cosmic college · quantum 101
quantum 101 · computing with waves
Quantum computing, explained for curious people who never took a physics class. First the story of a strange idea that took forty years to become hardware. Then qubits, measurement, interference, and entanglement, with numbers you can check by hand. Then the hard part, noise, and what these machines will and will not be good for.
a computer made of waves
Somewhere in California, in a refrigerator colder than deep space, a chip about the size of a postage stamp holds about a hundred tiny circuits. Each one can be a 0, a 1, or a delicate blend of both. Nudge them with precisely timed microwave pulses and they begin to behave less like switches and more like ripples on a pond, spreading, overlapping, cancelling, and reinforcing.
That is the quiet wonder of a quantum computer. It does not try every answer at once, which is the most common myth about it. It does something subtler and stranger: it sets up waves of possibility so that wrong answers cancel out and right answers ring loud. This lesson walks through how that works, why it is so hard to build, and where it could matter, from medicine and materials to the encryption that protects nearly everything online.
No physics degree needed. If you can square a decimal and add two numbers, you can follow every step below.
the story · from a thought experiment to a chip
In May 1981, at a small conference at MIT on the physics of computation, Richard Feynman asked a deceptively simple question. Nature is quantum mechanical, so why are we trying to simulate it on machines that are not? Every time you add a particle to a quantum system, the bookkeeping needed to describe it on an ordinary computer roughly doubles. Feynman suggested turning the problem around: build a computer out of quantum parts and let it imitate nature directly. His talk was published the following year1.
For more than a decade the idea stayed mostly theoretical. Then in 1994 Peter Shor, a mathematician at Bell Labs, showed that a quantum computer could find the prime factors of huge numbers dramatically faster than any known classical method2. That mattered far beyond math departments, since the difficulty of factoring is what keeps a widely used encryption system called RSA secure. Almost overnight, quantum computing went from a curiosity to a question of national interest.
Skeptics raised a fair objection. Quantum states are absurdly fragile, and any real machine would drown in errors. In 1995 Shor answered that too, showing that quantum information can be protected by spreading it across many qubits, an idea called quantum error correction. Physicists began building. In 2001 a team at IBM used a seven-qubit machine made of molecules in a liquid to run Shor’s algorithm on the number 15 and get 3 × 5. It was a tiny result and a huge proof of principle.
The next big moment came in October 2019, when Google reported that its 53-qubit Sycamore chip had finished a carefully chosen sampling task in about 200 seconds, a job its team estimated would take a leading supercomputer around 10,000 years3. IBM quickly argued that a smarter classical approach could do it in about two and a half days4. The task itself had no practical use. What it marked was a line: a quantum machine had done something very hard to copy.
The years since have been about quality more than size. In December 2023 a Harvard-led team with QuEra, MIT, and NIST/University of Maryland ran algorithms on up to 48 error-corrected logical qubits built from neutral atoms5. In August 2024 NIST finalized the first post-quantum encryption standards, built to resist a future quantum attack6. In December 2024 Google’s Willow chip showed that making an error-corrected qubit bigger made it more reliable, a milestone the field had chased for nearly thirty years7. In October 2025 the Nobel Prize in Physics went to John Clarke, Michel Devoret, and John Martinis for 1980s experiments showing that a circuit you could hold in your hand could behave quantum mechanically, the physics underneath today’s superconducting qubits8. And in July 2026 IBM and the University of Chicago reported running 70 error-corrected logical qubits on a sampling task built to be both hard for classical computers and checkable9, a company-reported result the field is still digesting.
timeline · from a thought experiment to a chip
- 1981simulate nature with natureFeynman proposes quantum computers at MIT; published 1982
- 1984a circuit goes quantumClarke, Devoret, and Martinis run their prize-winning experiments (1984 to 1985)
- 1994shor’s algorithma fast way to factor large numbers, on paper
- 1995error correctionShor shows fragile quantum information can be protected
- 200115 = 3 × 5a seven-qubit molecule machine at IBM runs Shor’s algorithm
- 2019sycamoreGoogle’s 53 qubits; a supremacy claim on a contrived task, disputed by IBM
- 202348 logical qubitsHarvard, QuEra, MIT, NIST/UMD, using neutral atoms
- 2024new locks, and willowAugust: NIST post-quantum standards. December: error correction below threshold
- 2025a nobel for circuitsClarke, Devoret, and Martinis share the physics prize
- 2026logical qubits at workIBM and UChicago report 70 logical qubits on a hard, checkable task (company-reported)
Dates are the commonly cited years for each milestone. Hundreds of labs stand behind these lines; these are a few of the moments most often remembered.
