With news of rogue AI agents hacking businesses and governments in recent weeks, it’s not surprising that many businesses are worrying how they can protect themselves against such attacks.
Big AI firms are scrambling to arrest these fears by deploying more security around autonomous agents, while seeking a way to make their AI safe to use.
The new threat from rogue AI is nascent. While the damage it can cause may eventually be extensive, it is a development that is still very much still in flux now.
What’s less in flux, and a lot more certain, is the threat of powerful quantum computers unscrambling the security that has been built into every digital transaction today. The root of trust for everything online is at risk.

By some estimates, the first quantum computers that can undo the encryption protecting our e-mails, shopping and banking will be up and running in as soon as five years. Others put that at 10 years or more.
That may seem a long time until you realise that it took 20 years for one of today’s public-key encryption systems – RSA (or Rivest-Shamir-Adelman) – to be adopted across the industry.
Plus, now, with all the focus on AI threats, organisations may just put their efforts and budgets into the immediate and urgent, and miss the big wave coming their way.
Delaying the inevitable is certainly not a good idea. Hackers are already harvesting the data now so they can feed it to quantum computers that are powerful enough in the coming years.
In other words, the longer an organisation doesn’t move to quantum-safe encryption algorithm, the more risk it puts itself and its stakeholders – customers, partners or citizens – under.
In a global study earlier this year, security firm Thales found that 61 per cent of security and IT professionals were worried about this threat of data being stolen to be decrypted in future.
Unfortunately, survey after survey has shown that organisations are not ready for when the quantum threat becomes live. This is despite deadlines rapidly closing in.
The United States’ National Institute of Standards and Technology (NIST) has advised organisations to switch to encryption that can withstand the brute force attacks of quantum computers that are many times more powerful than today’s classical machines by 2030. By 2035, vulnerable cryptography algorithms from today will be disallowed in the country’s federal government systems.
In Singapore, the Cyber Security Agency has provided a free assessment tool for organisations to test themselves and get ready.
That’s the first step, because migrating from a long-used encryption standard that’s been the foundation of all your digital transactions isn’t easy.
If you’re running IT systems for a bank or government agency, you don’t want to mess things up and “self pwn” yourself by taking down your own services accidentally.
This means the big move has to be done step by step. The most critical parts of an organisation might have to be the first ones to get onboard, before others are migrated over. Perhaps the new and old systems might have to run in parallel before cutting everything over.
And the job isn’t over once you have migrated to a quantum-safe encryption algorithm, by upgrading your encryption hardware and resetting your apps and networks.
Already, a potential quantum-safe algorithm being considered as a future standard has been ruled out after its vulnerabilities were exposed in July.
Called Hawk, it had its key strength cut by half when a tester guided by Anthropic’s AI found a previously unknown method for cracking a digital signature.
This is crucial because today’s most important algorithms, such as RSA and ECC (Elliptic Curve Cryptography), have stood the test of time, at least with today’s classical computers.
Even before quantum computers are that powerful today, a potential “quantum-safe” algorithm has been found to be actually not safe enough.
The good news is that the NIST’s three finalised “quantum-safe” cryptography standards from 2024 are not affected and remain fully secure. They can and still should be deployed by organisations looking to upgrade their security.
The big lesson here is to be ready for algorithm standards that evolve. Clearly, AI is finding ways to unlock encryption that humans haven’t found in decades before, which means organisations have to be ready to switch, should one standard be found to be unsafe.
That, of course, is easier said than done. Many vendors, including Thales, promise that their hardware will support “crypto-agility”, but organisations have to assess how difficult it will be to switch from one standard to another in future.
The key, of course, is getting started. Despite focussing on tasks like AI governance to keep AI agents from going rogue, organisations also have to build up their defences for the impending quantum threat that is getting closer by the day.
If you ask any large organisation’s head of cybersecurity, you’d hear a difficult answer on which defence to focus on. Both are vexing at the worst moment now.
It’s like being in a fancy new autonomous car that now threatens to get out of control, while a tsunami is slowing arriving in the horizon. Can you drive to safety in time?
