

By Duncan Jones
In September, nearly 200 senior cybersecurity leaders from around the world convened to discuss the state of U.S. cybersecurity at the 2022 Billington Cybersecurity Summit. Topics around cybersecurity were varied and included discussions about moral asymmetry of today’s global threat actors, lessons learned from Ukraine and general discussions around all things that “keep us up at night” concerning cyber threats.
As a speaker at the Summit, I wanted to take a moment to share my take-aways from an important discussion that took place during our breakout session, “Future of Encryption: Moving to a Quantum Resistant World.” My esteemed fellow panelists from NSA, NIST, CMU and AWS exchanged insights as to where U.S. government agencies stand in their preparation for current and future threats to encryption, the likely hurdles they face, and the resources that exist to assist in the transition. Those responsible for moving their agency to a quantum-resistant world should find the following insights worth considering.
With the prospect of powerful quantum computers breaking known encryption methods on the horizon and with federal mandate NSM-10 now in place, the good news is that quantum-proof encryption is finally being discussed. The not-so-good-news is that it isn’t clear to cybersecurity practitioners what they need to do first. Understanding the threat is not nearly as difficult as understanding the timing, which seems to have left agency personnel at the starting gate of a planning process fraught with challenges – and urgency.
Why is the timeline so difficult to establish? Because there is no way of knowing when a quantum-based attack will take place. The Quantum-safe Security Working Group of the Cloud Security Alliance (CSA) chose the date, April 14, 2030, to represent “Y2Q,” also known as “Q-Day” – the moment secure IT infrastructure becomes vulnerable to the threat of a fault-tolerant quantum computer running Shor’s algorithm. The Biden Administration based its implementation timeline on the day that NIST announced the four winning algorithms for standardization. Then there is the “hack now, decrypt later” timeline which suggests that quantum-related attacks may already be underway.
Regardless of the final timeline or potential drivers, one thing that was clear to the panel attendees was that they need to start the transition now.
I get this question often and was not disappointed when one attendee asked, “How can I convince my agency leadership that migrating to quantum-proof encryption is a priority when they are still trying to tackle basic cyber threats?”
The panelists responded and agreed that the U.S. government’s data storage requirements are unique in that classification dates are typically 20 years. This means that systems in development today, that are typically fielded over the next 10 years, will actually have a storage shelf life of 30 years minimum. Those systems need to be “future-proofed” today, a term that should be effective when trying to convince agency leaders of the priority.
The need to future-proof is driven by a variety of scenarios, such as equipment and software upgrades. In general, it takes a long time (and perhaps even longer for government entities) to upgrade or change equipment, software, etc. It will take an extremely long time to update all of the software that has cryptography in place.
The panelists also agreed that given the extensive supply chain supporting federal systems, vendors are a critical component to the overall success of an agency’s future-proofing for the quantum age. In 10-15 years, there will be some government partner/vendor somewhere who will not have transitioned to quantum-proof encryption. For leaders who have not yet prioritized their agency’s cryptography migration, let them ponder that thought — and start to focus on the need to prepare.
The panel shared several past technology migrations that were similar in their minds to the adoption of quantum computing.
Y2K was similar to the looming quantum threat by both the urgency and scale of the government’s need to migrate systems. However, without a deadline assigned to implementing the encryption migration, Y2K is really only similar in scale.
The panelists also recalled when every company had to replace the SHA-1 hash function, but concluded that the amount of time, effort, and energy required to replace current encryption will be way more important than SHA-1 — and way more ubiquitous.
While previous technology migrations help to establish lessons learned for the government’s quantum-proof cryptography migration, the panel concluded that this go-round will have a very unique set of challenges — the likes of which organizations have never had to tackle before.
