Explainer
What quantum computers are good for (and what they are not)
Quantum computers are expected to excel at simulating molecules and materials and at breaking some public-key encryption, not at speeding up ordinary computing.[1][2] As of October 2026, demonstrated speed-ups are on scientific benchmarks; useful applications still wait on fault-tolerant machines with hundreds to thousands of logical qubits.[3][4]
Not a faster computer, a different one
A quantum computer is not a faster laptop. It is expected to be very good at a few kinds of problems, especially imitating how atoms and molecules behave and finding hidden patterns and structures in information.[1] For most everyday tasks an ordinary computer will stay better and cheaper.
The strongest-founded applications are problems with special structure, notably simulating quantum systems and the cryptanalysis enabled by Shor’s algorithm.[5][2] Every candidate application has to beat classical algorithms that keep improving, as IBM’s 2026 advantage claims showed when one was reproduced on GPUs.[6]
Simulating nature
Molecules and materials obey quantum mechanics, so a quantum computer could in principle model them directly.[5] Google says its goal is a useful, beyond-classical computation relevant to a real application, and it cites drug discovery, battery design and energy research.[7] In October 2025 its Quantum Echoes experiment measured a physical quantity on Willow about 13,000 times faster than the Frontier supercomputer could, and a companion study applied the method to nuclear magnetic resonance of molecules, though not yet beyond classical reach.[8][3] In July 2026 IBM and Algorithmiq claimed advantage on a simulation of heterogeneous quantum matter.[9]
Breaking encryption
Shor’s algorithm would let a large fault-tolerant quantum computer break the public-key encryption that secures much of the internet, which is why NIST has led the development of post-quantum cryptography.[2] Estimates of the hardware needed keep shrinking. In 2019 the figure for 2048-bit RSA was 20 million noisy qubits; a May 2025 estimate brought it under one million.[10][11] In March 2026 Google estimated that 256-bit elliptic-curve cryptography, used widely including in cryptocurrencies, could fall to fewer than 1,200 logical qubits, or fewer than 500,000 physical qubits running for minutes.[4] Google released that estimate with zero-knowledge proofs rather than full attack details.[12]
For comparison, the largest error-corrected demonstrations in 2026 involve dozens of logical qubits, not thousands.[13][14]
Benchmarks versus useful work
Most “beyond classical” results so far are benchmarks designed to be hard for classical computers, such as random circuit sampling. Google said Willow did such a task in under five minutes that would take a supercomputer 10 septillion years, and China’s Zuchongzhi 3.0 reported a similar task as 10^15 times faster than a supercomputer.[15][16] These show the hardware doing something classically hard, but their outputs are random bitstrings that cannot be independently reproduced, which is why Google stressed that its later Quantum Echoes result was verifiable.[17] The IBM-backed quantum advantage tracker was created so claims of useful advantage can be tested by others.[18]
The yardstick: logical qubits and operations
The useful milestones are stated in logical qubits and operations. IBM targets 200 logical qubits running 100 million operations by 2029, and 2,000 logical qubits by 2033.[19][20] DARPA defines utility scale as the point where a quantum computer’s computational value exceeds its cost, and is testing whether any approach can reach it by 2033.[21]
Questions readers ask
Will quantum computers replace my laptop?
No. They are expected to help with specific tasks such as modelling physical systems, not with everyday computing.[1]
How big a quantum computer would break RSA encryption?
A 2025 Google estimate said fewer than a million noisy physical qubits running for under a week could factor a 2048-bit RSA number. No such machine exists yet.[11]
Sources
Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.
