There's a date that Google quietly updated some time ago to 2029. Q-Day: the day quantum computers reach the power needed to break the encryption schemes protecting what we currently consider private. Banking passwords, medical histories, personal communications, digital identities. This isn't science fiction or fearmongering. It's a technical projection based on documented advances in quantum hardware, and the fact that a company like Google includes it in its internal calendars says quite a bit about how serious it is.
What few people know, and what urgently needs explaining without jargon, is that the risk doesn't start in 2029. It's already underway.
There's an attack strategy analysts call "harvest now, decrypt later." The idea is straightforward: well-resourced actors, whether states or organized groups, are collecting encrypted data today that they can't yet read, and storing it. When Q-Day arrives, they decrypt it. This isn't a distant threat. It's an operation already in progress. Data stolen from a server in 2024 could be readable in 2029. Current encryption has an expiration date, and someone is waiting for it to expire.
This connects to a point the Manifesto touches on but doesn't fully resolve: state centralization of data.
Several governments have built identity structures that bring together biometric data, medical records, financial movements, and civil registries in a single place. The official justification is always efficiency, fraud prevention, faster services. Mexico offers a concrete example. Its national biometric ID, linked to interconnected databases, has suffered repeated attacks. These aren't speculation: citizens' data has been put up for sale on the dark web multiple times, including information from the National Population Registry. Mexico's president has publicly backed this centralization as a governance tool. That concentration, however, means every breach becomes a national disaster.
The problem goes beyond current vulnerabilities, which already exist. When Q-Day arrives, any data harvested during these preceding years will be exposed. Not gradually. All at once.
This is where the Manifesto hits its limit, and I'll say it plainly.
One of its core pillars is radical transparency in governance: auditable structures, visible decisions, less asymmetry between those who govern and those who are governed. That pillar holds up, and I stand by it. But there's a tension the text assumes without fully exploring: symmetrical oversight in governance is not the same thing as individual privacy as a right. These are separate categories, and Q-Day draws a clear line between them.
A public official's data in the context of public decisions belongs to the collective domain. Citizens have a right to access it. But that person's medical history—or anyone's, for that matter—does not belong to the collective domain. It's personal. Blending both under the same logic in a centralized architecture is a design flaw with consequences that go beyond politics. It's a technical failure that Q-Day will make worse.
I'm not offering a complete solution here. The Manifesto suggests decentralization as a foundation, and that holds up: distributed data is harder to harvest en masse. But decentralizing personal data within state environments requires legal and technical frameworks that no government has applied at scale. Researchers are working on self-sovereign identity, where citizens manage their own data without central servers. It sounds workable. It's still experimental.
And there's a challenge nobody has solved yet.
When artificial intelligence runs on quantum hardware, the opacity of today's models will multiply. AI systems are already hard to audit: they make decisions through logic that escapes even their creators. I've touched before on the tension between privacy and security in models like ChatGPT. But quantum AI isn't just faster. It breaks the assumptions behind any accountability framework. Processing centralized biometric data in real time, with broken encryption, creates scenarios that regulatory vocabulary simply doesn't have words for yet.
Fair enough to admit it: the Manifesto doesn't cover that. Its governance rules still stand, but the technical challenges of Q-Day are moving faster than any current proposal—including mine.
Societies have weathered technological transformations before. Not always well, not always on time, but by adapting frameworks rather than giving up. Speed is now the challenge. 2029 leaves little room to migrate to post-quantum encryption, to let people know what data of theirs is being harvested today, and to get laws to keep pace with hardware. There are alternatives already underway, like these experiments in self-sovereign identity, that deserve more attention.
It's worth laying this out even if it calls the proposal itself into question. A text that admits no self-criticism isn't an idea—it's a dogma. And I don't write dogmas.
Stones don't lie, but historians sometimes do.
Sources:
1. Google Quantum AI — Updates on quantum computing progress and capability projections (2024-2025)
2. NIST — Post-Quantum Cryptography Standardization Project (final standards publication, 2024)
3. INAI / Data breach reports in Mexico — Public records of security incidents in government systems (2022-2024)
4. "Harvest Now, Decrypt Later" — Analysis by Booz Allen Hamilton and multiple cybersecurity firms on early-collection strategies
5. Self-Sovereign Identity Foundation — Technical framework for citizen-controlled decentralized identity