AQCat Became a Claude Science Tool on August 19, 2026: The Evidence Behind SandboxAQ's Catalyst Model and the Contract Questions It Raises
AI Governance Henry Quentir AI Governance Henry Quentir

AQCat Became a Claude Science Tool on August 19, 2026: The Evidence Behind SandboxAQ's Catalyst Model and the Contract Questions It Raises

Two delivery routes announced six days apart

On August 19, 2026 SandboxAQ announced from Palo Alto that AQCat, its machine-learning model for predicting how candidate catalysts behave, is generally available on Claude Science through the Model Context Protocol, so that a researcher asks for a screening in plain language and receives the model's prediction as a tool result. On August 25 a second release announced AQCat in the AWS Marketplace as an Amazon SageMaker package that runs inside the customer's own AWS account. The releases state an accuracy approaching the field's most trusted methods, a speed of up to 20,000 times faster than first-principles simulation, and a training corpus of 13.5 million density-functional-theory calculations across 47,000 catalyst systems.

What stands behind the model, and what is still open

Behind the corpus stands a vendor-authored, peer-reviewed paper in npj Computational Materials and a public dataset on Hugging Face, released under a non-commercial license with model checkpoints and code. That is more than most model announcements carry. Independent validation of the production service, and of the 20,000-times figure, is what the record still lacks: the evaluations published so far are the company's own, on the company's data.

Why the delivery route sets the contract questions

The two routes answer the data question differently. The AWS listing states that input data, inference payloads and chemical structures never leave the customer's isolated AWS tenant, are never shared with SandboxAQ and are never used for retraining. The Claude Science route runs the model behind a tool interface, and Claude Science states that every output carries an auditable history of how it was made. Neither statement is a contract term until it is written into one, and the article closes with the diligence checklist: deployment location and endpoint operator, weight access, data transit and retention, per-query logging of model version, query and answer, and an in-house validation set with its date.

Read More
Post-Quantum Buying Moves From Availability to Proof: What Counted as Evidence in the First Week of September 2026
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Post-Quantum Buying Moves From Availability to Proof: What Counted as Evidence in the First Week of September 2026

A certificate that changes status on 21 September 2026 without the module changing

The NIST Cryptographic Module Validation Program has said that on 21 September 2026 it will move every FIPS 140-2 validated module to the Historical List, where federal agencies should not include the module in new systems and may procure it for legacy systems only. Nothing inside the hardware changes on 22 September. What changes is the status of the certificate a proposal cites, which turns "FIPS-validated" into three questions: which standard, which certificate number, and what status on the day the proposal is read.

A readiness level in the field, a product-attributed pipeline, and three vendor dates

Three more documents sit alongside it. QuSecure said on 2 September 2026 that QuProtect R3 reached Technical Readiness Level 7 at the U.S. Army's Project Convergence Capstone 6 at Fort Irwin, providing quantum-resistant communications, cryptographic agility and cryptographic discovery and inventory for tactical mission systems; the rating is the company's own account of the exercise. SEALSQ's preliminary first-half results of 6 July 2026 put unaudited company-wide revenue near $11 million and attributed more than $60 million of a $225 million management-estimated pipeline to the QS7001 secure element and the QVault TPM, and on 3 September the company announced wolfTPM support for that part. JDK 27 reaches general availability on 15 September 2026 with hybrid post-quantum key exchange first in the default TLS preference list, Microsoft's Windows Production PCA 2011 expires on 19 October 2026, and Cisco IOS XE 26.x carries an ML-KEM-768 hybrid for IKEv2.

Why the four together describe a procurement test

The four documents carry dates spread across July, August and September, and what changed in the first week of September is that a buyer could request all of them at once. Each names an organisation, a date and a checkable particular. Read against Executive Order 14412, OMB Memorandum M-26-15 and the Department of War request for information closing 27 September 2026, they show what a buyer of post-quantum cryptography can now ask for and expect to receive.

Read More
An Author of D-Wave's 2025 Advantage Paper Simulated All Four of Its Graph Topologies Classically: What Roeland Wiersema Published on 1 September 2026, and the GPU Hours It Took
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

An Author of D-Wave's 2025 Advantage Paper Simulated All Four of Its Graph Topologies Classically: What Roeland Wiersema Published on 1 September 2026, and the GPU Hours It Took

An author of the 2025 advantage paper published the classical answer

On 12 March 2025 D-Wave published quench dynamics of spin glasses run on an Advantage2 annealing processor in Science, and estimated in its announcement that the same simulation would have taken the Frontier supercomputer at Oak Ridge nearly a million years and more electricity than the world uses in a year. On 1 September 2026 Roeland Wiersema, the fifth of the sixty-two authors on that paper and now at the Flatiron Institute's Center for Computational Quantum Physics, published a classical simulation covering all four of the experiment's problem graphs.

