Every answer a federal buyer needs about post-quantum compliance is published. None of it is searchable in the database that governs the purchase.
Two of the 676 cryptographic modules currently validated under FIPS 140-3 carry both of the algorithms that CNSA 2.0 requires, and there’s no way to find that out by searching for it. Post-quantum compliance is on the public record, sitting in 676 separate PDFs. You’ve got to open all of them.
I did. The count comes from a caption-anchored census of every active FIPS 140-3 security policy on the NIST list as of August 15, 2026. It’s Laterstack’s own count rather than a published figure. The script and the per-module output are linked at the bottom so anyone can re-run it.
Both are hardware. Kryptus describes itself as a Hardware Security Module, multi-chip standalone, overall security level 3. Thales states Module Type: Hardware, Embodiment: MultiChipEmbed. No validated software module carries both.
Nine software modules get partway. Eight of them carry ML-KEM in an approved table and one carries ML-DSA, and not a single one carries both. AWS-LC 3, certificate 5314 is the recognizable name in that group, declaring Module Type: Software with ML-KEM approved and no ML-DSA.
That split is the shape of the problem. Key establishment is arriving in software and signatures aren’t, so the eleven modules carrying any post-quantum algorithm at all break into nine that solved half the suite and two hardware boxes that solved all of it.
The list moves every week, and that’s worth sitting with. It held 666 active modules on August 8 and 676 on August 15, so ten modules got validated in seven days. Not one of them qualified.
Two databases
NIST runs two validation databases, and the searchable one isn’t the one that governs the purchase.
The Cryptographic Algorithm Validation Program is fully searchable by post-quantum algorithm. Its filter offers ML-DSA KeyGen, SigGen and SigVer, ML-KEM EncapDecap and KeyGen, SLH-DSA, and LMS. Type in what you need and you’ll get results.
CAVP validates algorithm implementations. It isn’t sufficient for procurement.
The Cryptographic Module Validation Program validates modules, which is what actually gets bought and deployed, and it’s the one a national security systems buyer is required to use. Its Algorithm filter runs AES through Triple-DES. It includes Skipjack. It includes DES. There’s no option for ML-KEM, no option for ML-DSA, no option for SLH-DSA. Certificate pages list no algorithms at all, so pulling up certificate 5313 tells you nothing about what’s inside it.
That asymmetry points the wrong way. The database that can’t govern a purchase is the one built to be searched. The one that governs it leaves the security policy PDF as the only record of what a module can actually do in approved mode.
The captions
The same algorithm string shows up several times inside a single security policy, and only one of those appearances means the module can use it.
In the Thales policy, ML-KEM-1024 appears under Table 3, a modes list, under Table 4, Approved Algorithms, and again under Table 22, pre-operational self-tests. Same string, three tables, three different meanings. A keyword search across the corpus returns all three and can’t tell them apart, which is exactly how a keyword scan overcounts.
There’s a wrinkle that makes it worse. In these documents the caption gets emitted after the table body in the extracted text, not before it, so the nearest caption above a row is usually the wrong one. In the Kryptus policy the ML-DSA-87 row sits at line 376, with “Table 3: Modes List” above it and “Table 4: Approved Algorithms” below. The one below is the one that governs. Walking backward gives you the wrong answer every time, and the census only got trustworthy after that direction was tested against a document where the right answer was already known.
Both of those are the correct disclosure, and that’s the part worth being careful about. Listing an algorithm as non-approved is exactly what a vendor is supposed to do when the code exists but hasn’t been validated for approved mode, and both companies documented it in the format NIST asks for. They’re named here because they’re the two a reader will recognize, not because they stand out from the other 60 policies that mention post-quantum algorithms. The gap isn’t in anyone’s paperwork. It’s that a buyer running a search never reaches the paperwork. Microsoft and Apple were both sent detailed questions about this reading on August 15, 2026, and told the piece would publish the following week. Microsoft answered on August 19 through its media relations agency. A Microsoft spokesperson said the company “is committed to supporting post-quantum cryptography across our products and platforms and continues to advance support for NIST-standardized algorithms, including ML-KEM and ML-DSA,” and that “SymCrypt’s current and future validation efforts are intended to align with applicable cryptographic standards and customer requirements.” Nothing in that statement disputes the reading of certificate 5313’s policy. Apple didn’t respond before publication, and that needs saying carefully: the address used is Apple’s published media helpline, so the question may never have reached anyone who works on cryptography.
The signing path
CNSA 2.0 has two signature contexts, and conflating them is the easiest way to get this wrong. General digital signature is ML-DSA-87 under FIPS 204. Software and firmware signing is LMS or XMSS under SP 800-208, which is a separate requirement with a separate validated-module picture.
Eleven modules carry LMS in an approved table. Only two of those can generate signatures instead of only verifying them, which matters quite a bit if the job is signing your own firmware.
XMSS is the stranger case. It’s permitted under SP 800-208, CAVP offers no XMSS algorithm testing at all, and no validated module carries it in an approved table. A permitted algorithm with no test path and no implementations isn’t much of an option.
One absence needs to be read correctly. Not one of the 676 modules carries SLH-DSA in an approved table, and that’s a curiosity instead of a gap: NSA’s own FAQ says SLH-DSA “is not part of CNSA and is not approved for any use in NSS.” Nobody’s missing a requirement by not shipping it, and I’d have gotten that backwards without the FAQ.
The clock
January 1, 2027 is an acquisition gate rather than a signing deadline. That distinction changes who has a problem. CNSSP 15 states that by that date, all new acquisitions for national security systems will be required to be CNSA 2.0 compliant unless otherwise noted. NSA’s Dr. Morgan Stern put the same date on a timeline slide in a March 2026 conference presentation: “2027 / New NSS acquisitions / must be QR.”
Those last four words are doing real work. “Unless otherwise noted” is the kind of phrase that decides procurement fights, and the FAQ does not say who gets to note otherwise, on what grounds, or how a vendor would find out. With a supply of two qualifying modules, how that clause gets read may end up mattering more than the deadline it is attached to.
The same presentation supplies the link that makes the module census matter at all. Stern’s verbatim line is that “CNSSP-11 lays out that commercial-off-the-shelf products intended to protect National Security Systems must be validated using the FIPS and NIAP processes.” That’s the sentence tying a policy deadline to this specific list of 676 PDFs. Without it the census is trivia. With it, the validated-module list is the supply of what a buyer’s allowed to buy.
Doug Finke, Chief Content Officer at Global Quantum Intelligence, supplied the number that actually decides whether 2027 is early or late. Finding and remediating cryptography across a complex IT estate takes five years or more, and he was specific that five is a floor and not a ceiling. Nothing in the forecasting argument touches that figure. It is a statement about how long enterprise inventory and replacement takes, and it holds whichever year the machines arrive.
On arrival, GQI expects cryptographically relevant quantum computers to start showing up in 2029. The standing expert survey does not price that specific year, and what it does show is the direction of travel. The Global Risk Institute’s 2025 Quantum Threat Timeline, published March 9, 2026, with Mosca and Piani surveying 26 experts, puts it this way: a cryptographically relevant quantum computer is “quite possible (28-49%) within the next 10 years, and likely (51-70%) in the next 15.”
Run that against the remediation number and the lead time is the whole argument. If finding and replacing cryptography across an estate takes five years at the low end, and the experts who study arrival call it quite possible inside ten, an organization starting its acquisitions in 2027 is already inside the window, whatever the odds turn out to be.
So if you’re buying for a national security system today, your shortlist is two hardware modules. That’s the entire field and not a narrow slice of it, and anyone who needs this in software is still waiting: ten modules cleared validation during the week I was counting, and not one of them changed that number.
The order
The White House reached the same conclusion about CMVP two months ago, and the fix it ordered is not the one a buyer needs.Executive Order 14412, signed June 22, 2026, tells the Secretary of Commerce through the Director of NIST to “revise the processes used by the Cryptographic Module Validation Program to accelerate validations of cryptographic modules.” That is Section 6(b), it carries a 180-day clock, and the clock runs out around December 19, 2026.
Read the verb. Accelerate. The order is about how fast modules get through the queue, and it says nothing about whether anyone can find out what came out the other end. Those are different problems and only one of them is being fixed.
Section 6(c) widens the audience considerably. It directs the FAR Council to propose a rule requiring “covered contractors to comply by December 31, 2030, with NIST’s FIPS, including all applicable FIPS incorporating PQC compliant algorithms.” So this stops being a national security systems question and becomes a federal contracting question, on a proposed rule due the same December week.
