The question comes up in every first meeting: if post-quantum cryptography is coming to every browser and VPN, why would anyone install optical hardware? It is a fair question with a boring answer. The two protect against different things.
Different foundations
Post-quantum cryptography replaces the mathematics. Its security rests on problems believed to be hard for both classical and quantum computers. Believed is the operative word: these are young schemes, and the history of cryptanalysis is not kind to young schemes.
Quantum key distribution replaces the assumption. Its security rests on the behaviour of physical systems under measurement, not on the difficulty of a computation. No advance in algorithms changes it.
Different failure modes
A post-quantum scheme fails through analysis: someone publishes a paper and the scheme is gone overnight, retroactively, for every message ever sent with it. A QKD system fails through implementation: a detector behaves unexpectedly, a component drifts, a side channel appears. Those failures are local, visible in the monitoring, and fixable in the field.
Why hybrid is the sensible default
Combining a post-quantum key exchange with a QKD-derived key means an attacker has to defeat both. It costs almost nothing in a modern encryptor, and it removes the need to bet on either technology being flawless.
What this means for planning
Post-quantum cryptography goes everywhere, because it is software and it scales to every endpoint. QKD goes where the data is long-lived and the route is fixed: between data centres, along backbone routes, into facilities that hold records which must stay secret for decades. The two are complementary by construction.