Economist Quantum Article: Best in Media, Still Wrong
Table of Contents
July 29, 2026 – The Economist published “Quantum computers promise mathematical superpowers”, a 13-minute read covering quantum computing from first principles through applications, investment, and the cryptographic threat. It is, by a clear margin, the best quantum computing article I have seen in a major general-interest publication.
I say that to set the stakes, not to soften the criticism that follows. The Economist sourced from working scientists (Scott Aaronson, Toby Cubitt, Ashley Montanaro) and from a practitioner with deep cryptographic migration experience (Brian LaMacchia). It handled the uncertain applications in finance and optimization with more honesty than most specialist coverage manages. And it resisted the temptation to declare a quantum revolution, keeping its headline promise (“but like all superpowers, they will have their limits”) throughout the piece.
The bottom line: if the best quantum journalism in mainstream media still contains meaningful errors on how quantum computing works, what Shor’s algorithm threatens, and what data to trust, then every reader of every quantum article, including this one, should be checking sources and questioning claims independently. The topic is that hard.
The News
On July 29 the Economist’s Science & Technology section published a feature-length article surveying the state of quantum computing. The piece covers quantum mechanics fundamentals (superposition, entanglement), the competing hardware modalities (superconducting, trapped-ion, neutral-atom, photonic, silicon-spin), the investment picture (citing McKinsey’s Quantum Technology Monitor for both startup investment data and industry value forecasts), recent developments (Oratomic’s error-correction architecture, Google’s ECC resource reduction), the cryptographic threat (Shor’s algorithm and harvest now, decrypt later), quantum simulation for chemistry and materials science, and the uncertain case for quantum finance and optimization.
Sources include Scott Aaronson (University of Texas at Austin), Toby Cubitt and Ashley Montanaro (Phasecraft), and Brian LaMacchia (Farcaster Consulting Group). The article includes two McKinsey-sourced charts: one on global quantum startup investment and one on projected economic value by industry.
My Analysis
I went through the article with the same fact-checking process I apply to research papers and vendor announcements. The findings sort into three categories: explanations that risk reinforcing common misconceptions, imprecisions and conflations that compound into a misleading picture, and a data source that should not have passed without scrutiny.
How quantum computers actually work
The Economist opens its explanation of quantum mechanics well enough, with Aaronson’s Space Shuttle analogy (quantum computers are powerful for specific tasks, useless for most others) and a clear description of superposition and entanglement. Then it reaches for the analogy that has confused more people than any other sentence in quantum journalism:
“A classical computer that wanted to search through such a vast space… would have to try all the potential solutions one at a time. A quantum computer could represent and manipulate them all at once.”
To the article’s credit, it immediately adds the critical qualifier most publications omit: reading a quantum computer’s output “naively” produces a random answer, and the “trick is to exploit the mathematical structure of a problem” to amplify correct answers. That follow-up paragraph is accurate and important.
The phrasing risks reinforcing the most common misconception in quantum computing. Placing “represent and manipulate them all at once” in the explicit context of decrypting a coded message creates the impression that quantum computers break encryption by trying every key simultaneously. They do not, and the distinction is not academic. Shor’s algorithm breaks RSA by reducing factoring to period-finding, then using the quantum Fourier transform to extract the period. It exploits specific mathematical structure in the problem. It is cryptanalysis, not brute force. A quantum computer that simply “tried all keys at once” would, upon measurement, return one random key from the set of all possible keys, which is worthless.
Here is what actually happens: a quantum algorithm arranges computation so that the amplitudes (the mathematical weights describing the quantum state) of wrong answers cancel each other out while the amplitudes of right answers reinforce. Interference, not literal parallel search, is central to every known quantum speedup. I have spent the past year building an entire series to give cybersecurity professionals the tools to understand this properly, and the “tries all answers at once” myth is the single most important thing to unlearn.
What Shor’s algorithm actually threatens
The article’s opening paragraphs state that Peter Shor “worked out how to reduce the time taken to break many types of encryption from billions of years to hours or less.” That sentence is overbroad in a way that matters for every organization planning a migration.
Shor’s algorithm threatens a specific set of public-key cryptographic algorithms: RSA, elliptic-curve cryptography (ECC), and Diffie-Hellman key exchange. These all rest on mathematical problems (integer factoring and discrete logarithms) that Shor’s algorithm solves efficiently. When a sufficiently large quantum computer exists, these algorithms do not weaken. They break completely.
Symmetric encryption (AES) and hash functions (SHA-256) are a different story entirely. Grover’s algorithm provides a quadratic speedup against brute-force search, which in theory halves the effective key length: AES-128 drops to 64 bits of effective security, while AES-256 retains a comfortable 128 bits. In practice, even that theoretical halving is likely infeasible. Grover’s search is inherently sequential (it cannot be parallelized efficiently across multiple machines), and the error-correction overhead of sustaining 264 coherent quantum operations pushes the total cost to a point where the attack offers almost no advantage over classical brute force. The research consensus, including on the conservative assumption side, is that AES-256 is safe.