Then there’s the document that tells agencies how to actually do it. OMB memorandum M-26-15 runs eleven pages of implementation guidance and cites FIPS 203, FIPS 204, FIPS 205, FIPS 186-5, FIPS 199 and FIPS 201. It never mentions the Cryptographic Module Validation Program, FIPS 140, or a validated module anywhere in the document. The word “validated” does not appear in it.
What the memo does ask for is discovery, and the discovery points the wrong way. Agencies are told to build “a dynamic, continuously updated inventory of all cryptographic assets” using software composition analysis and SBOMs, which is a thorough answer to the question of what you already run. Nothing in the stack answers what you’re allowed to buy.
What this costs
A federal buyer who has to demonstrate post-quantum compliance today has two real options. Read 676 PDFs, and read them knowing the table captions sit below the rows and that the same algorithm string means three different things in three different tables. Or buy on a vendor’s word and find out at validation whether they’d read their own policy the same way.
For two of the 676, even reading is off the table. Certificates 4955 and 4987 link to a security policy the same way every other certificate does. The link works. What comes back is a single page, 5,725 bytes, and its entire text is four words: Security Policy Not Available. The equivalent file for Kryptus runs to 1.9 megabytes.
Neither one is a search.
Where every number came from
Every figure above traces to one of these. All were pulled and read on August 15, 2026.
NIST CMVP validated modules search, the source of the 676 count and the missing post-quantum filter: https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search
NIST CAVP validation search, which does filter by post-quantum algorithm: https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/validation-search
NSA, CNSA 2.0 FAQ, Ver 2.1, December 2024, for the algorithms, the parameter sets, the January 1 2027 CNSSP 15 acquisition language and the SLH-DSA exclusion: https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
Dr. Morgan Stern, NSA, Quantum Resistant Cryptography, Cryptologic Foundation conference, 17 March 2026, for the CNSSP-11 validation requirement and the 2027 timeline slide: https://cryptologicfoundation.org/wp-content/uploads/2026/03/Dr.-Morgan-Stern-QRC_NCF_Conf_20260317.published.pdf
Global Risk Institute, Quantum Threat Timeline Report 2025, the seventh edition, Dr. Michele Mosca and Dr. Marco Piani, evolutionQ, 26 experts surveyed, published March 9 2026. This supersedes the 2024 edition, whose ten-year range was lower: https://globalriskinstitute.org/publication/quantum-threat-timeline-report-2025b/
Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, signed June 22 2026, published in the Federal Register June 25 2026, for the Section 6(b) CMVP acceleration order and the Section 6(c) FAR rule: https://www.federalregister.gov/documents/2026/06/25/2026-12909/securing-the-nation-against-advanced-cryptographic-attacks
OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography, June 2026, the implementation guidance that never mentions CMVP or FIPS 140: https://www.whitehouse.gov/wp-content/uploads/2026/06/M-26-15-Execution-of-the-Migration-to-Post-Quantum-Cryptography.pdf
Microsoft SymCrypt security policy, certificate 5313: https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp5313.pdf
Apple corecrypto Module 18.3 security policy, certificate 5184: https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp5184.pdf
Doug Finke, Chief Content Officer, Global Quantum Intelligence, email interview August 1 2026, attribution and correction cleared by him August 15 2026: https://www.global-qi.com/
The census itself, one row per module and one row per individual mention with line numbers and governing captions, plus the script that produced both: `caption-anchor-census.py`, `pqc-caption-census-2026-08-15.csv` and `pqc-caption-hits-2026-08-15.csv`
1,365 metres under Swedish Lapland, at the bottom of the Kiruna mine, LKAB built a control room where one operator runs several loaders at once. Nobody sits in the machines. In one production area that took output from around 3,000 tonnes to 5,000, and that’s the number that matters, because it only turns up when the engineering is finished instead of announced.
The control room
The automation at Kiruna is real, and the people running it will tell you exactly what it does. Mikael Winsa, a production manager at the mine, described the setup in December 2020: three automated loaders running, five by the end of that month, all worked from a control room at level 1365. The gain came from running more machines at once rather than from any one machine getting faster. “We can boost production in one area from around 3,000 tonne to 5,000 tonnes, since we can run more machines, even at night time,” Winsa said. International Mining reported the same deployment independently that week, down to the control room level and the three-to-five scale up.
That is a hard thing to build. It is also a specific thing, and the specifics get lost almost immediately.
Supervised, not driverless
Kiruna runs supervised automation, which is a product tier and not a synonym for autonomy. The system is Sandvik’s AutoMine Multi-Lite, which the company’s own documentation describes as a system that “enables each system operator to remotely and simultaneously supervise multiple automated Sandvik loaders and trucks” while “performing automated missions in dedicated production areas.” Sandvik sells a separate platform for the thing most people mean by autonomous. Its own page calls AutoMine Core “a Sandvik comprehensive automation platform for fully autonomous operations tailored to mass mining operations,” built around “a fleet of Sandvik underground loaders and trucks sharing the same automated production area.” Multi-Lite supervises machines inside dedicated production areas. Core runs a fleet across large ones. Kiruna bought Multi-Lite Genom.
Almost nobody holds that line in writing. LKAB, Sandvik and the trade press all reach for automated, remote, driverless and autonomous to describe the same machines, sometimes inside the same article.
Five, on the record
The last published count of machines running this way at Kiruna is five, and it dates from December 2023. Joel Kangas, the mine manager, put it plainly in LKAB’s own release: “We are now running five loading vehicles remotely, but the plan is to successively increase the number.” LKAB headlined that release “12 electrical loaders coming to Kiruna, ready for automation.”
Sandvik’s announcement of the same order, issued that week, put it a different way: “With the new equipment, Kiruna’s fleet of Toro LH625iE cable-electric loaders grows to 20 units, all of which will now be automated.” Deliveries under that order ran through the end of 2025. The release does not say when twenty machines would actually be running automated, and “will now be automated” carries no date at all.
Both statements can be true at once. One is a mine manager counting what runs today, the other is a supplier describing an order book, and only one of them is a measurement. LKAB’s press office was asked on 14 August 2026 for the current number and had not responded by publication.
Washington’s number
America’s critical minerals alliance does not mention machines anywhere. FORGE, the Forum on Resource Geostrategic Engagement, launched on 4 February 2026 as the successor to the Minerals Security Partnership, with delegations from 54 countries in the room, Sweden among them. Its Guiding Principles establish two working groups, a Projects Investment Working Group and a Policy Coordination Working Group, and name four challenges: diversifying supply chains, de-risking investment, transparency and traceability, and recycling. The word mining appears once in the entire document, inside the transparency challenge, in a line about “supporting high standards in mining, processing, and recycling.” That is a sentence about how you mine, not about what you mine with. The machines are not in there.
The money ran the same direction. Two days before FORGE launched, the EXIM board approved a direct loan of up to $10 billion for Project Vault, a domestic strategic minerals reserve that State describes as more than double the largest financing in the bank’s history.
For technology, the State Department fact sheet lists “$355 million supporting: The ‘Mine of the Future – Proving Ground Initiative’ to advance next-generation mining technologies and piloting byproduct critical minerals and materials recovery at domestic industrial facilities.” That is one number covering two programmes, with the machines named first. The Department of Energy’s own announcement of that same funding splits it in two: up to $275 million for recovering minerals from industrial and coal byproducts, and up to $80 million for the Mine of the Future proving grounds. Other governments have been more direct about buying capability, whether that is Britain’s sovereign chip programme or Australia backing Diraq to keep quantum manufacturing at home.
Surface first
The United States got its first deployment of this kind in 2025, and it was above ground. Barrick and Komatsu announced on 31 July 2025 that Nevada Gold Mines would run the FrontRunner autonomous haulage system across its surface operations, automating 300 and 230 tonne haul trucks, in what the release called “the first implementation of the system for both companies within the United States.” Komatsu’s Braden Weisheit called it “a major milestone for autonomous mining in America.” Surface haulage and underground loading are different problems, and the underground one is harder.
I keep coming back to how LKAB’s own people describe the work. Five machines running remotely, said out loud, in the same week their supplier announced twenty. That kind of accuracy is worth copying. Right now America’s proving ground for next-generation mining runs on 80 million dollars, inside an announcement that leads with 355.
Where every number came from
LKAB, “More automation at greater depth”, 3 December 2020. Winsa quotes, control room at level 1365, the 3,000 to 5,000 tonne production gain.
US Department of State, 2026 Critical Minerals Ministerial fact sheet, 4 February 2026. FORGE launch, the 54 delegations including Sweden, Project Vault and the EXIM loan, the $355 million line.
US Department of State, FORGE Guiding Principles, 10 July 2026. Working groups and the four named challenges.
