top of page

Thales Luna 8 Targets the AI and Post-Quantum Security Bottleneck

Sep 15
13 min read

Thales launched Luna 8 after 59% of surveyed organizations reported testing post-quantum algorithms, yet moving those algorithms into production remains difficult. The new hardware security module places Thales Luna 8 between two expanding demands. Enterprises need more cryptographic capacity for AI workloads while preparing their oldest trust systems for quantum-resistant algorithms.

A hardware security module, or HSM, is a protected device that stores cryptographic keys and performs sensitive operations without exposing those keys. Thales says Luna 8 adds a company-designed cryptographic processor, native post-quantum support, stronger isolation, and more adaptable administration. Those features target infrastructure behind public key systems, software signing, digital identities, cloud encryption, and machine-to-machine authentication.

The tension is not whether post-quantum standards exist. NIST finalized its first principal standards in 2024, and competing HSM suppliers and cloud platforms have been adding support since then. The harder question is whether enterprises can replace foundational cryptography without interrupting applications, breaking integrations, or creating new operational weaknesses. Thales Luna 8 is therefore a migration bet, not merely a faster security appliance.

Thales Luna 8 Moves Post-Quantum Security Into New Hardware

The important change is that Thales has built its post-quantum strategy into a new HSM platform, rather than treating it only as a firmware feature.

Thales announced Luna 8 on August 4, 2026, describing it as the next generation of its general-purpose HSM portfolio. The company positions the system as a hardware root of trust, meaning the protected foundation where organizations generate, store, and use critical keys.

The Luna 8 launch emphasizes a Thales-designed cryptographic processor and support for both current and post-quantum algorithms. That combination matters because migration will not happen through a single switch. Enterprises will operate classical and quantum-resistant cryptography together across long transition periods.

Post-quantum cryptography, or PQC, uses mathematical problems intended to resist attacks from sufficiently capable quantum computers. It runs on conventional computers and does not require quantum hardware. The change lies in the algorithms, their implementation, and the systems that manage their keys.

Luna 8 also introduces an architecture that Thales says can accept faster updates and new cryptographic mechanisms. This quality is known as crypto agility, the ability to replace algorithms, certificates, and policies without rebuilding every dependent application. It is central to the company’s pitch because today’s standardized algorithms might still require implementation updates or future replacements.

Thales says customers can migrate from Luna 7 through compatible application programming interfaces and a key migration solution. API compatibility can reduce application changes, but it does not make an enterprise migration automatic. Security teams still need to inventory keys, certificates, software dependencies, and devices that assume particular algorithm formats.

The company also highlights automation, monitoring, high availability, and multi-tenant scaling. These features connect Luna 8 to AI infrastructure, where services can generate large numbers of authentication, signing, and encryption operations. They also address hybrid environments that divide workloads across private infrastructure, public clouds, and managed services.

Thales has not publicly attached comprehensive independent performance results to the launch announcement. Its descriptions of higher throughput and predictable performance therefore remain company claims. Buyers will need workload-specific benchmarks, particularly for larger post-quantum keys and signatures.

This distinction separates a product launch from a verified operating result. Luna 8 packages the required components into a new platform, but deployment evidence will determine whether it shortens migration projects. That evidence matters because the pressure behind those projects is already increasing.

AI Workloads Are Turning Key Management Into a Capacity Problem

AI does not create a separate cryptographic universe, but it multiplies the identities, services, data exchanges, and automated decisions that depend on trusted keys.

Enterprise AI systems connect models with internal documents, databases, software tools, and external services. Every connection can require authentication, encryption, signing, or access control. Agentic systems increase the challenge because software agents can initiate actions and exchange credentials without continuous human approval.

Thales links Luna 8 directly to this growth in machine activity. An HSM can protect the keys used to authenticate an AI service, sign a model artifact, encrypt sensitive training data, or verify software entering a deployment pipeline. The HSM does not judge whether an AI output is accurate. It protects the cryptographic evidence used to establish identity and authorization.

This boundary is important. Hardware-backed keys can stop an attacker from simply extracting a protected private key. They cannot correct excessive permissions, insecure application logic, poisoned data, or an agent that follows a harmful instruction. Luna 8 addresses the cryptographic layer within a much larger AI security problem.

The company’s own data threat survey illustrates that larger problem. The research covered 3,120 security and IT management professionals. It found that 61% reported attacks targeting their AI applications, while 52% named identity and access management as their most pressing security discipline.

The report also found that only 47% of sensitive cloud data was encrypted. That figure exposes a gap between owning security technology and applying it consistently. A faster HSM cannot protect data that an organization never classifies, encrypts, or places under controlled key management.

