HID, a prominent figure in the field of trusted identity solutions, has unveiled a comprehensive market study titled "Public Key Infrastructure (PKI) in the Age of AI and Automation."
This study surveys over 300 IT leaders across the United States and Europe, exploring their strategies and responses to the growing challenges in PKI brought on by advancements in AI, automation, and post-quantum computing. The research highlights emerging trends, potential threats, and new innovations, offering security professionals practical insights to adapt their strategies for future opportunities.
Automation takes centre stage
Automation has become a top priority as it significantly reduces the risk of human errors, particularly with certificate-related incidents, at a time when certificate lifespans are notably decreasing. The dwindling validity period of Transport Layer Security (TLS) certificates, expected to decline from 398 days to 47 days by 2029, exacerbates this issue.
Consequently, manual management of certificates is becoming unmanageable, prompting 67% of executives to automate renewal processes. Automation is also seen as vital for scaling operations and securing complex environments, such as Internet of Things (IoT) devices and AI agents, with 61% planning to invest in PKI automation within the next two years.
Popularity of PKI-as-a-Service (PKIaaS) is rising
PKI-as-a-Service is gaining traction by removing the necessity for physical hardware and servers
PKI-as-a-Service is gaining traction by removing the necessity for physical hardware and servers. This approach facilitates seamless automation from the issuance to the renewal and revocation of certificates.
Despite 76% of organisations integrating cloud elements into their PKI systems, only 23% have fully adopted cloud-based solutions. Larger enterprises prefer hybrid deployments that blend the flexibility of PKIaaS with the control of on-premise infrastructure, highlighting the need for a balanced approach.
Compliance as a strategic driver
As regulations such as GDPR, the Cyber Resilience Act, NIS2, and HIPAA proliferate, compliance has emerged as a vital motivator for adopting PKI. Errors in compliance carry significant costs, and 45% of executives view regulatory adherence as a primary business objective to be achieved via PKI. Furthermore, 39% of organisations consider compliance as a formal key performance indicator, emphasising its importance in the strategic framework.
Post-Quantum Cryptography (PQC) preparedness lags
Larger companies and those based in the United States are more proactive
Despite recognising quantum computing as a looming threat to current encryption methods, the rollout of Post-Quantum Cryptography remains hesitant.
Survey results show only 12% of respondents are testing PQC, while 25% are formulating internal plans and 37% are keeping an eye on evolving standards. Larger companies and those based in the United States are more proactive, as organisations with over 50,000 employees are significantly more likely to conduct PQC trials than their smaller counterparts.
AI agents: A new identity category
As AI standards progress, securing interactions between customers and automated systems, as well as inter-bot communications, becomes increasingly important.
The study noted that 34% of organisations have identified AI agent certificates as a key trend, responding to AI-driven trust imperatives. Adoption rates are slightly higher in the United States at 18% compared to Europe, which stands at 13%.
HID, a global pioneer in trusted identity solutions, announces the release of its Public Key Infrastructure (PKI) in the Age of AI and Automation market study, revealing how more than 300 IT leaders in the United States and Europe are responding to emerging PKI challenges in AI, automation and post-quantum computing.
The study identifies the trends, threats and innovations that are shaping this fast-moving market, equipping security leaders with actionable insights to align their strategies with emerging opportunities and future demands.
Automation becomes high priority
By minimising the threat of human error, automation decreases the risk of certificate-related incidents, a benefit that is growing increasingly urgent as certificate lifespans shrink. This includes Transport Layer Security (TLS) certificates, the digital credentials that secure encrypted connections across websites and applications.
The CA/Browser Forum has already approved a phased reduction of TLS certificate validity—from 398 days to just 47 days by 2029—making manual certificate management increasingly unsustainable and driving automation to the top of the security agenda. In response, 67% of executives surveyed are already automating renewal processes. Automation also enhances scalability and helps organisations secure dynamic environments like IoT devices and AI agents. Executives from organisations large and small have made it one of their top priorities, with 61% of respondents saying they plan to invest in PKI automation in the next 24 months.
PKI-as-a-service (PKIaaS) gets traction
PKIaaS eliminates the need for on-premise hardware and servers, ensuring seamless automation from issuance to renewal and revocation.
However, while 76% of organisations have incorporated cloud components into their PKI infrastructure, only 23% use fully cloud-based deployments. Enterprises with more than 100,000 employees tend to prefer hybrid PKI deployments, suggesting that organisations seek to balance the flexibility of PKIaaS with the security and control of on-premise infrastructure.
Compliance brings clear benefits
With the growing swarm of regulations—from GDPR, Cyber Resilience Act, NIS2, HIPAA and more—compliance has become a strategic driver of PKI adoption.
The cost of getting it wrong is high, as nearly half of executives (45%) list regulatory compliance among the primary business goals they hope to achieve through PKI, while 39% measure it as a formal key performance indicator.
Post-Quantum Cryptography (PQC) readiness is slower than expected
As quantum computing matures, it poses a fundamental threat to today's encryption: bad actors are harvesting encrypted data today, intending to decrypt it once quantum capabilities catch up. Yet despite the recognised threat, adoption remains cautious.
Only 12% of surveyed respondents are piloting PQC, 25% are developing internal plans and 37% are monitoring evolving standards. With PQC expected to be one of the most complex cryptographic transitions that the industry has ever experienced, larger enterprises and U.S.-based organisations are taking note. According to the survey, organisations with more than 50,000 employees are two to three times more likely to run PQC pilots than smaller companies.
AI Agents emerge as new identity category
While AI standards continue to evolve, securing both customer interactions and bot-to-bot exchanges is a pressing priority.
The study finds that 34% of organisations cite AI agent certificates as a top trend, reflecting the PKI community’s proactive adaptation to AI-driven trust requirements. Adoption is slightly higher in the United States (18%) than in Europe (13%).