PLAIN QUANTUM
← All articles
Reality check · Part 4 of 5

What quantum computers are good at (and what they aren't)

On this page
  1. Why only some problems?
  2. 1. Simulating nature
  3. 2. Factoring, and why security people care
  4. 3. Search: helpful, but modest
  5. 4. Optimisation and AI: still being tested
  6. 5. What about finance?
  7. Who's building them?
  8. The catch: today's machines are noisy
  9. So when will it be useful?
  10. Five questions for any quantum headline
  11. Sources and further reading

Quantum computers aren't faster computers. They're different computers, and the difference only pays off on certain kinds of problem. On most everyday tasks a quantum computer would be slower, more expensive and less reliable than the laptop you're reading this on. Knowing which problems are the exceptions is the quickest way to see through most quantum headlines.

Strong candidates
  • Simulating molecules and materials
  • Factoring large numbers
  • Some search and sampling problems
  • Certain physics and maths research
Stays on ordinary computers
  • Email, browsing, video, games
  • Spreadsheets and databases
  • Most everyday business software
  • Jobs that need huge amounts of data loaded in
The rough split. The left column is where researchers expect real advantage; the right column gains little or nothing.

Why only some problems?

Parts 1 to 3 gave us the tools to answer this. A quantum computer holds a huge number of amplitudes, but you can only read out one result per run. So it only helps when a problem has a hidden structure that lets an algorithm make wrong answers cancel and right ones reinforce.

Most everyday computing has no such structure to exploit. Opening a document, adding up a column of numbers or streaming a video is already easy for ordinary chips, and there's nothing for interference to speed up. Quantum advantage lives in a handful of problem types where nature, or mathematics, happens to have the right shape.

1. Simulating nature

This was the original idea. In 1981 the physicist Richard Feynman pointed out that nature is quantum, so the natural way to simulate it is with a quantum machine. Molecules are hard for ordinary computers because of the doubling problem from Part 2: each extra electron that interacts with the others multiplies the work. Chemists get around this today with clever approximations, but for some molecules the approximations break down exactly where it matters.

A quantum computer can represent those electrons with qubits that follow the same rules. That could help in several areas:

  • Fertiliser. The industrial process that makes ammonia for fertiliser uses roughly 1–2% of the world's energy. Some bacteria do the same job at room temperature using an enzyme that chemists still can't fully model. Researchers have identified it as a target for future quantum simulation.
  • Batteries. Designing better battery materials means understanding how electrons behave inside new compounds, which is the kind of calculation quantum machines suit.
  • Medicines. Simulating how a drug molecule binds to a protein could, in time, cut down on trial and error. This is further off than marketing suggests; most drug discovery problems aren't limited by this kind of calculation alone.

Simulation is the application many researchers consider most likely to deliver real value first, because the problem is quantum to begin with.

2. Factoring, and why security people care

In 1994 the mathematician Peter Shor showed that a large enough quantum computer could find the prime factors of huge numbers dramatically faster than any known ordinary method.

Factoring sounds academic. Multiplying two large prime numbers is easy; splitting the result back into its two primes is extraordinarily hard. For numbers of the size used in encryption, hundreds of digits long, the best known ordinary methods are estimated to need far longer than the age of the universe. Much of today's internet security relies on exactly that difficulty, and Shor's algorithm also breaks a related problem used in elliptic-curve cryptography.

Shor's algorithm works because factoring has a hidden repeating pattern, and quantum interference is very good at finding repeating patterns. This is the single biggest reason governments and banks pay attention to quantum computing. Part 5 is all about it.

3. Search: helpful, but modest

In 1996 Lov Grover found a quantum algorithm for searching through unsorted possibilities. Where an ordinary computer might need a million checks, a quantum computer needs roughly the square root: about a thousand.

That sounds dramatic, but it's a square-root speed-up, not magic. Each quantum step is far slower and more expensive than an ordinary one, and the error correction we'll discuss below adds more overhead. For many practical search problems the gain shrinks or disappears once you count those costs. Grover's main real-world effect so far is on security: it's the reason experts recommend longer keys for some encryption, such as 256-bit AES instead of 128-bit.

4. Optimisation and AI: still being tested

Logistics, scheduling, portfolio optimisation and machine learning appear in a lot of quantum marketing. They're real areas of research, and some companies are running experiments on real hardware. But clear, proven advantages over the best ordinary methods are not established yet.

There are two reasons for caution. First, ordinary optimisation software is very good and keeps improving, so the bar keeps rising. Second, there's a data problem that rarely makes the headlines.

Quantum machine-learning algorithms often look exponentially fast because they store data in amplitudes. Twenty qubits carry about a million amplitudes, so in principle a million numbers fit in twenty qubits. But that cuts both ways. Getting a million numbers into those amplitudes can take as long as the speed-up saves, and the efficient "quantum memory" many algorithms quietly assume doesn't exist yet at scale. Getting the answer out is limited too: measurement gives you samples, not the whole result, so you can usually only extract a summary such as an average.

That leaves three questions worth asking of any quantum AI or finance claim: how does the data get in, how does the answer get out, and is the problem well-behaved enough for the maths to deliver? The honest answers often shrink the advantage, sometimes to nothing.

You'll also see "quantum annealers", machines built specifically for optimisation problems. They work differently from the general-purpose quantum computers this series describes, and whether they beat ordinary methods on useful problems is still debated.

Treat bold claims about quantum AI or quantum optimisation with healthy suspicion until someone shows a fair comparison against the best ordinary methods.

5. What about finance?

Banks and insurers are among the most active early explorers of quantum computing, so it's worth a closer look. Three ideas come up most often.