AI can widen this gap. Teams often connect models to corporate information quickly, then add governance after a pilot proves useful. Credentials can spread across development environments, orchestration tools, plug-ins, and service accounts. Cryptographic capacity grows more valuable, but visibility and policy enforcement remain prerequisites.

Organizations managing AI research also face long confidentiality periods. Training records, proprietary documents, healthcare information, or government data collected today might remain sensitive for years. Attackers can capture encrypted material now and retain it until future methods make decryption practical.

This tactic is called harvest now, decrypt later. It creates a present risk even though no publicly known quantum computer can currently break widely deployed public-key encryption at useful scale. Organizations cannot recover confidentiality retroactively after stored ciphertext becomes readable.

The Thales survey found that 61% of respondents concerned with quantum computing cited future decryption of existing data as their leading quantum risk. It also found that 59% were prototyping or evaluating post-quantum algorithms. Those figures support demand for migration tools, but they do not prove that production adoption has reached the same level.

Luna 8 enters precisely at that divide. Experiments can run in isolated environments, while production cryptography touches certificates, customer transactions, software releases, backups, and disaster recovery. The cost of a failed experiment is limited. The cost of a failed trust infrastructure migration can stop core operations.

That makes AI a capacity accelerator and quantum risk a migration deadline. Thales is trying to address both with one platform. Its success depends on whether the underlying mechanism remains manageable outside a controlled pilot.

How Thales Luna 8 Handles the Cryptographic Transition

Thales Luna 8 combines protected key storage, post-quantum operations, and crypto agility, but organizations must still redesign the systems surrounding the appliance.

The platform’s first job is isolation. Cryptographic keys remain inside tamper-resistant hardware, while applications request approved operations through interfaces. This model reduces the chance that a compromised server can copy a high-value private key directly from memory or storage.

Its second job is algorithm support. NIST’s PQC standards include ML-KEM for establishing shared secrets and ML-DSA for digital signatures. NIST also standardized SLH-DSA as an alternative signature method based on different mathematics.

ML-KEM, short for Module-Lattice-Based Key-Encapsulation Mechanism, helps two systems establish secret key material across an untrusted network. ML-DSA, or Module-Lattice-Based Digital Signature Algorithm, allows a recipient to verify a signature’s origin and integrity. These algorithms address different tasks and cannot substitute for each other.

Thales had already added ML-KEM and ML-DSA support to Luna 7 firmware in July 2025. That release made standardized post-quantum mechanisms available to existing customers with compatible client software. Luna 8 changes the hardware foundation and makes PQC performance a central design goal.

That history prevents an exaggerated interpretation of the announcement. Luna 8 is not Thales’s first encounter with standardized PQC. It is an attempt to make the next migration stage easier to operate at higher scale.

Crypto agility is the connective tissue. Standards can change, implementations can expose flaws, and regulators can revise acceptable configurations. An agile platform should let an organization introduce a new mechanism while maintaining older services during testing.

In practice, that often means hybrid deployment. A system can combine a classical method with a post-quantum method so that an attacker must defeat both protections. Hybrid designs can reduce dependence on an unfamiliar algorithm, but they also increase message sizes, processing requirements, and integration complexity.

The HSM cannot update every dependent protocol by itself. Applications, certificate authorities, network devices, code-signing systems, and partner services must understand the selected mechanisms. Data formats and certificate chains may grow, creating pressure on systems designed around smaller classical signatures.

Migration also involves key mobility. Organizations need controlled backup, replication, recovery, and high-availability procedures. Thales documentation for its earlier Luna 7 implementation noted that ML-KEM and ML-DSA keys initially could not be wrapped off that HSM release.

That limitation illustrates why implementation details matter. An algorithm can be standardized while operational capabilities remain uneven across products and versions. Buyers evaluating Luna 8 should confirm how post-quantum keys behave during backup, cloning, failover, and migration.

Multi-tenancy adds another test. Organizations may divide one HSM among business units, applications, or customers through isolated partitions. Better utilization can lower operational overhead, but administrators must prove that policies, performance, and audit records remain separated under load.

AI applications make those load tests more demanding. Automated services can create bursts of signatures or authentication requests that differ from traditional transaction patterns. Predictable latency can matter as much as headline throughput when a cryptographic dependency sits inside an interactive service.

Thales says its custom processor was designed for high-volume post-quantum operations. Public launch materials do not provide enough comparable measurements to determine its advantage across every algorithm and workload. Independent testing should compare latency, sustained throughput, concurrency, failover behavior, and energy use.

The mechanism is therefore credible but incomplete as public evidence. Thales has aligned its architecture with standardized algorithms and known operational needs. Customers must verify whether those design choices translate into safer migrations under their own constraints.

