Allianz Quantum Risk Report Gets the Capital Thesis Right and the Cryptanalysis Wrong
Table of Contents
August 4, 2026 — On July 29, 2026, Allianz Research published “Cracking Finance: Why the Quantum Threat Could Arrive Before the Reward,” a 12-page assessment of quantum computing’s implications for the financial sector. The report is authored by Ludovic Subran, Allianz’s Chief Investment Officer and Chief Economist, alongside Olivier Salomon (Head of Quantum Hub for Allianz SE) and four colleagues from Allianz’s research and investment teams.
The report frames the quantum question for finance as a race between two clocks: one measuring the time until quantum computers become economically useful for financial applications, the other measuring the time until they can break the cryptography underpinning the financial system. Its central thesis is that the threat clock may strike first, because a cryptographically relevant quantum computer (CRQC) requires only the machine, while financial quantum advantage requires the machine and algorithms that outperform continuously improving classical methods.
Bottom line: this is one of the more technically serious quantum risk assessments published by a major financial institution’s research arm, and its capital-flow analysis is unusually effective. But the report’s cryptanalytic chart compresses incompatible resource estimates into a single qubit bar, its signature-risk analysis is not carried forward as a distinct operational workstream, and its regulatory language does not always distinguish proposed timelines from binding obligations.
Allianz’s Capital Analysis Sets the Standard
Allianz draws on PitchBook data to assemble an unusually effective synthesis of where quantum capital actually flows. Quantum-technology startups raised an estimated 12.6 billion USD in 2025, with more than 90% directed toward computing rather than sensing or communications. Within that total, venture investors deployed roughly 3.9 billion USD across around 125 rounds, more than triple the previous year.
Capital composition shifted faster than its size. Venture growth jumped from around 1% to more than 30% of deal value in a single year, the largest stage shift in the dataset. Mega-rounds of 25 million USD and above quadrupled to roughly 3.5 billion USD. The investors writing those checks are no longer specialist quantum funds but crossover institutions, strategic corporate balance sheets, and sovereign wealth funds.
The report’s most striking data point: of every venture dollar committed to quantum, around 97% has gone to the technology stack (qubits, control systems, the platform layer) and under 1% to financial-services applications. Capital markets are financing quantum capability much faster than finance-specific applications or institutional resilience. The same investor base that depends on the cryptographic foundations of the financial system is funding the hardware whose eventual success would threaten those foundations.
Allianz’s geographic data reinforces the concentration. Europe attracts only around 5% of global private quantum investment, against more than half for the United States. The five largest deals account for roughly 27% of all venture value, and the five largest investors for more than 70%. The headline figures (including the 12.6 billion USD total) also appear in McKinsey’s 2026 Quantum Technology Monitor, but several of Allianz’s derived cuts, particularly the 97/1% technology-stack-versus-applications split and the stage-shift analysis, are among the most useful I have seen.
What the Threat Assessment Gets Right
Allianz’s “two clocks” framing is accessible and intellectually honest, and builds to a conclusion most institutional reports avoid. For breaking cryptography, no known classical algorithm offers a viable alternative to quantum; the machine only needs to exist. For financial applications like Monte Carlo acceleration, quantum must outperform GPUs, variance-reduction techniques, and specialized classical chips that keep getting faster. Allianz correctly identifies this as the reason the threat machine can be smaller than the benefit machine.
Amplitude estimation for Monte Carlo acceleration is identified as the clearest finance-relevant application with a rigorous mathematical speedup, and the report correctly notes the quadratic (not exponential) nature of the gain. It is honest about the moving classical benchmark and the overhead costs of error correction, data loading, and state preparation. Refreshingly measured for a financial-sector report.
Harvest Now, Decrypt Later (HNDL) treatment is competent. The report frames harvest collection correctly as a present-tense operation, notes that the quantum threat is unusual because part of the exposure sits in the past, and cites Mosca’s inequality as the rational basis for early migration.
One observation stands out as especially useful: PQC migration competes for the same engineers, cloud spend, and board time as AI initiatives, and AI offers more visible and immediate returns. This budget competition explains more about institutional migration stalling than any technical analysis. Every CISO preparing a board deck on quantum readiness should borrow this framing.
The report also correctly references NIST’s August 2024 finalization of the first post-quantum standards, including ML-KEM (derived from CRYSTALS-Kyber) for key establishment and ML-DSA (derived from CRYSTALS-Dilithium) for digital signatures.
Where the Technical Analysis Goes Wrong
Three weaknesses in the threat assessment are consequential enough that anyone using this report for planning should know about them.
The ECC chart was not current on minimum logical width, and the correction is more complicated than a single number. The report uses 1,250–1,450 logical qubits as the resource requirement for breaking 256-bit elliptic-curve cryptography, citing Babbush et al. (2026). Babbush’s paper actually reports two trade-off points: no more than 1,200 logical qubits with 90 million Toffoli gates, or no more than 1,450 with 70 million. Allianz’s printed range sits 50–75 qubits above Babbush’s own best low-width point.
