Larry Orton
Founder & Chief Executive Officer, WireWolf Inc.
Abstract
Cybersecurity is entering a period in which artificial intelligence systems are becoming directly involved in the analysis, planning, and decision-making once performed exclusively by human operators. In this article I examine the emerging concept of AI-native offensive security and its relationship to a second technological transition: the eventual arrival of cryptographically relevant quantum computing.
Drawing on recent demonstrations of autonomous vulnerability discovery and, most notably, the first documented AI-orchestrated cyber-espionage campaign, I synthesize research across autonomous cyber reasoning, offensive security automation, and post-quantum cryptography. My central and original contribution is a new concept I introduce here, Cryptographically Relevant Autonomy (CRA)[1]: the threshold at which autonomous agents can independently identify and prioritize which encrypted information is worth collecting today for decryption once a quantum computer exists.
I argue that CRA, rather than the quantum computer itself, is the nearer and more decision-relevant milestone, because it supplies the targeting capability that has long been the missing ingredient in harvest-now, decrypt-later attacks. Rather than predicting imminent autonomous cyber conflict, I propose a framework for studying systems in which intelligence, computation, and operational decision-making increasingly converge, and I emphasize the technical limitations, governance challenges, and unresolved scientific questions that remain.
Keywords: artificial intelligence, offensive cybersecurity, autonomous cyber operations, AI agents, quantum computing, post-quantum cryptography, harvest-now, decrypt-later, cryptographically relevant autonomy
1. Introduction
Offensive cybersecurity has historically depended on human expertise. Security professionals interpret incomplete information, develop hypotheses, and adapt strategies based on changing technical environments. Automation has increased efficiency, but human judgment has remained central.
Recent advances in artificial intelligence introduce a different research possibility: systems that participate in portions of cyber reasoning rather than merely executing predefined tasks.
In this article I investigate the intersection of two developments usually studied in isolation: AI-native offensive security and the cryptographic implications of quantum computing. Each is typically assigned its own timeline. One is measured in the maturation of autonomous agents, the other in the engineering of a large-scale quantum computer. I argue that these timelines are not independent, and that the coupling between them creates risk earlier than either technology would on its own.
My goal is not to claim that autonomous cyber systems are inevitable, nor that a cryptographically relevant quantum computer is imminent, but to identify the point at which the two intersect. I introduce that point as a new concept, Cryptographically Relevant Autonomy, and argue that it may reshape the economics of data theft long before any quantum computer is switched on. The remainder of the article reviews the evidence for autonomous offensive capability (Sections 2 and 3), surveys the state of quantum cybersecurity (Section 4), develops the convergence thesis and the concept of Cryptographically Relevant Autonomy (Section 5), and proposes a research framework and set of open questions (Sections 6 and 7).

2. Literature Review and Research Context
Current research spans several connected domains: autonomous vulnerability discovery, large language models for cybersecurity, adversarial machine learning [1], cyber reasoning systems, and post-quantum cryptography [2].
Early work established that machines could perform cyber reasoning autonomously. The DARPA Cyber Grand Challenge [3] showed that computer systems could identify and even patch software vulnerabilities without human intervention. Rapid progress in large language models has since sharpened these capabilities, initially as assistance for security analysis and penetration testing [4].
By 2024 and 2025, autonomous discovery moved from research prototype to operational result. Google’s Big Sleep agent identified a previously unknown, exploitable memory-safety vulnerability in the widely used SQLite database. This was reported as the first public case of an AI agent finding such a flaw in real-world software, and the same agent later flagged a vulnerability that was already being prepared for exploitation in the wild [5]. In DARPA’s AI Cyber Challenge, concluded at DEF CON in August 2025, autonomous cyber reasoning systems discovered 86 percent of the synthetic vulnerabilities seeded across roughly 54 million lines of code, patched 68 percent of them, and surfaced 18 previously unknown real-world flaws, at an average cost of about 152 US dollars per task [6].
The most consequential demonstration came in November 2025, when Anthropic disclosed what it assessed to be the first documented large-scale cyberattack executed with minimal human intervention. A state-sponsored group manipulated an agentic coding tool into performing an estimated 80 to 90 percent of the tactical work across roughly 30 targets, with human operators intervening only at strategic decision points. Of particular relevance to this paper, the agent did not merely obtain access: it autonomously extracted data and categorized the results by intelligence value, performing the analytic triage that has traditionally demanded experienced human judgment [7].
These systems remain constrained by reliability, contextual understanding, and the ability to operate safely in complex environments; the November 2025 campaign, for instance, was limited in part by the agent’s tendency to hallucinate results [7]. Yet the trajectory is unambiguous: the capabilities most relevant to offensive operations (discovery, exploitation, and the prioritization of stolen information) are increasingly performed by machines rather than people.
