In the NIST laboratory, at Gaithersburg in Maryland, a competition of a peculiar kind has been running since 2016: teams from around the world submit encryption algorithms, and the others then spend years trying to break them, methodically, paper after paper. No quantum machine has ever run in that room.

A hundred and one components to obtain one usable qubit, eighteen bought by France, a machine delivered in 2027 to a public centre: none of it works yet at the scale that counts, and the bill stays out of reach of anyone who might want to pay it.
And yet, in that Maryland room, cryptographers have been working for ten years against a machine that does not exist.
Somewhere, a date is already written.
Twenty-six kilowatts against eleven megawatts, and why that ratio proves nothing
The field’s most seductive promise rests on a comparison where the reasoning turns slippery from the first line. It all starts with two units.
The kilowatt measures a power, meaning what a device draws at the instant you look at it, while the kilowatt-hour measures an energy, meaning what it has consumed after a certain time. A French home uses roughly 4,000 of them a year.

Google published the reference figure in 2019. Its Sycamore processor consumes 26 kilowatts, about ten electric radiators, and runs its test algorithm in a few seconds. Facing it, the European supercomputer JUPITER, at Jülich, draws 11 megawatts.

The ratio crushes everything: at instantaneous power, the supercomputer draws more than four hundred times as much. Three objections overturn it.
The first concerns what actually consumes. Those 26 kilowatts do not go into the computation but into the dilution refrigerator keeping the chip cold. And that refrigerator runs permanently, whether you compute or not. An idle quantum calculator therefore costs almost as much as one hard at work, where a classical supercomputer sees its bill fall when the load drops.
The second concerns what is being compared. The 26 kilowatts and the 11 megawatts do not solve the same problem, and when a Chinese team redid Sycamore’s computation classically in 2024, on 1,432 graphics processors, it went seven times faster than the quantum machine, with two orders of magnitude less energy than previous attempts. Its authors see in it the first unambiguous experimental refutation of the advantage claimed in 2019.
The third comes from the other camp. Physicists who popularise their own field treat the question of an energy advantage as open, which should be enough to discard any categorical claim in either direction.
A preprint from May 2026, not yet peer-reviewed, models the energy cost of a complete machine and supplies the figure that was missing: a dilution refrigerator draws between 10 and 25 kilowatts continuously, independently of the algorithm it supports.
Working out the energy spent is no mystery: a power multiplied by a duration. On the quantum side, though, the power does not move.

Hence the sector’s obsession with speedup. A quantum machine can win on the bill only by finishing much sooner, since it pays the same hourly rate from beginning to end.
An order of magnitude circulates to say by how much: the speedup would have to exceed a factor of one hundred to offset refrigeration alone. It must be handled with care. The preprint does not compute it, it takes it from an article in Nature Computational Science published in 2023, whose accessible abstract mostly says that specialists still do not agree on the metrics for measuring that consumption.
The preprint’s authors temper the role of cold themselves: today, they write, it is neither the number of operations nor cryogenics that sets the energy budget, but the cost of handling errors.
That figure describes the current state of the hardware, and nothing else. The same authors ask that refrigerator wall-plug efficiency become a published specification alongside the qubit count, which amounts to saying they expect it to improve.
No power station will close: here is the arithmetic
So how many power stations? The question deserves better than a dodge, and the calculation that follows is this article’s extrapolation, not a published result. Its input numbers are sourced.
A 26-kilowatt machine running without interruption consumes about 0.23 gigawatt-hours a year, when a French nuclear reactor produces of the order of 7,000. You would therefore have to run more than thirty thousand such calculators continuously to consume what a single reactor produces.
Thirty thousand cryogenic machines. No published roadmap mentions such a fleet, nor anything approaching it.
And on the savings side?
The world’s data centres consumed roughly 415 terawatt-hours in 2024, or 1.5% of global electricity, and for quantum computing to bring that total down it would have to take load away from classical servers. It takes none away.

