Thursday, August 27, 2026

The Quantum Tsunami is coming...and it isn't Q-Day

The Quantum Blind Spot

Why the Stack We Rely On Is Already Failing

Joe Bartolo, J.D.

Director of AI, Discernis.ai | LDI Architect

Executive Summary

Most conversations about emerging technology risk start with the wrong question. They ask what happens when quantum computing arrives, as though the moment a sufficiently powerful quantum computer comes online is the moment the risk begins. That framing is comfortable because it puts the problem safely in the future. It is also wrong.

The infrastructure underneath nearly every organization, the open source code libraries, the volunteer maintainers who patch them, and the data centers that run them, is already under sustained strain today. Attack volume against under-resourced open source projects is rising faster than the capacity to defend them. Data center energy and water demand is climbing in ways few organizations have factored into continuity planning. Artificial intelligence governance, an already unresolved problem of hallucination, shadow deployment, and rubber-stamp human oversight, is compounding the load. Quantum computing does not create this fragility. It arrives on top of it, and it starts collecting on that fragility years before a headline-grabbing "Q-Day" ever occurs.

This paper argues that the most urgent governance gap facing corporate and legal leadership is not a distant quantum event. It is the foundation quantum will eventually stand on, a foundation many organizations have never actually inspected. It also argues that the coming mandatory migration to post-quantum encryption standards, properly approached, is a rare opportunity: the one moment organizations will be forced to finally understand what data they hold, what of it matters, and what should have been deleted years ago.

I. Reading the Waterline

Anyone who has studied tsunami warning signs knows the detail that surprises people most: before the wave arrives, the water at the shoreline does not rise. It recedes, sometimes dramatically, pulling back to expose sand and reef that are never normally visible. Bystanders who don't recognize the signal often walk toward it, curious about the newly exposed seabed, precisely when they should be moving toward higher ground. The wave is dramatic. The drawback is the actual warning, and it is almost always misread or ignored.

This paper is not about the wave. It is about the drawback already underway, visible right now to anyone willing to look at it directly, in the condition of the technology stack nearly every organization depends on without having chosen it, audited it, or funded its upkeep.

II. The Stack Nobody Inspects

Open source software is not a niche technical concern. It is the connective tissue of virtually every corporate system, embedded in commercial software, cloud infrastructure, and internal tooling alike, almost always without a purchasing decision or a vendor contract that would normally trigger a risk review. The organizations relying on it typically have no direct relationship with the people who built and maintain it.1

Those maintainers are, in large part, volunteers. A widely cited 2024 survey found that roughly 60 percent of open source maintainers had quit, or seriously considered quitting, a project they were responsible for.2 This is not a story about people who don't care or don't work hard. It is the opposite: it is a story about a workforce doing skilled, high-stakes security work for little or no pay, absorbing an ever-growing volume of contributions to review, including a rising tide of low-quality, AI-generated submissions that the industry now bluntly calls "AI slop," all while carrying informal responsibility for software that underpins the global economy.

Two incidents illustrate what happens at the edges of that arrangement. The Log4Shell vulnerability, disclosed in December 2021, sat inside one of the most widely used logging libraries in enterprise software, and its blast radius was so large that many affected organizations initially had no idea they were exposed at all.3 More unsettling still, in March 2024 a single developer noticed a barely perceptible slowdown in SSH login times and, in tracing it, uncovered a backdoor that had been deliberately and patiently planted inside xz-utils, a compression library embedded in most Linux distributions, by a contributor who had spent roughly two years building trust within the project before inserting it.

That backdoor was caught by luck and a single person's attention to a strange performance anomaly, not by any institutional process built to catch it.4 Some corporate efforts to support maintainers financially exist and are genuinely valuable; one industry pledge program reports its members have collectively contributed $4.5 million to open source maintainers since launch.5 But set against the scale of global dependency on this code, that figure illustrates the mismatch rather than resolving it.

This is the load-bearing wall very few organizations have ever inspected. It was already cracking before anyone brought quantum computing into the conversation.

1GitHub's Octoverse 2025 report recorded approximately 36 million new developer accounts in 2025 and identified a widening gap between the number of contributors and the number of maintainers able to review their work, compounded by a rising volume of low-quality, AI-generated pull requests the industry has taken to calling "AI slop." InfoQ, "GitHub's Octoverse Points to a More Global, AI-Challenged Open Source Ecosystem in 2026," Mar. 2026.