The consensus among panelists was that agencies need to first understand what data they have today and how vulnerable it is to attack. Data that is particularly sensitive, and vulnerable to the “hack-now, decrypt-later” attacks, should be prioritized above less sensitive data. For some organizations, this is a very challenging endeavor that they’ve never embarked upon before. Now is an opportune time to build inventory data and keep it up to date. From a planning and migration perspective, this is an agency’s chance to do it once and do it well.
It is important to assume from the start that the vast majority of organizations will need to migrate multiple times. Panelists emphasized the need for “crypto agility” that will enable future replacement of algorithms to be made easily. Crypto agility is about how easy it is to transition from one algorithm (or choice of parameters) to another. Organizations that prioritize long-term thinking should already be looking at this.
The panelists added that communicating with vendors early on in the planning process is vital. As one panelist explained, “A lot of our service providers, vendors, etc. will be flipping switches for us, but a lot won’t. Understanding what your priorities are for flipping the switch and communicating it to your vendors is important.”
Matt Scholl of NIST shared about the work that NCCOE is doing to provide guidance, tips, and to answer questions such as what are discovery tools and how do I budget? The Migration to Post-Quantum Cryptography project, announced in July 2022, is working to develop white papers, playbooks, demonstrations, tools that can help other organizations implement their conversions to post-quantum cryptography. Other resources that offer good guidance, according to Scholl, include recent CISA Guidance, DHS’ roadmap and the Canadian Centre for Cybersecurity.
One additional resource that has been extremely helpful for our CISO customers is Quantinuum’s CISO’s Guide to Post-Quantum Standardization. The guide outlines what CISOs from any organization should be doing now and provides a basic transition roadmap to follow.
The discussion wrapped up with the acknowledgement that quantum has finally become part of the mainstream cybersecurity discussion and that the future benefit of quantum computing far outweighs the challenges of transitioning to new cryptography. As a parting thought, I emphasized the wonderful opportunity that agencies have to rethink how they do things and encouraged attendees to secure management commitment and funding for this much-needed modernization.
I want to give a special thanks to my fellow panelists for the engaging discussion: Margaret Salter, Director, Applied Cryptography, AWS, Dr. Mark Sherman, Director, Cybersecurity Foundations, CMU, Matthew Scholl, Chief of the Computer Security Division, ITL, NIST, and Dr. Adrian Stanger, Cybersecurity Directorate Senior Cryptographic Authority NSA.
Quantinuum, the world’s largest integrated quantum company, pioneers powerful quantum computers and advanced software solutions. Quantinuum’s technology drives breakthroughs in materials discovery, cybersecurity, and next-gen quantum AI. With over 500 employees, including 370+ scientists and engineers, Quantinuum leads the quantum computing revolution across continents.
AI + quantum computing: Quantinuum, NVIDIA, and Pfizer have combined transformer-based generative AI with quantum computing to automatically generate high-quality quantum chemistry circuits more efficiently than traditional optimization methods.
Practical pharma impact: The approach was used to prepare molecular ground states and validated on Quantinuum’s Helios hardware, demonstrating a path toward larger-scale computational chemistry and drug discovery.
Long-term vision: The team aims to build quantum foundation models that learn from increasingly complex quantum data, eventually enabling AI to design circuits for molecules too large for classical simulation.
Quantum computing has long promised a future that expands what we can do with compute — for example, in molecular simulation, materials discovery, or pharmaceuticals development. But between that promise and practical utility sits a stubborn bottleneck: quantum state preparation.
To run any algorithm on a quantum computer, you must first put the qubits in the right starting state. Think of it like setting up a Rube Goldberg machine- except in this case, you’re not sure exactly which initial setup will give you the results you want. This is what makes quantum state preparation so important: your choice of initial state dictates the accuracy and cost of the rest of the calculation.
We teamed up with NVIDIA and Pfizer to tackle this problem, with an eye towards developing meaningful industrial workflows. The result is a new generative quantum AI framework, called ADAPT-GQE, which we consider to be a canonical instance of GenQAI. ADAPT-GQE uses quantum data to train transformer models that ultimately synthesize quantum chemistry circuits faster, with better outcomes, in a sort of ‘virtuous cycle’.