- [1]
Quantum computers are expected to be best at modelling physical systems and finding patterns and structures in information, with possible uses in chemistry and pharmaceuticals. confirmedas of 2026-10-10
- What is quantum computing? · IBM (retrieved 2026-10-10)
- [2]
NIST leads development of post-quantum cryptography to protect data from future quantum computers that could break widely used encryption. confirmedas of 2026-10-10
- Quantum information science · NIST (retrieved 2026-10-10)
- [3]
A companion Google study applied the echo technique to nuclear magnetic resonance measurements of molecular structure, but those results were not yet beyond classical simulation. confirmedas of 2025-10-22
- A verifiable quantum advantage · Google Research · 2025-10-22 (retrieved 2026-10-10)
- [4]
In March 2026 Google researchers, in work framed around safeguarding cryptocurrency, estimated that 256-bit elliptic-curve cryptography could be broken with fewer than 1,200 logical qubits and 90 million Toffoli gates, or fewer than 500,000 physical superconducting qubits running for a few minutes, under standard hardware assumptions. confirmedas of 2026-03-31
- Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly · Google Research · 2026-03-31 (retrieved 2026-10-10)
- [5]
NIST describes quantum computers as a new kind of machine that can, in theory, simulate the quantum nature of matter and tackle certain problems that are currently unsolvable. confirmedas of 2026-10-10
- Quantum information science · NIST (retrieved 2026-10-10)
- [6]
An August 2026 preprint reported classically reproducing all 2,051 amplitude batches of IBM's 70-qubit doped Clifford sampling experiment in 37.3 minutes on 256 NVIDIA H100 GPUs, with results compatible with IBM's fidelity bound. reportedas of 2026-08-13
- Classical Simulation and Design Frontiers for IBM's Doped Clifford Sampling Experiment · arXiv · 2026-08-13 (retrieved 2026-10-10)
- [7]
Google's stated next goal is a first useful, beyond-classical computation relevant to a real-world application, citing areas such as drug discovery, battery design and energy research. confirmedas of 2024-12-09
- Meet Willow, our state-of-the-art quantum chip · Google · 2024-12-09 (retrieved 2026-10-10)
- [8]
On 22 October 2025 Google reported in Nature that its Quantum Echoes (out-of-time-order correlator) algorithm ran on Willow in about two hours, a task it estimated would take 13,000 times longer on the Frontier supercomputer. confirmedas of 2025-10-22
- A verifiable quantum advantage · Google Research · 2025-10-22 (retrieved 2026-10-10)
- [9]
On 30 July 2026 IBM and Algorithmiq claimed quantum advantage for a simulation of heterogeneous quantum matter run on IBM's Heron processor, a problem posted on the quantum advantage tracker about eight months earlier. confirmedas of 2026-07-30
- IBM and Algorithmiq Demonstrate Quantum Advantage, Establishing a Framework for Trusted Quantum Computation Beyond Classical Verification · IBM Newsroom · 2026-07-30 (retrieved 2026-10-10)
- [10]
A 2019 estimate co-published by the same author put the requirement at 20 million noisy qubits running for eight hours to factor 2048-bit RSA. confirmedas of 2025-05-21
- How to factor 2048 bit RSA integers with less than a million noisy qubits · arXiv (Google Quantum AI author) · 2025-05-21 (retrieved 2026-10-10)
- [11]
A May 2025 Google preprint estimated that a 2048-bit RSA integer could be factored in less than a week by a quantum computer with fewer than a million noisy qubits. confirmedas of 2025-05-21
- How to factor 2048 bit RSA integers with less than a million noisy qubits · arXiv (Google Quantum AI author) · 2025-05-21 (retrieved 2026-10-10)
- [12]
Google said it used zero-knowledge proofs to let others verify its elliptic-curve resource estimate without publishing sensitive attack details. confirmedas of 2026-03-31
- Safeguarding cryptocurrency by disclosing quantum vulnerabilities responsibly · Google Research · 2026-03-31 (retrieved 2026-10-10)
- [13]
In March 2026 Quantinuum researchers reported computations with up to 94 error-detected and 48 error-corrected logical qubits on Helios, using iceberg and concatenated codes, with logical gate errors around one in ten thousand - better than the physical gates. confirmedas of 2026-03-10
- Quantinuum Researchers Demonstrate Quantum Computations With Dozens of Protected Logical Qubits · The Quantum Insider · 2026-03-10 (retrieved 2026-10-10)
- Skinny Logic: Quantum Codes Go on a Diet · Quantinuum · 2026-03-04 (retrieved 2026-10-10)
- Computing with many encoded logical qubits beyond break-even · arXiv (Quantinuum researchers) · 2026-02-25 (retrieved 2026-10-10)
