Inside the New Spy Race: How the US, China, Russia, Israel and Italy Are Gearing Up for Agentic AI and Quantum Computing Threats

· Quantum Horizon Italia ·

8 min read Original article ↗

By Remo Pulcini — Quantum Horizon Italia

Nuclear warheads, submarines, and arms-control treaties defined intelligence rivalry for eight decades. In 2026, two converging technologies agentic artificial intelligence and quantum computing are rewriting the rules of espionage and counter-espionage at a pace no international framework has managed to keep up with. This is no longer speculative futurism: it is the explicit lens through which the US intelligence community, Chinese strategic planners, Russian security services, Israeli signals intelligence, and Italy’s own Servizi are now rebuilding doctrine, budgets, and operational priorities.

Two threats, one collision course

The danger runs along two parallel tracks that are increasingly merging into one. The first is agentic AI systems that plan, act, and adapt with minimal human supervision which by 2026 has become a genuine force multiplier for attackers and defenders alike. Security researchers now describe the “rogue agent” scenario, in which an autonomous system executes unauthorized actions across interconnected workflows, as the defining new nightmare for enterprise and government security teams. Tellingly, the concept of a “kill switch” is shifting away from a physical power cord toward the ability to instantly revoke an agent’s digital identity as part of lifecycle governance.

The second track is the so-called “Q-Day” the moment a cryptographically relevant quantum computer (CRQC) becomes capable of breaking today’s standard asymmetric encryption schemes: RSA, ECC, Diffie-Hellman. Most credible estimates place that threshold somewhere in the 2028–2030 window, with early experimental demonstrations expected as soon as 2026–2027. But the practical threat doesn’t wait for that date. It is already unfolding through “harvest now, decrypt later” the strategy by which state actors and organized cybercrime groups are hoovering up encrypted traffic today, betting they’ll be able to decrypt it retroactively once quantum capability catches up. Trade secrets, diplomatic cables, intelligence dossiers: anything that needs to stay confidential for more than a decade is, in effect, already compromised.

United States: encryption as critical national infrastructure

Washington has institutionalized its response more thoroughly than any other power. The foundation remains National Security Memorandum-10, signed by the Biden administration in May 2022, which set the goal of mitigating quantum risk “to the extent feasible by 2035” and mandated an annual inventory of vulnerable systems from every federal agency. The Trump administration has kept that framework intact its June 2025 executive order explicitly cites NSM-10 as the foundational document and in June 2026 the White House issued Memorandum M-26-15, “Securing the Nation Against Advanced Cryptanalytically Relevant Quantum Computers,” further accelerating post-quantum migration across federal networks.

The technical roadmap is now locked in. NIST finalized three post-quantum standards in August 2024 FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — and added HQC as a fifth encryption algorithm in March 2025. The National Security Agency mandates ML-KEM-1024 and ML-DSA-87 for national security systems, and all new defense acquisitions must be quantum-resistant starting in 2027 a requirement that cascades through the entire defense supply chain, from prime contractors down to individual software vendors.

On the intelligence side proper, the 2026 Annual Threat Assessment the document distilling collective judgments from the CIA, NSA, FBI and the rest of the sixteen-agency community treats AI and quantum computing not as future technologies but as structural forces already reshaping global competition. That’s a genuine doctrinal shift: technological disruption is now being weighed with the same analytical priority historically reserved for nuclear proliferation or transnational terrorism.

China: self-reliance doctrine and a parallel cryptographic track

Beijing is playing a different game, built on tight integration between the state, academic research, and national industrial champions. China’s new Five-Year Plan (2026–2030), unveiled by the Communist Party’s Central Committee, places quantum computing alongside AI among the “new quality productive forces” meant to drive economic growth and scientific leadership the document references AI more than fifty times and introduces a sweeping “AI+ action plan” for cross-sector integration.

The move with the biggest ripple effect for global intelligence-sharing is on the cryptographic front: China’s Institute of Commercial Cryptography Standards launched its own, independent post-quantum algorithm selection process back in 2025, running in parallel to and diverging from NIST’s standardization effort. That decision risks splitting global cybersecurity infrastructure into a US-aligned bloc and a China-aligned bloc, with direct consequences for interoperability among allied intelligence services and for information-sharing across coalitions like NATO and the Five Eyes.

On the offensive side, China’s Ministry of State Security has already demonstrated industrial-scale cyber-espionage capability. The Salt Typhoon campaign, which compromised nine US telecom carriers in 2024 and granted direct access to the communications of senior American officials, remains the textbook case Western analysts cite when describing Beijing’s ability to convert telecom-infrastructure access into geopolitical and negotiating leverage.

