OpenAI published ten results on 1 August on mathematical problems that had stood open for ten years or longer, ranging from sphere packings in high dimensions to questions from complexity theory. The results were generated by an internal model (Astra), formally verified with Lean certificates, and the total compute cost was, by OpenAI's own account, around $2,000 in tokens. What decades of human research failed to produce, a machine achieved in a few days for the budget of a laptop.
The result that concerns your encryption
One of the ten results touches directly on the foundations of modern cryptography: a hardness proof for the Closest Vector Problem, a core problem in lattice theory. Post-quantum cryptography rests on exactly this kind of problem — the new generation of encryption designed to withstand quantum computers, definitively standardised since 2024 with NIST's FIPS 203, 204 and 205.
It's important to be honest about what this result does and does not mean. It is a proof that the problem is hard. That actually strengthens trust in lattice-based cryptography. So there is no reason whatsoever for panic that "AI is breaking your encryption". Anyone who claims that is selling fear.
Why this still concerns your organisation
The real lesson sits one layer deeper. The security of all cryptography rests on mathematical assumptions, and those assumptions are now being tested at a pace that was unthinkable five years ago. In both directions: proving something is hard, and finding where it is weak. The durability of such assumptions is no longer a constant.
And separately from that, a clock is already ticking that has nothing to do with AI:
- The coordinated European PQC roadmap steers organisations to start inventory and a migration plan by the end of 2026 at the latest.
- High-risk systems should be migrated by the end of 2030 at the latest, the rest by 2035 at the latest.
- "Harvest now, decrypt later" is already a risk today: encrypted traffic that is intercepted and stored now can be decrypted later. For data with a long confidentiality lifetime — think medical records, legal documents and trade secrets — that threat already counts today.
“The question is not whether the assumptions underlying your current encryption will ever fail. The question is whether you'll already know what to replace, and in what order.”
You can only migrate what you can see
The first step of any PQC migration isn't technology but inventory: which algorithms, protocols, certificates and keys are actually running in your organisation, and which of them are quantum-vulnerable? The NCSC describes this approach together with TNO and the AIVD in the PQC migration handbook. In practice, most organisations turn out not to have this inventory. That's exactly what the SAIG PQC-Readiness Scan is for: a crypto inventory with risk classification and a prioritised migration roadmap, at a fixed price.
PQC-Readiness Scan, fixed price €3,500 excl. VAT
Crypto inventory, external attack surface, risk classification and a migration roadmap aligned with the NCSC handbook. In 2 to 3 weeks.
View the PQC-Readiness Scan (Dutch) →