The price of a right answer.
What does it cost to get one reliable answer from a quantum computer, and for which problems is that answer worth the cost?
A rumor by the weekend.
In April 1994, Peter Shor, a mathematician at AT&T Bell Laboratories in Murray Hill, New Jersey, had found a way for a computer obeying the rules of quantum mechanics to solve a problem called the discrete logarithm. He showed it to his colleague Jeff Lagarias, who found a minor bug, and to his manager, David Johnson, who suggested he present it at Henry Landau's seminar. The seminar met every Tuesday, and its audience, Shor recalled, "constantly interrupted the speaker with questions." He spoke on a Tuesday that April. His talk was about discrete logarithms only, because he had not yet worked out how to factor a number.
Later that week, he worked it out. That weekend he was at home with a bad cold when the telephone rang. The caller was Umesh Vazirani, a computer scientist whose talk at Bell Labs in 1992 had brought Shor back to the subject, and he had heard something. "I hear that you can factor efficiently with a quantum computer," he said. Between the seminar room and Vazirani, the story had passed from one listener to the next, as in the children's game of telephone, and discrete logarithms had turned into factoring on the way. By the time the rumor arrived, it was true, and Shor explained the factoring algorithm over the phone.
In Shor's words, "the news spread like wildfire." He gave a last-minute talk at a number theory symposium at Cornell in early May. Later that month, Vazirani presented the algorithm at a meeting at the Santa Fe Institute, which Shor could not attend. There Rolf Landauer of IBM raised the objection that would shape the next thirty years: nobody knew how a quantum computer could tolerate faults. Without it, as Shor later summarized the objection, a computation of N steps needs every step accurate to about one part in N, and factoring a number of cryptographic size takes something like a billion steps. The full paper appeared in November 1994, at a computer science conference in Santa Fe.
The rumor had run ahead of the proof by a few days. The machine has run behind it ever since. Shor's algorithm turns factoring the large numbers behind RSA encryption, a job that ordinary computers could not finish in any useful time, into a computation of reasonable length. It does so on a machine that must run billions of steps without an uncorrected error, built from parts that fail far more often than that. As of October 2026, the largest RSA challenge number ever factored has 270 digits, and ordinary computers factored it.
Before we start.
Landauer's objection did not deny that the algorithm was correct. It said that a correct answer would cost something no one knew how to pay. That cost, and what it buys, is the subject here: what does it cost to get one reliable answer from a quantum computer, and for which problems is that answer worth the cost?
The answer has two halves, and the chapters take them in order. For a small class of problems with hidden structure, such as the period of a repeating sequence or the behavior of electrons in a molecule, a quantum computer can arrange for wrong answers to cancel and the right one to reinforce, and reach an answer in far fewer steps than any known ordinary method. For most problems, sorting a list or running a spreadsheet among them, it offers nothing. The price is reliability. The best physical qubits err about once in a thousand operations, so a useful computation must be protected by error correction, which spends many physical qubits on each reliable one and needs a refrigerator, a microwave signal chain and a fast classical computer around them. A 2025 estimate for the guide's thread, factoring the 617-digit number known as RSA-2048, is just under a million physical qubits running for about five days, and designs published in 2026 trade fewer qubits for longer runs. The machines that ran error correction in 2026 hold hundreds of physical qubits, not hundreds of thousands.
A quantum computer never shows its state. Each run returns one sample, and every algorithm is a way of making that sample worth having. Reading a qubit gives a plain 0 or 1, drawn at random from odds the machine has prepared. Nothing in between can be read without changing it. Every claim in the chapters ahead, about speed, about errors or about a company's latest processor, comes down to how good that one sample is and how many runs it took to get it.
Two cases recur. The thread is RSA-2048 and the estimates, from 1994 to 2026, of the machine needed to factor it, which fell from about a billion qubits in 2012 to under a million in 2025, while the product of qubits and hours, on the same hardware assumptions, has fallen by only about a third since 2019. The second case is Willow, a 105-qubit chip from Google Quantum AI, which in 2024 showed a quantum memory whose errors fell by more than half each time it was made larger. The chapters build from one qubit to that chip, and from the chip to the bill.
How to read this guide
The 22 chapters form one sequence in eight parts. Each opens with the question left open by the chapter before it, and each contains at least one solved example worked with real numbers. Plates are numbered on their own, so any one can be cited by itself. Four kinds of box recur:
Blue edge. Carries the structural point of a section, or a calculation worked once with real values and stated assumptions.
Orange edge. Names a common misreading, a trap, or the limit of a claim.
Green edge. Maps the idea onto the reader's own work: specifying or evaluating hardware, reading a result or an announcement, or planning a project.
- Each chapter closes with what it established, in four lines.
The mathematics stays at arithmetic: powers, square roots, percentages and the remainder after a division. Quantum states appear as arrows, each with a length and a direction, and adding arrows is drawn rather than written as algebra; the plates do the geometry. Large and small numbers are written with powers of ten, as in 10¹⁵ for a million billion, and a rate as "1 in 10¹⁵". Where a figure is a company's own claim, the text says so. The guide uses US spelling.
Inside the plates, color is a legend and never decoration. The quantum state, drawn as arrows, is violet; the pulses the machine sends in to control it are gold; noise and errors are magenta; information protected by error correction is teal. Classical bits, the readings and every number computed from them, are always blue, and one orange mark in each plate points at the detail that matters most. A key strip under every plate lists only the colors that plate uses.
This is a reference for understanding, not an engineering specification, investment advice or a security assessment. Machines, records, company positions and estimates are stated as of October 2026 and will date. Where a figure comes from a company about its own product, or from a paper whose authors work for that company, the text says so. Named companies and machines are examples of a principle, not recommendations.
+ Part I · One sample
What is hard, and what a qubit is.
A laptop multiplies two primes of 309 digits each in a fraction of a millisecond, while no computer yet built can find them again from their 617-digit product. Part I starts from that asymmetry. Chapter 1 shows why the reverse direction defeats ordinary computers however fast they become, Chapter 2 what a qubit physically is and what reading one gives, and Chapter 3 what a quantum computer holds between readings: not odds, but arrows that can add up or cancel.
Problems that outgrow computers.
+ The questionWhy can't a faster ordinary computer factor a 617-digit number?
One sum, two directions
RSA-2048 is a number 617 digits long that RSA Laboratories published as part of a factoring challenge, with a prize of 200,000 dollars for anyone who found its two prime factors. The challenge ended in 2007 and the prize was never claimed. The number is the product of two primes of about 309 digits each, and finding them is the whole difficulty. Multiplying the two primes together is quick: the schoolbook method takes about 309 × 309, or roughly 95,000, single-digit multiplications, a fraction of a millisecond for a laptop.
Going back is another matter. The obvious method, dividing by every prime in turn, needs to try candidates up to the square root of the number, which for RSA-2048 has about 309 digits. There are far more such candidates than the roughly 10⁸⁰ atoms usually estimated for the observable universe. The asymmetry is what RSA encryption rests on: a public key contains a large product, and the private key that decrypts depends on knowing its factors. Anyone who could factor the product quickly could read what the key protects.
The best ordinary method
Mathematicians found far better methods than trial division, and the best known for numbers of this size is the number field sieve. It hunts for many small numbers with convenient factors, then combines them, with a very large matrix calculation, into a relation that splits the target. Every recent factoring record for numbers of this kind was set with it. The table lists the record challenge numbers factored since 2009 and the effort each team reported.
| Number | Digits | Completed | Effort reported by the team |
|---|---|---|---|
| RSA-768 | 232 | December 2009 | about 2,000 years of one 2.2 GHz processor core |
| RSA-240 | 240 | November 2019 | about 1,000 core-years |
| RSA-250 | 250 | February 2020 | about 2,700 core-years |
| RSA-260 | 260 | September 2026 | about 13.5 GPU-years (company figure) |
| RSA-896 | 270 | September 2026 | about 30 GPU-years |
The effort figures are not strictly comparable, because processors, software and accounting differ: RSA-240 took fewer core-years than RSA-768 despite being larger, thanks to better software and newer processors. The two 2026 records moved the work from processors to graphics processors. RSA-260 was factored on 3 September 2026 by a researcher at the AI company Cognition, using a version of the open-source CADO-NFS software rewritten for graphics processors with the company's coding agent; the company puts the cost at about 400,000 dollars and calls it ten times cheaper than the previous state of the art. Sixteen days later, RSA-896, with 270 digits, fell to a similar GPU version run by an engineer at Anthropic on up to 2,048 graphics processors over about ten days. Both factorizations can be checked by multiplying the published factors, and they are correct; the compute figures are the researchers' own.
The RSA-260 account shows where the effort goes. Choosing a good polynomial to sieve with took about 640 GPU-days, the sieve itself about 3,800, and the final matrix calculation about 470. That matrix had about 656 million rows and as many columns, with about 98 billion nonzero entries, and solving it is what turns billions of collected relations into the two factors. Every stage grows with the size of the number, which is why each record is a project of its own rather than a rerun of the last one with a bigger input.
How fast the wall rises
Each record took months or years of preparation and moved the frontier by about ten digits. The reason is the shape of the sieve's cost: each additional ten digits multiplies the work by roughly two and a half to three at today's sizes, and that multiplier shrinks only slowly as numbers grow.
The sieve's published cost formula gives a ratio of about 2.6 for each extra ten digits near 250 digits. The records agree: in the same team's accounting, RSA-250 took about 2,700 core-years against 953 for RSA-240, a ratio of about 2.8. Applying the formula from RSA-260 (862 bits) to RSA-2048 (2,048 bits) multiplies the work by about 9 × 10¹⁰. Starting from 13.5 GPU-years, that gives 13.5 × 9 × 10¹⁰, or about 1.2 × 10¹² GPU-years, the figure the RSA-260 team itself published. A million graphics processors working together would need about 1.2 million years. The formula drops a correction term, so the result is an order of magnitude, not a forecast.
The same arithmetic shows how little raw speed buys. A computer a thousand times faster factors, in the same time, a number only as much larger as a thousandfold increase in work allows: a thousand is seven or eight such multipliers, so the frontier moves by about eighty digits. From 270 digits, that is still more than 260 digits short of RSA-2048.
Speed improvements multiply what a machine can do; the cost of factoring multiplies with every few digits added. A millionfold faster computer would reach only about 450 digits by the sieve's formula, far short of 617. Only a method whose cost grows more slowly changes the picture, and that is what Shor's algorithm offers.
Polynomial, exponential and in between
Computer scientists sort methods by how their cost grows with the size of the input, here the number of digits. A cost is polynomial when it grows like a fixed power of the size: schoolbook multiplication grows with the square of the digits, so doubling the digits multiplies the work by four. A cost is exponential when each added digit multiplies it by a fixed factor: trial division multiplies its candidates by ten for every two digits added, because the square root of the number gains one digit. Doubling at every step is exponential growth, however slow its first steps look.
The number field sieve sits between the two. Its cost grows faster than any fixed power of the digits but more slowly than doubling with each one, and computer scientists call that sub-exponential. Between 1,024 and 2,048 bits it multiplies by about a billion. Shor's algorithm, by contrast, is polynomial: with schoolbook arithmetic inside it, its number of operations grows roughly with the cube of the number of bits, so doubling the length of the key multiplies its work by about eight.
A second wall: describing nature
Factoring is a problem about numbers. A second wall, older in the history of the subject, concerns physics. Describing the joint state of many interacting two-level systems, such as the spins of electrons in a molecule or a magnet, takes one number for every combination of their states, and with fifty systems that is 2⁵⁰, about 10¹⁵ numbers. Each added system doubles the count, so the description grows exponentially, and ordinary computers manage only small cases exactly or rely on clever approximations. In 1981, Richard Feynman proposed that a machine built from quantum parts could carry such a description naturally; Chapter 10 follows that idea to the chemistry it is meant to serve.
These two walls, structured problems in arithmetic and the simulation of quantum matter, hold almost every case in which a quantum computer is known to give a large speedup. Most problems ordinary computers handle, from sorting to spreadsheets, face neither wall, and Chapter 9 shows why a quantum computer gives them little or nothing.
What would change, and what it would cost
Shor's algorithm turns factoring from a sub-exponential problem into a polynomial one, on a machine that does not yet exist at the needed size. The change is in the growth rate, not in seconds: a quantum computer runs each step far more slowly than a laptop, and Chapter 6 shows that a modest speedup can be eaten entirely by that slowness. The algorithm's advantage is decisive only because the gap in growth rates, between about eightfold and about a billionfold for a doubled key, is so large.
The steps of that algorithm must also be correct. The rumor of 1994 ran into Landauer's objection within a month, and the objection is still the subject of most of the engineering in this guide. Chapters 7 and 8 show how the algorithm works, Chapters 12 to 16 what keeping its billions of steps correct costs, and Chapter 22 adds up the bill for RSA-2048.
When a quantum computer is compared with an ordinary one, ask three questions before reading the ratio of times. How does the cost of each method grow with the size of the problem? Which classical method, on which hardware, served as the baseline? And how large was the problem? A speedup measured at one size says little about the next, and a comparison against an outdated classical method says little at all.
- Multiplying two large primes is quick, while recovering them from their product defeats ordinary computers, and RSA encryption rests on that asymmetry.
- The best ordinary method, the number field sieve, multiplies its work by roughly 2.6 for every ten digits near today's records, which reached 270 digits on graphics processors in September 2026.
- Faster hardware moves that frontier by tens of digits, while RSA-2048 needs about a trillion GPU-years by the sieve's own formula.
- Shor's algorithm changes the growth rate itself, from sub-exponential to polynomial, but only on a quantum machine whose billions of steps are kept correct.
A thing with two levels.
+ The questionWhat is a qubit, physically, and what do you get when you read one?
An atom made of wire
Each Willow chip carries 105 transmons, small superconducting circuits patterned in aluminum on a chip and cooled to about a hundredth of a degree above absolute zero. At the heart of each transmon is a Josephson junction, two thin films of superconducting metal separated by a barrier of their own oxide, through which pairs of electrons can tunnel. A circuit built around such a junction behaves in one important way like an atom: its energy can take only certain values, called levels, and it moves between them by absorbing or giving up a definite amount of energy.
A qubit uses two such levels. In a transmon, the lowest level is called 0 and the next one up is called 1, and the energy between them corresponds to a microwave frequency of around 5 GHz, the range of a Wi-Fi radio. A microwave pulse at that frequency can lift the circuit from 0 to 1 or bring it back. The circuit has further levels above 1, and a practical guide to these devices explains why they stay unused: the step from 1 to 2 is designed to be smaller than the step from 0 to 1, typically by 200 to 300 MHz, so a pulse tuned to the first step does not drive the second.
The uneven spacing matters. A pendulum or an ordinary electrical resonator has evenly spaced levels, and a pulse that lifts it one step would lift it the next step too, so it cannot be confined to two. The name transmon comes from a 2007 design paper that made the circuit insensitive to stray electric charge, which had disturbed earlier versions, at the price of making the levels a little more evenly spaced. Both IBM and Google build their processors from transmons.
Many ways to make two levels
Any physical system with two levels that can be controlled and told apart can serve as a qubit, and the main approaches differ in what those levels are. The table lists five that appear in later chapters.
| Kind of qubit | What 0 and 1 are | Controlled with | Examples in this guide |
|---|---|---|---|
| Superconducting circuit (transmon) | the two lowest energy levels of the circuit | microwave pulses | Google Willow, IBM Heron |
| Trapped ion | two levels of an ion's outermost electron, split by the nucleus's magnetism | microwaves or lasers | ytterbium-171 (12.6 GHz apart); barium-137 in Quantinuum Helios |
| Neutral atom | two such levels of an uncharged atom held in a laser beam | lasers | rubidium-87 arrays |
| Photon | one photon in one of two waveguides | optical components on a chip | PsiQuantum's "dual-rail" qubits |
| Electron spin | an electron's spin pointing with or against a magnetic field | microwaves and voltages | silicon quantum dots |
The approaches differ in more than their parts list. Every ytterbium-171 ion is identical to every other, so ion and atom qubits start out alike and differ only through their surroundings. Transmons are manufactured, and no two come out exactly the same, so each one's frequency and pulses must be measured and tuned, the calibration that Chapter 18 describes. Photons need no refrigerator to hold their state but are hard to make interact, and electron spins in silicon borrow the methods of the chip industry but sit in material whose stray nuclei disturb them. Chapter 19 sets out what limits each approach.
Older superconducting designs used other pairs of states. The flux qubit, described in 1999, stores 0 and 1 as electric currents circulating in opposite directions around a small loop interrupted by three or four junctions. It is still studied, but the superconducting processors in the error-correction experiments of Part V are built from transmons, whose 0 and 1 are energy levels, not currents.
Reading gives one bit
Reading a qubit, which physicists call measurement, always produces one of two answers, 0 or 1. A transmon is read by sending a weak microwave tone past a small resonator coupled to it; the resonator's response shifts slightly depending on whether the qubit is in 0 or 1, and Chapter 18 follows that faint signal to a decision. A trapped ion is read by shining a laser that makes it glow in one of its two states and stay dark in the other. Either way, the output is a single classical bit.
Reading takes time, and the time is part of the cost. On Willow the readout tone lasts between about 250 and 480 nanoseconds, against 25 nanoseconds for a single-qubit gate and 42 for a two-qubit gate, so a reading is the slowest routine operation on the chip. Small laboratory devices have been read with errors of about 1 in 400 in 100 nanoseconds, but reading all the qubits of a large chip at once, as error correction requires, is harder than reading one well.
The reading also changes the qubit. Whatever the qubit held before, afterward it is, ideally, in the level that was read, and a second reading straight after the first gives the same answer. Readings also err: Google's specification sheet for its Willow error-correction chip gives an average measurement error of 0.77 %, and a 2025 paper by Quantinuum's staff on its Helios machine reports combined preparation and measurement errors of about 1 in 2,000.
Odds, estimated by repetition
A qubit can be prepared so that a reading gives 0 seventy times in a hundred and 1 thirty times. One reading reveals nothing about those odds: it is a single 0 or 1. The odds show up only when the same preparation is repeated and read many times, and each repetition is called a shot. Every probability a quantum computer reports is an estimate from shots, and its precision is paid for in shots.
Prepare a qubit with odds of 70 % for 0, and read it 1,000 times. The expected count of zeros is 700. The spread of such counts follows the rule for repeated coin tosses: the square root of 1,000 × 0.7 × 0.3, or about 14.5. About 95 % of runs of 1,000 shots therefore give between about 672 and 728 zeros, an estimate of 70 % give or take about 3 percentage points. The spread shrinks only with the square root of the shots: four times as many shots halve it, and a spread of a tenth of a percentage point needs about 210,000 shots.
The odds describe how the qubit was prepared, and the same odds can come from preparations that are physically different. That is where a qubit stops resembling a biased coin. Two qubits prepared with the same 70/30 odds can, after one more operation, give quite different results, and the difference lies in something a single reading never shows. Chapter 3 introduces it.
A qubit read as 0 was not secretly 0 before the reading, waiting to be discovered, in the way a coin under a hand is already heads or tails. Experiments of the kind described in Chapter 3 rule out the simplest such picture. The odds are a property of the preparation, and only repeated preparations reveal them.
The cost already visible
Two parts of the price this guide adds up appear in this chapter. The first is shots: an answer read from one run is one sample, and an answer known to a given precision needs many runs. The second is error: on full processors in 2026, two-qubit gates and readouts still fail between about 1 time in 2,000 and 1 time in 100, depending on the machine and the operation. Chapter 12 shows where those errors come from, and Chapter 13 how they compound over a long computation.
How many shots an answer needs depends on the question. An algorithm whose answer can be checked, such as a pair of factors that either multiply to the target or do not, needs only the few runs its method uses; one 2025 design for Shor's algorithm combines about nine runs per factorization in its classical post-processing. An algorithm that estimates an average, such as the energy of a molecule, needs enough shots to bring the spread below the precision wanted, and Chapter 10 shows how that requirement can dominate the cost.
A count of qubits says little by itself. Ask for the error of each kind of operation: preparation and readout, single-qubit gates and two-qubit gates, with how long each takes and how long the qubits hold their state. Ask whether figures are medians, means or best cases, and how widely they vary across the chip, and whether each ± value describes that spread or the uncertainty of a measurement. Ask how many shots stand behind each figure.
- A qubit is any physical system with two levels that can be controlled and told apart; IBM's and Google's are transmons, whose 0 and 1 are the two lowest energy levels of a superconducting circuit.
- A transmon's uneven level spacing lets a pulse at around 5 GHz drive the step from 0 to 1 without touching the levels above.
- Reading a qubit gives one bit, leaves the qubit in the state read, and itself errs: Helios's preparation and reading together err about 1 time in 2,000, and Willow's measurements about 1 time in 130.
- Odds are estimated only from many shots, and their precision improves with the square root of the number of shots.
What the machine holds between readings.
+ The questionIf every reading gives a plain 0 or 1, what is the machine holding the rest of the time?
A puzzle with two mirrors
Send single photons, one at a time, at a half-silvered mirror, and each one turns up at one of the two detectors placed behind it, half the time at each, with no way to predict which. Now let the two beams leaving the mirror travel separate paths, bring them back together at a second half-silvered mirror, and place the detectors behind that one. Common sense, and ordinary probability, predict half at each detector again: each photon chose a path at the first mirror and makes a fifty-fifty choice at the second. In the experiment, with the two paths adjusted to the same length, every photon arrives at the same detector, and the other stays dark.
The arrangement is called a Mach–Zehnder interferometer, and it had long been used with ordinary light, where the dark output is explained by waves canceling. The puzzle is that it still happens one photon at a time. In 1986, Philippe Grangier, Gérard Roger and Alain Aspect showed first that their source gave single photons: behind a single half-silvered mirror, a photon was almost never detected at both outputs at once. They then sent the same single photons through an interferometer and recorded interference with a visibility above 98 %, meaning that the dark output was very nearly dark.
A single photon cannot be split, and yet the result depends on both paths. Something associated with each path must combine at the second mirror. Probabilities cannot do this, because probabilities only add: two routes to the dark detector, each with some chance, could never sum to zero.
Arrows instead of odds
The description that works was popularized by Richard Feynman in his 1985 book QED: The Strange Theory of Light and Matter. Each way an event can happen contributes an arrow, and the arrow has a length and a direction. The arrows for all the ways an outcome can happen are added head to tail, and the chance of that outcome is the square of the length of the total arrow. Physicists call the arrow an amplitude, and its direction its phase.
For a half-silvered mirror, the rules are simple. Passing straight through shortens an arrow to about 0.707 of its length, which is 1 divided by the square root of 2, and leaves its direction alone. Bouncing off shortens it by the same amount and turns it a quarter turn. Squaring 0.707 gives one half, the familiar fifty-fifty of a single mirror.
A photon reaches the upper detector by two routes: straight through the first mirror and reflected at the second, or reflected at the first and straight through the second. Each route gets one quarter turn and two shortenings, so each arrives as an arrow of length 0.707 × 0.707 = 0.5, pointing the same way. The full mirrors that steer the two beams turn both arrows alike and can be left out. Head to tail the two arrows make one of length 1, and the chance is 1² = 100 %. The lower detector is reached by passing straight through both mirrors, with no turn, or by reflecting at both, with two quarter turns, a half turn. The two arrows of length 0.5 point in opposite directions and add to zero: a chance of 0². Block one path, and each detector gets a single arrow of length 0.5, a chance of 0.5², or 25 %; the other half of the photons hit the block. Blocking a path lights up the dark detector.
The last line of the example is the strongest evidence that arrows are the right bookkeeping. Removing a route to an outcome made that outcome more likely, which no account built on probabilities can produce. A 2007 experiment by a French team that included Grangier and Aspect, using single photons from a defect in diamond, made the point sharper still. When the apparatus could tell which path each photon took, it did so with an error below 1 % and showed no interference; when it could not, the interference returned with a visibility of 94 %.
A qubit is two arrows
The same bookkeeping describes a qubit. Between readings, a qubit is described by two arrows: one for the outcome 0 and one for the outcome 1. The squares of their lengths are the odds of reading 0 and 1, and they add to one. The qubit prepared at 70/30 in Chapter 2 has an arrow for 0 of length about 0.837 and an arrow for 1 of length about 0.548, because 0.837² is 0.70 and 0.548² is 0.30.
The directions of the two arrows do not show up in a single reading, and that is what Chapter 2 left open. Two qubits can both have arrows of length 0.707, so both read fifty-fifty, but in one the two arrows point the same way and in the other they point opposite ways. Read now, they are indistinguishable. Passed through one more operation of the half-silvered-mirror kind, one of them gives 0 every time and the other gives 1 every time, exactly as the two detectors behind the second mirror did. Chapter 4 shows that operation inside a quantum computer.
The arrows are the state of the machine, and they are what it computes with. They are not read; a reading draws one outcome with the odds the arrows set and leaves the qubit in that outcome. This is the invariant of the guide: a quantum computer never shows its state, and each run returns one sample. Everything a quantum algorithm does happens to the arrows before that sample is drawn.
A common account says that a quantum computer tries every possible answer at once and picks out the right one. The first half is loosely true: a register of many qubits can carry arrows for an enormous number of outcomes. The second half is false. Reading the register returns one outcome, drawn at random by the odds, and nothing more. A quantum algorithm is useful only if it first makes the arrows of wrong answers cancel and those of the right answer add, as the second mirror does for the dark detector.
Not knowing, or not having
A natural objection is that the odds might simply express ignorance: perhaps each qubit, or each photon, really is in one definite state all along, and the arrows merely summarize what is not known. In 1964 John Bell showed that this can be tested. If the outcomes of measurements on two separated particles were fixed in advance by properties carried with them, and if a measurement on one could not be influenced by the choice of measurement on the other, then the correlations between their results would obey a limit. In the version most experiments use, a combination of correlations called S cannot exceed 2. Quantum mechanics predicts values up to about 2.83.
Experiments followed for decades, and in 2015 three groups closed the main loopholes at once. A team in Delft measured the spins of two electrons 1.3 kilometers apart and found S = 2.42, give or take 0.20, from 245 trials, which is a modest margin; photon experiments in Vienna and at NIST, the US standards laboratory, reached far stronger statistics. The 2022 Nobel Prize in Physics went to Alain Aspect, John Clauser and Anton Zeilinger "for experiments with entangled photons, establishing the violation of Bell inequalities and pioneering quantum information science."
Bell's result rules out a precise class of explanations, those in which outcomes are fixed in advance by local properties. It does not rule out every hidden mechanism: a theory proposed by Louis de Broglie and David Bohm reproduces quantum predictions by allowing distant particles to influence each other instantly, and philosophers still debate what the arrows are. For building and using a quantum computer the debate changes nothing. The arrows predict every result, they can cancel, and the engineering in the rest of this guide is the work of keeping them intact until the one sample is drawn.
Correct odds alone prove little, because an ordinary random-number generator can produce any odds. What marks quantum behavior is interference: a result that depends on the directions of arrows, which changes when a path is blocked or a phase is shifted. When a device or a demonstration is described, ask what showed interference, and with what visibility. In a laboratory, the standard checks of a qubit are interference sequences of exactly this kind.
- Single photons sent through two half-silvered mirrors all leave by one output, and blocking one path lights up the dark one, which no account built on probabilities can explain.
- Arrows explain it: each way to an outcome contributes an arrow with a length and a direction, the arrows add head to tail, and the chance of the outcome is the square of the total length.
- A qubit between readings is two arrows, one for 0 and one for 1; their lengths set the odds, and their directions decide what later operations do.
- Bell tests, loophole-free since 2015, rule out outcomes fixed in advance by local properties, and a reading returns one sample drawn from the odds the arrows set.
+ Part II · Interference does the work
How arrows are steered, multiplied and made to cancel.
Eight possible answers, two rounds of a simple routine, and the right one comes out 94.5 % of the time; a sequence that repeats every four steps, and a reading that reveals the period without ever showing the sequence. Part II builds the machinery behind such results. Chapter 4 shows how gates turn arrows without reading them, Chapter 5 how a register of qubits carries an arrow for every possible output, Chapter 6 how a search makes one answer's arrow grow, and Chapters 7 and 8 how Shor's algorithm turns factoring into finding a period and reads that period through interference.
Turning arrows without looking.
+ The questionHow does a machine change the arrows without reading them?
A gate turns arrows
A gate is an operation that changes a qubit's arrows in a fixed and reversible way, without reading them. It is the quantum counterpart of a logic gate in an ordinary processor, with one difference that shapes everything after it: an ordinary gate takes in bits and puts out bits, while a quantum gate takes in arrows and puts out arrows, and nothing is learned about the qubit while it acts. A computation is a sequence of gates followed, at the end, by a reading.
A few gates recur throughout the guide. The X gate swaps the arrows for 0 and 1, so a qubit holding 0 ends up holding 1 and the reverse; it is the quantum version of NOT. The Z gate leaves the arrow for 0 alone and turns the arrow for 1 through half a turn. The S gate turns the arrow for 1 by a quarter turn, and the T gate by an eighth of a turn, 45 degrees. Applied to a qubit that reads 0 or 1 with certainty, the last three change nothing a reading could see; their effect appears only when arrows later combine.
Every gate can be undone by another gate, because turning and swapping arrows loses no information. Reading is the only step in a quantum computation that cannot be reversed.
Reversibility rules out some familiar logic. An ordinary AND gate takes two bits and returns one, so its output cannot reveal which inputs produced a 0, and information is thrown away. A quantum computer does its arithmetic with a reversible substitute, the Toffoli gate, which keeps both inputs and flips a third bit only when both inputs are 1. Every addition and multiplication inside Shor's algorithm is built from Toffoli gates and simpler ones, which is why estimates for RSA-2048 count Toffoli gates in their billions.
In hardware, a gate is a carefully shaped pulse. On Willow, a microwave pulse of 25 nanoseconds performs a single-qubit gate, and the pulse's duration, strength and timing decide how far the arrows turn; Chapter 18 follows the pulse from the electronics that shape it to the chip.
The mirror inside a qubit
The most important single-qubit gate is the Hadamard gate, written H, and it does to a qubit what a half-silvered mirror does to a photon. Applied to a qubit holding 0, it produces two arrows of length 0.707 pointing the same way, odds of fifty-fifty. Applied to a qubit holding 1, it produces two arrows of the same length pointing opposite ways, also fifty-fifty. A reading cannot tell the two results apart. The next gate can.
Start with a qubit holding 0 and apply H: arrows of 0.707 for 0 and 0.707 for 1. Apply H again. Each of the two arrows sends a share to each outcome, scaled by 0.707, and the share sent from the 1-arrow to outcome 1 is turned half a turn. Outcome 0 receives 0.707 × 0.707 + 0.707 × 0.707 = 0.5 + 0.5 = 1. Outcome 1 receives 0.707 × 0.707 − 0.707 × 0.707 = 0.5 − 0.5 = 0. The qubit is back at 0 with certainty. Now insert a Z gate between the two Hadamards: it turns the 1-arrow half a turn before the second H. Outcome 0 now receives 0.5 − 0.5 = 0, and outcome 1 receives 0.5 + 0.5 = 1. One gate that changed nothing a reading could see has changed the answer from certain 0 to certain 1.
The example is the two-mirror experiment of Chapter 3 run inside a qubit, and it contains the whole mechanism of a quantum algorithm in miniature. The first Hadamard spreads the qubit over two outcomes, a gate in the middle marks one of them with a turn, and the second Hadamard makes the arrows interfere, so that the mark decides which outcome survives. Chapters 6 and 8 repeat the same three moves on registers with millions of outcomes. The mark need not be a half turn. With a T gate in the middle, an eighth of a turn, the two shares reaching outcome 0 point 45 degrees apart and add to an arrow of length about 0.924, so the qubit reads 0 about 85 % of the time and 1 about 15 %. Partial turns give partial interference, and that is how gates set any odds between certainty and fifty-fifty.