How much you trust the AI is what decides whether it makes you sharper or hollows you out. That comes from a survey of 319 knowledge workers who use these tools every week, and it’s the opposite of how most people think about getting good at this. The ones who trusted the model most did the least checking. The ones who trusted themselves did the most.
Trust is the tell
Higher confidence in the AI goes with less critical thinking, and higher confidence in yourself goes with more. That’s the core result of a Microsoft Research and Carnegie Mellon survey presented at CHI 2025, built on 936 first-hand examples of real work tasks.
Sit with that. Trust is the variable, and trust runs inversely to checking. That’s why “just be careful with it” falls apart the moment the thing starts working well. The carefulness goes. Nothing in the experience tells you it left, and a chatbot that hands you something true feels identical to one that hands you something invented, which is how a confident wrong answer cost a company real money.
The job changed
The same paper found the work doesn’t shrink, it moves. Effort in critical thinking shifts “from information gathering to information verification; from problem-solving to AI response integration; and from task execution to task stewardship.”
Read that as a job description, because that’s what it is. You’ve been promoted to supervisor of something that lies convincingly, and nobody sent the memo. Most people never register the change, which is roughly the same blind spot we found inside companies where most of the AI in use was never approved by anybody.
What the EEG showed
The brain study everyone quotes is thinner than the coverage suggests, and it still points the same way. Researchers at the MIT Media Lab put 54 participants through EEG-monitored essay writing in three groups, one using an LLM, one using a search engine, one using nothing. Brain-only participants showed the strongest, most distributed networks. LLM users showed the weakest connectivity. The authors named the accumulated effect “cognitive debt.”
The limits are real, and the authors don’t hide them. On the project site they write that the paper hasn’t been peer reviewed, “thus all the conclusions are to be treated with caution and as preliminary.” They also flag a small sample pulled from one geographic area, and a task that was only ever essay writing in a classroom. Anyone selling you this study as proof that AI rots your brain hasn’t read the disclaimer sitting at the top of it. Treat it as a hint that lines up with better evidence, which is all it claims to be.
The backward move
Applying critical thinking only when the stakes are high is itself risky, and the Microsoft paper says so plainly in its discussion section: “without regular practice in common and/or low-stakes scenarios, cognitive abilities can deteriorate over time.”
So the move everybody reaches for runs backward. Hand the small stuff to AI, save your attention for the big stuff, and you’ve traded off the reps that keep you able to spot a bad answer when it counts. The small stuff was the practice.
Writing yours
A personal AI policy is a few lines you’d write before you need them, not in the middle of the argument with yourself. Mine come straight out of the research above.
Use it to find things, never to decide them. Keep the thesis yours, because the moment the framing comes from the model you’ve handed over the part of the work that was actually yours. Cap borrowed language at a couple of words, about what you’d take from a thesaurus. Link the primary document so a reader can check you, which is what turns the rest of these from good intentions into something anybody can audit. And keep doing a few easy things by hand on purpose, since that’s the practice the research says you’ll otherwise lose.
It doesn’t have to be public. It just has to exist before the week gets busy.
Where every number came from
Lee et al., “The Impact of Generative AI on Critical Thinking: Self-Reported Reductions in Cognitive Effort and Confidence Effects From a Survey of Knowledge Workers,” CHI 2025. Full paper, PDF. The 319 participants and 936 examples, and the confidence finding, are from the abstract on p.1. The three shifts are from the conclusion, independently reported by Campus Technology. The low-stakes practice warning is from the discussion section.
Kosmyna et al., “Your Brain on ChatGPT: Accumulation of Cognitive Debt when Using an AI Assistant for Essay Writing Task,” arXiv 2506.08872, v2 revised December 31, 2025. Study design and the EEG findings are from the abstract. Peer-review status and the stated limits are from the project site.
Featured image: “EEG Recording Cap” by Chris Hope, licensed CC BY 2.0, via Wikimedia Commons. Color graded, not otherwise altered.
The Federal Trade Commission has a two-word name for how the AI industry funds itself: circular spending. It sits in a staff report the agency published in January 2025, describing the deals between the largest cloud companies and the largest AI labs. Not a critic’s phrase. Not a short seller’s. The government’s own words, in a federal document, for the way the money moves.
Here is the arrangement that phrase describes. A cloud company invests billions of dollars in an AI lab. The lab then agrees to spend a large share of that same money buying computing power from the company that just funded it. The money leaves and comes home. The FTC found that these partnerships “include cloud commitments that require AI developers to spend a large portion of their CSP partner’s investment on cloud services from their partner,” and it named that feature, in plain type, circular spending.
That finding has been public for more than a year. So has a second fact, from a different stack of documents: the same small group of companies now floods Washington with more lobbyists than almost any other industry. What nobody has done is lay the two records side by side. Do that, and a single machine comes into focus. A money loop that funds its own demand, and a legal wall going up to keep anyone from regulating it. Same companies. Both halves. It is the first thing to understand about the AI economy, and it is hiding in plain public records.
The loop
The loop runs through three partnerships, and the FTC studied all three. The agency’s 6(b) study examined Microsoft and OpenAI, Amazon and Anthropic, and Google and Anthropic, the largest such deals in the industry. As the report tabulated the publicly reported figures through September 2024, Microsoft had put 13.75 billion dollars into OpenAI, Amazon 8 billion into Anthropic, and Google 2.55 billion into Anthropic. Microsoft’s own quarterly filing that fall put its total funding commitments to OpenAI at 13 billion, accounted for under the equity method.
These are not ordinary stock purchases. The FTC found the deals hand the cloud partners “significant equity and certain revenue-sharing rights,” and leave the door open for one company to fully acquire its partner down the line. They carry “consultation, control, and exclusivity rights,” including board seats and preferential treatment. The company writing the check also gets a hand on the wheel.
Then the money comes back as cloud spending. That is the circular part, and the FTC was direct about why it matters. The structure, in the agency’s reading, is one avenue through which a cloud provider may aim to reduce the size of the loss it might otherwise take on the billions it pours into a partner. The lab gets discounted computing it could not afford on the open market. The cloud gets its money returned as revenue, plus equity, plus a view inside a rival’s operation. The report found the arrangement reaches all the way down to the silicon, with “co-development plans for CSP-designed semiconductor chips” tuned to the labs’ models. Money, equity, control, and custom hardware, all moving in a ring.
The entanglement runs deeper than money. The FTC found the partnerships give the labs discounted access to the scarce computing they cannot get elsewhere, let the two sides embed their own engineers inside each other’s companies, and share training data along with detailed performance and financial figures on the models themselves. The people, the data, and the hardware are braided together as tightly as the cash. Unwinding one company from the arrangement would mean pulling all of it apart at once.
The agency also listed risks it thought were worth watching. In Section 5 of the report, staff flagged that these partnerships could limit other AI developers’ access to computing power and engineering talent, the two scarcest inputs in the field. They flagged that the deals could raise the cost of switching providers, through exclusivity terms and technical lock-in that make leaving expensive and slow. And they flagged that the arrangements hand the cloud partners access to sensitive financial and technical information, including confidential chip designs and a partner’s own customer and revenue numbers, which those same cloud companies could use to build products that compete with the labs they fund.
That section is contested, and the objection came from inside the agency. Commissioner Andrew Ferguson, joined by Commissioner Melissa Holyoak, filed a concurring and dissenting statement on January 17, 2025. Three days later Ferguson became Chairman of the FTC, the job he still holds. He voted to approve the report and said why: it “sheds light on three Big Tech-AI partnerships,” and “Congress, state officials, and the public deserve to understand how these partnerships work.” What he objected to was Section 5. The study was fast and narrow, he wrote, covering three partnerships between five companies, and “the limited, brief nature of the study should foreclose the drawing of broad conclusions about the AI industry and its future, or even about the partnerships themselves.” His instruction to readers was blunt: “Readers should skip Section 5 of the Report, or read it with tremendous skepticism.”
Fine. Skip it.
Nothing else in this piece needs it. The money loop, the equity and revenue-sharing rights, the board seats, the chip co-development, the embedded engineers, the shared training data and financial figures, all of that sits in the parts of the report Ferguson voted to publish and called valuable, drawn from what he described as “company documents produced in response to the Commission’s Section 6(b) orders.” The speculation about what it might mean is the part he wanted struck. What these companies actually signed is not in dispute.
It is worth noting what Ferguson did not say. He did not say the arrangement is harmless. His own statement holds that the Commission “must remain a vigilant competition watchman, ensuring that Big Tech incumbents do not control AI innovators in order to blunt any potential competitive threats.” His argument is that a study run in under a year should not be the last word. That is a reasonable thing for a regulator to say, and it cuts both ways. If a year was not enough to draw conclusions, it was not enough to rule anything out either.