More importantly, the minimum published logical width fell further before the report appeared. Chevignard, Fouque, and Schrottenloher published an optimized ECDLP construction at EUROCRYPT 2026, and on July 15 (two weeks before the Allianz publication date) Luo et al. posted a construction requiring 835 logical qubits for secp256k1, the lowest width yet reported for a 256-bit curve. But the lower width comes at a cost: roughly 2^30.63 Toffoli gates, approximately 1.66 billion, which is 20–26 times the gate count of the Babbush variants. The Luo result extends the resource frontier with a new space-optimized point; it does not replace the Babbush estimates as a single new threshold.
Allianz’s deeper error is therefore not relying on a March paper instead of a July preprint. It is presenting cryptanalytic feasibility as a one-dimensional qubit requirement when width, gate count, depth, and error-correction overhead are coupled quantities that move together. Figure 1 compresses a multidimensional resource frontier into a single bar, and that compression misleads regardless of which paper’s numbers go on it.
Figure 1 compresses RSA and ECC too aggressively. The report’s prose correctly recognizes that factoring RSA and solving elliptic-curve discrete logarithms are distinct problems, but the chart gives them a single “Break ECC-256 and RSA 2048” bar at 1,200–1,600 logical qubits. This lumps two mathematically distinct problems into one visual range. The Gidney 2025 RSA-2048 estimate (~1,409 logical qubits) and the Babbush ECC estimates happen to overlap in range, but this is a coincidence of current optimization, not an equivalence.
The chart also combines different classical security levels. NIST conventionally maps RSA-2048 to approximately 112 bits of classical security, while P-256 is mapped to 128 bits. The matched comparison is P-256 against RSA-3072. At the Roetteler et al. 2017 baseline, this yielded roughly 2.6 times fewer logical qubits and about 148 times fewer non-Clifford gates for the ECC attack at equivalent classical security. The 2026 optimization wave has changed the specific ratios (they now vary by more than an order of magnitude in gate count depending on which ECC construction is selected), but the directional finding has held: current studies generally place P-256 below RSA-3072 in minimum logical width.
A single bar hides that distinction and the resource trade-offs behind it, along with an architectural implication the report never develops: the financial sector’s migration from RSA to ECC over the past decade, driven by legitimate classical security gains, concentrated the estate on the curve families where the minimum quantum attack width is lower at matched classical strength. This is not a measured sector-wide exposure shift, but it is a structural concern any institution should carry into its quantum risk assessment.
The report recognizes signature forgery but does not structure it as a distinct threat track. Allianz never uses the label Trust Now, Forge Later (TNFL), but its “Systemic implications” section describes the underlying failure mode directly: impersonated institutions, altered payment instructions, and malicious software distributed under apparently valid signatures. It also introduces its threat discussion by noting that RSA and ECC secure digital signatures, authentication, and ownership, not merely encrypted confidentiality.
The analytical gap lies in what happens next. The report does not carry confidentiality and integrity forward as distinct classes of exposure with different assets, scenarios, and migration priorities. HNDL centers on information whose confidentiality must survive until after a capable machine arrives. Signature compromise affects authorization, software provenance, device identity, payment instructions, certificates, and other trust decisions that remain active when the capability becomes operational. Those tracks share much of the same migration machinery (cryptographic inventories, vendor dependencies, certificate infrastructure, replacement algorithms), but their loss mechanisms are different. A data breach from retrospective decryption is bounded by the historical value of the exposed information. A signature-forgery capability enables active interference with live systems. Both need to appear in scenario design for any institution that is serious about quantum risk.
For Allianz’s own sector, this gap matters most. Insurers pricing quantum risk in cyber policies could omit high-severity integrity and authorization scenarios from underwriting and accumulation analysis if the threat model treats quantum risk as a confidentiality problem alone. My tabletop exercises with financial institutions consistently show that the signature-forgery scenario produces worse outcomes than the data-harvesting scenario, because it attacks the integrity of operating instructions rather than the confidentiality of records. The report describes those consequences. It does not model them as a separate risk class.
What Else the Report Misses
The CRQC capability assessment reduces to a qubit gap, which is the same compression problem as the ECC chart. The report correctly notes once that “gate counts, fidelities and circuit depth matter as much as qubits,” then drops the multi-dimensional assessment entirely. Figure 1 juxtaposes an experimental logical-qubit record (96, from QuEra’s January 2026 demonstration) with logical circuit-width estimates for cryptanalytic attacks as though both measured the same capability. They do not. A CRQC assessment requires not merely enough encoded qubits, but logical error rates low enough for the required depth, a universal gate set, sufficient magic-state throughput, real-time decoding, and sustained operation across the entire computation. None of these dimensions appear in the chart or the analysis.
