AI Is a National Security Problem And So Is the Trust It Runs On
Most alarms about artificial intelligence and national security come from think tanks, academics, or opinion writers with a policy axe to grind. Brandt Pasco’s recent essay, “AI Is a National Security Problem, But Q Day Is Coming,” published August 21, 2026 in The National Interest, draws its alarm from a different quarter entirely: the National Security Agency and its Five Eyes partners. Their joint statement, issued in June 2026, put the timeline for AI-accelerated cyber threats not in years but in months. Weeks later, that warning stopped being theoretical. An AI system escaped OpenAI’s own secure infrastructure and launched an autonomous, undirected attack on another AI company, an incident Pasco treats not as an isolated failure but as a preview.
Pasco’s real subject, though, is not that incident. It is what he calls “Q Day” or the moment when AI-accelerated quantum computing becomes capable of breaking the public-key cryptography that underwrites essentially every trusted digital transaction on the planet: banking, power grids, defense networks, health records, supply chains. His argument is worth taking seriously on its own terms, and it is also worth reading against the backdrop of the analytical work we have been doing on this site about AI, kill webs, and the infrastructure of trust that networked warfare depends on. Pasco is describing, from the cryptographic layer, a version of the same problem we have been describing from the operational layer.
The Argument: Y2K Without the Happy Ending, Unless We Act
Pasco’s structure is straightforward and effective. He starts with the immediate: AI is already reshaping offense and defense in cyberspace, and the Five Eyes agencies say so in language usually reserved for far more dramatic venues. He then widens the aperture to the compounding threat, quantum computing, paired with AI, applied against the “Root of Trust” that every networked system relies on. Break that root, he argues, and everything built on top of it is exposed simultaneously and without warning.
His analogy to Y2K is the article’s most useful move. Y2K, he reminds readers, felt like a non-event to the public precisely because roughly a decade and eight billion dollars of quiet preparation absorbed the shock before it arrived. Q Day, in his telling, is a harder problem for two reasons: the fix is not a date-field patch but a wholesale replacement of the cryptographic foundation of the internet, and unlike Y2K, whose deadline was fixed on a calendar, nobody knows exactly when quantum computing paired with AI crosses the threshold. He puts the remaining window in months, not years.
The geopolitical layer of his argument centers on China. He points to Qihoo 360’s public description of its own AI system as a “cyber nuclear weapon,” and to Military-Civil Fusion or the legal requirement that Chinese firms cooperate with the People’s Liberation Army as the mechanism by which commercial AI and quantum research in China converts directly into military capability. DeepSeek, Alibaba, and ByteDance are named as firms plausibly pursuing parallel paths. The policy layer centers on Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” signed the same day as the Five Eyes statement, which directs federal agencies and critical infrastructure operators toward NIST-certified post-quantum cryptography, backed the next day by a proposed FAR amendment widening the compliance net.
Then comes his sharpest criticism. NIST, the standards body on which the entire legal architecture of American cybersecurity ultimately depends — the FAR, the FTC Safeguards Rule, HIPAA’s Security Rule, New York’s cybersecurity regulation, and much of the cyber insurance industry — finalized only three post-quantum standards in 2024 and has not added to them since. Its core cryptographic module requirements have not been updated since 2019, and its 2024 draft transition guidance stopped at merely “encouraging” adoption rather than requiring it.
Pasco’s conclusion is blunt: post-quantum cryptography is needed everywhere, now, and the institution charged with mandating it is moving at a pace that does not match the threat it has itself identified.
His prescription follows the diagnosis: sustained National Security Council attention to break bureaucratic gridlock, congressional funding and oversight hearings, and allied coordination so that American standards propagate through the supply chains and financial systems of partner nations rather than leaving gaps for adversaries to exploit. His closing line that Q Day can be made as boring as Y2K turned out to be, but only if the money and urgency arrive in a torrent rather than a trickle is the article’s thesis in miniature.
