On 17 June 2026, in Paris, France bought eighteen qubits.

GENCI and Alice & Bob signed on the stand of the national quantum strategy at the VivaTech trade fair. On one side, the public body that runs the French state’s supercomputers and hands out their computing hours to laboratories; on the other, a six-year-old company born in a Paris laboratory.
The thing they bought fits in a room. It can do fewer things than any phone you own.
Three questions come at once. Will these machines replace our servers? Shut down power stations? Save carbon?
No, no, and almost nothing. And yet the purchase is not absurd. What follows is the story of a machine that can barely do anything, and of the very good reason a state has for buying it anyway.
The point was never to do the same thing, faster
Start with the objection, the one everyone raises and which deserves a straight answer. This machine will cost more than a supercomputer, break down more often, run more slowly, and it will have to live one hundredth of a degree above absolute zero, inside a fridge the size of a wardrobe that cannot be opened without warming the whole thing up.
An ordinary computer examines the possibilities one after another, by the billion every second, but always one at a time, and that serves it well as long as their number stays reasonable. Some problems are not reasonable.
Two of them are worth a state’s money. You meet both every day without seeing them: the first protects your money, the second feeds part of humanity.
The first wall is a padlock you never look at
You cross it every day without noticing. When you pay online, when you open your bank account, when you write to someone, a small padlock appears somewhere on the screen, and it promises two things at once: that nobody else can read what passes, and that the site facing you really is what it claims to be. You never look at it.
That padlock holds neither by law, nor by trust, nor by a password. It holds by a bet: that nobody on Earth knows how to do a certain calculation fast enough. Your payments depend on it. So do your medical records, state secrets, and the updates your devices install.
All those padlocks rest on a calculation of disarming simplicity: take two large prime numbers, multiply them, and the product becomes the key, published for all to see, while breaking the protection means working backwards, from the product to the two numbers. Multiplying takes a microsecond. Working backwards has resisted for forty years.

Take 43 times 47: that makes 2,021, and you worked it out in your head. Now start from 2,021 and find 43 and 47. You are already struggling. With numbers hundreds of digits long, the gap becomes a chasm no computer can bridge.
So you make a 2,048-bit key in a few milliseconds, on any phone at all, and that costs no more than a key half as long. Only the attacker pays. He pays exponentially.
How far can he go? The question has its own competition. Since 1991 the RSA Factoring Challenge has published numbers to be broken whose factors nobody uses. They are not keys, they are yardsticks, built to measure the front line.
A team from the Loria, with American colleagues, pushed that front line to RSA-250 in February 2020: a 250-digit number, the product of two 125-digit primes. It would have taken 2,700 years on a single computer. They put ten thousand machines on it for a few months.
Your own keys are 2,048 bits, more than six hundred digits, against two hundred and fifty for the record. Cryptographers pick them deliberately far beyond what attackers can break, then enlarge them as the front line advances. They have been winning that game of hide-and-seek for thirty years, bit by bit, without effort.
No classical machine will ever cross that wall, and there lies the reversal: the problem has nothing to do with power, since every added bit doubles the work of whoever attacks while costing nothing to whoever defends.
The second wall, you eat it
Nitrogen fertilisers feed a large share of humanity, and making them costs a great deal of energy: the industrial process demands high temperatures and high pressures, continuously, in vast plants that never stop.
An enzyme manages it anyway, inside a plant, at room temperature and pressure, with no factory and no heat. It is called nitrogenase.
Nobody knows how it does it.
Industry would gain enormously from understanding that trick: the process could be redone for far less energy. Nobody manages it, because simulating the enzyme’s active site precisely is beyond what classical computers can do, the number of configurations to track exploding with the number of particles.
Richard Feynman was the first to draw the consequence and propose a machine of another kind. Since nature already computes, he said in substance, let us use one quantum system to simulate another.
These two walls teach the same lesson. The point is not to go faster on ordinary tasks, but to cross obstacles in front of which adding processors achieves nothing, whatever their number, whatever the budget.
Three conditions, and most candidates fail
An ambiguity must be cleared here, or the rest becomes unreadable. The word simulation immediately calls to mind an aircraft, a car, a factory. That is not what this is about.
A quantum machine simulates one thing well: another quantum system. The electrons of a molecule, the spins of a material, atoms bonding to one another. The air around an aircraft wing obeys ordinary physics: hard to compute, certainly, but with a classical hardness the quantum does not handle any better.
Three conditions follow, and a problem must meet all three.

The first concerns the nature of the problem: its hardness must come from quantum behaviour itself. The second concerns the data: the statement must fit in very little information, because everything has to be loaded into the machine one item at a time. The third concerns the gain.
This third condition governs everything else. A quadratic speedup takes the square root of the classical computing time: a problem that took a hundred years takes ten. A super-quadratic speedup does better than that square root, and far better.