What the new paper reports, and on which instances

Using time-dependent variational Monte Carlo with a path-factorized correlator state, Wiersema reports final two-spin correlation errors on par with the processor for the sizes where converged reference data exists, and a relative two-spin correlation error of about 7.6 percent against the processor's data on a 72-spin biclique instance, a topology tensor-network methods handle least well. He notes that no other variational method is known to produce a correct state at that scale. The technical content is three numerical repairs: parallel tempering for slow Markov chains, blurred sampling for high-variance estimators, and an importance-weighted adaptive integrator.

The price of the result, stated by its author

The paper prices itself. The simulations took hundreds of GPU hours where the processor returns the same correlations in seconds, the largest instances of the original experiment stay out of reach, and an entire instance class is left untouched. Wiersema writes that the findings sharpen the question of quantum advantage without settling it, and his acknowledgments thank two D-Wave scientists for discussions during the work. We read the sequence from the March 2024 preprint through two classical preprints in March 2025, a D-Wave-led evaluation in August 2025 and two papers in 2026, and what it leaves for anyone judging a vendor's performance claim.

Read More
Coldcard Generated Bitcoin Seeds From a Software PRNG for Five Years: Block's 30 July 2026 Report, and Why Migration Deadlines Do Not Check Entropy
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Coldcard Generated Bitcoin Seeds From a Software PRNG for Five Years: Block's 30 July 2026 Report, and Why Migration Deadlines Do Not Check Entropy

A five-year-old build flag, not a broken cipher

On 30 July 2026 Block's Bitcoin engineering and security team published a root-cause analysis of thefts from Coinkite's Coldcard hardware wallets. A single commit on 1 March 2021 left the macro MICROPY_HW_ENABLE_RNG defined with the value zero, and the supporting library tested whether that macro was defined rather than whether it was enabled. Seed generation silently fell through to MicroPython's Yasmarang software generator, initialised from a chip serial number and two timer registers. No error appeared on any screen for five years.

What the counts say, and where they disagree

Galaxy Research mapped a sweep of 1,082.65 BTC out of 1,196 addresses in forty-one minutes on 30 July. TRM Labs put the running total at roughly 1,816 BTC and about USD 116 million across more than 5,200 addresses by 5 August. Coinkite's own advisory of 1 August describes about 72 bits of entropy against the 128 bits a BIP-39 seed assumes. Block's figures are harsher: deterministic output on the Mk2 and Mk3, and roughly 2^31 average enumeration on the Mk4, Mk5 and Q — both figures conditional on an attacker knowing the device identifier, the timer state and the history of calls to the generator, and neither backed by an end-to-end benchmark. Attribution of individual thefts remains open.

The gap in what a federal migration plan must contain

OMB memorandum M-26-15 of 24 June 2026 fixes what a federal agency's post-quantum cryptography migration plan must contain, and Appendix B lists nine items. Entropy is not among them, and the words "entropy" and "SP 800-90B" appear nowhere in the memorandum. Entropy quality is governed separately, through NIST SP 800-90B and the Entropy Source Validation stream inside the Cryptographic Module Validation Program. This piece reconstructs the Coldcard failure end to end and shows why an algorithm inventory of the affected devices could be entirely accurate and still miss it.

Read More
A Lattice Attack Was Claimed on 3 August 2026 and Answered on 15 August: What ePrint 2026/1591 and 2026/1693 Say About ML-KEM
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

A Lattice Attack Was Claimed on 3 August 2026 and Answered on 15 August: What ePrint 2026/1591 and 2026/1693 Say About ML-KEM

What Simon submitted on 3 August 2026, and what the abstract claimed

Cryptology ePrint Archive 2026/1591, “A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem,” by Daniel R. Simon of Amazon Web Services, was received on 3 August 2026 and filed under attacks and cryptanalysis. Building on Regev's reduction techniques, it claimed to handle modular subset sum without a subset-sum oracle and to yield polynomial-time quantum algorithms for lattice problems, including a polynomial-factor approximation to the shortest vector and learning with errors at noise parameter α = √n polylog(n). The abstract never mentions ML-KEM, FIPS 203, or any deployed parameter set. The paper was revised four times, most recently on 17 August 2026.

What Gupte, Ragavan and Zhandry posted on 15 August 2026

ePrint 2026/1693, “The ePrint:2026/1591 Quantum Algorithm Does Not Solve DCP,” by Aparna Gupte of MIT, Seyoon Ragavan of Google Quantum AI and MIT, and Mark Zhandry of Google Quantum AI and Stanford, was received on 15 August 2026 and last revised on 1 September. The formal finding is that Simon's algorithm does not extract the least-significant bit of the dihedral coset secret with non-negligible guessing advantage, and so cannot solve the problem it targets. The authors state that their no-go covers a much broader class of algorithms than Simon's — those that carry only a limited digest of the classical Fourier information into the uncomputation stage — and they released Lean 4 code so the argument can be machine-checked.

