Session
Beyond Code Generation: AI Agents for Post-Quantum Cryptography Migration
AI agents can write code. But can we trust them to change the cryptography protecting an application? This talk puts that question to the test through a hands-on migration from classical to post-quantum cryptography.
Post-quantum migration is an unusually demanding test for an AI coding agent. It requires changing keys, signatures, verification logic, cryptographic libraries, and security assumptions while preserving application behavior and avoiding subtle security failures.
I’ll walk through an experiment in which an AI coding agent is given an existing application using classical cryptography and tasked with migrating it to NIST-standardized post-quantum cryptography. We’ll compare the system before and after, examining the exact code changes, key and signature sizes, token overhead, signing and verification performance, and negative security tests such as tampered payloads and incorrect keys.
The experiment goes beyond asking whether an AI agent can generate cryptographic code. It explores how much of a security-critical migration an agent can successfully perform and validate, what safeguards help establish confidence in the result, and what this teaches us about using AI agents for complex software migrations.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top