Quantum-GUARD’s One-Year Deadlines Put Grid Encryption on AI’s Power Risk List

Electric substation control room with encrypted data streams, illustrating Quantum-GUARD Act post-quantum cryptography for the grid

TL;DR · 30-second read

The Short Version

Two senators, one from each party, have proposed a law to prepare the power grid for quantum computers. These are a new kind of machine that could one day crack the digital locks protecting the grid’s control systems.

The bill gives the Energy Department one year to study the danger and set up a test lab where power companies can try stronger locks.

Why it matters: the huge computer warehouses that run artificial intelligence depend on the grid. If the grid’s security slips, their electricity is at risk too.

Legis1 reported that Sens. Chris Coons (D-DE) and Mike Rounds (R-SD) introduced the Quantum Grid Utility Assurance and Resilient Defense Act, or Quantum-GUARD Act, on August 14, 2026. The bill targets a future threat: quantum computers powerful enough to break the encryption that protects the electric grid’s IT and control systems.

The bill would require the Federal Energy Regulatory Commission (FERC) to weigh quantum risks when it reviews grid reliability standards. It would give the Department of Energy one year to stand up a post-quantum cryptography testing sandbox with utilities, grid operators and vendors, and one year to report to Congress on quantum risks to the bulk-power system. IonQ, American Binary, the Quantum Industry Coalition, the Quantum Economic Development Consortium and the Cyber Threat Alliance endorsed it.

Executive Summary

The Quantum-GUARD Act is the first bill aimed specifically at moving the electric grid onto post-quantum cryptography. These are encryption methods designed to withstand attacks from quantum computers. The bill does not order utilities to replace anything. It directs regulators to study the problem, build a joint testing environment and factor quantum risk into the rules that govern grid reliability. Sen. Rounds described it as codifying parts of President Trump’s June executive order on advanced cryptographic attacks, which set a federal policy of moving government systems to NIST-approved post-quantum standards and helping critical infrastructure owners do the same.

For the data center industry, the significance lies in the dependency, not the quantum computers themselves. AI campuses are among the largest new customers of the grid, and their uptime rests on utility control systems they neither own nor secure. Encryption upgrades to those systems are slow to plan and deploy. A bill that starts one-year federal clocks on assessment and testing marks the point at which grid cryptography becomes something power-hungry operators should track alongside capacity, interconnection and price.

Why Grid Encryption Belongs on the AI Power Risk List

A data center’s power is only as dependable as the systems that run the grid behind it. Those systems include substation controls, generator dispatch and the communications between control rooms and field equipment, which engineers call operational technology, or OT. Much of that traffic is protected by public-key cryptography, the same family of math that quantum computers are expected to threaten. The Quantum-GUARD Act names this directly: it would require FERC to consider post-quantum cryptography in both IT and OT systems, and it tasks the Energy Department with identifying obstacles to moving ‘high-value systems’ to new standards.

The one-year deadlines explain why operators should track this now rather than later. Under the bill, DOE’s Office of Cybersecurity, Energy Security, and Emergency Response would have twelve months to launch a testing sandbox and twelve months to deliver findings to the Senate Energy and Natural Resources and House Energy and Commerce committees. Those are the first steps of a migration, not the end of one. Grid control equipment often stays in service far longer than office IT, so any cryptographic change moves through procurement, testing and field replacement over years. For a company planning an AI campus that depends on a particular utility for a decade or more, how that utility handles the transition is a real long-term risk, even though the bill never mentions data centers.

In practice, this is a due-diligence item rather than an alarm. Large-load customers already question utilities about capacity, redundancy and restoration times. The bill’s framework makes it reasonable to add a question about cryptographic readiness, and to expect that the answer will be shaped by whatever the DOE study and sandbox produce.

What the Bill Does, and What It Leaves Open

The bill’s verbs matter. FERC would have to ‘consider’ quantum risk when reviewing proposed reliability standards. That makes quantum risk a factor in rulemaking but sets no deadline for migration. DOE would ‘study’ and ‘establish’ a sandbox, with no requirement that utilities adopt what it finds. This is a framework bill. It builds the evidence base that later mandates, if any, would rest on.

That restraint has advantages. Utilities run a very wide mix of legacy and modern equipment, and a mandate issued before anyone has tested post-quantum algorithms on real grid hardware could cause more reliability problems than it solves. The sandbox exists to test that, bringing utilities, vendors, federal agencies and state and local organizations into one environment to find where new cryptography breaks old equipment. The cost is time. By design, the bill’s first concrete output is a report, and the harder questions of who pays, on what schedule and under what enforcement come after it.

Why Now: The Standards Exist, the Threat Does Not Yet

The timing follows the standards. NIST finalized its first three post-quantum cryptography standards in August 2024 and has encouraged organizations to begin transitioning, which means there is now a defined target to migrate toward. Before that, a grid-specific migration bill would have had nothing concrete to point at.

The threat, by contrast, is still prospective. The bill is framed around protecting the grid ‘before sufficiently powerful quantum computers can undermine existing encryption,’ and it does not say when that might happen. That is the right way to frame it. The argument for starting early rests on how slowly large infrastructure changes its cryptography, not on any fixed date for when quantum machines will arrive. Readers should treat claims of an imminent quantum break, from any side, with the same caution the bill’s own wording shows.

A Quantum Industry Coalition Behind a Grid Bill

The endorsements come mainly from the quantum and cybersecurity sectors: IonQ, a quantum technology company; American Binary; the Quantum Industry Coalition; the Quantum Economic Development Consortium; and the Cyber Threat Alliance. Support from companies that build quantum and security technology is expected and does not weaken the bill’s reasoning, which rests on NIST’s published standards and an existing executive order. It does mean that the people who would carry out the migration, meaning utilities, grid operators and state regulators whose ratepayers ultimately fund utility upgrades, will shape how practical the plan turns out to be, and their public positions on the bill are worth watching.

Background

The US electric grid runs under mandatory reliability standards, including cybersecurity rules. These are largely developed by the North American Electric Reliability Corporation and approved by FERC. The Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) leads the department’s work on energy-sector security. Grid cybersecurity has historically focused on present-day threats such as intrusions and ransomware. Quantum computing adds a longer-horizon concern: that a sufficiently powerful machine could defeat the public-key encryption that protects much of the grid’s communications.

NIST’s finalization of its first three post-quantum cryptography standards in August 2024 gave organizations a concrete target for migration. Federal policy has since moved toward requiring that transition for government systems and supporting it for critical infrastructure. Meanwhile, rapid data center construction, driven largely by AI, has made grid reliability a central concern for the digital infrastructure industry.

Sources

Source: Bipartisan Bill Targets Cyber Threats to Electric Grid, Legis1’s report on the Quantum-GUARD Act introduced by Sens. Coons and Rounds.