The report’s own limits are real and worth stating plainly. It covers three partnerships. It reflects what the companies disclosed as of September 2024. It was aggregated to protect trade secrets. It says outright that it is “not a formal legal or economic analysis” and accuses no one of breaking the law. Circular spending is not a crime. The concern here is not illegality. It is that this structure concentrates enormous power in very few hands, and that the ordinary means of checking that power are being closed off one at a time.
What happened next
The FTC published those numbers in January 2025. Every one of the three partnerships has been rewritten since, and the public record of what replaced them is the strongest evidence in this piece.
Start with Amazon and Anthropic, because the arithmetic is right there in the announcement. On April 20, 2026, the two companies said Amazon “is investing $5 billion in Anthropic today, with up to an additional $20 billion in the future,” securing “up to 5 gigawatts (GW) of capacity for training and deploying Claude.” In the same announcement, Anthropic said: “We are committing more than $100 billion over the next ten years to AWS technologies.” That covers Amazon’s own Trainium chips, Trainium2 through Trainium4, plus Graviton processors and the option to buy future generations of Amazon silicon.
Read those two sentences together. Amazon puts in up to 25 billion dollars. Anthropic commits to spend more than 100 billion dollars back with Amazon. The purchase commitment running the other way is roughly four times the size of the investment. That is the arrangement the FTC described in January 2025, at ten times the scale, announced in public by the companies themselves. It is also a large share of the 2026 capex wave now reshaping the American power grid.
Google and Anthropic expanded too. On April 6, 2026, Anthropic announced a deal with Google and Broadcom for “multiple gigawatts of next-generation TPU capacity that we expect to come online starting in 2027,” Google-built chips supplied through Broadcom, with the vast majority of the capacity sited in the United States. Anthropic did not disclose the dollar terms. It did say its run-rate revenue had “surpassed $30 billion,” up from roughly $9 billion at the end of 2025, and pointed back to an earlier pledge to “invest $50 billion in strengthening American computing infrastructure.”
Microsoft and OpenAI went the other direction on some terms. On April 27, 2026, Microsoft announced an amended agreement. Its license to OpenAI’s models and products runs through 2032 but is “now non-exclusive.” OpenAI “can now serve all its products to customers across any cloud provider.” Microsoft “will no longer pay a revenue share to OpenAI.” Those are real changes, and they loosen exactly the kind of exclusivity the FTC described.
The same announcement says what did not change. Microsoft “remains OpenAI’s primary cloud partner,” and OpenAI’s products still ship first on Azure “unless Microsoft cannot and chooses not to support the necessary capabilities.” Microsoft “continues to participate directly in OpenAI’s growth as a major shareholder.” And revenue share payments from OpenAI to Microsoft “continue through 2030, independent of OpenAI’s technology progress, at the same percentage but subject to a total cap.”
So here is the honest accounting. One leg of the arrangement got looser. The other two got dramatically larger. Ferguson was right that a one-year study could not tell you where this was going. Sixteen months of company announcements can. The money still leaves and comes home, and the sums involved have gone from billions to hundreds of billions.
The shield
The companies inside the money loop are also among the largest lobbying forces in Washington. Public Citizen, a nonprofit watchdog, found that more than 3,500 lobbyists worked on AI issues in 2025, more than one in four of every registered federal lobbyist in the country. The overwhelming majority of that work, 82 percent of it, was done on behalf of corporate interests. The AI lobbying force grew 168 percent between 2022 and 2025. Sludge, working the same disclosure filings, put the precise count at 3,570 lobbyists, or 26 percent of everyone registered.
The growth is steeper than even that suggests. Public Citizen found the number of distinct lobbyist-and-client relationships working AI jumped 265 percent over those three years, from 1,672 to 6,110. Software and services became the single largest lobbying sector in the country by that measure, with about 1,448 lobbyists, close to 30 percent of the entire AI lobbying push. Lobbyists working specifically on data centers grew from 68 in 2022 to more than 400 in 2025, close to six times as many. An industry that barely registered on K Street four years ago now sits near the center of it. I have written before about the money behind AI policy and about the policy revolving door that moves people between the agencies and the firms they regulate.
Look at who is doing the spending. Public Citizen’s count of the top AI-lobbying operations in 2025 lists the US Chamber of Commerce with 91 lobbyists, Microsoft with 63, Meta with 55, Intuit with 51, and Amazon with 48. The names at the top of that list are the same names inside the money loop.
And the policy showing up is built to remove the biggest threat to the loop. On December 11, 2025, the White House issued an executive order titled “Ensuring a National Policy Framework for Artificial Intelligence.” It orders the Attorney General to stand up an AI Litigation Task Force whose only assignment is to challenge state AI laws in court. It directs the Commerce Department to identify state AI laws it considers onerous and hand them to that task force. It moves to cut states that keep the targeted regulations off the non-deployment portion of federal BEAD broadband funding, the money for planning, administration, and outreach, unless they fall in line. And it reaches further still, directing the FCC to weigh a federal reporting standard that would override conflicting state rules, and the FTC to spell out when a state law that forces changes to an AI model’s output is preempted by federal law. States have been the one level of government actually writing rules for this industry, and the fight over state AI laws had been running in 45 of them. The order is designed, layer by layer, to preempt them. It is the enforcement arm of the White House framework released earlier that year.
No one can prove the lobbyists wrote that order, and I am not going to claim they did. But the shape is hard to miss, and it is not the first time the question has come up about Big Tech’s hand in an executive order. The firms that dominate the money loop are among the heaviest spenders shaping AI policy, and the policy that arrived, federal preemption of state law, happens to sweep away the one venue that had started to regulate them. Public Citizen’s J.B. Branch put the stakes plainly: “Congress now has a once-in-a-generation opportunity to decide whether AI becomes another chapter in the story of unchecked corporate power.”
I asked Public Citizen how the two halves fit together. Eileen O’Grady, a researcher there and co-author of Generative Influence, told Laterstack:
“Last year’s AI lobbying surge and the preemption push are two parts of the same play. Big Tech spent heavily to shape federal policy and is effectively cashing in through the government’s attempt to wipe out state laws that would have created common sense guardrails for the industry. We can expect to see federal AI lobbying continue to intensify as preemption plays out in Congress and the courts, especially if bills like the draft Great American AI Act advance. We might also see more pressure directed at the executive branch, which has become the industry’s most effective route now that the direct legislative attempts have stalled.”
The bill she names is real and not yet law. Representatives Jay Obernolte, a Republican from California, and Lori Trahan, a Democrat from Massachusetts, released the Great American AI Act as a discussion draft on June 4, 2026. It has not been formally introduced. It carries a three-year preemption of state laws governing how AI models are built, while leaving states their authority over how those systems get used.
Her last point is the one to sit with. She reads the executive branch as the industry’s most effective route now that the direct legislative push has stalled. The December order came from the executive branch.
The same hands
Set the two records next to each other and the machine is whole. Microsoft and Amazon are principals in the arrangement the FTC called circular spending. Microsoft and Amazon also sit second and fifth on the list of the country’s biggest AI lobbying operations. The hands that built the loop are the same hands building the wall. This is not two stories about the AI industry. It is one story about a small number of companies that fund themselves in a circle and are working, out in the open, to keep anyone from stepping in.
None of the individual facts here are secret. The FTC report is on the agency’s website. Public Citizen published its lobbying count. The executive order is posted on the White House site. The partnership terms are on the companies’ own newsrooms. The pieces have been sitting in the open, in separate places, waiting for someone to set them on the same table. Standard Oil looked permanent too, right up until someone wrote the whole thing down in one place.
A quick word on why I am writing this. I am not trying to tell you what to think. I want to lay out what the public documents actually say and let you weigh it for yourself. How these companies are funded, and who gets to set the rules for them, touches things people feel directly, like prices, competition, and how much real choice they have. You can follow all of that without taking a political side, and it is already on the record.
No brakes
Two forces usually correct a concentration of corporate power, the market and the government, and in the AI economy both are being closed at once. The market is the first. Competitors move in, customers leave, the advantage erodes on its own. But a loop that funds its own demand does not wait on the market’s permission to keep running. Government is the second. Regulators and legislators draw the lines. But you cannot regulate a machine whose owners are writing the rules, and the December order is aimed squarely at the level of government that was trying.
The bill for all of it lands somewhere. Five gigawatts here, multiple gigawatts there, and the power and water to run them come from somewhere real. In Arizona that has already turned into the data center bill you never voted on, paid through electricity rates by people who were never asked.