The theory came first and fast: the big ideas were in place by 1995. The engineering is the long road. Most of the progress since 2019 is about making qubits better, not just more numerous.
bits and qubits
An ordinary computer stores everything as bits, switches that are either 0 or 1. Your laptop has billions of them, and at any instant each one is definitely one or the other.
A qubit is the quantum version. It can be 0, it can be 1, and it can also be in a superposition, a blend of both described by two numbers called amplitudes. The simplest way to picture it: an arrow on a circle. Point the arrow along one axis and the qubit is 0. Point it along the other and the qubit is 1. Anywhere in between is a blend. The amplitudes are just how far the arrow reaches along each axis.
a bit and a qubit · switch versus arrow
Every point on the dotted circle is a valid qubit state. The arrow always has length 1, which is why the squared amplitudes always add to 100%. Real qubits also carry a phase, so physicists draw them on a sphere; the circle captures the key idea.
Here is where it gets interesting. One qubit needs 2 amplitudes. Two qubits need 4, one for each of 00, 01, 10, and 11. Every qubit you add doubles the count.
worked example · how fast the numbers grow
amplitudes = 2number of qubits
- 3 qubits: 2 × 2 × 2 = 8 amplitudes.
- 30 qubits: about 1.07 billion amplitudes. Storing each as two 8-byte numbers takes about 17 GB, a big laptop’s worth of memory.
- 50 qubits: about 1.1 quadrillion amplitudes, or about 18 petabytes. That is supercomputer territory.
- 300 qubits: about 2 × 1090 amplitudes, more than the commonly cited estimate of 1080 atoms in the observable universe.
This doubling is exactly what Feynman noticed. It is why simulating quantum systems on ordinary computers gets hard so quickly, and why a machine that natively lives in that enormous space is interesting.
One honest caveat keeps this from becoming hype. A machine with 300 qubits does not give you 2300 answers to read. When you look, you get just 300 ordinary bits. The art of quantum computing is arranging things so the 300 bits you read are the ones you wanted.
A qubit is an arrow, not a switch. Each added qubit doubles the space the machine works in. You still only get one ordinary answer out per run.
measurement · the moment of truth
You cannot peek at a qubit’s amplitudes directly. When you measure it, you get a plain 0 or 1, and the blend is gone. Which one you get is random, with odds set by the amplitudes: square each amplitude to get its chance. This is called the Born rule, after the physicist Max Born, and it is one of the strangest and best-tested ideas in science.
worked example · reading a qubit
chance of a result = (its amplitude)²
Take the qubit from the diagram, with amplitude 0.6 for 0 and 0.8 for 1. Measure it and you read 0 with chance 0.6² = 36%, or 1 with chance 0.8² = 64%.
Prepare it the same way 1,000 times and measure each time, and you will see roughly 360 zeros and 640 ones. That is how experimenters learn what a quantum computer actually did: by running it many times and counting.
After a measurement reads 1, the qubit simply is 1. Measure again right away and you get 1 every time. The blend does not come back.
Measurement is both the payoff and the danger. It is how you get an answer out. It is also what the outside world does to a qubit by accident whenever a stray bit of heat, light, or vibration bumps into it. Keep that in mind; it returns in the section on noise.
Square the amplitude to get the odds. Measuring gives one ordinary bit per qubit and erases the blend, so a good algorithm saves measurement for the very end.
interference · the real trick
Drop two pebbles in a pond and the ripples cross. Where two crests meet, the water rises higher. Where a crest meets a trough, the water goes flat. That is interference, and it is the true source of quantum computing’s power.
Amplitudes behave like those ripples, with one twist that ordinary probabilities never have: they can be negative. Chances are always positive, so they can only pile up. Amplitudes can cancel. A quantum algorithm is a choreography that steers the amplitudes of wrong answers to cancel each other while the amplitudes of right answers add up.
