LastPass released findings from its inaugural 2026 State of AI and SaaS Security Report, confirming a reality that many businesses had already suspected, yet struggled to quantify: AI adoption is significantly outpacing IT’s visibility and control.
This proprietary research from LastPass, based on anonymized platform data and a survey of more than 400 business admins, comes as emerging agentic capabilities exacerbate the longstanding SaaS sprawl and shadow IT struggles that organizations have yet to contain.
“AI tools are now being adopted faster than previous categories of traditional software, and the growing popularity of autonomous agents is creating a new security reality that organizations cannot afford to ignore,” said Don MacLennan, Chief Product Officer at LastPass. “AI is silently embedding itself into tools that organizations have already approved, and even ‘approved’ agents are fanning out to multiple ungoverned interactions, creating risks companies may not even know they have. You can’t control what you can’t see, and this research proves the growing gap between AI adoption and organizational visibility is impossible to overlook.”
Key findings from the LastPass report include:
AI Is Moving Faster Than Organizations Can Govern It
- According to the LastPass 2026 State of AI and SaaS Security Report, 92% of business admins say AI is already in use across their organization, but only 27% have an enforced AI governance program.
- LastPass found that 42% of business admins say they have no technical controls at all for managing employee access to AI tools (no allow lists, block lists, or data loss prevention (DLP) rules covering AI traffic).
- 68% of business admins told LastPass that employees entering sensitive data into AI is their biggest concern, yet their confidence in identifying and addressing that risk sits at 2.5 when rated out of 5.
Organizations clearly recognize the risks associated with AI use, but many lack the visibility, controls, and confidence needed to effectively govern it. The hopeful note is that more than 40% of organizations plan to implement technical controls in the next 12 months.
Credential Risk Hasn’t Gone Away. AI Makes It Worse
AI adoption may be creating governance challenges, but the underlying visibility problem isn’t new. Password reuse shows how convenience-driven behavior has been creating risk long before AI, and how employees’ efforts to work faster and more easily can complicate governance.
According to the LastPass 2026 State of AI and SaaS Security Report, more than half (52.8%) of users reuse passwords across accounts, and at least 21% are actively logging in with a credential that has appeared in a known data breach. These trends mirror the realities of shadow AI: if security is not convenient for employees, they will find workarounds.
Employees are also using consumer-grade tools with personal accounts or accounts IT hasn’t connected to the company’s single sign-on (SSO) system, creating visibility gaps. The more unmanaged AI accounts employees create, the more ways credentials can be stolen, alongside the risk of sensitive data exposure.
Lack of AI Governance Carries Financial Risks Beyond Breach Costs
Even if invisible, ungoverned AI and SaaS usage doesn’t necessarily culminate in a breach (which now costs $4.99M, on average globally), it can still cost your organization a significant amount of money.
- More than 65% of the applications organizations sign up for go unused within 30 days.
- More than 64% of applications are in a category where organizations already use at least one other application, making use cases redundant.
Unmanaged AI adoption is also accelerating compliance exposure gaps, potentially leading to regulatory fines, legal action, loss of government contracts, and exclusion from future bids.
AI Governance Starts with Visibility
The answer to AI’s governance crisis is not blanket bans or blocking apps, which would only hurt productivity and push employees toward personal devices and accounts IT can’t see. Instead, organizations must understand which AI and SaaS tools are being used, where corporate data and credentials are flowing, and which applications create unnecessary risk or redundancy. Only with that visibility can organizations put the right controls around AI without slowing the productivity gains it enables.
Download The State of AI and SaaS Security Report by visiting the LastPass website.





