We are not in the prediction business, mostly because most predictions about technology are embarrassing in retrospect, but the start of the year is a useful prompt to look at the shape of the next twelve months and call out the things that are already in motion and likely to land, which is a different exercise from claiming to know what is going to surprise us. So here is what we think is going to actually happen, in order from most likely to least.
1. The agentic AI stack collapses into a few real patterns
The number of credible agentic products shipped in 2025 was north of 200, and the number of agentic use cases that actually saved the operator time was a small fraction of the 200. The next twelve months are going to see the survivors figure out which 5 to 10 use cases actually work in their environment, and the losers are going to keep demoing agents that cannot reliably call three tools in a row. The pattern that wins is going to look less like a chatbot with a tool belt and more like a worker with a queue, a budget, and a manager.
The reliable patterns we expect to see: code review agents that read a 2,000-line diff and produce a structured comment, with a 60 to 70 percent accuracy on real bugs. Research agents that pull 20 sources and produce a 2-page brief, with the human reviewer spending 15 minutes instead of 3 hours. Data pipeline agents that handle the schema drift, the rate limit, the retry logic, the part the human was spending 80 percent of the time on.
The unreliable patterns we expect to see: agents that do multi step customer service, agents that handle novel reasoning, agents that make decisions the user is going to regret, agents that operate in fast moving environments. The marketing will continue to sell the unreliable patterns as the reliable ones, until the buyers stop buying.
2. Passkey adoption crosses the halfway mark
Passkeys crossed the 30 percent mark for the top 1000 sites in 2025, and the curve continues upward. The standards are settled, the platforms support them, the password managers sync them. The friction that was the reason the adoption was slow in 2024 (the user education, the device recovery, the cross device sync) is being solved in 2025 and 2026. The sites that do not have the passkey support by the end of 2026 are going to be the sites that the security team is going to have to defend in the audit.
3. The post quantum migration stops being optional
NIST published the first three post quantum standards in 2024, and the major browsers have shipped the post quantum key exchange. The migration from RSA and ECDH to ML-KEM is going to start in earnest in 2026, and the organisations that handle the long lived secrets (the financial services firms, the government contractors, the certificate authorities) are going to be the first to migrate. The organisations that do not migrate are going to be the organisations the harvest now, decrypt later attackers are going to read in 2034.
4. The AI regulation becomes the bottleneck
The EU AI Act is in force. The state level AI laws in California, Colorado, and New York are biting. The sector specific regulators are issuing guidance at a pace the legal teams are struggling to keep up with. The bottleneck on the AI deployment in 2026 is going to be the legal and compliance review, not the engineering capacity. The engineering teams that have built the model card, the data lineage, the bias testing, and the human review into the development workflow are the teams that are going to ship. The engineering teams that are still treating the regulatory work as something that happens at the end of the project are the teams that are going to be stuck.
5. The open source funding crisis becomes acute
The xkcd cartoon about the unpaid maintainer is, in 2026, no longer a joke. The funding crisis in the open source supply chain has been building for a decade, and the crisis is now acute. The maintainers of the critical packages are burning out, the companies that depend on the packages are not contributing, and the foundations that are supposed to bridge the gap are running on fumes. The engineering teams that depend on the open source supply chain need to be planning for the day a critical maintainer walks away, because the day is going to come.
6. Cloud cost optimisation becomes a first class discipline
Cloud cost has been growing faster than cloud revenue for three years, and the gap is finally getting the executive attention it deserves. The FinOps movement, which started as a niche community in 2019, is now a board level conversation in any enterprise with a meaningful cloud bill. The new piece in 2026 serves as the AI workload cost: the GPU instances, the inference endpoints, the vector databases, the data egress for the training pipelines. The teams that have built the cost attribution into the platform are the teams that are going to survive the conversation.
7. The post EDR security stack takes shape
The endpoint detection and response category has matured to the point where the question is no longer whether to buy an EDR but which one, and the interesting action has moved up the stack. Cloud detection and response, identity threat detection and response, SaaS security posture management, the various flavours of XDR are the categories where the consolidation is happening now. The vendor landscape is going to be very different in 2027 than it was in 2025.
8. The year of the boring infrastructure
After three years of the AI hype, the enterprises that have shipped the AI projects are starting to pay attention to the boring infrastructure the AI projects depend on. The Kubernetes platform, the observability stack, the identity and access management, the network segmentation. The boring infrastructure is where the operational debt has been accumulating, and the operational debt is starting to bite. 2026 serves as the year a lot of engineering teams are going to stop adding new capabilities and start paying down the debt.
9. The compliance framework consolidates
SOC 2, ISO 27001, PCI DSS, HIPAA, the CMMC, the various state privacy laws, the EU regulations, the sector specific frameworks. The number of frameworks the average enterprise has to comply with has been growing, and the cost of the compliance has been growing with it. The 2026 trend runs as the consolidation: the frameworks are starting to align, the audits are starting to accept each other’s results, and the tooling is starting to automate the cross framework mapping. The compliance team of 2026 is going to be smaller than the compliance team of 2024, and the compliance team of 2026 is going to be more effective.
10. The data residency problem becomes real
The EU regulations, the data sovereignty concerns, the geopolitical shifts, the customer contracts. The data residency problem has been a theoretical concern for the last decade, and the data residency problem is now a practical concern. The engineering teams that have built the data residency into the platform from day one are the teams that are going to be able to serve the customers that have the data residency requirements, and the customers with the data residency requirements are the customers that are going to be the most valuable to serve.
11. The supply chain attack surface expands
Codecov, SolarWinds, 3CX, xz utils. The supply chain attack surface is not getting smaller, and the supply chain attack surface continues to expand. The mitigation (the signed artifacts, the reproducible builds, the SBOMs, the SLSA compliance) is going to start mattering in 2026, and the customers that are going to require the SLSA compliance are going to be the customers that the engineering teams have to serve.
12. The platform engineering team becomes the default
Every enterprise of meaningful size is going to have a platform engineering team by the end of 2026, and the platform engineering team is going to be the team that owns the developer experience, the deployment pipeline, the observability, the security baseline. The platform engineering team serves as the team that is going to free the application teams to do the application work, and the platform engineering team amounts to the team that is going to make the engineering organisation scalable.

The bottom line
The patterns the post covers have been showing up in production for long enough that the patterns have names, the failures, the mitigations, the gaps. The work the security team and the engineering team and the operations team are quietly doing today sits as the work that decides whether the practice the post names sits as a tool the team uses or a liability the team is paying for.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.


