Because the ONLY requirement should really be > 8 (or more) characters. Any other requirement will generally lead to users creating passwords with predictable patterns.
https://www.ncsc.gov.uk/guidance/password-guidance-simplifyi...
"Traditionally, organisations impose rules on the length and complexity of passwords. However, people then tend to use predictable strategies to generate passwords, so the security benefit is marginal while the user burden is high."
Edit: Adding NIST guidelines too, which say the same https://nakedsecurity.sophos.com/2016/08/18/nists-new-passwo...