Open problems are running out
Terence Tao calls open math problems a non-renewable resource. Why AI mining them threatens encryption, AI safety benchmarks, and how to respond.
Terence Tao, a Fields Medalist and one of the most prolific mathematicians alive, made an observation in 2024 that most people racing to build AI systems walked right past: open mathematical problems are a non-renewable resource, and AI has started mining them.
His point was not that AI solving math is bad. It’s that the supply is finite. A hard open problem - the Riemann Hypothesis, the twin prime conjecture, the assumed hardness of factoring large numbers - takes decades or centuries of human effort to pose in a form that’s both precise and deep. There are not that many of them. When you burn one as a demo or a benchmark, you don’t get it back. And the process that generates new ones is slow, human, and theory-driven in a way that mining is not.
That framing matters well beyond pure math. A surprising amount of the security infrastructure you use every day is a bet that a specific list of open problems stays open. If AI is now an extraction machine pointed at that list, the people running cybersecurity and AI safety need to treat those problems the way an oil economy treats proven reserves: a stock that depletes, not a spring that refills.
Why solved problems don’t grow back
Think about where new math problems come from. They aren’t dug out of the ground. They emerge when humans build a theory, and the theory generates questions the theory itself can’t yet answer. Number theory produced the questions about how primes are distributed. Cryptography as a field produced the question of whether factoring is truly hard. The problem is a byproduct of understanding.
An AI that solves an open problem by searching an enormous space of proof steps - without producing the surrounding theory - consumes the problem without replacing the machinery that made it. Tao’s non-renewable framing is precise here. Oil took geological time to form and minutes to burn. Open problems take intellectual generations to form and, potentially, one training run to burn.
This is why “AI will just generate new problems” is not a reliable answer. Posing a well-formed, genuinely hard, genuinely useful open problem is itself one of the hardest things mathematicians do, and there is no evidence yet that it automates the way solving does.
The problems holding up your encryption
Here is the part that turns an abstract math concern into an operational one. Most public-key cryptography - the encryption protecting your bank session, your messages, your software updates - rests on a handful of problems being computationally hard.
RSA, still everywhere, rests on the difficulty of factoring large numbers. Break factoring and RSA-2048 falls. Elliptic-curve cryptography, which secures most modern TLS handshakes and a lot of messaging, rests on the elliptic-curve discrete logarithm problem. The post-quantum schemes NIST standardized in 2024 - ML-KEM, formerly Kyber, and ML-DSA, formerly Dilithium - rest on the hardness of structured lattice problems.
None of these are proven hard. We have no proof that factoring requires exponential time. We have decades of very smart people failing to find a fast algorithm, and we’ve decided that failure is strong enough evidence to encrypt the world on top of it. That’s not a criticism; it’s just what the assumption is. Cryptographic security is a standing bet that a short list of open problems will stay unsolved.
What mining looks like as an attack
You don’t need artificial general intelligence to make this a problem. You need a system that searches algorithmic space faster than humans do.
The history of cryptanalysis is a history of incremental algorithmic wins. Factoring got dramatically faster with the quadratic sieve and then the general number field sieve. Discrete logs fell to index calculus. Each was a human insight that moved a problem from “impossible” to merely “expensive.” An AI that can propose, test, and refine candidate algorithms at machine speed is, functionally, a compression of that history. If it turns a discovery that would have taken the field fifteen years into one that takes eight months, the reserve of still-hard problems drains faster than any patch cycle can respond.
DeepMind’s systems already point in this direction. AlphaProof reached medal-level performance on International Mathematical Olympiad problems in 2024. AlphaEvolve has been used to find improved algorithms for concrete problems. None of these has broken a cryptographic assumption. The relevant question for a defender is not whether they have, but how much of the gap between “olympiad problem” and “cryptographic hardness result” is time rather than kind.
The benchmark you’re about to lose
AI safety has its own exposure here, and it’s less obvious. To know whether a system is getting dangerously capable, you measure it against hard problems it shouldn’t be able to solve yet. Hard open math problems are among the cleanest yardsticks we have, because you can’t memorize a solution to something no one has solved.
Mining destroys the yardstick. Epoch AI built FrontierMath specifically because older benchmarks were saturated - models were scoring near the ceiling, so the numbers stopped meaning anything. The moment a hard problem is solved and the solution enters a training set, it stops measuring reasoning and starts measuring recall. Every problem consumed as a capability demo is a ruler you can’t use again. You are spending your measurement instruments to generate press releases.
For safety work, that’s backwards. The whole point of a hard benchmark is to give you advance warning of a capability jump. If the benchmarks burn as fast as the capabilities grow, you lose the warning at exactly the moment you need it.
The audit gap
There is a second safety problem underneath the first. Security doesn’t only depend on problems being hard. It depends on humans understanding why they’re hard, so we can tell when a claimed break is real.
When a human breaks a cipher, the field can inspect the argument, reproduce it, and understand which assumption failed. If an AI produces a factoring algorithm or a lattice attack through a search process no human followed, you get the result without the understanding. Now you have a claimed break you can’t fully audit and can’t easily rederive, and you can’t cleanly tell whether the system is right about what it found. In a domain where the entire trust model rests on “we understand why this is safe,” a capability that produces answers faster than explanations is a governance problem, not just a technical one.
What to actually do about it
This is not a reason to panic, and it’s not a claim that RSA falls next quarter. It’s a reason to change how you account for cryptographic risk. Treat hardness assumptions as depreciating assets with an unknown and shortening life.
Inventory what you trust. You cannot manage crypto risk you can’t see. Build a real inventory of where RSA, ECC, and specific key sizes live in your systems - TLS termination, code signing, VPNs, hardware roots of trust. Most organizations can’t name these, which is the same failure Evan Francen points at: nobody owns the risk.
Get crypto-agile before you need to. The organizations that survive an algorithmic break are the ones that can swap a primitive without re-architecting. That means putting cryptographic primitives behind interfaces now, so a future migration is a configuration change and not a rewrite.
Adopt hybrids, and assume harvest-now-decrypt-later is already happening. Adversaries are recording encrypted traffic today to decrypt when the underlying problem falls, whether by quantum computer or by algorithm. Hybrid schemes that combine a classical and a post-quantum algorithm - already deployed in Chrome and Signal - force an attacker to break both.
Stop spending your benchmarks. If you do evaluation or safety work, keep a reserve of hard, private, uncontaminated problems that never touch a training set or a public leaderboard. A benchmark you’ve published is a benchmark you’ve already partly spent.
Fund the theory, not just the solve. Tao’s underlying point is that the renewable part of mathematics is human understanding - the theory-building that generates new problems and lets us audit solutions to old ones. In security terms, that’s the ability to know why something is safe. A pipeline that only optimizes for solving, and never for understanding, drains the reserve and removes the instrument you’d use to notice.
The uncomfortable version of all this: the security of a large part of the digital world was quietly premised on the idea that certain problems are hard because humans, working at human speed, hadn’t cracked them. That premise was always a bet on the rate of discovery. AI changes the rate. The problems were always finite. We just never had to treat them as a resource we could run out of.
Keep Reading
cybersecurityA helpful AI agent cannot be a private one
Meta's Muse personal AI agent is only useful because it reads your messages, contacts, and habits. What that access costs your privacy and safety.
data governanceThe Open Courts Act exposes what PACER fees hid
PACER's per-page fee was an accidental privacy brake. Making court records free is right - but only if redaction, governed bulk access, and security replace it.
distributed systems1994's eight fallacies hit AI agents harder
The eight fallacies of distributed computing turn 21, and autonomous AI agents make every one of those architectural assumptions more dangerous.
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.