When AI breaks post-quantum crypto, agility is the real defence
Crypto-agility, not faith in any single algorithm, is what keeps post-quantum security standing when a scheme falls.

Post-quantum security will be decided by crypto-agility, the ability to replace a cryptographic scheme when it fails, rather than by faith in any single algorithm, and the withdrawal of the HAWK-256 signature scheme makes that point with unusual force. On 28 July 2026 researchers disclosed that an AI model had discovered a previously unknown attack on HAWK-256, a lattice-based post-quantum signature scheme, and its developers withdrew it from NIST's additional signature standardisation process the following day. For every organisation planning a post-quantum migration, the question is no longer which algorithm is safest. It is whether your systems can change their cryptographic foundations without a crisis.
What happened to HAWK-256 and why was it withdrawn?
HAWK-256 was withdrawn on 29 July 2026, one day after the disclosure that an AI model had found a previously unknown attack against it. HAWK-256 was a lattice-based signature scheme competing in NIST's additional signature standardisation process, the track NIST runs alongside its finalised post-quantum standards to broaden its approved portfolio. The disclosure, reported by The Hacker News on 28 July 2026, is notable for two reasons. The attack was previously unknown, so the scheme had passed the human scrutiny applied to it, and the flaw was surfaced by an AI model, a sign of how quickly cryptanalysis now moves. A candidate that looked sound one day was out of the process the next.
Does this mean post-quantum cryptography is broken?
No. The withdrawal removes one candidate from a supplementary standardisation track, and it does not touch the post-quantum standards NIST finalised in August 2024, including ML-DSA, a lattice-based signature standard, and SLH-DSA, a hash-based signature standard built on very different mathematical ground. That diversity of foundations is deliberate, because if one family of assumptions weakens, the other still stands. The honest reading is narrower and more useful. No single cryptographic bet is safe forever, experimental candidates carry more risk than finalised standards, and any system that hard-wires one scheme into its core has quietly accepted a countdown it cannot see. The prudent response is not panic. It is to choose conservatively grounded, finalised algorithms for anything long-lived, and to design every signing system so schemes can be rotated.
What does crypto-agility mean for an audit record?
Crypto-agility means an audit record must be able to retire a signature scheme and adopt a new one without losing the ability to verify its own history. This matters because audit evidence has the longest life of almost anything an organisation signs. A contract may matter for years, but the record proving what an AI system did, who authorised it and when may need to survive regulatory scrutiny decades from now, well into the era when quantum computers and AI-assisted cryptanalysis are mature. That is why we sign every action in our Open Audit Record with post-quantum cryptography drawn from NIST's finalised, differently grounded algorithms rather than experimental candidates, and why the record is designed to be crypto-agile, so schemes can be rotated as the landscape shifts. Each entry is tamper-evident and verifiable offline, so the proof does not depend on any external service or vendor still cooperating on the day a supervisor asks.
“A cryptographic bet you cannot change is not a foundation, it is a countdown. We assume every scheme we rely on will one day need replacing, and we design the audit record so that day is an upgrade, not a crisis.”
How does AI-driven cryptanalysis change the threat model?
An AI model finding a previously unknown attack on a vetted cryptographic candidate confirms that AI is now a working tool for probing defences, not a hypothetical one. The same class of capability that drafts documents and reviews code can search for structural weaknesses in the systems protecting sensitive data, and it does not get tired. For defenders, this strengthens two old disciplines. The first is minimising exposure. A system that is air-gapped, running entirely on an organisation's own hardware with a hardware-held root of trust, presents no remote surface for an automated attacker to probe at leisure. The second is refusing to trust any single point of judgement. Inside our operating system, sensitive actions are not executed on the say-so of one model. A cooperative multi-model consensus substrate requires specialist models to agree before any sensitive action runs, and voice-biometric gating puts a verified human in front of the most consequential steps. When offence accelerates, defence in depth becomes the design brief.
What should regulated organisations do now?
Treat the HAWK-256 withdrawal as a planning input, not an alarm. The organisations that will handle the next withdrawal calmly are the ones doing five things today:
- Inventory every place a signature or key-exchange scheme is embedded in your estate, including audit logs, backups and archived evidence.
- Prefer NIST's finalised post-quantum standards over experimental candidates for anything that must remain verifiable for years.
- Demand crypto-agility from every supplier, meaning a documented path to rotate algorithms without invalidating historical records.
- Protect the evidence layer now, because records harvested today can be forged or repudiated later if their signatures fall.
- Reduce the remote attack surface of your most sensitive systems, air-gapping them where the data justifies it.
We built our Sovereign Intelligence Operating System around exactly these assumptions. It runs on the customer's own hardware, on-premise and fully offline where required, and it launches with ten production-ready studios of the 87 on the operating system, with 77 more in development. The architecture, including the audit record and its signing chain, is described across 104 filed UK patent applications spanning 2,340 claims held by Mickai LTD, filed rather than granted, though the moat matters far less than the practice it protects. Assume every scheme will one day move, and build so that it can.
Frequently asked questions
Was HAWK-256 one of NIST's finalised post-quantum standards?
No. HAWK-256 was a candidate in NIST's additional signature standardisation process, a supplementary track intended to broaden the portfolio of approved signatures. The standards NIST finalised in August 2024, including ML-DSA and SLH-DSA, were not the subject of the disclosed attack.
Does the HAWK-256 attack affect ML-DSA or SLH-DSA?
The disclosed attack was specific to HAWK-256, and no equivalent break of ML-DSA or SLH-DSA was reported. The two finalised standards also rest on different mathematical foundations, lattice-based and hash-based respectively, which is precisely the diversity that limits how far any single result can spread.
What is crypto-agility?
Crypto-agility is the designed-in ability to replace a cryptographic algorithm without rebuilding the system around it or losing the ability to verify historical records. It turns the failure of a scheme from an existential event into a managed migration.
Why do audit records need post-quantum signatures now?
Because records signed today must still be trustworthy decades from now, and adversaries can harvest them today intending to forge or repudiate them once stronger attacks mature. We sign every entry in the Open Audit Record with post-quantum cryptography from the outset, so the evidence layer never lags the threat.
How does an air gap help against AI-driven attacks?
An air gap removes the remote surface an automated attacker needs. AI-assisted probing works at machine speed against anything reachable over a network, and a system that runs fully offline on the organisation's own hardware is simply not reachable, so the attacker's speed advantage has nothing to act on.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System, a SIOS, that runs on the customer's own hardware, on-premise and air-gapped, so data and models never leave the organisation. Every action is signed into the Open Audit Record, a post-quantum secure, tamper-evident log that can be verified offline. The operating system carries 87 studios, with ten production-ready at launch and 77 in development, and the architecture is protected by 104 filed UK patent applications across 2,340 claims, filed rather than granted.