As quantum computing accelerates, Google is warning that the cryptographic foundations of the digital economy are approaching a breaking point. In a new policy push, the company says governments and industry must move faster to adopt post-quantum cryptography, arguing that the transition is no longer a theoretical exercise but a cybersecurity necessity.

Quantum computers promise breakthroughs in sectors from drug discovery to energy optimization. But the same machines could also unravel the public-key cryptography that secures bank transactions, private communications, corporate data, and classified government systems.

Google says advances in quantum research have narrowed the margin for complacency, even though a fully capable quantum computer has not yet arrived.

Not Alarm, Preparation

The risk, according to Google, is already taking shape. Sophisticated attackers are believed to be collecting encrypted data now under a store now, decrypt later strategy, betting that future quantum systems will enable them to unlock that information years from today. Data stolen in this way could retain its value long after it is harvested, particularly in sectors like healthcare, finance, and national security.

Google executives Kent Walker, president of global affairs at Google, and Hartmut Neven, founder of Google Quantum AI, argue the correct response is not alarm, but preparation. In a joint blog post, they stress that the security community has not been idle. Cryptographers have spent years developing quantum-resistant algorithms designed to withstand attacks from future quantum machines.

That effort reached a milestone in 2024, when the National Institute of Standards and Technology finalized the first set of post-quantum cryptography standards after a lengthy international review. Google is aligning its own migration plans with those standards and says it is on track to complete a post-quantum transition within NIST’s current guidance.

The company’s preparations began nearly a decade ago. Google started experimenting with post-quantum cryptography in 2016, deploying early implementations in products such as Chrome and embedding quantum-resistant protections across its internal infrastructure. Central to that effort is what the company calls crypto agility, the ability to replace or upgrade cryptographic systems without disrupting live services.

Google says it is now deepening its commitment on two fronts. First, it plans to continue researching how improvements in quantum hardware and algorithms affect the resources required to break existing encryption, sharing findings where possible to help industries refine their own timelines. Second, it is rolling out post-quantum protections across shared infrastructure and consumer-facing products, aiming to reduce systemic risk across the broader ecosystem.

Five Recommendations for Policymakers

Google emphasizes that private-sector action alone is not enough. Security in the quantum era, the company argues, will require coordinated public and private engagement. To that end, Google outlines five recommendations for policymakers.

The first is to drive society-wide momentum, particularly in critical infrastructure sectors such as energy, telecommunications, and healthcare, where legacy systems and workforce constraints could slow adoption.

Second, governments should ensure that AI systems are built with post-quantum cryptography from the outset, recognizing that cryptography underpins AI security.

Third, Google warns against fragmented global approaches. Broad adoption of NIST’s standards, it argues, would reduce the risk of incompatible or weak implementations.

Fourth, the company promotes cloud-first modernization, contending that migrating away from hard-coded legacy systems can accelerate the shift to quantum-safe security.

Finally, policymakers are urged to maintain ongoing dialogue with quantum experts to avoid strategic surprise, cautioning that a quantum computer capable of offering real attacks should not be assumed to be perpetually a decade away.

In essence, Google’s message warns that the transition window is shrinking. With standards now in place and attackers already positioning for a quantum future, the question is no longer whether quantum computers will break today’s encryption, but whether governments and industry can upgrade the world’s digital security infrastructure in time.