AI-DRIVEN CRYPTO-AGILITY: BUILDING AUTONOMOUS AGENTS FOR POST-QUANTUM CRYPTOGRAPHY MIGRATION
Quantum computing is expected to create new opportunities in scientific simulation, optimization, artificial intelligence, materials research and so many other areas. However, sufficiently powerful quantum computers could also challenge widely used public-key cryptographic algorithms such as RSA, Elliptic Curve Cryptography (ECC), Diffie-Hellman, and ECDSA.
Although cryptographically relevant quantum computers are not currently available, organizations may need to prepare before they become a practical threat. Sensitive encrypted information can remain valuable for many years. Attackers could collect encrypted data today, store it, and attempt to decrypt it when sufficiently capable quantum computers become available. This risk is popularly known as “Harvest Now, Decrypt Later.”
Post-Quantum Cryptography (PQC) addresses this challenge through algorithms designed to resist attacks from both classical and quantum computers. Unlike quantum cryptography, PQC does not require quantum hardware. These algorithms can run on existing servers, cloud platforms, applications, browsers, and mobile devices.
In August 2024, the U.S. National Institute of Standards and Technology (NIST) finalized its first three major PQC standards [1].
| NIST standard | Algorithm | Primary purpose |
|---|---|---|
| FIPS 203 | ML-KEM | Secure key establishment |
| FIPS 204 | ML-DSA | Digital signatures |
| FIPS 205 | SLH-DSA | Hash-based digital signatures |
Table 1: NIST three PQC Standards
The availability of standards is an important milestone, but migration remains a major enterprise challenge. Large organizations may operate thousands of applications, APIs, certificates, cloud services, databases, and legacy systems without complete visibility into where cryptographic algorithms are used.
This is where AI-driven crypto-agility can help.
What Is AI-Driven Crypto-Agility?
Crypto-agility is the ability to discover, replace, update, or reconfigure cryptographic technologies without redesigning an entire application.
In many traditional systems, cryptographic algorithms are directly embedded in application code. Replacing RSA or ECC may therefore require source-code modifications, certificate updates, dependency upgrades, protocol testing, and coordination among application, infrastructure, security, and vendor teams.
AI-driven crypto-agility introduces intelligent agents into this process. These agents can analyze source code, certificates, software dependencies, application configurations, and infrastructure metadata. They can identify cryptographic usage, add business context, estimate migration risk, recommend migration strategies, and monitor implementation progress.
The objective is not to allow AI to independently modify production cryptography. AI should support security teams through discovery, analysis, prioritization, and recommendations, while security policies and experts retain control over critical decisions.
Why Is PQC Important Now?
PQC is moving from academic research into practical deployment.
Cloudflare reported that the worldwide share of post-quantum encrypted traffic increased from approximately 29% at the beginning of 2025 to 52% in early December 2025 [2].

Figure 1: Growth in the worldwide share of post-quantum encrypted traffic observed by Cloudflare during 2025 [2].
This increase indicates that PQC is becoming part of real internet infrastructure rather than remaining only a future security concept. Migration may take several years because organizations must identify cryptographic dependencies, evaluate vendor support, update applications, test interoperability, and measure operational impact.
Early preparation can reduce the need for rushed security changes in the future.
How Autonomous AI Agents Can Support PQC Migration
A practical migration platform can use several specialized agents rather than relying on one general-purpose AI model.
| AI agent | Main responsibility | Example output |
|---|---|---|
| Discovery Agent | Detect cryptographic algorithms and libraries | “RSA-2048 detected in Payment API” |
| Context Agent | Identify purpose and business usage | “Used for production TLS authentication” |
| Risk Agent | Calculate migration priority | “Critical due to long-lived sensitive data” |
| Recommendation Agent | Suggest a migration approach | “Evaluate hybrid ML-KEM” |
| Validation Agent | Measure compatibility and performance | “TLS handshake latency increased” |
Table 2: Roles and Responsibilities of Autonomous AI Agents in PQC Migration
Following steps describe how an organization identifies its existing cryptography and decides which systems should be migrated to Post-Quantum Cryptography (PQC) first.
Step 1: Build a Cryptographic Inventory
The results can be stored in a Cryptographic Bill of Materials (CBOM). A CBOM records the algorithm, application, purpose, ownership, environment, and cryptographic dependencies.
A complete inventory is essential because an organization cannot migrate cryptographic technologies that it does not know exist.
Step 2: Add Technical and Business Context
Finding the term RSA in source code is not sufficient. The system must determine:
- Is the algorithm used in production or testing?
- Is it used for encryption, digital signatures, or key establishment?
- Is the application internet-facing?
- How long must the information remain confidential?
- Is the application business-critical?
- Is the cryptography internally managed or controlled by a vendor?
- An AI agent can analyze surrounding code, documentation, architecture information, and application metadata. Each result should include evidence and a confidence score so that security teams can review uncertain findings.
Step 3: Prioritize Quantum-Migration Risk
Applications can be prioritized using factors such as:
- Quantum-Migration Risk
- Algorithm Exposure
- Data Sensitivity
- Confidentiality Lifetime
- Business Criticality
- External Accessibility
The following scores are illustrative project values and are not an industry-standard risk model.
| Application | Current algorithm | Data lifetime | Risk score | Priority |
|---|---|---|---|---|
| Payment API | RSA-2048 | 15 years | 100 | Critical |
| Identity Service | ECDSA | 10 years | 85 | Critical |
| Customer Portal | RSA-2048 | 5 years | 70 | High |
| Internal Analytics | ECDSA | 3 years | 40 | Moderate |
Table 3: Example Quantum-Migration Risk Prioritization
The Payment API receives the highest priority because it combines long-lived information, high business importance, external exposure, and quantum-vulnerable public-key cryptography.
Short Hands-On Example
The following simplified Python logic demonstrates how applications can be prioritized:
risk = 0
if algorithm in ["RSA", "ECC", "ECDSA"]:
risk += 40
if data_retention_years >= 10:
risk += 30
if criticality == "High":
risk += 30
priority = "Critical" if risk >= 70 else "Planned"
In a production system, AI agents could extract these values from code, certificates, application documentation, and infrastructure inventories.
However, the final risk calculation should use transparent and deterministic policies. This makes security decisions reproducible, explainable, and auditable.
Real-World Example: Cloudflare
Cloudflare provides an important example of operational PQC adoption. Cloudflare supports hybrid post-quantum key agreement by combining established classical cryptography with post-quantum protection based on ML-KEM [3].