Russia: operational continuity despite a resource squeeze

The Russian case presents an apparent paradox. Post-2022 sanctions and technological isolation have significantly slowed domestic quantum-hardware development compared to the US and China, but they have done little to blunt the offensive capability of Russia’s services FSB, SVR, and GRU in weaponizing generative AI for influence operations, automated disinformation, and industrial-scale social engineering. Western analysts, including the authors of the US Annual Threat Assessment cited above, continue to rank Russia among the most aggressive users of audio and video deepfakes for social-engineering campaigns impersonating corporate executives or government officials a technique whose realism and evasiveness have grown sharply through 2025–2026.

Defensively, Moscow is pursuing partial cryptographic sovereignty through its national GOST standards, but its comparatively limited investment in frontier quantum research leaves it, according to several independent assessments, more exposed than average to the “harvest now, decrypt later” threat over the medium term even as it remains extremely dangerous on the offensive front thanks to decades of accumulated hybrid-warfare tradecraft.

Israel: Unit 8200’s fusion of AI, quantum cryptanalysis and kinetic operations

Israel arguably represents the most tightly integrated fusion of AI, quantum computing, and kinetic operations of any intelligence service in the world. Unit 8200, Israel’s equivalent of the NSA and reportedly the source of roughly ninety percent of the country’s intelligence material, has systematically accelerated investment in AI-powered intelligence analysis, autonomous cyber operations, and quantum-cryptanalysis capability, according to multiple independent assessments of the unit’s activity.

Publicly documented research lines include the development of dedicated ASICs for breaking lattice-based encryption ahead of the “NISQ” (Noisy Intermediate-Scale Quantum) era, evaluation of schemes like CRYSTALS-Kyber and NTRU for both defensive and offensive purposes combining lattice-sieving techniques with machine-learning-assisted pattern pruning and deployment of quantum-resistant, XMSS-signed VPN mesh networks for tactical field communications. In parallel, the unit has expanded its use of large-language-model copilots to summarize multilingual datasets, freeing human analysts to focus on hypothesis testing a human-machine collaboration model that has matured through the multi-year confrontation with Iran, where SIGINT, offensive cyber, and kinetic strikes are now integrated into a single operational cycle.

Italy: quantum officially enters the intelligence perimeter

Italy has taken its own significant doctrinal step. The 2026 annual report on information security policy, published by Italy’s Department of Information for Security (DIS), includes for the first time a thematic annex entirely devoted to quantum technologies. Its opening premise is unambiguous: the quantum computing challenge already ranks among the primary arenas of great-power competition, with direct implications for cryptography, intelligence, critical infrastructure, and national economic competitiveness. Italian investment is structured around three pillars quantum computing, quantum communication, and quantum sensing explicitly framed as a national security issue rather than merely an industrial-policy one.

On the ground, the threat picture from Exprivia’s 2025 annual Threat Intelligence Report is stark: Italy logged an average of more than a thousand hostile cyber events per quarter, with public administration remaining a top-priority target 351 recorded cases in 2025 versus 221 in 2024 precisely because of the combination of sensitive data handled and often heterogeneous, under-updated IT infrastructure. For the first time, industry experts note, 8.5% of 2025 incidents were potentially traceable to quantum-related dynamics a signal that attackers are already laying the groundwork for threat scenarios that remain largely theoretical today but will structurally reshape national cybersecurity dynamics over the medium term.

For a public-health administrator who handles sensitive clinical and administrative data on a daily basis, this is far from an academic exercise. Italy’s healthcare archives combining clinical, demographic, and administrative records that must remain confidential for decades fall squarely into the category of information most exposed to “harvest now, decrypt later” strategies. Post-quantum cryptographic migration is therefore no longer a concern confined to intelligence agencies alone; it is a governance issue that directly touches every public-sector information system, healthcare included.

An arms race with no red lines

What separates this technological competition from the old nuclear arms race is the near-total absence of shared arms-control treaties. However devastating, the atomic bomb remained for decades in the hands of a limited number of state actors bound by negotiated red lines. Agentic AI and quantum computing, by contrast, are technologies potentially accessible to anyone with sufficient technical resources and strategic determination non-state actors included. That’s precisely why, for the first time, leading Western intelligence reports from the American assessment to the Italian one — no longer treat AI and quantum computing as standalone technology chapters, but as structural components of strategic threat evaluation, on equal footing with traditional geopolitical scenarios.

The challenge for the years ahead, for Italy as much as for its NATO and EU allies, will be closing the gap between how fast these technologies evolve and the inherently slower pace of regulatory, organizational, and infrastructural adaptation a gap that, left unaddressed, risks becoming the next real strategic vulnerability in its own right.