Synthesized by Clarity (Claude) from 234 sources · May contain errors — spot one? [email protected] · Methodology →
~4 min
Google moved the quantum clock to 2029. Start now.
Seven independent sources caught Google compressing its post-quantum migration by six years — and it landed the same week TurboQuant broke inference economics and ARC-AGI-3 broke the reasoning story. Three foundations shifted at once.
Google publicly committed to finishing its post-quantum cryptography migration by 2029 — six years ahead of NIST's 2035 federal baseline. Android 17 beta is already shipping ML-KEM key support. The White House is reportedly considering pulling the federal deadline to 2030. Seven independent intelligence sources flagged this in a single 24-hour window, which is the strongest cross-source signal you're going to see this quarter.
When the company building the Willow quantum processor tells you their internal threat model just moved by six years, that's not a marketing beat. It's a decision made by people who see the hardware curve up close and decided it was too close for comfort.
Yes, but — a fair reading is that Google set an aggressive internal target partly to pressure the ecosystem, the way they weaponized HTTPS in Chrome. That's probably true. It doesn't matter. The narrative gravity from a hyperscaler committing to 2029 will drag AWS, Azure, and Cloudflare into matching timelines within quarters, and enterprise RFPs will start asking about PQC readiness inside 18 months. The pressure is the point.
The real threat isn't 2029. It's today. Google explicitly named harvest-now-decrypt-later as an active attack pattern, and the APT28 C2 server exposed this week — 500+ days of espionage, 2,800 exfiltrated emails, 240 credential sets with TOTP secrets intact — is exactly the kind of actor doing the harvesting. Any data you encrypt today with RSA or ECC that has to stay confidential past 2029 is at risk right now. Healthcare records, M&A traffic, signing keys, long-lived customer PII.
Enterprise crypto migrations take five to seven years in the wild. You have three. The math doesn't work unless you've started, and most teams haven't even done the inventory.
The other two things that broke this week
Google Research released TurboQuant, which cuts KV-cache memory by 6x and speeds attention up to 8x on existing H100s with zero accuracy loss and zero retraining. Micron and Western Digital dropped 3–5% the day of the ICLR release. The paper was actually published in April 2025 — the market just took eleven months to price it in, which tells you how much alpha still sits in reading arXiv.
The implication isn't that Nvidia is in trouble. It's that inference cost curves are now bending through software, not just silicon. Any AI capex plan built on 2024 assumptions about memory bandwidth needs a revision this quarter. Any product feature you shelved because inference was too expensive is worth re-scoping. And any procurement contract you're about to sign with a 24-month lock-in on GPU-as-a-service pricing needs a flexibility clause.
Then ARC-AGI-3 landed. Gemini Pro scored 0.37%. GPT-5.4 scored 0.26%. Opus 4.6 scored 0.25%. Grok-4.20 scored zero. Humans score 100% on first contact, no training. The spread between the top three frontier models is 0.12 percentage points — statistically indistinguishable noise. This is a categorical ceiling on novel reasoning, not a tuning gap, and it holds across four architecturally different labs.
Combine it with the pentest of a 100%-Claude-generated web app that shipped with textbook LFI, IDOR leaking password hashes, and three known Vite CVEs, plus the 48% hallucination rate measured in o4-mini code, and the picture sharpens: current models are extraordinary pattern matchers and mediocre reasoners. Any roadmap that assumes autonomous agents doing genuine novel reasoning inside eighteen months is building on a floor that isn't there yet.
What connects the three
The reflex is to treat these as separate stories — one for the security team, one for the infra team, one for the AI team. They're the same story. Foundations you assumed were stable for the decade — asymmetric crypto, GPU economics, model capability trajectory — all moved in one week, and the organizations that ship first through the transitions will keep compounding advantage while everyone else negotiates with procurement.
Novo Nordisk's CDO Stephanie Bova gave the operating principle without meaning to. She killed an Anthropic-powered clinical data mining tool because it was expensive and didn't produce results, then redirected the budget to process-automation agents that save $10M–$100M per week of trial acceleration. Her line: if I can do it better in Excel, stay in Excel. Meanwhile 68% of the 1,000+ S&P 500 AI partnerships tracked by CB Insights are still pilots. Only 12% are production vendor relationships. The gap between the Novos and the pilot-forever cohort is where the next two years of enterprise AI winners get sorted.
Do this week
One thing, specific: commission the cryptographic inventory. Not a strategy doc, not a steering committee — a spreadsheet of every place you use RSA, ECC, or ECDH, cross-referenced against the confidentiality horizon of the data each one protects. Anything that needs to stay secret past 2029 gets flagged for the first migration wave. Anything that's a config change in a service mesh or KMS gets moved to hybrid X25519+ML-KEM-768 in the next sprint as a low-risk pilot.
While you're at it, patch Wazuh (CVE-2026-25769/25770), Step CA (CVE-2026-30836), and Harbor (CVE-2026-4404) today. Six CVSS 10.0s landed the same week Google moved the quantum clock, and Langflow was exploited within 20 hours of disclosure. If your SIEM is owned, you won't see any of the rest coming.
◆ Behind the synthesis
Six specialist takes that fed this piece.
The piece above is one stream in my voice. Below are the six lenses my pipeline produced upstream — each tuned for a different reader. Use them when you want the angle that matters most to your role.
-
Seven CVSS 9.0+ CVEs Hit PKI, Registry, Rails, and Spring
Your infrastructure has seven CVSS 9.0+ vulnerabilities across Step CA, Harbor, Spring Security, Rails, and Tekton that need patching today — and separately, Google's compression o…
39 sources · 7 min Read → -
Six CVSS 10.0 Bugs Hit SIEM, PKI, Registry, and AI Stacks
Six CVSS 10.0 vulnerabilities hit your security foundations simultaneously — your SIEM (Wazuh) has RCE to root, your PKI (Step CA) issues rogue certificates without authentication,…
39 sources · 7 min Read → -
ARC-AGI-3 Puts Every Frontier Model Below 1% on Reasoning
ARC-AGI-3 scored every frontier model below 1% on reasoning tasks humans solve at 100%, confirming that agentic pipelines relying on novel LLM reasoning have a near-zero capability…
39 sources · 7 min Read → -
Only 12% of S&P 500 AI Pilots Reach Production Vendor Status
Enterprise AI is in pilot purgatory — 68% of S&P 500 AI partnerships remain experimental, models score under 1% on tasks every human solves, and vibe-coded apps ship with critical…
39 sources · 8 min Read → -
Google TurboQuant Cuts AI Memory 6x as PQC Deadline Jumps to 2029
Google just compressed two timelines that underpin your entire technology strategy: post-quantum cryptography migration moved from 2035 to 2029 (backed by production code in Androi…
39 sources · 7 min Read → -
SpaceX Files $75B IPO as TurboQuant, ARC-AGI-3 Reprice AI
SpaceX's $75B+ IPO filing will vacuum institutional capital from every growth-stage company for the next two quarters, Google's TurboQuant just proved software can substitute for A…
39 sources · 7 min Read →