Ultimately, this means we have developed a new interface between quantum computing and AI. By treating quantum circuit generation as a language modelling problem, we now have a system that can generate high-quality ground-state preparation circuits - with comparable or improved state preparation accuracy.
The goal of computational chemistry is to learn about chemical properties without performing expensive, time-consuming, and sometimes dangerous “wet-lab” experiments.
In principle, you can replace the majority of your physical experiments with computer simulations, saving billions of dollars and years of time.
In reality, computational chemistry is very tricky. To accurately simulate a chemical inside of a computer, you have to build it from the ground up. You start with a collection of atoms (in the case of imipramine, you have 19 Carbon atoms, 24 Hydrogen atoms, and 2 Nitrogen atoms). Then, like Nature’s ‘lego’, you assemble those atoms into a molecule: you set bond lengths, strengths, angles, interactions, and so on.
This is not straightforward: a single molecule can exist in many forms; with different angles, rotations, etc. We will call these different forms ‘conformations’.
Then, to actually estimate chemical properties, or to explore chemical reaction pathways, you have to reproduce the detailed physics that goes on at the atomic level: take your chosen conformation then figure out how each orbital is occupied, how the electrons are interacting with each other or the atomic nuclei, how is the addition of heat or a catalyst going to affect things.... it gets complicated, quickly.
Despite all this, computational chemistry is a powerhouse in pharmaceutical development. Right now, pharmaceutical companies save money and time by simulating as much as they can on computers, avoiding time consuming and expensive laboratory experiments. However, even with ~50 years of development, the existing classical methods have very real limitations.
This is where quantum computing comes in: this new computational paradigm can elide those limitations because it has many of the “hard parts” (like superposition or entanglement) natively encoded. Used correctly, quantum computing promises to break old barriers, further improving margins for pharma companies across the globe while contributing to meaningful, impactful, discoveries.
While quantum computational chemistry is one of the strongest candidates for near-term quantum advantage, current hardware is still in the earlier stages of development. With limited qubits and error rates, algorithm designers need to make every gate count, keep circuits shallow, and be able to tolerate some level of noise.
This is where generative AI enters the picture.
Instead of hand-designing chemistry circuits and laboriously experimenting to see how well they run, there is another idea: what if we trained an AI to solve the problems that quantum computational chemistry faces?
Using this approach, not only can we save time and resources; but we can shorten the timeline to realize practical results. With better state prep and other circuits, applications that were once considered far in the future come into view.
Our first attempt at this is called ADAPT-GQE. The central idea behind ADAPT-GQE is deceptively simple: instead of laboriously searching for good quantum circuits from scratch, train a transformer model to generate them directly.
Importantly, the framework is model-agnostic, which we showed by deploying it on complementary transformer architectures - Nemotron (a pretrained LLM) and Gemma (trained from scratch).
The initial goal here is to find the ‘ground state’ of the molecule imipramine (this is the electronic state with the smallest amount of energy stored inside it). To do this, you have to find the right ‘state preparation circuit’, as described above.
Until now, a leading method for finding the ground state with quantum computers was the ‘Variational Quantum Eigensolver (VQE)’, a hybrid quantum-classical approach. The VQE process starts with a ‘guess’ circuit for a particular conformation of the molecule. The quantum computer runs the circuit to measure the associated energy of the molecule. This result is fed back into a classical optimizer that then tweaks the circuit parameters, hopefully resulting in one with a lower molecular energy. This loop repeats until a minimum energy is found.
Unfortunately, VQE has a few severe limitations that make it infeasible for widespread use. The recently proposed ADAPT-VQE was a crucial step forward meant to address some of the issues with “plain” VQE. In ADAPT-VQE, instead of starting with a guess for the initial circuit, the process builds a circuit in steps by selecting operators from a pool(typically using gradient information) and optimizing. This approach can be more effective, but unfortunately still grows too large too quickly.
