7 MIN READ
February 2026 was a quieter month than the trade press wanted. The model releases the analysts had pencilled in did not land. The regulatory work the policy people had pencilled in did. The breach volume the security people had been dreading landed at roughly the rate the security people had been expecting. Of those, the one that is the throughline for the year is not the one the trade press was hoping for.

Story one: the regulatory tempo picked up
The US executive order on AI safety, signed in the second half of January, started to land in the implementation timeline. Federal contractors were told to begin the NIST AI Risk Management Framework adoption in February. The EU AI Act timeline continued to move, with the major member states publishing their guidance for the high risk systems classification. The UK Information Commissioner’s Office published its first round of AI related data protection guidance, and the ICO guidance was notably more aggressive than the trade press had been expecting.
None of that is the part the executive is going to be asking about yet. The part that will land on the board agenda is the audit cycle, the procurement checklist, and the second order policy work that arrives once the guidance settles. The compliance teams that started the work in February are the ones who will not be playing catch up in the second half. The ones who are still waiting for the guidance to settle are the ones who will be.
Story two: the supply chain attacks kept coming
Edge device exploitation kept paying off, with Fortinet, Ivanti, and Palo Alto devices remaining the highest value targets. Attackers compromised them within hours of a CVE being published and sat on the access for weeks before anyone noticed. Same playbook as the last several months, same one the security teams have been warning about for the last two years.
The more interesting story of the month was on the npm package registry. Two of the top 100 packages were compromised through a maintainer account takeover, and the malicious versions were distributed to downstream consumers within the usual update cycle. The lineage here is the one anyone paying attention already knows: xz utils in 2024, event stream in 2018, both maintainer takeovers, both downstream compromise inside the standard update window. The pattern is not going away, and any security team that is not treating the package registry as a primary attack surface is the one that is going to learn the lesson the hard way.
Story three: the agentic tools started to ship in production
Cursor, Claude Code, and the in editor Copilot all shipped the autonomous background worker feature in February. The early adopters, mostly engineering teams that had already standardised on the previous generation, started to roll it out at scale. Productivity numbers from those early cohorts were mixed, the usual internal debate about whether the numbers are real was in full swing, and the rest of the industry is going to spend the rest of the year watching the data roll in.
The more interesting development of the month was on the security side. SOCs that had been running AI assisted detection and response for the last eighteen months started to roll out the agentic version, and the agentic version started to take on the triage, the investigation, and the response for the low severity incidents. The early numbers from those SOCs are the numbers the rest of the industry is going to be looking at. If they hold, the analyst headcount conversation in 2027 is going to be a different conversation than the one in 2025.
Story four: the passkey adoption kept climbing
More than half of the new account creations on the major consumer platforms in February used a passkey rather than a password. That is sharply up from a year ago, which is what the trade press had been expecting, and which is exactly what the password manager vendors have been quietly working against. The vendors are still relevant because passkeys do not cover the password based accounts the user already has, and they do not cover the shared accounts, the service accounts, or the long tail of internal tools, so the password manager market is not going away even if it is no longer the growth story it was three years ago.
Enterprise passkey adoption is the slower story, and the reason is the legacy systems, the service accounts, and the regulatory requirement for multi factor authentication that the passkey stack does not yet cover for every workflow. Security teams pushing on this in February are the ones who will be ready for the audit cycle in the second half. The ones waiting for the stack to mature are the ones who will be explaining the gap to the board in November.
Story five: the ransomware payment rate kept falling
Sophos put the proportion of victims who paid at 29 percent in 2024, down from 46 percent in 2022. The trend continued in the first quarter of 2026, with Coveware quarterly data showing the average payment holding steady in the low to mid six figures and the proportion of victims who refused to pay anything continuing to climb. The reason is the obvious one: better backups, worse decryptors, and the OFAC sanctions regime that has been making the payment itself a federal offence in the United States.
The interesting number is not the headline. The real story is the negotiation length, the recovery cost, the insurance carrier position, and the regulatory framework that the executive is going to be asking about in the board meeting. That is the part of the incident nobody puts in the press release, and the part that ends up deciding whether the next breach is survivable.
Story six: the cloud cost optimisation kept getting harder
Egress fees were the most expensive surprise of the month, again. Architecture teams that had not built the cross cloud movement into the model are the ones now trying to explain a five figure line item to the finance team. AI workload costs kept climbing, and finance teams that had been pencilling in flat growth are the ones now trying to predict the actual trajectory for the board. The line item that is growing the fastest is the one that is hardest to forecast, which is the part of cloud cost work that has not gotten any easier in three years.
The storage tier mismatch is the silent killer. Workloads on the most expensive tier that do not need to be, audited by operations teams that have not had time to audit them, paying the highest rate for the lowest requirement. The fix is unglamorous, the work is dull, and the saving is usually the largest single line item on the monthly bill. Any finance team that is not running the tier audit on a quarterly cadence is the one that will be writing the variance explanation in November.
Story seven: the open source funding model kept struggling
The major open source foundations remained underfunded. The public conversation about the sustainability of the model continued, and the funding cuts from the major corporate sponsors kept landing on the foundations that had been relying on them.
The more interesting development of the month was the rise of the corporate backed model. The Linux Foundation, the Apache Foundation, and the Cloud Native Computing Foundation all reported increased corporate sponsorship, and the corporate backed model is the only one currently working. It is also the one the open source community is going to have to live with, because the alternative is fewer foundations and slower upstream maintenance. Neither outcome is great, but only one of them is one the enterprise can plan around.
The bottom line
February 2026 was the month the model release calendar slowed down and everything else did not. The regulatory tempo is the throughline, the supply chain attacks are the pattern, the agentic tools are the question, and the passkey adoption is the proof that the slow move still moves. The teams that are doing this well are not the ones with the biggest models. They are the ones treating the regulatory work, the supply chain risk, and the credential story as production problems rather than slide deck problems.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