A decision-maker who kept only one sentence of all this should keep this one: quantum computing opens no next generation, it adds a peripheral.
The energy saving, if it comes, will happen outside
Its defenders do put forward a serious argument, and it bears on two different savings. The one on computing stays negligible. The one on industrial processes could matter.

Researchers from ETH Zurich and Microsoft Research published in 2016 a demonstration of how a quantum calculator could elucidate the reaction mechanisms of complex chemical systems. Their example is the biological fixation of nitrogen by nitrogenase.
There, and only there, lies the honest answer to the carbon question. A quantum calculator will not bring down a data centre’s electricity bill. It might one day lighten a fertiliser plant’s.
The authors set the limit themselves, and it must be repeated: that prospect rests on resource estimates, not on computations performed. No verifiable commercial use case has been made public to date.
The only dated deadline is not a technical one
That leaves the most disturbing fact in the file, the one that explains why states buy machines that serve no purpose.
In 2019, in Google’s offices, Craig Gidney and the Swede Martin Ekerå worked out how many qubits it would take to break a 2,048-bit key, the one protecting your payments. Their verdict landed: twenty million imperfect qubits, for eight hours. As good as never. Six years later, Gidney picked up his own calculation. And demolished it.
In May 2025 he publishes a new estimate: fewer than a million qubits, in under a week. Twenty times fewer than he himself had announced six years earlier.

One sentence of method explains everything. Gidney reuses exactly the 2019 hardware assumptions: the same grid of qubits with nearest-neighbour connections, the same per-gate error rate, the same cycle time.
No hardware progress enters that factor of twenty, then. It is the mathematics that moved, while the machines stayed in the garage. The target is closing in on its own.
The scenario that follows waits for no machine, and that is precisely what makes it serious: an attacker intercepts an encrypted stream today that he cannot read, stores it somewhere, and waits.
Any information whose confidentiality must hold for ten or twenty years is therefore already exposed: an industrial contract, a patent file, a diplomatic cable. France’s cybersecurity agency draws the consequence and writes that after 2030, nobody should be buying a product without post-quantum cryptography.
That sentence deserves to be unpacked, because it does not ask for everything to be replaced. The agency asks the right question, and it is not the one you would expect: it asks organisations to inventory the data whose confidentiality or authenticity must be guaranteed after 2030, stating that duration in every case.
The criterion is therefore not the algorithm in use, but the property to be protected and how long it must hold. Three cases arise, with neither the same urgency nor the same reason.

