Skip to content
By 5G Technology

How CXOs Can Leverage 5G and Edge Networks in 2026

The radio network delivered, the business model mostly did not. Where 5G and edge actually pay in 2026, and what executives should do now.

How CXOs Can Leverage 5G and Edge Networks in 2026, by Deepak Gupta on guptadeepak.com

If you are being asked to fund a 5G or edge initiative in 2026, the honest framing is this. The radio network delivered, the business model mostly did not, and the two places where 5G reliably pays are fixed wireless access and network APIs. Everything else needs a specific latency or sovereignty requirement you can name in one sentence, or it is a science project.

I wrote the original version of this article in 2021, when the industry expectation was that 5G edge computing would reshape enterprise applications within a couple of years. Some of that was right. A meaningful part of it was wrong, including a security claim in my own text that I am correcting below.

Where 5G actually landed

The Ericsson Mobility Report of June 2026 gives the clearest public picture:

  • 5G subscriptions passed 3.1 billion in the first quarter of 2026, with 162 million added in that quarter alone, and are forecast to reach 6.4 billion by 2031.
  • 390 service providers have launched commercial 5G. Only more than 90 have launched 5G standalone.
  • 5G carried 48% of mobile data traffic at the end of 2025, forecast to reach 85% by 2031.
  • Commercial differentiated connectivity offerings built on 5G standalone network slicing rose from 65 in November 2025 to 84.
  • 71% of fixed wireless access providers now offer the service over 5G, up from 57% a year earlier.

Read those numbers together and the story is clear. Consumer 5G coverage is close to universal in developed markets, while the standalone core that makes slicing, deterministic latency, and enterprise differentiation possible exists at fewer than a quarter of operators. That gap is the reason so many enterprise 5G business cases stalled. The features being sold depended on a core most operators had not finished building.

A correction to my own 2021 article

The earlier version of this post said 5G uses 256-bit encryption, citing a widely repeated industry claim. That is wrong, and it is worth stating plainly because the claim still circulates.

5G air-interface confidentiality uses 128-bit algorithms: 128-NEA1 (SNOW 3G), 128-NEA2 (AES in counter mode), and 128-NEA3 (ZUC). 3GPP has specified 256-bit variants for future use, but they are not what your phone negotiates today. What 5G genuinely improved over 4G is subscriber-identity privacy: the permanent identifier is concealed as a SUCI using the network's public key, which closes the passive IMSI-catcher attack that worked reliably on earlier generations.

That is a real security gain. It is a narrower one than "the most advanced encryption standard used to date", which is how the industry sold it, and how I repeated it.

What actually pays in 2026

1. Fixed wireless access

The clearest commercial success of 5G is the least futuristic: replacing a fixed line with a radio link. For distributed retail, branch offices, temporary sites, and construction, FWA delivers usable broadband without a truck roll and without a copper timeline. If you run more than fifty sites, this is where the savings are.

2. Network APIs, especially for authentication and fraud

This is the development the 2021 article did not anticipate, and it is the one identity and fraud teams should care about. Operators standardised network capabilities through CAMARA, the open-source project run by the GSMA and the Linux Foundation. They commercialised them through Aduna, a joint venture formed by Ericsson with a dozen operators including AT&T, T-Mobile, Verizon, Deutsche Telekom, Orange, Telefonica and Vodafone. Aduna states it has agreements covering all three major US carriers, reaching over 300 million connections through one platform, and is rolling out network-based authentication as an alternative to SMS one-time codes.

Treat this precisely. Number verification confirms that a request comes from the device holding a given SIM. That is a strong possession signal and a good replacement for SMS codes, which are vulnerable to SIM swap and interception. It is not identity proofing, it does not tell you who the human is, and it must not become your only factor.

3. Private networks with a named physical constraint

Private 5G works where Wi-Fi genuinely does not: large outdoor yards, ports, mines, moving machinery, dense radio environments with deterministic requirements. It is expensive and operationally heavy. If the requirement can be met by Wi-Fi 6E or Wi-Fi 7, it will be, and the business case for private 5G should assume that comparison will be made by someone hostile to the project.

4. Edge computing, where the workload has moved

The 2021 pitch for edge computing was latency for consumer experiences. The 2026 demand is AI inference close to where data is produced, for cost, bandwidth, and data-residency reasons more than for milliseconds. Gartner has projected that more than half of enterprise data would be processed outside centralised cloud environments by 2026, and IDC expects half of enterprise AI inference to run on endpoints or edge nodes by 2030. Both are analyst forecasts, not measurements, and should be treated as direction rather than fact.

