Artificial Intelligence Revenues Would Need to Grow by 80 Percent Annually
Benedikt Langer
4 min. reading time Stijn Van Nieuwerburgh of Columbia Business School calculates that AI investment ...
In February the BSI (Federal Office for Information Security) set an expiry date for classical encryption for the first time: the end of 2031, and the end of 2030 where the protection requirement is high. Archives and backups captured now will be readable later. The real gap is the list of places where the old algorithm still runs.
Key takeaways
RelatedPost-quantum: why CIOs need a crypto inventory now / Post-quantum cryptography is pushing into corporate IT
What is post-quantum cryptography? The shift of public-key schemes to algorithms meant to hold against quantum computers as well. In the transition they run hybrid, together with the classical schemes in the same channel.
On 11 February 2026 the BSI, in its Technical Guideline TR-02102, specified for the first time when classical encryption alone is no longer enough. Key agreement is affected first: the moment two computers negotiate a shared session key at the start of a connection, for example when a VPN tunnel or an encrypted website is set up. Schemes such as RSA protect that moment with computational problems a large enough quantum computer could solve in hours rather than millennia.
| BSI requirement (TR-02102, 11 February 2026) | Deadline |
|---|---|
| Classical key agreement only in hybrid mode | End of 2031 |
| The same for a very high protection requirement | End of 2030 |
| Classical signatures only in hybrid mode | End of 2035 |
Source: BSI, press release and Technical Guideline TR-02102 of 11 February 2026.
Five years sounds like plenty of time. It runs short because the threat starts before the quantum computer arrives.
Anyone who captures tunnel recordings or backup sets today can store them until a cryptographically relevant quantum computer is available. The captured data can then be read. On 28 August 2026, Computer Weekly described this in an opinion piece by Antonio Paolo Mecci: the TLS stack on the network now negotiates hybrid, quantum-safe keys automatically. The magnetic tapes that went into the archive that same night, meanwhile, still carry a key hierarchy from the time when RSA was considered unbreakable.
The deadline therefore follows the lifetime of the data. A patient record or a design archive kept for ten years is already exposed today, even if the web server moves next week. A pilot at the public endpoint does not change that exposure.
In March 2026 the IT security provider SITS wrote that the real work is the list of affected applications and services, and the decision on what comes first. The product name of the TLS library is no substitute for that list.
The gap typically shows in three items that sit side by side in a corporate group: the magnetic tapes from the Computer Weekly example, whose keys are still wrapped with RSA and which must stay readable for years under retention rules. A channel between the machine controller and the control room, whose manufacturer has so far given no commitment to hybrid schemes. And a code-signing certificate for which nobody on the org chart is responsible. None of these three items appears if IT checks only the web server. In most corporate groups the list is missing because cryptography was bought along with products for years and nobody kept it as an inventory of its own.
For companies under the EU NIS2 directive, which obliges operators of important services to make risk management demonstrable, or under DORA, the rule set for financial IT, this list is more than housekeeping. If the regulator asks where migration stands, the inventory is the only answer that documents due care. Without a list, only intent remains.
Whoever orders hybrid operation orders it from manufacturers. The firewall, the VPN gateway and the machine controller must deliver dual mode. Only the supplier knows whether they will do so by 2030. Fraunhofer AISEC focuses on this point: without binding commitments from suppliers across the estate, there is no reliable switchover.
A roadmap on slides that lacks delivery dates, hybrid capability in writing and exit clauses therefore remains a statement of intent. Swap only the visible spot and the result is a new web server, an old archive and an untouched device channel.
Not all of it can be migrated by 2031. Production plants with hard-wired channels whose life cycles run longer than the BSI deadline. Archives without a migration path need exceptions too. Whether such an exception locks the residual risk in or keeps it manageable turns on whether it carries an owner, a reason and an expiry date.
The trade-offs are explicit: speed versus supplier lock-in, the estate versus the pilot, documentary proof versus a statement of intent. A narrow pilot calms the quarterly report, while the captured backups keep waiting for their quantum computer. Even the BSI does not say when it will arrive.
The highest tier of BSI IT-Grundschutz (baseline protection), for data whose loss can threaten the organization’s existence. For these systems the deadline is the end of 2030, for all others the end of 2031.
Schemes, keys, certificates, data lifetime and the vendor or the library. Transport, signatures, code signing, VPN, certificate authorities and archives with long retention belong on the same list.
Hybrid channels combine classical and post-quantum-safe schemes, so the channel holds if one side fails. The changeover takes years. A single cut-off date underestimates dependencies in devices, archives and supply chains.
Read more on Digital Chiefs
Digital ChiefsCloud, ERP and AI: Where switching providers gets expensiveDigital ChiefsDeloitte: 14 Percent of Firms Hit Their Savings TargetDigital ChiefsIONOS funds AI expansion through workforce reductionMore from the MBF Media Network
Header image source: AI-generated (September 2026)
Translated from the German original using artificial intelligence. The German version is authoritative.