Gates on two qubits
Single-qubit gates cannot make qubits influence each other, and a computation needs that. The standard two-qubit gate is the controlled-NOT, or CNOT: it applies an X gate to one qubit, the target, if and only if the other, the control, holds 1. Its table of results is the ordinary truth table of a reversible XOR: 00 stays 00, 01 stays 01, 10 becomes 11, and 11 becomes 10. Google's processors perform a related gate natively, the controlled-Z, which turns the arrow of the combined outcome 11 through half a turn and leaves the others alone; a Hadamard on the target before and after it makes a CNOT.
Two-qubit gates are slower and less accurate than single-qubit ones on every kind of hardware. On Willow, a controlled-Z takes 42 nanoseconds. Google's specification sheet for the error-correction chip gives an average error of 0.33 % per two-qubit gate, and the paper's supplement reports 0.41 % for the same gates. The second figure is the Pauli error, a related measure that for two-qubit gates is five fourths of the average error, and the specification sheet's single-qubit error is about a tenth as large. Two-qubit gates are therefore the main source of error in almost every computation.
A two-qubit gate also needs the two qubits to be coupled. On Willow, the qubits sit on a square grid and each is wired to at most four neighbors; Google's sheet gives an average of 3.47 connections per qubit. Two distant qubits can interact only after their states are moved next to each other by a chain of swap operations, each made of gates that add time and error. Trapped ions and neutral atoms can bring distant qubits together physically, which Chapter 19 compares with wiring. Time is the other budget. Willow's qubits keep their state for about 68 microseconds on average, long enough for about 1,600 two-qubit gates one after another, and a computation must fit inside that window or be protected against it.
If each two-qubit gate fails independently with a chance of 0.33 %, it succeeds 99.67 % of the time. The chance that 100 such gates all succeed is 0.9967 multiplied by itself 100 times, about 72 %. For 1,000 gates it is about 3.7 %, and for 10,000 gates less than 1 in 10¹⁴. Shor's algorithm for RSA-2048 needs billions of operations. Without some way to correct errors as they occur, no physical qubits of 2026 could finish it.
A short list of gates does everything
A small set of gates is enough to build any computation. Single-qubit gates together with the CNOT can produce any operation on any number of qubits, and a finite list, the Hadamard, S, T and CNOT gates, can approximate any operation as closely as needed. The cost of that approximation is modest: a 2016 analysis shows that turning one qubit's arrow by an arbitrary angle, to an accuracy of 1 part in 10¹⁰, takes about 100 T gates, together with cheaper gates between them.
The T gate earns its own count for a reason that belongs to Part V. The error-correcting codes that protect qubits make some gates easy to perform on protected information, including the Hadamard, S and CNOT, but not the T gate. A protected T gate needs a specially prepared ingredient called a magic state, which is made separately, checked, and discarded if it is faulty. A December 2025 preprint by Google's team reported magic states prepared on a superconducting processor at a fidelity of 99.99 %, keeping 8 % of the attempts. Chapter 16 shows that the factories making these states occupy much of an error-corrected machine.
A circuit's total number of gates is a poor guide to its cost on an error-corrected machine. Cheap gates, such as the Hadamard and CNOT, can run on protected qubits at modest cost; each T gate, or the closely related Toffoli gate used in arithmetic, consumes magic states. Resource estimates for useful algorithms, including every estimate for RSA-2048, are therefore stated mainly in T or Toffoli gates.
When an algorithm or a demonstration states its size, ask for three numbers. The count of two-qubit gates drives the error on today's hardware, and the count of T or Toffoli gates drives the cost on a protected machine. The depth, the number of time steps when gates that can run at once are run together, sets how long the qubits must hold their state. A count of qubits without these numbers says little about what a computation demands.
- A gate turns or swaps a qubit's arrows without reading them, and every gate can be undone; reading is the only irreversible step.
- The Hadamard gate is a half-silvered mirror for a qubit: applied twice it returns the qubit to where it started, and a Z gate between the two changes a certain 0 into a certain 1.
- Two-qubit gates such as the controlled-Z on Willow take about 42 nanoseconds and fail about 1 time in 300, so 1,000 of them in a row succeed only about 4 % of the time.
- A short list of gates builds any computation, and on an error-corrected machine the T gate, which needs magic states, dominates the cost.
Two to the power of n.
+ The questionWhat changes when there are two qubits, then fifty?
One arrow for every outcome
Two qubits need four arrows, one for each of the combined outcomes 00, 01, 10 and 11, and fifty qubits need 2⁵⁰ of them, about 1.1 × 10¹⁵. A register of qubits is described not by one pair of arrows per qubit but by one arrow for every string of 0s and 1s the register could be read as. Each added qubit doubles the number of strings, and so doubles the number of arrows. The squared lengths of all the arrows still add to one, and reading the register returns one string, drawn with the odds those lengths set.
The doubling is what makes a quantum computer hard to imitate. An ordinary computer that tracks a quantum register exactly must store every arrow, usually as two numbers of 8 bytes each, for the arrow's two components. Thirty qubits fit in the memory of a large workstation. Every further qubit doubles the bill, and somewhere in the high forties the memory of the largest supercomputers runs out.
At 16 bytes per arrow, 30 qubits need 2³⁰ × 16 bytes, about 17 gigabytes. 40 qubits need about 17.6 terabytes, and 47 qubits about 2.25 petabytes. 50 qubits need about 18 petabytes. A 2025 study on Europe's JUPITER supercomputer, published in 2026, simulated up to 47 qubits exactly; it reached 50, running among other circuits a 50-qubit adder of 1,001 gates, only by squeezing each arrow into 2 bytes, an eightfold saving that cost precision. Three more qubits, eight times the memory. At 300 qubits the count of arrows, about 2 × 10⁹⁰, exceeds the usual estimate of the number of atoms in the observable universe.
The same arithmetic shaped the first argument over a quantum advantage. When Google's 53-qubit experiment of 2019 claimed a task that would take a supercomputer thousands of years, IBM's researchers replied with a proposal to hold the full register on the disks of Summit, then the largest supercomputer in the United States: 64 pebibytes for 53 qubits, within its 250. They estimated the run at about two and a half days, and never carried it out. Chapter 11 follows that exchange and the ones that came after it.
Separate qubits and entangled ones
Some registers can be described far more cheaply. If each qubit was prepared on its own and no gate has acted between them, the arrow for any string is just the product of the arrows of its separate qubits. Two qubits each at fifty-fifty, for example, give four arrows of length 0.5, one for each string. Such a register is described completely by two arrows per qubit, 2n numbers for n qubits rather than 2ⁿ, and an ordinary computer handles it easily.
A two-qubit gate can produce registers that do not split up this way. Start two qubits at 00, apply a Hadamard to the first, and the arrows are 0.707 for 00 and 0.707 for 10. Now apply a CNOT with the first qubit as control: the string 10 becomes 11, and the register holds 0.707 for 00 and 0.707 for 11, with nothing on 01 or 10. Read either qubit and the result is fifty-fifty; read both, and they always agree. No pair of separate qubits can produce this, because a fifty-fifty first qubit and a fifty-fifty second qubit, prepared independently, would give 01 and 10 a quarter of the time each. A register whose arrows cannot be split into separate qubits is entangled, and this two-qubit example is called a Bell pair.
More CNOTs extend the pattern: a register can hold arrows only on the strings of all 0s and all 1s across ten or a hundred qubits, so that every qubit agrees with every other. Such states are useful and fragile. A stray interaction that reads any one of the qubits, even by accident, settles the whole register into one of the two strings and destroys the arrangement of arrows. The more qubits share an entangled state, the more ways there are for the surroundings to read one of them, a problem that Chapter 12 measures.
What entanglement carries
Entanglement is a correlation that no list of separate properties can produce, as the Bell tests of Chapter 3 confirmed. It is not a channel. Reading one qubit of a Bell pair gives a random result, whatever is done to the other, and the agreement shows up only when the two lists of results are brought together and compared, by ordinary means. A 1980 argument by Giancarlo Ghirardi, Alberto Rimini and Tullio Weber showed that no measurement on one part of an entangled system can change the odds seen at the other, so entanglement cannot send a message.
Accounts of entanglement often say that measuring one qubit "instantly affects" its partner. Whatever the right description of what happens, no experiment at one end can detect what was done at the other until the results are compared. Entanglement is a resource for computation and for some protocols, and it never carries information faster than an ordinary signal.
Entanglement matters for speed for a precise reason. A 2003 analysis by Richard Jozsa and Noah Linden showed that a computation whose arrows stay close to separate qubits can be followed by an ordinary computer with modest effort, so entanglement spreading across many qubits is necessary for an exponential speedup. It is not sufficient. Many heavily entangled circuits can still be simulated by clever classical methods that exploit their structure, and Chapter 11 shows such methods answering several claims of quantum advantage within weeks or months.
Many arrows, one reading
The first problem in which interference beat an ordinary method was set out by David Deutsch in 1985, and in the form textbooks now give it is small enough to follow by hand. A function takes one bit and returns one bit, and the question is whether it returns the same value for both inputs or different ones. An ordinary computer must evaluate the function twice. A quantum computer evaluates it once, on a qubit spread over both inputs by a Hadamard; the function's two values appear as the directions of the two arrows, and a second Hadamard makes them interfere, so that the reading gives 0 if the values were the same and 1 if they differed. One evaluation answers a question about both values, and never reveals either value itself.
A register of n qubits carries 2ⁿ arrows, and a gate sequence can, in one pass, give every input string its own output. Put the input register into an equal spread over all its strings with a Hadamard on each qubit, then run the circuit for some function: the register now holds an arrow for every input paired with that input's output. This is sometimes called quantum parallelism, and it is the step that popular accounts stop at.
The next step is a reading, and the reading returns one input and its output, chosen at random. That is no better than running the ordinary function once on a random input. The arrows for all the other pairs existed in the register and are gone. Whatever speed a quantum algorithm has comes from what it does between the parallel step and the reading: gates that make the arrows of the strings it wants add up and the others cancel, so that the one sample drawn is likely to be useful. Chapter 6 shows the simplest such scheme, and Chapters 7 and 8 the most powerful one known.
For any demonstration, ask whether an ordinary computer could have reproduced it, and whether anyone tried. Below about 40 qubits, an exact simulation is routine on a supercomputer, and larger circuits with limited entanglement or high noise can often be imitated approximately. A claim checked against the best classical simulation available is worth far more than one checked against none.
- A register of n qubits is described by 2ⁿ arrows, one for each string it could be read as, so each added qubit doubles both the arrows and the memory needed to track them exactly.
- In 2025 the JUPITER supercomputer's largest exact simulation held 47 qubits, about 2.25 petabytes at 16 bytes per arrow; 50 qubits needed each arrow squeezed into 2 bytes.
- Two-qubit gates create entanglement, as in the Bell pair whose two qubits always agree, and entanglement across many qubits is necessary, though not sufficient, for an exponential speedup.
- A register can pair every input with its output in one pass, but a reading returns one pair at random, so the speed of an algorithm lies in the interference that comes before the reading.
Finding one item in eight.
+ The questionCan interference find one marked item among eight, and how much faster does it get as the list grows?
A list with one marked item
In 1996 Lov Grover, a researcher at Bell Labs like Shor, published a way for a quantum computer to find one marked item in an unsorted list of N items in about the square root of N steps. An ordinary search of such a list has no shortcut: it checks items one at a time and, on average, finds the marked one after checking half of them. For a list of a million items that is half a million checks, against fewer than eight hundred rounds of Grover's method. The paper was presented in May 1996 at the annual symposium on the theory of computing of the Association for Computing Machinery.
The list in Grover's problem is not a table stored in memory. It is a test: a circuit, called an oracle, that takes an item's number and recognizes whether it is the marked one, much as a lock recognizes its key. The oracle does not know where the marked item is in any useful sense; it only checks. What the quantum computer can do that an ordinary one cannot is run the check once on a register spread over every item at the same time, and the oracle's only effect is to turn the arrow of the marked item through half a turn.
That mark is invisible to a reading, because a turned arrow has the same length as before. As in the Hadamard example of Chapter 4, the mark matters only when arrows are made to interfere, and Grover's contribution was a second step that converts the mark into a larger arrow.
Mark, then reflect
The second step is called inversion about the mean. Take the average of all the arrows, then replace each arrow by twice that average minus itself. An arrow sitting just below the average ends up just above it, and an arrow far below the average, as the marked one is after its half turn, ends up far above it. One round of Grover's method is a mark followed by a reflection, and each round moves a little more of the total from the unmarked items to the marked one.
The reflection is built from the same three moves as the Hadamard example of Chapter 4. A Hadamard on every qubit turns the equal spread back into the string of all 0s; a gate turns the arrow of that one string through half a turn; and a second layer of Hadamards spreads the register out again. The middle step must check every qubit at once, so its gate count grows with the size of the register, and the oracle's own circuit comes on top of it. Neither is free, and the next section shows why their cost matters. In the language of Chapter 3, the oracle is the step that marks one path, and the reflection is the second mirror that makes the paths interfere.
With eight items and three qubits, an equal spread gives each item an arrow of about 0.354, because 0.354² is one eighth, 12.5 %. The oracle turns the marked item's arrow to −0.354. The average of the eight arrows is now (7 × 0.354 − 0.354) ÷ 8, about 0.265. Reflecting, the marked arrow becomes 2 × 0.265 + 0.354 = 0.884, a chance of 78.1 %, and each other arrow becomes 2 × 0.265 − 0.354 = 0.177, a chance of 3.1 %. A second round marks −0.884, the average falls to about 0.044, and the marked arrow becomes 0.088 + 0.884 = 0.972: a chance of 94.5 %, with about 0.8 % left on each wrong item. A third round overshoots and the chance falls to 33 %.
The overshoot is part of the method, not a flaw in the example. Each round turns the register through a fixed angle, from the spread of all items toward the marked one, and a reading should be made when the register points as close to the marked item as it gets. For a list of N items with one marked item, the best number of rounds is close to π/4 times the square root of N, and going further lowers the chance again.
The square root, and no further
The table gives the best number of rounds for lists of several sizes, the chance of success after them, and the average number of checks an ordinary search needs. The count of rounds is the largest whole number that does not overshoot, which for some sizes is one fewer than rounding π/4 × √N would suggest.
| Items in the list | Ordinary checks, on average | Grover rounds | Chance of success | Ratio |
|---|---|---|---|---|
| 8 | 4 | 2 | 94.5 % | 2 |
| 100 | 50 | 7 | 99.5 % | 7 |
| 10,000 | 5,000 | 78 | 99.9999 % | 64 |
| 1,000,000 | 500,000 | 785 | above 99.9999 % | 637 |
| 10¹² | 5 × 10¹¹ | 785,398 | above 99.9999 % | 636,620 |
The advantage grows with the list, but only as a square root: a list a hundred times longer needs ten times as many rounds. Before Grover's paper appeared, Charles Bennett, Ethan Bernstein, Gilles Brassard and Umesh Vazirani had shown that no quantum method can do better on a problem with no structure, and a 1999 analysis by Christof Zalka showed that Grover's method is exactly the best possible. A quantum computer cannot search an unstructured space exponentially faster than an ordinary one.
If several items are marked, fewer rounds are needed: with t marked items among N, the count falls to about π/4 times the square root of N divided by t, and a 1996 paper by Michel Boyer, Gilles Brassard, Peter Høyer and Alain Tapp showed how to proceed when t is not known in advance. The comparison in the table is also with the plainest ordinary method, checking items one by one. For many practical problems, such as scheduling or circuit verification, ordinary software exploits structure and rarely checks most candidates, so the real baseline is far stronger than half the list. Problems that hide a period, the subject of the next two chapters, are a different matter.
Grover's method is often described as searching a database. A database stored in ordinary memory would have to be loaded into the quantum computer for every round, which costs at least as much as reading it. The method pays only when the oracle is a computation, such as a test of whether a candidate solves a puzzle, built from gates. Every round runs that whole computation, and its gate count multiplies the cost of every round in the table.
A square root is not enough, yet
The table counts rounds, not seconds, and the seconds decide whether the method is worth running. An error-corrected quantum computer performs each protected operation hundreds of thousands of times more slowly than an ordinary processor performs an instruction, because each operation is built from many physical gates and checks, as Part V explains. A 2021 analysis by Ryan Babbush and colleagues at Google worked out how long a square-root advantage takes to overcome that slowness on the error-corrected machines then foreseen. Their assumptions were generous to the quantum side: a physical error-correction cycle of one microsecond, a well-chosen code, and a factory of about 130,000 physical qubits preparing the ingredients for each Toffoli gate. Even so, one protected Toffoli gate took about 170 microseconds, while an ordinary processor performs a comparable logical step in a fraction of a nanosecond. A search round that needs a hundred such gates in sequence lasts about 17 milliseconds.
Suppose each quantum round takes time tQ and each ordinary check time tC. The quantum search wins once the square root of N rounds take less time than N checks, which happens after a running time of tQ² ÷ tC. Babbush and colleagues took, as a best case, 17 milliseconds per round and 33 nanoseconds per check. The break-even time is 0.017² ÷ 0.000000033, about 8,760 seconds, or 2.4 hours. Any shorter search is faster on one ordinary processor core. Against 3,000 cores working in parallel, the break-even stretches to about a year.
For a realistic optimization problem the same paper found break-even times of 320 days against one core and about 880 millennia against a million cores. Speedups that grow faster, such as a fourth-power advantage, brought the figure down to minutes or hours. The authors concluded that early error-corrected machines should look beyond square-root speedups, or that error correction must become much cheaper first. That verdict sets the scope of the rest of this guide: the problems that justify the price of a reliable answer are those with a much larger advantage, and Chapters 7 and 8 show the best-known one.
When a proposal rests on Grover's method or another square-root speedup, ask for the time of one quantum round on the intended machine, error correction included, and for the time of one classical step on competing hardware, counting parallel processors. Square the first, divide by the second, and compare the result with the running time the problem allows. If the break-even lies beyond that time, the speedup will not be seen.
- Grover's method searches N unsorted items in about π/4 × √N rounds, each a half-turn mark from an oracle followed by an inversion of all arrows about their mean.
- With eight items, two rounds raise the marked item's chance from 12.5 % to 78.1 % and then 94.5 %, and a third round overshoots to 33 %.
- No quantum method searches an unstructured list faster than the order of √N, so the advantage is a square root, never exponential.
- Because error-corrected operations are slow, a square-root speedup needs hours to hundreds of thousands of years of running time before it beats ordinary hardware.
Factoring as a rhythm.
+ The questionWhat does finding the period of a repeating sequence have to do with factoring?
A sequence that repeats
Start with 1, multiply by 7, and keep only the remainder after dividing by 15; then multiply that remainder by 7 and keep the remainder again. The sequence runs 1, 7, 4, 13, 1, 7, 4, 13, and then repeats forever. Arithmetic of this kind, in which only remainders are kept, is called modular arithmetic, and it works like a clock: on a clock with fifteen hours, 7 × 7 = 49 lands on hour 4, because 49 is three full turns of fifteen plus four.
The powers of any number, taken this way, must eventually repeat, because there are only so many remainders available, and once one repeats, the whole cycle does. The length of the cycle is called the period of the base, often written r. For the base 7 and the number 15, the period is 4. The surprising fact on which Shor's algorithm rests is that knowing the period of almost any base is enough to factor the number.
From a period to the factors
The reasoning takes three steps of school arithmetic. If the period r is even, then the base raised to the power r/2, multiplied by itself, gives a remainder of 1. So the number one less than that power and the number one more than it multiply to a product that leaves no remainder when divided by N: their product is a multiple of N. Unless one of them is itself a multiple of N, each must share a factor with N, and a shared factor is found quickly by Euclid's algorithm for the greatest common divisor, which needs at most a few thousand divisions even for numbers of hundreds of digits, a moment's work for a laptop.
For N = 15 and base 7, the period is 4, so r/2 = 2 and 7² = 49. The neighbors of 49 are 48 and 50. The greatest common divisor of 48 and 15 is 3, and that of 50 and 15 is 5: the factors, since 3 × 5 = 15. For N = 21 and base 2, the sequence runs 1, 2, 4, 8, 16, 11 and then returns to 1, a period of 6. Half the period gives 2³ = 8, whose neighbors 7 and 9 share the factors 7 and 3 with 21. A base can fail: for 15 and base 14, the period is 2, and 14¹ = 14 has neighbors 13 and 15, which give only the useless factors 1 and 15.
The arithmetic can be checked directly: 48 × 50 = 2,400, which is 160 × 15, so the product of the two neighbors is indeed a multiple of 15, while neither neighbor is a multiple of 15 on its own. Each must therefore hold part of 15, one the 3 and the other the 5. The same holds for 7 × 9 = 63, which is 3 × 21.
The failure in the example has a simple cause. The base 14 leaves a remainder of 14 at half its period, which is one less than 15, so the "one more" neighbor is 15 itself and carries no information. A base fails when its period is odd or when this happens, and the remedy is to try another base.
How often a base works
Shor proved that for a number with two distinct odd prime factors, as every RSA number has, at least half of all suitable bases work. The table shows the count for the two small examples. A base that shares a factor with the number is even better, since Euclid's algorithm finds that factor directly, but for a 617-digit number such a lucky choice essentially never happens.
| Number | Bases with no common factor | Bases that give the factors | Share that works |
|---|---|---|---|
| 15 | 8 | 6 (2, 4, 7, 8, 11, 13) | 75 % |
| 21 | 12 | 6 (2, 8, 10, 11, 13, 19) | 50 % |
The number 21 meets the bound exactly, which shows that the bound cannot be improved in general. In practice, a run that picks a base at random succeeds about half the time or better, and two or three tries make failure unlikely. The repetition joins the shots of Chapter 2 as part of the bill. Large designs build repeated runs in from the start: one 2025 design for RSA-2048 combines about nine runs for every factorization in its classical post-processing.
Only one step of the whole procedure needs a quantum computer. An ordinary computer picks the base, checks it for a common factor, and, once a period comes back, tests whether it is even, computes the two neighbors, runs Euclid's algorithm and multiplies the result to confirm it. The quantum computer is asked a single question, the period of one base, and its answer can be checked in a moment. Every quantum algorithm in this guide has the same shape: a classical program that calls a quantum computer for the one step it cannot do itself.
Why the period is hard to find
None of this helps an ordinary computer. For a 617-digit number, the period of a typical base can itself run to hundreds of digits, so stepping through the sequence until it repeats would take far longer than the age of the universe. Computing one term far out in the sequence is easy: squaring repeatedly gives the 1,024th power in ten steps. What no known ordinary method can do is find, from such scattered terms, where the sequence starts over, without work comparable to factoring the number in the first place.
A quantum computer can compute the terms for every exponent at once in a register spread over all exponents, using the reversible arithmetic of Chapter 4, and leave each exponent's arrow paired with its remainder. That step, called modular exponentiation, holds most of the gates of Shor's algorithm and nearly all its Toffoli gates, and it is the part every resource estimate for RSA-2048 works hardest to shrink. The register then holds a pattern that repeats with the period. Reading it directly would return one exponent and its remainder, at random, which reveals nothing. Chapter 8 shows the step that makes the repeating pattern visible.
The same machinery solves the problem Shor solved first. In the discrete logarithm problem, a base and a remainder are given, and the task is to find the exponent that produces that remainder; the elliptic-curve version of the problem secures much of the key exchange on today's internet. Finding the exponent also comes down to a hidden period, and Shor's method finds it in the same way. Chapter 22 shows that a 2026 estimate for breaking elliptic-curve keys needs far fewer Toffoli gates than RSA-2048.
Where the idea came from
The idea of finding a hidden period with a quantum computer did not begin with Shor. David Deutsch's 1985 problem, met in Chapter 5, and a 1993 paper by Ethan Bernstein and Umesh Vazirani had already shown quantum computers outperforming ordinary ones on problems built for the purpose. In 1994, Daniel Simon described the first problem in which a quantum computer finds a hidden pattern exponentially faster than any ordinary method given the same black-box access, a result that the program committee of one major conference rejected before it appeared at another. Shor, who sat on the committee that rejected it, recognized that Simon's method was finding a kind of period, and that periods are the key to the discrete logarithm problem. In his 1997 journal paper he wrote that "Simon's algorithm inspired the work presented in this paper." The discrete logarithm came first, then factoring, in the week described at the opening of this guide.
Factoring is not a search through possible factors, and Shor's algorithm does not try divisors in parallel. It converts factoring into a question about a repeating pattern and answers that question with interference. Problems with no such pattern get at most the square-root speedup of Chapter 6, which is why the list of problems with large quantum speedups is short.
When a problem is proposed for a quantum computer, ask what structure the algorithm exploits: a period, a symmetry, or the physics of a quantum system. If the answer is none, expect at most a square-root speedup and apply the break-even test of Chapter 6. If the answer is a period or a symmetry, ask which known algorithm uses it and what its arithmetic costs, because that arithmetic dominates the gate count.
- The remainders of the powers of a base repeat, and the length of the cycle is the base's period: 4 for the base 7 and the number 15.
- If the period is even, the neighbors of the base raised to half the period share factors with the number, so 48 and 50 reveal 3 and 5 for 15, and 7 and 9 reveal 7 and 3 for 21.
- At least half of all suitable bases work for any number with two distinct odd prime factors, and 21 meets that bound exactly.
- Ordinary computers know no fast way to find the period of a large number; a quantum computer can compute every term at once, and the next chapter shows how interference reads the period.
Reading a period you never see.
+ The questionHow does a quantum computer read a period it never sees?
A stroboscope for arrows
A stroboscope flashing at exactly the rate a fan turns makes the spinning blade appear to stand still, and a flash at any rate that does not match leaves it a blur. The final step of Shor's algorithm works on the same principle. After the arithmetic of Chapter 7, the register holds arrows only on the exponents whose remainders match the one remainder that, in effect, has been selected, and those exponents are spaced exactly one period apart. The step that follows tests that pattern against every possible rate at once, and only rates that fit the period survive.
The step is called the quantum Fourier transform, after the French mathematician whose method splits a signal into its frequencies. For each possible output, every occupied slot of the register sends an arrow turned by an amount that grows with the slot's position and the output's value. If the occupied slots repeat with a period that matches the output, their arrows all point the same way and add up; if not, they point in many directions and cancel. Reading the register afterward returns, with high probability, an output that reveals the period.
Take a register of four qubits, which has sixteen slots numbered 0 to 15, and suppose the arithmetic has left arrows of length 0.5 on slots 1, 5, 9 and 13, one period of 4 apart. For each output y, slot x sends an arrow of length 0.5 × 0.25 = 0.125, turned by x × y sixteenths of a full turn. For output 4, the four arrows turn by 4, 20, 36 and 52 sixteenths, which is a quarter turn plus whole turns each time: they all point the same way and add to 0.5, a chance of 25 %. For output 1, they turn by 1, 5, 9 and 13 sixteenths, each a quarter turn beyond the last, so they close into a square and add to zero. Outputs 0, 4, 8 and 12 each get 25 %, and every other output gets nothing.
Every surviving output is a multiple of 16 divided by 4, so the reading reveals the period through the spacing. An output of 12 means 12 sixteenths, or three quarters, and the denominator of that fraction is the period, 4. An output of 4 gives one quarter, with the same result. An output of 8 gives one half, which reveals only a divisor of the period, and an output of 0 reveals nothing, so the run is repeated or its results combined, at the small cost counted in Chapter 7.
When the period does not fit
Real periods rarely divide the number of slots exactly. For 21 with base 2, whose period is 6, a textbook register of nine qubits has 512 slots, and 512 divided by 6 is 85.33. The arrows then add up most strongly near the multiples of 85.33 rather than exactly on them. A 2026 calculation for this guide gives the six nearest whole-number outputs about 79 % of the total, with the rest spread thinly around them.
An output of 85, for example, gives the fraction 85/512, about 0.166, and the closest fraction with a small denominator is 1/6, so the period is 6. The method for finding that closest fraction, called continued fractions, is ordinary arithmetic and runs on an ordinary computer. Shor's paper chose the register large enough, with about twice as many qubits as the number being factored has bits, that the closest small fraction is reliably the right one.
The Fourier step is cheap next to the arithmetic. For RSA-2048, a textbook input register of 4,096 qubits needs 4,096 Hadamard gates and about 8.4 million small controlled turns, and in 1994 Don Coppersmith of IBM showed that the tiniest turns can be dropped with almost no effect. Later designs reuse a single qubit for the whole input register, reading and resetting it after each step: a 2003 circuit by Stéphane Beauregard needs only twice the number of bits plus three qubits in all, about 4,100 for RSA-2048 before any error correction. Nearly all the cost lies in the modular exponentiation.
The whole algorithm
Shor's algorithm, assembled, has five steps. An ordinary computer picks a base and checks it for a common factor. The quantum computer spreads an input register over every exponent with Hadamard gates, computes the base raised to each exponent with reversible arithmetic, applies the Fourier step and reads the result. The ordinary computer turns the reading into a candidate period with continued fractions, checks it, computes the two neighbors and their common factors with the number, and confirms the factors by multiplying them.
The answer is checked in a fraction of a second, which makes factoring the cleanest possible test of a quantum computer: a claimed result is either right or wrong. That makes the record of actual demonstrations sobering.
The checks also make the algorithm forgiving in one respect. A wrong period is caught at once and the run repeated, so the quantum computer need not succeed every time, only often enough. They do not make it forgiving of errors inside a run. A run for RSA-2048 is billions of operations long, and a single uncorrected error anywhere in the arithmetic scrambles the pattern the Fourier step reads. A run either finishes essentially without error or produces noise, which is why Chapter 13 starts the bill with the chance that a whole run succeeds.
What the demonstrations show
The first run of Shor's algorithm, published in 2001 by a team at IBM's Almaden Research Center, factored 15 using seven atomic nuclei in a molecule as qubits, controlled with radio pulses; it found the periods 2 and 4 for the bases 11 and 7. The computation for the base 7 took about 720 milliseconds of pulses, and the authors used a model of decoherence to account for how far the results fell short of the ideal. Molecules in a liquid cannot be scaled to many qubits, so the experiment showed that the steps could be carried out, not that the method could grow. Photonic experiments in 2007 and 2012 repeated the feat for 15 and for 21, but with circuits tailored to the known answer, which their authors described as compiled. A 2013 paper by John Smolin, Graeme Smith and Alexander Vargo of IBM showed how far tailoring can go: with enough knowledge of the factors built into the circuit, they "factored" a 232-digit number by tossing a coin. They proposed that an experiment be judged by the size of the period it actually found.
In 2016 a team in Innsbruck ran a version on five trapped calcium ions that, its authors argued, did not presume the answer; it found the period of 15 for five bases, each correct in about half the runs. A 2019 attempt to factor 35 on IBM's cloud processors succeeded only about 14 % of the time and, in its authors' words, eventually failed, because errors from its many two-qubit gates accumulated. In 2025, Craig Gidney of Google Quantum AI noted in a blog post that factoring 15 by the standard method takes 21 entangling gates, while 21 takes about 2,405, more than a hundred times as many. As of October 2026, no number larger than 15 has been factored by Shor's algorithm with the multiplications actually carried out on the machine.
Claims to have factored large numbers with quantum hardware appear regularly. A 2022 preprint claimed a 48-bit number factored with ten superconducting qubits, by a method that replaced Shor's algorithm with a classical lattice technique assisted by a small optimization routine; it projected 372 qubits for RSA-2048. A 2023 analysis by two Google researchers found that the classical part fails beyond about 70 to 80 bits whatever the quantum part does. Ask whether Shor's algorithm itself ran, and whether its modular arithmetic was performed in full.
Ask which period the quantum computer found, and whether the circuit could have produced it without knowledge of the answer. Ask how many runs it took and how often each gave the right period. Ask how many two-qubit gates the circuit used, and compare it with the count the honest algorithm needs: 21 for 15, about 2,405 for 21.
