HID has unveiled its latest market study, "Public Key Infrastructure (PKI) in the Age of AI and Automation," spotlighting how over 300 IT leaders across the US and Europe are confronting new PKI challenges introduced by AI, automation, and post-quantum computing advances.
The study provides security leaders with critical insights into the trends, threats, and innovations reshaping the PKI landscape, aiding them in aligning strategic plans with future market needs.
Automation Becomes a Critical Focus
Automation is growing in importance due to its potential to reduce human error-related risks, notably in certificate management. This has become vital as certificate validity periods, such as those for Transport Layer Security (TLS) certificates, shorten.
The CA/Browser Forum has sanctioned a phased reduction of TLS certificate validity from 398 days to just 47 days by 2029. As manual processes become untenable, 67% of surveyed executives are automating renewal processes, with 61% planning to invest in PKI automation over the next two years. Such automation is essential for scalability and the security of dynamic environments like IoT devices and AI agents.
Adoption of PKI-as-a-Service (PKIaaS)
PKIaaS provides full automation capabilities without the need for on-premise resources
PKIaaS provides full automation capabilities without the need for on-premise resources, streamlining the lifecycle from issuance to revocation.
While 76% of organizations have integrated cloud components into their PKI systems, only a minority—23%—have adopted completely cloud-based solutions. Larger organizations, especially those with over 100,000 employees, often choose hybrid setups, balancing PKIaaS's flexibility with the control offered by on-premise systems.
Compliance as a Strategic Driver
The growing complexity of global regulations such as GDPR, Cyber Resilience Act, and HIPAA underscores compliance as a significant motivator for PKI adoption. Non-compliance can carry substantial costs; nearly 45% of executives include regulatory adherence among their primary business goals, with 39% tracking it as a formal performance metric.
Challenges in Post-Quantum Cryptography (PQC) Readiness
The report reveals that navigating AI-driven trust demands is paramount as standards evolve
Despite the looming threat that quantum computing poses to current encryption standards, the pace of PQC adoption remains measured. While some bad actors already harvest encrypted data in anticipation of future decryption capabilities, only 12% of organizations have begun PQC trials, 25% are formulating internal strategies, and 37% monitor standard developments. Larger corporations, particularly U.S.-based, are more active, being two to three times as likely to pilot PQC than smaller counterparts.
AI agents are emerging as a crucial category in identity management, with 34% of organizations recognizing AI agent certificates as a key trend.
The report reveals that navigating AI-driven trust demands is paramount as standards evolve, with adoption rates slightly higher in the U.S. (18%) compared to Europe (13%). This uptake reflects the proactive efforts of the PKI community in addressing the new identity challenges presented by AI advancements.
HID, a global pioneer in trusted identity solutions, announces the release of its Public Key Infrastructure (PKI) in the Age of AI and Automation market study, revealing how more than 300 IT leaders in the United States and Europe are responding to emerging PKI challenges in AI, automation and post-quantum computing.
The study identifies the trends, threats and innovations that are shaping this fast-moving market, equipping security leaders with actionable insights to align their strategies with emerging opportunities and future demands.
Automation becomes high priority
By minimizing the threat of human error, automation decreases the risk of certificate-related incidents, a benefit that is growing increasingly urgent as certificate lifespans shrink. This includes Transport Layer Security (TLS) certificates, the digital credentials that secure encrypted connections across websites and applications.
The CA/Browser Forum has already approved a phased reduction of TLS certificate validity—from 398 days to just 47 days by 2029—making manual certificate management increasingly unsustainable and driving automation to the top of the security agenda. In response, 67% of executives surveyed are already automating renewal processes. Automation also enhances scalability and helps organizations secure dynamic environments like IoT devices and AI agents. Executives from organizations large and small have made it one of their top priorities, with 61% of respondents saying they plan to invest in PKI automation in the next 24 months.
PKI-as-a-service (PKIaaS) gets traction
PKIaaS eliminates the need for on-premise hardware and servers, ensuring seamless automation from issuance to renewal and revocation.
However, while 76% of organizations have incorporated cloud components into their PKI infrastructure, only 23% use fully cloud-based deployments. Enterprises with more than 100,000 employees tend to prefer hybrid PKI deployments, suggesting that organizations seek to balance the flexibility of PKIaaS with the security and control of on-premise infrastructure.
Compliance brings clear benefits
With the growing swarm of regulations—from GDPR, Cyber Resilience Act, NIS2, HIPAA and more—compliance has become a strategic driver of PKI adoption.
The cost of getting it wrong is high, as nearly half of executives (45%) list regulatory compliance among the primary business goals they hope to achieve through PKI, while 39% measure it as a formal key performance indicator.
Post-Quantum Cryptography (PQC) readiness is slower than expected
As quantum computing matures, it poses a fundamental threat to today's encryption: bad actors are harvesting encrypted data today, intending to decrypt it once quantum capabilities catch up. Yet despite the recognized threat, adoption remains cautious.
Only 12% of surveyed respondents are piloting PQC, 25% are developing internal plans and 37% are monitoring evolving standards. With PQC expected to be one of the most complex cryptographic transitions that the industry has ever experienced, larger enterprises and U.S.-based organizations are taking note. According to the survey, organizations with more than 50,000 employees are two to three times more likely to run PQC pilots than smaller companies.
AI Agents emerge as new identity category
While AI standards continue to evolve, securing both customer interactions and bot-to-bot exchanges is a pressing priority.
The study finds that 34% of organizations cite AI agent certificates as a top trend, reflecting the PKI community’s proactive adaptation to AI-driven trust requirements. Adoption is slightly higher in the United States (18%) than in Europe (13%).