3. AI-Native Offensive Security
AI-native offensive security describes a class of systems designed around artificial intelligence as a foundational capability. Unlike traditional automation, these systems are intended to evaluate information, generate possible strategies, and adapt based on feedback.
The research challenge is determining which portions of offensive workflows can be reliably delegated to autonomous systems while maintaining appropriate human oversight [8].
The offensive workflow divides into four functions: reconnaissance, exploitation, exfiltration, and the prioritization of what has been obtained. The demonstrations of Section 2 show autonomous systems performing the first three; the fourth (deciding what is worth taking and keeping) is both the newest to be automated and, as later sections argue, the most strategically significant when paired with a long-horizon threat such as quantum decryption.

4. Quantum Computing and Cybersecurity
Quantum computing research has primarily affected cybersecurity through cryptographic concerns. Shor’s algorithm [9] demonstrated that sufficiently capable quantum computers could threaten cryptographic systems based on integer factorization and discrete logarithms.
Current quantum cybersecurity efforts therefore focus on post-quantum cryptography, and in 2024 the U.S. National Institute of Standards and Technology finalized its first post-quantum standards [2]. A machine capable of running Shor’s algorithm against real-world key sizes is commonly termed a cryptographically relevant quantum computer (CRQC); no such machine is known to exist, and credible estimates for its arrival span the 2030s and beyond.
The cryptographic threat, however, does not wait for the CRQC. Under a strategy known as harvest-now, decrypt-later (HNDL; also called store-now, decrypt-later), an adversary intercepts and archives encrypted data today in the expectation of decrypting it once a CRQC becomes available. The U.S. National Security Agency, CISA, and allied agencies assess that such collection is already under way, and national mandates reflect this urgency: U.S. National Security Memorandum 10 directs federal agencies to complete post-quantum migration by 2035, while the NSA’s CNSA 2.0 timeline targets 2030 for national security systems [10], [11].
The urgency is captured by Mosca’s inequality: if the time a secret must remain confidential, plus the time required to migrate systems to quantum-resistant cryptography, exceeds the time until a CRQC arrives, then that data is already at risk today [12]. The prospect of quantum computing directly powering offensive AI remains speculative; its role in making today’s harvested data readable tomorrow does not.

5. The Convergence Thesis: Cryptographically Relevant Autonomy
Harvest-now, decrypt-later is usually framed as a storage problem, but storage is cheap and interception is passive; neither is the true constraint. The real bottleneck is selection. The volume of encrypted traffic crossing global networks is enormous, and the payoff from decryption lies years or decades in the future. An adversary who harvests indiscriminately accumulates an archive whose signal is buried in noise and whose value cannot even be assessed until a CRQC exists. Deciding what to harvest is an analytic problem that has historically required scarce human expertise. The adversary must judge what will still matter after the arrival of quantum decryption, and what justifies the cost of decades of retention.
This is precisely the function that autonomous agents have begun to perform. To name it, I propose a new term, Cryptographically Relevant Autonomy (CRA), which I define as the threshold at which autonomous systems can independently identify, prioritize, and curate encrypted information according to its expected long-term intelligence value. I introduce CRA as an original contribution of this work; to my knowledge it does not yet appear in the existing literature. Where a CRQC answers the question of when harvested data becomes readable, CRA answers the prior question of what is worth harvesting at all. The two are complementary rather than competing: CRA governs collection today, and the CRQC governs exploitation tomorrow.
The evidence assembled in Section 2 suggests that CRA is not a distant abstraction. The autonomous data extraction and intelligence-value categorization observed in the November 2025 campaign [7] is functionally the same triage that harvest-now, decrypt-later collection demands. Autonomous vulnerability discovery [5], [6] supplies the access; agentic orchestration supplies the scale; and value-based categorization supplies the selectivity. No single capability is novel in isolation. What is new is their composition into a system that can decide, at machine speed and marginal cost, which encrypted material is worth stealing and storing.
I name the result agentic harvest-now, decrypt-later, a further term I introduce here, and its significance is economic rather than cryptographic. Traditional HNDL forces an adversary to choose between costly, targeted collection and cheap, low-value bulk collection. CRA dissolves that trade-off: agents make precise, high-value targeting available at roughly the cost of bulk collection. This inverts the economics that have so far limited the strategy, and it does so using capabilities that already exist and cryptography that is already deployed, with no quantum computer required.