The simplest demonstration uses one qubit and one operation, the Hadamard gate, written H. Applied to a 0, H makes an even blend: amplitude about 0.71 for 0 and about 0.71 for 1 (0.71 is √½, so each squares to 50%). Applied to a 1, it makes almost the same blend, with one difference: the amplitude for 1 comes out negative. Now apply H twice in a row and watch the paths.
interference · two paths cancel, two paths add
Two routes lead to each final answer. Both routes into 0 are positive, so they reinforce. The routes into 1 have opposite signs, so they wipe each other out. If amplitudes were ordinary chances, you would get a 50/50 coin flip. Because they can cancel, you get 0 every single time.
worked example · follow the paths by hand
amplitude of a path = product of its steps
amplitude of an answer = sum of its paths
Each H step multiplies by 0.71, or by −0.71 on the 1-to-1 step. Into 0: (0.71 × 0.71) + (0.71 × 0.71) = 0.5 + 0.5 = 1. Into 1: (0.71 × 0.71) + (0.71 × −0.71) = 0.5 − 0.5 = 0.
Square them: 0 comes up 100% of the time, 1 comes up never. The blend was real, and it unblended itself through interference.
Real algorithms do the same thing on a grand scale. Shor’s algorithm sets up waves across an enormous number of possibilities so that they reinforce only at values that reveal a hidden repeating pattern, and that pattern gives away the factors. This is also why quantum computers are not universally faster. Interference only helps on problems with the right kind of hidden structure, and finding that structure takes real cleverness. Only a modest number of genuinely powerful quantum algorithms are known.
Superposition gives a quantum computer room to work. Interference is what does the work: amplitudes can be negative, so wrong answers can cancel. No interference trick, no speedup.
gates and circuits
Ordinary computers are built from logic gates such as AND, OR, and NOT. Quantum computers have gates too, operations that turn the qubit arrows in precise ways. A program is a circuit: a sequence of gates, read left to right, with one horizontal line per qubit, ending in measurement.
| gate | what it does | everyday picture |
|---|---|---|
| X | flips 0 to 1 and 1 to 0 | the quantum NOT |
| H | turns 0 or 1 into an even blend, and back again | open the possibilities, then let them interfere |
| Z | flips the sign of the 1 amplitude | invisible alone, decisive in interference |
| CNOT | flips a target qubit only if a control qubit is 1 | the gate that links qubits together |
| measure | reads 0 or 1 and ends the blend | collect the answer |
A small set of gates like these, repeated and combined, is enough to build any quantum computation, just as a few logic gates are enough to build any classical one. The circuit in the next section uses only two of them, and it produces one of the most famous effects in physics.
Gates turn arrows. Circuits are recipes of gates. Two-qubit gates such as CNOT are where the power lives, and they are also where most errors happen.
entanglement · linked outcomes
Put an H gate on one qubit, then a CNOT from that qubit to a second one, and something remarkable happens. The pair ends up in a shared state where neither qubit has its own answer, and the two answers always match. Measure them and you get 00 half the time and 11 half the time, never 01 or 10. This is entanglement, and the pair is called a Bell pair.
a circuit · making an entangled pair
Read left to right. H puts qubit a in an even blend. CNOT flips b only in the part of the blend where a is 1, so the pair becomes “both 0” and “both 1” at once. Neither qubit has an answer of its own until one is measured.
Albert Einstein was famously uneasy with this kind of linkage and called related effects “spooky action at a distance.” Experiments since the 1970s have confirmed it again and again, with entangled particles separated by kilometers and, as you will see later, by a satellite. One thing entanglement does not allow is faster-than-light messaging. Each side, on its own, sees a perfectly random string of 0s and 1s. The matching only shows up when the two sides compare notes over an ordinary channel.
Inside a computer, entanglement is what lets qubits act as one system instead of a row of independent coins. Without it, a quantum computer could be simulated easily on an ordinary one. Entanglement makes the 2n space truly shared, and interference makes it useful.
Entanglement links outcomes, not messages. It is the glue that makes many qubits behave as one machine, and a resource for secure communication.
noise and decoherence · why this is hard
Everything above assumes the qubits are left alone. In reality, a qubit is constantly being nudged by its surroundings: a little heat, a stray photon, a vibration, a fluctuating magnetic field. Each nudge is like a tiny accidental measurement. The blend leaks away and the delicate amplitudes drift. Physicists call this decoherence, and the time a qubit can hold its state is its coherence time.