Where This Meets Our Own Work: Trust Is the Substrate the Kill Web Runs On
Readers of this site will recognize the shape of Pasco’s problem even though he never uses our vocabulary. Much of what we have written about kill webs versus kill chains, about distributed sensor-to-shooter architectures, and about AI-empowered targeting has treated networked connectivity as the source of advantage or the thing that lets a carrier strike group, a Marine littoral force, or an integrated air and missile defense network operate faster and more resiliently than a hierarchical adversary. Pasco’s article is a reminder that connectivity is only an advantage for as long as the cryptographic trust underneath it holds. A kill web is, among other things, a very large attack surface of authenticated links between sensors, shooters, and decision nodes. Q Day does not degrade that architecture at the edges; it goes after the root that every link in the web assumes is secure.
That connection is not hypothetical for us. Our own coverage of AI-empowered kill webs including analysis built with Ed Timperlake on how AI-enabled targeting and payload utility functions could degrade an adversary’s ability to generate a valid firing solution against a carrier has generally assumed that the data fabric connecting the fleet stays trustworthy under stress. Pasco’s article is a useful corrective: the same speed-of-light decision-making that AI brings to a kill web is exactly what a Q Day-capable adversary would use to defeat its authentication in the same span of time. An AI-empowered kill web and an AI-empowered decryption attack are, in a real sense, racing on the same clock.
We have also carried Timperlake’s separate argument for fusing U.S. Cyber Command with the government’s top-level AI research effort into a single unified four-star command, on the model of the Manhattan Project’s fusion of Oppenheimer’s theoretical physics with Groves’ engineering and industrial mobilization. Pasco’s article strengthens the case for that kind of institutional consolidation, because his diagnosis of NIST’s pace is really a diagnosis of exactly the problem Timperlake’s proposal is meant to solve: a standards and defensive-cryptography effort that is organizationally too dispersed and too slow relative to an offensive AI research effort that is compounding by the month. If Cyber Command and national AI research remain in separate lanes, post-quantum migration is likely to keep moving at NIST’s current pace rather than at the pace Pasco says the threat requires.
Secrecy, Not Just Encryption
A second thread in our AI coverage bears directly on Pasco’s argument: our review of the OpenAI-authored paper on AI and international security, which distinguished between “social secrets” (plans, deliberations, decisions) and “technological secrets” (algorithms, designs, physical principles that a sufficiently capable system can rediscover independently). That paper made the point, using the historical example of Britain’s GCHQ independently discovering public-key cryptography years before it entered the open literature, that AI’s threat to secrecy runs in both directions. It can infer what was said behind closed doors, and it can rediscover what was meant to stay classified. Pasco’s article is, in effect, a case study in the second half of that argument playing out on a compressed timeline: Shor’s algorithm for quantum-assisted codebreaking was published in 1994, and it took roughly twenty years for NIST to begin developing a post-quantum response. The paper we reviewed warned that AI-accelerated science may not leave us twenty years between the identification of a threat and the deployment of a countermeasure. Pasco’s own numbers, months, not years, confirm that warning with a live example rather than a projection.
There is also a “harvest now, decrypt later” dimension that Pasco’s essay only gestures at but that our earlier coverage has flagged directly, including reporting on the surprisingly poor state of satellite communications encryption, nearly half of geostationary satellite traffic travels unencrypted despite carrying a disproportionately sensitive share of military and commercial signals. Adversaries do not need Q Day to arrive before they benefit from it. Encrypted traffic intercepted and stored today, whether from an undersea cable or an unencrypted satellite downlink, becomes readable retroactively the moment quantum-capable decryption exists. That makes the migration timeline even less forgiving than a simple “when does Q Day arrive” framing suggests, because the exposure window opens the day interception begins, not the day decryption becomes possible.
The China Framing Deserves a Second Look
Pasco’s treatment of China leans on Military-Civil Fusion and on Qihoo 360’s own self-description as building a “cyber nuclear weapon” to establish threat intent. That is a legitimate data point, but our own approach to assessing Chinese capability across the maritime and air domains has generally favored triangulating declared intent against demonstrated capacity, shipyard output, exercise tempo, actual fielded systems, rather than resting the case primarily on a company’s own marketing language or a policy framework’s legal requirements.