- The quantum Fourier transform sends arrows from every occupied slot turned by amounts that depend on position and output, so only outputs matching the period receive arrows that add up.
- With sixteen slots and a period of 4, the outputs 0, 4, 8 and 12 each have a 25 % chance, and an output of 12 reveals the period as the denominator of 12/16 = 3/4.
- When the period does not fit the register, continued fractions on an ordinary computer recover it, and the Fourier step costs little next to the modular arithmetic.
- No number above 15 had been factored by Shor's algorithm with its arithmetic actually performed as of October 2026, because 21 already needs about a hundred times as many entangling gates.
+ Part III · Which problems
Where the advantage is real, and how claims have fared.
In October 2019, a Google processor finished in 200 seconds a task that its authors estimated would take the largest supercomputer 10,000 years; days before the paper appeared, IBM's researchers put the classical figure at two and a half days. Part III answers the second half of the central question: for which problems is a reliable answer worth its price? Chapter 9 sets out what structure a problem needs, Chapter 10 follows the problem quantum computers were first proposed for, the simulation of molecules and materials, and Chapter 11 weighs the claims of advantage made since 2019 against the classical replies they drew.
What a speedup needs.
+ The questionWhy do period finding and simulation speed up while sorting and spreadsheets do not?
A speedup that disappeared
In 2018 a quantum algorithm presented as exponentially faster than any ordinary method, for recommending products to customers from a table of their past choices, lost its advantage to an ordinary algorithm. The quantum method had been published in 2016 by Iordanis Kerenidis and Anupam Prakash. The ordinary one was found by Ewin Tang, who, according to Quanta Magazine, was 18, had just graduated from the University of Texas at Austin, and had begun the work as an undergraduate thesis supervised by Scott Aaronson. Tang's method, given the same kind of access to the data as the quantum one, was only polynomially slower, so the exponential gap was gone.
The episode is now called dequantization, and it has been repeated for several other proposed quantum speedups in data analysis. Its lesson is that every claim of quantum advantage is a claim about the best known ordinary method, and that the best known ordinary method can improve. A speedup over a classical algorithm nobody has worked hard on is weak evidence. A speedup on a problem that has resisted classical attack for decades, as factoring has, with no polynomial method found, is far stronger evidence.
Claims often compare a quantum method with a generic classical solver, an old algorithm or one processor core. The baseline that matters is the best classical method for that problem, on the best hardware, given the same access to the data. Several reported speedups have disappeared when that baseline was found, and Chapter 11 shows the pattern repeating in public.
Three conditions
A problem repays a quantum computer only when three conditions hold together. The first is a large gap in growth rate between the best quantum method and the best ordinary one, large enough to survive the slowness of error-corrected operations that Chapter 6 measured. In practice that means an exponential gap or a high-power one, and such gaps have come only from structure: a hidden period or symmetry, as in Shor's algorithm, or the quantum physics of the problem itself, as in the simulation of molecules. The 2021 analysis of Chapter 6 makes the threshold concrete: a square-root gain took hours to millennia to break even, while a fourth-power gain broke even within minutes to hours.
The second condition is that the input be small. A quantum computer must have its input built into its circuit or loaded gate by gate, and its input and output channels are slow. A 2023 analysis by Torsten Hoefler, Thomas Häner and Matthias Troyer, with Microsoft staff among its authors, estimated that a future machine with 10,000 protected qubits would move data at about 1 gigabit per second, against about 10,000 gigabits per second for a modern graphics processor. They summarized the consequence as big compute on small data.
A terabyte is 8 × 10¹² bits. At 1 gigabit per second, loading it into the quantum machine takes 8 × 10¹² ÷ 10⁹ = 8,000 seconds, about 2.2 hours, before any computation starts. A graphics processor at 10,000 gigabits per second reads the same terabyte in 0.8 seconds. A quantum algorithm that touches every entry of a large dataset has lost its advantage before it begins, whatever its growth rate on paper.
The third condition is that the answer can be read out in a few samples. A reading returns one string, so an algorithm whose result is a long list of numbers must be run once for every number wanted, or more. An answer that is short and checkable, such as a pair of factors, an energy to a stated precision, or a yes or no, fits the machine; an answer that is a large table does not.
The fine print of linear algebra
A celebrated 2009 algorithm by Aram Harrow, Avinatan Hassidim and Seth Lloyd solves large systems of linear equations in a time that grows only with the logarithm of their size, an exponential gain on paper. In a 2015 commentary titled "Read the fine print," Aaronson listed what the gain assumes. The right-hand side of the equations must be loaded quickly. The matrix must be sparse and well behaved. And the output is not the solution but a quantum state holding it, from which reading any single entry needs many repetitions, "which would once again kill the exponential speedup." The algorithm remains useful as a component when only a few summary numbers of the solution are wanted, but each of the conditions is a place where a claimed application can fail. A 2025 perspective from Google's quantum team made a related point about applications in general: the least developed step is not the algorithm but finding concrete problem instances that are hard for ordinary computers and tied to a real use.
Machine learning on classical data is where these conditions bite hardest, because its datasets are large and its outputs are many numbers. Tang's recommendation result was one of several in which an exponential speedup in this area turned out to depend on the data-access assumption rather than on anything only a quantum computer can do.
Where no speedup exists
For some tasks a speedup is ruled out outright. Sorting a list by comparing its items needs, on a quantum computer as on an ordinary one, a number of comparisons that grows like the list length times its logarithm, as a 2001 analysis by Peter Høyer, Jan Neerbek and Yaoyun Shi proved; at most a constant factor can be gained. For the large family of hard puzzles called NP-complete, which includes scheduling and many routing problems, no exponential quantum speedup is known, and the result of Bennett and colleagues met in Chapter 6 shows that brute-force search can gain only a square root.
Optimization, often named as an early application, sits between proof and hope. The quantum approximate optimization algorithm, proposed in 2014, is a heuristic, and evidence for its advantage is mixed. A 2024 study by JPMorgan Chase and Quantinuum staff simulated it without noise on up to 40 qubits, combined with a square-root search, on one hard problem. Its cost grew as 1.21 to the power of the problem size, against 1.34 for the best classical heuristic, but the square-root part brings the overheads of Chapter 6 with it. A study published later that year tested quantum-enhanced heuristics on another standard family of problems: a classical annealing program solved instances of up to 128 variables in seconds on a smartphone, while the quantum method would have needed weeks, and the authors concluded that current methods may show no quantum advantage at all. A review in Nature Reviews Physics the same year, written by more than sixty authors from industry and universities, set out benchmarks and open questions rather than demonstrated advantages.
| Kind of problem | Best known quantum gain | Status as of October 2026 |
|---|---|---|
| Factoring and discrete logarithms | exponential | needs a large error-corrected machine (Chapter 22) |
| Simulating quantum physics and chemistry | exponential for some problems | problem by problem; classical methods keep improving (Chapter 10) |
| Unstructured search | square root | eaten by overheads on early machines (Chapter 6) |
| Optimization heuristics | unproven | no demonstrated advantage |
| Linear algebra and machine learning on large data | exponential only under strong assumptions | several cases dequantized |
| Sorting, databases, spreadsheets, everyday computing | none | no speedup possible or known |
The two rows with exponential gains share the profile that the three conditions describe. Factoring RSA-2048 takes in 617 digits and returns two numbers of about 309 digits each, which a multiplication checks. Simulating a molecule takes in a description of a few dozen orbitals and returns an energy, a single number. In between, both run long computations over registers far too large for any ordinary memory. The phrase big compute on small data describes both of them exactly.
Ask whether the problem has a known large gap in growth rate, and from what structure. Ask how big the input is and how it reaches the quantum computer. Ask how many numbers the answer contains and how many runs reading them takes. A proposal that cannot answer all three is a research question, not an application, and should be planned and funded as one.
- A claimed quantum speedup is a claim about the best known ordinary method, and Tang's 2018 dequantization of a recommendation algorithm showed that such a method can appear.
- A problem repays a quantum computer only with a large gap in growth rate from structure, a small input, and an answer that a few samples can read.
- Loading a terabyte at the 1 gigabit per second foreseen for a large machine takes over two hours, which rules out speedups on large datasets.
- Sorting gains nothing, brute-force search gains a square root, optimization heuristics have no demonstrated advantage, and the large known speedups are factoring and the simulation of quantum systems.
Molecules and materials.
+ The questionMolecules are quantum systems. How big a quantum computer does chemistry that matters need?
Feynman's proposal
In May 1981, at a conference on the physics of computation at MIT's Endicott House, Richard Feynman spoke about what computers could and could not imitate. He had not prepared a formal paper; his talk was transcribed and published in 1982 as "Simulating physics with computers." Its closing remarks contain the phrase most often quoted from it, "nature isn't classical, dammit," followed by the conclusion that a simulation of nature had better be quantum mechanical itself. His argument was the second wall of Chapter 1. Describing many interacting quantum particles takes a number of values that doubles with each particle, so an ordinary computer falls behind exponentially, while a machine built from quantum parts would carry the description in its own state.
Chemistry is the clearest case. The behavior of a molecule, how it bonds, which reactions it speeds up, what color it absorbs, is set by its electrons, and electrons obey quantum mechanics. Chemists describe the electrons as occupying orbitals, and each orbital can hold up to two electrons of opposite spin, so a simulation needs two qubits per orbital, one for each spin. A molecule described with 54 orbitals needs 108 qubits before any error correction, and its full description on an ordinary computer would need about 2¹⁰⁸ arrows.
Where approximations fail
Ordinary computers handle most chemistry well, because most molecules can be described by approximations that treat each electron as moving in the average field of the others. The approximations fail where electrons are strongly correlated, each one's behavior tied closely to the others', which is common in compounds of transition metals such as iron, molybdenum and copper. Many of the most interesting catalysts in industry and biology are of this kind.
The standard example is the FeMo cofactor, or FeMoco, the cluster of iron, molybdenum, sulfur and carbon atoms at the heart of nitrogenase, the enzyme that soil bacteria use to turn nitrogen from the air into ammonia at room temperature. Industry makes ammonia at high temperature and pressure, and the International Energy Agency puts ammonia production at about 2 % of the world's final energy use, 8.6 exajoules a year. A better understanding of how the enzyme does it cheaply has been a long-standing goal, and since 2017 FeMoco has been the benchmark molecule for quantum chemistry estimates.
The FeMoco bill, and how it fell
The first detailed estimate, published in 2017 by Markus Reiher and colleagues at ETH Zurich and Microsoft, modeled FeMoco with 54 electrons in 54 orbitals. For an accuracy chemists consider useful, its serial design, the one with the fewest qubits, needed about 10¹⁵ T gates on about 111 protected qubits, which at an assumed 10 nanoseconds per T gate came to roughly 130 days. With physical qubits erring 1 time in 1,000, the authors estimated about 200 million physical qubits in all. Later work changed both the model and the method. A 2019 analysis by Garnet Chan's group argued for a more representative model of 113 electrons in 76 orbitals, 152 qubits. A 2021 estimate by a Google-led team brought the machine for the 2017 model down to about four million physical qubits running for under four days. A 2025 method then cut the gate count for the larger model from 3.2 × 10¹⁰ Toffoli gates to about 10⁹, a factor of 32.
Reiher's serial estimate needs about 1.1 × 10¹⁵ T gates. At 10 nanoseconds each that is 1.1 × 10⁷ seconds, about 127 days. At the 170 microseconds per protected gate assumed in Chapter 6, it becomes 1.9 × 10¹¹ seconds, about 6,000 years. The 2025 count for the larger model, about 10⁹ Toffoli gates, takes 1.7 × 10⁵ seconds at 170 microseconds, about two days. Better algorithms cut the bill by more than faster hardware was ever expected to.
Classical chemistry moved too
The ordinary side did not stand still. In January 2026, a team led by Garnet Chan at Caltech, with the Flatiron Institute, reported that classical methods had reached chemical accuracy for the ground-state energy of the 152-qubit FeMoco model itself. They used about 2.8 million processor-core hours of a method called the density matrix renormalization group, together with high-order coupled-cluster calculations, and converted the cost into seconds to hours of idealized time on the Frontier supercomputer. The quantum figure they set against it was the 2025 Google-led estimate for the same model, about 4.5 million physical qubits running for 8.6 hours, which its own authors expected newer error-correction methods to shorten. Their summary was that the ground state "can be characterized as one of ranking many competing, but largely simple, states."
The result does not settle chemistry. It answers one question, the lowest energy of one model of one cluster, and the questions that matter for the enzyme, how the reaction proceeds step by step and how the cluster behaves in larger models, remain open. But it fits a broader assessment. A 2023 study in Nature Communications, by authors from universities and from Google and Amazon, found no evidence yet of an exponential quantum advantage for generic ground-state chemistry and concluded that "it may be prudent to assume exponential speedups are not generically available for this problem." The advantage, where it exists, will be problem by problem, and each benchmark molecule is a moving target.
A 2022 study of cytochrome P450, an enzyme central to how the body breaks down drugs, shows what problem by problem means in numbers. A team from Google, the drug company Boehringer Ingelheim and the software firm QSimulate placed the limit of reliable classical methods at an active space of about 40 to 43 orbitals. For a 58-orbital model just beyond it, they estimated about 4.6 million physical qubits running for 73 hours at a physical error of 1 in 1,000, or about 500,000 qubits for 25 hours if errors fell to 1 in 100,000. Both figures assume the error-correction machinery that Part V describes.
What has run on hardware so far
Chemistry run on quantum hardware has so far been small or partial. In 2020, Google ran a calculation on 12 qubits deliberately chosen to be easy to check classically. The near-term method called the variational quantum eigensolver, which estimates an energy from many shots, runs into the precision cost of Chapter 2. A 2022 analysis by Zapata Computing and BP staff estimated, under generous assumptions, about two days of measurement for a single energy of methane and about 71 days for ethanol, with dozens to hundreds of such energies needed per calculation.
The largest calculations of 2025 and 2026 split the work. A May 2026 study by Cleveland Clinic, RIKEN and IBM treated two protein-ligand complexes of over 11,000 and 12,635 atoms. The quantum processors handled only small fragments, of up to 94 qubits on two IBM Heron processors, while supercomputers handled the rest; the quantum part took 9,200 circuits, 1.3 billion shots and more than 100 hours. The authors wrote that they did "not regard the results reported here as basis of a quantum advantage claim." The work shows how a quantum computer could sit inside a larger simulation, and how many shots even a partial answer costs.
Announcements of large simulations often give the size of the whole system, such as 12,635 atoms. Ask how many qubits the quantum processor used, which part of the problem they handled, what classical method checked the result, and whether that method could have done the quantum part as well. Of the 2026 protein study, IBM itself wrote that the method did not yet outperform the best classical approaches.
For a chemistry proposal or result, ask how many orbitals and electrons the quantum part treats, because that sets the qubit count; which classical method gives the reference answer, and at what cost; and what accuracy the application needs. A chemistry problem worth a quantum computer is one where the best classical method fails at the needed accuracy within the time allowed, and that has to be shown for the specific molecule.
- Feynman proposed in 1981 that quantum systems be simulated by quantum machines, because their description doubles with each particle; a molecule needs two qubits per orbital.
- FeMoco, the nitrogen-fixing cluster of nitrogenase, has been the benchmark since 2017, and its estimated quantum cost fell from about 200 million physical qubits to about four million for the same model, while the gate count for a larger model fell by a further factor of 32 by 2025.
- In 2026 classical methods reached chemical accuracy on the 152-qubit FeMoco model, and a 2023 study advised against assuming exponential speedups for generic ground-state chemistry.
- Hardware results so far are small or partial, such as fragments of up to 94 qubits inside a 12,635-atom protein simulation, and their authors make no claim of advantage.
Beating a supercomputer, and the reply.
+ The questionWhen a quantum computer is said to have beaten a supercomputer, what was the contest, and did the result hold?
A sample nobody can check
In September 2019 a paper by Google's quantum team appeared briefly on a NASA website and was taken down, and on 20 September the Financial Times reported its claim. The paper, published in Nature on 23 October, described Sycamore, a processor with 53 working qubits, running random circuits of 20 cycles and collecting a million output strings in about 200 seconds. The authors estimated that the largest supercomputer would need about 10,000 years to produce the same samples. They called the result quantum supremacy; the field now mostly says quantum advantage.
The task, called random circuit sampling, was chosen because it is hard to imitate, not because anyone needs its output. A random sequence of gates spreads the register over all its strings with a pattern of odds no simple rule describes, and the machine is asked to produce strings with those odds. Whether it did so cannot be checked directly for 53 qubits. The authors estimated the quality of their samples with a statistic called cross-entropy benchmarking, computed exactly on smaller and simplified versions of the circuits and extrapolated to the full one, and found a fidelity of about 0.2 %: about one sample in 500 carried the intended pattern, and the rest were noise.
The reply, and the replies to the reply
IBM's researchers answered days before the paper appeared. In a preprint and a blog post of 21 and 22 October 2019, they estimated that Summit, using its disks to hold the full register as Chapter 5 described, could do the job in about two and a half days, and more exactly than the chip. They never ran it. Others did run classical methods. In 2022 a team at the Chinese Academy of Sciences produced a million samples of higher fidelity than Sycamore's in about 15 hours on 512 graphics processors. In 2024 a team including researchers from the University of Science and Technology of China produced three million samples in 86.4 seconds on 1,432 graphics processors, against 600 seconds for Sycamore, though using about three times its energy. Google's own later analysis put the 2019 experiment at about 6 seconds on the Frontier supercomputer.
Ten thousand years is about 3.2 × 10¹¹ seconds, so the 2019 claim was a ratio of about 1.6 billion over Sycamore's 200 seconds. IBM's estimate of two and a half days, about 216,000 seconds, cut the ratio to about 1,080. The 2024 GPU run, 86.4 seconds against Sycamore's 600 for three million samples, turned the ratio below one: the classical machine was about seven times faster. Each figure was correct for the classical method it assumed. The ratio measured the methods known at the time, not the problem.
Later sampling experiments raised the bar to stay ahead. Google's 2024 Nature paper used 67 qubits and 32 cycles and estimated about 10,000 years on Frontier. In December 2024 Google announced a run on 103 of Willow's qubits that it said would take Frontier 10²⁵ years, an estimate that assumed unlimited fast disk storage and that appeared in a company announcement and specification sheet rather than in a peer-reviewed paper. The University of Science and Technology of China's Zuchongzhi 3.0, published in March 2025, sampled 83-qubit circuits and estimated about 5.9 billion years on Frontier. No practical classical reproduction of these larger runs had appeared by October 2026, as far as the sources for this guide show, but none of them can be checked directly either.
Answers that can be checked, at a price
The claims since 2025 have moved toward outputs that can be checked in some way. In March 2025, a Nature paper by a team from JPMorganChase, Quantinuum, US national laboratories and universities used a 56-qubit trapped-ion machine, reached over the internet, to produce 71,313 bits of certified randomness: random numbers whose randomness was proved, under stated assumptions about what an adversary can compute, by checking samples against a classical computation. The check took a sustained 1.1 exaflops across four US supercomputers, Frontier and Summit among them, so the output was verifiable, at the cost of some of the largest classical machines.
In October 2025 Google reported Quantum Echoes, a measurement on 65 of Willow's qubits of how a disturbance spreads through a quantum system and partly refocuses. Its output is a set of average values rather than random strings, which another quantum computer or a physical experiment could in principle reproduce, which is the sense in which Google called it verifiable. Google estimated about 3.2 years on Frontier for each data point against 2.1 hours on the chip, a ratio of about 13,000. A 2026 study found that one leading class of tensor-network methods could not simulate it, but several of its authors work at Google; an independent classical reproduction had not appeared as of October 2026.
Sampling of a different kind was tried with light. In December 2020 the same Chinese university reported Jiuzhang, an optical machine that sent squeezed light through a network of 100 paths and counted the photons at its outputs, a task called boson sampling. Its authors estimated that the Sunway TaihuLight supercomputer would need about 2.5 billion years for the samples the machine produced in 200 seconds. A 2024 classical algorithm that exploits the loss of photons in such machines outperformed the experiments on the benchmarks used as their evidence, with modest computing resources.
The 2026 round
On 30 July 2026, IBM announced quantum advantage through three preprints written with partners. In the first, written with the University of Chicago, a circuit on 70 encoded qubits ran inside an error-detecting code, 97 physical qubits in all, with runs that showed a detected error discarded; the run took about 15 minutes, and a statistical bound certified its fidelity at 0.284 or better. In the other two, the case rested on different classical methods disagreeing with each other about the answer, not on any one of them being shown wrong. IBM's own announcement added that announcing advantage "does not close the case—it opens the results to a new level of scrutiny."
The scrutiny came quickly. On 13 and 14 August 2026, a preprint by researchers at the Singapore University of Technology and Design and NVIDIA reported a classical simulation of the first circuit in 37.3 minutes on 256 graphics processors, at a fidelity consistent with IBM's bound. The pattern had appeared before. IBM's 2023 "utility" experiment drew a classical reproduction within 12 days. D-Wave's March 2025 Science paper on the dynamics of magnetic models claimed millions of years on Frontier; five days earlier, a classical preprint from the Flatiron Institute had matched or beaten its accuracy on most of the lattices tested, and that preprint was later published in Science as well.
| Claim | Year | Quantum time | Classical estimate when claimed | What followed |
|---|---|---|---|---|
| Sycamore, random sampling | 2019 | 200 s | 10,000 years | 86.4 s on 1,432 GPUs by 2024, against 600 s on the chip for 3 million samples |
| Jiuzhang, photon sampling | 2020 | 200 s | 2.5 billion years | 2024 classical method beat its benchmarks |
| IBM Eagle, magnetic dynamics | 2023 | (not compared) | beyond brute force | reproduced classically within 12 days |
| D-Wave, annealing dynamics | 2025 | minutes | millions of years | tensor networks matched most lattices |
| Google Quantum Echoes | 2025 | 2.1 h per point | 3.2 years per point | no independent reproduction yet |
| IBM and Chicago, encoded sampling | 2026 | about 15 min | far longer, by IBM's estimate | 37.3 min on 256 GPUs, in a preprint |
A ratio of times compares a quantum machine with one classical method on one classical machine, as estimated at one moment. The estimate can fall by orders of magnitude when someone improves the method, and it often does within months. Read the ratio as a statement about the state of classical algorithms as well as about the quantum computer.
The one check that settles a claim
Factoring sits at the far end of the scale of checkability: a claimed pair of factors is verified by one multiplication. That makes it the cleanest possible demonstration, and Chapter 8 showed why none has yet been made beyond 15. A 2026 review by Dominik Hangleiter summarized the state of the field: quantum computers can now perform tasks that no classical computer can, but those tasks are close to useless, and the next milestone is a quantum advantage that ordinary computers can verify.
What was the task, and is its output useful to anyone? Which classical method and machine served as the baseline, and was the classical estimate run or extrapolated? Can the output be checked, and by whom: nobody, another quantum computer, or an ordinary computer? Has anyone outside the claiming team tried to reproduce it classically? And what happened in the months after the announcement?
- Random circuit sampling, used for the 2019 Sycamore claim and its successors, produces output that nobody can check directly and that has no use of its own.
- Sycamore's 10,000-year estimate fell to an estimated 2.5 days before the paper even appeared and to seven times faster than the chip by 2024, because each ratio measured the classical methods known at the time.
- Claims since 2025 have moved toward checkable outputs, such as certified randomness, verified at the cost of four supercomputers, and Quantum Echoes, which another quantum machine could reproduce.
- The first of IBM's three July 2026 claims was answered by a 37-minute GPU simulation about two weeks later, and as of October 2026 no advantage has been shown that is both useful and classically verifiable.
+ Part IV · Noise
What scrambles a qubit, and how errors add up.
Willow's qubits hold their state for about 68 microseconds on average, and about once an hour something disturbs many of them at once. Part IV measures the enemy that Landauer named in 1994. Chapter 12 sets out what scrambles a qubit's arrows and how fast, from defects in the chip's materials to particles from space, and Chapter 13 shows why errors that are rare for one operation become certain over a long computation, and why a quantum computer cannot simply keep backup copies.
What scrambles a qubit.
+ The questionWhat does noise do to the arrows, and how fast?
Two ways to lose a qubit
A Willow qubit left in the state 1 decays to 0 after about 68 microseconds on average, the figure Google's 2024 error-correction paper gives across the chip, and a single cycle of its error correction takes 1.1 microseconds. The loss of the 1 state is called energy relaxation, and its average time is written T1. In the picture of arrows, relaxation shrinks the arrow for 1 and lengthens the arrow for 0, as the circuit gives its energy to its surroundings.
The second kind of loss leaves the energy alone and attacks the directions. Small random shifts in the qubit's frequency make the arrow for 1 turn slightly faster or slower than expected, so that after a while the relative direction of the two arrows is no longer known. This is called dephasing, and the time over which the direction is lost is written T2. Relaxation contributes to it too, so T2 can be at most twice T1. A qubit that has lost its phase still reads 0 or 1 with the right odds, but it no longer interferes as intended, and interference is all that a quantum algorithm uses. Willow's paper gives a mean T2 of 89 microseconds, against 20 and 30 microseconds for T1 and T2 on Google's previous error-correction chip of 2023.
Both times are measured with the tools of Chapters 2 and 4. For T1, a qubit is prepared in 1, left alone for a chosen delay and read, and the fraction still found in 1 is plotted against the delay; the fall of that curve gives T1. For T2, a Hadamard spreads the qubit over both levels, a delay follows, and a second Hadamard makes the arrows interfere, so the fringes fade as the directions wander. Adding refocusing pulses in the middle of the delay undoes slow drifts in frequency, and the version with a train of such pulses, called CPMG after its inventors, is the one Google quotes.
The chance that a qubit with a T1 of 68 microseconds relaxes during a time t is 1 minus e to the power of minus t divided by 68 microseconds. During a 25-nanosecond single-qubit gate it is about 0.037 %. During a reading of 250 to 480 nanoseconds it is 0.37 to 0.70 %, close to Willow's measured readout error of 0.77 %. During one 1.1-microsecond cycle of error correction it is about 1.6 %; on Google's 2023 chip, 500 of the 921 nanoseconds of each cycle went to reading and 160 to resetting. A qubit reaches a 1 % chance of having relaxed after only about 0.68 microseconds, less than one cycle.
A coherence time stated alone may be the best qubit on one chip on one day. Processors are limited by their worst qubits and by drift, because a computation uses all of them, and defects change over hours. Ask for the mean or median across the chip, the spread, and how much it varies over time.
The surroundings take a reading
Every loss of this kind has the same root, and it is the effect met in Chapter 3. The arrows of a qubit interfere only while nothing records which outcome it is in. Any interaction that leaves a trace of the qubit's state in its surroundings, an emitted photon, a jostled defect, a shifted charge, acts like a partial reading nobody asked for, and the arrows lose their ability to interfere. The general name for this is decoherence, and fighting it is most of the engineering of a quantum computer.
In superconducting chips the leading culprits are known. Atom-sized defects in the thin oxide layers and surfaces of the circuit behave as tiny two-level systems of their own, and when one of them sits near the qubit's frequency, it soaks up the qubit's energy; because these defects drift in frequency, a qubit's T1 changes over time, as a 2018 Google study tracked. Stray microwave photons, magnetic flux noise and unpaired electrons in the superconductor add their share, and every gate on a neighbor risks a little crosstalk. Willow's team forecasts where the defects sit in frequency and moves each qubit's operating frequency away from them before a run.
Leakage out of the two levels
A transmon has levels above 1, and an imperfect pulse or a stray excitation can push it into level 2 or higher. A qubit in that state is said to have leaked. Leakage is worse than an ordinary error, because the error-correction schemes of Part V are built to catch flips and phase turns between 0 and 1, not escapes from the two-level space, and a leaked qubit can spread errors to its neighbors for many cycles. Willow resets its measurement qubits to clear leakage after each reading and periodically moves any leakage from the data qubits into dedicated qubits that are reset in turn. Four of the 101 qubits in its largest code do nothing else.
Bursts from space
Some errors strike many qubits at once. A 2022 Google study watched a 26-qubit chip and saw, on average every ten seconds, a burst in which errors spread across the chip and faded over about 25 milliseconds; in the largest events nearly every qubit erred. The cause was high-energy radiation, cosmic rays and traces of radioactivity in the surroundings, depositing energy in the chip and breaking up the electron pairs that carry the superconducting current. A Beijing group reported in 2025 that detectors placed inside the refrigerator had caught muons, particles produced by cosmic rays in the upper atmosphere, arriving at the same moments as correlated errors on its chip. A 2024 design trick called gap engineering, which makes the superconductor on the two sides of each junction slightly different, made the qubits largely insensitive to such broken pairs. In Willow, the remaining correlated bursts came about once an hour, roughly every 3 billion cycles, and their cause was uncertain.
Bursts matter more than their rarity suggests. Error correction assumes that errors strike qubits independently and rarely together, and a burst that hits dozens of neighbors at once breaks that assumption. Willow's simplest codes, which protect against only one kind of error and can therefore reach very low error rates, stopped improving near one error in 10¹⁰ cycles because of these bursts. A computation of billions of steps will meet such an event, so the hardware must suppress them and the codes must survive the ones that remain.
Better materials, one qubit at a time
Coherence times have risen steadily. Willow's mean T1 is about three and a half times that of Google's 2023 chip, and in 2025 a Princeton team reported transmons built from tantalum on silicon with a T1 of up to 1.68 milliseconds, about 25 times Willow's mean, together with single-qubit gate fidelities of 99.994 %. The 1.68 milliseconds was the best single device among those measured, not the average of a working processor, and bringing such materials into chips of hundreds of qubits, each wired, coupled and controlled, takes years. Longer coherence helps every later chapter: each gate and each reading costs a smaller fraction of the time a qubit can hold its state. Other kinds of qubit sit at very different points. A single trapped ytterbium ion held its phase for an estimated 5,500 seconds, about an hour and a half, in a 2021 laboratory record, and a 2025 Caltech array kept the phase of its atoms for about 12.6 seconds; Chapter 19 shows why their slower gates offset much of that advantage.
When evaluating a processor, ask how often it is recalibrated and how much its error rates drift between calibrations, how leakage is detected and removed, and how often correlated bursts occur and what limits them. These three effects, not the average error rate, set the floor that error correction can reach, and Chapter 15 shows that the floor decides how large a protected memory can usefully be.
- Energy relaxation, measured by T1, shrinks a qubit's arrow for 1, and dephasing, measured by T2, scrambles the relative direction of its arrows; Willow's means are 68 and 89 microseconds.
- With a T1 of 68 microseconds, about 1.6 % of qubits relax during one 1.1-microsecond cycle, and about 0.4 to 0.7 % during a single reading.
- Decoherence is an unintended reading by the surroundings, caused in superconducting chips by material defects, stray photons, crosstalk and leakage above the two working levels.
- Bursts from cosmic rays and radioactivity strike many qubits at once, every ten seconds or so on a 2022 chip and about once an hour on Willow, built with gap engineering, and they set a floor on what codes can reach.
Why errors compound.
+ The questionIf each operation fails once in a thousand, how long can a computation run and still finish correctly?
Copying and voting fails at the first step
The oldest way of protecting information, keeping three copies and taking a vote, fails for qubits at its first step, because an unknown qubit cannot be copied. In 1982 William Wootters and Wojciech Zurek, and independently Dennis Dieks, showed that no machine can take a qubit in an unknown state and produce two qubits each in that state. The proof uses only the fact that quantum operations act on arrows in a linear way, adding and scaling them without distortion. A machine that turned 0 into 00 and 1 into 11, as a copier must, would turn a qubit spread over 0 and 1 into arrows on 00 and 11 only: an entangled pair like the Bell pair of Chapter 5, not two independent copies, which would also carry arrows on 01 and 10.