Confidentiality is threatened today, and it is the most urgent case. A stream captured now will be read when the day comes: industrial contracts, patent files, health data, backups. The agency asks organisations to identify right now the business uses threatened by the future arrival of a machine.
Authenticity cannot be forged in advance. Nobody can forge today a signature he will only know how to counterfeit in 2035, and a signature already verified stays verified. The danger lies elsewhere: signed firmware, a root certificate, a legal timestamp must stay valid well beyond 2030, and it is that period of validity that makes them urgent.
The algorithm encrypting the data does hold firm, and the reason deserves to be understood rather than memorised. Shor does not break encryption in general: it breaks one precise mathematical structure, that of factorisation and the discrete logarithm, on which all asymmetric cryptography rests. Symmetric encryption offers no such structure to exploit. All that remains is trying keys one by one, and Grover’s algorithm speeds that search up only quadratically: doubling the key size is enough to return to the previous security level.
It would be a mistake, though, to conclude that your stored data is safe, and that is the trap in this whole line of reasoning. The safe holds; the problem is how the key got there.
In an ordinary secure connection, the two machines begin by agreeing on a symmetric key, and that agreement is negotiated asymmetrically. An attacker recording the session records both things: the encrypted stream, and the negotiation that produced the key. The day he knows how to break the asymmetric part, he recovers the key, then reads all the rest.
That is why the agency recommends post-quantum key encapsulation mechanisms, and not only signatures. Data encrypted symmetrically is durably protected only if its key never travelled through a vulnerable asymmetric mechanism, or if that exchange has already been migrated.
The name misleads everyone. Post-quantum cryptography contains nothing quantum: it gathers ordinary algorithms, running on today’s computers, but resting on other mathematical problems, the ones no known quantum algorithm can attack.
The agency also recommends something unusual: not trusting them straight away. Hybridisation means combining a post-quantum algorithm with a well-studied pre-quantum one, so that the protection holds even if the newcomer turns out to be weak.
What the inventory must produce is spelled out precisely: identify the equipment that will need updating, ask suppliers about their roadmap, know the replacement cycles of the estate, and stop buying products without post-quantum cryptography.
Note what is not being said, because the nuance is constantly lost. Nobody is announcing that RSA will fall in 2030. Estimates are dropping fast, and a regulatory calendar already exists: nothing more.
The date that binds a company comes from no laboratory. It comes from a regulator.
Four trades, and not at the same moment
“It changes everything for everyone” is the phrase that lets you decide nothing. Here are the categories genuinely concerned, in the order in which they become so.
Chief information security officers take the blow now, unconditionally and with no way out: their deadline comes from the regulator, it is already written down, and inventorying cryptographic assets takes years in a mid-sized organisation.
Chemists and materials manufacturers follow in the medium term, and they carry the field’s potential value. They will buy no machine: they will formulate their problems in a format that will be usable the day the machines arrive, which is exactly what free access to a national testbed allows.
In the hangar at Bruyères-le-Châtel, computing centre operators are already learning a rare trade: hosting, cooling and coupling experimental machines. France practises it ahead of the others.
Executive boards have nothing to do, and that must be said just as plainly: answering “zero” to the question of quantum investment stands up perfectly well. Answering “zero” on cryptographic migration does not.
Five bets, and this series followed only one
Everything above followed a single machine, and it now has to be put back in its place. France did not bet on one technology: it funds five of them side by side. On 5 March 2024 the Direction générale de l’armement signed framework agreements with five companies, for a maximum of five hundred million euros.