This is why superconducting quantum computers live inside dilution refrigerators that reach about a hundredth of a degree above absolute zero, more than a hundred times colder than deep space, which sits around 2.7 degrees. Even there, the best superconducting qubits hold their state for something like a hundred microseconds10. Gates are imperfect too. The best two-qubit gates today are right around 99.5% to 99.9% accurate (a rough range across leading platforms). That sounds excellent until you multiply.
noise compounds · chance of 1,000 clean gates
Each extra 9 of accuracy changes the picture completely. Even 99.99% is nowhere near enough for the billions of operations a code-breaking or chemistry algorithm needs. That gap is why error correction exists.
worked example · why 99.9% is not enough
chance of no errors = (accuracy per gate)number of gates
At 99.9% per gate: 0.9991,000 ≈ 0.37. A thousand-gate circuit runs cleanly about one time in three.
At a million gates: 0.9991,000,000 is so small it might as well be zero. Shor’s algorithm on real encryption keys needs billions of operations. No amount of polishing a single qubit gets you there, so the field needed a different idea.
One more catch makes quantum errors harder than ordinary ones. In a normal computer you can protect data by copying it three times and taking a vote. A basic law of quantum physics, the no-cloning theorem, forbids copying an unknown quantum state. And you cannot simply look to check for errors, since looking is measuring, and measuring destroys the blend.
Errors compound with every gate. Today’s physical qubits are good enough for thousands of operations, and useful algorithms need billions. The gap is closed by error correction, not by better qubits alone.
error correction · logical from physical
The way around both problems is clever and a little magical. Instead of storing one qubit of information in one physical qubit, you spread it across many. The group as a whole acts as one sturdier qubit, called a logical qubit. The individual hardware qubits are physical qubits.
Extra helper qubits then ask the group careful yes-or-no questions, such as whether neighboring qubits agree in a certain way. The answers reveal whether an error happened and where, without ever revealing the stored information itself, so the blend survives. A fast classical computer reads those answers, called the syndrome, and works out the fix. On Google’s Willow chip, this whole cycle repeats about every microsecond7.
the surface code
The most studied scheme is the surface code. Picture a checkerboard: data qubits sit on the grid points and measurement qubits sit in the squares between them, each checking its neighbors. A logical qubit is a whole patch of the board. The size of the patch is its distance, written d. A bigger patch can catch more errors before they add up to a mistake in the stored information.
surface code · one logical qubit, three sizes
In Google’s Willow experiment, each step from distance 3 to 5 to 7 cut the logical error rate by a factor of about 2.14. The distance-7 patch used 101 physical qubits, the 97 shown here plus 4 helpers, and kept its information more than twice as long as the best single qubit on the chip7.
There is a catch, and it is called the threshold. Bigger patches only help if each physical qubit is already good enough. Below the threshold, adding qubits suppresses errors exponentially. Above it, adding qubits just adds more ways to fail. For decades nobody could show a real chip clearly on the good side of that line as the patch grew. Willow’s 2024 result was the first convincing demonstration that it works, which is why it mattered so much more than a raw qubit count.
worked example · the overhead (estimate)
physical qubits per logical qubit ≈ 2 × d²
Starting point: Willow’s distance-7 logical qubit had an error rate of about 0.14% per correction cycle.
Assumption: each step up in distance (d + 2) keeps halving the error, as it did in the experiment. To reach about one error in a million cycles you need roughly 10 halvings, since 210 ≈ 1,000. That means d ≈ 7 + 2 × 10 = 27.
2 × 27² ≈ 1,460 physical qubits for one logical qubit. A machine with 100 logical qubits would need on the order of 150,000 physical qubits, and 1,000 logical qubits about 1.5 million.
- estimate range: published estimates commonly land around a few hundred to a few thousand physical qubits per logical qubit, depending on hardware quality and the target error rate.
- better qubits: lower physical error rates shrink the patch a lot, since each step then cuts errors by more than half.
- better codes: newer codes promise less overhead. IBM’s 2024 design stores 12 logical qubits in 288 physical qubits, where a comparable surface code would need nearly 3,00011. The trade is longer-range wiring between qubits.