Standards Have Shifted the HSM Contest From Support to Execution

NIST removed much of the uncertainty around which principal algorithms to deploy, so HSM vendors now compete on integration, certification, and migration quality.

NIST finalized FIPS 203, FIPS 204, and FIPS 205 in August 2024. The agency encouraged administrators to begin transitioning immediately. That decision moved PQC from a research selection process into an implementation program for governments and enterprises.

The shift pressures every provider that controls cryptographic infrastructure. Traditional HSM vendors such as Thales, Entrust, and Utimaco need standardized algorithm support and validated implementations. Cloud providers must expose compatible services without trapping customers inside incompatible key-management paths.

The competition is broader than a list of supported algorithms. Buyers need integrations with public key infrastructure, code-signing platforms, certificate management, databases, cloud services, and development pipelines. A nominal ML-KEM checkbox has little value if operational tools cannot monitor or recover the resulting keys.

Certification also matters. FIPS 140-3 evaluates cryptographic modules against security requirements, while algorithm validation tests specific implementations. These processes do not guarantee that an entire application is secure. They provide third-party assurance that is essential in regulated and government environments.

Thales has related evidence within its U.S. federal portfolio. In July 2026, Thales Trusted Cyber Technologies announced that its Luna T-Series received FIPS 140-3 Level 3 validation. The validated release included ML-KEM, ML-DSA, and the Leighton-Micali Signature scheme.

The T-Series validation applies to a separate U.S.-manufactured product line and should not be confused with certification for Luna 8. Thales states that FIPS 140-3 Level 3 and Common Criteria certification work for Luna 8 is underway. Until those processes finish, buyers should treat the certifications as pending.

This distinction creates the article’s central tradeoff. Waiting for every validation and integration reduces early deployment risk, but waiting also preserves exposure to harvest-now attacks. Moving first protects more long-lived data, yet it places greater testing responsibility on the adopter.

Government timelines increase the pressure. A White House national security memorandum set a goal of mitigating as much quantum risk as feasible by 2035. NIST’s migration guidance describes the expected transition away from quantum-vulnerable digital signatures and key-establishment schemes.

These dates can sound distant, but cryptographic migrations move slowly. An enterprise must locate cryptography embedded in source code, appliances, certificates, partner connections, and archived systems. It must then prioritize data by confidentiality period and confirm that replacement methods work across each dependency.

Certificate life cycles add another deadline. The CA/Browser Forum approved a gradual reduction in maximum public TLS certificate validity to 47 days by 2029. Shorter certificates require more automation, which can also create an opportunity to modernize algorithms and certificate management.

For Thales, the competitive advantage will come from reducing that operational burden. Compatible APIs, automated administration, and key migration can matter more than a laboratory speed record. Customers generally cannot pause a certificate authority or signing service while engineers redesign its trust foundation.

Cloud HSM services create another form of pressure. They can simplify procurement and capacity planning, particularly for teams without specialized hardware staff. Dedicated appliances offer greater control over location, administration, and physical custody, which remains important for some sovereignty and compliance requirements.

Thales supports on-premises, cloud, service-based, and hybrid deployment models across its portfolio. Luna 8 must show that this flexibility preserves consistent policy and recovery behavior. A fragmented management layer would undermine the crypto-agility argument.

The contest therefore has no simple winner based on the launch alone. Thales has assembled a credible combination of hardware, algorithms, and migration tooling. Entrust, Utimaco, and major cloud providers face the same standards, and buyers will compare verified behavior rather than slogans.

The Hardest Risks Sit Outside the Cryptographic Processor

Luna 8 can protect keys and accelerate approved operations, but it cannot repair incomplete inventories, weak access policies, or incompatible applications.

The first uncertainty is certification. Thales says Luna 8 was designed to meet FIPS 140-3 Level 3 and Common Criteria requirements, with validation work underway. Design intent is not equivalent to a completed certificate, especially for organizations whose procurement rules require a listed module.

The second is performance evidence. Post-quantum keys, ciphertexts, and signatures can be larger than their classical counterparts. Their impact varies by algorithm, security level, protocol, workload, and network path.

Thales describes its processor as optimized for PQC and says the platform provides high performance. The public announcement does not offer a complete benchmark methodology or direct competitor comparison. Buyers should request reproducible results rather than infer universal gains from product language.

The third risk is application compatibility. An HSM can execute ML-DSA correctly while an older certificate parser, network appliance, or signing workflow rejects the output. That failure can appear far from the hardware and become difficult to diagnose.

The fourth is migration governance. Many organizations do not know where all their cryptographic material lives. Keys can sit inside application code, local configuration, unmanaged certificates, devices, scripts, and third-party services.

