Blog
Recent
Cybersecurity

Allow, Warn, Block: A Practical AI Governance Model for Lean Teams

Shireen StephensonReviewed byMike KosakPublishedMay 21, 2026UpdatedJuly 24, 2026
What to Know Before You Read
  • The 2026 leaks from vibe code platforms like Lovable, Base44, and Replit weren't conventional intrusions but primarily access control failures.
  • An "AI acceptable use policy" in your employee handbook is a good start. But without enforcement at the point of access, the policy has little practical effect.
  • The LastPass Allow/ Warn/ Block model lets you apply different levels of access control, without blanket restrictions that kill productivity or drive behavior underground.
  • Most AI risk starts at the credential rather than network layer. Governing access in the browser catches what enterprise CASB or EDR tools miss.
  • LastPass surfaces every SaaS or AI tool your employees log into, enforcing controls at the moment of access.
AI governance tools are controls that determine what AI apps employees can access, how they access them, and what data they can share with them. For lean IT teams, the most practical starting point is visibility and access governance.
 
It seems everyone’s vibe coding now. Log into social media, and there’s no shortage of influencers bragging about their vibe-coding millionaire status.
Meanwhile, several of your employees have caught the vibe-coding fever. They’ve created accounts on Lovable, Base44, and Replit to spin up the next viral app.
Without IT knowing, they’ve also connected their vibe-coding accounts to your org’s CRM, Slack, Google Workspace, or another business-critical app.
If you run a small or midsize team, you know this is a nightmare, not knowing which credentials are exposed and where proprietary data is going.
And your unease about pasting company data into SaaS and AI platforms is widely shared: 90% of IT leaders are concerned about Shadow AI from a privacy and security perspective, while 46% say they’re “extremely worried.”
By the end of this article, you’ll know exactly what to do about it, without being forced to overspend or compromise on the core capabilities you need.
But first, let’s talk about the recent AI vibe coding leaks.

Were the 2026 AI vibe coding leaks breaches or access failures?

The most damaging AI vibe coding leaks so far haven’t been conventional intrusions involving perimeter compromise.
In many cases, anyone with the URLs to these vibe-coding apps could get access. For others, email logins were enough. There were no meaningful security controls to bypass.
Which means what leaked wasn't stolen but handed over willingly via unguarded access points.
The vibe code 10X developer myth
The 10X developer has the power of 10 programmers. They’re the Usain Bolt of coding...So you might be thinking: Could I become a 10X developer with the help of AI-assisted programming tools? Well, sorry to say, but probably not...Some developers have found themselves playing a loop of corrections with the AI to get to a sweet spot of accuracy, while others have had to spoon-feed the tools to get it to debug accurately...for the most part, these tools are your virtual assistants, not a replacement for your knowledge, skill, and experience. (AI-assisted programming by Tom Taulli)
 
The “build-your-app-in-minutes” promise and the rise in data leaks
Despite warnings about the “10X developer myth,” many continue to build AI-assisted apps in hopes of a quick payday.
 
But research shows that vibe-coding apps created by non-specialists are prone to data exposure. Unknown to creators, many of these apps are deployed publicly by default, with little to no authentication required.
 
In Oct 2025, the Escape research team scanned 5,600+ publicly accessible apps and found:
  • 2,000 high-impact vulnerabilities, 400+ exposed secrets (including API keys and access tokens), and 175 instances of PII including medical records and bank account numbers.
And in May 2026, cybersecurity firm RedAccess discovered:
  • 380,000 apps built with vibe coding tools like Replit, Lovable, and Base44 were publicly accessible.
  • About 5,000 of those assets contained sensitive corporate info.
And that’s not all:
  • AI-assisted code ships with 23.7% more security vulnerabilities.
  • Gartner predicts that prompt-to-app approaches could increase software defects by 2,500% by 2028.
  • According to Gartner, one AI agent often needs multiple accounts to function, hence the rapid adoption of SaaS/AI tools in corporate workflows.
This results in an explosion of shadow attack surfaces, which means growing risk for your business if you aren’t tracking SaaS and AI adoption.
 
Trusted by 100,000+ businesses and millions of users, LastPass is designed to help you manage SaaS and AI access with full control, delivering enterprise functionality at a realistic price point.
 
 

What risks do organizations face without clear AI governance?