That is the machine, at least the part you can already prove from public documents. It is also only two layers of it. The full stack runs from the chips and the packaging bottleneck that decides how many of them get built, up through the clouds and the labs, to the money loop and the law wrapped around it. The rest of this series follows it the whole way down.
Laterstack contacted Microsoft, Amazon, Google, OpenAI, and Anthropic for this piece. None provided an on-the-record comment.
Where every number came from
Every figure and quote in this piece comes from a public document. Here is where each one lives, in the order the claims appear.
The loop
1. The phrase “circular spending,” the cloud commitment finding, the equity and revenue-sharing rights, the board seats and exclusivity terms, the chip co-development, the discounted compute, the embedded engineers, the shared training and performance data, the Table 1 investment figures, and the report’s own scope limits: FTC Staff Report on AI Partnerships and Investments 6(b) Study, Federal Trade Commission, January 2025. The circular spending language appears in Finding 3 on page 19.
2. Microsoft’s own accounting of its OpenAI position, stated as “total funding commitments of $13 billion” under the equity method: Microsoft Form 10-Q for the quarter ended September 30, 2024, U.S. Securities and Exchange Commission. Note that this figure and the 13.75 billion in FTC Table 1 are not identical. The FTC tabulated publicly reported investment; Microsoft reported its own booked funding commitments. Both are cited here as each states them.
7. The non-exclusive license through 2032, the any-cloud provision, the end of Microsoft’s revenue share payments to OpenAI, the primary cloud partner and major shareholder language, and the revenue share running to Microsoft through 2030 subject to a cap: The next phase of the Microsoft-OpenAI partnership, Microsoft, April 27, 2026.
The shield
8. The AI lobbyist count, the corporate share, the growth figures from 2022 to 2025, the data center lobbyist growth, the lobbyist-and-client relationship growth, the software and services sector share, the top lobbying operations by headcount, and the J.B. Branch quote: Generative Influence, by Mike Tanglis and Eileen O’Grady, Public Citizen, February 24, 2026.
9. The 3,570 lobbyist count, the 26 percent share of all registered federal lobbyists, and corroboration of the top lobbying employers: AI Boom on K Street: One in Four Lobbyists Now Work on AI, by David Moore, Sludge, February 24, 2026.
10. Federal lobbying spending by the AI developers themselves, $3.13 million by Anthropic and $2.99 million by OpenAI in 2025: AI’s Biggest Builders Are Now Its Biggest Lobbyists, by Phoebe Liu, Forbes, February 20, 2026.
13. Eileen O’Grady’s comment was provided to Laterstack by email on July 22, 2026, and her attribution was confirmed by her on July 23, 2026.
Frequently Asked Questions
What is circular spending in AI?
Circular spending is the FTC’s term, from its January 2025 staff report, for cloud commitments that require AI developers to spend a large portion of their cloud partner’s investment back on that partner’s cloud services. The money is invested, then returns as revenue.
Which companies did the FTC 6(b) study cover?
Three partnerships between five companies: Microsoft and OpenAI, Amazon and Anthropic, and Google and Anthropic. The report reflects what those companies disclosed as of September 2024.
Did anyone at the FTC disagree with the report?
Yes. Commissioner Andrew Ferguson, joined by Commissioner Melissa Holyoak, voted to approve publication but dissented from Section 5, the Areas to Watch section. Ferguson wrote that readers should skip Section 5 or read it with tremendous skepticism. He became FTC Chairman three days later.
How much are these partnerships worth now?
In April 2026 Amazon announced a 5 billion dollar investment in Anthropic with up to 20 billion more, and Anthropic committed more than 100 billion dollars over ten years to AWS technologies. Anthropic separately signed with Google and Broadcom for multiple gigawatts of TPU capacity starting in 2027. Microsoft and OpenAI amended their agreement to make Microsoft’s license non-exclusive.
What does the December 2025 executive order do?
Executive Order 14365 directs the Attorney General to create an AI Litigation Task Force to challenge state AI laws, has Commerce identify state laws it considers onerous, conditions the non-deployment portion of BEAD broadband funding, and directs the FCC and FTC toward federal standards that would preempt conflicting state rules.
How many lobbyists work on AI?
Public Citizen found more than 3,500 lobbyists worked AI issues in 2025, more than one in four of every registered federal lobbyist. Sludge put the count at 3,570, or 26 percent. Public Citizen found 82 percent of that work was on behalf of corporate interests.
In short: Britain is betting that a public, procurement-led route to sovereign AI compute can keep pace with private buildouts moving several times faster. The government’s own flagship supercomputer was committed, cancelled, and revived across three and a half years, which is why the bet is hard. Asked about the gap, the government frames the slower pace as a deliberate two-track strategy rather than slippage.
In Edinburgh, the public purse paid for about £31m of housing for a supercomputer that never arrived. The machine, a national exascale system committed in October 2023 as part of a £900m compute investment, was shelved less than a year later when the incoming government cut £1.3bn of promised technology and AI funding. The shell of the building went up. The computer inside it did not.
That distance between the housing and the hardware is the sharpest picture of the question now sitting under British AI policy. A compute strategy built on public money and public procurement has to move fast enough to matter, at the exact moment private capital is racing past it.
A supercomputer committed, cancelled, then rebuilt
The flagship of Britain’s public compute plan has been rewritten twice in under three years. The original £800m Edinburgh exascale machine, paired with £500m for the national AI Research Resource, was cancelled in August 2024 as part of a wider £1.3bn cut, after the university had already spent £31m preparing the site. Ten months later the project came back, revived at up to £750m at the June 2025 Spending Review, with a firm plan to come online in early 2027.
The revived machine is a smaller ambition than the one it replaced. As one of its own architects put it, “we’re no longer calling this the exascale system, that moment has passed.” The department’s position at the time of the cut was straightforward: the money had been promised by the previous administration but never allocated in a budget. Read fairly, the episode is less a story of waste than a story of what public compute is exposed to. It lives and dies by fiscal cycles, and a spending review can restart the clock on hardware that takes years to build.
Public compute can move fast when it is funded and left alone
Britain’s public route has already proven it can deliver quickly when a project survives the budget process intact. The AI Research Resource’s flagship, Isambard-AI in Bristol, launched in July 2025 as a £225m facility built on 5,448 NVIDIA GH200 superchips, and opened to researchers and startups on schedule. The government’s Compute Roadmap sets a target of scaling the resource from 21 AI ExaFLOPS in 2025 to 420 by 2030.
So the constraint is not capability or ambition. Isambard-AI shows the state can stand up world-class compute on a normal timeline. The constraint is continuity, whether a project can cross several budget cycles without being paused, rescoped, or downgraded along the way.
The private buildout runs on a different clock
Private AI infrastructure in Britain is now being measured in months where the public flagship is measured in years. NVIDIA and its partners committed in September 2025 to up to £11bn and 120,000 Blackwell Ultra GPUs, built and operating by the end of 2026. Microsoft added a $30bn UK commitment across 2025 to 2028, including the country’s largest supercomputer. Nscale, a UK company incorporated only in May 2024, raised a $1.1bn Series B, the largest in European history, and reached a $14.6bn valuation by March 2026.
The pattern is not confined to Britain. In Texas, the first site of the $500bn Stargate program went from a mid-2024 construction start to energized within about twelve months, which its builder called a remarkable feat of speed. Set against the wider wave of AI capital spending, the private timeline is the benchmark the public one is implicitly being judged against.
The real bottleneck is power and process, not vision
What separates the two clocks is less about money than about what money cannot buy quickly: connections and permissions. Analysts at Deloitte note that a data centre can be built in a year or two, but face “a seven-year wait on some requests for connection to the grid.” Bessemer’s infrastructure team puts the same gap at 12 to 18 months to build against five to seven years to connect.
Private operators solve this by bringing their own power on-site and buying their way around the queue. Public procurement carries the opposite load. It layers spending reviews, value-for-money tests, and competitive tendering on top of the same grid and construction limits, and each of those steps is a place the clock can stop.
The government calls it a two-track approach
Asked how it reconciles a slower public route with faster private builds, the Department for Science, Innovation and Technology did not dispute the pace. Responding to Laterstack, a government spokesperson provided the following statement:
We are taking a two-track approach to ensure the UK has the AI infrastructure it needs. We are supporting the rapid rollout of data centres now, including through AI Growth Zones across the UK, while also progressing the AI Hardware Plan to ensure that advanced compute is developed, deployed and scaled here too.
There is a real strategy in that answer. The £1.1bn AI Hardware Plan announced in June 2026, the £500m Sovereign AI Unit backing British companies, and the AI Growth Zones together sketch a plan to host fast private capacity now while building domestic capability underneath it. The tell is subtle. The question was about speed, and the answer is about sequence. The government is not disputing that its own route is slower. It is arguing the slower track is the one that ends in genuine sovereignty.