The 1982 papers answered a published proposal to signal faster than light by copying one half of an entangled pair, and a 2018 historical study found that James Park had given a proof of the same fact in 1970, twelve years earlier. The result is called the no-cloning theorem. It does not forbid copying a qubit known to be 0 or known to be 1, which is just like copying a bit; it forbids copying one whose arrows are unknown, which is the state every useful computation passes through. Nor can the qubit be checked by reading it, since a reading destroys the arrows. Shor recalled in 2022 that the theorem seemed to say quantum error correction was impossible. Chapter 14 shows how it was done anyway, and this chapter shows why it had to be.
Errors add up
Suppose every operation in a computation fails independently with the same small chance p. The chance that a computation of N operations finishes with no error at all is the chance of success, 1 − p, multiplied by itself N times. For small p this is close to e to the power of minus p times N, so the success rate falls off steeply once N passes 1/p. At p of 1 in 1,000, about the best two-qubit error of today's full processors, half of all runs contain an error after about 693 operations.
The independent model flatters the machine. Real errors come in two kinds, flips between 0 and 1 and turns of the phase, and a phase error is invisible to a reading while still ruining the interference the algorithm depends on, so both must be caught. Some errors are also correlated: the bursts of Chapter 12 strike many qubits together, and leakage spreads to neighbors. Any of these makes long computations fail sooner than the simple formula predicts, and each needs its own countermeasure.
At an error of 1 in 1,000 per operation, 1,000 operations succeed about 37 % of the time, and a million operations essentially never. Craig Gidney's 2025 design for RSA-2048 needs about 6.5 × 10⁹ Toffoli gates for a whole factorization, spread over about nine runs, and each run keeps about 1,600 protected qubits, working space included, for about 12 hours. Counting every protected qubit in every microsecond cycle, a run involves about 6.9 × 10¹³ chances for a protected error. Gidney therefore sets the target at 1 in 10¹⁵ per protected qubit per cycle, which gives 1 minus 1 in 10¹⁵, raised to the power 6.9 × 10¹³, or about 93 % of runs free of error. Between the physical error of 1 in 10³ and the protected error of 1 in 10¹⁵ lies a factor of 10¹², and all of it must come from error correction.
The arithmetic explains the shape of the whole field. No foreseeable improvement in materials brings a physical qubit from 1 in 10³ to 1 in 10¹⁵. Chapter 12 showed coherence improving by factors of a few at a time, and even the best two-qubit gates reported by 2026 err about 1 time in 10,000. The remaining factor of a hundred billion or more has to be manufactured by spending many physical qubits on each protected one, which is why the qubit counts in every estimate for RSA-2048 run to hundreds of thousands or millions.
An error rate per gate means little until it is multiplied by the number of gates a useful computation needs. A two-qubit error of 1 in 1,000 is an achievement for a physical device and leaves a computation of a million gates with no chance of success. Ask what the computation needs, then what the protected error rate must be, then how it is to be reached.
Small turns, large drift
Errors in a quantum computer are not only flips. A gate that should turn an arrow by a quarter turn might turn it by a quarter turn plus a hair, and the hair is a continuous quantity, not a yes or no. In an ordinary digital circuit, every gate restores its output to a clean 0 or 1, so tiny deviations never add up. Rolf Landauer warned in 1995 that small errors would accumulate and send a quantum computation off track, and his paper's abstract calls it "a warning signal." Quantum computation, being a matter of continuous turns, seemed to lack the restoring step. Errors that repeat the same way at every gate, such as a pulse that always turns slightly too far, are the most dangerous, because they add in one direction instead of partly canceling as random errors do. Preskill estimated in 1998 that such systematic errors would have to be about a hundred thousand times smaller than random ones for long computations to work, which is why calibration, the subject of Chapter 18, is never finished. A careful error budget therefore separates random errors, systematic errors, leakage and bursts, and gives each its own allowance.
Others agreed. In a 1996 Physics Today article titled "Quantum computing: dream or nightmare?", Serge Haroche and Jean-Michel Raimond, two leading experimenters, worked out what factoring would demand and concluded that "performing large-scale calculations will remain an impossible dream for the foreseeable future." They estimated that factoring a 400-bit number would need a ratio of coherence time to gate time of about 4 × 10¹¹, far beyond any device they knew.
The answer, given by Shor in 1995 and developed by others in the following two years, is that measuring the right combinations of qubits converts continuous errors into discrete ones. A check that asks whether two qubits agree has only two answers, and asking it forces any small, continuous error into either no error at all or a definite flip that the check reports. Correction can then undo the flip. John Preskill, reviewing the debate in 1998, put the conclusion in Landauer's own terms: error correction allows encoded quantum information to be restored to standard, as digital electronics is.
The budget, then and now
Preskill's 1998 estimate gives a sense of how the budget has moved. To factor a 432-bit number, about 130 digits, he estimated about 2,150 protected qubits, about 3 × 10⁹ Toffoli gates and, with physical errors of 1 in a million, a machine of about a million physical qubits. Gidney's 2025 design for a 2,048-bit number uses about 1,400 protected qubits and about 7 × 10⁸ Toffoli gates in each of its runs, on about 900,000 physical qubits with errors of 1 in 1,000. The machines are the same order of size, but the 2025 design tolerates physical errors a thousand times more frequent and factors a number almost five times longer. Both estimates rest on the same algorithm, in different variants: the modular arithmetic of Chapter 7 and the Fourier step of Chapter 8. Three decades of better codes and smarter arithmetic made the difference, and Chapters 14 to 16 show how.
Start from the success rate a run must reach and the number of protected operations it contains. For a computation of 6.5 × 10⁹ operations to succeed nine times in ten, each must fail less than about 1 time in 6 × 10¹⁰. From that target, the code of Part V sets the size of each protected qubit, and the size sets the machine. Working the chain backward from the application is what turns a qubit count into a meaningful requirement.
- No-cloning, which follows from the linearity of quantum operations, forbids copying an unknown qubit, so copy-and-vote protection is impossible and reading to check would destroy the state.
- With independent errors of chance p, a run of N operations succeeds about e to the minus p times N of the time, so at 1 in 1,000 half of all runs fail within about 700 operations.
- Gidney's 2025 design for RSA-2048 needs protected errors of 1 in 10¹⁵ per qubit per cycle for 93 % of runs to succeed, a factor of 10¹² beyond physical qubits.
- Landauer and others argued in the 1990s that continuous errors would accumulate; measuring the right checks turns them into discrete flips that can be corrected, the basis of everything in Part V.
+ Part V · Error correction
How many fragile qubits make one reliable one.
In December 2024, each step up in the size of Willow's protected memory, from 17 qubits to 49 to 97, cut its error per cycle by a factor of about 2.14. Part V explains how that is possible when no qubit can be copied or read without damage. Chapter 14 shows how checks that compare qubits find errors without learning what the qubits hold, Chapter 15 how a grid of such checks became the standard design and what Willow's result means, and Chapter 16 what it costs to turn physical qubits into protected ones good enough for the computations of Part III.
Checking without looking.
+ The questionLooking destroys the state. How, then, can an error be found?
Parity in ordinary memory
A server's memory module with error correction carries extra chips that store check bits alongside the data, adding 12.5 % to its raw capacity. The idea goes back to Richard Hamming at Bell Labs, who complained in 1950 that in large computing machines "a single failure usually means the complete failure" of a calculation. The simplest check is a parity bit: one extra bit chosen so that the count of 1s in a word is even. If any single bit flips, the count becomes odd and the error is detected. Hamming's own code went further, storing four data bits with three check bits arranged so that the pattern of failed checks points to the bit that flipped, which can then be flipped back.
Ordinary error correction works because bits can be read and copied freely: the checks look at the data. A qubit permits neither, as Chapter 13 showed. The solution found in 1995 keeps the essential feature of a parity check, that it reports whether bits agree rather than what they are, and makes that the only thing ever read.
Checking qubits without reading them
Start with the simplest quantum code, which protects against flips only. One qubit's arrows are spread over three qubits by two CNOT gates, so that its arrow for 0 becomes an arrow for 000 and its arrow for 1 an arrow for 111. This is not copying, which no-cloning forbids: the three qubits hold one shared set of arrows, not three independent ones. If one of the three flips, the register's arrows move to strings such as 010 or 101, which the code never uses.
The checks ask two questions: do qubits 1 and 2 agree, and do qubits 2 and 3 agree? Each is answered by a helper qubit, called an ancilla, that is entangled with the two qubits it checks by a pair of CNOTs and then read. A reading of the helper reveals agreement or disagreement and nothing else, because both 000 and 111 agree everywhere. The arrows of the protected qubit are untouched, and the pattern of answers, called the syndrome, names the qubit that flipped.
Errors keep arriving, so the checks are not run once but over and over, in rounds. What signals an error is a change in the syndrome from one round to the next. That also guards against faulty checks: a helper qubit misread once produces a syndrome that changes and then changes back, while a real flip produces a change that persists. Telling the two apart from the history of syndromes is the job of a classical program called a decoder, which Chapter 15 shows running in real time.
If no qubit flipped, both checks report agreement. If qubit 1 flipped, the first check reports disagreement and the second agreement; if qubit 2, both report disagreement; if qubit 3, the first agrees and the second does not. The flipped qubit is then flipped back. The code fails only if two or three qubits flip before the check, which for independent flips of chance p happens with a chance of 3p² − 2p³. At p = 1 % that is about 0.03 %, thirty-three times better than an unprotected qubit; at p = 0.1 %, about 3 in a million. At p = 10 % it is 2.8 %, still better, because majority voting helps whenever flips are rarer than one in two.
Phase errors, and Shor's nine qubits
Flips are only half the problem. A qubit's arrows can also suffer a phase error, a turn of the arrow for 1 that no reading of 0 or 1 sees, and the three-qubit code is blind to it. A Hadamard gate turns phase errors into flips and flips into phase errors, so the same code built between Hadamards protects against phase errors instead. Shor's 1995 code, published that October, combined the two by nesting them: the qubit is first spread over three qubits against phase errors, and each of those is spread over three more against flips, nine qubits in all. A single error of either kind, on any one of the nine, can be found and undone.
The nine-qubit code also catches errors that are neither a clean flip nor a clean phase error. A small, continuous error, such as an arrow turned a little too far, appears to the checks as a mixture of no error and a definite error; the reading of the checks settles which one happened, and the correction undoes it. That is the discretization of errors described in Chapter 13, and it is why a finite set of checks can deal with a continuum of possible faults. Shor's patent on the scheme, filed in October 1995, gives the chance that a group of nine fails as about 36p², which is smaller than p, so that encoding helps, whenever p is below about 1 in 36, if the checks themselves were perfect.
Within a year others found better codes. Andrew Steane, at Oxford, built a seven-qubit code directly from Hamming's 1950 design, and Robert Calderbank and Shor proved that good quantum codes exist in general, protecting against many errors at a modest cost in qubits.
Correcting the correctors
The checks are made of gates, and gates err. A check that introduces more errors than it removes is worse than no check at all, and a scheme that is safe against its own faults is called fault tolerant. Shor showed in 1996 how to build checks that do not spread a single fault into many, but, as he wrote in 2022, his paper "did not give the result for fault-tolerance that I wanted to prove, which was a threshold theorem." Two groups soon proved it, Dorit Aharonov and Michael Ben-Or, and Emanuel Knill, Raymond Laflamme and Wojciech Zurek, by nesting codes inside codes many times, and Alexei Kitaev found a different route through codes laid out on a surface.
The threshold theorem says that if every physical operation errs less often than a fixed threshold, computations of any length can be made as reliable as desired, at a cost in qubits and time that grows only slowly with the length. The early estimates put the threshold near 1 error in a million operations, far below the hardware of the time, but the principle settled the argument with Landauer.
The price of nesting was steep. Preskill's 1998 review worked through three levels of Steane's seven-qubit code, 7 × 7 × 7 = 343 physical qubits for each protected one before counting helpers, and estimated thresholds of about 1 in 10,000 for gate errors if stored qubits were nearly perfect. Each check also had to reach qubits that sit far apart on a chip, which most hardware cannot provide, because qubits on a flat chip are wired only to their neighbors. Kitaev's alternative, codes whose checks involve only neighboring qubits on a surface, removed that obstacle, and Chapter 15 follows it to Willow. Landauer himself came round: his colleagues wrote in their 1999 obituary of him that by the late 1990s the proponents had answered his criticisms well enough "to win his grudging respect."
In the estimate of Knill, Laflamme and Zurek, each level of nesting turns an error rate p into at most about a million times p². Suppose physical operations err at 1 in 10⁷, ten times below the threshold of 1 in 10⁶. One level gives a million times the square of 1 in 10⁷, or 1 in 10⁸. Two levels give 1 in 10¹⁰, and three give 1 in 10¹⁴. Each level multiplies the qubit count, but the error falls faster and faster. Above the threshold the same squaring makes things worse at every level.
A code built from qubits that err too often makes the stored information less reliable than a single bare qubit, because its checks add more errors than they remove. Results that report a protected qubit outlasting its best physical qubit, called break-even, and results that report errors falling as the code grows, called operating below threshold, are the two milestones that show a code is helping at all.
For any error-correction scheme, ask whether it corrects both flips and phase errors or only one kind, how many physical qubits and gates each check takes, and how often the checks run. Ask whether runs with detected errors are corrected or simply discarded, a distinction Chapter 16 returns to. A code that only detects errors is useful in experiments but cannot carry a long computation.
- Ordinary memories use parity bits that report whether bits agree, and Hamming's 1950 code located and corrected a single flipped bit.
- The three-qubit code spreads one qubit's arrows over 000 and 111 and reads only whether qubits agree, so a flip is found without reading the protected arrows; it fails with a chance of about 3p².
- Shor's nine-qubit code of 1995 nests two such codes to correct any single error, including small continuous ones, which the checks turn into definite flips or phase errors.
- The threshold theorem of 1996 and 1997 shows that below a fixed physical error rate, nested codes make computations as reliable as needed, which answered Landauer's objection in principle.
A checkerboard of checks.
+ The questionWhy does almost every hardware roadmap use the same code, and what is a threshold?
Checks between neighbors
Willow's 2024 paper turns on one number, 2.14: each time its protected memory was made one step larger, the error per cycle fell by that factor. The memory used the surface code, the descendant of the codes Kitaev laid out on a surface in 1997, and the reason almost every superconducting roadmap uses it is geometric. Its data qubits sit on a square grid, and a second set of qubits, placed in the gaps between them, each check the four data qubits around it. Half the checks look for flips and half for phase errors, arranged like the dark and light squares of a checkerboard, and no check ever involves a qubit that is not a neighbor.
That fits a flat chip exactly. Each qubit needs couplings only to the qubits beside it, which is what a grid of transmons provides, and the same short sequence of gates runs in every square, every cycle. A patch of the code with sides of d data qubits holds one protected qubit; d is called the code distance, because the smallest set of errors that can change the protected qubit without being detected must stretch across the patch, d qubits long. A patch of distance d uses d² data qubits and d² − 1 checking qubits, 2d² − 1 in all: 17 for distance 3, 49 for distance 5 and 97 for distance 7.
The design tolerates relatively noisy parts. A 2012 analysis by Austin Fowler, Matteo Mariantoni, John Martinis and Andrew Cleland, which became the standard reference, put the tolerable error per operation as high as about 1 %, and 0.57 % in the detailed circuit they simulated, against 1 in a million for the nested codes of Chapter 14. The price is size: Fowler and colleagues estimated that a protected qubit good enough for long computations would need between a thousand and ten thousand physical qubits.
The threshold as a slope
Below the threshold, a larger patch is better, because an undetected error needs more physical errors to line up across it. Each increase of the distance by two divides the protected error by a factor written Λ, the Greek letter lambda, which is roughly the threshold divided by the physical error rate. A machine with physical errors at half the threshold has Λ of about 2, and one with errors at a tenth of the threshold has Λ of about 10. Above the threshold Λ falls below 1, and a larger patch is worse. Fowler's group wrote the rule as a short formula: the protected error per cycle is about 0.03 divided by Λ raised to the power of half of d + 1. Willow's numbers fit it: for distance 7, 0.03 divided by 2.14⁴ gives about 0.0014, the measured 0.143 %.
The relationship makes the threshold less like a finish line than a slope. Crossing it shows that the code works, and the steepness of the slope, Λ, decides how large a patch must be to reach a given error rate. A 2023 Google chip, with 72 qubits, had shown a distance-5 patch only just better than distance 3: 2.914 % error per cycle against 3.028 %, a Λ of about 1.04. The 2024 result on Willow was the first with a slope steep enough to matter.
Operating below threshold shows that adding qubits helps. It does not show that the protected qubit is good enough for anything: Willow's 0.143 % per cycle is about a trillion times too high for RSA-2048. Ask for the slope, the error at the largest distance tried, and whether a floor has appeared.
What Willow showed
Willow ran patches of distance 3, 5 and 7, for up to 250 cycles each, and found Λ = 2.14, give or take 0.02. The distance-7 patch, 101 qubits including the four that remove leakage, erred 0.143 % per cycle. Its protected qubit lasted 291 microseconds, 2.4 times longer than the best of its physical qubits, so the memory was past break-even. Those figures used a neural-network decoder run after the experiment; a standard matching decoder gave a Λ of 2.04. Simpler codes that protect against flips alone, run up to distance 29, reached about one error in 10¹⁰ cycles and then stopped improving, held back by the bursts of Chapter 12, which arrived about once an hour.
Start from 0.143 % per cycle at distance 7 and divide by 2.14 for every further step of two in distance. Ten steps give distance 27 and an error of about 7 in 10⁷ per cycle, which matches the paper's own projection: an error of 1 in a million needs a distance-27 patch of 1,457 qubits. One in 10⁹ needs distance 45, 4,049 qubits; one in 10¹² needs distance 63, 7,937 qubits; one in 10¹⁵, the target of Chapter 13, needs distance 81, 13,121 qubits for each protected qubit. The calculation assumes the slope holds and that no floor intervenes.
The example shows why physical error rates matter so much. Gidney's 2025 design for RSA-2048 reaches 1 in 10¹⁵ at distance 25, not 81, because it assumes physical errors of 0.1 % on every operation, three to eight times better than Willow's two-qubit and measurement errors. Better physical qubits steepen the slope, and a steeper slope shrinks every patch in the machine.
The decoder, a classical computer in the loop
Every cycle, every checking qubit reports one bit. A distance-7 patch produces 48 bits per cycle, and at Willow's 909,000 cycles per second that is about 44 million bits a second for a single protected qubit. A decoder must turn that stream into a judgment of which errors most likely occurred, and it must keep up: if its backlog grows, the computation stalls, and any step that depends on a corrected result waits for it. Willow's paper ran a separate real-time test on a second, 72-qubit Willow processor, decoding a distance-5 patch for up to a million cycles with an average delay of 63 microseconds per answer while keeping pace with the 1.1-microsecond cycle.
Delay matters as much as speed. Some steps of an algorithm, such as the corrections that follow a magic-state injection, must wait for the decoder's answer before the next gate, and Gidney's design assumes the whole loop, from reading to decision to new pulse, closes in 10 microseconds. In November 2025 IBM reported decoding of its own codes in less than 480 nanoseconds, a company figure. The decoder is a classical computer that sits inside the quantum one, and Chapter 18 places it in the signal chain.
The year after
Results through 2026 refined rather than overturned Willow's. Google reported a color code, a cousin of the surface code that makes more gates easy, with a Λ of 1.56 from distance 3 to 5, and surface codes run with fewer couplings per qubit. In July 2026 its team reported using reinforcement learning to adjust more than 1,000 control settings while the code ran, reaching 7.72 errors in 10,000 cycles at distance 7, about half the 2024 figure. A Chinese team reported a Λ of 1.40 at distance 7 on its Zuchongzhi 3.2 chip in December 2025, and in mid-2026 preprints from the same university and from Zhejiang University performed operations between two distance-3 patches. A Harvard and QuEra paper on neutral atoms reported a factor of 2.14 from distance 3 to 5 over four rounds of checks, a different measurement that coincides with Willow's figure only in its digits.
When a result reports error correction below threshold, ask for Λ and over which distances it was measured; whether the decoder ran in real time or afterward, and with what delay; how many cycles were run; and whether simpler codes on the same chip revealed a floor from correlated errors. Those four answers determine how large a machine built on that technology must be.
- The surface code checks groups of four neighboring qubits on a grid, so it suits flat chips, and a patch of distance d uses 2d² − 1 qubits: 17, 49 and 97 for distances 3, 5 and 7.
- Below the threshold, about 1 % per operation, each increase of two in distance divides the protected error by Λ, roughly the threshold divided by the physical error.
- Willow reached Λ = 2.14 and 0.143 % per cycle at distance 7 in 2024, with a protected qubit lasting 2.4 times longer than its best physical qubit.
- At Willow's slope, an error of 1 in 10¹⁵ would need distance 81 and about 13,000 qubits per protected qubit, and a decoder must keep pace with tens of millions of check bits per second for each.
From physical to logical.
+ The questionHow many physical qubits make one logical qubit good enough for a billion operations?
What one logical qubit costs
A logical qubit is a qubit made of many physical ones by an error-correcting code, so that its error rate is set by the code and the quality of its parts rather than by any single part. The surface code of Chapter 15 makes the cost of one easy to estimate, because only two numbers matter: the error rate the computation needs and the slope Λ the hardware achieves. The solved example works the arithmetic for four slopes, from about Willow's to one that physical qubits ten times better than the threshold would give.
Using the rule of Chapter 15, an error per cycle of 0.03 divided by Λ raised to the power of half of d + 1, and the patch size 2d² − 1, find the smallest distance that reaches each target. For 1 error in 10⁹ per cycle: at Λ = 2, distance 49 and 4,801 qubits; at Willow's 2.14, distance 45 and 4,049; at Λ = 4, distance 25 and 1,249; at Λ = 10, distance 15 and 449. For 1 in 10¹²: 9,521, 7,937, 2,449 and 881 qubits. Doubling Λ from 2 to 4 cuts the cost of each logical qubit by about a factor of four. The calculation holds the 0.03 fixed and assumes no floor, so it is a guide to scale, not a design.
Published designs sit across that range. Fowler and colleagues in 2012 estimated about 14,500 physical qubits per logical qubit for their factoring machine. Gidney's 2025 design for RSA-2048 uses 1,352 per logical qubit for the qubits being worked on, at distance 25, and only about 430 for qubits waiting in storage, by adding a second layer of checks across groups of stored patches, a scheme called yoked surface codes. Averaged over the whole machine, including the factories described next, it spends about 640 physical qubits per logical qubit.
The layout of Gidney's machine shows where the qubits go. About 1,280 logical qubits wait in yoked storage at about 430 physical qubits each, some 550,000 in all. About 131 are being worked on at any moment, at 1,352 each, some 177,000. The remaining 170,000 or so make up the working area where arithmetic happens and six factories prepare the ingredients for Toffoli gates. The total is 897,864 physical qubits, the figure behind the headline of fewer than a million.
The gate the code does not make easy
A surface code makes some operations cheap. Two patches can be merged and split again to perform a CNOT between their logical qubits, a technique called lattice surgery: a 2012 paper showed a CNOT between two distance-3 patches using 53 physical qubits. The Hadamard and S gates are similarly manageable. The T gate is not, as Chapter 4 warned, and neither are the Toffoli gates of Shor's arithmetic, which are built from T gates or performed directly with prepared ingredients.
The way around it was found by Sergey Bravyi and Alexei Kitaev in 2005: prepare special magic states separately, accept that they come out noisy, and refine them, a process called distillation, in which many noisy copies are consumed to produce fewer, better ones. A protected T gate then consumes one good magic state. The refining happens in magic state factories, regions of the chip that do nothing else, and in older designs they took up most of the machine. In 2024, Gidney, Noah Shutty and Cody Jones of Google proposed cultivation, which grows a single magic state gradually inside one patch; in their simulations it reached errors of about 2 in 10⁹ at a physical noise of 1 in 1,000, with about a tenth of the space and time of earlier methods. A December 2025 experiment by Google's team, described in Chapter 4, grew such states on a superconducting chip. The factories also set the pace of a computation. In Gidney's design, six of them feed the arithmetic, and over a whole factorization the machine completes one Toffoli gate about every 66 microseconds on average. Fewer factories would mean fewer qubits and a longer run, which is the trade Chapter 22 follows through the estimates.
Codes with less overhead
The surface code's cost comes from its simplicity: each check involves four neighbors, and the code protects one logical qubit per patch. Codes whose checks reach further can pack many logical qubits into one block. In a 2024 Nature paper, a team at IBM described a code of this family, a quantum low-density parity-check code, that would store 12 logical qubits in 288 physical qubits, 24 per logical qubit, with a threshold of 0.8 %, where a surface code with the same protection would need nearly 3,000. The catch is wiring: each qubit must be coupled to six others, some of them far away, which needs two layers of connections on the chip.
The result was a simulation, and the hardware is behind it. The first superconducting demonstration of such codes, by a team at Zhejiang University published in 2026, ran errors of about 8 to 9 % per logical qubit per cycle, far above Willow's surface code. IBM's own roadmap, a company plan, puts a first chip storing information in such a code, Kookaburra, in 2026 and a fault-tolerant machine, Starling, with 200 logical qubits running 100 million gates, in 2029. A February 2026 design by the start-up Iceberg Quantum, using such codes with the same error assumptions as Gidney's, put RSA-2048 within reach of fewer than 100,000 physical qubits running for about a month, or about 381,000 for a single day, provided the hardware offers the longer-range links the codes need. Other teams reduce overhead through the qubits themselves. Amazon's Ocelot chip of 2025 used cat qubits, oscillators whose bit flips are suppressed by design, leaving mainly phase errors for a simple code to catch, and the French company Alice & Bob, which builds the same kind of qubit, reported bit-flip times above ten seconds in 2024.
What "logical qubit" means in announcements
Counts of logical qubits have appeared in many announcements since 2023, and they are not counted the same way. A careful 2025 review by John Preskill, not a vendor, distinguished error detection from error correction and stressed that discarding runs with detected errors, called post-selection, does not scale to long computations, because the share of runs kept shrinks with their length. Preskill noted that on atomic platforms, at the time of writing, "it has not been possible to perform more than a few rounds of error syndrome measurement," with results relying on detection and post-selection; several 2025 results went further. The claims fall on three rungs.
| Rung | What the code does | Examples |
|---|---|---|
| Detected, with post-selection | finds errors and discards the run; often distance 2 | 48 logical qubits on an array of up to 280 atoms (Harvard and QuEra, 2023); up to 96 distance-4 logical qubits with errors detected (Harvard and QuEra, 2025); 24 on 48 atoms (Microsoft and Atom Computing, 2024); 94 on Quantinuum's Helios (2025, company figure); 70 encoded qubits on 97 (IBM, 2026) |
| Corrected for a few rounds | corrects errors, often with some runs discarded | 8 logical qubits through five rounds of correction, with half the runs discarded (Microsoft and Quantinuum, 2024); a distance-5 surface code corrected over four rounds on an array of up to 448 atoms (Harvard and QuEra, 2025); 48 error-corrected on Helios (2025, company figure) |
| Repeated memory, real time, Λ above 1 | corrects every cycle, errors fall as the code grows | one logical qubit at distance 7 on Willow (2024; improved in 2026) |
Every rung is real progress, and the lower rungs often run more logical qubits at once than the top one. None of them yet provides logical qubits at the 1 in 10¹⁵ that RSA-2048 needs, or the 1 in a million per operation that Preskill takes as the mark of a first useful error-corrected machine, which he calls a megaquop machine because it would run a million operations. Alice & Bob published five criteria for logical-qubit claims in June 2026, a vendor's framework that asks, among other things, whether performance holds across all runs rather than after heavy post-selection.
A headline count of logical qubits needs three qualifiers before it means anything: the code distance, whether errors were corrected or only detected, and what share of runs was kept. A distance-2 code with post-selection and a distance-7 memory with real-time correction are both called logical qubits, and they are separated by orders of magnitude in what they can sustain.
For a claim of logical qubits, ask for the logical error per operation or per cycle, the number of cycles or operations sustained, the acceptance rate if runs were discarded, and the physical qubits used per logical qubit. Then compare them with the budget of Chapter 13 for the computation in view. The ratio of physical to logical qubits matters less than whether the logical error rate falls as the code grows.
- A logical qubit's cost follows from the error rate needed and the slope Λ: for 1 error in 10⁹ per cycle, about 4,800 physical qubits at Λ = 2 and about 450 at Λ = 10.
- Cheap operations on surface codes include CNOTs by lattice surgery, while T and Toffoli gates need magic states, refined in factories or grown by cultivation.
- Codes with longer-range checks promise far less overhead, such as 12 logical qubits in 288 physical qubits on paper, but their first hardware runs erred 8 to 9 % per cycle.
- Logical-qubit counts in announcements span detected and post-selected codes, codes corrected for a few rounds, and repeated real-time memories, and only the last has sustained correction cycle after cycle with errors falling as the code grows.
+ Part VI · The machine as an instrument
Cold, wiring and the signal chain of a qubit.
In 1984 and 1985, John Clarke's group at the University of California, Berkeley, with John Martinis as a graduate student and Michel Devoret as a postdoctoral researcher, set out to show that a whole electrical circuit could behave like an atom. Wired the way such experiments usually were, the first attempt, in Martinis's words, "completely failed." The group filtered every line, above all at microwave frequencies, and then "the data made perfect sense": a circuit at 18 to 28 millikelvin absorbed microwaves in discrete steps. The paper appeared on 7 October 1985, forty years to the day before the Nobel Prize in Physics honored it. Part VI treats a quantum computer as that experiment already was, an instrument whose hardest problem is keeping the world out while signals go in and come back. Chapter 17 follows the cold, Chapter 18 the signal chain of one qubit, and Chapter 19 the machines built from ions, atoms, photons and spins.
Inside the refrigerator.
+ The questionWhy does a superconducting quantum computer need a refrigerator colder than space, and what does each stage do?
A chandelier of stages
A dilution refrigerator wired for qubits hangs as a stack of round metal plates, each colder than the one above. In a 2019 description of such a system at ETH Zurich, built on a commercial Bluefors refrigerator, the plates ran at about 35 K, 2.85 K, 0.88 K, 0.082 K and, at the bottom, 6 millikelvin, about six thousandths of a degree above absolute zero. The quantum chip sits in a shielded can on the coldest plate. Every cable from the room-temperature electronics runs down through the plates, and each plate exists to remove heat that would otherwise reach the stage below. The plates also serve as shields, each blocking the infrared glow of the warmer plate above it.
The coldest plate is called the mixing chamber, after the process that cools it. Below about 0.87 K, a mixture of the two isotopes of helium, helium-3 and helium-4, separates into two layers, one rich in helium-3 and one dilute. Helium-3 atoms crossing from the rich layer into the dilute one absorb heat, much as evaporation cools a liquid, and pumping helium-3 out of the dilute side at a warmer plate, the still, keeps them crossing. A mechanical cooler called a pulse tube precools everything to about 3 K, so the refrigerator needs no bath of liquid helium. The method was proposed by Heinz London in the early 1950s and first made to work in 1964 at the Kamerlingh Onnes Laboratory in Leiden.
The cooling power at the bottom is tiny. The 2019 system could absorb about 19 microwatts at 20 millikelvin, about two hundred-thousandths of a watt. The manufacturer's current models list more than 30 microwatts at 20 millikelvin, and its largest platform, built for over a thousand qubits, more than 90 microwatts, split across three cooling units. Every design choice below the still is a decision about how to spend those microwatts.
Why so cold
A qubit at 5 GHz stores the energy of one microwave photon, and the surroundings at any temperature are full of such photons. Their average number at a given frequency follows a simple formula from the physics of heat, and it falls steeply once the temperature drops below the photon's energy expressed as a temperature, about 0.24 K at 5 GHz. A stray photon absorbed by a qubit in 0 flips it to 1, so the qubit's surroundings must hold almost none.
