30 Sep 2026

IM Blog: Why Should Records Professionals Care About Quantum Technology?

When artificial intelligence first arrived in the workplace, plenty of records and information professionals waved it off as something for the IT department to worry about.

Blog  Peta Sweeney  Why Should Records Professionals Care About Quantum Technology (1).png

That turned out to be a mistake. AI now touches information creation, governance, privacy, discovery, risk and compliance – for many it's simply part of the job now.

Quantum technology is on the same trajectory. And this time, we have a head start.

You Don't Need to Be a Physicist

Understanding the governance implications of quantum technology doesn't require a physics degree any more than understanding information architecture requires you to design databases yourself.

What it requires is enough literacy to ask the right questions before the decisions get made without you in the room.

The Real Risk - Harvest Now, Decrypt Later

Here's the part most quantum explainers skip and it's the one that actually matters for records management: quantum computers, once powerful enough, will be able to break the encryption that currently protects almost everything we store.

Most of today's digital security - including the encryption protecting archived and 'secure' records - relies on math problems that are extremely hard for ordinary computers to solve but comparatively easy for a sufficiently powerful quantum computer. Security researchers believe such a machine could plausibly exist within the next decade.

That sounds like a future problem. It isn't. Adversaries are already running attacks nicknamed 'harvest now, decrypt later' collect encrypted data today, sit on it and decrypt it once the technology catches up. For a profession built around retention - keeping records for 7, 30 or 100 years - that timeline isn't abstract. If you're retaining sensitive records for decades, today's 'secure' encryption may not still be secure by the time those retention periods end.

This is why the U.S. National Institute of Standards and Technology (NIST) finalised its first post-quantum cryptography standards in August 2024 and why Australia has named quantum a strategic national capability with a push to lift quantum literacy across government and industry. The migration is already underway. The only question is whether records and information teams are at the table for it.

Why This Sits Squarely in Our Lane

Records and information management lives at the intersection of trust, evidence, accountability and long-term preservation - exactly where quantum technology bites. Expect these questions to land on your desk sooner than you'd think:

  • Crypto-agility - can our systems swap out encryption methods without a complete rebuild or are we locked into something that won't survive the transition?
  • Evidentiary trust - what do we need to retain to prove a decision was sound, when that decision came from an increasingly complex computational system?
  • Long-term authenticity - how do we prove a record hasn't been tampered with, decades after it was created, in an environment where the tools to verify it keep changing?
  • Metadata for automation -  what documentation will future audits expect to explain how an automated process reached its outcome?
  • Preservation strategy - how do we keep moving forward when the technology underneath us won't stop shifting?

These aren't physics questions. They're governance questions and governance has always been ours.

What You Can Actually Do This Year

Quantum literacy shouldn't stay theoretical. Three concrete starting points:

  1. Build baseline literacy deliberately, not by osmosis. You don't need a course in quantum mechanics. A few hours is enough to get conversational: a good starting point is the Australian Government's National Quantum Strategy, which lays out the policy direction without requiring a physics background. RIMPA Global also has webinars and eLearns on the topic.
  1. Ask your vendors directly: What's your post-quantum migration timeline and is it aligned with NIST's FIPS 203/204/205 standards? If they don't have an answer, that's useful information in itself.
  1. Flag your longest-retention records. Anything classified as sensitive and kept for 10+ years is the highest-priority candidate for crypto-agility review - it's the most exposed to 'harvest now, decrypt later'.
  1. Get a seat in the room. Cybersecurity and IT teams are already having these conversations. Records professionals bring the retention schedules, the risk classifications and the institutional memory that those conversations need but only if someone invites information governance to the table, or better, asks for one.

Looking Ahead

The profession has already adapted to paper, microfilm, electronic records, the cloud and AI. Quantum is the next adaptation not a different kind of challenge.

No one needs to become a quantum physicist. But understanding why this matters - not just that it matters - is what turns 'quantum literacy' from a buzzword into a professional capability worth having before the decade's out.

Meet your blog author:

Peta Sweeney.png

 

Peta Sweeney CXRIM FRIM (Life), Information and Content Specialist, RIMPA Global