Passkeys went mainstream. Here’s what changes.

Five billion passkeys, default sign-in at Microsoft and Google, and new NIST guidance. How passkeys work, why they beat passwords, and what they mean for the AI era.

For decades the password was the front door to our digital lives — and the weakest part of it. Passwords get reused, guessed, phished and leaked in bulk. In the last two years that has finally started to change, and faster than most people noticed.

The numbers: passkeys are now normal

On World Passkey Day in May 2026, the FIDO Alliance — the industry body behind the standard — reported that around five billion passkeys are in use worldwide. Its State of Passkeys 2026 research, covering 11,000 consumers and 1,400 enterprise decision-makers in ten countries, found:

  • 90% of people are now aware of passkeys;
  • 75% have enabled a passkey on at least one account;
  • 68% of organisations have deployed or are deploying passkeys for employee sign-in.

The biggest platforms have moved too. Google made passkeys the default sign-in option for personal accounts in October 2023. Microsoft made brand-new consumer accounts passwordless by default from May 2025. And in the US, NIST's updated Digital Identity Guidelines (SP 800-63-4, finalised in 2025) bring syncable passkeys explicitly into scope.

How a passkey works, in plain English

A passkey is a pair of cryptographic keys created for one website or app:

  • The private key stays on your device (or in your device's encrypted keychain). It never leaves, and the website never sees it.
  • The public key is stored by the website. On its own it's useless to an attacker.

When you sign in, the site sends a random challenge, your device signs it with the private key after you unlock it with your fingerprint, face or PIN, and the site checks the signature with the public key. No secret is ever typed, sent or stored on the server.

Why that's a big deal for security

  • Nothing to phish. A passkey only works on the real website it was created for, so a look-alike site can't trick you into handing it over.
  • Nothing to leak. Servers store only public keys, so a database breach doesn't spill reusable secrets.
  • Nothing to reuse. Every passkey is unique to one service.
  • Your biometrics stay home. Your fingerprint or face only unlocks the key on your own device; it isn't sent anywhere.

The honest caveats

Passkeys aren't magic. Most consumer passkeys sync through Apple, Google or Microsoft so they survive a lost phone — convenient, end-to-end encrypted, but it does mean trusting a platform's sync service. Account recovery still needs care, and not every site supports passkeys yet. The FIDO research also found that one in three people had an account compromised or received a breach notice in the past year: the transition is far from finished.

What passkeys mean for AI

Here's the part that matters for the next decade. A passkey isn't just a better login; it's a cryptographic key that you hold. That makes it a natural root for encryption you control.

In AI Memory Vault, your vault's encryption keys are derived from your passkey credentials. That means the same gesture that signs you in — a fingerprint, a glance — is what unlocks your memory, and the key never sits on our servers. We explore where that leads in Own your keys: passkeys, your own AI and real decentralisation.

Passwords were a shared secret between you and every service you used. Passkeys turn that into something you own. In an era when AI will act with your data, owning the key is everything.

Frequently asked questions

What is a passkey?

A pair of cryptographic keys for one site or app. The private key stays on your device and is unlocked with your fingerprint, face or PIN; the site only stores the public key.

Are passkeys safer than passwords?

Yes. Passkeys can't be phished on look-alike sites, aren't reused across services, and a server breach doesn't leak a reusable secret.

How many people use passkeys?

The FIDO Alliance reported around five billion passkeys in use worldwide in May 2026, with 75% of surveyed consumers having enabled at least one.

Sources

  1. FIDO Alliance — Five Billion Passkeys: World Passkey Day 2026
  2. FIDO Alliance — The State of Passkeys 2026
  3. TechCrunch — Google makes passkeys the default sign-in method (Oct 2023)
  4. The Hacker News — Microsoft makes passkeys default for new accounts (May 2025)
  5. NIST — Syncable authenticators (glossary / SP 800-63)

Figures are as reported by the sources above at the time of writing; survey data from vendors is indicative. AI Memory Vault is in private beta — product details describe how it is designed.

Follow Hushkey:

AI Memory Vault

Give your AI a memory you own.

Private, encrypted, passkey-protected — with permissioned access for your AI agents. Join the private beta waitlist.

No spam. One email when your invite is ready.

Keep reading

Inside AI Memory Vault: how the architecture differs from the last generation

Passkey-derived keys, on-device AES-256-GCM encryption, zero-knowledge storage and permissioned AI agents. How AI Memory Vault is built, and why the future needs it.

Your personal data is scattered — and that’s the security problem

Record breach costs, AI-assisted attacks and data spread across dozens of apps. What the 2026 IBM and Verizon reports tell us, and what a safer home for personal data looks like.