Looking Back at February in Tech

A look back at February 2026 in tech, with the seven stories that actually mattered, the ones that looked like they mattered but did not, and the throughline that connects them.

A single brass sundial on a dark wood surface, dim warm amber side light, deep navy shadows, no people visible.

February 2026 in tech was, in the end, mostly a month of consolidation rather than a month of disruption. The model releases that the trade press was expecting did not land. The regulatory moves that the policy people were expecting did land. The breaches that the security people were dreading landed in roughly the volume the security people were expecting. The trade press had a quiet month, the security teams had a busy month, and the engineering teams had a productive month. This amounts to the month in seven stories.

Editorial photo of a calendar page for February 2026 with three dates circled in red ink and a single yellow sticky note attached, dark wood desk.
February 2026 in seven stories, with the ones that mattered and the ones that just looked like they did.

Story one: the regulatory tempo picked up

The biggest story of the month was the regulatory tempo. The US administration’s executive order on artificial intelligence safety, signed in the second half of January, started to show up in the implementation timeline, with the federal contractors being told to start the NIST AI Risk Management Framework adoption in February. The EU AI Act implementation timeline continued to move, with the major member states publishing their guidance for the high risk systems classification. The UK Information Commissioner’s Office published its first round of guidance for the AI related data protection failures, and the ICO guidance was notably more aggressive than the trade press was expecting.

The regulatory tempo sits as the throughline for the year. The regulatory tempo continues to the thing the executive is asking about, and the compliance team continues to the thing the compliance team is being asked about. The teams that are doing this well are the ones that have already started the compliance work, and the teams that are doing this poorly are the ones that are still waiting for the guidance to settle.

Story two: the supply chain attacks kept coming

The supply chain attacks of February were dominated by the continued exploitation of edge device vulnerabilities. The Fortinet, Ivanti, and Palo Alto devices continued to be the highest value targets, with the threat actors compromising the devices within hours of a CVE being published, and the threat actors maintaining persistence on the devices for weeks before the compromise was detected. The pattern was the same as the last several months, and the pattern was the one the security teams have been warning about for the last two years.

The interesting story of the month was the npm package registry. Two of the top 100 packages were compromised through the maintainer account takeover, and the compromised packages were distributed to the downstream consumers within the usual update cycle. The pattern was the same as the xz utils backdoor, the pattern was the same as the event stream incident, and the pattern is not going away. The pattern is going to keep happening, and the pattern sits as the one the security teams have to plan for.

Story three: the agentic tools started to ship in production

The agentic coding tools started to ship in production at the major technology companies. Cursor, Claude Code, and the in editor Copilot all shipped the autonomous background worker feature, and the feature started to be adopted by the engineering teams that were the early adopters of the previous generations of the tools. The productivity numbers from the early adopters were mixed, the productivity numbers were the subject of the usual internal debate, and the productivity numbers are the numbers the rest of the industry is going to be looking at for the rest of the year.

The interesting development of the month was the emergence of the agentic security tool. The security operations centres that had been using the AI assisted detection and response tools started to roll out the agentic version, and the agentic version started to take on the triage, the investigation, and the response for the low severity incidents. The early numbers from the SOCs that had rolled out the agentic version were promising, and the early numbers are the numbers the rest of the SOC industry is going to be looking at.

Story four: the passkey adoption kept climbing

The passkey adoption continued to climb, with the major consumer platforms reporting that more than half of the new account creations in February used a passkey rather than a password. The number is up sharply from the prior year, the number amounts to the number the trade press had been expecting, and the number serves as the number the password manager vendors have been quietly working against. The password manager vendors are still relevant, the password manager vendors are still the right answer for the password based accounts that the user already has, and the password manager vendors are not going away.

The enterprise passkey adoption amounts to the slower story, and the enterprise passkey adoption sits as the one the security teams have been pushing for. The enterprise passkey adoption is complicated by the legacy systems, by the service accounts, and by the regulatory requirement for the multi factor authentication. The enterprise passkey adoption continues to, the enterprise passkey adoption continues to the story for the rest of the year, and the enterprise passkey adoption sits as the one the security teams should be tracking.

Story five: the ransomware payment rate kept falling

The Sophos State of Ransomware 2024 put the proportion of victims who paid the ransom at 29 percent, down from 46 percent in 2022. The trend continued in the first quarter of 2026, with the Coveware quarterly data showing the average payment holding steady in the low to mid six figures, and the proportion of victims who refused to pay anything continuing to climb. The reason amounts to the obvious one: better backups, worse decryptors, and the OFAC sanctions regime that has been making the payment itself a federal offence in the United States.

The story is not the headline number. The story is what is sitting underneath. The story becomes the negotiation length, the recovery cost, the insurance carrier position, and the regulatory framework. The story stands as the part of the incident that nobody puts in the press release, and the story becomes the part of the incident that the executive is going to be asking about in the board meeting.

Story six: the cloud cost optimisation kept getting harder

The cloud cost optimisation story of February was the story of the egress fees, the AI workload costs, and the storage tier mismatch. The egress fees continued to be the most expensive surprise, the egress fees continued to be the surprise the architecture team had not accounted for, and the egress fees continued to be the surprise the finance team was being asked to explain to the board. The AI workload costs continued to climb, the AI workload costs continued to be the line item that was growing the fastest, and the AI workload costs continued to be the line item the finance team was being asked to predict.

The storage tier mismatch continued to be the silent killer. The storage tier mismatch counts as the workload that is on the most expensive storage tier but does not need to be, the storage tier mismatch serves as the workload that the operations team has not had time to audit, and the storage tier mismatch counts as the workload that is paying the most expensive rate for the least expensive requirement.

Story seven: the open source funding model kept struggling

The open source funding model continued to struggle. The major foundations continued to be underfunded, the major foundations continued to be the subject of the public conversation about the sustainability of the model, and the major foundations continued to be the organisations that were the most likely to receive the funding cuts from the major corporate sponsors.

The interesting development of the month was the rise of the corporate backed open source foundation. The Linux Foundation, the Apache Foundation, and the Cloud Native Computing Foundation all reported increased corporate sponsorship. The corporate backed model counts as the model that is working, the corporate backed model stands as the model that is going to keep working, and the corporate backed model stands as the model the open source community is going to have to live with.

The bottom line

February 2026 was a month of consolidation rather than disruption. The regulatory tempo picked up, the supply chain attacks kept coming, the agentic tools started to ship, the passkey adoption kept climbing, the ransomware payment rate kept falling, the cloud cost optimisation kept getting harder, and the open source funding model kept struggling. The throughline becomes the same as the throughline for the last several months: the technology is moving, the threats are moving, the regulatory environment is moving, and the teams that are doing this well are the ones that are moving with them.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading