Security features usually arrive with a story attached. Someone found a flaw, someone exploited it, a patch followed. You can point at the thing that went wrong.
The Pixel 11 ships with a defense against something that has never happened, using a machine nobody has built. Google put a new security chip in all four models, the Titan M3, and the headline feature is that it meets the post-quantum cryptography standards the US National Institute of Standards and Technology finalized in 2024. It is the first Google phone to do so.
It would be easy to file that under marketing. It is not, and the reason has less to do with quantum computers than with a promise Google made about how long this phone will keep working.
The short version
- Titan M3 is a separate chip, not part of Tensor G6. It stores keys, verifies the boot chain and runs Google’s trusted operating system.
- It is in all four Pixel 11 models, not just the expensive ones.
- Quantum safe secure boot uses ML-DSA, NIST’s post-quantum signature standard, inside Android Verified Boot.
- The driver is the seven year support promise. A phone sold in 2026 is still receiving updates in 2033, past the date NIST wants RSA and elliptic curve retired.
- It holds Common Criteria certification at the level used for SIM cards and bank cards.
- It does not make your messages quantum safe. That is a different problem with a different solution, and Apple and Signal got there first.
The problem is not the quantum computer. It is the archive.
No one has built a quantum computer capable of breaking the encryption your phone uses. Serious estimates for when one might appear cluster loosely around 2030 and later, and plenty of people think that is optimistic.
That sounds like a problem for 2030. It is not, because of a strategy the security world calls harvest now, decrypt later.
An attacker who cannot read your encrypted traffic today can still record it. Storage is cheap and patience is free. If the traffic is recorded in 2026 and a capable machine arrives in 2032, everything captured in the intervening years becomes readable at that moment. The encryption did not fail. It simply expired while the data was still sensitive.
What Titan M3 actually is
It is a physically separate chip, which is the part most coverage skips past.
Your phone’s main processor, the Tensor G6 in this case, runs everything: apps, the operating system, the camera pipeline, the machine learning models. It is enormous, complicated and therefore impossible to fully verify. Titan M3 is the opposite. It is small, it is tamper resistant, and it does a short list of jobs.
It holds cryptographic keys so that the main processor never has to. It checks that the phone booted software Google actually signed. It enforces the delay after a wrong PIN, which is what stops someone from simply guessing a four digit code a million times. And it runs Trusty, Google’s trusted execution environment, which handles the operations that must stay isolated from Android itself.
The certification is worth a sentence. Titan M3 holds Common Criteria certification at the assurance level used for SIM cards and bank payment cards. That is not a marketing badge. It means an independent lab spent a long time attacking the hardware, including with physical access, and documented what it took.
Worth knowing
Google put Titan M3 in all four Pixel 11 models rather than reserving it for the Pro tier. Security features are the one category where segmenting the lineup is genuinely indefensible, and Google has avoided it here. The same cannot be said of the hardware, where the notification light came back only on the Pro models.
Signatures, not secrets
Here is the distinction that most explanations of this feature get wrong, and it changes what the feature is for.
NIST published two main post-quantum standards in 2024. ML-KEM handles key establishment, which is the encryption side, the part that matters for harvest now, decrypt later. ML-DSA handles digital signatures, which is about proving that something came from who it claims to have come from.
Quantum safe secure boot uses ML-DSA. Android 17 moves Android Verified Boot toward it, and the Pixel 11 is the first Google phone to use post-quantum signatures for that chain. It is not protecting your recorded traffic. It is protecting the phone’s ability to tell genuine Google software from a forgery.
| ML-KEM | ML-DSA | |
|---|---|---|
| Job | Agreeing on an encryption key | Proving who signed something |
| Protects against | Recorded traffic being opened later | Forged software being accepted |
| Urgency | Immediate, data is being collected now | Matters when the device is still alive later |
| Used by Pixel 11 for | Key storage and protected operations | Verified Boot, the headline feature |
Why does forgery matter in 2033 and not now? Because signature schemes break retroactively in a specific way. If someone can eventually derive the private key behind today’s signing algorithm, they can produce a boot image your phone will happily accept as genuine. A device still in service at that point, dutifully verifying updates with an algorithm that no longer means anything, is worse than a device with no verification at all, because it reports that everything is fine.
