Council Post: AI Agents Are Pulling The Post-Quantum Deadline Forward
Mohan Shekar is VP at SAP, driving enterprise AI adoption, with a focus on emerging computing technologies.

getty
A finance agent receives what appears to be a routine instruction from a procurement agent: update a supplier's bank details and release the next payment run. No human reviews it; the payment clears at machine speed. The instruction was forged. The exchange relied on an identity and signing architecture designed for today’s application landscape, not for an autonomous, post-quantum future.
This is the shape of the next enterprise security crisis: autonomous agents trusting the wrong machine at the wrong time. And it is about to collide with the quantum timeline sooner than most boards realize.
Boards have spent the past two years asking whether AI agents can book travel and close the books. Far fewer have asked what secures the conversations between them. As agents take on more operational responsibility, trust between machines becomes just as important as their ability to perform tasks. In the agent economy, identity is infrastructure, making quantum-safe trust a foundational requirement rather than a future consideration.
The Two Curves That Are Converging
Two trends are converging to create this risk. The first is the agent economy. Agents no longer just answer prompts; they discover one another, delegate subtasks and act with little human oversight. New agent-to-agent and agent-to-tool standards turn API calls into a dense mesh of machine-to-machine activity, each interaction depending on cryptographic trust: an identity to assert, a key to exchange or a message to sign and verify.
The second is the post-quantum transition. In 2024, NIST finalized its first post-quantum cryptography standards, and governments followed with migration timelines. But the risk does not begin when a cryptographically relevant quantum computer arrives. Under the "harvest now, decrypt later" model, adversaries can capture encrypted data today and store it until future quantum systems can decrypt it.
Enterprises treat these as two roadmaps owned by separate teams. They are one roadmap, and the agent buildout is pulling the cryptographic deadline forward.
Why Agents Change The Shape Of The Problem
The quantum threat applies to everything: TLS, VPNs, the software supply chain and more. So why single out agents? Because they change the shape of the exposure, not just its size.
• Scale: One agentic workflow can spawn dozens of authenticated sessions and signing operations; across a fleet, the attack surface expands dramatically.
• Shadow Agents: Business units are already spinning up low-code and no-code agents with little oversight—the shadow IT of the agent era. Each agent can create new cryptographic connections that bypass traditional inventories, leaving CISOs unable to see the full scope of their enterprise’s exposure.
• Autonomy: Without humans reviewing each step, proving a message’s authenticity matters as much as keeping it secret. A spoofed agent can create operational, financial and reputational damage before anyone has time to intervene.
• Longevity: Agent sessions carry context-rich data that may need to remain confidential for years, creating a valuable harvest target. This includes not just metadata, but business context, operational instructions, sensitive workflows and other information that adversaries could seek to decrypt later.
The Real Timeline: Shorter Than The Headline Date
The number often quoted is 2035, but the NSA’s CNSA 2.0 guidance sets migration milestones that require organizations to begin moving toward quantum-resistant capabilities well before full transition deadlines. The deadline that matters is not when a cryptographically relevant quantum computer arrives, but when enterprises allow today’s cryptography to become embedded in systems too large, complex and costly to re-engineer.
Any data that must remain confidential for years is part of the quantum risk window once it moves across public networks, because encrypted traffic can be harvested today and decrypted in the future. Replacing cryptography in deployed systems is slow, often taking years when it is deeply embedded. The agent infrastructure built this year will likely still be running when the threat arrives; build around classical-only cryptography now, and you create an expensive retrofit across a much larger, more autonomous fleet later.
What Leaders Should Do
The algorithm choices are no longer theoretical; NIST has standardized the first post-quantum algorithms, so the hard part is execution.
Inventory your cryptography, including your agents.
You cannot migrate what you cannot see, and most technology inventories stop at servers and applications. Expand that inventory to include agent identities, signing keys, tool connections, inter-agent communication paths and shadow agents, then use the results to build a prioritized remediation backlog jointly owned by architecture, procurement and risk.
Make crypto-agility a procurement requirement.
Every agent-platform RFP should require crypto-agility, a post-quantum roadmap, key rotation and signed agent identity. Standards such as A2A and MCP are evolving rapidly, but they do not yet mandate quantum-safe cryptography or provide a uniform, end-to-end model for agent identity, delegation and message provenance.
Crypto-agility also provides algorithm insurance: if a vulnerability emerges in a cryptographic algorithm, organizations can replace it through configuration changes rather than costly code rewrites.
Pilot hybrid cryptography on your highest-value flows.
Run classical and post-quantum algorithms together where data is most sensitive, so a weakness in either does not break the channel.
Require verifiable agent identity.
Make cryptographic proof of an agent’s identity non-negotiable in production. Every agent should have a verifiable identity that is signed, permissioned, monitored and revocable. Existing mechanisms such as SPIFFE/SPIRE, decentralized identifiers (DIDs), and TPMs or HSMs can help bind agent identities and code to authorized permissions, including at the hardware level.
Make quantum readiness a board-level priority.
Additionally, boards should answer four questions:
1. Which autonomous agents are already operating in the enterprise?
2. How do those agents prove their identity?
3. Which agent conversations hold data that must stay confidential for years?
4. Can our agent platforms move to quantum-safe cryptography without a major rebuild?
If those answers are unclear, there is no post-quantum roadmap for the autonomous enterprise yet.
The Strategic Read
A competitive advantage hides inside this risk. Building quantum-safe foundations from the start costs a fraction of retrofitting them later, while also opening access to regulated markets where readiness is becoming a condition of doing business. The U.K.’s NCSC has set migration milestones for 2028, 2031 and 2035, while the EU’s coordinated roadmap calls to begin transitioning by the end of 2026 and critical infrastructure to move toward PQC by 2030. As these requirements flow through supply chains, quantum readiness will increasingly become table stakes for organizations operating across borders.
The agent economy is being built now. The mistake would be to secure it for yesterday’s internet rather than tomorrow’s threat model.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?