Third round of PQC algorithms faces AI threat
A new phase in post-quantum cryptography (PQC) is underway, with the field of candidate digital signature algorithms narrowing just as AI systems begin to expose weaknesses in the very schemes designed to withstand quantum attacks.
After a decade of assessments and three rounds of evaluation and analysis, the National Institute of Standards and Technology (NIST) in the US selected the first four algorithms to be standardised that are resistant to cracking by quantum computers. Nine new algorithms are now going forward for assessment over the next two years in the face of AI attacks.
The race to secure data
The public-key encapsulation mechanism (KEM) selected for standardisation for post-quantum cryptography (PQC) was CRYSTALS-KYBER (ML-KEM). The digital signatures selected were CRYSTALS-Dilithium (ML-DSA), FALCON (FN-DSA), and SPHINCS+ (SLH-DSA). Except for SPHINCS+, all of these schemes are based on structured lattices. While several non-lattice-based KEMs remained under consideration in the fourth round, no signature schemes remained.
So in September 2022, NIST called for additional digital signature proposals to be considered to diversify its post-quantum signature portfolio. Since two signature schemes based on structured lattices had already been standardized, NIST expressed particular interest in additional general-purpose signature schemes based on a security assumption that did not use structured lattices as well as signature schemes with short signatures and fast verification.
Forty algorithms were evaluated in the first round and reduced to fourteen second-round candidates. Now, after 18 months of evaluation, NIST has selected nine candidates for the third round of the Additional Digital Signatures for the PQC standardisation process.
The advancing digital signature algorithms are:
FAEST
HAWK
MAYO
MQOM
QR-UOV
SDitH
SNOVA
SQIsign
UOV
These third-round candidates will have the opportunity to submit tweaks to the specifications and implementations and this third phase of evaluation and review is expected to last approximately two years.
However, AI has already reduced the safety of one of these algorithms, HAWK, and the existing AES encryption scheme.
Researchers at AI developer Anthropic have discovered improved ways to attack HAWK, a digital signature scheme that was built for a post-quantum world. The second identifies a new way to attack round-reduced AES, the most widely used symmetric cipher.
Anthropic’s Claude framework had previously found bugs in cryptographic libraries as the result of the incorrect implementation of the algorithms. Now, the same team has found that Claude’s successor, Mythos, is able to find mathematical flaws in the algorithms themselves.
One paper details an improved attack against a digital signature scheme called HAWK, one of the third-round candidates under consideration from this call. Despite HAWK having survived two rounds of expert human review over a period of two years, Mythos was able to improve the best-known attack on it in just 60 hours of work—effectively cutting its key strength in half.
The second result concerns the current Advanced Encryption Standard (AES) symmetric cipher adopted by NIST in 2001. This has received more scrutiny than almost any other encryption algorithm, and weaker variations of the algorithm are regularly studied in cryptography research; Mythos found a way to break one such weaker version, and eliminated one of the guesses an attacker needs to make, improving the speed of the previous best attacks by 200 to 800x.
Both results show the potential for frontier AI models to help discover flaws in important cryptographic algorithms, both before and after real-world deployment. This is cryptography research working as intended: stress-testing algorithms to build trust and ultimately make systems more secure.
Mythos achieved these results mostly autonomously and mostly without human intervention. Each of the results cost roughly $100,000 in API costs to develop.
The researchers also worked with academics at ETH Zurich, Tel Aviv University, and TU Berlin to build CryptanalysisBench, a benchmark that packages together many cryptographic ciphers and makes it easy for others to evaluate the capabilities of large language models (LLMs) on this important topic.
The Five Eyes consortium of the US, UK, Canada, Australia and New Zealand is also highlighting the risks posed by AI to encryption technologies.
“Adversaries are already using AI to move faster and more effectively. Defenders must do the same,” it said in June 2026. “Organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents – reducing both the cost and impact of incidents. Success will not come from having the most tools. It will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy. The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years.”
Quantum timeline
Microsoft has acknowledged that the quantum-safe timeline has changed and these PQC algorithms will need to be fully implemented by 2030.
For years, planning for post-quantum cryptography (PQC) was framed as a future problem: important, inevitable, but distant. That perspective is evolving as technology advances and organizations prepare for the scale and complexity of the transition ahead.
“At Microsoft, we are acting on this shift by bringing our quantum-safe timeline forward so organizations can begin the transition earlier and with greater confidence,” said Mark Russinovich, Chief Technology Officer for Microsoft Azure.
“Advances in quantum research and development have shifted the risk horizon,” he said. “We believe cryptographically relevant quantum computers could arrive sooner than previously expected—and the work required to prepare is significant so organizations need to start now.”
Recent government actions, including US and French guidance to adopt quantum-safe cryptography as early as 2030 in certain high-risk systems, reflect the same conclusion: preparing for this transition is already underway.
“In response to these shifts, we are accelerating the Microsoft Quantum Safe Program (QSP) timeline, and the goal is to transition products and services to PQC by 2029,” he said.
Accelerating the timeline means pulling forward key engineering work so new standards can be adopted earlier and modernization can begin well ahead of broad quantum impact.