Telco multi-access edge did not disappear. AWS was still opening Wavelength Zones on Verizon's network in 2025. It also did not become the default deployment target anyone predicted in 2021. Most enterprise "edge" in production today is a server in a factory or a store, not a workload in an operator's data centre.

The security implications executives should actually track

  • Legacy interconnect is still the weak point. A 5G device roams onto older networks and inherits older signalling weaknesses. The security of your fleet is set by the worst network it will ever attach to, not the best.
  • Telecom infrastructure is a confirmed nation-state target. The intrusions into US carrier networks disclosed from late 2024 onward changed the threat model for anyone treating the mobile network as a trusted channel. Encrypt end to end at the application layer and assume the transport is hostile.
  • Slicing is isolation by configuration, not by physics. If you buy a slice for a regulated workload, ask for the isolation guarantees in the contract and the evidence that supports them.
  • Network APIs create a new consent surface. Location, SIM-swap status, and number verification are personal data. Using them without a clear legal basis converts a fraud control into a privacy incident.
  • Edge nodes expand the physical attack surface. A box in a retail back room has different threat exposure from a rack in a data centre. Disk encryption, secure boot, and remote attestation are not optional there.
  • Every edge node and network function is a non-human identity. It needs an owner, scoped credentials, an expiry, and logging, which is where most 5G and edge programmes have no plan at all.

What a CXO should do in the next two quarters

  1. Ask your operator one question: is this on standalone? If a proposal depends on slicing, guaranteed latency, or differentiated connectivity, and the operator has not launched 5G SA in your markets, the proposal is a roadmap, not a service.
  2. Move fixed connectivity to FWA where the economics are obvious and stop treating it as an innovation programme. It is a procurement decision.
  3. Pilot network-based authentication as an SMS replacement, alongside passkeys, not instead of them. The two solve different parts of the problem: possession of a SIM versus phishing resistance.
  4. Locate your edge requirement precisely. Write down the workload, the latency budget in milliseconds, and the data that cannot leave a jurisdiction. If you cannot fill in all three, you do not yet have an edge requirement.
  5. Put non-human identity on the same plan. Devices, gateways, and edge nodes need lifecycle management before they need connectivity.
  6. Retire the 2021 talking points. Including the 256-bit encryption claim, wherever it survives in your internal decks.

How I verified this

Subscription, standalone, slicing, and traffic figures come from the Ericsson Mobility Report of June 2026 and its accompanying press release, checked in September 2026. Encryption algorithm detail is from 3GPP security specifications and published analyses of the 5G security architecture. Network API claims come from Aduna's own announcements and the CAMARA project. The edge adoption figures are analyst forecasts from Gartner and IDC, labelled as such. AWS Wavelength availability was checked against AWS service announcements.

Last verified: September 2026.

Frequently Asked Questions

Did 5G fail?

No, but it succeeded as infrastructure rather than as a product. Consumers got faster phones, operators got better spectral efficiency, and the enterprise revenue that justified the capital expenditure largely did not arrive. That is a different outcome from failure and a poor basis for the next round of forecasts.

Is 5G standalone worth waiting for?

If your use case needs slicing or deterministic latency, you are already waiting, because fewer than 90 operators worldwide had launched it as of mid-2026. Design so the application degrades gracefully on non-standalone networks.

Is edge computing the same as 5G edge?

No, and conflating them wasted a lot of budget. Edge computing means processing near the data source, which is usually a server you own. 5G edge means compute inside the operator's network. Most enterprises need the first and have been sold the second.

Should we replace SMS one-time codes with network APIs?

For fraud-sensitive flows, network-based verification is a clear improvement over SMS codes, which NIST now treats as a restricted authenticator. For login, passkeys remain the stronger control because they are phishing-resistant. Use both where the risk justifies it.

What about 6G?

Standardisation work is underway and commercial deployment is toward the end of the decade. Anyone selling you 6G readiness in 2026 is selling you a slide. The useful preparation is the same as it was for 5G: clean identity for devices, application-layer encryption, and no dependence on a single transport.

How do we know a 5G or edge proposal is real?

Ask for the named latency budget, the named data-residency constraint, and the name of the operator's standalone deployment in your market. A proposal that cannot produce all three is an experiment, which is fine, as long as it is funded as one.

Related reading

Get new Scams & Cybersecurity writing

Enjoyed this? Subscribe and tell us what you read most. Scams & Cybersecurity is already ticked for you. No tracking pixels, unsubscribe with one click.

Tell us what you read most (optional)

About DeepakPublicationsAnalysisAll tracks