Two definitions of sovereign, and a new government
Britain is about to get a second opinion on what sovereign compute should even mean. The current approach treats sovereignty as something achieved through partnership, with NVIDIA supplying the chips, Microsoft the cloud, and Nscale the domestic operator. A different reading is arriving with a change of government. Andy Burnham is expected to become Prime Minister around 20 July, and his team has signalled a shift toward British ownership and away from what they view as an overly US-centric approach, with AI Growth Zones among the policies they may reassess.
That tension is the one worth watching, because both camps use the same word to mean opposite things. Sovereignty through the fastest available partnership, or sovereignty through ownership and control even if it costs time. It is the same fork that runs through Europe’s sovereign cloud debate and the interventions governments are now willing to make to keep strategic technology at home. Britain has spent two years answering it one way. The incoming government may answer it another.
The speed test, then, is not really about whether Britain can build fast AI compute. Isambard-AI shows it can. It is about whether a public strategy can hold a straight line for the three to five years a sovereign compute base takes to build, across budgets, spending reviews, and now a change of Prime Minister, while the private clock keeps running at full speed.
Featured image: UK Compute Roadmap. Contains public sector information licensed under the Open Government Licence v3.0.
Frequently Asked Questions
Can the UK build sovereign AI compute fast enough?
On capability, yes. Isambard-AI in Bristol launched on schedule in July 2025. The risk is continuity, because the national supercomputer was committed, cancelled, and revived across three and a half years, which is where the public route loses time to private builds.
Why was the Edinburgh supercomputer cancelled?
In August 2024 the incoming government cut £1.3bn of promised technology and AI funding, including £800m for the Edinburgh exascale machine, after £31m had already been spent on the site. It was revived at up to £750m in June 2025, no longer as an exascale system, to come online in early 2027.
What is the UK’s two-track AI compute approach?
The Department for Science, Innovation and Technology describes it as supporting the rapid rollout of private data centres now through AI Growth Zones, while progressing the £1.1bn AI Hardware Plan to develop, deploy and scale domestic compute capability underneath.
The U.S. federal government is targeting the transition away from vulnerable public-key cryptography by around 2030, according to NIST and NSA guidance. SEALSQ’s QSOC constellation targets full operational capability in 2033. That is roughly a three-year window where a globally available, sovereign-grade satellite answer does not yet exist, and SEALSQ Corp, a small Nasdaq company, is among those racing to build one.
What QSOC Actually Is
The Quantum Spatial Orbital Cloud is a 100-satellite low-Earth-orbit constellation jointly operated by SEALSQ and WISeSat.Space, both subsidiaries of WISeKey International Holding. The deployment runs from now through 2033, when SEALSQ targets Full Operational Capability. As of June 2026, 21 satellites are already in orbit. The constellation is designed to deliver quantum key distribution, quantum random number generation, and post-quantum identity services as a subscription offering to enterprises and governments worldwide.
Carlos Moreira, SEALSQ’s CEO, told Laterstack the recent Miraex acquisition “strengthens our execution capabilities and enhances vertical integration across critical components of the ecosystem.” The company “does not foresee any material delay to the deployment roadmap.”
That is the on-record commitment to 2033. The cryptography migration timeline, meanwhile, does not move.
The Three-Year Gap
NIST’s post-quantum cryptography migration guidance points to 2030 as the practical window for federal contractors to begin retiring RSA-2048 from production systems. The NSA’s CNSA 2.0 suite references the same window, and FedRAMP guidance points at it. Several studies published in 2025, which Laterstack covered, suggested that advances in quantum computing could compress estimates for when RSA-2048 becomes vulnerable, raising concern about the 2030 transition timeline.
QSOC reaches Full Operational Capability in 2033. That gap is roughly three years where federal customers know they have to migrate and a globally available, sovereign-grade satellite-based post-quantum infrastructure may not yet exist. It is a window that does not appear on the FedRAMP procurement calendar, in CNSA 2.0, or in NIST’s published migration guidance.
The trade press has covered the cryptographic timeline. It has covered the QSOC deployment. In our reading, it has not yet connected the two.
Who QSOC Is Built For
Moreira would not name specific QSOC customers, citing confidentiality. He did name the five buyer categories SEALSQ is actively engaged with: government agencies, defense and security organizations, sovereign digital infrastructure operators, critical infrastructure providers, and financial institutions. The demand, he said, is being driven by “the growing need for quantum-resilient communications, trusted digital identities, and secure data sovereignty solutions in preparation for the post-quantum era.”
Five buyer classes is a market structure, not a customer list. It is the slate of federal-and-equivalent purchasers every G7 procurement office is preparing for, and SEALSQ is positioning itself as one of the few companies publicly pursuing all five segments through a single integrated platform.
Trust Infrastructure Root to Qubit
Moreira sums up what SEALSQ is building in a single phrase: “an end-to-end trust infrastructure root to qubit.” In plain terms, that is one company running the whole chain, the chips, the digital identities, the satellites, the networks, and the cloud that ties them together.
That matters because most of the industry has not built it that way. Companies like IBM, Cisco, and Toshiba are strong in specific parts of the post-quantum puzzle. SEALSQ is betting on putting all of those parts under one roof. Moreira expects the market to move his way. He told Laterstack he sees “increasing consolidation and partnerships across the industry as organizations recognize that post-quantum security is not a standalone product but an ecosystem challenge.”
That is the bet underneath the satellite race. The way we read it, one of two things happens. Either the all-in-one approach proves right and SEALSQ becomes a serious early player in post-quantum infrastructure for governments and large institutions, or a bigger company copies the model, buys its way to the same setup, and SEALSQ ends up as the one that proved it could work.
What It Means For The Apps You Use
Most consumers will not interact with QSOC satellites directly. The infrastructure runs above the apps, not inside them. If you have a bank account, government benefits, healthcare records, or any service that depends on encryption for privacy, that encryption is on the migration calendar.
The banks, insurance carriers, and healthcare providers that move early on post-quantum infrastructure are better positioned to maintain trust after 2029. Institutions that delay migration may face significantly higher long-term security risks.
Consumers will likely see more banks, insurers, and healthcare providers publicly communicating their post-quantum migration strategies in the years ahead.
The Prediction
The bigger question is whether the major vendors adopt a similar approach. IBM, Cisco, and Toshiba all have the balance sheets to do it, and none has moved publicly so far. If the integrated-stack thesis proves correct, larger vendors may feel growing pressure to pursue similar strategies through partnerships, acquisitions, or internal development.
In our reading, the consolidation question is tied to which institutions maintain trust past 2029. The three-year gap, from the roughly 2030 transition target to QSOC’s 2033 timeline, is the procurement officer’s planning problem more than the cryptographer’s. Watch the procurement orders as much as the press releases.
Either way, post-quantum infrastructure is moving from a research milestone into a procurement question.
Frequently Asked Questions
What is the Quantum Spatial Orbital Cloud (QSOC)?
QSOC is a planned 100-satellite low-Earth-orbit constellation jointly operated by SEALSQ and WISeSat.Space, both subsidiaries of WISeKey International Holding. It is designed to deliver quantum key distribution, quantum random number generation, and post-quantum identity services as a subscription offering. Deployment runs from now through 2033, when SEALSQ targets Full Operational Capability. As of June 2026, 21 satellites are already in orbit.
Who is SEALSQ Corp?
SEALSQ Corp (Nasdaq: LAES) is a Geneva-based semiconductor and quantum technology company, and a subsidiary of WISeKey International Holding. Carlos Moreira is the CEO.
What is the 2030 cryptographic migration window and why does it matter?
NIST’s post-quantum cryptography migration guidance points to 2030 as the practical window for federal contractors to begin retiring RSA-2048 from production systems. The NSA’s CNSA 2.0 suite and FedRAMP guidance reference the same window. Several studies published in 2025 suggested that advances in quantum computing could compress estimates for when RSA-2048 becomes vulnerable, raising concern about the 2030 transition timeline.
What are the main alternatives to QSOC for post-quantum satellite infrastructure?
Companies like IBM, Cisco, and Toshiba are strong in specific parts of the post-quantum puzzle, but none has publicly committed to a sovereign satellite-grade post-quantum infrastructure deployment. SEALSQ is positioning itself as one of the few companies publicly pursuing the full integrated stack: semiconductors, identities, satellite communications, quantum-resilient networks, and trusted cloud services.