Without clear AI governance, organizations face data leakage, credential exposure, and compliance failures.
Yet, risk isn’t always due to malicious intent. Employees are doing what they've always done, which is finding the fastest path to getting work done.
The problem is, many don’t realize that a deployed app is a publicly accessible website, while others think vibe coding platforms “handle all the security stuff.”
Here's what risk looks like when your employees use vibe coding sites without the right access controls:
  • Data leakage from unapproved AI tools: An employee uploads a client proposal to an AI tool. The privacy policy says chats could be used for model training, which means your client's data is now in a system you didn't approve and can't audit.
  • Credential and API key exposure: A non-technical founder pastes a production API key into an AI coding platform. The key isn't encrypted, and the AI coding agent embeds it into generated source code. This means anyone who opens the app or inspects the code can see the API key. The AI agent doesn’t treat a secret (API key) any differently from regular text.
  • False confidence from policy-only governance: An "AI acceptable use policy" is a great first step. But without enforcement at the point of access, the policy has limited effectiveness.
  • Compliance and audit risk: Your SOC 2 auditor asks which AI tools your employees are using and what data flows through them. The key motivation for this question rests on two figures: $5.27 million and 20.2%. That’s the average cost of a breach involving Shadow AI and how much longer it takes to contain this type of breach - IBM
Those stats carry weight with auditors because every major compliance framework requires controls to protect sensitive data. Here’s where each expectation maps to specific regulations and how LastPass addresses each.
Regulation
Governance Expectation
LastPass Capability
HIPAA (§164.312)
Control access to systems containing PHI
-SaaS Monitoring helps identify unauthorized AI tools
- SaaS Protect can block access to these tools, preventing the sharing of PHI
-Dark Web Monitoring flags compromised credentials, critical for accounts with PHI access
Logical access controls
-SSO + MFA helps enforce identity-based access to approved AI tools
-SaaS Protect can restrict unapproved AI tool access
Appropriate measures to ensure ongoing confidentiality, integrity, availability and resilience of systems and services
-SSO + MFA helps ensure only authorized users access systems processing EU personal data
-SaaS Monitoring helps surface shadow AI tools
-SaaS Protect can block these shadow tools, critical for preventing access to platforms with no data processing agreements
ISO 27001 Annex A.5 & A.8 controls
Asset inventory and access control
-SaaS Monitoring helps provide a continuous AI/SaaS asset inventory
-SaaS Protect can enforce access controls against unvetted tools
NIST AI RMF (GOVERN function)
Govern and monitor AI use
-SaaS Monitoring can deliver the live AI tool inventory recommended by GOVERN 1.6
-Access logs and authentication records create accountability trails supporting MANAGE and MEASURE functions.
Given the risks Shadow AI poses, is it any surprise that 79% of IT leaders report negative outcomes from employees sharing corporate data with AI? - Komprise
Of the 5,000 exposed AI-coding apps, RedAccess researchers also found:
  • Hospital work assignments with the PII of doctors
  • Detailed ad purchasing and go-to-market strategy docs
  • Full logs of chatbot conversations with retail customers
  • A shipping firm's cargo records
  • Sales and financial records from a variety of orgs
And most alarmingly of all, security researchers Joseph Thacker and Joel Margolis discovered that Bondu, an AI toy company, had left over 50,000 chat logs with children exposed on its web portal.
So, anyone with a Gmail account could log in and see sensitive info such as children’s names, birth dates, and other PII.
While the issue has since been corrected, one thing is clear: When platforms prioritize convenience over security, sensitive info is far more likely to leak, creating operational, legal, and reputational liabilities for your business.

Why does banning AI tools fail as a governance strategy?

Banning AI tools doesn't reduce risk. It just relocates it elsewhere.
In other words, when enforcement feels punitive, people stop telling IT about the tools they're using.
That's how you end up with 98% of employees using unapproved apps while IT thinks the situation is under control - Varonis.
Real AI governance isn't about eliminating AI but about shaping how it’s accessed and used (with IT in the picture).
The organizations with the healthiest posture on AI focus on visibility first and then apply measured controls to contain the risk.

Where does your organization sit on the AI governance maturity curve?