The average number of photons in one 5 GHz mode is 1 divided by (e to the power 0.24 K divided by the temperature, minus 1). At room temperature, 300 K, that is about 1,250. At 4 K it is about 16, and the cosmic microwave background, the 2.7 K glow of space, gives about 11. At 100 millikelvin it falls to 0.1, at 20 millikelvin to about 6 in a million, and at 10 millikelvin to about 4 in 10¹¹. A qubit at 10 millikelvin is therefore far quieter than one in deep space, by a factor of several hundred billion in stray photons.
The same arithmetic explains the 1985 filters. Cooling the chip is not enough if a cable carries photons down from a warmer stage. A line from room temperature delivers about 1,250 photons per mode at 5 GHz, and only absorbing them along the way, at stages cold enough not to emit new ones, removes them. The Berkeley experiment of 1985 worked at frequencies from 2 to 5.7 GHz, where a line anchored at 4 K would have carried dozens of photons per mode at the low end, against about five thousandths at the 18 millikelvin of the junction.
Every line brings heat and noise
Each cable that drives a qubit is a path for heat and for noise. The 2019 study measured the heat that one stainless-steel drive line conducts into each plate: about 45 milliwatts into the 35 K plate, 1 milliwatt into the 3 K plate, and about 13 billionths of a watt into the mixing chamber. Adding 66 lines raised the mixing chamber from 6.1 to 8.4 millikelvin. Pulses sent through the lines add heat of their own wherever they are absorbed.
Noise is removed with attenuators, components that absorb most of a signal and turn it into heat at their own stage. The 2019 design placed 20 decibels of attenuation, a factor of 100 in power, at each of the 3 K plate, the 0.08 K plate and the mixing chamber, so that the qubit receives about a millionth of the power sent from the room, together with the leftover noise. The result was about 0.003 thermal photons at the chip, close to the target. Putting all the attenuation at the 3 K plate would have left more than ten, because an attenuator cannot cool a signal below its own temperature: it replaces the photons it absorbs with photons of its own.
Filters complete the job. Absorbing filters block the infrared light that leaks down cables and breaks the electron pairs of the superconductor; a 2011 study by Martinis's group found that a second light-tight shield around the chip improved its circuits about tenfold. Magnetic shields protect components that steer the readout signal, and every gap that lets in warm light or stray fields shows up, as in 1985, as qubits that refuse to behave. A June 2026 preprint reported that better infrared shielding cut the rate at which stray energy disturbed its qubits by more than ten-thousandfold, leaving them at an effective temperature of about 17 millikelvin, measured from the qubits themselves.
A refrigerator's base temperature says little by itself. What reaches the qubits depends on how every line is attenuated, filtered and anchored at each stage, and a single badly anchored cable can warm the qubits it serves. Ask what the effective temperature of the qubits is, measured from their own excitation, not what the thermometer on the plate reads.
The wiring bottleneck
The cables also run out of room. In 2019 a 50-qubit processor needed 124 radio-frequency lines, and the ETH team estimated that their refrigerator's heat budget would allow about 150 qubits if three times as many lines could be fitted, which they could not. Space, not heat, was the binding limit. IBM reported in 2023 that its 1,121-qubit Condor processor used more than a mile of flat, dense cryogenic wiring inside a single refrigerator, a company figure. A year earlier it had shown Goldeneye, a concept refrigerator of 6.7 tonnes with about 1.7 cubic meters of cold space and room for six cooling units, which it described as a proof of concept rather than a production system.
One answer is to move the electronics into the cold. Ordinary control electronics use about a watt per qubit, by Google's 2019 estimate, far more than a 3 K plate can remove, so a controller placed in the cold must be hundreds of times more frugal; the chip Google showed that year ran at 3 K on less than 2 milliwatts. A 2026 preprint argues that the limit is now shifting to the 3 K stage itself, where each readout amplifier of the usual kind draws several milliwatts at its rated bias. One 2026 analysis of a machine large enough for RSA-2048, using Gidney's estimate of about 900,000 physical qubits and assuming about 10,000 qubits per refrigerator, arrived at roughly 90 refrigerators working together.
For a system design, count the lines each qubit needs for drive, readout and tuning, and multiply by the passive heat per line at each stage; add the heat of the pulses absorbed in the attenuators and of the amplifiers at 3 K. Compare each stage's total with its cooling power, with margin. The stage that runs out first, not the base temperature, sets how many qubits one refrigerator can hold.
- A dilution refrigerator cools a superconducting chip to about 10 millikelvin through a stack of plates at roughly 35 K, 3 K, 0.9 K and 0.1 K, with only about 20 to 90 microwatts of cooling at the bottom.
- At 5 GHz a qubit's surroundings hold about 16 thermal photons per mode at 4 K and about 4 in 10¹¹ at 10 millikelvin, which is why the cold is needed.
- Attenuators at several cold stages and absorbing filters remove the noise every cable brings down, leaving about 0.003 photons at the chip in one 2019 design; attenuation at a single warm stage cannot do it.
- Wiring space, heat at 3 K and amplifier power limit how many qubits one refrigerator holds, and one 2026 analysis puts an RSA-2048 machine at about 90 refrigerators.
The signal chain of one qubit.
+ The questionHow does a pulse made at room temperature become a gate, and a qubit's state become a bit?
Reading without touching
A transmon cannot be wired to anything that would carry its energy away, yet its state must be read in under a microsecond. The answer, proposed in 2004 by Alexandre Blais and colleagues and demonstrated in 2004 and 2005 by Robert Schoelkopf's group at Yale, is to read it indirectly. Each qubit is coupled to its own small microwave resonator, a circuit that rings at one frequency, and the resonator's frequency shifts slightly depending on whether the qubit holds 0 or 1. A weak microwave tone sent past the resonator comes back carrying that shift, and the qubit itself absorbs almost nothing. Because the tone is tuned to the resonator and not to the qubit, the reading leaves the qubit in the state it reports, as Chapter 2 requires of a measurement.
The method, called dispersive readout, turns the reading of a qubit into a problem every radio engineer knows: detecting a faint signal against noise. On Willow, the readout resonators sit near 4.5 GHz, below the qubits at about 6 GHz, and each tone lasts 250 to 480 nanoseconds. The signal that comes back is extremely faint, and everything after the chip exists to make it large enough to read before the qubit changes.
The chain, end to end
Seen as an instrument, a quantum computer runs the same chain as any measuring system: sense, condition, digitize, compute, connect and decide. For a qubit the chain runs in a loop, because what is decided in one cycle sets the pulses of the next.
| Step | What it does for a qubit | Typical parts |
|---|---|---|
| Sense | the resonator shifts its frequency with the qubit's state | on-chip resonator, about 4.5 GHz on Willow |
| Condition | the faint readout signal is amplified with little added noise, and the drive pulses are attenuated and filtered on the way down | parametric amplifier near 10 millikelvin, transistor amplifier at about 3 K, isolators, attenuators and filters |
| Digitize | fast converters sample the returning signal and generate the outgoing pulses | analog-to-digital and digital-to-analog converters at room temperature |
| Compute | each shot is reduced to a point and classified as 0 or 1, and the checks of the code are decoded | field-programmable gate arrays, workstations, custom chips |
| Connect | results move between control units and to the decoder fast enough to keep up | low-latency links |
| Decide | the next pulses are chosen, including any correction | the control system's sequencer |
Control-system makers sell the room-temperature part as instruments. Quantum Machines describes generating pulses directly from digital waveforms up to 10.5 GHz; Zurich Instruments quotes a feedback delay of 350 nanoseconds for a controller that drives and reads six qubits; Qblox sells racks of about 20 qubits each; and Keysight has installed a control system for more than 1,000 superconducting qubits in Japan. All are company figures, and they show how much ordinary instrument engineering a quantum computer contains.
Making a gate
A gate starts as numbers. Software computes the shape of a pulse, the converter turns it into a microwave waveform, and the waveform travels down the attenuated lines of Chapter 17. On Willow a single-qubit pulse lasts 25 nanoseconds. Its shape matters: a 2009 paper by Felix Motzoi, Jay Gambetta and colleagues showed that adding a second component, proportional to how fast the first is changing, keeps a short pulse from leaking the transmon into level 2, reducing the error by about an order of magnitude. Pulses of this kind, called DRAG pulses, are now standard. Two-qubit gates on Willow, controlled-Z gates between neighbors, take 42 nanoseconds.
Amplifying the answer
The returning readout signal is weaker than the noise any ordinary amplifier adds, so the first amplifier sits on the coldest plate and works near the limit quantum physics sets for added noise. Such parametric amplifiers use a pumped superconducting circuit to boost the signal; a 2015 design from MIT Lincoln Laboratory and Berkeley spread the amplification along a line and could read 20 qubits at once. A second amplifier, a cooled transistor of the kind used in radio astronomy, sits at about 3 K, and components that let signals pass in one direction only keep its noise from flowing back to the chip. Several qubits share each readout line and amplifier: their resonators are built at slightly different frequencies, so one burst containing several tones reads them all at once and the electronics separate the answers by frequency. Willow's paper describes a newer compact parametric amplifier design that replaced the type used on earlier Google chips.
At 4.5 GHz, the least noise a phase-preserving amplifier can add corresponds to a temperature of about 0.11 K, half a photon. A cooled transistor amplifier with a noise temperature of 1.5 K, a manufacturer's figure, adds about 7 photons. With the transistor first, total noise is about 7.5 photons; with a quantum-limited amplifier in front, about 1. For the same signal-to-noise ratio, the reading must last about 7.5 times longer without the parametric amplifier. Willow's 250 to 480 nanosecond readings would become about 1.9 to 3.6 microseconds, during which a qubit with a T1 of 68 microseconds decays 2.7 to 5.1 % of the time, against 0.37 to 0.70 % as built.
From a voltage to a bit
At room temperature, the amplified tone is sampled, and its phase and amplitude are reduced to a single point on a plane. Readings of qubits in 0 cluster in one cloud and readings of qubits in 1 in another, and a dividing line between the clouds turns each point into a bit. Errors come from the clouds overlapping, because of noise, and from qubits that decayed during the reading and landed between them. Small laboratory devices have pushed this far: a 2024 ETH Zurich study read with an error of 0.25 % in 100 nanoseconds, and a 2025 RIKEN study read four qubits at once in a little over 50 nanoseconds. Reading every qubit of a large chip at once, as error correction demands, is harder, which is why Willow's figure is 0.77 %.
The bits then go to the decoder of Chapter 15. In the real-time test reported in Willow's paper, run on a second, 72-qubit Willow processor, the decoder ran on a 64-core workstation linked to the control system over low-latency Ethernet and returned answers in about 63 microseconds. IBM reported in 2025 a decoder on a programmable logic chip that processed twelve cycles of check results for its own codes in about 480 nanoseconds, measured on recorded data rather than on a running machine. The decoder is the "compute" and "decide" of the chain, and its delay limits how fast a computation that needs corrected results can proceed.
A readout error quoted for one qubit read alone, on a small device, describes what the method can do, not what a processor achieves when all its qubits are read together and their tones crowd the same amplifier. Ask whether a figure was measured simultaneously across the chip, and with what reading time.
Keeping the chain calibrated
No two transmons are alike, as Chapter 2 noted, and their parameters drift as defects move. Every pulse must therefore be calibrated, and the calibrations depend on each other: a qubit's frequency must be known before its pulse can be tuned, and its pulse before a two-qubit gate. A 2018 Google paper organized calibration as a graph of such dependencies, each with its own time before it must be repeated, and gave as an example a pulse that must turn the arrow to within one ten-thousandth of a radian. A full calibration runs a chain of such experiments for every qubit, from finding its frequency and the strength of a pulse that flips it, to setting the dividing line between its readout clouds and tuning each two-qubit gate with each neighbor, and on a chip of a hundred qubits the graph grows large. Until recently, recalibrating meant stopping the computation.
In July 2026, Google reported the alternative: using the stream of check results from a running error-correction code as a signal for a learning program that adjusted more than 1,000 control settings while the code ran. Stability under drift improved 3.5-fold, and the distance-7 memory reached 7.72 errors in 10,000 cycles. The result moves calibration from a maintenance task into the control loop itself, which is where an instrument engineer would expect it.
For each qubit, list the parts from pulse generator to decoder with the gain, noise, delay and heat of each, as for any sensing system. Then check three budgets: noise at the first amplifier, which sets reading time; delay around the loop, which sets how fast corrections arrive; and heat at each cold stage, which sets how many chains fit in one refrigerator. Instrument engineering decides how many qubits work, not only how many exist.
- A transmon is read through a resonator whose frequency shifts with the qubit's state, so the reading becomes the detection of a faint microwave tone lasting 250 to 480 nanoseconds on Willow.
- The control and readout of a qubit follow the instrument chain of sense, condition, digitize, compute, connect and decide, run in a loop, and much of it is built from commercial instrument hardware.
- A quantum-limited amplifier at the coldest stage lets readings be about seven and a half times shorter than with a cooled transistor amplifier alone, which keeps decay during readout below 1 %.
- Calibration keeps every pulse matched to its drifting qubit, and in 2026 Google moved it into the running computation, adjusting over 1,000 settings while the code ran.
Ions, atoms, photons and spins.
+ The questionTrapped ions, neutral atoms, photons and spins are all qubits. Do they hit the same limits?
The same definition, different instruments
Any two-level system that can be prepared, turned, entangled and read can serve as a qubit, and the main alternatives to superconducting circuits meet that definition with different physics and therefore different instruments. Each trades the same quantities against each other: how accurately gates work, how fast they run, how long qubits hold their state, which qubits can interact, and how many can be built and controlled together. Through 2025 and 2026 the accuracy of the best two-qubit gates converged across the leading approaches, so the comparison now turns on speed, losses and scale.
Trapped ions
A trapped-ion machine holds charged atoms in a vacuum above a chip, suspended by electric fields from electrodes on its surface, and drives them with lasers or microwaves. Every ion of a species is identical, so qubits need no individual tuning of the kind transmons do, and they hold their state for a long time: a 2021 laboratory record kept one ytterbium ion's phase for an estimated 5,500 seconds. Ions can also be moved, so that any qubit can be brought next to any other for a gate, which gives the machine full connectivity.
Quantinuum's Helios, announced in November 2025 and described in Nature in June 2026 by the company's staff, holds 98 barium-137 ions. Its two-qubit gates err about 8 times in 10,000, about 99.92 % fidelity, its single-qubit gates about 2.5 times in 100,000, and preparation with readout about 5 times in 10,000. A two-qubit gate takes about 70 microseconds, and because ions must be moved, cooled and gated in turn, an average layer of operations across the machine takes about 55 milliseconds. In October 2025 a team at Oxford Ionics, by then part of IonQ, reported two-qubit gates above 99.99 % on one pair of ions, controlled electronically rather than with lasers, each lasting about 226 microseconds. In September 2026 IonQ announced a 256-qubit system built on that method, with deliveries planned for 2027, a company claim with no published fidelities for the full machine.
Neutral atoms
A neutral-atom machine holds uncharged atoms in tightly focused laser beams called optical tweezers, arranged in arrays that can be rearranged by moving the beams. Atoms interact when one is excited to a very large, high-energy state, a Rydberg state, in which its outer electron orbits far from the nucleus. Arrays have grown fast. A Caltech team reported in 2025 an array of over 6,100 atoms that kept their phase for 12.6 seconds, though without two-qubit gates, and a Harvard and MIT team kept more than 3,000 atoms running for over two hours by reloading 300,000 atoms a second as others were lost.
Gate accuracy followed. A 2023 Harvard experiment reached 99.5 % for two-qubit gates on 60 atoms in parallel, and an April 2026 preprint from the same group reported 99.854 %, close to the best superconducting chips. The limits lie elsewhere: atoms are lost from their traps, and moving them takes milliseconds, so a cycle of error correction on atoms is far slower than on a superconducting chip. A June 2026 preprint trapped 11,000 atoms with a single patterned optical element, a scale figure for trapping, not for computing.
Photons
Photons hold their state almost indefinitely, because they barely interact with anything, and for the same reason they are hard to make interact with each other. Photonic machines therefore build entanglement through carefully timed measurements on pairs of photons, an approach PsiQuantum calls fusion-based computation, and their dominant error is not decoherence but loss: a photon that never arrives. PsiQuantum's 2025 Nature paper, by its staff, reported qubit preparation and measurement at 99.98 % and fusion operations at 99.22 % on chips made in a commercial 300-millimeter foundry, figures that do not count lost photons. Its 2023 design analysis tolerated about a 10 % chance of loss in each fusion.
Xanadu's Aurora, described in Nature in January 2025 by the company's staff, linked 35 chips in a modular photonic machine but lost more than 95 % of photons along some of its optical paths, against a budget of about 1 % for fault tolerance; its authors called it a scale model that does not yet perform. Photon loss is the single number that decides whether the photonic route reaches error correction.
Spins in silicon
A spin qubit is a single electron held in a quantum dot, a region tens of nanometers across defined by electrodes on a silicon chip, with 0 and 1 its spin pointing with or against a magnetic field. The approach borrows the manufacturing of the chip industry. Intel's 12-dot Tunnel Falls chip of 2023 was made on 300-millimeter wafers, and in a 2025 Nature paper, a team including Diraq and imec staff reported four devices made in an industrial foundry with every operation above 99 %; in the team's preprint, two-qubit gates took about 212 nanoseconds. Their main remaining error came from traces of silicon-29, whose nuclei disturb the electron. Like transmons, spin qubits run in dilution refrigerators. A related 2025 paper ran a control chip of about 100,000 transistors at millikelvin temperatures beside spin qubits and degraded their single-qubit fidelity by only 0.07 %.
Topological qubits and annealers
Microsoft has pursued topological qubits, which would store information in exotic states of special superconducting wires and resist errors by their nature. In February 2025 it announced Majorana 1, a chip it described as holding eight topological qubits, with a companion Nature paper on a measurement in such a device. According to an APS report, the paper's peer-review file stated that "the results in this manuscript do not represent evidence for the presence of Majorana zero modes." In June 2026 the company reported a second device, Majorana 2, with a parity lifetime of about 20 seconds, in a preprint, and Nature published a critique by Henry Legg of the University of St Andrews arguing that the 2025 signals could arise from ordinary mechanisms, together with Microsoft's reply standing by its results. No two-qubit gate on such qubits had been reported as of October 2026.
D-Wave's machines are of a different kind, quantum annealers that settle a large network of qubits toward a low-energy state rather than running sequences of gates; its Advantage2, released in May 2025, has more than 4,400 qubits by the company's count. Chapter 11 described the debate over its 2025 claim.
A billion cycles of error correction on Willow, at 1.1 microseconds each, take about 1,100 seconds, some 18 minutes. A billion layers of operations on Helios, at 55 milliseconds each, take 5.5 × 10⁷ seconds, about 1.7 years. The ions' gates are more accurate, and their connectivity can make codes more efficient, but the factor of 50,000 in clock time does not disappear. Fewer, better operations can close part of the gap; the rest becomes run time. Neutral atoms sit between the two: their gates take about a quarter of a microsecond, but moving atoms between cycles takes milliseconds.
Two-qubit fidelities near 99.9 % now appear on superconducting, ion and atom machines, so fidelity alone no longer ranks them. Ask how long one cycle of error correction takes on each, including movement, cooling and readout, and multiply by the cycles a useful computation needs. Ask also what is lost per cycle: atoms from traps, photons from paths.
For any platform, request the duration of one full cycle of the error-correcting code intended for it, the logical error per cycle achieved, and the qubits per logical qubit at that error. Those three numbers, not the physical qubit count or the best gate fidelity, convert into the run time and machine size of Chapter 22's bill.
- Trapped ions are identical by nature, hold their state for very long times and can be moved to connect any pair, but Helios's layers of operations take about 55 milliseconds.
- Neutral atoms scale to arrays of thousands and reached 99.85 % two-qubit gates in 2026, with atom loss and slow movement as their limits.
- Photonic machines hold qubits easily but lose photons, with Aurora losing over 95 % on some paths against a 1 % budget, and spin qubits borrow chip manufacturing, with foundry devices above 99 % in 2025.
- Topological qubits remain disputed and annealers are not gate-model machines, and across platforms the clock time of an error-correction cycle now separates machines more than gate fidelity does.
+ Part VII · The field in 2026
Who builds the machines, and what the latest results show.
On 4 May 2016, IBM put a five-qubit processor, housed at its research center in Yorktown Heights, New York, on the internet for anyone to program, and forecast processors of 50 to 100 qubits within a decade. Ten years later to the day, every machine on its cloud had more than 100 qubits by the company's count, and its Heron r3 processors had 156, with a median two-qubit error of about 12 in 10,000. Part VII steps back from the single machine to the field that builds them. Chapter 20 maps the companies by the layer of the machine they make and the kind of qubit they use, and Chapter 21 tables what changed in 2025 and 2026, measured with the yardsticks of the earlier chapters.
Companies, by layer and by qubit.
+ The questionWho is building quantum computers, and which part of the machine does each company make?
A roster drawn up by a tester
In April 2025, the US Defense Advanced Research Projects Agency, DARPA, began naming the companies whose designs its Quantum Benchmarking Initiative would examine, with one question in mind: could any of them build, by 2033, a quantum computer whose computational value exceeds its cost? By the end of the year the first stage held 18 companies. Between them they covered most of the qubits of Chapter 19: superconducting circuits from IBM, Google, Rigetti, Alice & Bob and others, ions from Quantinuum, IonQ and Oxford Ionics, atoms from QuEra and Atom Computing, photons from Xanadu, and spins in silicon from Diraq, Quantum Motion and Silicon Quantum Computing.
Two more, Microsoft with its topological qubits and PsiQuantum with photons, had come through an earlier DARPA program and were placed directly in the final stage. In November 2025 eleven companies moved to the second stage, a year of closer review with up to 15 million dollars each; Google and Rigetti were not among them. In March 2026 the program's manager, Micah Stoutimore, said that "it now seems likely that someone will build a utility-scale quantum computer by 2033." The roster is useful because an agency that tests claims drew it up, not the companies making them, and it is the frame for the rest of this chapter.
The layers of a machine
Chapter 18 followed one qubit's signal chain from pulse to decision, and the industry divides along the same lines. Few companies make every layer. Most make one, and the processor makers buy much of the rest.
| Layer | What it supplies | Examples |
|---|---|---|
| Qubits and processor | chips, ion traps, atom arrays or photonic circuits | IBM, Google, Quantinuum, IonQ, QuEra, PsiQuantum and the others in this chapter |
| Cryogenics | dilution refrigerators and their wiring | Bluefors; Quantum Design Oxford, formerly Oxford Instruments NanoScience |
| Control electronics | pulse generation, readout and fast feedback | Quantum Machines, Qblox, Zurich Instruments, Keysight |
| Error correction and software | real-time decoders, error suppression, compilers | Riverlane, Q-CTRL; IBM and Google build their own decoders |
| Access | cloud services that run users' programs | IBM Quantum; Amazon Braket, which hosts other companies' machines |
The suppliers' own figures show the scale they are preparing for. Bluefors describes its KIDE platform as supporting more than 1,000 qubits, with over 4,000 radio-frequency lines and three separate cooling units, and Keysight describes control systems for about 1,000 qubits. Ownership is moving as well. Oxford Instruments sold its quantum business to Quantum Design for 60 million pounds, a deal announced in June 2025 and completed by early January 2026. Two of the largest deals of 2026 pulled layers inside processor makers: IBM bought HRL Laboratories from Boeing and General Motors for its work on spin qubits, cryogenics and control electronics, and IonQ bought the chip foundry SkyWater for about 1.8 billion dollars, completing the purchase on 31 July 2026.
Superconducting circuits
IBM's Heron r3 chips hold 156 qubits with a median two-qubit error of 1.17 in 1,000, by the company's figures. Its Nighthawk chips, 120 qubits joined by 218 tunable couplers, reached a second revision on 31 August 2026 that IBM says runs circuits of more than 7,500 gates accurately. In 2025 it showed Loon, an experimental chip with the long-range couplers that the codes of Chapter 16 need, and in August 2026 it joined two refrigerator modules into one system cooled below 15 millikelvin. IBM's roadmap, a company plan, puts a first module with logical qubits, Kookaburra, in 2026; it had not been announced as delivered by early October. After it come Starling in 2029, with 200 logical qubits running 100 million operations, and Blue Jay, listed for 2033 or later, with 2,000 logical qubits and a billion operations.
Google Quantum AI has announced no successor to the 105-qubit Willow, and its published roadmap still shows its third milestone, a logical qubit that errs about once in a million steps, as unreached. In March 2026 it added a second hardware program, neutral atoms, at a laboratory in Boulder, Colorado, led by the physicist Adam Kaufman, noting that atoms reach arrays of about ten thousand qubits while superconducting chips run microsecond cycles. Rigetti made its 108-qubit Cepheus system, built from twelve chiplets of nine qubits, generally available in April 2026 with a median two-qubit fidelity of 99.1 % by the company's figures. Amazon's Ocelot and the French company Alice & Bob pursue cat qubits; Alice & Bob made its first system, Helium, available to research partners in June 2026, planning 18 cat qubits for its first logical qubit.
Elsewhere, IQM in Finland plans systems of 150 qubits for error-correction research by the end of 2026. Fujitsu and RIKEN built a 256-qubit machine in Japan in April 2025; the next, of about 1,000 qubits, is scheduled for the fiscal year ending March 2027 and had not been installed by the end of September 2026, according to Fujitsu's own pages. In China, the University of Science and Technology of China's Zuchongzhi 3.0 set the sampling record of Chapter 11, and a later version ran a distance-7 surface code with a Λ of 1.40. Two larger Chinese chips come with fewer published numbers: China Telecom's 504-qubit Tianyan-504 of December 2024, and Origin Quantum's Wukong-180 of May 2026, whose fidelities appear only in reports quoting the company.
IBM's Condor of 2023 held 1,121 qubits on one chip, yet the main processors IBM has offered since then have had between 120 and 156. A count says how much was built, not how well it works. Before comparing machines by count, ask for the two-qubit error measured across the whole chip, how many qubits run at once, and the cycle time of Chapter 19.
Ions, atoms, photons and spins
Quantinuum built Helios, described in Chapter 19, and listed its shares on Nasdaq on 4 June 2026, raising 1.68 billion dollars. Its roadmap, filed with the US Securities and Exchange Commission, puts about 100 logical qubits in a machine called Sol in 2027 and hundreds in Apollo in 2029, a year earlier than its 2024 plan. IonQ has grown by acquisition. Between May 2025 and July 2026 its completed purchases included a controlling stake in ID Quantique, maker of quantum communication equipment, the interconnect company Lightsynq, Oxford Ionics for 1.075 billion dollars, the satellite-radar company Capella Space, the sensor maker Vector Atomic and SkyWater. Its Superion 256, announced in September 2026 for delivery in 2027, uses the electronic control Oxford Ionics developed, and its roadmap reaches 80,000 logical qubits in 2030.
Neutral atoms moved from laboratories to products. QuEra, which builds machines with the Harvard and MIT team of Chapter 19, plans a fault-tolerant machine called Libra for Amazon's cloud in 2028, with more than 256 logical qubits erring once in a million operations. Atom Computing announced more than 300 million dollars of funding in June 2026 and is building, with Microsoft, a machine called Magne for Denmark's QuNorth, with 50 logical qubits from 1,225 atoms, due around the start of 2027. Pasqal in France reported seven machines in operation and filed in June 2026 to list on Nasdaq. Infleqtion, listed on the New York Stock Exchange since February 2026, reported 30 logical qubits in September 2026 in a distance-2 code that detects errors and discards the affected runs, the bottom rung of Chapter 16.
PsiQuantum raised 1 billion dollars at a valuation of 7 billion in September 2025 and broke ground on two sites for full-scale photonic machines, in Chicago that month and at Moreton Bay in Queensland, Australia, in June 2026; neither has a published date for a working machine. Xanadu listed on Nasdaq and the Toronto Stock Exchange in March 2026. Spin qubits are pursued by Diraq, Quantum Motion and Silicon Quantum Computing, all three in DARPA's second stage, and now by IBM through HRL. Microsoft, the disputed case of Chapter 19, has set 2029 as its target for a scalable machine, and D-Wave, maker of annealers, added gate-model qubits in 2026 by buying Quantum Circuits, in a deal of about 550 million dollars in cash and shares completed in January 2026.
India
India's National Quantum Mission, approved by the Union Cabinet in April 2023, has ₹6,003.65 crore for the eight years to 2030–31 and aims at machines of 50 to 1,000 physical qubits by the end of that period. Four hubs set up in 2024–25 lead its themes, with computing at the Indian Institute of Science in Bengaluru and communication, sensing and materials at the Indian Institutes of Technology in Madras, Bombay and Delhi. By February 2026 the government had sanctioned ₹2,330.68 crore and released ₹699.50 crore, about 12 % of the total, and by August it counted 17 supported start-ups.
The machines so far come from one of those start-ups, QpiAI of Bengaluru. Its 25-qubit QpiAI-Indus was launched under the mission on 14 April 2025 and its 64-qubit Kaveri chip unveiled in November 2025, with no gate fidelities published for either. In March 2026 the company reported a hardware decoder for a distance-5 surface code on Kaveri with an end-to-end delay of 1.5 microseconds per cycle. Imported machines are planned too. IBM, with Tata Consultancy Services and the Andhra Pradesh government, set out to commission a 156-qubit System Two in Amaravati by September 2026, with no installation announced by early October, and Rigetti lists a 108-qubit system program with C-DAC, the government's advanced computing agency.
Gidney's 2025 design for RSA-2048 needs about 1,400 logical qubits at its peak and 6.5 billion Toffoli gates. IBM's Starling, planned for 2029, offers 200 logical qubits and 100 million operations: 7 times too few qubits and 65 times too few operations. Blue Jay, listed for 2033 or later, offers 2,000 logical qubits, enough, and a billion operations, still 6.5 times short, and a Toffoli costs more than a typical operation. QuEra's Libra, at about a million operations, is some 6,500 times short. IonQ's 2030 target of 80,000 logical qubits from 2 million physical implies 25 physical qubits for each logical one, against about 640 in Gidney's design, so it depends on codes not yet shown at that scale.
For a company in the news, identify which layer it builds and which qubit it uses. Check whether its figures were measured on a full machine or a test device, and whether they appear in a peer-reviewed paper, a preprint or a press release. Then convert any roadmap into logical qubits, logical error per operation and operations sustained, and compare them with the bill of Chapter 22.
- DARPA's Quantum Benchmarking Initiative has examined about 20 companies across every major kind of qubit, with the test of whether any can build, by 2033, a machine whose computational value exceeds its cost.
- A quantum computer is built in layers, processor, cryogenics, control electronics, error-correction software and cloud access, and most companies make one layer while processor makers buy, or now acquire, the rest.
- IBM, Google, Quantinuum, IonQ, QuEra, Atom Computing, PsiQuantum and others publish roadmaps toward hundreds or thousands of logical qubits between 2027 and 2033, all company plans.
- India's National Quantum Mission funds hubs and 17 start-ups toward 50 to 1,000 physical qubits by 2031, with QpiAI's 25- and 64-qubit machines the first results.
What changed in 2025 and 2026.
+ The questionWhich results of 2025 and 2026 moved the field, measured by the yardsticks this guide has built?
Three yardsticks, not one headline
A two-qubit gate that fails about 8 times in 100,000, a protected memory that fails about 46 times in a million cycles, and a quantum computation matched by graphics processors in 37 minutes: the results of 2025 and 2026 moved in different directions at once. A scorecard kept by company would hide that, because each company reports the figures that flatter its own machine. This chapter keeps it by metric instead, using the yardsticks of the earlier chapters: the error of a physical two-qubit gate, the error of a protected qubit and the slope Λ behind it, and claims of advantage together with the classical replies they drew. Each figure is labeled by where it was measured and in what kind of source, since a pair of qubits in a laboratory and the median of a whole chip are different measurements.