- [14]
On 24 September 2026 Infleqtion reported entangling 30 logical qubits encoded in 80 physical neutral-atom qubits on its Sqale system, in a circuit of about 1,000 physical operations, and said it targets 100 logical qubits by 2028. reportedas of 2026-09-24
- Infleqtion Achieves 30 Entangled Logical Qubits on Its Sqale Quantum Computer · Infleqtion · 2026-09-24 (retrieved 2026-10-10)
- [15]
Google said Willow performed a random circuit sampling computation in under five minutes that would take one of the fastest supercomputers 10 septillion years. confirmedas of 2024-12-09
- Meet Willow, our state-of-the-art quantum chip · Google · 2024-12-09 (retrieved 2026-10-10)
- [16]
The University of Science and Technology of China reported in Physical Review Letters in March 2025 that its 105-qubit Zuchongzhi 3.0 superconducting processor ran an 83-qubit, 32-layer random circuit sampling task it estimated at 10^15 times faster than the most powerful supercomputer. confirmedas of 2025-03-06
- Zuchongzhi-3 sets new benchmark with 105-qubit superconducting quantum processor · University of Science and Technology of China (via EurekAlert!) · 2025-03-06 (retrieved 2026-10-10)
- [17]
Google called the Quantum Echoes result verifiable because its outputs are physical expectation values that another quantum computer or a natural quantum system can reproduce, unlike random bitstrings. confirmedas of 2025-10-22
- A verifiable quantum advantage · Google Research · 2025-10-22 (retrieved 2026-10-10)
- [18]
IBM said in November 2025 that it expected verified quantum advantage by the end of 2026 and launched an open quantum advantage tracker with partners to monitor and test claims. confirmedas of 2025-11-12
- IBM Delivers New Quantum Processors, Software, and Algorithm Breakthroughs on Path to Advantage and Fault Tolerance · IBM Newsroom · 2025-11-12 (retrieved 2026-10-10)
- IBM Delivers New Quantum Processors, Software, and Algorithm Breakthroughs on Path to Advantage and Fault Tolerance · IBM Newsroom · 2025-11-12 (retrieved 2026-10-10)
- [19]
In June 2025 IBM said it would build IBM Quantum Starling, a fault-tolerant quantum computer with 200 logical qubits able to run 100 million quantum operations, in Poughkeepsie, New York, by 2029. confirmedas of 2025-06-10
- IBM Sets the Course to Build World's First Large-Scale, Fault-Tolerant Quantum Computer at New IBM Quantum Data Center · IBM Newsroom · 2025-06-10 (retrieved 2026-10-10)
- [20]
IBM's roadmap follows Starling with Blue Jay in 2033, targeting 2,000 logical qubits and 1 billion operations. confirmedas of 2025-06-10
- IBM Sets the Course to Build World's First Large-Scale, Fault-Tolerant Quantum Computer at New IBM Quantum Data Center · IBM Newsroom · 2025-06-10 (retrieved 2026-10-10)
- Quantum Roadmap (IBM Technology Atlas) · IBM (retrieved 2026-10-10)
- [21]
DARPA's Quantum Benchmarking Initiative aims to determine whether any quantum computing approach can reach utility-scale operation - computational value exceeding cost - by 2033. confirmedas of 2026-10-07
- Four more teams enter Quantum Benchmarking Initiative's final stage · DARPA · 2026-10-07 (retrieved 2026-10-10)
Revision history (1)
- Page created.
Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.
Cite this page
"What quantum computers are good for (and what they are not)." ContentLora, updated Oct 10, 2026. https://contentlora.com/explain/what-quantum-computers-are-good-for
Spotted an error? Suggest a correction or emailcorrections@contentlora.com.
Keep exploring
- ExplainerQuantum computing in 2026: a crash courseA sourced crash course on quantum computing: qubits, error correction, logical qubits, advantage claims and who leads as of October 2026.
- AnalysisHas quantum advantage arrived? The 2026 debateQuantum advantage claims from Google, USTC and IBM, why classical computers keep catching up, and what would settle the debate.
- WikiDARPA Quantum Benchmarking Initiative (QBI)DARPA's Quantum Benchmarking Initiative tests whether any quantum computer can reach utility scale by 2033. Its stages, teams and October 2026 Stage C.
- WikiGoogle WillowWillow is Google Quantum AI's 105-qubit superconducting chip, used for the first below-threshold error correction and the Quantum Echoes experiment.
- WikiIBM QuantumIBM Quantum builds superconducting quantum computers. Its Nighthawk and Loon chips, 2026 advantage claims and the 2029 fault-tolerant Starling plan.
- WikiNeutral-atom qubitsNeutral-atom quantum computers trap thousands of atoms with laser tweezers. How they work, the 448-atom and 6,100-atom milestones, and who builds them.