I suspect we might move to some sort of cipher that uses the AES round function but isn't full AES, like AEGIS, for performance benefits. Same permutation, but arguably a different primitive. That move won't be because AES got broken though, it'd be because AES wasn't as fast as desired.