Crypto agility depends on that inventory. A replaceable algorithm offers little protection when administrators cannot locate the systems using its predecessor. Discovery must therefore precede large-scale migration.

AI compounds the inventory problem because teams build new integrations quickly. A model application can acquire database credentials, service tokens, encryption keys, and signing rights across several environments. Each connection expands the surface that security teams must map and control.

Protected keys also do not guarantee appropriate use. An overprivileged AI agent might ask the HSM to sign an authorized but harmful operation. The key never leaves hardware, yet the surrounding authorization decision still fails.

Security architects must separate cryptographic trust from application trust. HSM policies should limit which identities can use a key, for which operations, and under which approval conditions. Logs must connect cryptographic events with application identities and business context.

Migration itself can create downtime or data loss when backup and recovery procedures are incomplete. Teams should test failure scenarios involving unavailable appliances, damaged partitions, expired certificates, incompatible clients, and rolled-back software. A successful demonstration under normal conditions is not enough.

Algorithm diversity creates another challenge. NIST selected multiple signature approaches partly to avoid depending on a single mathematical foundation. Supporting more algorithms can improve resilience, but each new option adds configuration and testing decisions.

Organizations should resist declaring systems “quantum-safe” as a single permanent state. Security depends on the selected algorithm, its parameters, its implementation, and every surrounding protocol. It also depends on an organization’s ability to change those elements later.

The same caution applies to harvest-now risk estimates. There is no agreed public date for a cryptographically relevant quantum computer. The absence of a precise date does not remove the exposure for information that must remain secret for decades.

A rational migration program prioritizes by consequence and confidentiality period. Long-lived government, healthcare, financial, research, and intellectual-property data deserves earlier attention. Short-lived information with limited impact can follow a different schedule.

Luna 8 gives those programs another infrastructure option. It does not replace discovery, architecture review, testing, or governance. Thales’s strongest claim is therefore narrower than absolute future protection: the platform is designed to make cryptographic change more manageable.

Three Signals Will Show Whether Luna 8 Delivers

Certification, independently comparable performance, and production migration evidence will determine whether Luna 8 becomes infrastructure or remains an early platform promise.

The first signal is completed third-party validation. Buyers should watch for Luna 8 entries under FIPS 140-3 Level 3 and applicable Common Criteria programs. Completed certifications would strengthen Thales’s case in government, finance, healthcare, and other regulated markets.

The exact validated configuration will matter. Certificates normally apply to defined hardware, firmware, and operating conditions. Customers must confirm that the version they plan to deploy matches the version covered by an evaluation.

A delayed or narrowly scoped certification would weaken adoption among buyers with formal assurance requirements. It would not prove that the product is insecure. It would limit where organizations can deploy it without additional exceptions or controls.

The second signal is independent or customer-verifiable performance data. Useful tests should measure classical and post-quantum operations, mixed workloads, concurrent clients, failover, backup, and management overhead. They should also disclose algorithm parameters and system configurations.

Strong results across sustained workloads would support Thales’s custom-processor argument. Results limited to isolated peak throughput would offer less evidence for AI services or certificate systems that require predictable latency.

Performance should include operational recovery. A fast signing service that becomes difficult to restore after failure creates a different business risk. Tests involving replication and disaster recovery will reveal more than ideal-path demonstrations.

The third signal is documented production migration. Thales needs customer examples showing how Luna 7 applications, keys, policies, and integrations moved to Luna 8. The strongest evidence would include migration duration, compatibility findings, rollback procedures, and service availability.

Early deployments should also show how organizations run hybrid cryptography. They should explain which applications use classical and post-quantum methods together, and how teams monitor both paths. That evidence would turn crypto agility from an architectural promise into an operating practice.

Competitor responses belong inside this signal. Expanded PQC support from Entrust, Utimaco, or cloud HSM providers would validate market demand while increasing pressure on Thales. Comparable certifications and migration tools would reduce the differentiation of Luna 8.

Enterprise buyers do not need to wait passively for every result. They can begin with a cryptographic inventory, identify data with long confidentiality periods, and test standardized algorithms outside production. They can also document which systems depend on RSA or elliptic-curve cryptography.

Teams building AI services should map machine identities alongside human identities. They should examine where agents obtain credentials, which actions those credentials authorize, and whether high-impact operations require additional approval. That work remains valuable regardless of the chosen HSM vendor.

The immediate question is not whether to replace every cryptographic system at once. It is whether an organization can identify its most durable risks and test a controlled migration before deadlines compress its choices. Thales Luna 8 offers a new hardware path for that process, but evidence must now catch up with architecture. Security leaders should ask vendors for validated configurations, reproducible workload results, and complete recovery demonstrations before treating post-quantum readiness as finished.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page