Why not wait until AI is under control?
This is the most common reason organizations give for deferring, and it deserves a real answer rather than a dismissal, because the premise behind it is largely correct.
AI genuinely is consuming security attention, budget, and executive patience. Boards are asking about it. The risks are present-tense and visible in a way this one is not. An organization that put every security dollar into quantum migration this year while ignoring model governance would be making a serious mistake.
The real answer is narrower: the 2 programs compete for far less than they appear to, and only 1 of them gets more expensive the longer it waits.
The short version:
- The objection is partly right, and this page concedes that before arguing with it.
- The 2 programs use different people, budgets, and vendors. They contend for executive attention rather than for the same resources.
- Deferring behaves differently here. AI risk deferred costs response time. This deferred costs data permanently, because what’s collected while you wait can’t be un-collected.
- The long pole is procurement rather than effort. Your vendors’ timelines run for years, and starting later leaves them unchanged.
- The first step serves both programs. You can’t govern what flows into a model without knowing how it’s protected.
- AI raises the value of the archive, which makes the 2 risks compound rather than substitute.
Where is the objection right?
Three places, and conceding them is what makes the rest credible.
AI risk is present-tense and this is not. Model misuse, data leakage into third-party tools, prompt injection, and shadow AI adoption are all happening in your organization right now. No quantum computer capable of breaking encryption exists. If you have finite attention this quarter and one of these is live, the live one wins.
Attention is genuinely finite. This dynamic was named on the record at a Washington quantum conference in June 2026, where the chief scientist of the Government Accountability Office described AI as “sucking the oxygen out of the room” for quantum funding, because it shows demonstrable benefits on existing hardware. That’s an accurate description of the competition, made by someone with no product to sell.
Source: Forum Global, “The Report: Quantum USA 2026,” Washington D.C., June 18, 2026. The publisher states that third-party figures and characterizations belong to the sources who advanced them rather than being findings of Forum Global. The report isn’t posted at a public URL, so this attribution names the speaker, event, and date instead of linking. Every claim in this Guide that rests on it is listed at Every figure and where it comes from.
Source: Forum Global, “The Report: Quantum USA 2026,” Washington D.C., June 18, 2026, recording remarks by Sterling Thomas of the Government Accountability Office. Statements are attributed to the speakers who made them.
Nobody should run a crash program. The correct posture here has never been urgency for its own sake. It’s a scoped inventory, a named owner, and a sequenced plan, which is a fraction of what an AI governance program costs.
Do the 2 programs actually compete?
Much less than they look like they do. They overlap on executive attention and almost nowhere else.
| AI security program | Post-quantum migration | |
|---|---|---|
| Who does the work | Data science, model risk, governance, legal | Infrastructure, PKI, procurement, vendor management |
| What you buy | Monitoring, governance tooling, policy | Almost nothing. The algorithms are free |
| What it costs | Staff and tooling, ongoing | Labor and coordination, plus hardware replacement |
| Vendor dependency | Your AI vendors | Your infrastructure and software vendors |
| Time to first value | Weeks to months | The inventory is weeks; the migration is years |
| What happens if deferred | Risk accumulates and stays addressable | Data exposed during the delay is exposed permanently |
The row that matters is the last one, and it’s the whole argument.
What makes deferring this one different?
Most risk deferral is reversible. You wait, the risk grows, and when you finally act you address the accumulated risk. Late is worse than early, and late still works.
This one has a property almost nothing else in security has: the data collected during the delay cannot be protected afterward. If your records crossed a network under today’s encryption while you were busy, and somebody recorded them, migrating in 2029 does nothing for that traffic. You can protect everything from the migration forward and nothing from before it.
That’s what makes “we’ll get to it” a decision rather than a postponement. Deferring AI work leaves you exposed until you act. Deferring this work leaves a permanent window in your data that no future action closes.
Whether that matters to you depends entirely on one question: how much of what you send has to stay confidential for a decade? For an organization whose data genuinely stops mattering in 18 months, the answer is that this can wait. For one holding medical records, intellectual property, legal files, or anything with a lifetime horizon, the window you leave open is the loss.
Isn’t there time, given no machine exists?
The machine’s arrival date isn’t what sets your timeline. Two other things do, and both are already running.
