Artificial intelligence and quantum technology are radically redefining cybersecurity, and the scale and speed with which both digital attackers and their defenders can work.
AI-based cyberattacks are already becoming a formidable opponent for current defences. Cybercriminals are able to automate their attacks more quickly than ever with AI. It is possible to use generative AI for social engineering at large scales, create tens or thousands of customized phishing email in seconds, and access voice cloning technology that can bypass security measures. Agentic AI is raising the stakes with autonomous systems capable of reasoning, acting, and adapting like humans.
The threat landscape is not only shaped by AI. If quantum computing is not regulated, it could seriously compromise current encryption standards. Quantum algorithms are capable of solving the mathematic problems that underlie most cryptography. This includes public-key system like RSA, Elliptic Curve and digital signatures.
Quantum is here. “We know quantum is coming.
Bailey says that most organizations understandably focus on AI threats because of their immediacy. Quantum may sound science-fiction, but these scenarios will arrive faster than most people realize. Start investing in defences now that are able to withstand AI and quantum threats.
This defense relies on a zero-trust approach to cyber security, which is built upon the assumption that no device or user can be trusted inherently. Zero trust enforces continuous verification and allows for constant monitoring. This ensures any attempt to exploit vulnerabilities is quickly detected in real-time. The approach adopted is technology-independent and provides a robust framework that can withstand a constantly changing threat landscape.
Installing AI defences
AI lowers the entry barrier for cyberattacks. Hackers with little or no resources can infiltrate and manipulate digital vulnerabilities.
Nearly three quarters of cyber professionals (74%) say AI-enabled attacks are already having an impact on their organizations, and 90% expect such threats to occur in the next year or two.
Bailey says AI-powered opponents have sophisticated techniques and work at machine speed. The only way to stay ahead is by using AI to automate responses and defend at machine-speed.
Bailey says that to achieve this, security organizations need modernize their systems, platforms and operations in order to automate the detection of threats and responses, processes which previously depended on manual rule writing and reaction time. The systems need to adapt as criminal tactics and environments change.
Companies must also strengthen their AI data and models to protect themselves from AI malware. These risks include prompt injections where malicious users craft a prompt that manipulates an AI model to perform unintended action, bypassing the original instructions and safety safeguards.
Agentic AI is a step up in the game, as hackers can use AI agents for automated attacks and to make tactical decisions with no constant oversight from humans. Bailey says that “Agentic AI can reduce the costs of the kill-chain.” Cybercriminals of all stripes could now launch campaigns which are currently only available to well-funded intelligence operations.
AI agents are being explored by organizations to help them keep up with the competition. Cisco’s AI Readiness Index 2025 shows that nearly 40% of organizations expect to use agentic AI in the coming 12 months to assist or augment teams, particularly those involved with cybersecurity. AI agents that are trained to analyze telemetry can be used for identifying anomalies and signals in machine data.
Quantifying the threat
Quantum is unaffected by the AI-driven threats that are causing so much concern. KPMG surveyed almost three quarters of US organisations (73%) who believe that it’s only a question of time until cybercriminals use quantum to disrupt and decrypt today’s security protocols. Despite this, more than half (81%) of respondents admit that they can do more to protect their data.
Businesses are justified in being concerned. Actors of threat are stockpiling encrypted sensitive data for cracking once quantum technology is mature. State-sponsored actors could intercept government communications, while cybercriminal groups might store encrypted financial data or internet traffic.
Quantum defenses are being developed by large technology companies. Apple, for example, uses the cryptography protocol PQ3 in its iMessage platform to protect against attacks that harvest now and decrypt later. Google has been testing the post-quantum encryption (PQC), which is immune to both attacks by quantum computers and classic ones, in its Chrome browser. Cisco, says Bailey, “has invested significant amounts in quantum-proofing its software and infrastructure.” In the coming 18-24 months, you’ll likely see many more businesses and government agencies taking similar measures.
A wider variety of organizations are preparing for quantum defenses as regulations such as the US Quantum Computing Cybersecurity Preparedness Act outline requirements to mitigate against quantum threats. These include standardized PQC algorithm by the National Institute of Standards and Technology.
Bailey offers two important actions for organizations that are just beginning their journey. First, establish visibility. He says to “understand your data and its location.” Take inventory, evaluate sensitivity and examine your encryption keys. Rotate any weak or obsolete ones.
Plan for migration. Next, determine what is required to implement post-quantum algorithm across all your infrastructure. Bailey says that this means not only addressing the technology but also considering the implications for people and processes.
Adopting proactive defense
Bailey says that a zero-trust approach is the best way to build resilience in both AI and quantum. This approach embeds zero-trust access controls in users, business apps, networks and clouds. It only grants the minimal access necessary to accomplish a task. This approach can minimize the surface of attack by limiting a possible threat to a small area, and preventing them from gaining access to other systems.
In this architecture of zero-trust, organisations can incorporate specific measures that will protect them against AI and quantum threats. Quantum-immune encryption and AI-powered security and analytics tools, for example, can be used in order to detect complex attacks and automate responses.
Bailey adds that “zero trust” slows attacks down and increases resilience. It ensures even in the event of a security breach, that crown jewels are protected and operations recover quickly.
In the end, businesses should not be waiting for new threats and changes to occur. It is imperative that they act now. Bailey says that this is not a “what-if” scenario, but a “when”. The organizations that make investments early are the ones who will set the pace and not those scrambling behind.
The content of this article was created by Insights – the custom content division of MIT Technology Review. The editorial staff of MIT Technology Review did not write this content. The article was written, researched and designed by humans, including writers, editors and analysts. It includes writing surveys and collecting data for surveys. AI tools were only used in secondary production that was human reviewed.