Skip to content

TechChannels Network:      Whitepaper Library      Webinars         Virtual Events      Research & Reports

×
Artificial Intelligence (AI) Cybersecurity

Q&A: Part 2: Yubico’s Albert Biketi Offers a Roadmap for Post-Quantum Readiness

Teri Robinson

Oct 05, 2026

The challenge for organizations trying to reach crypto agility becomes even more consequential when viewed alongside advances in artificial intelligence. In the second of a two-part interview, Albert Biketi, Chief Product and Technology Officer at Yubico, envisions a future in which cryptographically relevant quantum computing could converge with agents operating at machine speed, making strong identity, human authority and resilient security architectures increasingly important.

Biketi examines what organizations can do now to prepare for the post-quantum era, why an iterative transition may be more practical than a wholesale transformation, and how enterprises can build security foundations capable of adapting to technologies that are advancing at extraordinary speed. And he lays out a practical roadmap for post-quantum readiness.

Q. What should organizations do first to prepare for the post-quantum transition?

A. The basic things to get going revolve around actually understanding what's going on in your environment and knowing exactly where specific types of information are stored. Basically, understanding your encryption architecture and your encryption dependencies with a lot more clarity is the first step. And so, for a lot of organizations, that process alone is going to be a multi-year effort. Just understand it properly, then when you do that, you don't necessarily want to start just climbing to the summit right away.

Q. Why should organizations take an iterative approach rather than attempt the entire transition at once?

A. As a climber, you always want to climb then go down again, so you acclimate then you go up again. That’s necessary here because that's how you build and test and understand your agility. And build a community around the most critical things that you're working with, really staying connected.

Q. How can post-quantum security be introduced without completely changing the authentication experience?

A. If you look all around, FIDO has become pervasive, and so what we wanted to do in this post-quantum era was to understand how we could make that same authenticator. And that same authenticator experience work in a very constrained device, but give people an authenticator that could work in the same way people use and love Fido, but with post-quantum algorithms. So, in October last year, we showed the world the first authenticator that was running ML Chem and MLDSA, checking which are the digital signature algorithm and the key encapsulation. We did this using the same form factor that people know, and over NFC and USB, so we're now getting ready to bring that in a more meaningful way to the world.

Q. What needs to happen behind the scenes before organizations can make that transition?

A. There are a lot of things that have to happen behind the scenes that help what I just talked about: understanding your inventory, understanding how relying parties will work, understanding how certification will work. A lot of those things that happen in the backend to make many of those things happen are things that we are now enabling, so that the infrastructure is ready and so that it becomes less complicated for people to make those changes when they are ready. We can't force people to be ready, but we can make the things that people need so that when they're ready that infrastructure is there.

Q. How do AI and post-quantum security intersect?

A. We think there will come a time when some of our most powerful adversaries will be cryptographically relevant quantum computers that have agentic speed. I'm not very good at predicting when that will be, but it'll come.

Q. What could the combination of agentic AI and quantum computing mean for cybersecurity?

A. What you then will have is the combination of incredibly powerful agents that have very persistent reward mechanisms that are backed by capabilities that can solve problems that don't look feasible today in the kind of classical cryptography we have. So, even if that day is far away, we need to be thinking about all the trends that tell us that that day is coming. One of the places we see that is in the incredible advances in computational methods, in algorithmic analysis, things that really would take a very long time for teams of humans to do are now being done by these very powerful agents, combined with just the amount of investment that is going into AI.

Q. As AI increasingly operates at machine speed, where does human authority fit?

A. AI authorization, making sure that it's really the human who is the authority, tells us one thing very clearly: there will be some things that need to operate at machine speed. So basically, a little bit lower than the speed of light, but it's almost indistinguishable from the speed of light for a human. Then there will be some things which have to happen at human speed, because there will be times when it is human judgment that will be part of creating the policy that makes sure that alignment continues. I’m not a doomer around what's going on in AI, or but neither am I just naive about the fact that these are very powerful capabilities that humans are creating. And for the first time, we are creating something that can operate at a scale and speed that was previously considered incomprehensible for a machine.

Q. Why will strong human identity become even more important as AI and quantum technologies advance?

A. As important as these advances are, it still remains extremely important that we understand the role of human authority and the role of making sure that we really give ourselves the opportunity to understand these systems and create the kinds of policies around them that we can. Phishing resistance and the fact that you can very strongly bind a site is really difficult. If used correctly to spoof an identity that is so fundamental at a time when machines will be creating synthetic identities, and we really want to do that.

Whatever else happens downstream, whether it's post quantum or AI, we want to make sure that human link and how that human recovers if they lose their credential is very strong. We see the pervasiveness of enrollment problems, enrolling identities, as well as recovery, as places where people get tripped up and false identities get into the system and poison things.

Q. Post-quantum expertise is still concentrated among a relatively small group of people. How can organizations find the talent and expertise they need?

A. What happens is that even when we have constraints around expertise, the market has a way of accelerating how solutions evolve. Because when you have a very constrained capability around expertise in particular area usually it starts out being extremely lucrative for a small group of people. But people also invest significantly in simplification, and that's what we're doing.

Q. Does solving the skills challenge ultimately depend on making post-quantum security easier to deploy?

A. For a lot of the investments we're making we don't want people to struggle to figure out how a new authenticator works if it's post-quantum capable. We just make it look like the previous one. So what you'll see is that gradually the hardest parts of this will get more investment, and that investment will accelerate simplification, because I think any time you have a severe weakness in security in one sector, everybody is weaker and everybody is less secure. And I think we all know that we have to make progress more or less together in this area.

Ultimately, post-quantum readiness is less about predicting a single date than building an organization capable of changing when the moment demands it. That means understanding the environment, simplifying adoption, preserving strong human identity and designing security architectures that can evolve as cryptography, AI and computing itself advance. As Biketi puts it, “I cannot remember another time in technology when things moved as quickly as they are moving today.”

Share on

More News