The national strategy portal describes them one by one, and no two lines look alike. Alice & Bob works on cat qubits. C12 traps electron spins in carbon nanotubes. Pasqal cools neutral atoms with lasers. Quandela bets on photonics. Quobly etches electron spins onto silicon, using the processes of existing microelectronics.
These five paths share neither the same physics, nor the same industrial obstacles, nor necessarily the same cold. Several of them need no dilution refrigerator at all, which shifts everything this episode has just said about energy.
The programme advances by elimination: five companies at the start, three kept in 2028, two in 2032, aiming at prototypes of 128 logical qubits. The state spreads its risk rather than naming a winner, and the official portal admits it is still too early to know which will clear every obstacle.
This series therefore describes one way of doing it, not quantum computing in general. The questions hold for every machine. The answers change from one architecture to the next.
What a cloud provider selling quantum is actually selling
Your cloud provider may already be offering quantum computing. Amazon calls it Braket, Microsoft Azure Quantum, IBM its quantum platform. You rent machine hours there, by the second or by the task, as you would rent a server.
Those hours run on hardware they do not own. Braket opens access to superconducting chips from IQM and Rigetti, to ion traps from AQT and IonQ, to neutral atoms from QuEra. The provider runs the counter, the billing and the development tools; the cold and the qubits are elsewhere. Some of those hours touch no qubit at all, since these offerings also sell simulators, classical programs that imitate a quantum machine on ordinary servers: perfect, noiseless, far cheaper, and hopelessly slow past a few dozen qubits.
What remains is to know what those researchers do with their hours, since none of the above works at the scale that counts.
Running an algorithm and drawing an advantage from it are two different things. Today’s machines do run circuits and do return a result, but that result comes out noisy: the run has to be repeated thousands of times and what comes back statistically straightened, where an ordinary computer would give the answer first time.
The preprint cited earlier gives the exact scale of what runs. Its authors instantiated their model on time-evolution simulations at 96 and 100 qubits, executed on an IBM processor, plus a representative chemistry workload.
Those hundred qubits do not compare with the hundred and one of the previous episode, and the confusion is common. Google was spending a hundred and one components to make a single corrected qubit. Here nobody corrects anything: the hundred qubits are used raw, with their noise.
Two regimes coexist, then, and that same preprint treats them separately because they have neither the same costs nor the same methods. The first takes qubits as they are and catches the noise afterwards, by statistical means. The second manufactures corrected qubits, at a hundred and one components apiece, and exists only in the laboratory.
Every machine available online belongs to the first regime. They are not empty, then: they work, but in a world where noise is accepted rather than eliminated.
The work consists in taming the machine rather than making it produce. IBM offers research at the level of circuits and gates, and highlights error mitigation: instead of preventing the noise, you measure it and correct the result afterwards.
Three trades share those benches. Manufacturers measure their own chips and publish their error rates. Algorithm designers check at small scale that a circuit behaves as the theory says. Industrialists learn to phrase their problems in a language the machine will accept when the day comes.
What these offerings sell is therefore not production capacity but a testbed, and their own pages say so without hedging: Amazon titles its service accelerate quantum computing research, IBM offers to turn foundational ideas into experiments. Neither announces that it will solve an operational problem.
That is exactly what France bought, with two differences. It paid for the machine rather than the hour, and access will be free for its researchers.
What to ask for next time
Faced with a proposal, commercial or political, a decision-maker saves time by asking this.