A useful quantum computer is counted in logical qubits, and each logical qubit costs hundreds to thousands of physical ones (estimate). Watch error rates and logical-qubit demos more than headline physical-qubit counts.
the ways to build a qubit
Anything that can hold a clean two-level quantum state can, in principle, be a qubit. In practice a handful of families lead the race, and each makes a different trade between speed, accuracy, and how hard it is to scale. Nobody knows yet which will win, and it is quite possible that more than one will, for different jobs.
superconducting
- qubit
- tiny circuits on a chip, chilled to near absolute zero
- strength
- very fast gates; built with chip-making tools
- challenge
- short coherence; wiring and cooling thousands of qubits
- who
- Google, IBM, Rigetti, and others
trapped ion
- qubit
- single charged atoms held in place by electric fields
- strength
- top-tier accuracy and long memory; any ion in a trap can talk to any other
- challenge
- slower gates; linking many traps together
- who
- Quantinuum, IonQ, and others
neutral atom
- qubit
- uncharged atoms held by focused laser beams called tweezers
- strength
- thousands of identical atoms that can be rearranged mid-calculation
- challenge
- slower cycles; atoms occasionally escape
- who
- QuEra, Pasqal, Atom Computing, Infleqtion
photonic
- qubit
- single particles of light on chips and in optical fiber
- strength
- light barely notices heat; a natural fit for networks
- challenge
- photons get lost; many operations only succeed some of the time
- who
- PsiQuantum, Xanadu, Quandela
spin in silicon
- qubit
- the spin of single electrons trapped in silicon
- strength
- extremely small; could ride decades of chip-factory know-how
- challenge
- early stage; making millions of them behave identically
- who
- Intel, Diraq, Quantum Motion
topological
- qubit
- exotic states spread out so local noise struggles to disturb them
- strength
- error protection built into the physics, in theory
- challenge
- not yet convincingly demonstrated
- who
- Microsoft; its 2025 chip announcement is still debated12
The scale of these systems already varies a lot. In 2025 a Caltech team held more than 6,100 atoms in a single tweezer array, each a candidate qubit, with coherence lasting over 12 seconds13. Superconducting chips hold far fewer qubits, about a hundred on Willow, and run gates much faster. Trapped ions have posted some of the highest gate accuracies of any platform. Each figure on its own tells you little. What matters is how they combine into logical qubits that run long, reliable calculations.
Fast and noisy, slow and clean, or many and loosely linked. Every platform is strong on two of speed, accuracy, and scale today, and the race is to get all three.
what it’s actually good for
A quantum computer is not a faster laptop. It is a specialized instrument, a bit like a telescope, extraordinary for some jobs and pointless for most. The useful jobs fall into a short list.
chemistry and materials · the original idea
Molecules are quantum systems, so Feynman’s logic applies directly. Designing a better battery material, a catalyst for fertilizer, or a drug that binds just right all depend on how electrons share space, and the hardest cases are exactly the kind of 2n problem that overwhelms ordinary computers. A famous target is FeMoco, the iron-and-molybdenum core of the enzyme that lets certain bacteria pull nitrogen from the air at room temperature, something industry does with high heat and pressure. A 2021 estimate put a high-quality simulation of it at about four million physical qubits running for under four days14 (estimate, using the same 0.1% error assumption as below). This is widely seen as the most likely first area of real scientific value.
shor’s algorithm and the great migration
Much of today’s internet security, including RSA and elliptic-curve cryptography, rests on math problems that are hard for ordinary computers and easy for a large, error-corrected quantum computer running Shor’s algorithm. Nobody can do it yet. The estimates of what it would take keep falling.
worked example · how big a code-breaker? (estimates)
target: RSA-2048, a common key size for securing websites and signatures
- 2019 estimate: about 20 million noisy physical qubits, running for about 8 hours.
- 2025 estimate: fewer than 1 million noisy physical qubits, running for under a week15.
- assumptions in both: 0.1% error per gate, a correction cycle every microsecond, qubits wired in a square grid.
- today: the largest machines have roughly a hundred to a few thousand physical qubits (rough, depending on how you count), with error rates near that 0.1% assumption at best.
1,000,000 ÷ ~1,000 ≈ a gap of several hundred times in size, plus better speed and control at the same time. Large, and shrinking from both ends.
So why act now? Because of a strategy called harvest now, decrypt later. An adversary can record encrypted traffic today and simply wait until a capable quantum computer exists. Anything that must stay secret for ten or twenty years, such as medical records, state secrets, and trade secrets, is already exposed in that sense. And swapping cryptography across every bank, phone, satellite, and power grid takes many years.
