News
Thales: AI and Quantum Risks Converge on Enterprise Data, Especially in the Cloud
Artificial intelligence and quantum computing are putting pressure on the same enterprise data protections, with a Thales survey finding that organizations are increasing AI security spending while preparing for threats to today's encryption.
The 2026 Thales Data Threat Report: Quantum & AI Trends, based on responses from 3,120 security and IT management professionals across 20 countries, found that 98% are considering how the two technologies affect each other. Thirty percent reported a significant increase in security budgets specifically for AI.
The research, conducted by 451 Research by S&P Global, examines both the risks and potential benefits of the technologies. Fifty-seven percent believe quantum computing will enhance machine learning, while 54% expect it to enable advanced simulations of complex systems. The security findings span data governance, cloud infrastructure and preparations for quantum-resistant encryption.
Cloud Assets Top the Target List
Cloud-based storage, cloud-delivered applications and cloud management infrastructure were the three most frequently cited asset types targeted by attackers, at 35%, 34% and 32%, respectively. The report connects that exposure to the large datasets required for AI training and the rapid expansion of AI infrastructure.
[Click on image for larger view.] Cloud Assets Lead Attack Targets (source: Thales).
Organizations are also looking to cloud providers for protection: 67% reported investing in their cloud provider's AI-specific security tools, compared with 63% using an established security provider. Respondents could identify multiple sources of protection, including startups, large language model providers and internally developed controls.
Encryption coverage remains incomplete. Only 7% of organizations reported encrypting more than 80% of their sensitive cloud data, while 29% reported encrypting more than 60%. The report's chart puts the average share encrypted at 47% in 2026, down from 51% in 2025.
The findings extend concerns raised in last year's coverage of Thales' cloud security research, when AI security already ranked second to cloud security in spending priorities and 52% of respondents reported that AI security spending was displacing existing security budgets. The latest report again places AI security second, while its historical comparison shows average sensitive cloud data encryption coverage falling from 51% in 2025 to 47% in 2026.
AI Spending Meets Data Governance Gaps
AI security was the second-highest prioritized security spending category overall, behind cloud security. But protecting data ranked much lower among the measures organizations use to judge AI projects: Reducing or managing risks of data loss or noncompliance placed sixth among seven success criteria, at 35%.
Improving customer experience led those measures at 68%, followed by reducing employee toil through greater task automation at 63%. Meanwhile, poor data quality or initial data governance was the leading inhibitor to AI adoption, cited by 65%; security risks from exposed data followed at 61%. Another 51% cited AI initiatives moving too quickly to be properly secured.
Rapid changes in the AI ecosystem led security concerns, with 70% placing them among their top three risks. Trust in third-party systems followed at 58%, ahead of sensitive data exposure at 46% and agents or processes with excessive permissions at 42%.
[Click on image for larger view.] Leading Risks to AI Security (source: Thales).
The researchers argue that these pressures increase the importance of basic data protections. As the report puts it, "When applications and systems become easier to compromise, identity and data security become the last lines of defense."
Preparing for Quantum Threats
Harvest now, decrypt later (HNDL) was the leading quantum security concern, cited by 61%. In an accompanying Thales blog post, the company explains that attackers can collect encrypted information now and retain it until sufficiently powerful quantum computers can defeat the encryption protecting it.
Fifty-nine percent expect to prototype or evaluate post-quantum cryptography (PQC) algorithms within the next 18 to 24 months. Other planned measures include assessing current encryption strategies, at 45%, and creating resilience contingency plans, at 39%. These figures describe intended security measures, rather than completed migrations.
[Click on image for larger view.] Planned Measures for Quantum Security (source: Thales).
Progress varies across the systems that depend on cryptography. Among 2,140 organizations surveying, exploring or experimenting with quantum computing, 66% were on track or ahead of their public key infrastructure objectives. The corresponding figures were 58% for enterprise key management, 56% for code signing and 53% for certificate life-cycle management.
Interoperability with broader ecosystems was less advanced: 39% were on track or ahead, while 34% were behind and 27% were unsure or considered the question inapplicable. The report emphasizes planning changes across infrastructure and development processes while building the ability to adopt new cryptographic algorithms without disrupting operations.
Stronger Fundamentals Accompany Greater Readiness
The study also compared organizations classified as AI leaders -- those investing in AI-specific security and identifying themselves as ahead of peers -- with laggards. Leaders more often reported complete knowledge of where their data was stored, at 36% versus 28%, and the ability to classify all their data, at 43% versus 35%.
Those comparisons show an association, not proof that AI leadership causes better security. The methodology explicitly describes the research as observational and makes no causal claims. The survey targeted larger organizations, excluding those with annual revenue below $100 million and applying a higher cutoff in selected countries.
The report recommends more effective data discovery and classification, unified security controls spanning hybrid infrastructure, faster deployment of post-quantum cryptography and simpler security tooling and operations. Its conclusion links AI-specific defenses with broader efforts to understand and protect enterprise data.
About the Author
David Ramel is an editor and writer at Converge 360.