▽ SECURITY & DEFENSE 10 YEARS HORIZON RESOLVES 28 SEPT 2036 · in 10.0y

A quantum computer decrypts standard 2048-bit RSA encryption before 2035.

Advances in quantum computing threaten public-key cryptography. Decrypting 2048-bit RSA within practical timeframes would demonstrate breaking modern cryptographic standards.

Across 6 frontier models answering independently, the panel has all but ruled it out: the median is 13%.

They broadly agree, 16 points between GPT at 18% and Qwen at 2%.

Nothing is settled until 28 Sept 2036, when the outcome is checked against sources and every number above gets a permanent score.

MODEL BY MODEL

What each one said

  • GPTOpenAI

    It turns on whether fault-tolerant machines reach millions of high-quality physical qubits, not today’s noisy-qubit scaling curves.

    • Shor factoring RSA-2048 needs roughly millions of physical qubits plus long-lived error correction, far beyond 2026 systems.
    • IBM, Google and Quantinuum must demonstrate scalable logical qubits and decoding by the early 2030s; roadmaps are not deployments.
    • A credible million-qubit fault-tolerant prototype by 2030 would sharply raise the odds; repeated logical-error stalls would lower them.
    openai/gpt-5.6-terra · asked 1 Oct 2026
    18%
  • GrokxAI

    Needs million-scale fault-tolerant qubits running Shor’s on 2048-bit RSA by 2034.

    • IBM/Google/Quantinuum must deliver ~10k logical qubits with <10^{-12} error by ~2032; current devices are ~1k noisy physical qubits.
    • No quantum factoring beyond RSA-15 exists; expert medians sit in the 2040s, so 9-year window sits well below base rate.
    • A 100-logical-qubit high-fidelity demo before 2029 would raise this sharply.
    x-ai/grok-4.6 · asked 1 Oct 2026
    18%
  • GeminiGoogle

    Breaking RSA-2048 requires millions of physical qubits with error correction, far outstripping current hardware roadmaps before 2035.

    • Shor's algorithm requires roughly 20 million noisy physical qubits or 4,000 logical qubits; state-of-the-art remains under 2,000.
    • Roadmaps from IBM and Google target only a few hundred logical qubits by 2030, leaving a massive scaling gap to close by 2035.
    • A radical algorithmic breakthrough cutting needed logical qubits below 500 or sudden fault-tolerant scaling would shift odds sharply.
    google/gemini-3.8-flash · asked 1 Oct 2026
    14%
  • DeepSeekDeepSeek

    This turns on whether a fault-tolerant machine with millions of physical qubits exists before 2035, not on qubit-count headlines.

    • Shor's algorithm needs roughly 4,000 logical qubits and ~10^9 Toffoli gates for RSA-2048; today's devices have zero logical qubits at that scale.
    • Google, IBM, Quantinuum and PsiQuantum roadmaps target fault tolerance in the early-to-mid 2030s, leaving little margin for a 2048-bit run by 2035.
    • Base rate for cryptographic-scale milestones slipping: RSA-1024 factoring was 'imminent' for two decades; this case sits below even that, since error correction is the…
    deepseek/deepseek-v4.1-flash · asked 1 Oct 2026
    12%
  • ClaudeAnthropic

    Requires millions of physical qubits with low error rates; current hardware is off by orders of magnitude.

    • Current best quantum computers have ~1000 noisy qubits; breaking RSA-2048 needs ~20 million physical qubits with error correction per leading estimates.
    • Error correction overhead and fault-tolerance milestones are progressing slowly, with most experts projecting cryptographically relevant quantum computers post-2035 if…
    • NIST and industry are migrating to post-quantum cryptography as a hedge, reflecting expert consensus that RSA-2048 break by 2035 is unlikely but not impossible with a…
    anthropic/claude-sonnet-5 · asked 1 Oct 2026
    6%
  • QwenAlibaba

    Requires millions of physical qubits with error correction; current best machines have ~1,000 noisy qubits.

    • Shor's algorithm for 2048-bit RSA needs ~4,000 logical qubits, implying millions of physical qubits at current error rates; IBM's roadmap targets ~100K physical qubits…
    • No architecture has demonstrated fault-tolerant logical qubits at scale; even optimistic roadmaps (Google, IBM, IonQ) place cryptographically relevant machines in the…
    • A breakthrough in error correction or a radically new algorithm would be needed to close the gap; neither has appeared in peer-reviewed literature as of late 2026.
    qwen/qwen3.8-max-0902 · asked 1 Oct 2026
    2%

6 of 6 models answered · 16 points between the highest and lowest. None was shown the market price.

WHAT DO YOU THINK?
loading…

Question sourced from a news sweep on 1 Oct 2026. Forecast by google/gemini-3.8-flash, anthropic/claude-sonnet-5, openai/gpt-5.6-terra, x-ai/grok-4.6, deepseek/deepseek-v4.1-flash, qwen/qwen3.8-max-0902 via OpenRouter.