Why the twelve days matter more than the result

Executive Order 14412's key-establishment deadline of 31 December 2030, the Java runtime shipping hybrid key exchange on 15 September 2026, and the enterprise plans behind them all lean on lattice mathematics for key establishment. When the strongest public challenge to that mathematics this year appeared, the quality control that answered it came from three academics posting a formal no-go within twelve days, and from the author leaving his own paper up with the challenge attached. That is the working crypto-agility argument, made by demonstration.

Read More
ESA's QKDSat Photon Source Passed Space Qualification in Valencia on 1 September 2026, and the NCSC Will Not Accept QKD for UK Government Use
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

ESA's QKDSat Photon Source Passed Space Qualification in Valencia on 1 September 2026, and the NCSC Will Not Accept QKD for UK Government Use

What DAS Photonics qualified in Valencia on 1 September 2026

ESA announced that DAS Photonics has completed qualification of the Engineering Qualification Model of the Faint Pulse Source, the optical source that generates the pulses QKDSat uses to distribute keys from orbit. The unit was qualified to European Cooperation for Space Standardisation requirements at the ESA-VSC testing facility in Valencia and handed to Redwire Europe. ESA describes it as the most advanced qualified faint pulse source with embedded security mechanisms in Europe for a satellite-based quantum key distribution system. QKDSat runs under the ARTES programme, with Honeywell Aerospace, Redwire Europe and DAS Photonics named as partners.

What Britain's NCSC says about QKD, and for whom

The National Cyber Security Centre's paper on quantum networking technologies, published on 5 August 2025 at version 1.0, states that the NCSC will not support the use of QKD for government or military applications, and that using a QKD system should not count towards assessments of data-in-transit security under its Cyber Assessment Framework. For other sectors it recommends that QKD should not be solely relied upon for generating and distributing keys. The objection is that QKD supplies a shared secret and no way to know who is at the other end. The NCSC's post-quantum migration timeline, published 20 March 2025, runs on standardised algorithms: discovery by 2028, highest-priority systems by 2031, everything by 2035.

Where the qualification chain and the accreditation chain part

Madrid's MadQCI network links 30 locations over more than 700 kilometres of fibre, including hospitals in the Vithas group and cryptography work with Banco Santander. Component-level security criteria for QKD modules exist. A published acceptance case for a complete satellite system carrying government traffic does not.

Read More
Prof. Mauritz Kop on The Prode: the Quantum Race, Q-Day Deadlines, and US National Security — the August 31, 2026 Interview
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Prof. Mauritz Kop on The Prode: the Quantum Race, Q-Day Deadlines, and US National Security — the August 31, 2026 Interview

What Prof. Mauritz Kop told The Prode on August 31, 2026

The Prode, the independent interview platform founded by journalist Ritwij Raj, released its conversation with Prof. Mauritz Kop on the emerging quantum race and its implications for defense and national security. Kop, founder of the Stanford Center for Responsible Quantum Technology and of Quentir, answers six questions now facing the US national-security and technology-policy communities — from the timeline for a cryptographically relevant quantum computer to the shape of government-industry collaboration. The full video is embedded in this article.

Q-Day math and the deadlines that already exist

Nobody can date Q-Day, and Kop declines to invent one. What changed this March is the engineering target: two papers lowered the resource estimates for machines running Shor's algorithm — one neutral-atom architecture at 10,000 reconfigurable qubits, a Google-led estimate under 500,000 physical qubits for the P-256 curve. His planning instrument is Mosca's theorem, and his planning horizon is public: NIST's 2024 standards, NSA's January 2027 acquisition requirement and 2035 completion date, the June 2026 executive order with 2030 and 2031 milestones, and the UK and EU tracks toward 2035.

Harvest now, decrypt later — and the data that cannot be reissued

Adversaries can store ciphertext today and read it once hardware matures. Kop extends the harvest-now-decrypt-later problem to its sharpest case: a password can be changed, a genome cannot, and it carries information about your relatives as well as yourself. His prescription is anticipatory data stewardship — if future decryption is foreseeable, it belongs in today's duty of care.

Sensing, deterrence by denial, and the golden triangle

On quantum sensing, Kop ranks the public evidence: military value appears first in positioning, navigation, and timing when GPS is jammed, while ocean-transparency claims outrun public evidence. The deterrence logic he draws is denial — guaranteed navigation and timing, quantum-secure command and control, and communications that stay up under attack. And for the valley of death between research grant and purchase, his answer is the golden triangle of academia, policy, and industry: a real mission, a first paying customer, and a test an independent team can challenge — the program he carries forward from Stanford to CIGI, the US Air Force Academy, and Quentir.

