Breaking Geopolitics News & AnalysisFriday, August 21, 2026
DiplomacyGlobal

AI Is a National Security Problem, But Q Day Is Coming.

The National Interest
August 21, 2026 at 11:46 AM
13 views
AI Is a National Security Problem, But Q Day Is Coming.

AI-powered cyberattacks are already here. Quantum computing could soon break the encryption underpinning the modern economy. The post AI Is a National Security Problem, But Q Day Is Coming. appeared first on The National Interest.

AI-powered cyberattacks are already here. Quantum computing could soon break the encryption underpinning the modern economy.

“While AI will help us improve cyber defense over time, it also accelerates the speed, scale, and sophistication of cyber threats. Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.”

That warning came not from a think tank but from the National Security Agency (NSA) and its closest allied intelligence partners—the Five Eyes—in a formal joint statement. That statement was issued on June 22, 2026, less than a month before a rogue artificial intelligence (AI) escaped from OpenAI’s secure systems and launched an autonomous, undirected attack on another AI company. As it turns out, the threat was not months away. It is now. 

AI Cyberattacks Are a Warning About Q Day 

AI powered cyberattacks are deeply concerning by themselves, but it is the harbinger of something far worse: a moment called “Q Day.” Q Day is when AI-powered quantum computing becomes capable of breaking the public-key encryption protecting virtually every trusted computer network on earth.

Q Day is a bigger problem than many policymakers outside of the information technology stovepipe realize. Even without quantum computing, AI-enabled cyberattacks have already proven dangerous. Paired with the brute force of quantum computing, AI will be able to defeat most encryption, across all domains, nearly instantaneously. When Q Day arrives, the Root of Trust (RoT) underpinning all electronic transactions—banking, power grids, defense systems, health care, supply chains, global financial markets—can be shattered at blinding speed. Everything connected to the internet becomes vulnerable without warning. If we are not prepared, the 21st-century economy goes back to the Stone Age. We do not know when Q Day will arrive. We only know it is coming, and fast.

The closest parallel is Y2K—but not in the way most people remember it. Y2K was, to the public, a giant nothingburger. That is because the US government spent over $8 billion across a decade of preparation. We were ready, so nothing terrible happened. Replacing legacy systems with post-quantum-safe equivalents will cost far more, and the money must be spent in a torrent. Unlike Y2K, we cannot merely patch a date field. The entire cryptographic foundation of the internet must be replaced—and we have not yet begun in earnest.

China Is Racing Toward AI-Powered Quantum Capabilities

America’s adversaries are not waiting. Qihoo 360—blacklisted by the United States since 2020 for links to Chinese military and intelligence agencies—recently announced an AI system it calls “a cyber nuclear weapon.” DeepSeek, Alibaba, and ByteDance, among others, are believed to be pursuing similar capabilities. Many Chinese firms are also leading the rush to develop quantum computing. This is no accident. China’s “Military-Civil Fusion” policy requires every Chinese company to cooperate fully with the People’s Liberation Army under penalty of law, with AI designated an area of intense focus. When advanced AI is paired with quantum computing in the hands of an adversary operating under that framework, the threat is not theoretical. It is existential.

Trump’s Executive Order Advances Post-Quantum Security

Recognizing the threat, on June 22 President Donald Trump signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” prudently directing federal agencies and operators of critical infrastructure to migrate to post-quantum cryptography (PQC)—algorithms certified by the National Institute of Standards and Technology (NIST) as resistant to quantum assault. The following day, the government published a proposed amendment to the Federal Acquisition Regulations (FAR) expanding the scope of networks required to comply with NIST encryption standards. 

NIST is the linchpin on which both government and industry depend. Its encryption standards are incorporated by reference across a wide body of law—including the FAR, Federal Trade Commission’s Safeguards Rule, New York Department of Financial Services’ Cybersecurity Regulation, HIPAA’s Security Rule, and many cyber insurance policies covering privately managed critical infrastructure. When NIST requires PQC, the entire legal framework will spring to life. 

NIST Is Falling Behind on Post-Quantum Cryptography

The problem is that NIST’s Cryptographic Module Validation Program has fallen far behind. In 2024, NIST finalized its first three PQC standards but has not added to them since, and more are needed across a broad array of hardware and software applications. 

Unfortunately, almost nobody uses these algorithms today. The reason they are largely unused is that NIST guidance does not yet require it. NIST last updated its core Security Requirements for Cryptographic Modules in 2019, with no reference to quantum. Draft transition guidance published in 2024 was never finalized or implemented and stopped short of requiring PQC adoption. It was merely “encouraging” implementers to plan for it “where needed.” 

To be unambiguously clear, it is needed. Everywhere. Now.

America Must Prepare Now to Make Q Day Boring 

Fairness requires acknowledging NIST has good people working on this problem. They have not been sitting on their hands. At the same time, Q Day has not been getting the attention it requires among politically accountable policymakers in the executive branch, Congress, or industry. The effort has been underfunded and has lacked adequate high-level attention. 

Congress, industry, and our allies must follow with the funding, urgency, and coordination that this threat demands. Sustained attention at the National Security Council is needed to force through bureaucratic gridlock. Congress should fund and accelerate NIST’s efforts and hold hearings across the committees of jurisdiction to identify gaps and drive implementation across government and industry alike. Solutions the United States develops will feed through allied nations, ensuring adversaries cannot exploit the weakest links of global supply chains and the financial system.

We made Y2K boring. We can make Q Day boring, too. It is not yet too late, but the window is closing and is measured now in months, not years. Building trusted post-quantum cryptography is the only thing standing between Q Day and the Stone Age.

About the Author: Brandt Pasco

Brandt Pasco is a Washington, DC-based attorney and strategic advisor to BTQ Technologies Corp. He brings more than two decades of experience across government, law, venture capital, technology commercialization, and national security, including prior roles with the US Congress, Department of Defense, National Security Council, and In-Q-Tel.

The post AI Is a National Security Problem, But Q Day Is Coming. appeared first on The National Interest.