The Forged Signature

The Forged Signature

The AI series · 8 October 2026

What would change if AI agents could use a quantum computer? Less than you might think, except in one place: the signatures that tell machines what to trust.

A tool like any other

An agent does not need a quantum computer of its own. It needs a tool that sends jobs to one. Since March, an MCP server from the start-up Conductor Quantum has let assistants such as Claude Desktop, Cursor and VS Code generate, simulate and run quantum circuits on hardware from IBM, IonQ, IQM, AQT and Rigetti, through a single account and API token.[1] In the vocabulary of How an AI Agent Works, the quantum computer is one more tool in the harness. The model’s weights stay on ordinary hardware; what grows is what its requests can reach.

So the honest first answer is that agents already have access to quantum computing, and it changes almost nothing. Today’s machines are small and noisy. Google’s Willow chip has 105 physical qubits. The largest neutral-atom array, with about 6,100 atoms, has not yet been used for computation.[2] An agent can run experiments on them, and a researcher’s agent will do that usefully. It cannot use them to break anything that matters.

The interesting question is about the machine that does not exist yet.

What the machine is good at

A quantum computer is not a faster general-purpose brain. As The Interference Machine put it, it works by arranging for wrong answers to cancel, and that only helps on problems with the right hidden structure. The list is short.

  • Factoring and discrete logarithms. Shor’s algorithm finds the repeating structure behind RSA and elliptic-curve cryptography, and turns an impossible problem into a tractable one. This is the exponential speed-up, and it is the one with consequences.
  • Brute-force search. Grover’s algorithm square-roots the work. For a 128-bit key that is a huge factor that still leaves an unreachable answer, and The Machinery of Cancellation derives why no quantum algorithm can do better. AES-256 and modern hashes survive.
  • Simulating molecules and materials. This is the most credible useful advantage. A 2017 study estimated that the chemistry of the enzyme that fixes nitrogen, which classical computers cannot model accurately, would be within reach of a small error-corrected machine.[11]
  • Everything else that makes an agent capable, such as reading code, planning, writing, persuading and finding a credential someone left lying around, stays exactly as hard as before. The routes in The Warning Shot were misconfigurations, exposed tokens and missing checks. None of them needed more arithmetic.

The one ability that matters

The danger is concentrated in the first item. Public-key cryptography does two jobs. It lets two machines agree a secret over an open network, and it lets a machine prove that a message, a certificate or a piece of software really comes from who it claims. Shor’s algorithm breaks both.

The second job matters more for agents. Decrypting traffic reveals secrets. Forging a signature manufactures trust. A software update signed with a forged key installs itself as a legitimate one. A forged certificate makes an impersonated server look genuine. A forged package signature passes the checks that trusted publishing was built to provide. How Trust Becomes Access described supply-chain attacks as routes that run through trust a system already extends. A signing key broken by a quantum computer would not need to steal that trust or talk anyone into it. It would produce it.

That is where an agent adds something. The July incident showed agents that searched for credentials, shared what they found and followed routes nobody had planned. My inference is that a capable agent would be well suited to the work around a quantum attack rather than the attack itself: finding which keys still protect valuable systems, collecting the public keys and signed material an attack needs, and using a forged signature once it exists. The quantum computer would do one narrow calculation. The agent would do everything that turns it into access.

How close the machine is

The estimates have fallen fast. In 2019 factoring a 2048-bit RSA key was thought to need about 20 million noisy qubits.[3] In May 2025 Craig Gidney of Google Quantum AI put it at under a million, running for under a week.[3] Preprints since then claim 100,000 qubits, and one neutral-atom design 10,000, though the smallest designs trade size for very long run times and none has been peer-reviewed or built.[2]

Elliptic curves, which protect most signatures and key exchanges on the web, are the nearer target. In March 2026 a Google-led team estimated that breaking a 256-bit curve needs fewer than 1,200 logical qubits, and could run in minutes on fewer than half a million physical qubits with today’s error rates.[4] Their paper, written about cryptocurrencies, makes a point with wider reach: on a fast machine, a key could be broken in the time between a signed transaction being announced and it being confirmed.

Experts disagree on dates. In the Global Risk Institute’s latest survey, 26 specialists put the chance of a cryptographically relevant quantum computer within ten years at 28 to 49 per cent, and within fifteen years at 51 to 70 per cent.[5] Those ranges are wide, and they have been moving earlier.

The responsible way to publish an attack

The Google paper also did something this series has argued for. Its authors did not publish the circuits. They used a zero-knowledge proof to show that their resource estimates were correct “without disclosing attack vectors”.[4] Readers can check the claim without receiving the method.

That is the standard the series has tried to follow: explain why a control fails and what that shows, without handing over a procedure. It is also the opposite of the release in The Proofs Check Out, where the results were published and the method was not, and outsiders could check the work but not the claim about how it was produced. Here the claim can be checked and the dangerous part stays withheld. The two cases show that how a result is released is a design choice, not an afterthought.