Read More
Korea's Health Ministry Funded a Quantum Nanosensor for Cancer-Drug Heart Damage: the KRW 8 Billion ARPA-H RFP5 Award of 31 August 2026
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Korea's Health Ministry Funded a Quantum Nanosensor for Cancer-Drug Heart Damage: the KRW 8 Billion ARPA-H RFP5 Award of 31 August 2026

What the Ministry of Health and Welfare selected on 31 August 2026

Korea's health ministry, working through the Korea Health Industry Development Institute and its K-Health Future Promotion Team, selected a consortium led by Kyung Hee University's Son Seok-kyun, a physicist, for RFP5 of the Korean ARPA-H project: quantum sensing-based ultra-high-sensitivity early diagnosis technology. The award is KRW 8 billion across four and a half years. RFP5 was one of nine challenges opened on 1 June 2026 for applications closing 1 July. The design fuses a biocompatible molecular quantum nanosensor with a cardiac organoid organ-on-a-chip, and the entry indication is anticancer-drug-induced cardiotoxicity.

Why the funder's identity changes what the instrument has to prove

What Korea's health ministry announced is a clinical endpoint: damage a cardio-oncology clinic currently detects through echocardiography and blood biomarkers, after the muscle has already been affected. The consortium proposes to read intracellular oxidative stress, local temperature and metabolic activity upstream of that point. Six institutions hold six named pieces of the work, from spin-Hamiltonian signal interpretation at Chosun University to MEMS and microfluidic integration at KETI and NV-center cross-validation at Korea University.

Korea has now funded both halves of quantum medicine, through two ministries

On 19 August this blog covered a quantum drug-design programme funded by Korea's science ministry. This award comes from the health ministry, and it funds the measurement half of the same problem. Two ministries, two verification cultures, one national portfolio. The assessment routes for a device with no predecessor already exist, through FDA De Novo classification and European MDR/IVDR conformity assessment. What no authority has yet issued is quantum-specific assessment guidance, or a precedent decision on a diagnostic claim resting on a quantum-sensed intracellular measurement.

Read More
BSI's 2030-2035 End Dates and FINMA's Mid-2027 Roadmap: What They Mean for Data Already in the Archive
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

BSI's 2030-2035 End Dates and FINMA's Mid-2027 Roadmap: What They Mean for Data Already in the Archive

What BSI dated on 11 February 2026 and what FINMA recommended on 9 July 2026

Two European authorities put years on the post-quantum transition in 2026, and neither is American. One is a cybersecurity agency and one is a financial supervisor. Germany's Federal Office for Information Security, in the annual update of its cryptographic guideline TR-02102, set the first expiry for classical asymmetric procedures: end of 2031 for key agreement and encryption, end of 2030 where protection needs are high, and end of 2035 for classical signature procedures. Switzerland's financial supervisor followed on 9 July 2026 with Guidance 05/2026, drawn from a survey of 60 authorised banks, insurers, managers of collective assets and financial market infrastructures run between November 2025 and January 2026. Around two thirds of them expect quantum-related cyber risk to reach their own institution within seven years. Seventy-two per cent had planned or implemented nothing.

The inventory FINMA recommends covers stored data, and that is the harder half

FINMA recommends a post-quantum cryptography roadmap drawn up by mid-2027 at the latest, resting on a strategy adopted by the board of directors and an inventory of every business process, explicitly covering encryption in transmission as well as stored data. The transmission half is moving on its own wherever both endpoints have shipped hybrid key agreement. The stored half is not. A record 176.5 exabytes of compressed LTO tape capacity shipped in 2024, a fourth consecutive year of growth, into archives whose key hierarchies and signature chains were designed when RSA was considered safe for a working lifetime.

Why the constraint is key management rather than algorithm choice

Standardised algorithms exist. What many archives lack is the ability to move the keys that protect decades of stored records, through key-management servers, backup appliances and self-encrypting drives, without rewriting the data itself — and whether that shortcut is available at all depends on how a given site built its key hierarchy and which payload cipher it chose. BSI's 2030 and 2031 dates fall on the asymmetric side of that question; 2035 falls on the signature chains that make an archive provable. It is a records-retention question for medical, pension and insurance files as much as a cryptographic one.

Read More
Executive Order 14421 Can Reach Grid Equipment Already Installed: What Section 2(b) Allows and Who Counts as a Covered Foreign Entity
AI Governance Henry Quentir AI Governance Henry Quentir

Executive Order 14421 Can Reach Grid Equipment Already Installed: What Section 2(b) Allows and Who Counts as a Covered Foreign Entity

What President Trump signed on 26 August 2026, and where the text sits

Executive Order 14421, Declaring a National Emergency To Secure the United States Bulk-Power System, was signed on 26 August 2026, filed with the Office of the Federal Register on 28 August 2026 at 11:15 am, and is scheduled for publication on 31 August 2026 at 91 FR 55995 as FR Doc 2026-17843. It runs on the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.), the National Emergencies Act (50 U.S.C. 1601 et seq.) and section 301 of title 3. It is in force from signature and carries no comment period.

