Noah MitchellVIEW PROFILE →
The Slow Death of the Password: Passkeys Hit 5 Billion but Struggle to Finish the Job
The FIDO Alliance estimates 5 billion passkeys are now in use, and 68 percent of organisations are deploying them. Passkeys log in successfully 93 percent of the time versus 63 for passwords, yet most services still keep passwords, and platform lock-in slows a truly passwordless future.
The humble password has been the weakest link in online security for decades. In 2026, its long awaited replacement is finally arriving at scale, as passkeys spread across the internet, though the transition is proving far messier than its champions had hoped.
Billions of passkeys, already
The scale of the shift is now hard to dismiss. The FIDO Alliance, the industry body behind the technology, estimates that around 5 billion passkeys are already in use worldwide, a remarkable figure for a standard still relatively early in its life.
Businesses are moving quickly too. According to a 2026 industry report, some 68 per cent of organisations are already deep into deployment, whether they are piloting, rolling out or fully integrating passkeys across their workforce.
What a passkey actually is

For the uninitiated, a passkey replaces the familiar typed password with something far harder to steal. Instead of a string of characters, it relies on a cryptographic key stored on a device and unlocked with a fingerprint, a face scan or a PIN.
That design closes off a whole class of attacks. Because there is no password to phish, to guess or to leak in a data breach, passkeys strip away the single most common route that criminals use to break into online accounts.
Consumers are warming up
Ordinary users are increasingly on board. Some 69 per cent of consumers now have passkeys enabled on at least a few of their accounts, a sign of how quickly the technology has moved from novelty toward something like normality.
Uptake varies sharply by country, however. Enablement rates reach 88 per cent in China and India, 77 per cent in the United Kingdom, 70 per cent in Germany and 64 per cent in France, reflecting different habits and different device platforms.
Turning that on is not the same as using it. Only about 49 per cent of consumers actually use passkeys whenever possible or most of the time, exposing a real gap between having the option enabled and genuinely relying on it day to day.
The numbers make the case
Where passkeys are used, the results are striking. They log people in successfully about 93 per cent of the time, compared with roughly 63 per cent for traditional passwords, which are so often forgotten, mistyped or reset by frustrated users.
Organisations feel the benefit as well. On average, those deploying passkeys report a 73 per cent reduction in sign in time and an 81 per cent drop in login related support tickets, easing a costly and persistent burden on help desks.
Users notice the difference too. Among the benefits people report are greater confidence in their security, faster logins and, importantly for the security world, a meaningful reduction in the phishing incidents that plague passwords.
Why the password refuses to die
For all the momentum, the old password is proving stubborn. Most services still require a traditional password alongside a passkey, which means the underlying attack surface has not actually shrunk as much as the headlines might suggest.
True passwordless security demands more. It requires removing passwords entirely rather than simply offering passkeys as an extra option, a step many companies have been reluctant to take for fear of locking frustrated users out of their accounts.
A walled garden problem
There is a final catch that frustrates many. A passkey created on an Apple, Google or Microsoft device is often locked into that company's own credential manager, making it hard to carry across platforms and leaving the dream of a truly seamless, password free internet still just out of reach.