2A 2024 Tidelift survey of open source maintainers, reported by The Register, found that roughly 60 percent had either quit or seriously considered quitting maintenance of a project they were responsible for. The Register, "Open source maintainers are really feeling the squeeze," Feb. 16, 2025.

3The Log4Shell vulnerability in the widely used Apache Log4j logging library, disclosed in December 2021, allowed remote code execution across an enormous and largely unmapped footprint of enterprise software, illustrating how a single volunteer-maintained component can sit at the center of global digital infrastructure without most affected organizations knowing they depended on it.

4In March 2024, a lone developer, Andres Freund, discovered a deliberately planted backdoor in xz-utils, a compression library embedded in most Linux distributions, after noticing an unexplained slowdown in SSH login times. The backdoor had been introduced gradually over roughly two years by a contributor who had spent that time building trust within the project. It was caught by chance, not by process.

5Sentry's Open Source Pledge program reports that its member companies have collectively paid open source maintainers and foundations $4.5 million since the pledge launched, including $750,000 distributed in 2025 alone. Sentry Blog, "Another year, another $750,000 to Open Source maintainers," 2026. The figure is offered here not to diminish the contribution, but to illustrate the scale mismatch between voluntary corporate support and the dependency the global economy places on this labor.

III. The Drain Nobody Is Pricing In

A second, related strain sits underneath the same stack: the physical infrastructure running it. Deloitte's 2025 industry outlook projects that global data center electricity consumption, driven substantially by generative AI training and inference, could roughly double by 2030.6 U.S. government forecasters expect data center demand to help push national electricity consumption to record highs in both 2025 and 2026.7

Water consumption tells a similarly stark story. Data centers already rank among the ten most water-intensive industries in the United States, and research presented at Lehigh University's ACES Symposium projects that AI-driven data centers could consume between 731 and 1,125 million cubic meters of water annually by 2030, comparable to the yearly household water use of six to ten million Americans.8

Very few enterprise risk registers or business continuity plans account for this dependency in any concrete way. Most organizations treat power, cooling, and water as someone else's utility problem, quietly assumed to be handled, rather than as a genuine constraint on the availability and cost of the infrastructure their entire data environment sits on.

IV. Escalating, Not Steady

None of this is static. Attack sophistication against the open source stack is rising, not holding level, while the volunteer base defending it is shrinking under the very burnout pressures described above. Layered on top is a governance backlog the industry has not resolved even for problems that predate quantum entirely: hallucinating models producing confidently wrong output, a growing volume of low-quality AI-generated content, unsanctioned "shadow AI" tools adopted by employees without security or legal review, and agentic AI systems deployed with little coordinated planning or expected return on investment.

A particular structural problem deserves its own mention: human-in-the-loop oversight, as actually practiced in many organizations, has become theater rather than a genuine check. Meaningful human review requires that the reviewer have real time, real authority, real competence in the subject matter, and real information about what the system did and why. Agentic AI systems built to move fast create constant pressure to shrink or skip that review, because every pause for a human decision is, by design, friction the system is built to minimize. The result in practice is often a signature on a decision the signer had no realistic ability to evaluate.

6Deloitte's 2025 technology, media, and telecommunications predictions estimate that global data center electricity consumption, driven substantially by generative AI training and inference, could roughly double from approximately 536 terawatt-hours in 2025 to 1,065 terawatt-hours by 2030. Deloitte Insights, "GenAI power consumption creates need for more sustainable data centers," 2025.

7The U.S. Energy Information Administration's Short-Term Energy Outlook projected that data center demand would help push total U.S. electricity consumption to record highs in both 2025 and 2026, with sales to commercial and industrial customers alone approaching all-time highs. Reuters, "Data center demand to push US power use to record highs in 2025, '26, EIA says."

8Research presented at Lehigh University's ACES Symposium projects that AI-driven data centers could consume between 731 and 1,125 million cubic meters of water annually by 2030, roughly equivalent to the yearly household water use of six to ten million Americans, with data centers already ranking among the top ten water-consuming industries in the United States.

