How Much Can AI Help With PQC Migration?


Table of ContentsIntroductionWhere AI Helps TodayThe Most Ambitious Version of the ArgumentWhere the Years Actually GoWhy Effort Compression Is Not Schedule CompressionBuilding CBOM and Crypto-Agility Are Organizational TransformationsThe Dangerous Misreading
Introduction
Every few weeks, someone tells me that AI is about to solve the PQC migration timeline problem. The pitch varies. Sometimes it comes from a vendor demonstrating an AI-powered cryptographic discovery tool. Sometimes it surfaces in a LinkedIn thread where someone argues that frontier models will “automate away” the multi-year programs that organizations are staring at. Sometimes it appears in a conference panel where a speaker projects a slide showing “Traditional: 10+ years” on one side and “AI-Accelerated: 2-3 years” on the other, with an arrow between them.
The pitch is appealing. PQC migration at enterprise scale involves upwards of 120,000 discrete tasks spanning network infrastructure, application code, PKI hierarchies, key management, hardware security modules, embedded systems, operational technology, and vendor relationships. The deadlines are already arriving from multiple directions. Executive Order 14412, signed on June 22, 2026, directs federal agencies to migrate high-value and high-impact systems to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031, and requires federal contractors to comply with PQC FIPS by the end of 2030. NIST IR 8547 proposes deprecating quantum-vulnerable public-key algorithms (RSA, ECDSA, ECDH, DH) by 2030 and disallowing them by 2035. CNSA 2.0 imposes separate requirements for National Security Systems. Google and Cloudflare have set internal 2029 migration targets. These are not interchangeable commitments, but they all point the same direction: organizations no longer have an unlimited planning horizon. If AI could compress the timeline from a decade to a few years, the problem would be far more t…