The implication for defenders is a reframing of the migration timeline. Mosca’s inequality treats the arrival of the CRQC as the one variable outside human control [12]. But CRA acts on the other side of the same inequality: by expanding both the volume and the quality of data harvested before migration is complete, autonomous targeting increases the store of secrets that a future CRQC will render readable. Post-quantum migration is therefore not only a cryptography problem to be solved before quantum decryption arrives; in its most urgent form it is an artificial-intelligence problem being shaped right now.
Two caveats bound this claim. First, current agents remain unreliable: hallucination and brittle long-horizon reasoning still require human supervision at key junctures [7], so CRA describes a threshold being approached, not one decisively crossed. Second, the same capabilities are available to defenders, who can use autonomous discovery to find and remediate vulnerabilities before adversaries reach them [5], [6]. The thesis is not that offense inevitably wins, but that the strategic clock on post-quantum migration is being advanced by progress in AI and should be modeled accordingly.
6. Proposed Research Framework
I propose that future research examine autonomous offensive intelligence along five dimensions: reasoning capability, operational capability, curatorial capability (the capacity to prioritize information by long-term value), computational resources, and governance. The addition of curatorial capability follows directly from the convergence thesis, because it is the dimension along which harvest-now, decrypt-later collection becomes strategically effective.
Such a framework must evaluate not only technical performance but also reliability, control, and societal impact. In the quantum context, it must also weigh the confidentiality horizon of the data an autonomous system can identify and collect.

7. Research Gaps
· How should autonomous offensive capability be measured?
· What levels of autonomy are technically reliable?
· How should responsibility and oversight be maintained?
· What practical cybersecurity advantages may quantum computing provide?
· How can cryptographically relevant autonomy be detected and measured before it is fully realized?
· How should post-quantum migration priorities account for agent-curated data harvesting?
8. Conclusion
AI-native offensive security represents an emerging research area where artificial intelligence becomes increasingly integrated into cybersecurity reasoning and operations. Current evidence demonstrates progress in automation and cyber reasoning, but significant limitations remain.
Quantum computing’s most immediate security impact is unlikely to come from quantum computers acting as offensive engines. It is more likely to arrive indirectly, through the interaction of autonomous AI, which decides what encrypted data to collect, with a future quantum capability that decides when that data can be read.
The central research challenge, then, is to recognize Cryptographically Relevant Autonomy, the milestone I introduce in this article, as significant in its own right, and to build the scientific frameworks needed to measure and govern autonomous cyber systems before their capabilities, and the archives they help assemble, mature beyond our ability to respond.
References
[1] MITRE Corporation, “MITRE ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems,” 2021. [Online]. Available: https://atlas.mitre.org
[2] National Institute of Standards and Technology, “Post-Quantum Cryptography Standards,” FIPS 203, FIPS 204, and FIPS 205, Aug. 2024.
[3] Defense Advanced Research Projects Agency, “Cyber Grand Challenge Final Event,” Las Vegas, NV, Aug. 2016.
[4] G. Deng, Y. Liu, V. Mayoral-Vilches, P. Liu, Y. Li, Y. Xu, T. Zhang, Y. Liu, M. Pinzger, and S. Rass, “PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration Testing,” in Proc. 33rd USENIX Security Symposium (USENIX Security 24), Philadelphia, PA, Aug. 2024, pp. 847–864.
[5] Google Project Zero, “From Naptime to Big Sleep: Using Large Language Models to Catch Vulnerabilities in Real-World Code,” Nov. 2024. [Online]. Available: https://googleprojectzero.blogspot.com
[6] Defense Advanced Research Projects Agency and Advanced Research Projects Agency for Health, “AI Cyber Challenge (AIxCC) Final Competition Results,” DEF CON 33, Las Vegas, NV, Aug. 2025. [Online]. Available: https://aicyberchallenge.com
[7] Anthropic, “Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign,” Threat Intelligence Report, Nov. 2025. [Online]. Available: https://www.anthropic.com/news/disrupting-AI-espionage
[8] National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100–1, Jan. 2023.
[9] P. W. Shor, “Algorithms for Quantum Computation: Discrete Logarithms and Factoring,” in Proc. 35th Annual Symposium on Foundations of Computer Science, Santa Fe, NM, 1994, pp. 124–134.
[10] Cybersecurity and Infrastructure Security Agency, National Security Agency, and National Institute of Standards and Technology, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” Aug. 2023.
[11] National Security Agency, “Announcing the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0),” Sept. 2022.
[12] M. Mosca, “Cybersecurity in an Era with Quantum Computers: Will We Be Ready?,” IEEE Security & Privacy, vol. 16, no. 5, pp. 38–41, 2018.
[1] The abbreviation CRA is used in this paper exclusively for Cryptographically Relevant Autonomy. It is unrelated to the European Union’s Cyber Resilience Act (also abbreviated CRA), with which it shares only the acronym.