Physical gates
The plate below lists the best two-qubit gates of the period, from lowest error to highest, each labeled with what it was measured on and the kind of source that reported it. The first was measured on a single pair of ions; the rest are averages or medians across many qubits.
Two patterns stand out. Ions and superconducting chips ran gates below 0.2 % across whole machines, and a laboratory array of atoms matched them, so the kind of qubit no longer decides who has the best gates, as Chapter 19 argued. And the best single pair beat the best whole machine by about a factor of ten, the usual distance between what a method can do and what a processor achieves when every qubit runs at once.
The table also leaves out two things that matter as much. One is speed: Helios's gates take about 70 microseconds and Willow's 42 nanoseconds, a factor of more than a thousand that Chapter 19 turned into run time. The other is the kind of average. Companies quote medians or means over pairs of qubits, and some quote an error averaged over all inputs while others quote the Pauli error, which for a two-qubit gate is five fourths as large, as Chapter 4 showed for Willow's 0.33 % and 0.41 %. Two figures that differ by a fifth may describe the same gate.
At an error of 1 in 1,000 per gate, the chance that a run of N gates has no error is 0.999 raised to the power N, which falls to one half at N = 693. At 1 in 10,000 it falls to one half at N = 6,931, and at the Oxford Ionics figure of 8.4 in 100,000, at about 8,250. A fourth nine therefore buys ten times longer circuits without error correction. Inside a surface code it buys more: Λ is roughly the threshold divided by the physical error (Chapter 15), so a tenfold lower error raises Λ about tenfold, and every protected qubit shrinks.
Protected qubits
Error correction produced the year's most important results and its most confusing headlines. The table sorts them by the rungs of Chapter 16, from memories corrected every cycle to codes that only detect errors and discard the runs that show them.
| Result | Code and scale | Figure | Rung |
|---|---|---|---|
| Google Willow, Dec 2024 | surface code, distance 7, 101 qubits | 0.143 % per cycle; Λ = 2.14 | corrected every cycle |
| Google Willow, learned calibration, 2026 | same code, on a Willow processor | 0.077 % per cycle | corrected every cycle |
| Zuchongzhi 3.2, Dec 2025 | surface code, distance 7 | Λ = 1.40 | corrected every cycle |
| Quantinuum Helios, Sep 2026 | distance-6 code, 2 logical qubits in 20 ions | 0.0046 % per cycle | corrected, preprint |
| Harvard, MIT and QuEra, Nov 2025 | surface code at distances 3 and 5, four rounds, on an array of up to 448 atoms | 0.62 % per round at distance 5 | corrected for a few rounds |
| Atom Computing, Jun 2026 | toric code at two sizes, up to 90 cycles | the larger code erred less over short runs | corrected, preprint |
| IBM and University of Chicago, Jul 2026 | 70 encoded qubits on 97 | errors ten times below physical, after discarding runs | detected |
| Infleqtion, Sep 2026 | 30 logical qubits on 80 atoms, distance 2 | no logical error rate published | detected |
The leader on the top rung, judged by code distance and by errors shown to fall as the code grows, is still Google's distance-7 memory, which reached 7.7 errors in 10,000 cycles in 2026 with learned calibration. Google's own roadmap sets its next milestone at one error in a million, about 770 times lower. Quantinuum's distance-6 code reached 4.6 in 100,000 per cycle, the lowest per-cycle logical error found for this guide, but for two logical qubits in a small code and, like Google's memory, without the T gates of Chapter 4. Neither is within many orders of magnitude of the 1 in 10¹⁵ of Chapter 13.
What moved the top rung was mostly control and design rather than new kinds of chip. Google's 2026 result came on a Willow processor tuned by a learning program that adjusted more than 1,000 settings, which the team credits with about 20 % lower logical error than expert calibration alone, and the Chinese team's result rested on removing leakage, the escape to level 2 of Chapter 12, with microwave pulses alone. The Harvard team's decoders used the knowledge of which atoms had been lost, and Quantinuum's compact code packed two protected qubits into 20 ions. Each gain came from treating the machine as a whole system, the instrument view of Part VI.
Logical errors are quoted per cycle, per round, per operation or per logical qubit, for codes of different distances, decoded in real time or afterward, with or without discarded runs. A figure from one row of the table above cannot be set against another until all of these are converted. A count of logical qubits from the lower rungs says nothing about the slope Λ.
Λ is the ratio of the logical errors at two distances two steps apart, so it says how fast a code improves as it grows. A thousandfold cut needs enough steps for Λ, multiplied by itself once per step, to reach 1,000: at 2.14 that takes ten steps, since nine give only about 940, and at 1.40 it takes twenty-one. Starting from distance 7, Willow's slope reaches the thousandfold cut at distance 27, a patch of 1,457 qubits. Zuchongzhi 3.2's slope needs distance 49, a patch of 4,801 qubits, more than three times as many for the same protection.
Scale, advantage and the classical side
Arrays of qubits grew faster than machines that compute with them. A Caltech team held more than 6,100 atoms in 2025, with long coherence but no two-qubit gates, and a June 2026 preprint trapped 11,000 atoms loaded at random. IBM's largest chip remains the 1,121-qubit Condor of 2023, and D-Wave's annealer counts more than 4,400 qubits of a different kind. The claims of advantage that Chapter 11 examined moved toward results that can be checked: certified randomness in March 2025, Google's Quantum Echoes in October 2025, and IBM's three claims of 30 July 2026, one of them backed by a certified bound on its fidelity.
The classical side answered quickly. About two weeks after IBM's claim, a preprint by a team at the Singapore University of Technology and Design and NVIDIA reported simulating the 70-qubit circuit on 256 graphics processors in 37.3 minutes, against about 15 minutes on the quantum machine. In September 2026 the classical factoring record moved twice in sixteen days, RSA-260 and then RSA-896, both on graphics processors running sieve software rewritten with AI coding tools, as Chapter 1 described. Neither record brings RSA-2048 within reach of classical machines, which would need tens of billions of times more work, but both show that the classical baseline in every comparison keeps moving.
Estimates, programs and honors
The estimates of what useful machines need also changed. In February and March 2026, three teams published designs that cut the qubits needed to break public-key cryptography by reorganizing the machine: Iceberg Quantum with codes that need long-range links, a team from Oratomic, Caltech and Berkeley with reconfigurable neutral atoms, and a Google-led team for the elliptic-curve systems used in cryptocurrencies. Chapter 22 sets them against the bill. Governments added public tests to their funding. The US Department of Energy announced its Quantum Genesis initiative in June 2026 and in September opened a competition for machines with at least 100 logical qubits able to run hundreds of millions of fault-tolerant operations, with applications due on 19 October 2026.
The field's foundations were honored in the same period. The 2025 Nobel Prize in Physics, announced on 7 October 2025, went to John Clarke, Michel Devoret and John Martinis for the 1985 Berkeley experiments of Chapter 17, which showed a whole circuit behaving like an atom. In March 2026 the 2025 A.M. Turing Award went to Charles Bennett of IBM and Gilles Brassard of the University of Montreal, whose work from the 1970s to the 1990s established much of quantum information science, including quantum teleportation.
For each new result, record the metric, the value, the scale at which it was measured, from one pair of qubits to a whole chip or one protected qubit, the date and the kind of source. Compare it only with entries on the same row. Update the classical baseline beside every claim of advantage, and add a result to the protected-qubit rows only once its rung is clear.
- Two-qubit gates below 0.2 % now run across whole machines of ions and superconducting circuits, and on a laboratory array of atoms, and the best pair of ions reached 8.4 errors in 100,000, about ten times better than any whole machine.
- On the top rung of error correction, Google's distance-7 memory reached 7.7 errors in 10,000 cycles and a Chinese team reached Λ = 1.40, while many larger logical-qubit counts came from codes that only detect errors.
- Claims of advantage moved toward results that can be checked, and classical replies kept pace: IBM's July 2026 circuit was reproduced on graphics processors within two weeks, and the classical factoring record moved twice in September 2026.
- New 2026 designs cut the qubits needed to break public-key cryptography, the US Department of Energy set a public test of 100 logical qubits, and the Nobel and Turing prizes honored the field's foundations.
+ Part VIII · The bill
What one reliable answer costs.
Fewer than a million noisy qubits, running for less than a week: in May 2025 that was Craig Gidney's price for factoring RSA-2048 on a machine whose qubits err about once in a thousand operations. Part VIII sets that price beside every earlier estimate and beside the machines and roadmaps of 2026, and with them answers the central question. Its single chapter adds up the bill, says what to watch, and closes the guide where it began, with Shor's weekend in April 1994.
What one reliable answer costs.
+ The questionWhat would it take to factor RSA-2048, and how far are the machines of 2026 from it?
Six estimates of one machine
In August 2012, Austin Fowler, Matteo Mariantoni, John Martinis and Andrew Cleland put a number on the machine Shor's algorithm would need for a 2,000-bit number: about a billion physical qubits, running for about a day. Earlier counts had been of perfect qubits. A 2003 circuit by Stéphane Beauregard, described in Chapter 8, needs only 4,099 of them for RSA-2048, a figure still quoted as if it were the size of a real machine. The 2012 estimate, an early and influential one, priced in the surface code of Chapter 15, and most of its billion qubits went into factories for the magic states of Chapter 16. Every estimate since has reworked that design, and the table lists the main ones with what each assumes.
| Year | Estimate | Physical qubits | Run time | Main assumptions |
|---|---|---|---|---|
| 2003 | Beauregard | 4,099, all perfect | not estimated | no errors at all |
| 2012 | Fowler and colleagues | about 1 billion | about 27 hours | surface code; physical error about a tenth of threshold (0.06 to 0.1 %); 100 ns cycle |
| 2019 | Gidney and Ekerå | 20 million | 8 hours | surface code on a grid of neighbors; 0.1 %; 1 µs cycle; 10 µs reaction |
| 2025 | Gidney | 897,864 | about 5 days | the same as 2019 |
| 2026 | Iceberg Quantum | about 94,000, or 381,000 | about a month, or one day | the same errors and cycle; codes needing long-range links |
| 2026 | Cain and colleagues | about 102,000 atoms | about 97 days | movable atoms; 0.1 %; 1 ms cycle |
From 2019 to 2025 the hardware assumptions did not change; the savings came from method. Gidney's 2025 design computes with approximate arithmetic, which tolerates small errors in intermediate results, stores idle qubits in the yoked patches of Chapter 16, and grows magic states by cultivation instead of distilling them. It uses about 1,400 logical qubits at its peak and about 6.5 billion Toffoli gates, and a factorization combines about nine runs of roughly half a day each, as the method's classical post-processing requires. The two 2026 designs change the machine instead. Iceberg Quantum's needs links between distant qubits within each processing block, which no superconducting chip yet offers at scale, and the design by Cain and colleagues at Oratomic, Caltech and Berkeley moves atoms to make those links, paying with a clock a thousand times slower. The discrete logarithm of Chapter 7 came out cheaper still. A Google-led estimate of March 2026 for the 256-bit elliptic-curve keys used by cryptocurrencies needs at most about 1,450 logical qubits and 90 million Toffoli gates, about an eighth of the Toffoli gates in one run of Gidney's RSA-2048 design, on fewer than half a million physical qubits running for under half an hour.
An estimate's headline number depends on the physical error rate, the cycle time, which qubits can interact and how quickly corrections arrive. A smaller count from a design that assumes long-range links or slower cycles is a different machine, not a cheaper version of the same one, and a count of perfect qubits describes no machine at all.
Qubits fell, qubit-hours barely moved
The physical qubit count dropped a thousandfold between 2012 and 2025. The run time rose over the same years, from about a day to about five, partly because later designs assume a cycle ten times slower than the 2012 one, and partly because fewer factories feed the arithmetic, so each Toffoli gate waits longer for its ingredients. Multiplying the two gives the quantity that tracks the real work, qubit-hours: how many qubits must be kept protected, and for how long.
In 2012: a billion qubits for 26.7 hours, about 2.7 × 10¹⁰ qubit-hours, at a cycle ten times faster than later designs assumed. In 2019: 20 million qubits for 8 hours, 1.6 × 10⁸. In 2025: 897,864 qubits for 119 hours, about 1.1 × 10⁸, only about one and a half times less than 2019 although the qubits fell twenty-two-fold. The 2026 atom design, 102,000 qubits for 97 days, comes to about 2.4 × 10⁸. Only the design that assumes long-range links moves the figure: 94,000 qubits for a month is about 6.8 × 10⁷, and 381,000 for a day about 9.1 × 10⁶.
On the hardware assumed since 2019, a grid of neighbors erring once in a thousand operations with a microsecond cycle, the bill for RSA-2048 has stayed near 10⁸ qubit-hours for seven years. What changed was how it is paid: in qubits, which are hard to build, or in time, which an operator can usually wait out. The only route to a much smaller bill so far is a different machine, with longer-range links or better physical qubits, and both are still to be shown at scale.
The chemistry bill
The same accounting applies to the other problem this guide found worth the cost. In 2021 a Google-led team priced the FeMoco model of Chapter 10 at about 2,100 logical qubits and 5.3 billion Toffoli gates, running on about four million physical qubits for under four days, with the same 0.1 % error and microsecond cycle as Gidney; with physical errors ten times lower, about a million qubits for under two days. That is the same order as RSA-2048 on every axis, up to about 4 × 10⁸ qubit-hours. Methods have since cut the gate count for the larger model about thirty-twofold, and in 2025 the same group, on the same hardware assumptions, priced that model at about 4.5 million physical qubits for 8.6 hours: about 4 × 10⁷ qubit-hours, a tenth of the 2021 bill for the smaller model. But in January 2026 classical methods reached chemical accuracy for the larger model's lowest energy, as Chapter 10 described. The chemistry case for a first machine therefore rests on harder questions than one ground-state energy, such as how a reaction proceeds step by step.
Against the machines of 2026
The table compares the bill for RSA-2048 with the best results reported by October 2026.
| Quantity | What the bill needs | Best shown by October 2026 | Gap |
|---|---|---|---|
| Protected qubits | about 1,400 | 1 at distance 7 with errors shown to fall as the code grows (Willow); 2 in a distance-6 code (Quantinuum) | about 700 to 1,400 |
| Error per protected qubit per cycle | 1 in 10¹⁵ | 7.7 in 10,000 (Willow, distance 7); 4.6 in 100,000 (Quantinuum, distance 6, two logical qubits) | 10¹¹ to 10¹² |
| Physical qubits at 0.1 % error | about 900,000 | 156 on IBM's cloud; 105 on Willow; 98 on Helios | about 6,000 |
| Continuous correction | about 5 days, decoded in real time | about one second, a million cycles, in a 2024 Google experiment | about 400,000 in duration |
The roadmaps of Chapter 20 close parts of the gap on paper. IBM's Starling in 2029 would have 200 logical qubits and 100 million operations. Quantinuum's Apollo, also for 2029, would have hundreds of logical qubits and about 10 billion operations before an error. That matches the bill's Toffoli count only if one operation could stand for one Toffoli, which it cannot, and it would run on ions whose layers of operations take milliseconds, so it would need a design built around that slower clock, as Cain's group drew one for atoms. IonQ's plan goes furthest, with 1,600 logical qubits in 2028 and 80,000 erring less than once in 10¹² operations by 2030, at 25 physical qubits for each, a ratio not yet shown for codes of that strength. All three are company plans, to be read as Chapter 20's solved example reads them.
What to watch
The dates that will show whether those plans hold are public. The US Department of Energy's Quantum Genesis Q Competition, with applications due on 19 October 2026, asks for machines in 2028 with at least 100 logical qubits running hundreds of millions of fault-tolerant operations, with bonus pools at 150 and 200. DARPA's second-stage reviews of eleven companies run into late 2026 against its 2033 test. IBM's Kookaburra, due in 2026, would be its first module with logical qubits; Quantinuum's Sol, due in 2027, about 100 logical qubits; QuEra's Libra, due in 2028, more than 256 at one error in a million operations. Google's next milestone, a logical qubit erring once in a million cycles, is still open.
Four measurements will say more than any date. The first is a slope Λ above 2 sustained to distance 9 or beyond. The second is a logical error per operation for the T and Toffoli gates that algorithms need, not only for memory. The third is real-time decoding across many logical qubits at once, and the fourth a logical algorithm corrected throughout that ordinary computers cannot simulate. Cryptographers have not waited for any of these: new public-key methods designed to resist quantum attack already exist, and moving to them is a subject outside this guide.
For a resource estimate, write down the physical qubits, the run time, the physical error rate, the cycle time, the connectivity and the reaction time it assumes, and multiply qubits by hours. Compare two estimates only when their assumptions match. Set an estimate against a machine only once that machine has shown the error rate, cycle and connectivity the estimate takes for granted.
The rumor and the bill
In April 1994 Shor's result traveled from a seminar room to a telephone in a few days, and by the time the rumor arrived it was true. The machine it implied has taken longer, and in 2026 its price can be stated. One reliable answer to RSA-2048, on the best published design for the hardware assumed since 2019, costs about a million physical qubits, each erring no more than once in a thousand operations, which on superconducting hardware means chips held near 10 millikelvin, checked every microsecond for about five days, with a classical decoder keeping pace throughout. Designs that assume longer-range links or movable atoms need about a tenth of the qubits and pay in connectivity not yet built or in months of running.
That price is worth paying only for problems with hidden structure that ordinary computers cannot exploit: factoring and discrete logarithms, whose answers can be checked at once, and the simulation of molecules and materials whose electrons resist classical methods, each benchmark rechecked as classical methods improve. For unstructured search, sorting and most problems dominated by data, it does not pay for itself. As of October 2026 Google's best protected memory errs about 8 times in 10,000 cycles, and the largest RSA challenge number factored has 270 digits, factored by ordinary computers. The rumor ran ahead of the proof by days; the machine has run behind it for thirty-two years, and the distance is now a bill that can be itemized line by line.
- Estimates for factoring RSA-2048 fell from about a billion physical qubits in 2012 to 897,864 in 2025 and about 100,000 in 2026 designs that assume long-range links or movable atoms, each with different assumptions about the hardware.
- Measured in qubit-hours, the bill on the hardware assumed since 2019 stayed near 10⁸: qubits fell, and run time rose to about five days.
- Against the bill, the machines of 2026 are short by hundreds to about a thousand times in protected qubits, 10¹¹ to 10¹² in protected error and about 400,000 times in the duration of continuous correction.
- The cost is worth paying for factoring, discrete logarithms and hard problems in chemistry and materials, and the tests to watch are the DOE competition, DARPA's reviews and the logical-qubit milestones of IBM, Quantinuum, QuEra and Google.
Lessons.
The chapters leave thirteen working rules for anyone who reads, funds, buys or reports on quantum computers. After each rule come the chapters that explain why it holds.
- Ask how the cost grows, not how many seconds it took. A ratio of run times measures the classical method of its day; whether an advantage is real depends on how each cost grows with the size of the problem (Chapters 1, 9 and 11).
- Treat every quantum output as one sample. Each run returns a single 0 or 1 per qubit, drawn from odds the machine prepared, so any probability quoted from a machine was estimated from many runs and carries their spread (Chapters 2 and 3).
- Look for hidden structure before choosing a quantum method. Large speedups come from interference that cancels wrong answers, which needs structure such as a period; unstructured search gains only a square root, and a square root rarely survives the cost of error correction (Chapters 6, 7 and 9).
- Count the data as well as the arithmetic. A quantum computer loads and reads data slowly, so problems dominated by input and output gain little however fast the arithmetic inside (Chapter 9).
- Set every claim against the best classical method on the best hardware. Sampling claims, chemistry benchmarks and the factoring record all moved when classical methods improved, sometimes within weeks of the claim (Chapters 1, 10, 11 and 21).
- Quote errors per operation, then multiply by the operations needed. A gate that errs once in a thousand is good hardware and useless for a computation of billions of steps; for RSA-2048 error correction must close a gap of about 10¹² (Chapters 4 and 13).
- Read a threshold as a slope. Below threshold each step up in code distance divides the error by Λ, and the size of Λ, more than the crossing itself, sets how many physical qubits each protected qubit costs (Chapters 14, 15 and 16).
- Ask how a logical qubit was counted. Code distance, real-time correction, discarded runs and the logical error per operation decide what a count means, and counts from codes that only detect errors measure something else (Chapters 16 and 21).
- Budget the instrument, not only the chip. Refrigerator stages, wiring, amplifiers, control electronics and the decoder each limit how many qubits can work together and how quickly corrections arrive (Chapters 17 and 18).
- Compare platforms by cycle time and losses as well as by fidelity. With two-qubit gates near 99.9 % on ions, atoms and superconducting chips, the time for one error-correction cycle and the qubits lost in it now separate them (Chapters 19 and 21).
- Restate every resource estimate as qubits, hours and assumptions. Error rate, cycle time, connectivity and reaction time decide the headline number, and on the hardware assumed since 2019 the bill for RSA-2048 has stayed near 10⁸ qubit-hours (Chapter 22).
- Convert a roadmap into the units of the bill. Logical qubits, error per logical operation and operations sustained can be set against a known problem, while a date or a count of physical qubits cannot (Chapters 20 and 22).
- Label every figure by where it was measured and who reported it. A single pair of qubits and a whole-chip median, or a peer-reviewed paper and a company release, are different kinds of evidence, and this guide marks which is which (Chapters 20 and 21).
Glossary.
Terms are defined as they are used in this guide.
- Amplitude
- The arrow of this guide: a length and a direction attached to each possible outcome of a measurement, whose squared length gives that outcome's probability.
- Ancilla
- An extra qubit used to check other qubits, for example by collecting their parity, and then measured without measuring them.
- Attenuator
- A component that absorbs most of a signal and turns it into heat at its own temperature stage, removing the thermal noise that came down with it.
- Bell pair
- Two entangled qubits whose readings always agree, or always disagree, although each reading alone is random.
- Break-even
- The point at which a protected qubit holds its information longer, or errs less, than the best of the physical qubits it is made from.
- Cat qubit
- A qubit stored in an oscillator whose bit flips are suppressed by design, so that a simple code need correct mainly phase errors.
- Certified randomness
- Random bits produced by a quantum computer together with a classical test showing, under stated assumptions, that they could not have been generated in advance.
- Code distance
- The smallest number of physical errors that can change a protected qubit without being detected; written d.
- Coherence time
- How long a qubit keeps its state: T1 for loss of energy, T2 for loss of phase.
- Color code
- An error-correcting code related to the surface code in which more gates can be applied directly to the protected qubits.
- Controlled-NOT (CNOT)
- A two-qubit gate that flips the target qubit when the control qubit is 1, and entangles them when the control is in a superposition.
- Controlled-Z (CZ)
- A two-qubit gate that reverses the phase of the arrow for the outcome in which both qubits are 1; the native two-qubit gate of Willow.
- Coupler
- A circuit element that joins two qubits so that a two-qubit gate can act on them, often tunable so the interaction can be switched off.
- Cross-entropy benchmarking (XEB)
- A score that checks whether a machine's samples favor the outcomes a simulation says should be likely; used to estimate fidelity in random circuit sampling.
- Cultivation
- A method of growing a magic state gradually inside one code patch, checking it as it grows, instead of distilling many noisy copies.
- Cycle
- One round of an error-correcting code in which every check is measured once; about 1.1 microseconds on Willow.
- Decoder
- The classical computer and algorithm that turn a stream of check results into a judgment of which errors most likely occurred.
- Decoherence
- The loss of a qubit's state to its surroundings, through energy relaxation and dephasing.
- Dephasing
- Loss of the relative direction of a qubit's arrows, scrambling the phase without changing the odds of 0 and 1.
- Depth
- The number of time steps a circuit takes when gates on separate qubits run at the same time.
- Dequantization
- A classical algorithm that matches a claimed quantum speedup by using the same access to data the quantum algorithm assumed.
- Dilution refrigerator
- A refrigerator that cools to a few thousandths of a degree above absolute zero by letting helium-3 cross into a dilute mixture with helium-4.
- Discrete logarithm
- The power to which a number must be raised, in modular arithmetic, to give another; Shor's algorithm finds it as efficiently as it factors.
- Dispersive readout
- Reading a qubit through the small frequency shift it causes in a coupled resonator, without the qubit absorbing the probe.
- Distillation
- Producing a few high-quality magic states by consuming many noisy ones.
- DRAG pulse
- A shaped control pulse with an added component that keeps a transmon from leaking into its third level.
- Energy relaxation
- A qubit in 1 decaying to 0 by giving its energy to the surroundings; its time constant is T1.
- Entanglement
- A shared state of two or more qubits that cannot be described qubit by qubit, so their readings are correlated beyond anything separate objects allow.
- Error detection
- A code that flags errors without being able to correct them; runs with flagged errors are discarded.
- Fault tolerance
- Computing with protected qubits in such a way that errors during the checking itself do not spread uncontrollably.
- FeMoco
- The iron-molybdenum cofactor of the nitrogenase enzyme, a metal cluster whose electrons are a standard test case for quantum chemistry.
- Fidelity
- How close an operation or state comes to the ideal one; a two-qubit gate fidelity of 99.9 % means an error of about 1 in 1,000.
- Fusion
- A measurement on two photons that entangles the clusters they belong to; the basic operation of PsiQuantum's photonic design.
- Gate
- An operation that turns a qubit's arrows, or the arrows of two or three qubits together, by a set amount.
- General number field sieve
- The fastest known ordinary algorithm for factoring large numbers such as RSA keys; its cost grows faster than any polynomial and slower than any exponential.
- Grover's algorithm
- A quantum search that finds a marked item among N in about the square root of N steps, by repeated reflections that amplify the marked item's arrow.
- Hadamard gate
- A single-qubit gate that turns 0 into an equal superposition of 0 and 1, and back again when applied twice.
- Interference
- The adding of arrows for the different ways an outcome can happen, so that some outcomes reinforce and others cancel.
- Josephson junction
- A thin insulating barrier between two superconductors that gives a superconducting circuit unequally spaced energy levels.
- Lambda (Λ)
- The factor by which a code's logical error falls for each increase of two in code distance; above 1 means the code is below threshold.
- Lattice surgery
- Merging and splitting code patches to perform gates such as CNOT between the logical qubits they hold.
- Leakage
- A qubit escaping its two working levels into a higher one, an error that ordinary codes do not catch.
- Logical qubit
- A protected qubit made from many physical qubits by an error-correcting code.
- Magic state
- A specially prepared state consumed to perform a T gate or Toffoli gate on protected qubits.
- Magic state factory
- A region of a fault-tolerant machine that does nothing but prepare magic states.
- Mixing chamber
- The coldest plate of a dilution refrigerator, on which the quantum chip sits.
- Modular arithmetic
- Arithmetic on a clock: numbers wrap around after a fixed modulus, so 7 × 13 mod 15 is 1.
- Neutral atom
- An uncharged atom held in a laser trap and used as a qubit; atoms interact when excited to a Rydberg state.
- No-cloning theorem
- The result that an unknown quantum state cannot be copied, which rules out protecting qubits by keeping backup copies.
- Optical tweezers
- Tightly focused laser beams that hold single atoms and can move them.
- Oracle
- The part of a search circuit that marks the item sought; it must be built as a circuit, and its cost counts.
- Parametric amplifier
- A superconducting amplifier, pumped by a microwave tone, that adds close to the least noise quantum physics allows.
- Parity check
- A check that reports whether a group of qubits holds an even or odd number of 1s, without revealing the individual values.
- Pauli error
- An error measure for gates that counts bit flips, phase flips and both; for a two-qubit gate it is five fourths of the average error.
- Period finding
- Finding how often a sequence repeats; the step of Shor's algorithm that a quantum computer performs.
- Phase
- The direction of a qubit's arrow; it cannot be read directly but decides how arrows interfere.
- Physical qubit
- A qubit as built, a circuit, ion, atom, photon or spin, with its own error rate.
- Polynomial and exponential
- Two ways a cost can grow with the size of a problem: as a fixed power of the size, or by a fixed factor for each step up in size.
- Post-selection
- Discarding the runs in which an error was detected and keeping the rest; the share kept shrinks as computations grow longer.
- Quantum advantage
- A task performed by a quantum computer faster, or at all, beyond what the best ordinary computers can do; the claim depends on the classical method compared.
- Quantum annealer
- A machine that lets a network of qubits settle toward a low-energy state rather than running sequences of gates.
- Quantum dot
- A region of a semiconductor, defined by electrodes, that holds single electrons whose spins serve as qubits.
- Quantum Fourier transform
- The step of Shor's algorithm that turns a periodic pattern of arrows into peaks at multiples of the inverse period.
- Quantum LDPC code
- An error-correcting code whose checks reach beyond nearest neighbors, storing many logical qubits in one block with fewer physical qubits each.
- Qubit
- A physical system with two levels, 0 and 1, that can be prepared, turned, entangled and read.
- Qubit-hours
- The number of qubits kept protected multiplied by the hours they must be kept, a measure of the work in a computation.
- Random circuit sampling
- Running random sequences of gates and collecting samples, a task designed to be hard for ordinary computers to imitate.
- Reaction time
- The time from reading the checks of a code to applying a gate that depends on the decoded result.
- Resonator
- A circuit that rings at one frequency; coupled to a qubit, it is used to read the qubit's state.
- RSA-2048
- A 617-digit challenge number whose size matches the 2,048-bit keys of RSA encryption; the thread of this guide.
- Rydberg state
- A highly excited state of an atom in which the outer electron orbits far from the nucleus, letting nearby atoms interact.
- Shor's algorithm
- Peter Shor's 1994 method for factoring numbers and finding discrete logarithms on a quantum computer by period finding.
- Shot
- One run of a quantum program ending in one reading of each qubit.
- Spin qubit
- A qubit stored in the spin of a single electron, usually in a quantum dot in silicon.
- Surface code
- The error-correcting code on a square grid whose checks involve only neighboring qubits; the basis of most superconducting roadmaps.
- Syndrome
- The pattern of check results that points to which error occurred.
- T gate
- A single-qubit gate that turns the arrow by an eighth of a turn; needed for universal computation and the costliest gate to protect.
- Thermal photon
- A unit of energy that warm surroundings supply at a qubit's frequency; one absorbed by a qubit in 0 flips it to 1.
- Threshold
- The physical error rate below which making a code larger lowers the logical error instead of raising it.
- Toffoli gate
- A three-qubit gate that flips the target only when both controls are 1; the basic step of the arithmetic in Shor's algorithm.
- Topological qubit
- A proposed qubit that would store information in collective states of special superconducting wires, protected from local errors by their nature.
- Transmon
- The most common superconducting qubit, a small circuit with a Josephson junction whose two lowest energy levels serve as 0 and 1.
- Trapped ion
- A charged atom held by electric fields in a vacuum and used as a qubit, driven by lasers or microwaves.
- Variational quantum eigensolver
- A method that runs short quantum circuits whose settings an ordinary computer adjusts to lower an estimated energy.
- Yoked surface code
- Surface-code patches in storage joined by an extra layer of checks across groups of patches, so each needs fewer physical qubits.
Sources.
Sources are listed by the chapter in which they are first used. Figures from companies, and from papers whose authors include company staff, are identified as such. Company plans, products and results are stated as of October 2026.