An npm supply chain attack that crossed three open-source ecosystems and shipped the whole way with valid SLSA Build Level 3 provenance, the standard federal procurement leans on, is now an open-source project on GitHub. The group behind it, TeamPCP, published the Mini Shai-Hulud worm’s full source code on May 12, the day after compromising TanStack.
The supply chain attack story is no longer about who got hit. It is about what the defenders thought they had locked down, and didn’t.
Socket flagged the malicious SAP mbt package, the npm-distributed Cloud MTA Build Tool, as known malware. Source: Socket.
The next day the worm jumped ecosystems. PyTorch Lightning’s PyPI release for April 30 (version 2.6.2) carried a credential-stealing payload that downloaded the Bun JavaScript runtime and executed an 11 MB obfuscated harvester. By that afternoon, the npm intercom-client (versions 7.0.4 and 7.0.5) was tainted. Hours later, the Packagist build of intercom/intercom-php (5.0.2, twenty million lifetime downloads) carried the same payload. A Security Boulevard writeup reported credentials exposed across more than 1,800 developer repositories.
SLSA Build Level 3 is the highest-confidence provenance standard for software integrity. It is the layer federal procurement leans on. CNSA 2.0 references it. FedRAMP guidance points at it. The promise: if you trust the build environment and verify the provenance attestation, you trust the artifact.
Public research reported that later Mini Shai-Hulud packages were published with valid SLSA Build Level 3 provenance attestations. Public research showed that provenance checks can still pass when the trusted publishing pipeline itself is compromised, which is what happened here.
What Federal Contractors Pulled
Feross Aboukhadijeh, Socket’s CEO, told Laterstack that federal contractors who pulled the tainted packages between late April and mid-May need to treat the exposure as build-environment-wide, not dependency-tree-wide.
“If a federal contractor pulled a tainted package into dev, CI, or a build environment, the exposure may include npm tokens, PyPI credentials, GitHub credentials, cloud secrets, and CI/CD credentials,” Aboukhadijeh said. “The meaningful remediation is token rotation, build environment review, artifact cache review, and confirmation that no follow-on publishing activity occurred.”
That is the supply chain attack consequence the trade press has largely skipped on the federal procurement side. A clean dependency tree does not guarantee a clean build environment, and a clean build environment in early May 2026 cannot be assumed.
What It Means For The Apps You Use
SAP’s Cloud MTA Build Tool deploys the back-office systems that handle payroll, HR records, and supply chain logistics for thousands of companies. PyTorch Lightning is the framework that trains AI models for products consumers use every day, from voice assistants to enterprise chatbots. The intercom-client and intercom-php packages power customer support chat across thousands of consumer-facing apps.
If you spoke to a customer service bot in late April, or used a workplace platform built on SAP, the infrastructure you touched may have flowed through code compromised by Mini Shai-Hulud. The harvested credentials open the door to follow-on attacks against the companies running those services, not just the developers who built them.
A supply chain attack on developer infrastructure becomes a consequence for the people who use the products that infrastructure builds. The trade press misses that line.
TeamPCP Open-Sourced the Worm
On May 12, the day after the TanStack compromise was disclosed, TeamPCP published the full Mini Shai-Hulud worm source code to a public GitHub repository. Installation documentation included.
The supply chain attack threat surface has changed. The attack mechanism is now portable to any registry where stolen maintainer credentials can publish trusted updates. PyPI, npm, Packagist, Cargo, Maven, RubyGems. Any registry that respects maintainer ownership is a candidate.
The Defenders Were Faster
Socket flagged the malicious PyTorch Lightning release 18 minutes after publication. The Lightning AI community pulled the compromised versions and shipped a clean release within 42 minutes total. Lightning’s postmortem named Socket’s contribution directly: “vulnerability scanning services including socket.dev also detected the attack, reported to us on GitHub and Discord, and published detailed technical analysis that aided our response.”
Aboukhadijeh told Laterstack that PyTorch Lightning’s handling is “pretty much the gold standard for disclosure.” Lightning disclosed fast to its open-source community and followed with a transparent postmortem that named the researchers who helped, including Socket. That is what a good-faith response to a compromise looks like.
That counter-story is what federal procurement should be funding, not just provenance.
The Prediction
Provenance was the federal procurement bet. Provenance failed. The next bet has to be runtime detection and rapid community response, the two things that actually caught Mini Shai-Hulud.
What this means for the everyday person buying apps or using a customer service chatbot is that the security of the software you use every day depends on a small set of dedicated research teams catching attacks faster than attackers can iterate. The worm’s source code is now public, but these groups change tactics with every wave, which means any published analysis of how this one worked is already dated by the time the next campaign lands. You don’t write this defense as a playbook once. It comes down to a small set of research teams catching each new variant faster than the last. The cycle is accelerating in both directions.
Watch the next FedRAMP and CNSA guidance updates. The supply chain attack defense doctrine is about to shift.
Frequently Asked Questions
What is Mini Shai-Hulud?
Mini Shai-Hulud is a self-propagating worm developed by the threat group TeamPCP. Between April 29 and May 12, 2026, it compromised packages across the npm, PyPI, and Packagist ecosystems, harvested developer credentials and cloud secrets, and used those credentials to publish further malicious package versions. TeamPCP published the worm’s source code on GitHub on May 12.
Who is TeamPCP?
TeamPCP is a financially motivated threat group tracked publicly since late 2025. Google Threat Intelligence Group tracks the group as UNC6780. Other observed aliases include DeadCatx3, PCPcat, ShellForce, and CipherForce. Prior campaigns hit LiteLLM, Telnyx, and Xinference before the Mini Shai-Hulud cascade.
What is SLSA Build Level 3 and why does it matter here?
SLSA Build Level 3 is the highest-confidence software provenance standard maintained by the Open Source Security Foundation. It certifies that an artifact was built in a hardened, auditable environment with verified provenance attestations. CNSA 2.0 and FedRAMP guidance reference it. Mini Shai-Hulud packages were published with valid SLSA Build Level 3 provenance attestations. Public research showed that provenance checks can still pass when the trusted publishing pipeline itself is compromised, which is what happened here.
What should federal contractors do who pulled tainted packages?
Per Socket: treat the exposure as build-environment-wide. Rotate npm, PyPI, GitHub, cloud, and CI/CD tokens. Review the build environment, the artifact cache, and any follow-on publishing activity from the compromised window.
Korial, formerly Energy Robotics, builds hardware-agnostic AI software for autonomous industrial inspection, running robots and drones across hazardous sites like refineries and chemical plants.
It spun out of TU Darmstadt’s Team Hector after winning Total’s ARGOS Challenge in 2017, the first autonomous oil-and-gas inspection robot.
The platform has logged over a million autonomous inspections across five continents for Shell, BP, BASF, and others, removing more than 30,000 hours of hazardous human labor.
In May 2026 it rebranded to Korial to signal the shift from inspecting on individual robots to running autonomy as one enterprise operating layer.
In 2017 a team of roboticists from the Technical University of Darmstadt won a contest most of the technology press never noticed. The ARGOS Challenge, run by the French oil major Total, asked competitors to build the first autonomous ground robot that could run complex inspection missions on an oil and gas platform with no human steering it. The Darmstadt group, known as Team Hector, won it. Then they did the part almost no academic team manages. They turned the prize into an autonomous industrial inspection company.
That company spent the next several years quietly becoming the backbone of the field. Founded in 2019 as a spin-out of TU Darmstadt, Energy Robotics has now logged more than a million autonomous inspections across five continents, work that took more than thirty thousand hours of hazardous duty off human shoulders at facilities run by Shell, BP, Repsol, BASF, Merck, and E.ON. In May 2026 the company rebranded as Korial. The name change looks like a coat of paint. It is closer to a thesis.
The bet underneath the rebrand
Most robotics companies sell robots. Korial’s founding bet was that the robot is the least durable part of the problem. Hardware gets better, cheaper, and replaceable every cycle. What does not commoditize is the layer that makes a machine trustworthy enough to walk a live chemical plant alone. So the company built that layer instead, and made it hardware-agnostic on purpose. Korial’s software runs the same autonomy across a Boston Dynamics Spot, an ANYbotics legged unit, an ExRobotics explosion-proof platform, and a DJI drone overhead, then folds their data into one governed operating layer that ties back into a customer’s existing systems and digital twin.
Read the rebrand language and the strategy is right there. Energy Robotics described the shift as moving from powering individual robots and drones to orchestrating autonomy as an enterprise platform. That is the difference between selling a tool and owning the standard a whole industry runs on. It is a bold place for a German deep-tech company to plant a flag, and the track record is what makes it defensible rather than aspirational.