Modernizing network cryptography is a prerequisite for post-quantum adoption. As an example, adopting TLS 1.3 establishes a baseline that enables hybrid and post-quantum key exchange as standards mature.
The ability to change cryptography without redesigning systems enables the safe, timely adoption of new cryptographic standards. This crypto-agility requires making cryptographic settings configurable outside of the application, standardizing key management and rotation, and eliminating hard-coded algorithms.
The most complex work is securing the chains of trust that underpin software, devices, and services at scale. That includes code signing, certificate issuance, key protection, and update pipelines. This includes hardware-backed key protection, updated certificate lifetimes and policies, and auditable signing and issuance processes for critical trust anchors, with a transition to PQC algorithms as they become available.
For most organizations, the hardest part isn’t selecting post-quantum algorithms. It’s understanding and updating where cryptography already exists across apps, services, networks, identities, certificates, and hardware.
“Across industries and regions, organizations are already taking steps, with several consistent themes emerging,” he said.
Building crypto‑agility into systems delivers long-term resilience so new cryptography standards can be adopted over time without redesigning systems. Long-lived, sensitive data requires earlier protection. Organizations are prioritizing data with long confidentiality lifetimes, recognising that encrypted data captured today could be exposed in the future (harvest now, decrypt later) as cryptographic capabilities evolve.
Executive order
This is reflected in the recent Executive Order from the US administration.
Executive Order 14409 mandates the transition to post-quantum cryptography. Securing the Nation Against Advanced Cryptographic Attacks accelerates the transition from legacy cryptography and provides a sharp focus for federal agencies, critical infrastructure operators, and industry, supply chain and vendors. If you do business with the US government, compliance is no longer optional.
This legally binding defence strategy aims to counteract the Harvest-Now-Decrypt-Later threat from foreign adversaries, and it marks a significant escalation in the US defence posture against quantum computing. It’s a fundamental shift, from encouraging quantum readiness to enforcing it, and it alters the timeline for PQC adoption, with hard deadlines replacing ‘best efforts’ and deploying the Federal Acquisition Regulatory Council (FAR) to force contractor compliance, according to Matthew Stubbs, an engineer at UK cryptography specialist PQShield.
The order establishes explicit, legally binding compliance deadlines for key establishment by 2030, with another year for the implementation of digital signatures and identity verification.
There is now a requirement for the Department of Commerce to complete an active PQC migration pilot by the end of 2027. The aim is to provide an immediate blueprint for the rest of the ecosystem.
The EO also tasks the State Department with the challenge of driving international adoption, and establishes NIST standards as the de facto standard for critical infrastructure.
US agencies are now required to designate a dedicated PQC Migration Lead, and crypto-agility is now an explicit requirement for federal procurement and ongoing contracts, and is no longer a buzzword. Contractors will have to meet strict standards and vulnerability disclosure policies by the end of 2030.
This is reflected by timelines around the world. ANSSI, the French cybersecurity agency, will require quantum-resistant encryption from 2027 so that French businesses and government bodies purchase exclusively quantum-safe products by 2030.
The EU Agency for Cybersecurity (ENISA) has published the first draft of Version 3 of the Agreed Cryptographic Mechanisms (ACM) document.
The draft marks a significant move by defining which cryptographic functions are accepted by all national cybersecurity certification authorities (NCCAs) for products undergoing European Cybersecurity Certifications.
With quantum threats advancing, the lifespan of the algorithms needs rethinking. So ENISA is replacing legacy algorithms with a scheme that gives the newer algorithms a timeline, a date for when an algorithm should be deprecated. Version 3 has already removed a number of mechanisms, including SGA-224 and SHA-512.
AES key length
Some commentators suggest the quantum threat requires an immediate doubling of symmetric key lengths (for example, using AES-256 rather than AES-128). However ENISA points out that key doubling is not strictly necessary for PQC use. The suggestion here is a key length longer than 192.
Appendix C of the draft also details how the document will adapt in the future, including the pipeline for new algorithms. To be included in future versions, candidate algorithms should be standardised and stable for a minimum of two years, as well as highly secure. They also need to be peer-reviewed for side-channel analysis and fault-attack testing, with public documentation.
Consultation has just finished for Version 3 of ENISA’s document. This is not a minor update. It’s a structural realignment for the post-quantum era, and it’s likely to define the EUCC certification of cryptographic products of the future.
This concept represents a deviation from the approach recommended by NIST and CNSA 2.0, where “Deprecated” and “Disallowed” mechanisms are all mandated to be phased out by no later than 2033 with no extensions proposed.
“EO 14409 draws a line in the sand,” said Stubbs. “Quantum readiness is now an active compliance milestone, and the tightened timelines make PQC migration a priority that organizations cannot afford to delay. Increasingly, the overhaul of cryptographic systems is becoming a significant discussion at boardroom level, and the time to build strategic PQC roadmaps is now.”
“There’s little doubt: this is a new age for cybersecurity, and the US is lighting the way, with aggressive timelines and PQC requirements, alongside rapidly advancing technology and shrinking implementation windows. The quantum era is here,” said Stubbs.
The post Third round of PQC algorithms faces AI threat appeared first on eeNews Europe.