how long a platform keeps defensible time after the satellite signal stops. Against a documented rise in GNSS jamming and spoofing across the Baltic, the Black Sea, the eastern Mediterranean and the Middle East, that is a civil infrastructure question as much as a military one.

The qualification route is unnamed

DARPA's companion OASIC effort is building fee-based, certification-style testbeds open to outside users, and its atomic-clock testbed team is Vector Atomic — the company IonQ acquired in October 2025 — with the University of Colorado. Yet neither the DARPA announcement nor the IonQ release says whether the delivered clocks will be qualified there, or anywhere else: no national metrology institute, no international comparison, no cited military standard is named for the units. Meanwhile the same physics is being assessed on a separate civilian calendar, where the international committee responsible for the second is working toward a possible redefinition around 2030. A quantum instrument is entering pilot manufacturing while the reference frame it will be judged against is itself under revision.

Read More
What Would Have to Hold for the New DCP Result to Reach ML-KEM
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

What Would Have to Hold for the New DCP Result to Reach ML-KEM

A preliminary paper reaches the mathematics under lattice-based post-quantum cryptography

The Cryptology ePrint Archive received Paper 2026/1591 on August 3, 2026 and posted it three days later. In it, Daniel R. Simon of the Amazon Web Services Cryptography Group presents a polynomial-time quantum algorithm for the Dihedral Coset Problem, which has resisted a polynomial-time solution for more than two decades. Combined with Oded Regev's reduction of lattice problems to that problem, the abstract claims polynomial-time quantum algorithms for two distinct targets: the Shortest Vector Problem at a square-root-of-n polylogarithmic approximation factor, and Learning With Errors instances in a parameter regime the abstract states as alpha equal to square-root-of-n polylog(n).

What the paper does not claim

It analyzes no standardized scheme, offers no key-recovery attack, and gives no qubit, gate or error-correction estimate. The claim is complexity-theoretic and unreviewed; the author records discussions in progress with Daniele Micciancio, Vinod Vaikuntanathan and Thomas Vidick. Nothing standardized broke in August 2026, and no honest reading of the abstract says otherwise.

Why it still lands on the migration desk

Four conditions stand between this abstract and ML-KEM, and none has been met. But certification calendars were set on the cryptographic judgment of 2024 and do not pause for a preprint. What lets an organization respond to a result like this is crypto-agility resting on a current cryptographic inventory: knowing which systems use which algorithms, and how long a substitution actually takes. That capability is built before the verdict arrives, not after.

Read More