This is where the joint team jumped in.
Combining the best of all worlds, the team’s new framework, ADAPT-GQE, combines AI with the ADAPT-VQE to create something entirely new – and something that, so far, is a scalable, hardware-validated pathway toward automated quantum circuit synthesis.
First, transformers (in this case, Nemotron and Gemma) are trained via supervised fine-tuning on ADAPT-VQE data. In this way, the old method isn’t thrown away but is instead treated as a high-quality data-producing “oracle”.
Then, once the transformer has been initially trained, it defines a distribution over circuits, each one with some probability of corresponding to the ground state. This distribution can be used in a fine-tuning loop, for example, reinforcement learning. In reinforcement learning, the framework takes a circuit from that distribution, runs it, and measures the energy. It feeds the results back into the transformer, which adjusts its distribution. Over time, the model learns to prioritize circuits that prepare increasingly accurate ground states.
Crucially, reinforcement learning allows the system to surpass its original training data instead of merely imitating it. The model is no longer acting as a compressed lookup table for ADAPT-VQE. It begins exploring novel circuit configurations that may outperform the teacher algorithm itself. This is one of the most important conceptual shifts in the project.
In this case, instead of running all the initial circuits on Quantinuum’s Helios, the reinforcement learning circuits were run using NVIDIA accelerated computing and the CUDA-Q platform, simulating a quantum processor.
Finally, once the transformers are optimized via reinforcement learning, the best resulting circuits are validated for accuracy and feasibility, by running them using InQuanto and Nexus on Quantinuum’s newest hardware, Helios. With InQuanto v5.2, users can now interface directly with both the Helios quantum computer and the Selene quantum emulator through Nexus.
This powerful combination of InQuanto and Nexus enabled the execution one of the largest AI-generated quantum chemistry circuits to date on a quantum computer; helping to turn the promise of quantum computing into a practical tool for pharmaceutical development.
Looking farther in the future, the researchers envision something much larger than a single molecular benchmark.
For bigger and more complex molecules, ADAPT-VQE won’t work in the first place as the initial training “oracle”. In addition, the molecular energy calculations used in the reinforcement learning grow too large for classical systems simulating quantum computers, so the quantum processor becomes essential.
Luckily, this is not a problem. The ultimate goal of the ADAPT-GQE framework is to develop a “curriculum” for the transformers. This means instead of re-training them for every new molecule, you instead keep what you already learned, and expand your knowledge from there.
By initially teaching it on molecules that are smaller, and that can be fully simulated, you ensure it learns on good data that can be double checked using known methods. From there, you can carefully build up the complexity to see how the transformer learns. Eventually, you hope to train it on molecules that can’t be simulated classically, using purely quantum data, all the while getting closer to the complexity levels you’re chasing.
This penultimate result is called a ‘foundation model’, which is a massive AI neural network trained on vast, broad datasets that can be adapted to a wide variety of downstream tasks. In this case, the team is building the very ‘foundations’ of a model that can solve the ‘electronic structure problem’, which is the core computational challenge lying at the heart of quantum (and classical) computational chemistry.
What makes this work particularly interesting is that it treats quantum circuit generation as a language modeling problem: circuits become sequences, transformers learn distributions over those sequences, and reinforcement learning optimizes them against physical reward functions.
The result is an AI system capable of proposing quantum circuits that were never explicitly programmed by humans.
That does not mean generative AI is replacing physics or chemistry. Instead, it is becoming a new interface layer for navigating unimaginably large search spaces that traditional optimization methods struggle to explore efficiently.
For quantum chemistry, that could become transformative.
If successful, frameworks like ADAPT-GQE may eventually allow researchers to synthesize useful quantum circuits for molecular systems too large for classical computation, accelerating everything from materials discovery to pharmaceutical design.
The broader implication is difficult to ignore: foundation models may eventually extend beyond language, images, and code — and into the fabric of physical reality itself.
