Using AI to chart a course for our post-quantum migration
- ID
- 29812
- Status
- summarized
- Published
- 29 Sep 2026, 9:00 PM
- Fetched
- 29 Sep 2026, 10:55 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/ai-driven-cryptography-discovery/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 6.0
- Created
- 29 Sep 2026, 10:55 PM
- Tags
- Audience
- developersstartup_founders
What happened
Cloudflare's Sharon Goldberg and Tiago Silva describe the company's push to full post-quantum readiness by a 2029 deadline, under a self-described 'PQ everything' maximalist stance. Most Cloudflare products already use post-quantum encryption over TLS 1.3, but post-quantum authentication is still early, so they built an internal tool called CryptoLabe (named after the mariner's astrolabe) to inventory where classical vs post-quantum crypto is used per repository and per product. A third goal is surfacing prerequisites early: protocols, standards, and libraries that have no PQ migration plan yet, so they can push those stakeholders before the 2029 clock runs out. The excerpt cuts off before explaining the specific AI techniques used.
Why it matters
The concrete split is worth acting on: encryption over TLS 1.3 is largely handled on Cloudflare's side, but authentication — cert signing, code signing, SSH, key management — is where they admit it's still early days and where your own stack likely has no PQ plan. If you terminate TLS on Cloudflare, you are already riding their PQ encryption defaults; that does not extend to anything you sign or verify yourself. Their 2029 internal deadline is also a useful reference point when vendors ask you about crypto roadmaps.
Discussion angle
How would you actually inventory crypto usage across your own repos — grep patterns, dependency scanning, or something LLM-assisted like CryptoLabe — and which of those findings (auth, signing, long-lived keys) would you fix first given a 2029-style deadline?