Skip to content Skip to footer

Why AI Applications Need to Test Post-Quantum Certificates Before Production Migration

What Happened

Microsoft launched a PQC TLS Pilot Program for approved certificate authorities to test roots and certificate issuance using ML-DSA-87. Its pilot certificates are not publicly trusted and must not be used for production trust or public-facing websites. Supported Windows 11 testing requires specified updates released from July 28, 2026; seven pilot roots were added in August. [1]

The security issue is broader than replacing an encryption algorithm. Post-quantum authentication affects certificate chains, PKI processes, applications, devices and hardware security modules. Larger chains may expose compatibility or operational failures. [1]

Why It Matters to Businesses

AI applications depend on authenticated connections among model gateways, retrieval services, data stores and agent tools. If a certificate change breaks a client or weakens trust validation, an otherwise secure AI workflow may lose availability or connect to an untrusted service. This is an infrastructure threat, distinct from prompt injection or model-level attacks, but it affects the same production systems.

Kimbodo Engineering Perspective

The right near-term decision is to test trust paths, not deploy pilot certificates as production trust. Inventorying only public web certificates misses internal APIs, service-to-service connections and vendor-managed endpoints. Conversely, changing every certificate at once would make compatibility failures difficult to isolate. [1]

How We Would Implement It

  • Map certificate issuers, trust stores, TLS termination points and dependencies across AI applications, agent tools and supporting data services.
  • Build a non-production test environment with supported Windows 11 clients and eligible pilot certificates; keep pilot roots out of production trust stores. [1]
  • Test chain validation, handshake behavior, certificate renewal, revocation handling and observability across representative clients, proxies and hardware security modules.
  • Record vendor support gaps and define migration gates: successful interoperability tests, rollback procedures and ownership of each trust relationship.

Risks, Costs and Security

The principal costs are dependency discovery, test environments, vendor coordination and potential upgrades to clients or PKI hardware. The principal risks are service outages from incompatible certificates and accidental trust expansion if test roots reach production. Separate test and production trust stores, restrict who can issue certificates, and monitor certificate changes before any broader rollout. [1]

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Security & Guardrails practice, or Request a Security Review.

Sources

  1. [1] Post-quantum authentication: Why organizations should start testing certificate ecosystems now

Leave a comment

0.0/5