Recently, industry peers—including Quantinuum’s Startup Program Partners Qedma and BlueQubit, as well as our partner RIKEN—published a paper exploring quantum magnetism that “extends beyond the reach of the state-of-the-art classical methods considered;” evidence of a quantum advantage result. Interestingly, the team validated their results on Quantinuum machines (both Helios and System Model H2).
In 2025, we published a paper (now in Nature), exploring a similar system - also at scales that frustrate classical computation. This got us thinking: with more successes like this in the literature, what does this mean for the ecosystem at large? What are the key lessons to learn from these early demonstrations? And, perhaps most importantly, what’s next?
The answer to the first question, ‘what does this mean for the ecosystem at large’, is a delight to answer. After decades of promises, we are finally in the era where quantum computing is matched with, if not outright exceeding, classical HPC and supercomputing.
Examples of (complexity-theory proven) quantum advantage are already common, usually in the form of Random Circuit Sampling. This was extended to generating certified randomness, which was one of the earliest commercial applications of quantum computing.
Since then, we have seen a number of results from different groups that push the limits of classical computing while exploring ‘real’ problems; these range from papers exploring quantum magnetism (as mentioned above), to papers exploring things like superconductivity or peaked circuits.
Whether or not these are definitively ‘quantum advantage’ results is almost beside the point. They mark a distinct place on the path towards broad scale quantum utility, when quantum computers will be widely useful for researchers and industry alike. More importantly, these papers all speak to a certain level of ‘technological readiness’, showing that quantum computers are now proven to work on problems that are relevant (to some people, at least), at scales that aren’t easily reproduced elsewhere.
One of the key lessons we can learn from all these demonstrations is that hardware accuracy is paramount. Without accuracy, quantum computers are very expensive noise generators, unable to move the needle beyond HPC. Happily, we are finding that current generation machines are still capable of quite a lot, thanks to baseline physical accuracy, optionally coupled with clever error mitigation on top.
In general, we are very pleased to see how error mitigation can significantly reduce the impact of hardware errors and improve the quality of computed results by applying sophisticated post-processing techniques. However, error mitigation is not free. As hardware noise increases, mitigation becomes increasingly computationally expensive, and the techniques themselves can skew the results. If the underlying hardware is insufficiently accurate, it becomes more difficult to distinguish genuine physical phenomena from artifacts introduced via mitigation.
This is precisely where hardware quality matters. The validation on Quantinuum systems provided an important independent confirmation that the mitigated results from another vendor reflected real physical behavior rather than bias introduced through the mitigation process. Because Quantinuum's hardware operates with substantially lower native error rates, it served as a high-confidence reference point for validating scientific results. Importantly, this validation was about confirming the underlying physics, not validating a claim of quantum advantage.
All the above reflects our systems' strong native performance: when hardware begins with exceptionally high fidelity, there is simply less error to overcome. However, error mitigation remains an interesting and valuable approach: high-quality hardware establishes the baseline, and software extends what is possible.
However, native accuracy affects more than scientific confidence—it also influences computational efficiency. As program complexity and size increases, hardware error rates increase, and successful error mitigation generally requires more sampling, more processing, and more computational resources. The lower the physical fidelity, the greater the overhead required before arriving at trustworthy results.
By starting with significantly lower native error rates, Quantinuum systems reduce the amount of mitigation needed to achieve comparable scientific outcomes. This creates a practical advantage in computational cost while helping to preserve confidence in the resulting data.
Finally, we can answer the question of what comes next. This may seem obvious, but it’s multifaceted. What’s next is large-scale fault tolerant quantum computing. But the real question is, what does that look like?
A truly large-scale fault tolerant quantum computer will operate with error correction embedded into the workflow, working on the ‘logical’ level. That means that programmers will write their code to operate on logical qubits, with all the mechanisms of error correction hidden under the hood. The result will be error rates low enough to run some truly behemoth workflows.