Your vendors’ schedules. Most of your cryptography sits inside purchased products. If a critical vendor ships post-quantum support in 2029, your migration for those systems completes in 2029 regardless of when you start or how hard you push. Starting later doesn’t compress that; it just means you begin the conversation with less leverage and closer to a deadline. The moment to get a dated commitment is at renewal, and renewals arrive on a calendar you don’t control.
Your own migration duration. Migrations of this size run for years in large organizations. The published federal schedule runs 2025 to 2035 for a reason.
So the arithmetic that decides urgency has nothing to do with predicting quantum computers: how long must this data stay confidential, plus how long will our migration take, against how long we have? Both of those inputs are knowable today, and neither improves by waiting.
Does AI make this better or worse?
Worse, in a specific way that’s worth understanding, and it’s the part that turns the 2 risks from substitutes into a compound.
An archive of decrypted material is only as dangerous as somebody’s ability to exploit it. Historically, reading a decade of an organization’s traffic meant somebody had to actually read it. That labor was a real limit on the harm.
That limit is disappearing. The same capabilities absorbing your attention now are what make a future archive cheap to mine, correlate, and turn into something usable at scale. The value of collecting your traffic today rises as the cost of exploiting it falls.
Which inverts the argument entirely: AI progress is a reason the collection happening now matters more, not a reason to attend to it later.
What should we actually do, given both?
Five things, and they’re deliberately small, because the point is that this doesn’t compete with your AI program.
- Fund a scoped inventory, not a migration. Time-boxed, aimed at your most sensitive systems. This is weeks of work, not a program, and it produces the numbers everything else needs.
- Put the vendor question into renewals you’re already doing. No new process. When a contract comes up, the post-quantum question goes into it. This is the highest-value thing on the list and it costs nothing.
- Name an owner, even a part-time one. Ambiguous ownership is the single most common reason nothing starts.
- Sort your data by confidentiality lifetime. Business owners answer this rather than engineers, and it tells you whether you have a 2027 problem or a 2032 one.
- Let the migration itself wait if it must. Sequencing the work behind AI is defensible. Sequencing the inventory and the vendor conversations behind it is what costs you, because those are the long-lead items.
The distinction in point 5 is the practical answer to the whole objection. You can defer the expensive part. Defer the cheap part and you lose the leverage and the data both.
What does the inventory do for the AI program?
More than most teams expect, which is why it’s the item to fund first even under an AI-dominated agenda.
An AI governance program has to answer where sensitive data lives, which systems it flows through, which third parties receive it, and how it’s protected in transit and at rest. A cryptographic inventory answers a large part of that, because it’s a map of where sensitive data moves and what protects it.
Organizations that build one for quantum reasons routinely find it’s the first accurate data-flow map they’ve ever had. That’s a genuine argument for doing it now under either banner.
Questions people ask
We have 3 people on security. Is this realistic? The 5 items above are, and a migration program isn’t. For an organization that size, the vendor question at renewal does most of the work. See What if we are a small business.
Our board only asks about AI. Then bring it as a dated obligation rather than a technology topic. Your binding date comes from your own contracts and certifications, and that framing survives a board meeting where a technology briefing wouldn’t. See How do I explain this to my board.
Is there a version where waiting is correct? Yes, and it’s honest to say so. If nothing you hold stays sensitive beyond a couple of years, no customer or certification imposes a date on you, and you own no long-lived equipment, then the inventory is worth an afternoon and the migration can wait.
Could AI solve the migration for us? It helps with discovery, and there’s genuine tooling for inventory assistance. It doesn’t change vendor timelines or replace hardware, which are the long poles.
What if quantum computers never work? A real possibility, argued by credible people. The inventory retains its value regardless, because it’s a data-flow map, and the dated obligations in your contracts don’t depend on the machine arriving. See Is this overhyped.
Which do we do first if we can only do one? Do the AI work first, and spend the afternoon on the inventory and the vendor question anyway. Those 2 are hours, not a program, and they’re the parts that get more expensive to skip.
Where to go next
- Where do we actually start is the first 90 days, for someone with no idea where to begin.
- What of our company data is at risk answers the confidentiality-lifetime question.
- What can I not fix myself covers the vendor timelines that set your schedule.
- How do I explain this to my board covers the framing that survives an AI-dominated agenda.
- For Business Leaders MOC is the full business route.
Go deeper into the technical detail
The technical version, on the psychology that makes a slow invisible threat easy to wave off, is Why Is the Quantum Threat So Easy to Ignore.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.