LastPass Research Finds AI Adoption Accelerating Faster Than Governance Can Keep Pace
New data reveals why organizations need greater visibility to govern AI and SaaS without slowing innovation
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
LastPass, the secure access solution that helps organizations and users work, move faster, and stay protected, today released findings from its inaugural 2026 State of AI and SaaS Security Report, confirming a reality that many businesses had already suspected, yet struggled to quantify: AI adoption is significantly outpacing IT’s visibility and control.
This proprietary research from LastPass, based on anonymized platform data and a survey of more than 400 business admins, comes as emerging agentic capabilities exacerbate the longstanding SaaS sprawl and shadow IT struggles that organizations have yet to contain.
“AI tools are now being adopted faster than previous categories of traditional software, and the growing popularity of autonomous agents is creating a new security reality that organizations cannot afford to ignore,” said Don MacLennan, Chief Product Officer at LastPass. “AI is silently embedding itself into tools that organizations have already approved, and even ‘approved’ agents are fanning out to multiple ungoverned interactions, creating risks companies may not even know they have. You can’t control what you can’t see, and this research proves the growing gap between AI adoption and organizational visibility is impossible to overlook.”
Key findings from the LastPass report include:
AI Is Moving Faster Than Organizations Can Govern It
- According to the LastPass 2026 State of AI and SaaS Security Report, 92% of business admins say AI is already in use across their organization, but only 27% have an enforced AI governance program.
- LastPass found that 42% of business admins say they have no technical controls at all for managing employee access to AI tools (no allow lists, block lists, or data loss prevention (DLP) rules covering AI traffic).
- 68% of business admins told LastPass that employees entering sensitive data into AI is their biggest concern, yet their confidence in identifying and addressing that risk sits at 2.5 when rated out of 5.
Organizations clearly recognize the risks associated with AI use, but many lack the visibility, controls, and confidence needed to effectively govern it. The hopeful note is that more than 40% of organizations plan to implement technical controls in the next 12 months.
Credential Risk Hasn’t Gone Away. AI Makes It Worse
AI adoption may be creating governance challenges, but the underlying visibility problem isn’t new. Password reuse shows how convenience-driven behavior has been creating risk long before AI, and how employees’ efforts to work faster and more easily can complicate governance.
According to the LastPass 2026 State of AI and SaaS Security Report, more than half (52.8%) of users reuse passwords across accounts, and at least 21% are actively logging in with a credential that has appeared in a known data breach. These trends mirror the realities of shadow AI: if security is not convenient for employees, they will find workarounds.
Employees are also using consumer-grade tools with personal accounts or accounts IT hasn’t connected to the company’s single sign-on (SSO) system, creating visibility gaps. The more unmanaged AI accounts employees create, the more ways credentials can be stolen, alongside the risk of sensitive data exposure.
Lack of AI Governance Carries Financial Risks Beyond Breach Costs
Even if invisible, ungoverned AI and SaaS usage doesn’t necessarily culminate in a breach (which now costs $4.99M, on average globally), it can still cost your organization a significant amount of money.
- More than 65% of the applications organizations sign up for go unused within 30 days.
- More than 64% of applications are in a category where organizations already use at least one other application, making use cases redundant.
Unmanaged AI adoption is also accelerating compliance exposure gaps, potentially leading to regulatory fines, legal action, loss of government contracts, and exclusion from future bids.
AI Governance Starts with Visibility
The answer to AI’s governance crisis is not blanket bans or blocking apps, which would only hurt productivity and push employees toward personal devices and accounts IT can’t see. Instead, organizations must understand which AI and SaaS tools are being used, where corporate data and credentials are flowing, and which applications create unnecessary risk or redundancy. Only with that visibility can organizations put the right controls around AI without slowing the productivity gains it enables.
Download The State of AI and SaaS Security Report by visiting the LastPass website.
Learn more about how LastPass can help your business bring AI and SaaS usage into view and under control by visiting the company’s website.
Methodology
LastPass analyzed anonymized aggregated platform data, including credential data from 450,784 users across 20,631 organizations, and app-usage data from 15,907 organizations. The research also includes a survey of 412 LastPass Business and Business Max admins and interviews with 10 prospective customers at organizations of roughly 100 to 2,500 employees in data-sensitive industries such as professional services, healthcare, education, finance, and technology, to capture IT leaders’ perspectives on AI and SaaS adoption, governance, and risk.
About LastPass
LastPass is an access security platform trusted by more than 100,000 organizations and millions of users for storing passwords and passkeys, sharing credentials across teams, enforcing multifactor authentication, managing employee access, and securing SaaS and AI applications. LastPass is built on a zero-knowledge encryption model, encrypting data with AES-256 on the user’s own device. For businesses, Business Max from LastPass surfaces the applications and AI tools in use across an organization, including the ones SSO and identity systems miss, helping IT teams see and secure AI use without slowing employees down. Founded in 2008, LastPass is headquartered in Boston. Discover how LastPass can help you work, move fast, and stay protected at www.lastpass.com and follow us on LinkedIn, X, Instagram, and Facebook.
FAQs
Q: What are the real risks of employees using unapproved AI tools?
A: Unapproved AI tools can create blind spots where corporate data and credentials are going, making it harder for IT to enforce security and compliance policies. They can also introduce unmanaged accounts and additional access points that increase credential and data exposure risks.
LastPass helps close this gap, giving IT teams visibility into the AI tools employees are actually using. This capability is included with LastPass Business Max.
Q: What does LastPass do, and does it catch shadow AI?
A: LastPass gives organizations greater visibility into their digital environment, helping IT identify applications in use, understand risk, and act on unmanaged or redundant apps. This visibility can also help uncover shadow AI tools that employees adopt outside of IT’s approved technology stack.
Q: How do I accelerate AI adoption and reduce risk at the same time?
A: Start with visibility, fully understanding which AI tools employees are using, how they’re being accessed, and where sensitive data and credentials are flowing. From there, organizations can apply risk-based controls that enable low-risk AI use while adding safeguards or restrictions where the potential risk is higher.
Business Max from LastPass delivers that first layer of visibility, showing which AI tools and other SaaS apps are in use across your organization, including those outside your SSO or IdP.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260922647870/en/
Media gallery

