Key takeaways
- Willow's significance is error correction below threshold, not qubit count — adding qubits now reduces the logical error rate instead of increasing it.
- This crosses the line that quantum computing has been stuck behind since the 1990s.
- It does not mean useful quantum computers exist yet; the resource gap to running Shor's algorithm on real keys remains enormous.
- The encryption threat is not immediate, but “harvest now, decrypt later” makes migration planning urgent regardless.
Google's Willow processor produced a result that matters more than the benchmark headlines suggested. The widely reported claim — that it completed in minutes a computation that would take a classical supercomputer an implausible span of time — is the least interesting part. Those benchmarks are chosen to favour quantum hardware and have repeatedly been narrowed by better classical algorithms.
The genuinely important result is quieter: Willow demonstrated error correction operating below threshold.
Why below-threshold error correction is the whole game
Qubits are extraordinarily fragile. They decohere from thermal noise, stray electromagnetic fields, and vibration, and every gate operation introduces error. A useful quantum algorithm requires millions of sequential operations, so physical qubits alone are hopeless — errors accumulate faster than computation proceeds.
The answer since the 1990s has been quantum error correction: spread the information of one logical qubit across many physical qubits so errors can be detected and corrected without measuring — and thereby destroying — the encoded state.
The catch is that error correction is itself performed by imperfect qubits using imperfect gates. If your physical error rate is too high, adding more physical qubits per logical qubit introduces more errors than it fixes. The system gets worse as it gets bigger. That is the threshold, and quantum computing has been stuck on the wrong side of it for three decades.
Willow crossed it. As Google scaled its surface-code lattice from a 3×3 to a 5×5 to a 7×7 array of physical qubits, the logical error rate halved with each step. Bigger now means better. That is the qualitative change.
What this does not mean
It is worth being precise, because the gap between this result and a useful machine is still vast.
- One logical qubit is not a computer. Willow demonstrated the scaling behaviour of a logical qubit. Running commercially interesting algorithms requires thousands of them.
- The physical overhead is brutal. Depending on the target error rate, a single high-quality logical qubit may require a thousand or more physical qubits. Thousands of logical qubits therefore implies millions of physical ones.
- Nothing here breaks encryption today. Factoring an RSA-2048 key with Shor's algorithm requires a fault-tolerant machine several orders of magnitude beyond current hardware.
The cryptography timeline
The reason security teams are not treating this as a distant concern is the “harvest now, decrypt later” problem. An adversary can capture encrypted traffic today and store it until a machine capable of breaking it exists. Any data whose confidentiality must survive a decade or more — medical records, state secrets, long-lived credentials — is already exposed to a future capability.
This is why post-quantum cryptography standardisation has moved faster than the hardware. Lattice-based algorithms are now standardised, and migration has begun in browsers, messaging protocols, and TLS libraries. The right posture is not panic but inventory: know which systems use public-key cryptography, know which data has a long confidentiality lifetime, and plan the crypto-agility to swap primitives without re-architecting.
What to watch next
The meaningful metrics from here are not qubit counts. Watch logical qubit count and logical error rate, since those are what algorithms consume. Watch whether the below-threshold scaling continues at larger lattice sizes — the result so far covers a modest range, and physics has a habit of introducing new noise mechanisms at scale. Watch gate fidelity for two-qubit operations, which remains the limiting factor.
Willow does not make quantum computing useful. It makes the path to useful quantum computing an engineering problem rather than an open question in physics, and those are very different categories of difficulty.
Comments (2)
Alex Thompson
65w ago
Incredible analysis. The points about multimodal reasoning are spot on — this is exactly the kind of deep dive we need to understand these models properly.
Nour Al-Rashid
65w ago
Great article! I appreciate the balanced approach — acknowledging both the capabilities and the safety considerations. Looking forward to your follow-up piece.