Report: Convergence of AI, Quantum Risks Impacting Cybersecurity

New research from Thales highlights how AI adoption and emerging quantum computing threats are putting pressure on existing security measures. The 2026 Thales Data Threat Report: Quantum & AI Trends, based on responses from 3,120 security and IT management professionals across 20 countries, found that 98% are considering how the two technologies affect each other. Thirty percent reported a significant increase in security budgets specifically for AI.

The research, conducted by 451 Research by S&P Global, examines both the risks and potential benefits of the technologies. Fifty-seven percent believe quantum computing will enhance machine learning, while 54% expect it to enable advanced simulations of complex systems. The security findings span data governance, cloud infrastructure, and preparations for quantum-resistant encryption.

Cloud Assets Top the Target List

Cloud-based storage, cloud-delivered applications, and cloud management infrastructure were the three most frequently cited asset types targeted by attackers, at 35%, 34%, and 32%, respectively. The report connects that exposure to the large datasets required for AI training and the rapid expansion of AI infrastructure.

Cloud Assets Lead Attack Targets
[Click on image for larger view.] Cloud Assets Lead Attack Targets (source: Thales).

Organizations are also looking to cloud providers for protection: 67% reported investing in their cloud provider's AI-specific security tools, compared with 63% using an established security provider. Respondents could identify multiple sources of protection, including startups, large language model providers, and internally developed controls.

Encryption coverage remains incomplete. Only 7% of organizations reported encrypting more than 80% of their sensitive cloud data, while 29% reported encrypting more than 60%. The report's chart puts the average share encrypted at 47% in 2026, down from 51% in 2025.

The findings extend concerns raised in coverage of Thales' 2025 cloud security research, when AI security already ranked second to cloud security in spending priorities and 52% of respondents reported that AI security spending was displacing existing security budgets. The latest report again places AI security second, while its historical comparison shows average sensitive cloud data encryption coverage falling from 51% in 2025 to 47% in 2026.

AI Spending Meets Data Governance Gaps

AI security was the second-highest prioritized security spending category overall, behind cloud security. But protecting data ranked much lower among the measures organizations use to judge AI projects: Reducing or managing risks of data loss or noncompliance placed sixth among seven success criteria, at 35%.

Improving customer experience led those measures at 68%, followed by reducing employee toil through greater task automation at 63%. Meanwhile, poor data quality or initial data governance was the leading inhibitor to AI adoption, cited by 65%; security risks from exposed data followed at 61%. Another 51% cited AI initiatives moving too quickly to be properly secured.

Rapid changes in the AI ecosystem led security concerns, with 70% placing them among their top three risks. Trust in third-party systems followed at 58%, ahead of sensitive data exposure at 46%, and agents or processes with excessive permissions at 42%.

Leading Risks to AI Security
[Click on image for larger view.] Leading Risks to AI Security (source: Thales).

The researchers argue that these pressures increase the importance of basic data protections. As the report puts it, "When applications and systems become easier to compromise, identity and data security become the last lines of defense."

Preparing for Quantum Threats

Harvest now, decrypt later (HNDL) was the leading quantum security concern, cited by 61% of respondents. In an accompanying Thales blog post, the company explains that attackers can collect encrypted information now and retain it until sufficiently powerful quantum computers can defeat the encryption protecting it.

Fifty-nine percent expect to prototype or evaluate post-quantum cryptography (PQC) algorithms within the next 18 to 24 months. Other planned measures include assessing current encryption strategies, at 45%, and creating resilience contingency plans, at 39%. These figures describe intended security measures, rather than completed migrations.

Planned Measures for Quantum Security
[Click on image for larger view.] Planned Measures for Quantum Security (source: Thales).

Progress varies across the systems that depend on cryptography. Among 2,140 organizations surveying, exploring, or experimenting with quantum computing, 66% were on track or ahead of their public key infrastructure objectives. The corresponding figures were 58% for enterprise key management, 56% for code signing, and 53% for certificate life-cycle management.

Interoperability with broader ecosystems was less advanced: 39% were on track or ahead, while 34% were behind and 27% were unsure or considered the question inapplicable. The report emphasizes planning changes across infrastructure and development processes while building the ability to adopt new cryptographic algorithms without disrupting operations.

Stronger Fundamentals Accompany Greater Readiness

The study also compared organizations classified as AI leaders — those investing in AI-specific security and identifying themselves as ahead of peers — with laggards. Leaders more often reported complete knowledge of where their data was stored, at 36% versus 28%, and the ability to classify all their data, at 43% versus 35%.

Those comparisons show an association, not proof that AI leadership causes better security. The methodology explicitly describes the research as observational and makes no causal claims. The survey targeted larger organizations, excluding those with annual revenue below $100 million and applying a higher cutoff in selected countries.

The report recommends more effective data discovery and classification, unified security controls spanning hybrid infrastructure, faster deployment of post-quantum cryptography, and simpler security tooling and operations. Its conclusion links AI-specific defenses with broader efforts to understand and protect enterprise data.

For the full report, visit the Thales site (registration required).

Featured

  • shattered digital cloud with red warning alert icons

    CSA's Top Cloud Threats: Identity, AI

    Cloud Security Alliance's 2026 Top Threats report ranks identity first while adding two AI-related risks to its list of 11 leading cloud security concerns.

  • Data cybersecurity warning alert

    Flashpoint Patents Ransomware Risk Model, Tying Vulnerabilites to Likelihood of Attack

    Cybersecurity company Flashpoint recently announced it has received U.S. Patent No. 12,705,360 for its Ransomware Risk model, a methodology designed to help security teams determine which newly disclosed vulnerabilities more closely resemble those historically used in ransomware attacks.

  • young man hand working on a laptop, bokeh blurred at night

    Redesigned Copilot Will Build Apps and Work on Its Own

    Microsoft recently announced that it's redesigning Copilot, the company's all-encompassing AI assistant, so users can hand off complex tasks, build tools by describing what they need and assign work to an agent that keeps going after they log off.

  • A glowing digital brain with neural connections and light trails

    AI Giants Warn It May Be Time to Slow Down

    For years, leaders in the artificial intelligence industry have warned that increasingly capable AI systems could eventually become dangerous, all the while continuing to race to build them. Now, their sentiments have changed.