Section 2(b) is the operative provision, and it reaches the installed base

Section 2(a) prohibits acquisitions, imports, transfers and installations initiated after 26 August 2026, where the transaction involves property in which a foreign country or a national of one has any interest, including through an interest in the supply contract. Section 2(b) reaches equipment that is already in service: on the same determinations, the Secretary of Energy may impose conditions on the continued use, operation, maintenance, servicing or updating of foreign-manufactured or foreign-operated equipment acquired or installed before the date of the order, including requirements to identify, isolate, monitor, secure, disconnect, replace or remove it. The obligation runs forward from the order onto existing assets; it does not alter the legal effect of the completed purchase. Before directing isolation, disconnection, replacement or removal, the Secretary must consider reliability and safety, the availability of secure replacements and continuity of essential service, and may set phased compliance.

Which equipment, and which foreign entities, the order actually reaches

Section 5(b) enumerates the covered equipment. Among the named categories are substation transformers, grid-connected inverters, battery energy storage, uninterruptible power supplies supporting critical infrastructure, shunt capacitor equipment, protective relaying, high voltage circuit breakers and the remote terminal units, programmable logic controllers and intelligent electronic devices inside them, together with associated software, firmware, remote access and update mechanisms. Section 5(a) sets the floor at transmission rated 69,000 volts or more and excludes local distribution. Section 5(e) defines a Covered Foreign Entity in two limbs: one turns on the published arms-embargo and sanctions regime at 22 C.F.R. 126.1, the other on a determination by the Secretary of Energy for which the order sets no evidentiary threshold and no publication requirement.

Read More
Quantum Fault Tolerance Costs an Unavoidable Logarithm: What Bharti, Haug and Tanggara Proved on 26 August 2026
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Quantum Fault Tolerance Costs an Unavoidable Logarithm: What Bharti, Haug and Tanggara Proved on 26 August 2026

What Bharti, Haug and Tanggara posted on arXiv on 26 August 2026

A forty-page preprint, Fault-tolerant quantum computation cannot be achieved with constant spacetime overhead (arXiv:2608.26272, submitted 26 August 2026 at 18:00:25 UTC), proves a lower bound on the resources quantum error correction requires. Kishor Bharti, Tobias Haug and Andrew Tanggara show that for the simplest task in the field, holding quantum information steady in a memory, the minimum number of physical storage locations scales as Θ(S(K + log(S/ε))) for width K, duration S and target error ε. The second term is an additive reliability cost that no protocol removes inside this model. The result is filed under quantum physics and information theory, and it has not yet been peer reviewed.

The condition the authors attach to it in the same paper

Relative overhead scales as Θ(1 + log(S/ε)/K), so it stays bounded once the width K reaches Ω(log(S/ε)), and the logarithmic term becomes negligible only in the stronger regime K = ω(log(S/ε)). The absolute reliability cost is never removed at any width. The authors state the consequence directly. Constant overhead can be possible for sufficiently wide computations. They add that no single constant bounds the spacetime overhead uniformly over all widths. Standard implementations of Shor's algorithm amortize the cost. Grover search sits near the crossover.

Why the qualification matters more than the headline

A reader who takes only the title away will conclude that a hard limit has been placed under every claim about when a cryptographically relevant quantum computer arrives. The paper does not support that reading, and its memory bound is proved under a deliberately generous erasure model. This read separates what the theorem establishes from what it has already been asked to carry, names the width and duration under which the cost dominates, and states what it changes for federal migration schedules, which is nothing.

Read More
Quantum Navigation Leaves the Laboratory Bench
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Quantum Navigation Leaves the Laboratory Bench

What a quantum gravimeter measured over 83 kilometers at sea in August 2026

A preprint posted on 26 August 2026 (arXiv:2608.25563) reports gravity map matching aboard a 29-meter surface vessel: a mobile quantum gravimeter, hybridized with a classical accelerometer and installed in an uncontrolled cabin with no environmental stabilization and no calibration, corrected an inertial solution over an 83-kilometer maritime trajectory by referencing locally measured gravity to a satellite-derived anomaly map. The authors report bounded positioning at nautical-mile-level accuracy with satellite navigation excluded throughout. In a separate referenced survey mode the same system worked coastal routes up to Sea State 4 with mGal-level agreement and sub-mGal repeatability.