This is the governance debt organizations are carrying before quantum computing enters the picture at all. It is compounding, not holding steady, and very little of it is currently being priced into risk assessments, insurance decisions, or board-level reporting.

V. Quantum: One More Load on a Cracking Foundation

Quantum computing does not need a single dramatic "Q-Day" moment to matter. Federal guidance already directs agencies to plan for "harvest now, decrypt later" attacks, in which encrypted data is stolen today and simply held until a sufficiently powerful quantum computer can decrypt it retroactively.9 Mosca's Inequality frames the practical risk clearly: an organization is already exposed the moment the time its data must stay confidential, plus the time a full migration to quantum-safe systems will take, exceeds the time remaining until a cryptanalytically relevant quantum computer exists.

Under that framing, some categories of data may already be exposed today, even though no quantum computer capable of breaking current encryption yet exists. Attorney-client privileged material is a particularly sharp example: privilege is generally treated as though it has no expiration date, but confidentiality in practice does, once the underlying data has been harvested and is simply waiting to be unlocked.10

Quantum mechanics also strains the forensic and evidentiary assumptions much of eDiscovery and litigation practice is built on. Standard chain-of-custody and hash-verification methodology assumes a stable record can be copied without being altered. Superposition and the no-cloning theorem, real physical constraints of quantum systems rather than legal abstractions, undercut that assumption at the level of physics, not procedure. None of this requires a dramatic breakthrough to be a live governance question; the gap is operational and evidentiary today, not merely theoretical.

VI. Where the Adults in the Room Are, and Are Not

Some serious institutional work is underway. NIST finalized its first set of post-quantum cryptography standards in August 2024, giving organizations an actual algorithmic foundation to migrate toward.11 The UK's National Cyber Security Centre has published a three-phase migration roadmap: identify and plan through 2028, execute high-priority upgrades from 2028 to 2031, and complete migration by 2035.12 Forrester's analysis puts the arrival of a cryptanalytically relevant quantum computer at roughly a decade out on average, with a plausible range of five to

9Office of Management and Budget Memorandum M-23-02 (Nov. 18, 2022), issued pursuant to National Security Memorandum 10, directs federal agencies to begin migrating to post-quantum cryptography on the express premise that adversaries can record encrypted data today and decrypt it later once a cryptanalytically relevant quantum computer exists, commonly termed "harvest now, decrypt later."

10Michele Mosca, "Cybersecurity in an Era with Quantum Computers: Will We Be Ready?" IEEE Security & Privacy, 2018. Mosca's Inequality frames the risk as a race between how long sensitive data must remain protected, how long a full migration to quantum-safe systems takes, and how soon a cryptanalytically relevant quantum computer arrives, an organization is already exposed if the first two numbers together exceed the third.

11The National Institute of Standards and Technology finalized its first set of post-quantum cryptography standards in August 2024, providing the algorithmic foundation organizations will need to build migration plans around.

12The UK National Cyber Security Centre's post-quantum cryptography migration guidance sets a three-phase roadmap for all sectors: identifying vulnerable systems and building a migration plan through 2028, executing high-priority upgrades from 2028 to 2031, and completing migration for all systems by 2035. NCSC, "Cyber chiefs unveil new roadmap for post-quantum cryptography migration."

twenty years, while noting that several governments have already set binding deadlines regardless of that uncertainty, Australia's Signals Directorate has set the most aggressive target, 2030.

13Quantum computing also offers at least a partial answer to a piece of the problem it creates: true random number generation. Much of modern cryptography depends on randomness that is only pseudo-random, generated by deterministic algorithms that a sufficiently capable adversary could theoretically predict. Genuinely random values, of the kind quantum processes can generate, close off that avenue of attack for key generation and other cryptographic building blocks. It is a meaningful piece of the puzzle, not a solution to the broader governance gap described in this paper.

What is comparatively rare is coordinated private-sector engagement with any of this before it is contractually or regulatorily forced. Ralph Losey's Quantum Law course is one of the more developed efforts to translate this landscape into practical legal guidance, and it is instructive that the course spends real time on questions the profession has not yet answered: when does a duty to notify a breach actually trigger if the data was stolen years before it becomes decryptable, and can a court obtain meaningful visibility into a system's safeguards without effectively re-litigating the underlying computation itself.14

VII. The PQE Migration as a Forcing Function

There is a practical opportunity buried inside all of this urgency, and it is worth naming plainly. The migration to post-quantum encryption standards is not an optional initiative organizations can quietly defer. It is coming on a government-driven timeline, and every organization holding sensitive data will eventually have to move it into PQE-compliant infrastructure.