We are well along the path to realizing this at scale: we have demonstrated all the necessary primitives, have world-leading logical error rates, and have a platform flexible enough to use new codes as they are invented; a crucial advantage in a quickly-evolving landscape. All of this is enabled by our high native accuracy; the accomplishments listed would be impossible without hardware that wasn’t ultra-low error to begin with.
However, even with the full force of error correction, error mitigation may still play an important role in the post fault-tolerance era. While error correction will be applied broadly to all workflows, there will still be some special cases where error mitigation may stretch the hardware further, always ensuring we stay on our front foot as computational power grows.
Scientific breakthroughs matter because they move the field forward. But lasting enterprise value will come from quantum computers that consistently deliver results organizations can trust.
With Helios—the world's most accurate commercial quantum computer[1]—and a growing ecosystem of partners building complementary technologies, Quantinuum is creating the accurate, scalable foundation needed to transform scientific achievements into practical quantum computing.
[1] Based on two qubit gate fidelity, as of December 31, 2025.
While there is ongoing debate around the pace of quantum computing’s development, a more grounded way to assess progress is through concrete demonstrations of foundational algorithms at meaningful scale. In this context, Mitsui & Co. and Mitsubishi Electric are taking a pragmatic view of quantum progress—focusing on how close the field is to executing core algorithmic primitives that underpin many potential industrial applications, rather than relying on abstract milestones or timelines.
In a new white paper, the industrial giants teamed up with Quantinuum to measure how close we are to running the Quantum Fourier Transform (QFT), a widely-used algorithmic primitive, at scales necessary for industrial applications. In the process, the team successfully ran one of the largest instances of the approximate QFT ever demonstrated. This achievement matters because the QFT is an essential primitive that underpins many of the quantum algorithms expected to deliver practical advantages.
You may have heard of the (classical) Fourier transform (FT), due to its ubiquity throughout modern computing. The FT is essential in everything from image analysis to data compression, with almost limitless applications in between. The quantum Fourier transform (QFT) is similar; it’s used in everything from chemistry to finance.
Because the QFT is a foundational primitive underpinning many quantum algorithms, demonstrating it at larger scales and higher fidelity is a practical way to measure quantum computing readiness. This is exactly the type of benchmarking that organizations should consider to understand where today’s systems are useful, and to see how fault-tolerant approaches are progressing. Ultimately, algorithm-level benchmarking like this is one of the most useful ways to understand not just where we are, but where we are going.
Primitives like Fourier Transform are so widespread because they simplify problems by transforming them into something that is easier to deal with. At Quantinuum, we are very interested in transforms: not only are they crucial for industrial applications but they can also simplify algorithms, making them possible to run now instead of later. This ‘transformational’ approach extends beyond the QFT - other transforms exist, and we have even invented our own quantum-native transforms.
Using our Helios quantum computer and Guppy language, the joint team explored running the QFT on both physical qubits and on logical qubits, showing that fault tolerance is progressing quickly. Running the QFT on 98 physical qubits; the paper shows a clear progression from previous results.
Then, using the Steane code, one of the best-studied quantum error correcting codes, the team used Helios’ 98 physical qubits to form 12 logical qubits, successfully running the QFT with the mechanisms of quantum error correction interwoven into the algorithm. This marks a crucial step forward for the field.
Taken together, these results provide a more concrete lens through which to view progress in quantum computing: not as abstract projections, but as measurable advances in the execution of foundational algorithms at increasing scale. By benchmarking the Quantum Fourier Transform on both physical and logical qubits, Mitsui & Co. and Mitsubishi Electric are helping to clarify what today’s hardware can already achieve, and where fault-tolerant approaches begin to extend those limits.
More broadly, the organizations best positioned to benefit from quantum computing will be those that focus on these foundational capabilities early, and use them to build a clear, evidence-based understanding of how the technology fits into their business goals.