Post-quantum cryptography is beginning to move from standards documents into production internet infrastructure. Cloudflare has enabled validation of ML-DSA-44 post-quantum signatures for DNSSEC on its 1.1.1.1 public DNS resolver, providing a useful example of what migration looks like when new cryptography meets real networks.

The change matters because quantum risk is often discussed as a distant problem. NIST now says its three completed post-quantum cryptography standards are ready for implementation, and organisations are being encouraged to begin migration work rather than wait for a cryptographically relevant quantum computer to arrive.

Cloudflare’s DNSSEC work also illustrates why migration is not simply a matter of replacing one algorithm with another. An ML-DSA-44 signature is much larger than the ECDSA P-256 signatures widely used today. Cloudflare cites 2,420 bytes for ML-DSA-44 compared with 64 bytes for ECDSA P-256. Larger signatures affect packet size, transport behaviour, compatibility and the risk of fallback or downgrade problems.

Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.

DNSSEC is an important example because it highlights a different quantum threat from the familiar 'harvest now, decrypt later' scenario. Harvest-now attacks concern encrypted information that an adversary records today in the hope of decrypting it in the future. DNSSEC is primarily about authenticity rather than secrecy. The concern is that sufficiently powerful quantum systems could eventually undermine the signatures used to prove that DNS records are genuine, creating a forgery risk rather than a retrospective decryption risk.

That distinction should shape enterprise migration programmes. Organisations need to map where cryptography is used for confidentiality, where it is used for signatures, and where it underpins certificates, identity, machine-to-machine trust and network protocols. They also need to understand which suppliers and legacy systems can support hybrid or post-quantum approaches and which cannot.

NIST’s work on Personal Identity Verification is a further sign that transition will be gradual. Its June 2026 materials are initial working drafts, not final PIV standards, and centre on a dual-stack model in which existing classical PIV keys and data objects coexist with new post-quantum credentials to support backward compatibility and incremental deployment.

The practical lesson is that post-quantum readiness is increasingly a systems engineering and inventory problem. The organisations that can identify their cryptographic dependencies, test new algorithms and manage compatibility are likely to be better placed than those treating quantum risk as a future procurement decision.


The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.
Share this post
The link has been copied!