“Energy Robotics was the right name when the main challenge was proving that robots and drones could operate autonomously in complex industrial environments. That has now been proven across hundreds of thousands of operating hours. The next challenge is bigger: connecting machines, sites, and data into one trusted operational system.”
In his telling, the company is moving from inspecting sites to running them.
Why autonomous industrial inspection matters
The marketing line for inspection robotics is efficiency. What actually matters is who does not have to go inside. The environments Korial automates are the ones that hurt people: high-heat refineries, toxic-gas chemical sites, offshore platforms, remote substations. Every autonomous round the platform runs is a round a technician does not walk through a hazard zone. The thirty-thousand-plus hours of hazardous labor the company says it has removed from human workers is the number that should lead, and to the founders’ credit, it is the one they keep pointing at.
The customer list reads like a who’s who of heavy industry because heavy industry is where the danger and the scale both live. At Shell’s Energy and Chemicals Park Rheinland, Korial coordinates a mixed fleet of ground robots and drones for autonomous inspection across a sprawling site. These are standing deployments at some of the most safety-obsessed operators on earth, well past the pilot-for-a-press-release stage, and that is the highest bar a young robotics company can clear.
What autonomous industrial inspection changes for the rest of us
You will never see one of these robots, and that is the point. But the infrastructure they inspect is the infrastructure your normal day runs on. The refinery that makes your gasoline. The chemical plant behind everything from your medicine to the coating on your phone screen. The power substation a few miles from your house. These places are dangerous to walk, so they get inspected on a human schedule built around that risk, which means less often than anyone would like.
A robot can walk them every day, in the heat and the fumes, and never get tired or cut a corner. That shifts the math in a quiet but real way. A corroding pipe, a small gas leak, a failing valve gets caught early, when it is a maintenance ticket, instead of late, when it is an explosion, a blackout, or a plume of something toxic drifting toward a neighborhood. More frequent inspection of dangerous places shows up quietly, as the bad thing that never happened: the spill you never read about, the outage that never hit your block, the worker who went home.
The team that stuck with it
The founding group carried its academic DNA straight into the company. CEO Marc Dassler and co-founder Alberto Romay came out of the same TU Darmstadt robotics lab that produced the ARGOS win, alongside roboticists like Dorian Scholz, Oskar von Stryk, and Stefan Kohlbrecher. That continuity is rare and it shows. Energy Robotics raised a Series A backed by climate and infrastructure investors including Blue Bear Capital and Climate Investment, after a seed round led by Earlybird and a European Innovation Council grant. Patient capital for a patient build, the kind that has grown scarcer as venture money concentrates at the very top.
The honest open question is whether a software-first, hardware-agnostic position holds as the robot makers themselves push up into autonomy and the platforms push down into hardware partnerships. Korial is betting that the company who logged the first million inspections, on everyone else’s robots, is the one industry trusts to run the next hundred million. Eight years in, with the rebrand staking the larger claim, that is no longer a moonshot. It is a lead they have to keep.
Frequently Asked Questions
What does Korial do?
Korial, formerly Energy Robotics, builds a hardware-agnostic AI software platform that turns inspection robots and drones into autonomous inspectors for hazardous industrial sites like refineries, chemical plants, and offshore platforms.
Where did Korial come from?
It spun out of the Technical University of Darmstadt in 2019, from the “Team Hector” group that won Total’s international ARGOS Challenge in 2017 for the first autonomous oil-and-gas inspection robot.
Who are Korial’s customers?
Named operators include Shell, BP, Repsol, BASF, Merck, and E.ON. The company says it has completed over a million autonomous inspections across five continents.
Why did Energy Robotics rebrand to Korial?
To signal a shift from powering individual robots to running autonomy as an enterprise-wide AI operating layer across mixed robot fleets.
Sanctioned states and entities received about $104 billion in cryptocurrency in 2025, roughly eight times the 2024 total, according to Chainalysis’s 2026 Crypto Crime Report. The number matters because sanctions are the main tool the United States uses to pressure hostile governments without sending troops. When the money finds another road, the tool loses force.
Here is how the tool is supposed to work. Under the International Emergency Economic Powers Act of 1977, the president can declare a national emergency and order assets blocked. The Treasury’s Office of Foreign Assets Control runs the program, publishes the list of banned people and companies, and cuts them off from the US dollar and the banks that touch it. Almost every large transaction in the world eventually passes through a dollar bank, so landing on that list has historically meant being frozen out of the global economy.
Stablecoins are also where the government has its best new lever, when the issuer cooperates. A stablecoin is a token a company promises to redeem for a dollar, and that company can freeze any wallet holding it. Tether, the largest issuer, has done exactly that after Treasury designations, freezing $344 million in its token on the Tron network in April 2026. A freeze like that happens at the code level in minutes. Freezing a bank account can take days of calls to a correspondent bank. The catch is the word cooperates. The power only reaches issuers who choose to answer to Washington.
That gap is what the GENIUS Act, signed July 18, 2025, was written to close. It is the first US law for stablecoins. It puts issuers under the Bank Secrecy Act, tells FinCEN to write anti-money-laundering rules, and sets conditions on foreign issuers that want to reach American users. The plainspeak problem is that its main lever is access to the US market, and a ruble stablecoin made in Kyrgyzstan for Russians does not want that access. The law can discipline the issuers who want in. It cannot reach the ones built to stay out.
So who gains and who pays. The winners are the governments the sanctions were meant to isolate, Russia and Iran’s Revolutionary Guard and North Korea, which now have a working way to move money, plus the offshore operators who build the tokens for them. North Korea alone stole more than $2 billion in crypto in 2025, including $1.5 billion from the Bybit hack, per Chainalysis. The losers are harder to see. Sanctions are the pressure option a government uses short of military force, and when that option leaks, what remains is costlier and riskier. Compliant US stablecoin companies pay too, carrying the cost of the new rules while their offshore competitors carry none.
The blockchains are public, so Treasury can watch this money move in a way it never could through shell-company bank wires. Watching it and stopping it are different problems. Whether the GENIUS Act’s foreign-issuer rules can make a sanction stick when the money travels as tokens is the test the next few years will run.
Frequently Asked Questions
How much crypto reached sanctioned states in 2025?
About $104 billion, roughly eight times the 2024 total, according to Chainalysis’s 2026 Crypto Crime Report.
What is the A7A5 stablecoin?
A ruble-backed stablecoin issued by Kyrgyzstan-based Old Vector and sanctioned by OFAC on August 14, 2025. It was backed by Russia’s state-owned Promsvyazbank and Moldovan politician Ilan Shor, and at its peak moved about $1 billion a day.
What does the GENIUS Act do?
Signed July 18, 2025, it is the first US law for payment stablecoins. It places issuers under the Bank Secrecy Act, directs FinCEN to write anti-money-laundering rules, and sets conditions on foreign issuers seeking access to American users.
About two-thirds of the wallets that have bought the TRUMP memecoin are now holding losses, a combined $3.81 billion, according to blockchain analytics firm Nansen in data reported by CoinDesk and The New York Times. Of the roughly 1.48 million wallets that bought the token since its January 2025 launch, 988,905 are underwater.
The gains went to a smaller, earlier group. Just under 500,000 wallets locked in about $4.04 billion in profit, mostly by selling into the first rally, per the same Nansen data. The token trades about 96% below the $73.43 peak it reached within two days of launch.
The split is the central finding. Early buyers who sold near the top realized billions. The later and larger group who bought on the way up, or who held, absorbed the losses. Nansen’s figures are drawn from on-chain activity, which is public, so the outcomes can be counted wallet by wallet. What the data does not show is who is behind those early wallets, so this piece does not describe them beyond when they bought and sold.
The takeaway for anyone weighing one of these tokens is simple. A token tied to a famous name has no earnings, no product, and no floor under its price. Its value is whatever the next buyer will pay. In a structure like that, the people who buy after the launch spike are the exit liquidity for the people who bought before them. That holds regardless of whose name is on the coin.
The TRUMP token still trades, and wallets still move in and out of it. The $3.81 billion is a snapshot of realized and unrealized losses as of this week’s Nansen data, not a final tally. What it captures is timing. The wallets that came out ahead were the earliest ones in and out.
Frequently Asked Questions
How much have TRUMP memecoin buyers lost?
About two-thirds of the roughly 1.48 million wallets that bought the token are holding a combined $3.81 billion in losses, per Nansen data reported by CoinDesk and The New York Times.
Who made money on the TRUMP coin?
Just under 500,000 earlier wallets locked in about $4.04 billion, mostly by selling into the first rally, per the same Nansen data.
How far has the TRUMP token fallen?
It trades about 96% below the $73.43 peak it reached within two days of its January 2025 launch.