TL;DR: Passkey awareness is broadening, with 75% of global consumers recognizing them and 28% enabling them whenever possible, while 45% of organisations have deployed them in at least one app and 87% still rely on passwords for customer-facing authentication, according to FIDO Alliance and Descope. The gap is no longer about demand; it is about whether identity teams can modernise authentication without breaking existing customer journeys.
Editorial analysis by NHI Mgmt Group, based on content published by Descope: “Passkey Trends for 2026: What the Data Says”.
By the numbers:
- 45% of organisations have deployed passkeys in at least one app.
- 87% of organisations still use passwords for customer-facing auth.
Key questions
Q: How should organisations roll out passkeys without breaking customer login flows?
A: Start with journeys that already tolerate fallback, such as signup, account recovery, and step-up authentication.
Q: Why do passkey programmes stall after an initial rollout?
A: They stall when users cannot see the credential at the right moment, when stale credentials still appear, or when failures make the method seem unreliable.
Q: What are the signs that passkey adoption is not working well enough?
A: Warning signs include low enrollment rates, repeated login failures, heavy reliance on password fallback, and support demand around device changes or account recovery.
Practitioner guidance
- Map customer authentication journeys Inventory every customer sign-in, signup, recovery, and step-up path before introducing passkeys so you can see where passwords still anchor the experience.
- Start with lower-stakes flows Pilot passkeys in signup, account recovery, or step-up authentication first, where you can measure adoption and failure patterns without disrupting the primary login path.
- Define fallback rules explicitly Document where passwords, OTPs, or magic links remain acceptable and what conditions trigger them, so hybrid authentication does not quietly become permanent password dependence.
Bottom line: Passkeys are gaining traction, but customer IAM readiness still lags because most organisations have not fully reworked the journeys that depend on passwords.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passkey adoption is now constrained by operating model maturity, not user demand. Consumers are ready to use passkeys, and many organisations have started deployment, but that does not mean customer IAM programmes are ready to absorb them cleanly. The real constraint is whether identity teams can rework enrollment, recovery, and step-up flows without leaving passwords as the hidden control plane. The practitioner conclusion is that adoption metrics alone do not equal readiness.
A few things that frame the scale:
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Should customer IAM teams keep passwords as a fallback when deploying passkeys?
A: Yes, in most environments they should keep controlled fallback paths during migration, but those paths need explicit boundaries. The goal is to reduce password dependence over time, not to let fallback methods become the permanent primary control for customer authentication.
👉 Read our full editorial: Passkey adoption is rising, but customer IAM readiness lags