Thales Report Reveals AI and Quantum Computing Converge on Enterprise Data, Heightening Immediate and Future Security Risks
Thales has released its 2026 Quantum & AI Threat Report, a comprehensive study based on a survey of 3,120 security and IT professionals across 20 countries. The report's central finding is that artificial intelligence (AI) and quantum computing are increasingly converging on enterprise data as their primary target, presenting a dual challenge to contemporary cybersecurity strategies. It details that while quantum threats like "harvest now, decrypt later" (HNDL) are a leading concern for 61% of respondents, AI-driven risks are already manifesting, with 59% of organizations having experienced deepfake attacks and only 3% reporting no harm from AI-generated threats. The report also highlights that cloud environments remain a significant attack surface, with cloud storage, applications, and management infrastructure being the most frequently targeted assets.
This report is crucial for practitioners because it fundamentally reframes the perception of AI and quantum computing from theoretical future threats to immediate, interconnected challenges. It underscores that the cybersecurity landscape is rapidly evolving, demanding a proactive rather than reactive stance. The prevalence of deepfake attacks and other AI-generated threats demonstrates that organizations are already experiencing tangible harm, necessitating a re-evaluation of current defensive postures. Furthermore, the emphasis on HNDL attacks serves as a stark warning that data considered secure today could be compromised by future quantum capabilities, urging immediate action to protect long-term sensitive information. Ignoring this convergence risks leaving critical data vulnerable to both present-day exploitation and future decryption.
The findings align with a broader, well-established trend in cloud and DevOps security, where the focus has shifted from perimeter defense to data-centric protection. As organizations increasingly adopt cloud-native architectures and leverage AI for various operations, the attack surface expands, and traditional security models become less effective. This report reinforces the industry-wide push towards Zero Trust principles, which advocate for continuous verification and least-privilege access, assuming compromise is inevitable. The report's highlighting of cloud environments as prime targets also resonates with the ongoing challenges in cloud security posture management and the need for robust controls around cloud data storage and applications. The integration of AI into security operations, while beneficial, also introduces new vulnerabilities, creating a complex interplay that requires sophisticated threat detection and response capabilities.
In practice, this means that security and DevOps teams must prioritize strengthening foundational data security practices. This includes implementing advanced encryption for data at rest and in transit, coupled with robust key management strategies that consider post-quantum cryptography roadmaps. Organizations should conduct thorough data classification exercises to identify and protect sensitive data that could be targeted in HNDL scenarios. Furthermore, given the cloud's role as a primary attack vector, practitioners need to double down on cloud security best practices, including continuous monitoring of cloud configurations, identity and access management (IAM) within cloud environments, and securing cloud-native applications. Investing in AI-powered security tools is essential for detecting sophisticated threats, but equal attention must be paid to securing these AI systems themselves against adversarial attacks and ensuring their ethical and secure deployment. The report implicitly calls for a holistic, adaptive security strategy that anticipates future threats while addressing current vulnerabilities with enhanced data protection measures.
Read original source