- Opening — Shor P.W. The early days of quantum computation. arXiv:2208.09964 (2022; v2 26 Oct 2022). (first-person account written up from talks at QC40 (2021) and the 2022 Solvay Conference: the April 1994 seminar, the weekend call, “the news spread like wildfire”, Landauer’s objection at the Santa Fe Institute)
- Opening — Zierler D. (interviewer), Dahn R. (adapter). Peter Shor on the genesis of Shor’s algorithm. Physics Today 78(4) (April 2025; online 7 Mar 2025). doi:10.1063/pt.ifad.hcak (edited from the AIP oral history of 28 Aug 2020, whose full transcript has not been released)
- Opening — Chu J. It’s a weird, weird quantum world (report of Shor’s Killian Lecture). MIT News (10 Mar 2023). news.mit.edu (secondary)
- Opening — MacTutor History of Mathematics. Peter Williston Shor (biography). mathshistory.st-andrews.ac.uk/Biographies/Shor (secondary)
- Opening — Shor P.W. Algorithms for quantum computation: discrete logarithms and factoring. In Proc. 35th Annual Symposium on Foundations of Computer Science, Santa Fe, 20–22 Nov 1994, IEEE Computer Society, 124–134 (1994). doi:10.1109/SFCS.1994.365700
- Opening — Weis S.A. RSA-896 (blog post, September 2026). saweis.net/posts/rsa-896.html (270 digits; up to 2,048 H100 graphics processors for about ten days, about 30 GPU-years)
- Opening — Wikipedia. RSA Factoring Challenge; RSA numbers (web pages, accessed Oct 2026). en.wikipedia.org (secondary)
- Opening — Google Quantum AI and Collaborators (Acharya R., et al.). Quantum error correction below the surface code threshold. Nature 638, 920–926 (2025). doi:10.1038/s41586-024-08449-y; arXiv:2408.13687; and its Supplementary Information (gate durations, readout, decoder hardware) [authors include company staff]
- Opening — Fowler A.G., Mariantoni M., Martinis J.M., Cleland A.N. Surface codes: towards practical large-scale quantum computation. Phys. Rev. A 86, 032324 (2012). doi:10.1103/PhysRevA.86.032324; arXiv:1208.0928
- Opening — Gidney C., Ekerå M. How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits. Quantum 5, 433 (2021). doi:10.22331/q-2021-04-15-433; arXiv:1905.09749 (2019) (abstract read) [authors include company staff]
- Opening — Gidney C. How to factor 2048 bit RSA integers with less than a million noisy qubits. arXiv:2505.15917 (2025) [authors include company staff]
- Opening — Webster P., Berent L., Chandra O., Hockings E.T., Baspin N., Thomsen F., Smith S.C., Cohen L.Z. The Pinnacle architecture: reducing the cost of breaking RSA-2048 to 100 000 physical qubits using quantum LDPC codes. arXiv:2602.11457 (2026) [authors include company staff]
- Opening — Cain M., Xu Q., King R., Picard L.R.B., Levine H., Endres M., Preskill J., Huang H.-Y., Bluvstein D. Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits. arXiv:2603.28627 (2026) [authors include company staff]
- Ch. 1 — Kleinjung T., Aoki K., Franke J., Lenstra A.K., Thomé E., Bos J.W., Gaudry P., Kruppa A., Montgomery P.L., Osvik D.A., te Riele H., Timofeev A., Zimmermann P. Factorization of a 768-bit RSA modulus. In CRYPTO 2010, LNCS 6223, 333–350 (2010). doi:10.1007/978-3-642-14623-7_18 (read in the CWI repository copy; DOI not opened)
- Ch. 1 — Boudot F., Gaudry P., Guillevic A., Heninger N., Thomé E., Zimmermann P. Comparing the difficulty of factorization and discrete logarithm: a 240-digit experiment. In CRYPTO 2020, LNCS 12171 (2020). doi:10.1007/978-3-030-56880-1_3; arXiv:2006.06197 (RSA-240 effort, the RSA-250 accounting and the number field sieve cost formula)
- Ch. 1 — Boudot F., Gaudry P., Guillevic A., Heninger N., Thomé E., Zimmermann P. Factorization of RSA-250 (announcement, 28 Feb 2020). caramba.loria.fr/rsa250.txt
- Ch. 1 — Lu E. Factoring RSA-260. Cognition blog (9 Sep 2026). cognition.com/blog/factoring-rsa-260 (compute, cost and the RSA-2048 extrapolation are the author’s own figures) [company figure]
- Ch. 1 — Ivezic M. RSA-260 factored on GPUs with code built by Devin agent. postquantum.com (4 Sep 2026) (secondary; checks the published factors by multiplication)
- Ch. 1 — Shor P.W. Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer. SIAM J. Comput. 26, 1484–1509 (1997). doi:10.1137/S0097539795293172; arXiv:quant-ph/9508027
- Ch. 1 — Feynman R.P. Simulating physics with computers. Int. J. Theor. Phys. 21, 467–488 (1982). doi:10.1007/BF02650179 (received 7 May 1981)
- Ch. 2 — Bluefors. XLD dilution refrigerator (product page, accessed 7 Oct 2026). bluefors.com (base temperature and cooling power). Manufacturer.
- Ch. 2 — Gao Y.Y., Rol M.A., Touzard S., Wang C. A practical guide for building superconducting quantum devices. PRX Quantum 2, 040202 (2021). arXiv:2106.06173 (read as the arXiv version)
- Ch. 2 — Koch J., Yu T.M., Gambetta J., Houck A.A., Schuster D.I., Majer J., Blais A., Devoret M.H., Girvin S.M., Schoelkopf R.J. Charge-insensitive qubit design derived from the Cooper pair box. Phys. Rev. A 76, 042319 (2007). doi:10.1103/PhysRevA.76.042319 (abstract read)
- Ch. 2 — Kim Y., Eddins A., Anand S., et al. Evidence for the utility of quantum computing before fault tolerance. Nature 618, 500–505 (2023). doi:10.1038/s41586-023-06096-3 [authors include company staff]
- Ch. 2 — Olmschenk S., Younge K.C., Moehring D.L., Matsukevich D.N., Maunz P., Monroe C. Manipulation and detection of a trapped Yb+ hyperfine qubit. Phys. Rev. A 76, 052314 (2007). doi:10.1103/PhysRevA.76.052314
- Ch. 2 — Ransford A., Allman M.S., Arkinstall J., et al. Helios: a 98-qubit trapped-ion quantum computer. arXiv:2511.05465 (2025); published as A 98-qubit trapped-ion quantum computer with all-to-all connectivity, Nature (17 Jun 2026) (journal version not opened) [authors include company staff]
- Ch. 2 — Bluvstein D., Evered S.J., Geim A.A., et al. Logical quantum processor based on reconfigurable atom arrays. Nature 626, 58–65 (2024). doi:10.1038/s41586-023-06927-3 [authors include company staff]
- Ch. 2 — Alexander K., Bahgat A., Benyamini A., et al. A manufacturable platform for photonic quantum computing. Nature 641, 876–883 (2025). doi:10.1038/s41586-025-08820-7; arXiv:2404.17570 (abstract read) [authors include company staff]
- Ch. 2 — Veldhorst M., Yang C.H., Hwang J.C.C., et al. A two-qubit logic gate in silicon. Nature 526, 410–414 (2015). doi:10.1038/nature15263 (abstract read)
- Ch. 2 — Mooij J.E., Orlando T.P., Levitov L., Tian L., van der Wal C.H., Lloyd S. Josephson persistent-current qubit. Science 285, 1036–1039 (1999). doi:10.1126/science.285.5430.1036 (DOI not opened)
- Ch. 2 — Google Quantum AI. Willow spec sheet (9 Dec 2024). quantumai.google/static/site-assets/downloads/willow-spec-sheet.pdf (two chips: error correction and random circuit sampling). Manufacturer.
- Ch. 2 — Swiadek F., et al. Enhancing dispersive readout of superconducting qubits through dynamic control of the dispersive shift: experiment and theory. PRX Quantum 5, 040326 (2024). doi:10.1103/PRXQuantum.5.040326 (abstract read)
- Ch. 3 — Grangier P., Roger G., Aspect A. Experimental evidence for a photon anticorrelation effect on a beam splitter: a new light on single-photon interferences. Europhys. Lett. 1, 173–179 (1986). doi:10.1209/0295-5075/1/4/004 (read via a university-hosted course copy)
- Ch. 3 — Feynman R.P. QED: The Strange Theory of Light and Matter. Princeton University Press (1985). (not opened; publisher’s page only)
- Ch. 3 — Jacques V., Wu E., Grosshans F., Treussart F., Grangier P., Aspect A., Roch J.-F. Experimental realization of Wheeler’s delayed-choice gedanken experiment. Science 315, 966–968 (2007). doi:10.1126/science.1136303 (abstract read)
- Ch. 3 — Bell J.S. On the Einstein Podolsky Rosen paradox. Physics 1, 195–200 (1964). doi:10.1103/PhysicsPhysiqueFizika.1.195 (read via a university-hosted course copy)
- Ch. 3 — Shimony A. (and possibly co-authors). Bell’s theorem. Stanford Encyclopedia of Philosophy (substantive revision 25 Jan 2024). plato.stanford.edu/entries/bell-theorem (authorship of the 2024 revision not confirmed)
- Ch. 3 — Hensen B., Bernien H., Dréau A.E., et al. Loophole-free Bell inequality violation using electron spins separated by 1.3 kilometres. Nature 526, 682–686 (2015). doi:10.1038/nature15759 (abstract read)
- Ch. 3 — Giustina M., Versteegh M.A.M., Wengerowsky S., et al. Significant-loophole-free test of Bell’s theorem with entangled photons. Phys. Rev. Lett. 115, 250401 (2015). doi:10.1103/PhysRevLett.115.250401 (abstract read)
- Ch. 3 — Shalm L.K., Meyer-Scott E., Christensen B.G., et al. Strong loophole-free test of local realism. Phys. Rev. Lett. 115, 250402 (2015). doi:10.1103/PhysRevLett.115.250402 (abstract read)
- Ch. 3 — Nobel Committee for Physics. Scientific background on the Nobel Prize in Physics 2022 (Oct 2022). nobelprize.org
- Ch. 3 — Nobel Prize Outreach. The Nobel Prize in Physics 2022 (summary page with the prize citation). nobelprize.org/prizes/physics/2022/summary
- Ch. 3 — Goldstein S. Bohmian mechanics. Stanford Encyclopedia of Philosophy (substantive revision 20 Sep 2025). plato.stanford.edu
- Ch. 4 — Nielsen M.A., Chuang I.L. Quantum Computation and Quantum Information, 10th anniversary ed. Cambridge University Press (2010). ISBN 978-1-107-00217-3 (gate definitions and universality, Secs. 1.3 and 4.2–4.5; table of contents checked only)
- Ch. 4 — Nielsen M.A. A simple formula for the average gate fidelity of a quantum dynamical operation. Phys. Lett. A 303, 249 (2002). arXiv:quant-ph/0205035 (the conversion between Pauli error and average gate error)
- Ch. 4 — Ross N.J., Selinger P. Optimal ancilla-free Clifford+T approximation of z-rotations. Quantum Inf. Comput. 16, 901–953 (2016). arXiv:1403.2975 (abstract read)
- Ch. 4 — Rosenfeld E., Gidney C., Roberts G., Morvan A., Lacroix N., et al. Magic state cultivation on a superconducting quantum processor. arXiv:2512.13908 (2025) (abstract read) [authors include company staff]
- Ch. 5 — De Raedt H., Kraus J., Herten A., Mehta V., Bode M., Hrywniak M., Michielsen K., Lippert T. Universal quantum computer simulation of 50 qubits on Europe’s first exascale supercomputer harnessing its heterogeneous CPU-GPU architecture. Future Gener. Comput. Syst. (2026) 108592. arXiv:2511.03359 (read as the arXiv version; two authors at NVIDIA, whose processors ran the simulation) [authors include company staff]
- Ch. 5 — De Raedt H., Jin F., Willsch D., Willsch M., Yoshioka N., Ito N., Yuan S., Michielsen K. Massively parallel quantum computer simulator, eleven years later. Comput. Phys. Commun. 237, 47–61 (2019). arXiv:1805.04708
- Ch. 5 — Arute F., Arya K., Babbush R., et al. Quantum supremacy using a programmable superconducting processor. Nature 574, 505–510 (2019). doi:10.1038/s41586-019-1666-5 [authors include company staff]
- Ch. 5 — Pednault E., Gunnels J.A., Nannicini G., Horesh L., Wisnieff R. Leveraging secondary storage to simulate deep 54-qubit Sycamore circuits. arXiv:1910.09534 (21 Oct 2019) (an estimate, never run; IBM authors replying to a competitor’s claim) [authors include company staff]
- Ch. 5 — Ghirardi G.C., Rimini A., Weber T. A general argument against superluminal transmission through the quantum mechanical measurement process. Lett. Nuovo Cimento 27, 293–298 (1980). doi:10.1007/BF02817189 (not opened)
- Ch. 5 — Jozsa R., Linden N. On the role of entanglement in quantum-computational speed-up. Proc. R. Soc. Lond. A 459, 2011–2032 (2003). doi:10.1098/rspa.2002.1097 (abstract read)
- Ch. 5 — Deutsch D. Quantum theory, the Church–Turing principle and the universal quantum computer. Proc. R. Soc. Lond. A 400, 97–117 (1985). doi:10.1098/rspa.1985.0070 (not opened)
- Ch. 6 — Grover L.K. A fast quantum mechanical algorithm for database search. In Proc. 28th Annual ACM Symposium on Theory of Computing, 212–219 (1996). doi:10.1145/237814.237866; arXiv:quant-ph/9605043
- Ch. 6 — Boyer M., Brassard G., Høyer P., Tapp A. Tight bounds on quantum searching. Fortschr. Phys. 46, 493–506 (1998). arXiv:quant-ph/9605034 (1996)
- Ch. 6 — Bennett C.H., Bernstein E., Brassard G., Vazirani U. Strengths and weaknesses of quantum computing. SIAM J. Comput. 26, 1510–1523 (1997). doi:10.1137/S0097539796300933; arXiv:quant-ph/9701001 (abstract read)
- Ch. 6 — Zalka C. Grover’s quantum searching algorithm is optimal. Phys. Rev. A 60, 2746–2751 (1999). doi:10.1103/PhysRevA.60.2746 (abstract read)
- Ch. 6 — Babbush R., McClean J.R., Newman M., Gidney C., Boixo S., Neven H. Focus beyond quadratic speedups for error-corrected quantum advantage. PRX Quantum 2, 010103 (2021). doi:10.1103/PRXQuantum.2.010103; arXiv:2011.04149 [authors include company staff]
- Ch. 7 — Bernstein E., Vazirani U. Quantum complexity theory. In Proc. 25th ACM STOC, 11–20 (1993). doi:10.1145/167088.167097; SIAM J. Comput. 26, 1411–1473 (1997). doi:10.1137/S0097539796300921 (not opened; bibliographic records only)
- Ch. 7 — Simon D.R. On the power of quantum computation. In Proc. 35th IEEE FOCS, 116–123 (1994). doi:10.1109/SFCS.1994.365701; SIAM J. Comput. 26, 1474–1483 (1997). doi:10.1137/S0097539796298637 (not opened; bibliographic records only)
- Ch. 7 — Babbush R., Zalcman A., Gidney C., Broughton M., Khattar T., Neven H., Bergamaschi T., Drake J., Boneh D. Securing elliptic curve cryptocurrencies against quantum vulnerabilities: resource estimates and mitigations. arXiv:2603.28846 (2026) [authors include company staff]
- Ch. 8 — Coppersmith D. An approximate Fourier transform useful in quantum factoring. IBM Research Report RC 19642 (1994). arXiv:quant-ph/0201067 (abstract read)
- Ch. 8 — Beauregard S. Circuit for Shor’s algorithm using 2n+3 qubits. Quantum Inf. Comput. 3, 175–185 (2003). arXiv:quant-ph/0205095
- Ch. 8 — Vandersypen L.M.K., Steffen M., Breyta G., Yannoni C.S., Sherwood M.H., Chuang I.L. Experimental realization of Shor’s quantum factoring algorithm using nuclear magnetic resonance. Nature 414, 883–887 (2001). doi:10.1038/414883a [authors include company staff]
- Ch. 8 — Lu C.-Y., Browne D.E., Yang T., Pan J.-W. Demonstration of a compiled version of Shor’s quantum factoring algorithm using photonic qubits. Phys. Rev. Lett. 99, 250504 (2007). doi:10.1103/PhysRevLett.99.250504
- Ch. 8 — Lanyon B.P., Weinhold T.J., Langford N.K., Barbieri M., James D.F.V., Gilchrist A., White A.G. Experimental demonstration of a compiled version of Shor’s algorithm with quantum entanglement. Phys. Rev. Lett. 99, 250505 (2007). doi:10.1103/PhysRevLett.99.250505
- Ch. 8 — Martín-López E., Laing A., Lawson T., Alvarez R., Zhou X.-Q., O’Brien J.L. Experimental realization of Shor’s quantum factoring algorithm using qubit recycling. Nat. Photonics 6, 773–776 (2012). doi:10.1038/nphoton.2012.259
- Ch. 8 — Smolin J.A., Smith G., Vargo A. Oversimplifying quantum factoring. Nature 499, 163–165 (2013). doi:10.1038/nature12290; arXiv:1301.7007 (arXiv title: Pretending to factor large numbers on a quantum computer)
- Ch. 8 — Monz T., Nigg D., Martinez E.A., Brandl M.F., Schindler P., Rines R., Wang S.X., Chuang I.L., Blatt R. Realization of a scalable Shor algorithm. Science 351, 1068–1070 (2016). arXiv:1507.08852 (read as the arXiv version; DOI not verified)
- Ch. 8 — Amico M., Saleem Z.H., Kumph M. Experimental study of Shor’s factoring algorithm using the IBM Q Experience. Phys. Rev. A 100, 012305 (2019). doi:10.1103/PhysRevA.100.012305 [authors include company staff]
- Ch. 8 — Gidney C. Why haven’t quantum computers factored 21 yet? (blog post, 30 Aug 2025). algassert.com/post/2500
- Ch. 8 — Yan B., Tan Z., Wei S., et al. Factoring integers with sublinear resources on a superconducting quantum processor. arXiv:2212.12372 (2022)
- Ch. 8 — Khattar T., Yosri N. A comment on “Factoring integers with sublinear resources on a superconducting quantum processor”. arXiv:2307.09651 (2023)
- Ch. 9 — Kerenidis I., Prakash A. Quantum recommendation systems. arXiv:1603.08675 (2016) (abstract read; conference version, ITCS 2017, not verified)
- Ch. 9 — Tang E. A quantum-inspired classical algorithm for recommendation systems. In Proc. STOC 2019. doi:10.1145/3313276.3316310; arXiv:1807.04271 (2018) (abstract read)
- Ch. 9 — Hartnett K. Major quantum computing advance made obsolete by teenager. Quanta Magazine (31 Jul 2018) (secondary)
- Ch. 9 — Hoefler T., Häner T., Troyer M. Disentangling hype from practicality: on realistically achieving quantum advantage. Commun. ACM 66(5), 82–87 (2023). arXiv:2307.00523 [authors include company staff]
- Ch. 9 — Harrow A.W., Hassidim A., Lloyd S. Quantum algorithm for linear systems of equations. Phys. Rev. Lett. 103, 150502 (2009). doi:10.1103/PhysRevLett.103.150502 (abstract read)
- Ch. 9 — Aaronson S. Read the fine print. Nat. Phys. 11, 291–293 (2015). doi:10.1038/nphys3272
- Ch. 9 — Babbush R., King R., Boixo S., Huggins W., Khattar T., Low G.H., McClean J.R., O’Brien T., Rubin N.C. The grand challenge of quantum applications. arXiv:2511.09124 (2025) (abstract read) [authors include company staff]
- Ch. 9 — Høyer P., Neerbek J., Shi Y. Quantum complexities of ordered searching, sorting, and element distinctness. Algorithmica 34, 429–448 (2002). doi:10.1007/s00453-002-0976-3; arXiv:quant-ph/0102078 (2001) (abstract read)
- Ch. 9 — Farhi E., Goldstone J., Gutmann S. A quantum approximate optimization algorithm. arXiv:1411.4028 (2014) (abstract read)
- Ch. 9 — Shaydulin R., Li C., Chakrabarti S., DeCross M., et al. Evidence of scaling advantage for the quantum approximate optimization algorithm on a classically intractable problem. Sci. Adv. 10, eadm6761 (2024). arXiv:2308.02342 [authors include company staff]
- Ch. 9 — Costa P.C.S., Morales M.E.S., An D., Sanders Y.R. Assessing quantum and classical approaches to combinatorial optimization: testing quadratic speed-ups for heuristic algorithms. arXiv:2412.13035 (2024)
- Ch. 9 — Abbas A., et al. Challenges and opportunities in quantum optimization. Nat. Rev. Phys. 6, 718–735 (2024). doi:10.1038/s42254-024-00770-9 (abstract read) [authors include company staff]
- Ch. 10 — Garfinkel S. Tomorrow’s computer, yesterday. MIT Technology Review (27 Apr 2021) (secondary)
- Ch. 10 — Reiher M., Wiebe N., Svore K.M., Wecker D., Troyer M. Elucidating reaction mechanisms on quantum computers. PNAS 114, 7555–7560 (2017). doi:10.1073/pnas.1619152114; arXiv:1605.03590 (read as the arXiv version) [authors include company staff]
- Ch. 10 — International Energy Agency. Ammonia Technology Roadmap, executive summary (Oct 2021). iea.org
- Ch. 10 — Li Z., Li J., Dattani N.S., Umrigar C.J., Chan G.K.-L. The electronic complexity of the ground-state of the FeMo cofactor of nitrogenase as relevant to quantum simulations. J. Chem. Phys. 150, 024302 (2019). doi:10.1063/1.5063376 (abstract read)
- Ch. 10 — Lee J., Berry D.W., Gidney C., Huggins W.J., McClean J.R., Wiebe N., Babbush R. Even more efficient quantum computations of chemistry through tensor hypercontraction. PRX Quantum 2, 030305 (2021). doi:10.1103/PRXQuantum.2.030305; arXiv:2011.03494 (read as the arXiv version) [authors include company staff]
- Ch. 10 — Low G.H., King R., Berry D.W., Han Q., DePrince A.E. III, White A., Babbush R., Somma R.D., Rubin N.C. Fast quantum simulation of electronic structure by spectral amplification. Phys. Rev. X 15, 041016 (published 31 Oct 2025). doi:10.1103/pb2g-j9cw; arXiv:2502.15882 (FeMoco, 76-orbital model: about 4.5 million physical qubits for 8.6 h at code distance 27, physical error 0.001, 1 µs cycle, four factories; the source of the 8.6 h quoted by Zhai et al.) [authors include company staff]
- Ch. 10 — Zhai H., Li C., Zhang X., Li Z., Lee S., Chan G.K.-L. Classical computational simulation of the FeMo-cofactor model to chemical accuracy and its implications. arXiv:2601.04621 (2026)
- Ch. 10 — Lee S., Lee J., Zhai H., Tong Y., Dalzell A.M., et al. Evaluating the evidence for exponential quantum advantage in ground-state quantum chemistry. Nat. Commun. 14, 1952 (2023). doi:10.1038/s41467-023-37587-6 (abstract read) [authors include company staff]
- Ch. 10 — Goings J.J., White A., Lee J., Tautermann C.S., Degroote M., Gidney C., Shiozaki T., Babbush R., Rubin N.C. Reliably assessing the electronic structure of cytochrome P450 on today’s classical computers and tomorrow’s quantum computers. PNAS 119, e2203533119 (2022). doi:10.1073/pnas.2203533119 [authors include company staff]
- Ch. 10 — Google AI Quantum and Collaborators (Arute F., et al.). Hartree-Fock on a superconducting qubit quantum computer. Science 369, 1084–1089 (2020). doi:10.1126/science.abb9811 (abstract read) [authors include company staff]
- Ch. 10 — Gonthier J.F., Radin M.D., Buda C., Doskocil E.J., Abuan C.M., Romero J. Measurements as a roadblock to near-term practical quantum advantage in chemistry: resource analysis. Phys. Rev. Research 4, 033154 (2022). arXiv:2012.04001 [authors include company staff]
- Ch. 10 — Merz K.M. Jr., Shajan A., Kaliakin D., et al. Crossing the 12,000-atom barrier with heterogeneous quantum-classical supercomputing: quantum chemistry of protein-ligand complexes. arXiv:2605.01138 (2026) [authors include company staff]
- Ch. 10 — IBM. Cleveland Clinic, RIKEN and IBM protein-ligand chemistry result (IBM Quantum blog, 5 May 2026). ibm.com/quantum/blog/cleveland-clinic-riken-chemistry. Manufacturer.
- Ch. 11 — MIT Technology Review. Google researchers have reportedly achieved “quantum supremacy” (20 Sep 2019) (secondary)
- Ch. 11 — Fortune. Google claims quantum supremacy (20 Sep 2019) (secondary)
- Ch. 11 — Pednault E., Maslov D., Gunnels J., Gambetta J. On “quantum supremacy”. IBM Research blog (October 2019; current page dated 22 Oct 2019). ibm.com/quantum/blog/on-quantum-supremacy [company figure]
- Ch. 11 — Pan F., Chen K., Zhang P. Solving the sampling problem of the Sycamore quantum circuits. Phys. Rev. Lett. 129, 090502 (2022). doi:10.1103/PhysRevLett.129.090502 (abstract read)
- Ch. 11 — Zhao X.-H., Zhong H.-S., Pan F., Zhang P., Lu C.-Y., Pan J.-W., Chen M.-C. Leapfrogging Sycamore: harnessing 1432 GPUs for 7× faster quantum random circuit sampling. arXiv:2406.18889 (2024); Natl. Sci. Rev. (2025) (journal volume not confirmed)
- Ch. 11 — Morvan A., Villalonga B., Mi X., et al. Phase transitions in random circuit sampling. Nature 634, 328–333 (2024). doi:10.1038/s41586-024-07998-6; arXiv:2304.11119 (classical-time table read in arXiv v2) [authors include company staff]
- Ch. 11 — Neven H. Meet Willow, our state-of-the-art quantum chip. Google blog (9 Dec 2024). blog.google. Manufacturer.
- Ch. 11 — Gao D., Fan D., Zha C., et al. Establishing a new benchmark in quantum computational advantage with 105-qubit Zuchongzhi 3.0 processor. Phys. Rev. Lett. 134, 090601 (2025). doi:10.1103/PhysRevLett.134.090601; arXiv:2412.11924
- Ch. 11 — Liu M., et al. Certified randomness using a trapped-ion quantum processor. Nature 640, 343–348 (2025). doi:10.1038/s41586-025-08737-1 (abstract read) [authors include company staff]
- Ch. 11 — Google Quantum AI and Collaborators. Observation of constructive interference at the edge of quantum ergodicity. Nature 646, 825–830 (2025). doi:10.1038/s41586-025-09526-6 (abstract and summary read) [authors include company staff]
- Ch. 11 — Mi X., Kechedzhi K. A verifiable quantum advantage. Google Research blog (22 Oct 2025). Manufacturer.
- Ch. 11 — Bermejo P., Villalonga B., Ware B., Vidal G., Szasz A. Tensor networks with belief propagation cannot feasibly simulate Google’s quantum echoes experiment. arXiv:2604.15427 (2026) (abstract read) [authors include company staff]
- Ch. 11 — Zhong H.-S., Wang H., Deng Y.-H., Chen M.-C., et al. Quantum computational advantage using photons. Science 370, 1460–1463 (2020). doi:10.1126/science.abe8770; arXiv:2012.01625 (read as the arXiv version)
- Ch. 11 — Oh C., Liu M., Alexeev Y., Fefferman B., Jiang L. Classical algorithm for simulating experimental Gaussian boson sampling. Nat. Phys. 20, 1461–1468 (2024). arXiv:2306.03709 (abstract read)
- Ch. 11 — Kandala A., Javadi-Abhari A., Gambetta J. Researchers demonstrate quantum advantage through trusted quantum computation. IBM Quantum blog (30 Jul 2026). ibm.com/quantum/blog/quantum-advantage. Manufacturer.
- Ch. 11 — IBM. IBM and the University of Chicago demonstrate quantum advantage, establishing trusted quantum computation on logical circuits (press release, 30 Jul 2026). newsroom.ibm.com. Manufacturer.
- Ch. 11 — Martiel S., Chung J.-U., Seif A., Ghosh S., Hincks I., Deshpande A., Fefferman B., Gambetta J.M., Javadi-Abhari A. Sampling hard circuits with verifiably high fidelity. arXiv:2607.25941 (2026) (abstract read via an aggregator, qubitsok.com) [authors include company staff]
- Ch. 11 — Leviatan E., et al. Resolving structure in prethermal Floquet dynamics with precision quantum computation. arXiv:2607.24937 (2026) [authors include company staff]
- Ch. 11 — Barron S.V., et al. Observable estimation in the absence of classical verification. arXiv:2607.25998 (2026) [authors include company staff]
- Ch. 11 — Manabe H., Gu H., Pan F. Classical simulation and design frontiers for IBM’s doped Clifford sampling experiment. arXiv:2608.13110 (2026) (abstract read via aggregators; one author at NVIDIA, whose processors ran the simulation) [authors include company staff]
- Ch. 11 — Tindall J., Fishman M., Stoudenmire E.M., Sels D. Efficient tensor network simulation of IBM’s Eagle kicked Ising experiment. PRX Quantum 5, 010308 (2024). arXiv:2306.14887 (abstract read)
- Ch. 11 — King A.D., Nocera A., Rams M.M., Dziarmaga J., Wiersema R., et al. Beyond-classical computation in quantum simulation. Science 388, 199–204 (2025). doi:10.1126/science.ado6285; arXiv:2403.00910 (read as the arXiv version) [authors include company staff]
- Ch. 11 — Tindall J., Mello A., Fishman M., Stoudenmire M., Sels D. Dynamics of disordered quantum systems with two- and three-dimensional tensor networks. Science 392, 868–872 (2026). doi:10.1126/science.adx2728; arXiv:2503.05693 (abstract read)
- Ch. 11 — Hangleiter D. Has quantum advantage been achieved? arXiv:2603.09901 (2026)
- Ch. 12 — Krantz P., Kjaergaard M., Yan F., Orlando T.P., Gustavsson S., Oliver W.D. A quantum engineer’s guide to superconducting qubits. Appl. Phys. Rev. 6, 021318 (2019). doi:10.1063/1.5089550; arXiv:1904.06560
- Ch. 12 — Google Quantum AI. Suppressing quantum errors by scaling a surface code logical qubit. Nature 614, 676–681 (2023). doi:10.1038/s41586-022-05434-1; arXiv:2207.06431 [authors include company staff]
- Ch. 12 — Klimov P.V., et al. Fluctuations of energy-relaxation times in superconducting qubits. Phys. Rev. Lett. 121, 090502 (2018). doi:10.1103/PhysRevLett.121.090502 (abstract read) [authors include company staff]
- Ch. 12 — McEwen M., Faoro L., Arya K., et al. Resolving catastrophic error bursts from cosmic rays in large arrays of superconducting qubits. Nat. Phys. 18, 107–111 (2022). doi:10.1038/s41567-021-01432-8 [authors include company staff]
- Ch. 12 — Li X., Wang J., Jiang Y.-Y., Xue G.-M., Cai X., et al. Cosmic-ray-induced correlated errors in superconducting qubit array. Nat. Commun. 16 (2025). doi:10.1038/s41467-025-59778-z; arXiv:2402.04245 (abstract read)
- Ch. 12 — McEwen M., Miao K.C., Atalaya J., et al. Resisting high-energy impact events through gap engineering in superconducting qubit arrays. Phys. Rev. Lett. 133, 240601 (2024). doi:10.1103/PhysRevLett.133.240601 [authors include company staff]
- Ch. 12 — Bland M.P., Bahrami F., Martinez J.G.C., et al., Houck A.A. Millisecond lifetimes and coherence times in 2D transmon qubits. Nature 647, 343–348 (2025). doi:10.1038/s41586-025-09687-4; arXiv:2503.14798 (abstract read)
- Ch. 12 — Wang P., Luan C.-Y., Qiao M., Um M., Zhang J., Wang Y., Yuan X., Gu M., Zhang J., Kim K. Single ion qubit with estimated coherence time exceeding one hour. Nat. Commun. 12, 233 (2021). doi:10.1038/s41467-020-20330-w (abstract read)
- Ch. 12 — Manetsch H.J., Nomura G., Bataille E., Leung K.H., Lv X., Endres M. A tweezer array with 6100 highly coherent atomic qubits. Nature 647, 60–67 (2025). doi:10.1038/s41586-025-09641-4; arXiv:2403.12021 (abstract read)
- Ch. 13 — Wootters W.K., Zurek W.H. A single quantum cannot be cloned. Nature 299, 802–803 (1982). doi:10.1038/299802a0 (abstract read)
- Ch. 13 — Dieks D. Communication by EPR devices. Phys. Lett. A 92, 271–272 (1982). (not opened)
- Ch. 13 — Weigert S. No-cloning theorem. In Compendium of Quantum Physics, Springer (2009).