Regulatory granularity needs both more detail and more precise labels. NIST finalized the first PQC standards in 2024, but its 2030/2035 dates remain proposed transition timelines in the initial public draft of NIST IR 8547, not yet final. The EU coordinated roadmap says member states should begin transitioning by end-2026 and that critical infrastructure should complete migration no later than end-2030; it derives from a Commission Recommendation, not directly binding legislation.
Supervisory action sends a stronger signal: ECB Banking Supervision told significant institutions in July 2026 that PQC adoption must start now, while FINMA recommends board-approved strategies and PQC migration roadmaps by mid-2027. The FS-ISAC/Europol joint report on prioritizing PQC migration in financial services, published January 2026, provides sector-specific operational guidance. None of these appear in the Allianz report. As I have argued extensively, these supervisory expectations and sector-specific deadlines, not Q-Day predictions, are what should drive migration planning.
The loss estimates receive more careful treatment than most secondary accounts, but could go further. The report cites the BIS’s probability-weighted figure (roughly 0.1% of GDP within five years, rising above 1% over 15–20 years, from BIS Papers No. 149, 2024) and the Hudson Institute’s tail scenario (2.0–3.3 trillion USD in GDP-at-risk from a quantum-enabled Fedwire attack). To its credit, Allianz explains Hudson’s two-stage model architecture, separately identifies the older single-day estimate as cruder, notes Hudson’s own “preliminary and imprecise” caveat, and warns against combining figures. That is more transparent than most secondary accounts. What the report does not do is test the sensitivity of the initiating assumptions, assign a credible probability to the tail scenario, or examine whether it is suitable for insurance capital allocation.
The “35% completed cryptographic inventory” statistic lacks a source. The report states this figure twice without citation. The probable source is Capgemini Research Institute’s 2025 survey, which found that 35% of respondents maintained a centralized inventory of cryptographic keys, algorithms, and certificates. The formulations are not identical (“maintained a centralized inventory” vs. “completed a comprehensive inventory”), and Allianz’s stronger wording should be sourced.
My Analysis
I want to be clear about something before assessing this report’s significance: Allianz Research has done something most financial institutions have not. They published a quantum risk assessment under the name of their Chief Investment Officer and Chief Economist, with specific numbers, specific claims, and a specific thesis that the threat clock may strike before the reward clock. Most financial institutions confine their quantum thinking to internal memos that say nothing actionable.
The “two clocks” framing is good enough to enter the conversation. I expect to see it cited in board presentations for the next year. The investment data (the 97/1% technology-stack-versus-applications split, the stage shift in venture capital, the geographic concentration, the winner-take-most power law) is an unusually effective synthesis of PitchBook and McKinsey data with several derived cuts I have not seen assembled this cleanly elsewhere. The observation that quantum has graduated from science-risk bets to institutional allocation while the defense side remains an internal IT budgeting decision competing with AI captures the preparedness problem better than most technical analyses.
But the technical weaknesses are not minor. Presenting cryptanalytic feasibility as a one-dimensional qubit count, when the published resource estimates involve coupled trade-offs between width, gate count, depth, and error-correction overhead, teaches the reader that the threat is simpler than it is. The chart’s single RSA/ECC bar at different classical security levels hides the finding that ECC can be the lower-width quantum target at matched strength. And recognizing signature-forgery consequences without structuring them as a distinct risk class means the report models one failure mechanism (retrospective data breach from HNDL) while describing but not pricing the other (active trust compromise from signature forgery).
That last point matters most for Allianz’s own sector. Insurers are going to be asked to price quantum risk in cyber policies. A threat model that does not separately identify confidentiality assets and authorization/trust assets, map them to different failure scenarios, and carry that distinction into underwriting analysis risks omitting the high-severity integrity scenarios that my tabletop exercises consistently show produce the worst outcomes.
One thing the report gets exactly right, and which aligns with a position I have held for years: Q-Day forecasts are becoming less decision-relevant for migration initiation. NIST’s proposed deprecation timeline, the EU’s coordinated roadmap, supervisory expectations from the ECB, FINMA, and others — these increasingly determine planning and procurement even where they are not yet statutory deadlines. A CRQC may arrive in 2032 or 2042, but the first compliance deadlines and counterparty expectations are indifferent to that uncertainty. Allianz’s closing line captures this: “Institutions do not need to know which clock will strike first to know that preparing for only one is the wrong strategy.” Correct.
Financial institutions using this report as their quantum risk baseline should supplement it with three things: a threat model that separately identifies the integrity/authorization exposure alongside HNDL, the full multidimensional CRQC capability picture that goes beyond qubit counts, and the current state of the ECC resource-estimation race (where multiple independent teams have been shrinking attack circuits throughout 2026 across several dimensions). The report provides a strong investment thesis and an effective strategic frame. The threat assessment needs the depth that comes from following the research week by week.