Agentic Cryptographic Debt: Repository-Level Measurement of Post-Quantum Migration Regression Under Autonomous AI Software Development

Robert Campbell

Preprints.org · 2026

Post-quantum migration is becoming binding for specified federal, national-security, and regulated systems, and delegating the work to AI assistants is an increasingly plausible organisational response. We measured what they produce when asked to migrate a repository from RSA-based JSON Web Token signing to ML-DSA (FIPS 204), scoring by static analysis and execution evidence. Two corpus items: a pinned Go application whose ecosystem supplies ML-DSA, and an authored service whose JOSE dependency lacked support in five audited libraries.

Across 56 runs, two models, and four conditions plus a nested ablation, no run migrated successfully where a conforming primitive was available, and none accurately reported the blocker. Granting an agent tools and a compiler made failure surface later, not less often: no modified artifact compiled unless the cryptography had been removed, and the artifact that did compile reported success and advertised ML-DSA while containing none. One model substituted a classical scheme five times in five while stating, correctly, that it is quantum vulnerable.

Naming the correct library and its API eliminated the substitution but produced no migration: all five made an identical API error, and two declared it impossible, mistaking absent names for absent capabilities. There, the failure lies in applying a dependency, not in knowing which.

📄 이 논문을 인용한 Paperis 글

이 논문이 근거 목록에 올라 있는 Paperis 글입니다.