- Ch. 13 — Ortigoso J. Twelve years before the quantum no-cloning theorem. Am. J. Phys. 86, 201 (2018). arXiv:1707.06910 (abstract read)
- Ch. 13 — Hughes A.C., Srinivas R., Löschnauer C.M., Knaack H.M., Matt R., Ballance C.J., Malinowski M., Harty T.P., Sutherland R.T. Trapped-ion two-qubit gates with >99.99% fidelity without ground-state cooling. arXiv:2510.17286 (2025) (one pair of ions on a laboratory prototype) [authors include company staff]
- Ch. 13 — Landauer R. Is quantum mechanics useful? Phil. Trans. R. Soc. Lond. A 353, 367–376 (1995). doi:10.1098/rsta.1995.0106 (abstract read)
- Ch. 13 — Preskill J. Quantum computing: pro and con. Proc. R. Soc. Lond. A 454, 469–486 (1998). arXiv:quant-ph/9705032
- Ch. 13 — Haroche S., Raimond J.-M. Quantum computing: dream or nightmare? Physics Today 49(8), 51 (1996). doi:10.1063/1.881512
- Ch. 13 — Shor P.W. Scheme for reducing decoherence in quantum computer memory. Phys. Rev. A 52, R2493–R2496 (1995). doi:10.1103/PhysRevA.52.R2493 (not opened); the same scheme, with its failure probability, read in Shor P.W., Method for reducing decoherence in quantum computer memory, US Patent 5,768,297 (filed 26 Oct 1995; granted 16 Jun 1998). patents.google.com/patent/US5768297A
- Ch. 13 — Preskill J. Reliable quantum computers. Proc. R. Soc. Lond. A 454, 385–410 (1998). arXiv:quant-ph/9705031
- Ch. 14 — Luo Y., Ghose S., et al., Mutlu O. Using ECC DRAM to adaptively increase memory capacity. arXiv:1706.08870 (2017)
- Ch. 14 — Hamming R.W. Error detecting and error correcting codes. Bell Syst. Tech. J. 29, 147–160 (1950).
- Ch. 14 — Lindley D. Quantum Milestones, 1995: correcting quantum computer errors. Physics 18, 59 (2025). physics.aps.org/articles/v18/59 (secondary; publication date of Shor’s 1995 paper)
- Ch. 14 — Steane A.M. Error correcting codes in quantum theory. Phys. Rev. Lett. 77, 793 (1996). doi:10.1103/PhysRevLett.77.793
- Ch. 14 — Calderbank A.R., Shor P.W. Good quantum error-correcting codes exist. Phys. Rev. A 54, 1098 (1996). arXiv:quant-ph/9512032 (abstract read)
- Ch. 14 — Shor P.W. Fault-tolerant quantum computation. In Proc. 37th IEEE FOCS (1996). arXiv:quant-ph/9605011 (not opened)
- Ch. 14 — Aharonov D., Ben-Or M. Fault-tolerant quantum computation with constant error. In Proc. 29th ACM STOC, 176–188 (1997). arXiv:quant-ph/9611025
- Ch. 14 — Knill E., Laflamme R., Zurek W.H. Resilient quantum computation: error models and thresholds. Proc. R. Soc. Lond. A 454, 365–384 (1998). doi:10.1098/rspa.1998.0166; arXiv:quant-ph/9702058; and Accuracy threshold for quantum computation, arXiv:quant-ph/9610011 (1996)
- Ch. 14 — Kitaev A.Yu. Fault-tolerant quantum computation by anyons. Ann. Phys. 303, 2–30 (2003). doi:10.1016/S0003-4916(02)00018-0; arXiv:quant-ph/9707021 (1997)
- Ch. 14 — Fowler A., Bennett C.H., Keller S.P., Imry Y. Obituary: Rolf William Landauer. Physics Today 52(10), 104 (1999).
- Ch. 15 — Lacroix N., Bourassa A., Heras F.J.H., Zhang L.M., Bausch J., et al. Scaling and logic in the color code on a superconducting quantum processor. Nature 645, 614–619 (2025). doi:10.1038/s41586-025-09061-4; arXiv:2412.14256 (abstract read) [authors include company staff]
- Ch. 15 — Google Quantum AI and Collaborators. Demonstration of dynamic surface codes. Nat. Phys. (published online 17 Oct 2025). doi:10.1038/s41567-025-03070-w; arXiv:2412.14360 (not opened; read via Google Research blog, 13 Jan 2026) [authors include company staff]
- Ch. 15 — Sivak V., Morvan A., Broughton M., Cortiñas R.G., Bausch J., Senior A.W., et al. Reinforcement learning control of quantum error correction. Nature (2026). doi:10.1038/s41586-026-10759-2; arXiv:2511.08493 (read as arXiv v4; journal publication date of 8 Jul 2026 reported by a secondary source) [authors include company staff]
- Ch. 15 — Sivak V., Klimov P. Towards a quantum computer that learns from its errors. Google Research blog (22 Jul 2026). Manufacturer.
- Ch. 15 — He T., et al. (University of Science and Technology of China, Pan J.-W. group). Experimental quantum error correction below the surface code threshold via all-microwave leakage suppression. Phys. Rev. Lett. 135, 260601 (22 Dec 2025). doi:10.1103/rqkg-dw31 (paper not opened; title, authors and figures from the APS Viewpoint below)
- Ch. 15 — Emerson J. Plugging leaks in quantum computing. Physics 18, 200 (22 Dec 2025). physics.aps.org (APS Viewpoint on He et al.: distance-7 surface code on 97 qubits, 40 cycles, error suppression factor 1.4)
- Ch. 15 — Wang Y., Shen F., Xie H., Zhang A., Gao Y., et al. A superconducting surface-code processor with lattice-surgery logical operations. arXiv:2606.06598 (2026) (Zhejiang University; 125-qubit processor; runs with detected errors discarded)
- Ch. 15 — Lin W., Guo S., Ma Y., Yi Z., Zhang K., et al. Surface code logical operations on a superconducting quantum processor. arXiv:2607.01473 (2026) (University of Science and Technology of China with QuantumCTek and others; 107-qubit processor)
- Ch. 15 — Bluvstein D., Geim A.A., Li S.H., Evered S.J., et al., Lukin M.D. A fault-tolerant neutral-atom architecture for universal quantum computation. Nature 649, 39–46 (2026; online 10 Nov 2025). doi:10.1038/s41586-025-09848-5; arXiv:2506.20661 (preprint title: Architectural mechanisms of a universal fault-tolerant quantum computer) [authors include company staff]
- Ch. 15 — IBM. IBM delivers new quantum processors, software, and algorithm breakthroughs on path to advantage and fault tolerance (press release, 12 Nov 2025). newsroom.ibm.com. Manufacturer.
- Ch. 16 — Gidney C., Newman M., Brooks P., Jones C. Yoked surface codes. Nat. Commun. 16 (2025). doi:10.1038/s41467-025-59714-1; arXiv:2312.04522 (abstract read) [authors include company staff]
- Ch. 16 — Horsman D., Fowler A.G., Devitt S., Van Meter R. Surface code quantum computing by lattice surgery. New J. Phys. 14, 123011 (2012). doi:10.1088/1367-2630/14/12/123011 (abstract read)
- Ch. 16 — Bravyi S., Kitaev A. Universal quantum computation with ideal Clifford gates and noisy ancillas. Phys. Rev. A 71, 022316 (2005). doi:10.1103/PhysRevA.71.022316 (abstract read)
- Ch. 16 — Gidney C., Shutty N., Jones C. Magic state cultivation: growing T states as cheap as CNOT gates. arXiv:2409.17595 (2024) (abstract read) [authors include company staff]
- Ch. 16 — Bravyi S., Cross A.W., Gambetta J.M., Maslov D., Rall P., Yoder T.J. High-threshold and low-overhead fault-tolerant quantum memory. Nature 627, 778–782 (2024). doi:10.1038/s41586-024-07107-7 (abstract read) [authors include company staff]
- Ch. 16 — Wang K., Lu Z., Zhang C., et al., Deng D.-L. Demonstration of low-overhead quantum error correction codes. Nat. Phys. (2026). arXiv:2505.09684 (abstract read)
- Ch. 16 — IBM. IBM sets the course to build world’s first large-scale, fault-tolerant quantum computer at new IBM Quantum Data Center (press release, 10 Jun 2025); and IBM lays out clear path to fault-tolerant quantum computing (IBM Quantum blog, 10 Jun 2025). Manufacturer.
- Ch. 16 — Putterman H., Noh K., Hann C.T., MacCabe G.S., Aghaeimeibodi S., et al., Painter O. Hardware-efficient quantum error correction via concatenated bosonic qubits. Nature 638, 927–934 (2025). doi:10.1038/s41586-025-08642-7 (abstract read) [authors include company staff]
- Ch. 16 — Réglade U., Bocquet A., Gautier R., et al., Leghtas Z. Quantum control of a cat qubit with bit-flip times exceeding ten seconds. Nature 629, 778–783 (2024). arXiv:2307.06617 (abstract read; journal details partly unverified) [authors include company staff]
- Ch. 16 — Preskill J. Beyond NISQ: the megaquop machine. ACM Trans. Quantum Comput. (2025). arXiv:2502.17368
- Ch. 16 — Reichardt B.W., Paetznick A., Aasen D., Basov I., Bello-Rivas J.M., et al., Bloom B.J. Fault-tolerant quantum computation with a neutral atom processor. arXiv:2411.11822 (v1 18 Nov 2024, titled Logical computation demonstrated with a neutral atom quantum processor; v3 9 Jun 2025) (abstract read) [authors include company staff]
- Ch. 16 — Reichardt B.W., Aasen D., Chao R., Chernoguzov A., et al. Demonstration of quantum computation and error correction with a tesseract code. arXiv:2409.04628 (2024) [authors include company staff]
- Ch. 16 — Quantinuum. Introducing Helios: the most accurate quantum computer in the world (blog) and Quantinuum announces commercial launch of new Helios quantum computer (press release), 5 Nov 2025. Manufacturer.
- Ch. 16 — Roberts W., Eid C. Defining the logical qubit: five criteria to benchmark logical qubit claims. Alice & Bob (white paper, 5 Jun 2026). Manufacturer.
- Ch. 17 — Martinis J.M., Devoret M.H., Clarke J. Energy-level quantization in the zero-voltage state of a current-biased Josephson junction. Phys. Rev. Lett. 55, 1543–1546 (1985). doi:10.1103/PhysRevLett.55.1543 (published 7 Oct 1985; read via a university course-site copy)
- Ch. 17 — Hassinger S. (host), Martinis J.M. (guest). Macroscopic quantum tunneling with Nobel laureate John Martinis. The New Quantum Era, episode 71 (podcast transcript, 26 Nov 2025). podcast.newquantumera.com/71/transcript
- Ch. 17 — Nobel Prize Outreach. The Nobel Prize in Physics 2025 (summary page with the prize citation). nobelprize.org/prizes/physics/2025/summary
- Ch. 17 — Krinner S., Storz S., Kurpiers P., Magnard P., Heinsoo J., Keller R., Luetolf J., Eichler C., Wallraff A. Engineering cryogenic setups for 100-qubit scale superconducting circuit systems. EPJ Quantum Technol. 6, 2 (2019). arXiv:1806.07862
- Ch. 17 — Bluefors. How does a dilution refrigerator work? (14 Feb 2023). bluefors.com. Manufacturer.
- Ch. 17 — Wikipedia. Dilution refrigerator (accessed Oct 2026). en.wikipedia.org (secondary)
- Ch. 17 — Bluefors. KIDE cryogenic platform (product page, accessed 7 Oct 2026). bluefors.com. Manufacturer.
- Ch. 17 — Barends R., et al. Minimizing quasiparticle generation from stray infrared light in superconducting quantum circuits. Appl. Phys. Lett. 99, 113507 (2011). arXiv:1105.4642
- Ch. 17 — Suppression of quasiparticle poisoning to 10⁻¹¹ levels in superconducting qubits via infrared shielding. arXiv:2606.07339 (2026) (abstract read; authors not recorded)
- Ch. 17 — IBM. Quantum roadmap to 2033 and the Condor processor (IBM Quantum blog, 4 Dec 2023). ibm.com/quantum/blog/quantum-roadmap-2033. Manufacturer.
- Ch. 17 — IBM. Goldeneye cryogenic concept system (IBM Quantum blog, 8 Sep 2022). ibm.com/quantum/blog/goldeneye-cryogenic-concept-system. Manufacturer.
- Ch. 17 — Bardin J.C., et al., Martinis J.M. Design and characterization of a 28-nm bulk-CMOS cryogenic quantum controller dissipating less than 2 mW at 3 K. IEEE J. Solid-State Circuits 54, 3043–3060 (2019); and Google Research blog (21 Feb 2019) (abstract and blog read) [authors include company staff]
- Ch. 17 — Shresthamali S., Byun I., Tanimoto T., Uzawa Y., Inomata K., Yamamoto T., Inoue K. Revisiting thermal scalability for large-scale superconducting quantum systems. arXiv:2608.00990 (2026) (abstract read)
- Ch. 17 — Low Noise Factory. LNF-LNC4_8F cryogenic low-noise amplifier (product page, accessed 7 Oct 2026). lownoisefactory.com (noise temperature and bias, from which the power is computed). Manufacturer.
- Ch. 17 — Kawabata S. Integration and resource estimation of cryoelectronics for superconducting fault-tolerant quantum computers. arXiv:2601.03922 (2026)
- Ch. 17 — UC Berkeley Department of Physics. News item on the 2025 Nobel Prize in Physics (John Clarke; Michel Devoret, then a postdoctoral fellow; John Martinis, then a graduate student). physics.berkeley.edu (read 8 Oct 2026)
- Ch. 18 — Blais A., Huang R.-S., Wallraff A., Girvin S.M., Schoelkopf R.J. Cavity quantum electrodynamics for superconducting electrical circuits: an architecture for quantum computation. Phys. Rev. A 69, 062320 (2004). arXiv:cond-mat/0402216 (abstract read)
- Ch. 18 — Wallraff A., Schuster D.I., Blais A., Frunzio L., Huang R.-S., Majer J., Kumar S., Girvin S.M., Schoelkopf R.J. Strong coupling of a single photon to a superconducting qubit using circuit quantum electrodynamics. Nature 431, 162–167 (2004). doi:10.1038/nature02851 (abstract read)
- Ch. 18 — Quantum Machines. OPX1000 (product page, accessed 7 Oct 2026). quantum-machines.co. Manufacturer.
- Ch. 18 — Zurich Instruments. SHFQC+ qubit controller (product page, accessed 7 Oct 2026). zhinst.com. Manufacturer.
- Ch. 18 — Qblox. Product overview (documentation, accessed 7 Oct 2026). docs.qblox.com. Manufacturer.
- Ch. 18 — RCR Wireless. Report on Keysight’s quantum control system for AIST G-QuAT, Japan (30 Jul 2025). rcrwireless.com (secondary; reports the manufacturer’s figures)
- Ch. 18 — Motzoi F., Gambetta J.M., Rebentrost P., Wilhelm F.K. Simple pulses for elimination of leakage in weakly nonlinear qubits. Phys. Rev. Lett. 103, 110501 (2009). arXiv:0901.0534
- Ch. 18 — Macklin C., O’Brien K., Hover D., Schwartz M.E., Bolkhovsky V., Zhang X., Oliver W.D., Siddiqi I. A near-quantum-limited Josephson traveling-wave parametric amplifier. Science 350, 307–310 (2015). doi:10.1126/science.aaa8525 (abstract read)
- Ch. 18 — Spring P.A., Milanovic L., Sunada Y., Wang S., van Loo A.F., Tamate S., Nakamura Y. Fast multiplexed superconducting-qubit readout with intrinsic Purcell filtering using a multiconductor transmission line. PRX Quantum 6, 020345 (2025). doi:10.1103/PRXQuantum.6.020345 (abstract and RIKEN release read)
- Ch. 18 — Maurer T., Bühler M., Kröner M., Haverkamp F., Müller T., Vandeth D., Johnson B.R. Real-time decoding of the gross code memory with FPGAs. arXiv:2510.21600 (2025) (abstract read) [authors include company staff]
- Ch. 18 — Kelly J., O’Malley P., Neeley M., Neven H., Martinis J.M. Physical qubit calibration on a directed acyclic graph. arXiv:1803.03226 (2018) [authors include company staff]
- Ch. 19 — IonQ. IonQ completes acquisition of Oxford Ionics (press release, 17 Sep 2025). investors.ionq.com. Manufacturer.
- Ch. 19 — IonQ. IonQ launches Superion product line (press release, 8 Sep 2026, as reprinted by The Quantum Insider). Manufacturer.
- Ch. 19 — Chiu A., Trapp E.C., Guo J., Abobeih M., Stewart L., et al., Lukin M. Continuous operation of a coherent 3,000-qubit system. Nature 646, 1075–1080 (2025). doi:10.1038/s41586-025-09596-6; arXiv:2506.20660 (abstract read)
- Ch. 19 — Evered S.J., et al. High-fidelity parallel entangling gates on a neutral-atom quantum computer. Nature 622, 268–272 (2023). arXiv:2304.05420 [authors include company staff]
- Ch. 19 — Evered S.J., Xu M., Li S.H., Geim A.A., Bonilla Ataides J.P., Kalinowski M., Bluvstein D., Maskara N., Kokail C., Greiner M., Vuletić V., Lukin M.D. High-fidelity entangling gates and nonlocal circuits with neutral atoms. arXiv:2604.25987 (2026)
- Ch. 19 — Wang Y., Zhang Z., et al., Chen W., Zhai H. Trapping 11,000 atoms in a tweezer array generated by a single metasurface. arXiv:2606.02715 (2026) (abstract read)
- Ch. 19 — Bartolucci S., Birchall P., Bombín H., et al. Fusion-based quantum computation. Nat. Commun. 14, 912 (2023). doi:10.1038/s41467-023-36493-1 (abstract read) [authors include company staff]
- Ch. 19 — Aghaee Rad H., et al. Scaling and networking a modular photonic quantum computer. Nature 638, 912–919 (2025). doi:10.1038/s41586-024-08406-9 (abstract read) [authors include company staff]
- Ch. 19 — Intel. Tunnel Falls quantum computing research chip (newsroom, 15 Jun 2023). intel.com. Manufacturer.
- Ch. 19 — Steinacker P., Dumoulin Stuyck N., Lim W.H., et al., Dzurak A.S. Industry-compatible silicon spin-qubit unit cells exceeding 99% fidelity. Nature 646, 81–87 (2025). doi:10.1038/s41586-025-09531-9; arXiv:2410.15590 [authors include company staff]
- Ch. 19 — Bartee S.K., et al. Spin-qubit control with a milli-kelvin CMOS chip. Nature 643, 382–387 (2025). doi:10.1038/s41586-025-09157-x (abstract read) [authors include company staff]
- Ch. 19 — Microsoft. Microsoft’s Majorana 1 chip carves new path for quantum computing (Microsoft Source, 19 Feb 2025). Manufacturer.
- Ch. 19 — Microsoft Azure Quantum (Aghaee M., et al.). Interferometric single-shot parity measurement in InAs–Al hybrid devices. Nature 638, 651–655 (2025). doi:10.1038/s41586-024-08445-2 (abstract read) [authors include company staff]
- Ch. 19 — Ball P. Experts weigh in on Microsoft’s topological qubit claim. Physics 18, 57 (25 Feb 2025). physics.aps.org/articles/v18/57 (secondary; quotes the Nature peer-review file, which was not opened)
- Ch. 19 — Aghaee M., Alam Z., Andrzejczuk M., Antipov A., et al. 20 second parity lifetime in an InAs–Pb tetron device. arXiv:2606.03884 (2026) (abstract read; not peer reviewed) [authors include company staff]
- Ch. 19 — Legg H.F. On the robustness of topological gap detection via transport. Nature (24 Jun 2026). doi:10.1038/s41586-026-10567-8 (abstract read)
- Ch. 19 — Microsoft Quantum (Aghaee M., et al.). Reply to: On the robustness of topological gap detection via transport. Nature (24 Jun 2026). doi:10.1038/s41586-026-10568-7 (first paragraph read) [authors include company staff]
- Ch. 19 — University of St Andrews. Critique published by Nature challenges Microsoft’s quantum computing claims (news release, 24 Jun 2026). news.st-andrews.ac.uk
- Ch. 19 — D-Wave. D-Wave announces general availability of Advantage2 quantum computer (press release, 20 May 2025). Manufacturer.
- Ch. 20 — IBM. IBM makes quantum computing available on IBM Cloud to accelerate innovation (press release, 4 May 2016). newsroom.ibm.com. Manufacturer.
- Ch. 20 — IBM. IBM: a decade of quantum on the cloud (press release, 4 May 2026). newsroom.ibm.com. Manufacturer.
- Ch. 20 — DARPA. DARPA’s ‘landscape scan’ identifies companies targeting industrially useful quantum computers (news, 3 Apr 2025; updated 29 Apr and 9 Sep 2025). darpa.mil
- Ch. 20 — DARPA. DARPA selects two discrete utility-scale quantum computing approaches for evaluation (news, 6 Feb 2025). darpa.mil
- Ch. 20 — DARPA. Quantum Benchmarking Initiative: Stage B selection (6 Nov 2025). darpa.mil
- Ch. 20 — Quantum Computing Report. DARPA’s Quantum Benchmarking Initiative (QBI) advances with eleven teams moving to Stage B (6 Nov 2025) (secondary)
- Ch. 20 — DARPA. Quantum Benchmarking Initiative expands quest to separate hype from reality (news, 10 Mar 2026). darpa.mil
- Ch. 20 — Keysight. Quantum Control System (product page, accessed 7 Oct 2026). keysight.com. Manufacturer.
- Ch. 20 — Riverlane. Deltaflow (website, accessed 7 Oct 2026). riverlane.com. Manufacturer.
- Ch. 20 — Q-CTRL. Fire Opal and Boulder Opal (website, accessed 7 Oct 2026). q-ctrl.com. Manufacturer.
- Ch. 20 — Rigetti Computing. Rigetti announces general availability of 108-qubit system (7 Apr 2026); and second-quarter 2026 results, SEC exhibit 99.1 (6 Aug 2026). Manufacturer.
- Ch. 20 — Oxford Instruments. Sale of Oxford Instruments’ quantum business, NanoScience (10 Jun 2025). oxinst.com. Manufacturer.
- Ch. 20 — Quantum Design. Quantum Design acquires Oxford NanoScience (press release, as reprinted by The Quantum Insider, 5 Jan 2026). Manufacturer.
- Ch. 20 — IBM. IBM to acquire HRL Laboratories to power the future of quantum (press release, 23 Jul 2026). newsroom.ibm.com. Manufacturer.
- Ch. 20 — IonQ. IonQ to acquire SkyWater Technology (26 Jan 2026); IonQ completes acquisition of SkyWater Technology (31 Jul 2026) (press releases). Manufacturer.
- Ch. 20 — Haas H., McKay D., Davis R. Nighthawk r2. IBM Quantum blog (31 Aug 2026). ibm.com/quantum/blog/nighthawk-r2. Manufacturer.
- Ch. 20 — IBM. IBM connects its first modular cryogenic systems in milestone toward fault-tolerant quantum computing (press release, 19 Aug 2026). newsroom.ibm.com. Manufacturer.
- Ch. 20 — IBM. Quantum roadmap (IBM Technology Atlas, 2026 page, read 7 Oct 2026). ibm.com/roadmaps/quantum. Manufacturer.
- Ch. 20 — Google Quantum AI. Roadmap (read 7 Oct 2026). quantumai.google/roadmap. Manufacturer.
- Ch. 20 — Neven H. Building superconducting and neutral atom quantum computers. Google blog (24 Mar 2026). blog.google. Manufacturer.
- Ch. 20 — Google Research. A new era of innovation: Google Research at I/O 2026 (blog, 28 May 2026). research.google. Manufacturer.
- Ch. 20 — Alice & Bob. Alice & Bob unveils first quantum system, Helium (press release, June 2026, as reprinted by The Quantum Insider, 11 Jun 2026). Manufacturer.
- Ch. 20 — Quantum Computing Report. IQM launches Halocene product line to scale quantum error correction research (13 Nov 2025) (secondary)
- Ch. 20 — Fujitsu Ltd., RIKEN. Fujitsu and RIKEN develop world-leading 256-qubit superconducting quantum computer (press release, 22 Apr 2025); and Fujitsu, 2030: the year of practical quantum computing (web page dated 1 Jul 2026) and Japanese quantum research page (read 7 Oct 2026). Manufacturer.
- Ch. 20 — Xinhua. China unveils Tianyan-504 (as reprinted by the Chinese Academy of Sciences, 6 Dec 2024). english.cas.cn (secondary)
- Ch. 20 — Quantum Computing Report. Origin Quantum unveils Origin Wukong-180 fourth-generation quantum computer (14 May 2026); and China Daily (9 May 2026) (secondary)
- Ch. 20 — Quantinuum. Quantinuum announces pricing of upsized initial public offering (3 Jun 2026) and closing of upsized initial public offering (5 Jun 2026) (press releases). Manufacturer.
- Ch. 20 — Quantinuum Holdings, Inc. Form S-1/A registration statement. SEC EDGAR (26 May 2026). Manufacturer.
- Ch. 20 — Quantinuum. Quantinuum unveils accelerated roadmap to achieve universal, fully fault-tolerant quantum computing by 2030 (press release, 10 Sep 2024). Manufacturer.
- Ch. 20 — IonQ. Press releases on acquisitions: ID Quantique (completed 6 May 2025), Lightsynq (3 Jun 2025), Oxford Ionics agreement (9 Jun 2025), Capella Space (15 Jul 2025), Vector Atomic (7 Oct 2025). investors.ionq.com. Manufacturer.
- Ch. 20 — IonQ. Roadmap (web page, read 7 Oct 2026). ionq.com/roadmap. Manufacturer.
- Ch. 20 — QuEra Computing. QuEra announces 2028 fault-tolerant quantum computer and expanded multi-year strategic collaboration with AWS (press release, 15 Jun 2026). Manufacturer.
- Ch. 20 — Atom Computing. Atom Computing raises more than $300 million to accelerate deployment of fault-tolerant neutral-atom quantum computers (press release, 16 Jun 2026). Manufacturer.
- Ch. 20 — Quantum Computing Report. Denmark’s QuNorth to acquire 50-logical-qubit Magne quantum computer from Atom Computing and Microsoft (Jul 2025); and IEEE Spectrum, report on neutral-atom quantum computing (secondary)
- Ch. 20 — Quantum Computing Report. Pasqal and Bleichroeder Acquisition Corp. II file Form F-4 SEC registration for $2 billion public Nasdaq merger (30 Jun 2026) (secondary)
- Ch. 20 — Infleqtion; Churchill Capital Corp X. Infleqtion and Churchill Capital Corp X complete business combination (13 Feb 2026). Manufacturer.
- Ch. 20 — Infleqtion. Infleqtion achieves 30 entangled logical qubits on its Sqale quantum computer (press release and technical post, 24 Sep 2026). Manufacturer.
- Ch. 20 — PsiQuantum. PsiQuantum raises $1 billion to build million-qubit scale, fault-tolerant quantum computers (10 Sep 2025); breaks ground on America’s largest quantum computing project in Chicago (30 Sep 2025); breaks ground in Australia (18 Jun 2026) (press releases). Manufacturer.
- Ch. 20 — Crane Harbor Acquisition Corp. Form 8-K and release on shareholder approval of the business combination with Xanadu Quantum Technologies (19 Mar 2026). SEC EDGAR. Manufacturer.
- Ch. 20 — Nayak C. Majorana 2: Microsoft’s scalable quantum processor with reliable, long-lasting qubits. Microsoft Quantum blog (June 2026). quantum.microsoft.com. Manufacturer.
- Ch. 20 — Quantum Computing Report. D-Wave reports Q1 2026 results, record bookings and strategic expansion into gate-model systems (12 May 2026) (secondary)
- Ch. 20 — Press Information Bureau, Government of India. Cabinet approves National Quantum Mission (19 Apr 2023). pib.gov.in, PRID 1917888
- Ch. 20 — Press Information Bureau, Government of India. Parliament question: National Quantum Mission (NQM) (4 Feb 2026). pib.gov.in, PRID 2223187
- Ch. 20 — Press Information Bureau, Government of India. Parliament question: National Quantum Mission (12 Aug 2026). pib.gov.in, PRID 2298218
- Ch. 20 — The Quantum Insider. QpiAI launches 25-qubit superconducting system under India’s National Quantum Mission (15 Apr 2025) (secondary)
- Ch. 20 — CXO Digital Pulse. India unveils Kaveri, its most powerful 64-qubit quantum chip (4 Nov 2025) (secondary)
- Ch. 20 — Quantum Computing Report. QpiAI implements high-speed hardware decoder for 64-qubit Kaveri processor (25 Mar 2026) (secondary)
- Ch. 20 — Quantum Computing Report. IBM to commission one of India’s first physical quantum computers in Amaravati by September 2026 (3 Jul 2026); and Wikipedia, Amaravati Quantum Valley (secondary)
- Ch. 20 — Quantum Computing Report. D-Wave Quantum to acquire Quantum Circuits, Inc. (7 Jan 2026) and D-Wave finalizes $550 million acquisition of Quantum Circuits (20 Jan 2026). quantumcomputingreport.com (secondary, reporting company releases)
- Ch. 20 — Fierce Sensors. DARPA QBI Stage A selections, quoting Nord Quantique on Stage A and Stage B funding (3 Apr 2025) (secondary, reporting a company statement)
- Ch. 21 — Infleqtion. Infleqtion delivers the UK’s only operational 100-qubit quantum computing system at the National Quantum Computing Centre (press release, 15 Mar 2026, as reprinted by The Quantum Insider). Manufacturer.
- Ch. 21 — Berthusen N., Lavasani A., Benhemou A., et al., Potter A.C. Experimental validation of a compact fault-tolerant architecture for trapped ions. arXiv:2609.03194 (2026) (abstract read; not peer reviewed) [authors include company staff]
- Ch. 21 — Atom Computing and collaborators. Quantum error correction with the toric code. arXiv:2606.04079 (2026) (abstract read) [authors include company staff]
- Ch. 21 — Atom Computing. Atom Computing reveals quantum error correction with toric code (press release, 3 Jun 2026). Manufacturer.
- Ch. 21 — US Department of Energy, Office of Science. Energy Department announces initiative to create and deploy the world’s first scientifically relevant, fault-tolerant quantum computers (23 Jun 2026). energy.gov
- Ch. 21 — US Department of Energy, Office of Science. DOE launches competition to accelerate development of world’s first fault-tolerant quantum computer (17 Sep 2026). energy.gov
- Ch. 21 — IBM. IBM Fellow and quantum pioneer Charles H. Bennett receives A.M. Turing Award, computing’s highest honor (press release, 18 Mar 2026; read via the AAP/Cision copy). Manufacturer.
Take the PDF with you.
Reading online needs no sign-up. For the PDF edition, laid out for print and offline reading, tell us where to send it and we will email you.
Check your inbox.
The download link is on its way to your email. If it has not arrived in a few minutes, check your spam folder or write to info@unplex.tech.
Preview only — nothing was sent
Let's Talk