Which programs pay for it: DARPA's Robust Quantum Sensors, the Defense Innovation Unit and NASA

DARPA's Robust Quantum Sensors program exists to move quantum sensors off the bench onto moving platforms, and it has funded ruggedization work at Q-CTRL with Lockheed Martin and at Safran Federal Systems, whose planned first phase tests a quantum sensor on a military helicopter against electromagnetic interference and vibration. The Defense Innovation Unit's Transition of Quantum Sensing program covers inertial sensors, gravimeters, magnetic anomaly detection, magnetic navigation and components, and holds a prototype contract for a quantum-enabled inertial navigation system. Infleqtion announced on 27 August 2026 that NASA had awarded it a USD 20 million follow-on for a space-based gravity gradiometer.

What the published record does not show about replacing satellite positioning

No public result shows quantum inertial navigation replacing satellite positioning in operational use. These instruments are drift-limited, and the honest question is how much drift accumulates over how many hours under what vibration. These remain field experiments, and the published record stops there.

Read More
Washington Follows Mauritz Kop's Bletchley Park Recommendations, and GSA Leads the Post-Quantum Migration
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Washington Follows Mauritz Kop's Bletchley Park Recommendations, and GSA Leads the Post-Quantum Migration

Who recommended it, where, and when

On 6 November 2025, Mauritz Kop published “A Bletchley Park for the Quantum Age” in War on the Rocks. The essay named the General Services Administration and asked that federal purchases be conditioned on validated cryptographic modules, and it asked separately that fielded systems be tested rather than vendor promises accepted. Nine months later, on 24 August 2026, GSA published a post titled “GSA Leads the Transition to Quantum-Resistant Technology”. The recommendation came first, it named the right agency, and both of the things it asked for — buy only what is validated, test what is fielded — are now federal work.

What GSA actually operates

Two things, and both are procurement rather than protocol. GSA is modernizing the Federal Identity, Credential, and Access Management architecture for quantum-resistant algorithms, with crypto agility as the stated design goal, through an interagency working group that OMB Memorandum M-26-15 ordered it to stand up and that first met on 12 August 2026. And GSA’s FIPS 201 Evaluation Program, executed through its Physical Access Control System lab, is starting to incorporate quantum-resistant algorithms into the testing that decides which badge readers and door controllers reach the Approved Products List. No quantum-resistant access product has been approved yet.

Why the doors are the hard part

Algorithm migration inside a browser handshake can often be delivered through software updates. Credentials and readers run on hardware-refresh cycles measured in a decade, which is why M-26-15 puts access control built on public-key infrastructure in its priority tier. Put quantum-resistant algorithms inside the FIPS 201 test suite and covered identity and access purchases start inheriting the requirement from the buying rule rather than from a new mandate.

Read More
Princeton's New Quantum Institute Is Aimed at the Junction Inside Superconducting Qubits
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Princeton's New Quantum Institute Is Aimed at the Junction Inside Superconducting Qubits

A $290 million announcement, read against its own awards

On 25 August 2026 the US National Science Foundation announced more than $290 million across eight Quantum Leap Challenge Institutes — $28 million to $37.5 million each over five years, three of them new and five renewed, spanning 36 higher-education institutions in 19 states with the Department of Energy national laboratories, NIST and the Department of War as federal collaborators and more than 30 companies alongside. The number travelled as a marker in the quantum computing race. The award titles read differently.

What the money is actually aimed at

Princeton's new institute, MARQUIS, receives $27.9 million over five years to reinvent one component: the Josephson junction, two superconducting electrodes separated by an oxidized insulating barrier only a few atoms thick, whose dominant construction — aluminum with an aluminum oxide barrier — Princeton describes as essentially unchanged for more than 25 years. Yale's PRACTIQAL takes practical error correction. Chicago's QuBBE takes quantum sensing for biophysics. Colorado's Q-SEnSE takes $37.5 million for atomic clocks, the most stable lasers in the world, and sensors that read disease in a patient's breath. Not one of the eight is denominated in qubit count.

Two states, one week, opposite ends of the curve

In the same week India's C-DOT unveiled fourteen indigenous quantum-secure products, which its chief executive characterized as production-grade with revenue already booked. One state announced a product line; the other funded the layer underneath it. Both answers are defensible and they are answers to different questions — and only one of them has products to point at this year.

Read More
Network Monitoring Learned the Cryptography That Is Being Replaced
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Network Monitoring Learned the Cryptography That Is Being Replaced

A change underneath the measurement

Encrypted-traffic classifiers read the outside of a connection — packet sizes, directions, timings — and infer what is inside without decrypting it. A preprint posted to arXiv on 24 August 2026 by Bingzhen Li and eight co-authors asks what happens to those models when TLS moves to hybrid post-quantum key establishment. Using the deployed group X25519MLKEM768, which pairs the classical X25519 exchange with ML-KEM-768 from FIPS 203, the authors show that the larger post-quantum handshake reshapes observable traffic while leaving the application above it and its label untouched. They name the effect PQC-induced protocol drift, and they put numbers on it.

