September 29, 2026, (Inside AI) — Cloudflare has set a hard deadline of 2029 to achieve full post-quantum readiness across its entire platform. The company is developing an internal AI-powered tool called CryptoLabe to discover, analyze, and migrate cryptographic code before quantum computers can break current encryption standards.
The initiative addresses a critical challenge: finding every use of cryptography across thousands of repositories. Classical algorithms like RSA and ECDSA are vulnerable to future quantum attacks. Cloudflare's infrastructure serves a significant portion of the internet, making its migration a bellwether for the industry.
"We're taking a maximalist stance ('PQ everything!'), because as an infrastructure provider to the world, we want to give our customers the peace of mind that using Cloudflare ensures that their traffic is future-proofed against quantum adversaries," the company stated in a technical blog post.
CryptoLabe, named after the ancient mariner's astrolabe, uses large language models to scan codebases. It identifies cryptographic operations, classifies their usage, and generates migration reports for engineers and product managers. The tool runs on Cloudflare's own Developer Platform, leveraging Workers, Durable Objects, and AI Gateway to orchestrate scans across many repositories simultaneously.
Read: Cloudflare Launches Adaptive Security Framework to Counter AI-Driven Attacks
The scale of the problem is immense. Cryptography rarely appears plainly in code. It hides in shared libraries, configuration files, protocol defaults, and dead code. Simple pattern matching overcounts and undercounts. AI can follow evidence across files and understand runtime context.
"It turns out that AI is pretty good at doing more than just grepping," the company noted. "A model can search a codebase, follow evidence across files, and return structured analysis."
Cloudflare's approach involves two stages: discovery and analysis. The discovery stage maps the repository and searches for cryptographic patterns. Each raw observation then undergoes analysis, where the model re-checks the code, investigates runtime usage, and assigns a classification. If evidence is insufficient, it flags the finding for further review rather than guessing.
The company has already transitioned many products to post-quantum encryption over TLS 1.3. However, post-quantum authentication remains in early stages. Cloudflare aims to support both encryption and authentication to fully protect against quantum threats.
To manage model costs and capacity, Cloudflare routes requests through AI Gateway to open-weight models on Workers AI. A global Durable Object paces all model requests, preventing rate-limit errors during concurrent scans.
Beyond code scanning, CryptoLabe identifies prerequisites and hard cases. Prerequisites are findings that individual product teams cannot resolve alone, such as dependencies on external parties or missing library support. Hard cases involve custom protocols, size-constrained fields, or hardware cryptography that lack post-quantum standards.
Read: Cloudflare Tests WAF Against Frontier AI Models, Finds Gaps and Fixes Them
"An exhaustive cryptographic inventory is not a prerequisite for action," the company advised. "Instead, organizations should first identify the systems whose compromise would matter most, discover their use of cryptography, and then PQ that cryptography in priority order."
Cloudflare is sharing selected prompts from CryptoLabe to help other organizations. However, the company cautions that prompts are starting points and require engineering review. No ground-truth dataset exists for reproducibly comparing prompt performance.
The 2029 deadline aligns with broader industry expectations. The National Institute of Standards and Technology (NIST) finalized several post-quantum algorithms in 2024. The Internet Engineering Task Force (IETF) continues standardizing protocols. Cloudflare deployed X25519MLKEM768 in TLS 1.3 in 2022, before it became RFC 10024 in 2026.
For most organizations, Cloudflare recommends a risk-based approach. Prioritize systems with high-value data and long-lived secrets. Use post-quantum encryption where available, such as through Cloudflare's own services, as a compensating control while migrating internal systems.
CryptoLabe remains internal and is not available to customers. Cloudflare hopes its learnings will aid others in their post-quantum journeys.