The response is post-quantum cryptography: new math that runs on ordinary computers and resists quantum attack. NIST finalized the first three standards in August 2024, ML-KEM for setting up shared keys and ML-DSA and SLH-DSA for digital signatures6. NIST’s draft transition plan proposes deprecating today’s vulnerable algorithms after 2030 and disallowing them after 203516. Some of the most widely used messaging apps already use post-quantum key exchange, including Signal17 and Apple’s iMessage18.
optimization · hype versus reality
You will hear that quantum computers will optimize delivery routes, financial portfolios, and supply chains. Be careful here. For most optimization and search problems, the known quantum speedups are modest, often a square-root improvement. That sounds big. Searching a million possibilities takes an ordinary computer up to a million checks and a quantum one about a thousand steps. Each quantum step is far slower, and it carries heavy error-correction overhead. Careful analyses suggest square-root speedups alone will struggle to beat classical machines for a long time19, and classical optimization software keeps getting better. Treat claims of near-term quantum advantage in optimization with polite skepticism until they come with a head-to-head comparison against the best classical method.
what it isn’t for
- everyday computing: email, video, spreadsheets, and games will stay classical. There is no speedup to be had.
- big data: loading huge datasets into qubits is slow, which erases most of the advantage for data-heavy tasks.
- training large AI models: that is massive, repetitive arithmetic, exactly what GPUs are built for. Quantum is not expected to replace them (estimate, based on the algorithms known today).
- trying every answer at once: it never did that. It uses interference on problems with the right hidden structure.
Big wins: simulating nature and breaking certain codes. Modest wins: search and optimization. No wins: most everyday computing. The encryption fix is ordinary software, and the migration has already begun.
what’s next · a directional roadmap
Forecasting this field is humbling, so everything in this section is an estimate or a stated target. The milestones in the story above are public and checkable. The road ahead is a mix of company targets, standards deadlines, and educated guesses.
roadmap · what may come next (estimates)
- nowlogical qubits, by the dozenserror-corrected demos keep growing; advantage claims on scientific tasks, each debated
- 2029first fault-tolerant machinescompany target: IBM aims for 200 logical qubits running 100 million gates20; others aim for similar windows
- 2030old locks deprecatedNIST draft plan for RSA and elliptic-curve cryptography
- early 2030sfirst useful scienceestimate: chemistry and materials problems beyond classical reach
- 2035old locks disallowedNIST draft plan; the migration should be done by here
- 2030sa code-breaking machine?estimate: plausible, timing genuinely uncertain; plan as if it will come
Grey dashed dots are targets or estimates, not facts. Company roadmaps have slipped before and may again. The NIST dates come from a draft and could change.
The signals worth watching are not raw qubit counts. Watch logical error rates, how many logical qubits run at once, how many logical operations they survive, and whether a quantum result comes with a solid comparison against the best classical method.
The physics is proven, the engineering is underway, and the timeline is uncertain. Migrate encryption on a schedule that does not depend on guessing the date.
space, ai, and infrastructure
Quantum technology reaches well beyond computers, and some of the most practical pieces point straight at the frontier this site follows.
quantum sensing and navigation
The same fragility that makes qubits hard to compute with makes them superb sensors. A cloud of atoms chilled to near absolute zero responds to tiny changes in gravity, rotation, and magnetic fields. You already rely on quantum physics for navigation: every GPS satellite carries atomic clocks, and your phone finds itself by timing their signals. NASA’s Cold Atom Lab, launched to the International Space Station in 2018, has run the first atom interferometer in orbit, an early step toward quantum sensors that could map gravity from space21. On Earth, with GPS jamming and spoofing on the rise, companies are flight-testing quantum magnetometers that navigate by matching the planet’s magnetic field, with no satellite signal at all22 (company-reported results).
quantum keys from orbit
Quantum key distribution, or QKD, uses single photons to share a secret key. Any eavesdropper who looks at the photons disturbs them, and the disturbance shows up as errors, so both ends know the line was tapped. Fiber absorbs photons over long distances, so the farthest links go through space. In 2017 China’s Micius satellite delivered quantum keys to ground stations up to about 1,200 km away23, and then relayed keys for a video call between China and Austria, about 7,600 km apart24.
quantum key distribution · by satellite
Simplified picture. The satellite sends single photons to each station, and the stations turn them into a shared key. In the Micius intercontinental demonstration the satellite acted as a trusted relay, so the satellite itself had to be secure. Key rates are still low, and a satellite can only link stations it can see.
