Google Willow: 105 Qubits, Below-Threshold Error Correction, and the Long Road to Quantum Relevance

Why Willow Matters
Google Willow was announced December 9, 2024 with 105 superconducting physical qubits. The headline: it demonstrated below-threshold quantum error correction across surface code distances 3, 5, and 7. Each step up in code distance cut the logical error rate roughly in half. This is the critical scientific milestone the quantum computing field has been pursuing since the mid-1990s.
What "Below Threshold" Means
Quantum error correction works only if the underlying physical qubits operate below a technology-specific error threshold (roughly 1 percent for the surface code on superconducting qubits). Above threshold, adding more qubits makes things worse. Below threshold, adding qubits exponentially reduces logical error.
For years, quantum computers operated above threshold in practice. Willow is the first superconducting system to convincingly demonstrate below-threshold operation at distances 3, 5, and 7.
What Willow Did Not Do
Willow did not:
- Break any cryptography.
- Run Shor's algorithm on any real-world key.
- Produce more than one logical qubit.
- Achieve the logical error rate needed for fault-tolerant Shor (roughly 10^-10 per logical gate).
Willow demonstrated a single logical qubit with logical error rate around 10^-3 to 10^-4 depending on code distance. That is good progress; it is not a CRQC.
The Random Circuit Sampling Benchmark
Willow's paper included a Random Circuit Sampling (RCS) benchmark claiming the circuit would take roughly 10 septillion years to simulate classically. This benchmark is:
- Real: measures quantum-advantage on a contrived problem.
- Not cryptographically useful: RCS does not run Shor.
- Contested: classical simulation algorithms keep improving; some academic analyses suggest the specific circuit might be simulable faster than Google's estimate.
Resource Estimate Implications
Willow confirms the surface code scaling story. Extrapolating responsibly:
- To reach logical error 10^-10 (needed for Shor on RSA-2048), we need surface code at approximately distance 25.
- Distance 25 requires approximately 1,250 physical qubits per logical qubit.
- Shor's algorithm needs thousands of logical qubits.
- Total: several million physical qubits. Gidney and Ekera 2021 estimate ~20 million at current error rates.
Willow's 105 qubits is, by this accounting, roughly five orders of magnitude short of a CRQC. What Willow changed is the feasibility: we now have empirical evidence that scaling up works. It did not change the arithmetic of how much scaling is needed.
Google's Broader Quantum Program
Google Quantum AI has operated since 2012 at the Santa Barbara lab. Prior milestones:
- Sycamore (October 2019): 53 qubits used, 54 physical. First RCS quantum supremacy claim, Nature 574:505.
- Willow (December 2024): 105 qubits with below-threshold QEC, Nature s41586-024-08449-y.
Google has publicly stated goals of scaling to a fault-tolerant, utility-scale quantum computer by 2029-2030 (aspirational).
Willow and Post Quantum Cryptography
Google is simultaneously the world's largest deployer of PQC:
- Chrome X25519Kyber768 hybrid: shipped experimental August 2023.
- Chrome X25519MLKEM768 default: shipped November 2024 (Chrome 131) across tens of billions of TLS handshakes.
- Google internal infrastructure (ALTS): uses PQ hybrid since 2023 on sensitive internal channels.
The same company racing toward CRQC is urgently protecting its own traffic with PQC. This is a clear signal for everyone else.
Frequently Asked Questions
When was Google Willow announced?
December 9, 2024 via Google blog and Nature paper s41586-024-08449-y. 105 superconducting qubits demonstrating below-threshold quantum error correction across surface code distances 3, 5, and 7.
Did Willow break any cryptography?
No. Willow ran Random Circuit Sampling, a contrived benchmark. It did not run Shor's algorithm on any real cryptographic parameters.
Is Willow closer to a CRQC than IBM Condor?
In terms of error correction quality, yes. Willow demonstrated the surface code works as theory predicts. IBM Condor has more physical qubits but has not shown equivalent below-threshold results. Both are still orders of magnitude from a CRQC.
What does Willow mean for my PQC migration?
It confirms the quantum threat is real and the surface code path to CRQC is feasible. It does not change migration urgency from before: migrate to Post Quantum Cryptography on the NIST FIPS 203/204/205 timeline.
Sources
Related Articles
- Quantum Error Correction
- Logical vs Physical Qubits
- IBM Quantum
- CRQC Explained
- Quantum Supremacy vs CRQC
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.
Try QNSQYOriginally published at quantumsequrity.com/blog/google-quantum-willow-chip.