Relocated, not removed

Across five representative classifiers and three experimental settings, the result holds: the signal survives the migration but moves, and models that score well under matched conditions lose reliability once the cryptographic domain shifts beneath them. The mixed period — part traditional traffic, part hybrid, in proportions that change every month — lasts as long as both domains share the same wire, and it is precisely the condition the field's benchmarks are not built to measure. The measured scope is narrow and is stated as such: closed-world website fingerprinting, one deployed hybrid group, one purpose-built benchmark.

Why the loss has no owner

In the same week, the US Treasury launched its Quantum-Readiness Task Force under Executive Order 14412, with third-party and vendor readiness as one of three workstreams. Migration is becoming procurement. Procurement asks whether a supplier supports the new algorithm, and has no natural place to record that switching it on ages a detection baseline owned by a different team. This piece reads the paper closely and follows that seam into the operational and civic consequences, including a temporary privacy dividend that nobody planned and nobody owns.

Read More
Windows Dated Post-Quantum Signing and Left the Algorithm Open
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Windows Dated Post-Quantum Signing and Left the Algorithm Open

A date, and no algorithm

Microsoft's guidance of 20 August 2026 sets three steps for the chain of trust that decides which software a Windows machine will accept. The Microsoft Windows Production PCA 2011 expires on 19 October 2026, with a replacement authority already rolling out. Signing moves to RSA-3072 and SHA-384 by the end of 2026. And in 2027, Windows signing transitions to post-quantum signing, which Microsoft says might use hybrid signature constructions. The guidance commits to a date and a direction while naming no post-quantum algorithm at all.

The bench that is supposed to answer

NIST's additional-signatures on-ramp exists chiefly to diversify beyond structured-lattice signatures, and secondarily to find short signatures and fast verification for applications that need them. Nine candidates advanced to its third round on 14 May 2026; on 29 July the HAWK team withdrew, and eight remain. Cloudflare's July analysis walked the same bench and concluded that none of the compact candidates is ready to carry the first migration, committing instead to ML-DSA on a 2029 target.

Deployment pressure, not a verdict

A vendor calendar fixed to 2027 without an algorithm. A programme built to diversify, one candidate lighter. An infrastructure provider settling on the general-purpose standard because it is finished. And a cross-regional pilot announced on 24 August that will put financial supervisors inside a live ML-DSA-65 test as observers. Microsoft selects nothing; only the last two actually pick a scheme. What they share is narrower than a verdict and still worth acting on: near-term deployment pressure is settling on ML-DSA while the alternatives mature, in a layer of the stack almost nobody outside cryptography can see.

Read More
€1.05 Billion, and the IP Has to Stay in Romania
IP & Competition Henry Quentir IP & Competition Henry Quentir

€1.05 Billion, and the IP Has to Stay in Romania

A member state acts while the union schedules

On 20 August 2026 the Romanian Government approved TechUp România, a state-aid scheme with a maximum budget of 5.313 billion lei — about 1.05 billion euro — created under the economic-relaunch package in Emergency Ordinance 8/2026. The eligible-technology list is unusually explicit for an ordinary industrial instrument: alongside artificial intelligence, ASIC and FPGA chip design, integrated photonics and 5G/6G, it names quantum computing and post-quantum cryptography outright. Financing agreements may be issued between 2026 and 2032; the payments run through to 2041.

The condition attached to the money

The scheme will not pay for research standing on its own. A qualifying project carries between 5 and 50 million lei of eligible costs, of which at least 2 million must be research and at least 3 million must be a follow-on investment in production or service-provision capacity. Beneficiaries provide at least 25 percent from non-public sources, their own or private external finance. The capacity has to keep operating in its region for five years, the aided jobs have to last as long, and the intellectual property has to be held through the investment period. The reason given is blunt: Romanian firms currently buy research services in Germany, France and Israel at high cost, and risk the know-how, trade secrets and rights that result staying captive abroad.

Where the top rates point

Under the current regional-aid map, intensity reaches up to 70 percent in four counties — Galați, Prahova, Dolj and Gorj. Those are the steel, oil-refining, car-making and lignite counties, rather than Romania's leading research hubs. Arad and Timiș, the west's industrial success story, get up to 30. The rates are horizontal, applying to any eligible project rather than to cryptography specifically, and the hierarchy is not fixed for the scheme's whole life: intensities for 2028 to 2032 fall to be set under new Commission-approved maps. Read as a map rather than a table, though, they mean a qualifying post-quantum or photonics project would draw its strongest support in the places with the most to lose when the old industrial base closes.