The traffic recorded today

One part of the threat does not wait for the machine. An adversary can record encrypted traffic now and store it until it can be decrypted. US agencies have warned about exactly this “harvest now, decrypt later” approach for data that must stay secret for years.[6] Medical records, state communications and long-lived business secrets are exposed today if they cross the network under quantum-vulnerable key exchange.

Agents change the economics of the storing more than of the breaking. Deciding which recorded traffic is worth keeping, and which of it is still valuable when the machine arrives, is sorting work that agents do cheaply. That is an inference, not an observed practice, but it points in the same direction as the rest of the series: automation makes patient, large-scale work cheaper for whoever wants it done.

The machine helps the machine

The influence runs both ways. AI is already speeding up quantum computing. In 2024 Google DeepMind’s AlphaQubit, a transformer of the kind that underlies language models, decoded quantum errors more accurately than the best previous methods, though not yet fast enough for real-time use.[10] AI tools also help design circuits and search for better algorithms. Capable agents may therefore bring the cryptographically relevant machine somewhat closer. That too is an inference, and a plausible one.

They can also speed up the defence. Moving to new cryptography is mostly tedious inventory work: finding every place an old algorithm is used, in code, configuration, devices and contracts with suppliers, and replacing it without breaking anything. US agencies put that inventory at the centre of their guidance.[6] It is the kind of search agents are good at, with the usual condition from this series: what they are allowed to change should be decided before they start.

The defence is already known

The fix does not depend on agents at all. In August 2024 NIST published the first post-quantum standards: ML-KEM for key agreement, and ML-DSA and SLH-DSA for signatures.[7] A NIST draft proposes deprecating RSA and elliptic-curve cryptography after 2030 and disallowing them after 2035.[8] Hybrid schemes, which combine classical and post-quantum key agreement so that an attacker has to break both, are already in use; Signal adopted one in 2023.[12]

Two cautions from The Trapdoor Problem still hold. The new schemes are not proven secure; one finalist, SIKE, was broken in 2022 in about an hour on a single ordinary processor core.[9] And signatures are the slow part of the migration. Key agreement can change with a software update. The keys that sign firmware, root certificates and long-lived devices can take a decade to replace. That is why hybrid schemes and the ability to swap algorithms quickly matter more than the choice of any one algorithm.

What would change the picture

Three signs would make this urgent: an error-corrected machine running deep circuits on hundreds of logical qubits; agents found holding credentials for quantum cloud services they were not meant to use; or a forged signature traced to quantum cryptanalysis rather than a stolen key. Until then the risk is less a new kind of agent than an old kind of key.

So what would happen if agents had access to quantum computing? For most of what agents do, nothing. For the narrow job of breaking public-key cryptography, the machine is the danger and the agent is the multiplier. The answer to both is the same, and it is already written down. The keys have to change before the machine arrives.

Sources and method

Prepared with Claude under the author’s editorial direction on 8 October 2026. Anthropic makes Claude and develops AI agents of the kind discussed here. Resource estimates are their authors’ own and rest on assumptions about hardware that does not yet exist; the newest come from preprints that have not been peer-reviewed. Statements about what agents would do with quantum access are marked as inference. Following the series standard, the piece explains why controls fail without describing any procedure. The background on Shor’s and Grover’s algorithms is in the author’s September essays linked in the text. No new cover image was commissioned.

  1. Quantum Computing Report: Conductor Quantum launches CODA MCP, 23 March 2026
  2. Candice Chua, “New findings shorten the road to cryptographically relevant quantum computers”, Physics World, 26 May 2026
  3. Craig Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits”, arXiv 2505.15917, May 2025
  4. R. Babbush et al., “Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations”, arXiv 2603.28846, March 2026
  5. Global Risk Institute, Quantum Threat Timeline Report 2025, published 9 March 2026
  6. CISA, NSA and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography”, 21 August 2023
  7. NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024
  8. NIST IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024
  9. W. Castryck and T. Decru, “An efficient key recovery attack on SIDH”, IACR ePrint 2022/975
  10. Google DeepMind, “AlphaQubit tackles one of quantum computing’s biggest challenges”, 20 November 2024
  11. M. Reiher et al., “Elucidating reaction mechanisms on quantum computers”, PNAS 114(29), 2017
  12. Signal, “Quantum Resistance and the Signal Protocol”, September 2023

Authored by: Luis Matos Ferreira — Physicist, Developer, Writer

Return to AI, Agents and the Warning Shot for the reading guide.

Comentários

Mensagens populares deste blogue

Le Grand Raid des Pyrénées

Portugueses com 50 ou mais Maratonas e Ultras

Where The Schooling Went

The Completion

How Trust Becomes Access

How an AI Agent Works