Risk simulation. Banks estimate risk by running huge numbers of random scenarios, a technique called Monte Carlo simulation, often overnight on large computing clusters. A quantum method called amplitude estimation can, in theory, reach the same accuracy with far fewer runs: roughly the square root of the number needed today. That could turn an overnight job into something closer to real time. The catch is the same as for search: it needs large, error-corrected machines to beat today's highly tuned systems.

Portfolio optimisation. Choosing the best mix of thousands of assets under many constraints is a hard optimisation problem. Quantum approaches are being tested, but as above, no clear advantage over the best classical methods has been shown yet.

Security. This is the one with a real deadline, because quantum computers threaten the cryptography that protects payments. Ironically, it's the area where finance needs to act soonest, even though it's about defending against quantum computers rather than using them.

Several large banks have published research on these topics and run experiments on real hardware. The honest summary is that finance is a likely early customer once machines mature, but today's work is exploration and preparation, not production.

Who's building them?

There isn't one quantum computer design; there are several competing ones, and it's not yet clear which will win. Large technology companies such as IBM and Google build superconducting chips cooled close to absolute zero. Others, including Quantinuum and IonQ, use individual trapped atoms held by electric fields. Newer companies use neutral atoms arranged by lasers, or particles of light travelling through chips. Each approach trades off speed, error rates and how easily it scales. That variety is healthy: if one approach hits a wall, others may not. It also means comparing announcements across companies is tricky, because a qubit in one design isn't directly equivalent to a qubit in another.

The catch: today's machines are noisy

The qubits in current machines are fragile and make errors, roughly one mistake every few hundred to few thousand operations on the best hardware. Useful algorithms like Shor's need billions of operations. Without a fix, errors would swamp the answer long before the end.

The fix is error correction: combining many physical qubits so they act as one reliable "logical" qubit. That multiplies the hardware needed, often by hundreds of physical qubits per logical qubit. The physicist John Preskill coined a name for today's era in 2018: NISQ, for "noisy intermediate-scale quantum". Machines are big enough to be interesting but too noisy for the famous algorithms.

This is why estimates for the machine needed to break today's encryption are so large. A 2025 estimate from Google researcher Craig Gidney put breaking 2048-bit RSA at under a million noisy qubits running for less than a week. That's far beyond today's machines. But it's around twenty times smaller than his own estimate from 2019, which needed about twenty million. Better algorithms and better error correction keep bringing the target closer. The direction of travel is why people are preparing now.

So when will it be useful?

Nobody knows exactly, and anyone who gives you a precise year is guessing. A reasonable summary of where things stand:

  • Now: machines with up to hundreds or low thousands of physical qubits, used mainly for research and experiments. Demonstrations of "quantum advantage" exist, but mostly on problems chosen to suit quantum hardware rather than problems anyone needs solved.
  • Next: the first error-corrected logical qubits working together. Several major companies publish roadmaps aiming at useful, error-corrected machines around the end of this decade.
  • Later: machines large enough to break today's public-key encryption. No such machine exists today, and credible experts' estimates for when one might range widely. Treat any confident date, early or late, as a guess.

That uncertainty cuts both ways. It's too early to expect quantum computers to transform your business. It's not too early to prepare for the one thing they're expected to break.

Five questions for any quantum headline

  1. Was the problem useful, or chosen because it's easy for a quantum machine?
  2. Was it compared against the best ordinary methods, or a weak baseline?
  3. Are they counting physical qubits or error-corrected logical qubits?
  4. Has anyone independent checked the result?
  5. Is the source a peer-reviewed paper or a press release?

There's a full guide to these questions, with real examples, in the library: How to read a "quantum breakthrough" headline.

Three things to remember
  • Quantum computers are specialists. Simulating nature and factoring are the strongest cases.
  • Search gets a modest square-root speed-up. Optimisation and AI gains are still unproven.
  • Noise is the main obstacle, and it's why useful machines need many more qubits than today's.

Sources and further reading

Tags show what kind of source each one is. A standard or government guidance is an official document; a peer-reviewed paper has been checked by other experts; a preprint has not been peer-reviewed yet; an experiment reports a real-world demonstration; a company announcement is the company's own account. Dates and figures were checked against these sources on 11 October 2026. Spotted an error? Email hello@plainquantum.com and it will be corrected, with a note.

  1. Peer-reviewed paperSimulating physics with computersRichard Feynman, International Journal of Theoretical Physics, 1982
  2. Peer-reviewed paperPolynomial-time algorithms for prime factorization and discrete logarithms on a quantum computerPeter Shor, SIAM Journal on Computing, 1997
  3. Peer-reviewed paperA fast quantum mechanical algorithm for database searchLov Grover, STOC, 1996
  4. Peer-reviewed paperElucidating reaction mechanisms on quantum computers (nitrogen fixation)Reiher et al., PNAS, 2017
  5. Peer-reviewed paperQuantum speedup of Monte Carlo methodsAshley Montanaro, Proceedings of the Royal Society A, 2015
  6. Peer-reviewed paperQuantum algorithm for linear systems of equations (HHL)Harrow, Hassidim and Lloyd, Physical Review Letters, 2009
  7. Peer-reviewed paperRead the fine printScott Aaronson, Nature Physics, 2015
  8. Peer-reviewed paperQuantum Computing in the NISQ era and beyondJohn Preskill, Quantum, 2018
  9. Peer-reviewed paperHow to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubitsCraig Gidney and Martin Ekerå, Quantum, 2021
  10. PreprintHow to factor 2048 bit RSA integers with less than a million noisy qubitsCraig Gidney, 2025