Seven years is the actual argument
Google promises seven years of operating system updates on the Pixel 11. Ship in 2026 and you are committing to a device still in the field in 2033.
Now put that next to the migration schedule. NIST has set 2030 as the deprecation date for RSA and elliptic curve cryptography and 2035 as the date they are disallowed entirely. The NSA’s CNSA 2.0 requires quantum resistant algorithms in new national security acquisitions from January 2027.
Read it that way and the feature stops looking speculative. Google is not predicting that a quantum computer will arrive in 2030. It is acknowledging that a phone it sells today will still be under warranty of a sort when the rest of the industry is being told to move on, and that retrofitting a boot chain on a device already in someone’s pocket is close to impossible.
This is the unglamorous reality of long support commitments. Seven years of updates is a genuinely good thing for buyers, and it quietly forces the manufacturer to make decisions about 2033 while designing a phone in 2025.
Google is late to the broader idea
Post-quantum cryptography on phones did not start here, and it is worth being clear about that.
Signal added PQXDH in late 2023, becoming the first large messaging platform to give new conversations post-quantum protection at key establishment. Apple followed in early 2024 with PQ3 in iMessage, which went further by applying post-quantum cryptography to the ongoing message exchange rather than only the initial handshake, with keys rotating at least every seven days.
| Where | Arrived | What it covers |
|---|---|---|
| Signal, PQXDH | Late 2023 | Initial key agreement for new chats |
| Apple, PQ3 | iOS 17.4, 2024 | Key agreement plus ongoing messages |
| Google, Titan M3 | Pixel 11, 2026 | The boot chain and hardware key storage |
These are not competing with each other. Signal and Apple secured conversations. Google secured the device the conversation happens on. A phone with perfect messaging encryption running forged firmware is not secure, and neither is a phone with a flawless boot chain running a messenger with expired cryptography. Both layers need doing, and the industry is doing them in a fairly sensible order.
What it does not fix
An honest accounting, because the phrase “post-quantum” is about to appear on a great many spec sheets where it means considerably less.
Your web browsing is not made quantum safe by this chip. That depends on the servers you connect to and the browser you use, and most of the internet is still on classical cryptography. Your apps are not covered either. A messaging app that uses old key exchange is exactly as vulnerable on a Pixel 11 as anywhere else. Data you already sent is beyond help, which is the whole cruelty of harvest now, decrypt later.
And none of it addresses the mundane ways phones actually get compromised. Post-quantum secure boot does nothing about a malicious app, a phishing page, a reused password, or a flaw in a component the chip does not govern. Those remain, by an enormous margin, the likelier thing to happen to you. The Android ecosystem spent this year dealing with exactly that sort of problem when a modem flaw let a single video call reach the kernel on millions of budget phones, and no amount of quantum resistant signing would have helped.
So does it matter to you
Today, almost certainly not in any way you will feel. Nothing about your phone behaves differently, and no attacker is currently decrypting anything of yours with a quantum computer.
It matters in the way that building codes matter. You do not notice the reinforcement in a wall until the one time it is needed, and by then it is too late to add it. Cryptographic migrations take a decade because every device, server and protocol has to move, and the ones that cannot be updated in the field have to ship correct on day one.
There is also a practical caveat. All of this rides on Android 17, and the Pixel 11 has it because Pixels always do. The wider Android world moves considerably slower, as we found when we looked at how Android 17 had been out since June and still had not reached most phones in use. Whatever Google has built here will take years to become normal across the ecosystem, and plenty of phones sold this year will never get it at all.
The bottom line
Titan M3 is a quiet, well judged piece of engineering that solves a problem nobody is experiencing yet, and it is in every Pixel 11 rather than only the expensive ones.
The marketing will oversell it, because “quantum” is an irresistible word and most readers will come away believing their messages are now safe from a future supercomputer. They are not. What is protected is the chain that decides whether the phone is running Google’s software or somebody else’s, and that protection is aimed at a device that will still be answering calls in 2033.
That is a boring thing to put on a box. It is also the correct thing to have built, and the only moment it could have been built was before the phone shipped.

