The LastPass 2026 State of AI and SaaS Security Report - LastPass

2026 industry report

The LastPass 2026 State of AI and SaaS Security Report

Only 27% of IT leaders have the controls to govern AI use. If you’re concerned about AI’s potential impact on your organization, you aren’t alone. Get the insights you need to stay ahead of the risk and close the AI governance gap today.

illustration_seo-hero_2026-ai-security-report-svg

How does unauthorized AI usage affect SaaS security and SaaS spend management?

LastPass research indicates that AI adoption is accelerating faster than the controls to govern it. The result is reduced visibility into app usage and growing sprawl that complicates both AI governance and SaaS spend management. The numbers below show where organizations are experiencing the biggest gaps.

92% of IT leaders say their employees are using AI. Less clear is whether IT can see and govern that use.

Why it matters: Rapid AI adoption without visibility is outpacing traditional SaaS app security. You can't govern what you can't see.

21.2% of employees are actively logging in to SaaS & AI tools with credentials already flagged in third-party breaches.

Why it matters: If IT can’t see which credentials tie back to which SaaS or AI tool, breach response becomes slower and more reactive.

65.5% of SaaS apps are abandoned within 30 days of being provisioned.

Why it matters: Abandoned apps still hold data and active permissions — a security liability that expands your attack surface.

64.4% of SaaS apps are redundant, duplicating the function of another app already in the stack.

Why it matters: Redundancy is a major driver of SaaS spend waste; it multiplies the number of apps IT has to govern, adding complexity to cost.

73% of organizations lack a comprehensive, actively enforced AI usage policy.

Why it matters: A policy that isn’t technically enforced isn’t governance. This gap is where AI risk lives.

42% of organizations have no technical controls at all to govern AI use.

Why it matters: Without governance, employees can adopt AI without oversight, creating significant SaaS security risks.

Are your governance controls keeping up with AI adoption?

See where your business may be falling behind on AI governance and which controls to prioritize first.

illustration_100large-card_2026-ai-security-report-svg
illustration_6col_lifestyle-about-us-access-2x-jpg

You already recognize the risks. Can you trust your instincts?

Yes, our research supports your instincts. Like you, the IT admins we interviewed didn’t need convincing that AI governance and SaaS spend management are growing challenges.

They already see SaaS & AI adoption moving faster than their ability to track. In one afternoon, an employee can sign up for an AI tool and grant it access to corporate data through an approved (or unapproved) SaaS integration. The barrier to adoption is close to zero. But while IT leaders understand the risks, they’re far less confident they have the right tools to address it.

Survey respondents rate the importance of detecting sensitive data entered into AI at 4.22 out of 5.

illustration_50half-card_detecting-data-stat-svg

But their confidence in their ability to detect it is 2.5 out of 5.

illustration_50half-card_confidence-data-stat-svg
illustration_6col_lifestyle-about-us-protected-2x-jpg

The gap between awareness and action is significant

Seven out of 10 IT leaders told us that banning AI doesn't eliminate the risk. It just moves usage to personal accounts and devices, making the problem less visible, not smaller.

The challenge isn’t so much creating a policy but gaining visibility into how AI is being used.

The organizations making real progress on governance share one thing in common: They focus on visibility first before they try to enforce anything. The effective sequence is simpler than it sounds: See it first, then govern it.

This report reveals where visibility gaps exist and what organizations are doing to strengthen AI governance today.

illustration_6col_business-saas-app-monitoring-svg

See it first, then govern it

The LastPass 2026 State of AI and SaaS Security Report describes the visibility gap. LastPass Business Max closes it. SaaS Monitoring and SaaS Protect show you the apps your SSO and identity tools don't and let you decide what happens next for each one.

Set Allow, Warn, or Block rules per app, and target that friction to the people or groups who actually need it, so a quick heads-up at login can redirect risky app use without slowing down the rest of the organization. It's a way to close the SaaS visibility gap without adding infrastructure, headcount, or a long rollout.

What data is the report based on?

The LastPass 2026 State of AI and SaaS Security Report is based on:

15,907

organizations analyzed for app usage

450,784

users' login habits across 20,631 orgs

412

IT leaders surveyed

2026

latest AI adoption & SaaS governance trends

Download the LastPass 2026 State of AI and SaaS Security Report and prioritize your next move

See which governance gaps deserve attention first and which controls help reduce risk without adding complexity.

illustration_100large-card_2026-ai-security-report-svg

Frequently asked questions

  • According to the LastPass 2026 State of AI and SaaS Security Report, 92% of IT leaders say their employees are using AI tools, but only 27% say they have the controls needed to govern that use.
  • LastPass found that 21.2% of employees log into SaaS and AI tools using credentials that have already appeared in a third-party breach, based on login behavior from 450,784 users across 20,631 organizations.
  • In a LastPass analysis of 15,907 organizations, 65.5% of provisioned SaaS apps were abandoned within 30 days, and 64.4% duplicated the function of another app already in the stack.
  • LastPass research found that 73% of organizations lack a comprehensive, actively enforced AI usage policy, and 42% have no technical controls governing AI use at all.
  • IT leaders surveyed by LastPass in 2026 rated the importance of detecting sensitive data entered into AI at 4.22 out of 5, but rated their confidence in actually detecting it at just 2.5 out of 5.
  • Seven out of 10 IT leaders told LastPass that banning AI does not eliminate the risk, it moves usage to personal accounts and devices where IT has no visibility.

LastPass research, seen in the LastPass 2026 State of AI and SaaS Security Report, provides a breakdown of what SaaS & AI tools employees are using independently:

  • ChatGPT (consumer): 64%
  • Claude (consumer): 39%
  • Gemini (consumer): 36%
  • Microsoft Copilot (personal/free tier): 35%
  • Grammarly: 29%
  • Perplexity: 11%

Many organizations assume AI adoption is happening within approved apps. But the reality is that employees frequently sign up for SaaS & AI tools before IT has visibility into their use.

The real risk isn’t just usage. It’s the fact that sensitive data and credentials may be entering these apps without authorization, which increases the likelihood of data leakage and compliance exposure.

The best way to discover which AI tools are being used across your business is to continuously monitor app access and login activity.

The LastPass 2026 State of AI and SaaS Security report explores how this type of visibility has become the foundation of modern AI governance.

With LastPass SaaS Monitoring, you can continuously uncover Shadow AI usage and gain the visibility to make informed governance decisions.

Many organizations assume the next step is to block access immediately.

But even though this is a natural response, seven out of 10 IT leaders have discovered that hard bans don’t eliminate the risk. They just push users toward personal accounts and unmanaged devices, reducing visibility rather than risk.

A more effective approach is to first evaluate the risks posed by individual tools before applying controls.

The LastPass 2026 State of AI and SaaS Security Report explores how organizations are balancing security and productivity as AI adoption grows. It highlights risk-based governance, where lower-risk tools can be monitored while higher-risk tools get stricter controls.

LastPass SaaS Protect supports this model through configurable Warn and Block policies that help you govern AI use without resorting to bans.

Download the report to see how your AI governance approach compares to industry trends and identify the controls that provide the greatest impact.

Don't see your questions here? Visit Support Center.

Get started with LastPass for Business

No credit card required for the 14-day trial.