Does the announced gain exceed the quadratic? Is the qubit count logical or physical? Is there a verifiable use case, or only a resource estimate?
A vague answer to any one of the three is enough to set the proposal aside.
Go back to the VivaTech stand, on 17 June 2026. The communiqué signed that day announces that the system will strengthen the strategic autonomy of France and of Europe. That is a promise, in the proper sense of the word.
But a promise is not a result. What France bought that day is not a machine that will replace anything, nor one that will lighten an electricity bill: it is the right to learn how to use it before the others, on a technology with exactly one certain application, dated by a regulator, and destructive.
Eighteen qubits, then. Not a computer, not a revolution, not a power station saved. A testbed, at the bottom of a refrigerator nobody will open without three days of warming.
The communiqué had written “calculator” where the press was about to write “computer”. That was no communications caution. It was an exact description.
Suggestion to go further
If you are interested by learning more on Quantum Physics, I can recommend this series:
What Is Space?
The Illusion of Time (click on the picture to access Youtube. This video could not be embedded) :

Quantum Leap :
Universe or Multiverse?
More recently published:
Sources
- CEA, “La France acquiert auprès d’Alice & Bob un premier calculateur quantique basé sur la technologie de qubits de chats”, 2026-06-17: https://www.cea.fr/presse/Pages/actualites-communiques/ntic/France-acquiert-Alice-Bob-premier-calculateur-quantique-qubits-de-chats.aspx (retrieved 2026-08-25, tier 1)
- Google Quantum AI and Collaborators, “Quantum error correction below the surface code threshold”, 2024-08-27: https://arxiv.org/abs/2408.13687 (retrieved 2026-08-25, tier 1)
- Craig Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits”, 2025-05-21: https://arxiv.org/abs/2505.15917 (retrieved 2026-08-25, tier 1)
- Siyuan Niu, Di Wu, Ozgur Ozan Kilic, Kwangmin Yu, “Estimating The Energy Consumption of Quantum Computing from A Full System Aspect”, 2026-05-10: https://arxiv.org/html/2605.09580 (retrieved 2026-08-25, tier 2)
- Commission européenne, direction générale de l’énergie, “In focus: Data centres, an energy-hungry challenge”, 2025-11-17: https://energy.ec.europa.eu/news/focus-data-centres-energy-hungry-challenge-2025-11-17_en (retrieved 2026-08-25, tier 2)
- EuroHPC Joint Undertaking, “European Exascale Supercomputer JUPITER Sets New Energy Efficiency Standards with #1 Ranking in GREEN500”, 2024-05-13: https://eurohpc-ju.europa.eu/european-exascale-supercomputer-jupiter-sets-new-energy-efficiency-standards-1-ranking-green500-2024-05-13_en (retrieved 2026-08-25, tier 1)
- Torsten Hoefler, Thomas Häner, Matthias Troyer, “Disentangling Hype from Practicality: On Realistically Achieving Quantum Advantage”, 2023-07: https://arxiv.org/html/2307.00523 (retrieved 2026-08-25, tier 1)
- Xian-He Zhao et al., “Leapfrogging Sycamore: harnessing 1432 GPUs for 7x faster quantum random circuit sampling”, 2024-06-28: https://arxiv.org/abs/2406.18889 (retrieved 2026-08-25, tier 1)
- Markus Reiher, Nathan Wiebe, Krysta M. Svore, Dave Wecker, Matthias Troyer, “Elucidating Reaction Mechanisms on Quantum Computers”, 2016-05-11: https://arxiv.org/abs/1605.03590 (retrieved 2026-08-25, tier 1)
- The Conversation, “Could energy efficiency be quantum computers’ greatest strength yet?”, 2022-10-26: https://theconversation.com/could-energy-efficiency-be-quantum-computers-greatest-strength-yet-191989 (retrieved 2026-08-25, tier 2)
- RTE, “Bilan électrique 2025”, 2026-02-25: https://www.rte-france.com/actualites/bilan-electrique-2025-conditions-sont-reunies-permettre-france-accelerer-electrification (retrieved 2026-08-25, tier 1)
- Connaissance des Énergies, “La production électrique bas carbone de la France a atteint un maximum historique en 2025”, 2026-02-26: https://www.connaissancedesenergies.org/la-production-electrique-bas-carbone-de-la-france-atteint-un-maximum-historique-en-2025 (retrieved 2026-08-25, tier 2)
- ANSSI, “FAQ sur la cryptographie post-quantique”, 2026: https://cyber.gouv.fr/enjeux-technologiques/cryptographie-post-quantique/faq-pqc/ (retrieved 2026-08-25, tier 1)
- EDF, espace particuliers, “La consommation électrique moyenne et comment économiser”, 2026: https://particulier.edf.fr/fr/accueil/guide-energie/electricite/consommation-moyenne-electricite.html (retrieved 2026-08-25, tier 2)
- Interstices, Inria, “La fragilité inattendue du chiffrement symétrique dans le monde post-quantique”, 2020: https://interstices.info/la-fragilite-inattendue-du-chiffrement-symetrique-dans-le-monde-post-quantique/ (retrieved 2026-08-25, tier 1)
- Sophia Chen, “Are quantum computers really energy efficient?”, 2023: https://www.nature.com/articles/s43588-023-00459-6 (retrieved 2026-08-25, tier 1)
- Amazon Web Services, “Amazon Braket, accélérer la recherche en informatique quantique”, 2026: https://aws.amazon.com/fr/braket/ (retrieved 2026-08-25, tier 1)
- IBM, “IBM Quantum Platform”, 2026: https://quantum.cloud.ibm.com/ (retrieved 2026-08-25, tier 1)
- Craig Gidney et Martin Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits”, 2019: https://arxiv.org/abs/1905.09749 (retrieved 2026-08-25, tier 1)
- Portail de la stratégie nationale quantique, France 2030, “Programme PROQCIMA”, 2026: https://quantique.france2030.gouv.fr/acces-aux-marches/programme-proqcima/ (retrieved 2026-08-25, tier 1)
- Ministère des Armées, Direction générale de l’armement, “La DGA a notifié des accords-cadres auprès de cinq sociétés pour le développement d’ordinateurs quantiques universels”, 2024-03-05: https://www.defense.gouv.fr/dga/actualites/dga-notifie-accords-cadres-aupres-cinq-societes-developpement-dordinateurs-quantiques-universels (retrieved 2026-08-25, tier 1)