QKD is promising and also limited. It needs special hardware at every endpoint, works best at night and in clear weather, and today’s long satellite links rely on trusted relays. U.S. security agencies currently favor post-quantum cryptography over QKD for most uses25. The likely future mixes both: post-quantum math almost everywhere, and quantum links where the stakes justify the cost.
compute, energy, and ai
Quantum computers will not live alone. They are being built as accelerators that sit beside classical supercomputers and AI clusters, the way GPUs sit beside CPUs. Error correction itself depends on fast classical computing: a decoder must read the syndrome and decide on a fix every microsecond or so. AI is already helping. In 2024 Google DeepMind’s AlphaQubit, a neural network, decoded errors more accurately than earlier methods on real hardware data26, and the Willow experiment used a neural network decoder too.
Energy looks different than it does in AI. A superconducting quantum computer’s biggest power draw is usually its refrigeration, on the order of tens of kilowatts per system (estimate), while a large AI datacenter can draw hundreds of megawatts (estimate). For the problems quantum computers suit, the energy per answer could be tiny compared with a brute-force classical attempt. The flow could run the other way too: quantum simulations could one day generate high-quality chemistry data to train AI models (estimate, speculative).
And then there is infrastructure that lasts. A satellite launched this year may still be flying in the late 2030s, a power-grid controller may run for decades, and both will likely outlive today’s encryption. Building them so post-quantum algorithms can be swapped in later, sometimes called crypto-agility, is one of the most practical quantum decisions any operator can make right now.
Quantum sensing is the nearest-term win, quantum keys from orbit are real and niche, and quantum computers will plug into classical and AI infrastructure instead of replacing it. Long-lived hardware should be ready for new cryptography today.
check yourself
Eight quick questions. Think of your answer, then tap to reveal.
1How many amplitudes describe 3 qubits? And 10?
23 = 8, and 210 = 1,024. Every added qubit doubles the count.
2A qubit has amplitude 0.6 for 0 and 0.8 for 1. What is the chance you read 1?
0.8² = 0.64, so 64%. Square the amplitude to get the odds.
3Where does a quantum speedup really come from?
Interference. Amplitudes can be negative, so an algorithm can make wrong answers cancel and right answers reinforce. Superposition without interference gives you nothing useful.
4Can entanglement send a message faster than light?
No. Each side sees random results on its own. The matching only appears when both sides compare notes over an ordinary channel.
5Each gate is 99.9% accurate. What is the chance 1,000 gates all run cleanly?
0.9991,000 ≈ 0.37, so about 37%. Errors compound, which is why error correction is essential.
6What is the difference between a physical and a logical qubit?
A physical qubit is one piece of hardware. A logical qubit is information spread across many physical qubits and protected by constant error checks. Useful machines are measured in logical qubits.
7No machine can break RSA today. Why migrate to post-quantum cryptography now?
Harvest now, decrypt later. Traffic recorded today could be decrypted once a capable machine exists, and migrating every system takes years.
8Name something quantum computers are not expected to be good at.
Everyday computing such as email or video, crunching huge datasets, or training large AI models. They are specialized instruments for problems with the right hidden structure.
glossary
| term | plain meaning |
|---|---|
| amplitude | a number attached to each possible outcome; square it to get that outcome’s chance. It can be negative. |
| bit | an ordinary switch that is either 0 or 1. |
| qubit | a quantum bit that can be 0, 1, or a blend of both. |
| superposition | a blend of possible states, described by amplitudes. |
| measurement | reading a qubit; gives 0 or 1 at random, with odds set by the amplitudes, and ends the blend. |
| interference | amplitudes adding up or cancelling out, like overlapping ripples. The real engine of quantum speedups. |
| entanglement | a shared state where qubits’ outcomes are linked more tightly than any classical arrangement allows. |
| gate | an operation that turns qubit arrows in a precise way, such as X, H, Z, or CNOT. |
| circuit | a sequence of gates on a set of qubits, ending in measurement. A quantum program. |
| decoherence | the loss of a quantum state as the environment leaks in. |
| fidelity | how accurately an operation does what it should, often written as a percentage. |
| physical qubit | one actual piece of qubit hardware. |
| logical qubit | a protected qubit built from many physical qubits with error correction. |
| surface code | the leading error-correction scheme: a checkerboard of data and measurement qubits. |
| code distance | the size of an error-correcting patch; bigger catches more errors. |
| threshold | the physical error rate below which adding qubits makes a logical qubit better instead of worse. |
| fault tolerance | running long computations reliably while every part is a little noisy. |
| shor’s algorithm | a quantum method for factoring large numbers that threatens RSA and elliptic-curve encryption. |
| grover’s algorithm | a quantum search method with a square-root speedup. |
| post-quantum cryptography | new encryption math that runs on ordinary computers and resists quantum attack. |
| QKD | quantum key distribution: sharing secret keys with single photons, where eavesdropping leaves traces. |
| quantum advantage | a quantum computer doing a task faster or better than the best classical method. “Supremacy” is the older term. |
| dilution refrigerator | the cryogenic system that cools superconducting qubits to about a hundredth of a degree above absolute zero. |
closing rules of thumb
- Feynman proposed quantum computers in 1981 to simulate nature. Shor showed in 1994 they could break common encryption.