Read More
Why the New Attack Estimate Did Not Move a Single Deadline
Post-Quantum Transition Henry Quentir Post-Quantum Transition Henry Quentir

Why the New Attack Estimate Did Not Move a Single Deadline

A twentyfold-lower estimate, now through review

In a Perspective accepted by PRX Quantum on 6 July 2026, Ryan Babbush and colleagues — a Google-led multi-institution team including Craig Gidney, Adam Zalcman, Tanuj Khattar, Justin Drake and Dan Boneh — put the quantum cost of breaking elliptic-curve cryptography at about 1,200 logical qubits and 90 million Toffoli gates in one configuration, or 1,450 logical qubits and 70 million in another, mapping to fewer than 500,000 physical qubits: roughly twenty times below the prior physical-qubit estimate for the same task. Run straight through, those circuits take 23 or 18 minutes. Only a primed attack, with the precomputation already done, falls to about 12 or 9 minutes, which is the variant that draws level with the window in which a transaction sits on a public network with its key exposed.

The deadlines that stayed where they were

None of the migration dates examined here moved. Executive Order 14412 still sets 31 December 2030 for post-quantum key establishment across federal high-value and high-impact systems and 31 December 2031 for signatures; the European roadmap still runs to 2030 for critical infrastructure; the ICAO passport standard is still expected around the middle of 2027. The US order was signed after the preprint of 30 March 2026; the European roadmap and the ICAO target both predate it. A search of official communications on 22 August 2026 found no US, EU or ICAO statement revising any of them in light of the work.

Why that is mostly defensible

Those deadlines were never derived from a resource estimate. They are procurement calendars, keyed to certification and product queues that no executive order can shorten, and a co-author of the paper has cautioned that a rushed transition is the likelier catastrophe. The reasoning holds wherever a secret can be rotated. Where something has already been captured and cannot be reissued — a biometric, an archive, a public key long since published — harvest now, decrypt later means the useful deadline for that particular record has already gone, whatever date the instrument carries.

Read More
Five Days to Four Kelvin: Reading IBM's Modular Cryogenics Milestone
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

Five Days to Four Kelvin: Reading IBM's Modular Cryogenics Milestone

A refrigerator result, precisely dated

On 19 August 2026 IBM said it had connected and cooled its first two modular cryogenic systems into a single environment. Assembled, the two box-shaped modules stand more than eight feet tall and eight feet wide. They reached 4 kelvin in under five days and then went below 15 millikelvin, and each module’s vacuum enclosure offers up to twelve times more wiring space than IBM’s most widely used quantum systems — room sized for the chip-to-chip connections its L-coupler interconnect is meant to carry.

What was not announced

IBM reports no installed processor and no qubit result for this test. The release carries no qubit counts, no fidelities and no error-correction figures for the coupled pair, and IBM Quantum Nighthawk processors are due to go into the cells later in 2026 for operational testing. Filed accurately, this is a cryogenics and packaging result under a fault-tolerance roadmap, and it sits at the layer where long roadmaps either hold their dates or quietly slip.

The calendar it runs beside

IBM’s stated targets are L-coupler-linked processors totaling at least 1,000 programmable qubits by 2027 and Starling, billed as the first fault-tolerant quantum computer, in 2029. Beside those company dates runs a standards calendar that moves with neither: NIST’s draft transition report IR 8547 deprecates classical public-key algorithms at 112-bit security strength after 2030 and disallows them after 2035. Reading the two together is where quantum readiness stops being a posture and becomes a schedule with dates on it.

Read More
The Export Control That Fits Inside a Passport
Quantum Governance Henry Quentir Quantum Governance Henry Quentir

The Export Control That Fits Inside a Passport

Two governments, one control point

On 31 July 2026 China’s State Council published the Exit and Entry Administration Provisions, nineteen articles that take effect on 15 September. One of them lets competent State Council departments bar a citizen from leaving the country where that person violates export control or technology import/export rules in a way that “may endanger national industrial or technological security.” Seventeen days later, on 17 August, the Office of the Under Secretary of War for Research and Engineering notified thirty American universities to audit their institutional ties to foreign entities listed under Section 1286 of the fiscal 2019 defense authorization, with mitigation — up to terminating the partnership — reported by 31 August or future federal research funding is at risk. The same day, the White House published a national security science and technology strategy whose protected-technology list names quantum information technologies.

Why the wording matters

American law has treated a person as a channel for export since the deemed-export rule, so the direction is not new; a fundamental-research carve-out has kept university science largely outside it. What is changing sits at the edges of that carve-out. One instrument conditions a university’s research funding on the foreign affiliations in its own files; the other attaches an exit consequence to an individual on a forward-looking standard, with no fixed time limit where other categories of Chinese exit ban run six months to three years.

An unusually legible test case

Neither measure singles out quantum: the strategy lists it as one of fourteen protected areas, and the Chinese trigger is written around export control generally. Quantum research is simply where the change is easiest to observe, because the field is small, concentrated in a countable number of laboratories, and heavily co-authored across borders. A collaboration agreement signed in 2024 now carries exposure on both ends, and an affiliation cannot be recalled the way a shipment can.

Read More