Q-Day Could Arrive Before Quantum Computers Are Commercially Useful, EU Warns

The joint committee of the EU's three financial supervisors warned that an advanced quantum computer could break cryptographic protections for communications, transactions, databases and blockchains, and that such a threat might appear before quantum machines are otherwise commercially useful. The regulators urged member states to adopt post-quantum cryptography migration plans by the end of 2026 and recommended continued planning for AI- and quantum-related risks alongside stronger cybersecurity and operational resilience.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
Q-Day Could Arrive Before Quantum Computers Are Commercially Useful, EU Warns

Why It Matters

If attackers capture encrypted data now, they could decrypt it later once sufficiently powerful quantum machines exist, putting long-lived financial records and blockchain assets at risk. The EU's timeline for migration planning creates a near-term policy deadline for member states and regulated firms.

Key Facts

  • Issuing bodies: Joint committee of the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA)
  • Core warning: An advanced quantum computer could undermine some cryptography used to secure communications, transactions, databases and blockchains
  • Harvest now, decrypt later: Data captured today could be stored and decrypted in the future once quantum-capable decryption exists
  • Policy deadline: NIS Cooperation Group recommended member states adopt a post-quantum cryptography migration strategy by the end of 2026
  • Regulation referenced: Digital Operational Resilience Act requires financial entities to adopt state-of-the-art cryptography against emerging threats

The European Union's banking, insurance and markets supervisors have flagged quantum computing as a material risk to cryptographic protections used across the financial system. In their autumn assessment, the joint committee of the EBA, EIOPA and ESMA cautioned that an advanced quantum computer could render current cryptographic schemes ineffective for securing communications, transactions, databases and blockchains.

A central concern in the report is the tactic known as "harvest now, decrypt later": adversaries could intercept and store encrypted information today and decrypt it later when quantum decryption capabilities exist. The supervisors noted that any data intercepted now that retains value over a decade is effectively at risk under that scenario.

The EU's regulatory framework already addresses emerging cryptographic threats. The Digital Operational Resilience Act mandates that financial entities use state-of-the-art cryptography, and the NIS Cooperation Group has urged member states to adopt a post-quantum cryptography migration strategy by the end of 2026. The supervisors recommended continued planning for quantum and AI-driven risks, alongside measures to bolster operational resilience and cybersecurity.

The report also highlighted potential upside from quantum technology over the medium term, pointing to improvements in optimisation, fraud detection, compliance, pricing and simulation. For distributed ledgers, the exposure is quantifiable: research cited in the assessment found that 6.04 million bitcoins — about 30.2% of issued supply and valued at more than $469 billion in May — have public keys visible on-chain and could be targeted without executing a transaction. Estimates for a so-called "Q-Day," when a machine could break the cryptography underpinning Bitcoin and Ethereum, range from 2030–2032 and beyond, according to the report.

Keep Reading