“Many types of encryption” erases this distinction. A CISO who reads the phrase walks away thinking the entire cryptographic stack is under threat and that symmetric ciphers need replacing. The migration burden is concentrated overwhelmingly on the public-key layer: key exchange, digital signatures, PKI hierarchies, code signing. The symmetric foundation, at adequate key lengths, largely stays. Getting that scope right is a planning question worth billions of dollars across the global economy, and a single imprecise sentence in The Economist makes it harder for every executive who reads it.
The resource gap that vanishes
The article covers two recent resource-reduction results: Oratomic’s neutral-atom error-correction architecture (a preprint proposing that certain cryptographically relevant computations could be performed with as few as 10,000 reconfigurable atomic qubits, down from prior estimates in the millions) and Google’s ECC resource reduction (fewer than 1,200 logical qubits to break 256-bit elliptic-curve cryptography). Both are accurately reported.
What is missing is the number that gives either claim its meaning: what exists today. Current experiments range from one below-threshold surface-code memory (Google, 101 physical qubits) to demonstrations involving tens of error-corrected logical qubits under varying error-detection and correction regimes (Quantinuum’s Helios showed 48 logical qubits in late 2025; Microsoft and Atom Computing entangled 24 in 2024). None of these combines roughly 1,200 concurrent logical qubits, universal fault-tolerant logic, and tens of millions of non-Clifford operations. Google’s ECC circuit, per the paper itself, needs fewer than 1,200 logical qubits executing 90 million Toffoli gates. IBM’s most ambitious near-term fault-tolerance target, Starling, aims for 200 logical qubits by 2029 with 100 million total operations. The operations gap is even starker than the qubit gap: demonstrated logical-gate counts today sit in the thousands, against tens of millions required.
The Economist writes that Oratomic’s work means “there may be less time than they had thought,” and places the word “just” before “1,200 logical qubits.” The “just” plausibly signals the drop from prior estimates rather than imminent feasibility, but without current-state context, readers have no way to judge the remaining distance. Neither framing connects to the hardware reality. These resource reductions are significant for the field’s trajectory, and I have written about them at length, but presenting them without the current-state baseline is the kind of gap that feeds Q-FUD on one side and false urgency on the other.
The article also blurs IBM’s hardware path. It says IBM “has its own quantum chip, named Nighthawk” and, in the same sentence, notes the firm’s plan to build a fault-tolerant quantum computer by 2029. The juxtaposition invites readers to see Nighthawk as the path to that milestone. It is not. Per IBM’s published roadmap, Nighthawk is a 120-qubit, 218-coupler processor built for near-term advantage experiments. The 2029 fault-tolerance target is Starling, a modular qLDPC-based architecture with 200 logical qubits and 100 million operations, with the experimental Loon chip serving as its pathfinder. The article compounds the ambiguity later by describing the planned Starling system as a single “chip.”
On Google Willow: the article says Google “used its new ‘Willow’ quantum processor to complete a task in hours that would have taken a conventional supercomputer thousands of times longer.” The timing and magnitude match Google’s October 2025 Quantum Echoes experiment, an out-of-time-order-correlator (OTOC) calculation that Google estimated was roughly 13,000 times faster than its best classical method. The Economist compresses that into “a task,” making the result sound more general than it was. Quantum Echoes had a more substantive scientific motivation than a pure sampling benchmark, and Google attached a proof-of-principle molecular-structure application, but it was still a highly specialized physics experiment, not a general-purpose enterprise workload. The article then mentions, several paragraphs later, that Google in 2024 demonstrated error correction below the surface code threshold (101 physical qubits, one logical qubit). That was the engineering milestone that moved the field’s trajectory. The two results appear in different sections with no connection drawn between them.
The McKinsey question
The article leans on McKinsey’s Quantum Technology Monitor for two data points: a chart showing $12.6 billion in global quantum startup investment in 2025 and a chart projecting quantum computing’s economic value by industry through 2035. Both charts carry the McKinsey name as their sole source.
I examined the Monitor’s finance chapter in detail in July. The headline finding: the arithmetic on McKinsey’s own slide cannot be reproduced from the assumptions displayed on it. The “affected share” percentages that appear as model inputs never participate in the computation. The impact estimates measure quantum computing and AI together with no allocation between them. The classical baseline is either frozen at today’s technology or not disclosed at all. And nothing in the finance chapter engages the peer-reviewed resource estimates, including two papers from Goldman Sachs’ own researchers, that quantify what these applications would demand from hardware. The 400 to 600 billion USD finance figure is an expert-interview percentage multiplied by a revenue baseline, with the conditional stripped from the headline.