Six researchers at Google Quantum AI published an analysis in 2021 that did the sector’s marketing a great deal of harm: below the super-quadratic, the constant cost of error correction eats the gain of scale, and nothing at all is left.
Put the natural candidates through the filter. Almost all of them fail. Fraud detection and anomaly detection fall at the first two conditions: nothing quantum about a bank transaction, and millions of lines would have to be loaded. A world model fails all three. Fluid mechanics fails the first and the third, and the reference analysis rules it out by name, along with meteorology and climate.
The same verdict strikes machine learning, general optimisation and database search. Not because those problems are too big, but because their speedup stays quadratic.
The authors of those papers work inside the field, and that changes everything: no outside sceptics here, but the teams at Google and Microsoft, whose business is selling quantum computing. When a vendor narrows his own addressable market, he can be believed.
The market has nothing to do with computing
The mathematician everyone keeps invoking, here is what he does. He does not program, he discovers. Fitting a problem into a quantum machine means finding a way to restate it, and nobody knows how to do that on demand. It is research work, not engineering.
Thirty years of it have yielded two families. A sufficient speedup is established only for simulating quantum systems, meaning chemistry, materials and physics, and for cryptanalysis. Everything else waits for its mathematician.
More candidates pass the filter than you might think. Designing a catalyst, understanding a battery electrode, predicting how a molecule binds to a protein, delivering on the promise of a less energy-hungry fertiliser: all of it belongs to chemistry and materials, where the hardness is quantum by nature and the statement fits in a few dozen numbers.
That market overlaps computing not at all. It is called chemistry, pharmaceuticals, energy, materials, plus the cryptography that will have to be replaced from top to bottom. Narrow in number of trades, considerable in value, and with no overlap whatsoever with the servers that run our companies.
No, there will be no ultra-fast applications replacing our information systems. There will be, perhaps, two or three walls crossed.
This machine still resembles nothing we know: an object that lives one hundredth of a degree above absolute zero, that cannot be opened without three days of warming, and of which eighteen units are enough to interest a state. The next episode opens the box and looks at what it is made of.
Sources
- CEA, “La France acquiert auprès d’Alice & Bob un premier calculateur quantique basé sur la technologie de qubits de chats”, 2026-06-17: https://www.cea.fr/presse/Pages/actualites-communiques/ntic/France-acquiert-Alice-Bob-premier-calculateur-quantique-qubits-de-chats.aspx (retrieved 2026-08-25, tier 1)
- Craig Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits”, 2025-05-21: https://arxiv.org/abs/2505.15917 (retrieved 2026-08-25, tier 1)
- Siyuan Niu, Di Wu, Ozgur Ozan Kilic, Kwangmin Yu, “Estimating The Energy Consumption of Quantum Computing from A Full System Aspect”, 2026-05-10: https://arxiv.org/html/2605.09580 (retrieved 2026-08-25, tier 2)
- Ryan Babbush et al., “Focus beyond quadratic speedups for error-corrected quantum advantage”, 2021-03-31: https://arxiv.org/abs/2011.04149 (retrieved 2026-08-25, tier 1)
- Torsten Hoefler, Thomas Häner, Matthias Troyer, “Disentangling Hype from Practicality: On Realistically Achieving Quantum Advantage”, 2023-07: https://arxiv.org/html/2307.00523 (retrieved 2026-08-25, tier 1)
- Bpifrance, “Alice & Bob lève 100 millions d’euros lors de sa Série B”, 2025-01-28: https://presse.bpifrance.fr/alice-amp-bob-leve-eur-100-millions-lors-de-sa-serie-b-menee-par-future-french-champions-ffc-avp-et-bpifrance-pour-progresser-vers-un-ordinateur-quantique-utile (retrieved 2026-08-25, tier 1)
- Markus Reiher, Nathan Wiebe, Krysta M. Svore, Dave Wecker, Matthias Troyer, “Elucidating Reaction Mechanisms on Quantum Computers”, 2016-05-11: https://arxiv.org/abs/1605.03590 (retrieved 2026-08-25, tier 1)
- CNRS Sciences informatiques, “Un logiciel open-source établit un nouveau record de factorisation”, 2020: https://www.ins2i.cnrs.fr/fr/cnrsinfo/un-logiciel-open-source-etablit-un-nouveau-record-de-factorisation (retrieved 2026-08-25, tier 1)
- Craig Gidney et Martin Ekerå, “How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits”, 2019: https://arxiv.org/abs/1905.09749 (retrieved 2026-08-25, tier 1)



