At this year’s G7 summit in Evian, seated beside heads of state were the chief executives of AI and quantum computing leaders, including OpenAI, Anthropic, Google DeepMind, and Microsoft, who were called in to discuss national security and critical infrastructure, territory once reserved for governments alone.
Cyber-security concerns about AI and quantum computing now occupy important seats at the table, according to a policy piece by Kearney.
And events since the meeting have moved fast. OpenAI disclosed that AI models it was testing had found an unknown security weakness, broken out of their test environment, and reached a partner’s live systems, with no attacker involved. The European Commission’s new Action Plan on Cybersecurity and AI told companies to close security gaps with AI faster than attackers can exploit them. NVIDIA, with more than 80 industry partners, launched an alliance to keep AI-powered cyber capability from concentrating in a handful of firms.
According to the consulting firm’s analysis, the key takeaway for corporate boards is that AI and quantum computing are changing cyber risk and digital trust at the same time, and the winners won’t be the companies with the fewest breaches. They’ll be the ones that can prove they can keep running when something breaks.
AI and Quantum Computing Cyber Risk
Cyber risk used to move at human speed and defenders had days or weeks to respond. That’s no longer a safe assumption because frontier AI models are compressing timelines for attackers and defenders alike, even as companies grow more reliant on cloud providers, software vendors and other outside platforms they don’t control.
In the World Economic Forum’s latest outlook, 94% of executives said they expect AI to be the biggest driver of change in cybersecurity this year, and 87% called AI-enabled vulnerabilities their fastest-growing risk. AI-generated phishing emails are getting clicked at roughly 54%, versus about 12% for ordinary phishing. Microsoft has reported a 195% jump in AI-generated fake identities world-wide. Anthropic said it disrupted an AI-orchestrated espionage campaign against roughly 30 targets in which the AI ran an estimated 80% to 90% of the operation itself.
Defenders have access to the same technology, though, as when Google’s “Big Sleep” research flagged a critical flaw in SQLite that only attackers had known about, cutting off exploitation before it spread. Mozilla ran Anthropic’s Claude Mythos through its own security pipeline and fixed 271 bugs the model flagged in a single Firefox release. Kearney’s insights for directors is that the advantage now goes to whoever fixes fastest and can prove it, not whoever finds the most problems.
There’s a less obvious risk boards are just starting to reckon with. When U.S. export controls this year barred foreign nationals from accessing Anthropic’s Claude Mythos, Anthropic switched the model off world-wide — a move more than 100 security professionals publicly pushed back on.
The lesson for risk committees is that a technology choice can turn into a strategic dependency without warning. Companies that build security operations, software development or decision-making around one AI provider inherit that provider’s access rules, commercial terms and exposure to geopolitics. Kearney’s recommendation is to treat architecture portability, model optionality and vendor diversification as resilience questions, not procurement details.
Q-Day Is Already a Board Issue
Quantum computing poses a different kind of threat, according to Kearney, a leading management consulting firm and trusted partner to three-quarters of the Fortune Global 500 and governments around the world. Eventually, a sufficiently powerful quantum computer will be able to break the cryptography that secures digital identities, transactions and communications today, an event shorthanded as “Q-Day.” Exactly when that happens matters less than a harder fact: rebuilding a large company’s cryptographic infrastructure takes years, not months.
That makes post-quantum cryptography, or PQC, urgent now, for three reasons. First, adversaries are already running “harvest now, decrypt later” operations, stealing encrypted data today to decrypt once quantum computers can do it. Any data with a five-to-20-year sensitivity window — customer records, intellectual property, health data — is exposed already.
Second, the standards are in place. NIST has finalized its first post-quantum cryptography standards, ready for use now. The U.K.’s National Cyber Security Centre wants discovery done by 2028, priority systems migrated by 2031, and the job finished by 2035. Google has said it will complete its own migration by 2029.
Third, the market has started moving without waiting for regulators. Apple has added post-quantum protection to iMessage; Signal has adopted a post-quantum key-agreement protocol; Cloudflare has turned on post-quantum key agreement across nearly all the domains it serves. Manufacturers, pharmaceutical companies and insurers are putting PQC into their own roadmaps.
Regulators Want Proof, Not Promises
In Europe, a stack of new rules is pushing companies from compliance toward demonstrated resilience. The Digital Operational Resilience Act, in force since January 2025, requires financial firms to show they can keep critical services running when a third party fails. The revised NIS2 directive puts boards directly on the hook for cyber risk. The Cyber Resilience Act phases in product-security duties through 2027. The EU AI Act adds governance requirements for high-risk AI systems starting in 2027. The European Central Bank has told banks that lacking access to the most advanced AI tools is no excuse to delay their own resilience testing.
What Boards Should Do About AI and Quantum Computing Now
Kearney’s analysis lays out four steps:
- Treat cyber as a resilience issue, not an IT issue. Map critical services and dependencies, and set clear decision rights for disruption scenarios.
- Find and reduce ecosystem fragility. Know where the company is concentrated — cloud providers, software vendors, AI platforms — before it becomes a vulnerability.
- Start migrating to PQC now. Inventory cryptographic dependencies, protect the longest-lived sensitive data first, and hold vendors to post-quantum roadmaps tied to the 2028-2035 milestones the market has already adopted.
- Build a record, not just a policy. Keep evidence of how AI systems are governed and how resilience has actually been tested, so the board can show its work under scrutiny.
Kearney piece on AI and quantum computing suggest that resilience is turning into a competitive advantage. The companies that come out ahead won’t be the ones that avoid every incident. Instead, they’ll be the ones that can show, when something goes wrong, that they were ready for it.



