LastPass, the secure access solution that helps organizations and users work, move faster, and stay protected, today released findings from its inaugural 2026 State of AI and SaaS Security Report, confirming a reality that many businesses had already suspected, yet struggled to quantify: AI adoption is significantly outpacing IT's visibility and control.
New data reveals why organizations need greater visibility to govern AI and SaaS without slowing innovation.
This proprietary research from LastPass comes as emerging agentic capabilities exacerbate the longstanding SaaS sprawl and shadow IT struggles that organizations have yet to contain.
"AI tools are now being adopted faster than previous categories of traditional software, and the growing popularity of autonomous agents is creating a new security reality that organizations cannot afford to ignore," said Don MacLennan, Chief Product Officer at LastPass. "AI is silently embedding itself into tools that organizations have already approved, and even 'approved' agents are fanning out to multiple ungoverned interactions, creating risks companies may not even know they have. You can’t control what you can’t see, and this research proves the growing gap between AI adoption and organizational visibility is impossible to overlook."
According to the report, organizations clearly recognize the risks associated with AI use, but many lack the visibility, controls, and confidence needed to effectively govern it. The hopeful note is that more than 40% of organizations plan to implement technical controls in the next 12 months.
AI adoption may be creating governance challenges, but the underlying visibility problem isn't new. Password reuse shows how convenience-driven behavior has been creating risk long before AI, and how employees' efforts to work faster and more easily can complicate governance.
According to the LastPass 2026 State of AI and SaaS Security Report, more than half (52.8%) of users reuse passwords across accounts, and at least 21% are actively logging in with a credential that has appeared in a known data breach. These trends mirror the realities of shadow AI: if security is not convenient for employees, they will find workarounds.
Employees are also using consumer-grade tools with personal accounts or accounts IT hasn't connected to the company's single sign-on system, creating visibility gaps. The more unmanaged AI accounts employees create, the more ways credentials can be stolen, alongside the risk of sensitive data exposure.
Lack of AI governance carries financial risks beyond breach costs. More than 65% of the applications organizations sign up for go unused within 30 days. More than 64% of applications are in a category where organizations already use at least one other application, making use cases redundant. Unmanaged AI adoption is also accelerating compliance exposure gaps, potentially leading to regulatory fines, legal action, loss of government contracts, and exclusion from future bids.
AI Governance starts with visibility — understanding which AI and SaaS tools are being used, where corporate data and credentials are flowing, and which applications create unnecessary risk or redundancy rather than blanket bans that push employees toward personal devices IT can't see.
About LastPass
LastPass is an access security platform trusted by more than 100,000 organizations and millions of users for storing passwords and passkeys, sharing credentials across teams, enforcing multifactor authentication, managing employee access, and securing SaaS and AI applications. LastPass is built on a zero-knowledge encryption model, encrypting data with AES-256 on the user's own device. For businesses, Business Max from LastPass surfaces the applications and AI tools in use across an organization, including the ones SSO and identity systems miss.