Yup! I've been in information security (until I retired a few months back) for 30+ years, I have been awestruck by the ingenuity of humans to make any task easier, even if that means putting the entire organisation at risk.
I think you've missed the point.
If the burden of following the rules is unworkable, people will have to work around. A mixed symbol long password changed monthly, and different for maybe 6 to 10 systems cannot be remembered - this isn't people being sloppy; it just can't be done. It's gonna be written down of necessity.
Granted it shouldn't be on the keyboard, but written down at all is a problem.
I recall my password for the SAP finance system had to be changed monthly. I only used SAP for
my timesheet so every fourth use I had to change the f-ing password.