- A qubit is an arrow, not a switch. Each added qubit doubles the space the machine works in.
- Square an amplitude to get a chance. Measuring gives one ordinary bit and ends the blend.
- Interference is the real source of speedup: wrong answers cancel, right answers add.
- Entanglement links outcomes, never messages.
- Noise compounds with every gate. Useful machines are counted in logical qubits, each built from hundreds to thousands of physical ones (estimate).
- The biggest expected wins are chemistry, materials, and code-breaking. The encryption fix is already standardized and rolling out.
- Quantum sensing and quantum keys from orbit are already here, in early form.
- Underneath it all, nature keeps its books in amplitudes that can cancel, and that is the wonder of it.
sources
- r. p. feynman · simulating physics with computers (international journal of theoretical physics) · 1982 · link ↩
- p. w. shor · polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer · 1994, expanded 1997 · link ↩
- arute et al. (google) · quantum supremacy using a programmable superconducting processor (nature) · 10/2019 · link ↩
- ibm research · on “quantum supremacy” · 10/2019 · link ↩
- bluvstein et al. · logical quantum processor based on reconfigurable atom arrays (nature) · 12/2023 · link ↩
- nist · nist releases first 3 finalized post-quantum encryption standards · 08/13/2024 · link ↩ ↩
- google quantum ai · quantum error correction below the surface code threshold (nature) · 12/2024 · link ↩ ↩ ↩
- nobelprize.org · the nobel prize in physics 2025 · 10/2025 · link ↩
- ibm newsroom · ibm and the university of chicago demonstrate quantum advantage on logical circuits (70 logical qubits) · 07/30/2026 · link ↩
- google · meet willow, our state-of-the-art quantum chip (t1 approaching 100 µs) · 12/2024 · link ↩
- bravyi et al. (ibm) · high-threshold and low-overhead fault-tolerant quantum memory (nature) · 03/2024 · link ↩
- nature · microsoft claims quantum-computing breakthrough, and some physicists are sceptical · 02/2025 · link ↩
- caltech · caltech team sets record with 6,100-qubit array · 09/2025 · link ↩
- lee et al. · even more efficient quantum computations of chemistry through tensor hypercontraction (prx quantum) · 2021 · link ↩
- c. gidney (google) · how to factor 2048 bit rsa integers with less than a million noisy qubits · 05/2025 · link ↩
- nist · ir 8547 (initial public draft), transition to post-quantum cryptography standards · 11/2024 · link ↩
- signal · quantum resistance and the signal protocol · 09/2023 · link ↩
- apple security research · imessage with pq3 · 02/2024 · link ↩
- babbush et al. · focus beyond quadratic speedups for error-corrected quantum advantage (prx quantum) · 2021 · link ↩
- ibm · ibm sets the course to build world’s first large-scale, fault-tolerant quantum computer (starling, 2029 target) · 06/10/2025 · link ↩
- nasa · cold atom laboratory · link ↩
- q-ctrl et al. · quantum-assured magnetic navigation in airborne and ground-based field trials (preprint) · 04/2025 · link ↩
- liao et al. · satellite-to-ground quantum key distribution (nature) · 2017 · link ↩
- liao et al. · satellite-relayed intercontinental quantum network (physical review letters) · 01/2018 · link ↩
- nsa · quantum key distribution (qkd) and quantum cryptography (qc) · link ↩
- bausch et al. (google deepmind, google quantum ai) · learning high-accuracy error decoding for quantum processors (nature) · 11/2024 · link ↩