7 MIN READ
We are not in the prediction business, mostly because most predictions about technology are embarrassing in retrospect, but the start of the year is a useful prompt to look at the shape of the next twelve months and call out the things that are already in motion and likely to land. This is a different exercise from claiming to know what is going to surprise us. So here is what we think is going to actually happen, in order from most likely to least.
1. The agentic AI stack collapses into a few real patterns
More than 200 credible agentic products shipped in 2025, and only a small fraction of those use cases actually saved the operator time. The next twelve months are going to see the survivors figure out which 5 to 10 use cases actually work in their environment, and the losers are going to keep demoing agents that cannot reliably call three tools in a row. The pattern that wins is going to look less like a chatbot with a tool belt and more like a worker with a queue, a budget, and a manager.
The reliable patterns we expect to see: code review agents that read a 2,000-line diff and produce a structured comment. Research agents that pull 20 sources and produce a 2-page brief, with the human reviewer spending 15 minutes instead of 3 hours. Data pipeline agents that handle the schema drift, the rate limit, and the retry logic, leaving the human to do the part that actually needs judgement.
The unreliable patterns we expect to see: agents that do multi step customer service, agents that handle novel reasoning, agents that make decisions the user is going to regret, agents that operate in fast moving environments. The marketing will continue to sell the unreliable patterns as the reliable ones, until the buyers stop buying.
2. Passkey adoption crosses the halfway mark
Passkeys crossed the 30 percent mark for the top 1000 sites in 2025, and the curve continues upward. The standards are settled, the platforms support them, and the password managers sync them. The friction that slowed adoption in 2024 (the user education, the device recovery, the cross device sync) is being solved in 2025 and 2026. The sites without passkey support by the end of 2026 are the sites the AppSec team is going to have to defend in the audit.
3. The post quantum migration stops being optional
NIST published the first three post quantum standards in 2024, and the major browsers have shipped the post quantum key exchange. The migration from RSA and ECDH to ML-KEM is going to start in earnest in 2026, and the organisations that handle the long lived secrets (financial services, government contractors, certificate authorities) are going to be the first to move. The organisations that do not move are the ones the harvest now, decrypt later attackers are going to read in 2034.
4. The AI regulation becomes the bottleneck
The EU AI Act is in force. The state level AI laws in California, Colorado, and New York are biting. The sector specific regulators are issuing guidance at a pace the legal teams are struggling to keep up with. The bottleneck on AI deployment in 2026 is going to be the legal and compliance review, not the engineering capacity. The engineering orgs that have built the model card, the data lineage, the bias testing, and the human review into the development workflow are the ones that are going to ship. The ones still treating the regulatory work as something that happens at the end of the project are the ones that are going to be stuck.
5. The open source funding crisis becomes acute
The xkcd cartoon about the unpaid maintainer is, in 2026, no longer a joke. The funding crisis in the open source supply chain has been building for a decade, and the crisis is now acute. The maintainers of the critical packages are burning out, the companies that depend on the packages are not contributing, and the foundations that are supposed to bridge the gap are running on fumes. Engineering orgs that depend on the open source supply chain need to be planning for the day a critical maintainer walks away, because the day is going to come.
6. Cloud cost optimisation becomes a first class discipline
Cloud cost has been growing faster than cloud revenue for three years, and the gap is finally getting the executive attention it deserves. The FinOps movement, which started as a niche community in 2019, is now a board level conversation in any enterprise with a meaningful cloud bill. The new piece in 2026 is the AI workload cost: the GPU instances, the inference endpoints, the vector databases, the data egress for the training pipelines. The engineering orgs that have built the cost attribution into the platform are the ones that are going to survive the conversation.
7. The post EDR security stack takes shape
The endpoint detection and response category has matured to the point where the question is no longer whether to buy an EDR but which one, and the interesting action has moved up the stack. Cloud detection and response, identity threat detection and response, SaaS security posture management, the various flavours of XDR are the categories where the consolidation is happening now. The vendor landscape is going to be very different in 2027 than it was in 2025.
8. The year of the boring infrastructure
After three years of the AI hype, the enterprises that have shipped the AI projects are starting to pay attention to the boring infrastructure the AI projects depend on. The Kubernetes platform, the observability stack, the identity and access management, the network segmentation. The boring infrastructure is where the operational debt has been accumulating, and the operational debt is starting to bite. 2026 is the year a lot of engineering orgs are going to stop adding new capabilities and start paying down the debt.
9. The compliance framework consolidates
SOC 2, ISO 27001, PCI DSS, HIPAA, the CMMC, the various state privacy laws, the EU regulations, the sector specific frameworks. The number of frameworks the average enterprise has to comply with has been growing, and the cost of the compliance has been growing with it. The 2026 trend is consolidation: the frameworks are starting to align, the audits are starting to accept each other’s results, and the tooling is starting to automate the cross framework mapping. The compliance team of 2026 is going to be smaller than the compliance team of 2024, and more effective.
10. The data residency problem becomes real
The EU regulations, the data sovereignty concerns, the geopolitical shifts, the customer contracts. The data residency problem has been a theoretical concern for the last decade, and is now a practical concern. The engineering orgs that have built the data residency into the platform from day one are the ones that are going to be able to serve the customers that have the data residency requirements, and those customers are the ones that are going to be the most valuable to serve.
11. The supply chain attack surface expands
Codecov, SolarWinds, 3CX, xz utils. The supply chain attack surface is not getting smaller, and continues to expand. The mitigation (the signed artifacts, the reproducible builds, the SBOMs, the SLSA compliance) is going to start mattering in 2026, and the customers that are going to require SLSA compliance are the ones the engineering orgs have to serve.
12. The platform engineering team becomes the default
Every enterprise of meaningful size is going to have a platform engineering team by the end of 2026, and that team is going to own the developer experience, the deployment pipeline, the observability, and the security baseline. Platform engineering is the function that frees the application teams to do the application work, and the function that makes the engineering organisation scalable.

The bottom line
Twelve predictions, twelve things already in motion. The agentic stack, passkeys, post quantum, the open source bill, the data residency problem. The org that is still treating 2026 like 2023 is the one that will spend the year explaining why the dashboard shows what it shows.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