The default failure mode is predictable: under deadline pressure, most organizations will simply migrate everything they already have, including years of accumulated redundant, obsolete, and trivial data, commonly abbreviated ROT, because sorting it first feels like extra work when a compliance clock is running. That is the expensive path. It multiplies the volume, cost, and risk surface of the migration by dragging forward exactly the data that never needed to survive in the first place.

The Legal Data Intelligence, or LDI, discipline offers a better sequence: classify before you migrate, not after. LDI's guiding framework identifies data as Sensitive, Urgent, or Necessary, commonly referred to as SUN, the affirmative counterpart to ROT. Applied ahead of a PQE migration, AI-enhanced classification can identify what genuinely requires quantum-grade protection and what can be defensibly eliminated rather than carried forward at new expense.

The economics are straightforward. Every gigabyte of ROT data identified and eliminated before migration is a gigabyte an organization never has to encrypt, transport, or maintain under the new standard. Positioned correctly,

13Forrester's analysis notes that while the timing of a cryptanalytically relevant quantum computer cannot be predicted with confidence, current best estimates cluster around a decade out, with a plausible range of five to twenty years; several governments have nonetheless set binding migration deadlines, with Australia's Signals Directorate setting the most aggressive target of 2030 and most others converging on 2035. Forrester, "It's Time To Start Planning Your Postquantum Migration."

14Ralph Losey, Quantum Law Course (EDRM, Aug. 2026), an eight-part continuing legal education course on AI, quantum computing, and the future of legal judgment. References here are to Losey's teaching materials and classroom framing, offered as expert commentary and pedagogical hypothesis rather than as controlling authority or decided case law.

the cost of AI-enhanced classification work can be substantially offset, in many cases more than offset, by what an organization saves by not migrating data that never needed to be kept. Discernis, an AI-native eDiscovery and document review platform built for exactly this kind of identification and classification at scale, is a practical means of executing that discipline: not as an added compliance cost, but as the mechanism that makes the coming migration materially cheaper and better governed than it would otherwise be.

VIII. What This Means for Risk Officers and General Counsel

A few concrete steps follow directly from the analysis above:

Know your open source dependency graph, not just your known vulnerabilities. Ask not only whether a component has a current CVE, but whether it is maintained by a well-resourced team or a single overextended volunteer.

Treat data center and infrastructure dependency as a genuine continuity risk, not an assumed utility. Build it into vendor diligence and business continuity planning rather than leaving it unexamined.

Treat harvest-now-decrypt-later as a present-tense threat to any data with a long confidentiality horizon, privileged communications chief among them, not a future problem tied to a single dramatic event.

Ask cloud and software vendors directly about their post-quantum migration plans and timelines, rather than assuming the question will be answered for you.

Approach the coming PQE migration as a classification project first and a technical migration second. Sort before you move.

Build governance for model-centric, probabilistic evidence now, rather than waiting for a court to force the question in the middle of a dispute.

IX. Higher Ground

The wave, whatever form it ultimately takes, whether a dramatic quantum breakthrough or simply the accumulated weight of a stack that was never properly resourced, is not the signal to watch for. The water has already been running out for some time: in maintainer burnout statistics, in unpatched dependencies nobody mapped, in energy and water demand curves nobody is pricing into risk models, in privileged data quietly being harvested today for decryption tomorrow.

This paper does not claim to have all the answers. It is intended as a set of questions the author believes deserve far more serious attention than they are currently receiving, in the hope that the researchers, regulators, and institutions already working on pieces of this problem continue that work with the urgency it warrants, and that more of the private sector joins them before the timeline forces the issue. The signal is already visible to anyone willing to look at the waterline directly. The moment to start moving toward higher ground is now, not after the wave arrives.

Joe Bartolo, J.D. is Director of AI at Discernis.ai and an LDI Architect with 22+ years of legal technology and eDiscovery consulting experience.