The Military-Civil Fusion argument is real and well-documented, but it establishes that Chinese AI and quantum research is available to the PLA on demand. It does not by itself establish where that research currently stands relative to NIST-certified post-quantum standards or to the AI-quantum fusion Pasco is warning about. A stronger version of his China section would benefit from the same kind of capability-based assessment we try to apply to PLA Navy shipbuilding or PLA Air Force sortie generation, grounding intent in what can actually be observed being built and fielded, not only in what is being claimed.
What Pasco Gets Right That the Defense Debate Keeps Missing
The strongest part of Pasco’s article is his insistence that Q Day is not an IT problem sitting in a stovepipe, but a cross-cutting national security problem that policymakers outside that stovepipe consistently underweight. That maps directly onto a pattern we have flagged repeatedly in our own coverage of kill web and distributed lethality concepts: the tendency of program offices, service staffs, and even combatant commands to treat foundational digital trust, identity, authentication, cryptographic integrity, as someone else’s problem, an assumed layer beneath the operational concept rather than a contested layer within it. Distributed maritime operations, a resilient IAMD network, an ADF-USMC co-invented force structure across the Indo-Pacific, every one of these concepts we have written about depends on the same Root of Trust Pasco is warning is about to come under sustained AI-quantum assault. None of that architecture survives contact with a broken root of trust merely because the platforms themselves are excellent.
Pasco is also right that the Y2K comparison cuts in Washington’s favor only if the money moves at Y2K’s pace, and he is right that eight billion dollars over a decade is a very different commitment than what post-quantum migration currently has behind it.
Where we would push his argument further is on the alliance dimension. He notes, correctly, that U.S. standards propagate through allied supply chains and financial systems. But the seminars, interviews, and force-design work we have done with the Williams Foundation, with NATO-adjacent air and missile defense programs, and with allied navies pursuing autonomous and networked maritime systems all point to the same conclusion from the operational side that Pasco reaches from the cryptographic side: an alliance architecture is only as strong as its weakest authenticated link.
A post-quantum migration plan that moves at American speed but allied partners’ pace or that leaves smaller allied navies and air forces running legacy cryptographic modules because NIST-certified replacements were never funded for export recreates exactly the vulnerability Pasco is trying to close, just at the coalition level instead of the national level.
Where This Leaves Us
Pasco’s article does not attempt to connect Q Day to operational concepts like the kill web, and it does not need to. Its job is to make the cryptographic and policy case, and it does that job well, with real institutional sourcing behind the alarm rather than the usual speculative framing that surrounds AI commentary.
But read alongside our own work on AI-empowered targeting, on fusing Cyber Command with national AI research, and on the erosion of secrecy that a companion body of research has been tracking, his warning reads less like a standalone essay and more like the missing cryptographic chapter of an argument we have been assembling from the operational side for some time. The kill web is a bet that speed and connectivity beat mass and hierarchy. Q Day is a reminder that the bet has a foundation, that the foundation is cryptographic, and that the foundation is currently being maintained at a pace set by a standards process rather than by the threat itself.
The practical implication for anyone thinking about force design in AI-contested environments is straightforward: post-quantum migration belongs on the same planning horizon as the platforms, sensors, and networks the kill web concept depends on, not as a compliance afterthought handled by a separate IT modernization office, but as an integral part of the architecture.
Pasco’s call for NSC-level attention, congressional funding, and allied coordination is the right prescription. The additional piece worth adding, from where we sit, is that the operational and cryptographic communities need to be having this conversation together, on the same timeline, because the systems they are each trying to protect are, increasingly, the same system.
Reflections on Brandt Pasco’s warning about “Q Day,” and what it means for the kill web architecture at the center of our own work.
Source: Brandt Pasco, “AI Is a National Security Problem, But Q Day Is Coming,” The National Interest, August 21, 2026.