Figure 2: Hybrid TLS Key Establishment Using Classical Cryptography and ML-KEM
How it works
- Browser or Application initiates a secure connection.
- Classical Key Agreement and Post-Quantum ML-KEM run simultaneously.
- Both algorithms generate a Hybrid Shared Secret.
- The shared secret establishes a secure encrypted TLS connection.
This example demonstrates that PQC can operate using current internet infrastructure. Users do not require access to quantum computers because post-quantum algorithms execute on classical computing systems.
Implementation Strategy
Organizations can adopt AI-driven crypto-agility through five stages.

Figure 3. Five-Stage AI-Driven Crypto-Agility Adoption Framework
Stage 1. Discover
Identify all cryptographic assets across applications, infrastructure, certificates, source code, and software dependencies. Build a Cryptographic Bill of Materials (CBOM) to gain complete visibility.
Stage 2. Assess
Evaluate the risk and migration priority of each cryptographic asset based on data sensitivity, algorithm exposure, business criticality, and internet accessibility.
Stage 3. Plan
Select the most appropriate post-quantum migration strategy by mapping existing cryptographic algorithms to suitable PQC alternatives, such as ML-KEM or ML-DSA.
| Current cryptographic use | Potential migration direction |
|---|---|
| RSA or ECDH key establishment | Evaluate ML-KEM or a hybrid approach |
| RSA or ECDSA signatures | Evaluate ML-DSA |
| Long-term signature requirements | Evaluate SLH-DSA |
| Existing TLS services | Test configurations with hybrid classical and PQC |
Table 4: Mapping Existing Cryptographic Algorithms to PQC Migration Options
Stage 4. Test
Validate the performance and compatibility of the selected PQC solution by measuring latency, resource utilization, and interoperability under realistic conditions.
Stage 5. Deploy & Monitor
Gradually deploy the validated solution using controlled releases while continuously monitoring cryptographic assets, performance, and compliance to maintain crypto-agility.
Open Quantum Safe provides open-source tools for prototyping and evaluating quantum-resistant cryptography. The liboqs library which includes implementations of post-quantum key-encapsulation and digital-signature algorithms [4].
Best Practices and Lessons Learned
- Build visibility before migration. Hidden cryptographic dependencies in legacy applications and third-party integrations can create long-term security gaps.
- Use AI as an advisor. AI can analyze evidence, explain risks, and recommend priorities. Security experts should approve production cryptographic changes.
- Separate AI reasoning from security policy. Use AI for contextual understanding and natural-language explanations. Use deterministic policy engines for risk scoring and approval decisions.
- Evaluate hybrid approaches. Combining classical and post-quantum mechanisms can support a gradual transition while standards, products, and vendor ecosystems continue to mature.
- Measure operational impact. Evaluate latency, CPU usage, memory consumption, network traffic, and compatibility before production deployment.
- Design for future changes. Avoid tightly coupling applications to one cryptographic algorithm. Cryptographic abstraction layers and centrally managed policies make future upgrades easier.
- Maintain human oversight. Autonomous agents should not silently replace production keys, certificates, algorithms, or security configurations.
Conclusion
Post-Quantum Cryptography is becoming an enterprise architecture and migration challenge rather than only a research topic.
AI-driven crypto-agility can help organizations discover cryptographic assets, build CBOMs, assess quantum-related risks, prioritize applications, recommend migration strategies, and monitor implementation progress.
AI can make PQC migration faster and more manageable, but cryptographic decisions should remain transparent, testable, and governed by security experts.
Organizations that begin developing cryptographic visibility and crypto-agility today will be better prepared for future changes in quantum technology and cybersecurity standards.
References
[1] National Institute of Standards and Technology (NIST), “NIST Releases First Three Finalized Post-Quantum Encryption Standards,” August 13, 2024.
[2] Cloudflare, “The State of the Post-Quantum Internet in 2025,” 2025.
[3] Cloudflare Developer Documentation, “Post-Quantum Cryptography for SSL/TLS.”
[4] Open Quantum Safe Project, “liboqs: Open-Source Library for Quantum-Safe Cryptographic Algorithms.”