The Economist reproduces McKinsey’s industry-value chart without noting any of these issues. The chart does carry a “Forecast range” label, so The Economist is not hiding that these are projections. The problem is missing methodological caveats: a reader who sees McKinsey forecast bars ranging to 800 billion USD for chemicals and 600 billion for financial services in The Economist has no way to know that the published inputs produce different figures than the ones displayed, or that quantum-specific value cannot be separated from AI value within those numbers.
I should note that the investment data chart carries a different concern than the value projections. Investment figures are at least grounded in disclosed transactions, though methodology still matters (what counts as a “quantum” investment, how double-counting between rounds is handled, what definition of “quantum startup” is applied). The value projections are a different product entirely: modeled estimates with no empirical anchor. The Economist presents both under the same “Source: McKinsey Technology” label without distinguishing them.
For CISOs and CTOs in my readership, the practical consequence is specific: if McKinsey’s quantum finance projections appear in a board presentation or vendor pitch deck citing The Economist as a secondary source, the number acquires a second layer of institutional authority without carrying forward the methodological qualifications needed to interpret it.
What the article left out
Two omissions weaken the article’s practical value for anyone making migration decisions.
First, the article covers harvest now, decrypt later (HNDL) but says nothing about Trust Now, Forge Later (TNFL), the signature-side analog. HNDL threatens confidentiality: data encrypted today can be stored and decrypted once a CRQC exists. TNFL threatens integrity and authenticity: once an adversary can derive an old private key, it can create new signatures that appear valid under the corresponding public key, and without trustworthy time evidence or archival validation, a verifier may be unable to distinguish a genuine historical signature from one created after the key was compromised. For certificate authorities, code-signing infrastructure, legal documents, and firmware signing, the TNFL threat has a different and in many cases more urgent migration profile than HNDL, because those systems must prove historical authenticity and need cryptographic-renewal strategies in place before the original algorithms become forgeable. An article that discusses quantum migration urgency and mentions only HNDL gives readers half the threat picture.
Second, the article mentions NIST’s 2035 recommendation for completing the switch to post-quantum cryptography but frames the urgency entirely around Q-Day timing (“there may be less time than they had thought”). The more important argument, and the one I have made at length, is that debating Q-Day predictions is now almost beside the point. Multiple institutions have already set their own quantum timetables. NSA’s CNSA 2.0 establishes staggered milestones for National Security Systems: CNSA 2.0 support in new acquisitions from 2027, software and firmware signing plus traditional networking equipment on exclusively post-quantum algorithms by 2030, and operating systems, web services, and legacy platforms by 2033. Switzerland’s FINMA issued supervisory guidance in July 2026 expecting PQC migration roadmaps by mid-2027. These instruments differ in legal force and geographic scope, but together they mean that many organizations must plan against institutional timetables, not a speculative CRQC date. Framing urgency around Q-Day predictions, as the article does, is like arguing about exactly when the fire will reach the building while the building code already requires sprinklers by next year.
What the article got right
Credit where it is earned. Brian LaMacchia’s section on the “long tail” of vulnerable systems (hospital equipment, cash machines, toll roads, sewage treatment) is the most vivid description of PQC migration difficulty I have seen in any publication, specialist or general. Aaronson’s observation that the two most impressive quantum speedups “are the same ones we knew about 30 years ago” is a corrective that the quantum industry needs to hear more often. The QAOA section correctly notes that classical approaches outperformed quantum in the 2025 Fraunhofer study on real-world data. And the chemistry section accurately conveys why quantum simulation has a genuine scientific basis that finance applications lack: quantum computers can simulate quantum-mechanical systems because they are quantum-mechanical systems, a match between tool and problem that does not exist for portfolio optimization or Monte Carlo pricing.
The wider lesson
The Economist employs talented science journalists, sources from working researchers, applies editorial scrutiny that most publications skip, and produces a piece that is useful for a non-specialist reader trying to understand what quantum computing is and why it matters. And even at that level, the article contains a misleading setup that risks reinforcing the most common quantum computing myth, an overbroad claim about what Shor’s algorithm threatens, a hardware juxtaposition that blurs IBM’s roadmap, resource reductions presented without the current-state baseline that gives them meaning, and uncritical reproduction of forecasts from a source whose methodology does not hold up to examination.
None of these are unique to The Economist. Most quantum articles I read in mainstream media make some subset of these errors. Most make more, and worse ones. The difference is that The Economist’s reputation means its version will be forwarded to boards, cited in briefings, and treated as authoritative in ways that a lesser publication’s errors would not be.
The recommendation for every reader: when you encounter a claim about quantum computing, whether in The Economist, in a vendor pitch, or in a McKinsey slide deck, ask three questions. What is the primary source? Does the claimed capability match the demonstrated capability? And what assumptions, incentives, or simplifications shape the way the claim is framed? The topic is hard, the incentives to oversimplify are strong, and even the best coverage leaves gaps that can cost organizations real money.