AI governance maturity can run from ad hoc (no policy or working inventory) to auditable (documented controls, available on demand).
Level 1 (Ad Hoc): At this level, there’s no formal policy or inventory of AI tools. Employees adopt tools at will, and IT has no visibility into what's being accessed or what credentials are being used. This is where most teams find themselves when they start tackling Shadow AI.
Level 2 (Visible): You have a rough inventory of which AI tools your employees are signing in to. This is a good start, but you don't yet have controls in place.
Level 3 (Partial Control): You have an approved AI tool list and some access controls, including MFA. But this is only for the tools you manage. Unapproved tools are discouraged but not blocked.
Level 4 (Governed + Auditable): This is where the LastPass Allow/Warn/Block access controls live. Approved tools are accessible, risky tools get a policy reminder at login, and high-risk tools are stopped at the point of access.
You can also produce a complete AI tool inventory and access logs on demand. Your controls are documented and tested, which means you can easily prove compliance.
Most small to mid-sized teams sit between Level 1 and Level 2 when they start. To get to Level 4, you need enforcement at the point of access.
If your team is at Level 2 or below, start with discovery first. LastPass surfaces every
SaaS and AI tool your employees log into through the browser.
 
Once you know what's in use, you can make informed decisions about what to allow or block.
Start your free trial now to see which AI tools your team is using.
 
 

What’s the optimum AI governance approach for lean IT teams?

For lean IT teams, it isn’t so much which approach to choose but where to start without incurring undue overhead.
Most mature AI governance programs combine several of the approaches below.
But for lean IT teams, identity-layer governance, i.e. controls applied at the credential level in the browser, at the point of login, will deliver the highest enforcement-to-overhead ratio. Here’s how the approaches compare.
Approach
What it controls
Strengths
Weaknesses
Policy-only or Allow-lists
Approved apps
Easily communicated
No technical controls at the point of access
Network-level blocking
Traffic to AI sites
Strong enforcement
Requires significant infrastructure & ongoing tuning; misses browser-based logins entirely
Endpoint monitoring
Device activity
Good visibility
Often alerts after activity occurs
Identity-layer governance
User access at login
Controls access regardless of network; aligns with least privilege; requires no proxy configuration or endpoint agents; low time-to-value
Controls access at login, not post-login data flows.

Note: To track post-login actions, pair LastPass with tooling like Permit.io or Salt Security.
 
 
TL; DR If you’re a lean IT team, prioritize:
  • Enforcement at the point of access
  • Controls that apply automatically
  • Low time to value and operational overhead
Each of the approaches in the table above maps to a category of tools:
  • Policy-only governance lives in your acceptable use policy.
  • Network-level blocking is what CASB tools do.
  • Endpoint monitoring is where EDR comes in.
  • And identity-layer governance is where LastPass operates, in the browser at the moment of login.
For lean IT teams evaluating tools in this space, a few things matter more than features.

How should you evaluate AI governance tools if you run a lean IT team?

The right AI governance tools for a lean IT team are the ones that deliver visibility and enforcement without requiring a dedicated security staff to run. That means evaluating based on operational fit, not features.
Here's what to look for:
  • Time to value: Can you see which AI tools your employees are using within days of deployment? Governance that requires months of configuration becomes a risk in itself.
  • No agents or complex integrations: If a tool requires installing agents on every endpoint, you’ll need to budget accordingly or opt for more practical controls.
  • Enforced controls, not just reports: A dashboard that shows you what's happening is useful. But a tool that also stops high-risk behavior at the point of access makes a real difference.
  • Productivity impact: Governance tools that frustrate employees will be bypassed. Controls should be proportionate to actual risk, which means they’re visible enough to matter and lightweight enough to keep compliance rates high.
  • Fit for SaaS and AI sprawl: 78% of employees use AI tools without company approval. Your governance layer must be equipped to handle that reality.
If you’re considering a CASB or EDR, remember: CASB tools enforce security at the network layer, while EDRs protect endpoints.
This is good but doesn’t address risk at the point of access.
With LastPass, you’re securing the identity layer, i.e. the point of access, where most AI risk actually starts. Here's how the three compare for lean teams.
Capability
LastPass
CASB tools
EDR tools
Governance
Identity (controls access at login)
Network (controls traffic to AI sites)
Endpoint (monitors device activity)
 
Discovery of AI tools in use
Automatically discovers SaaS and AI logins
Discovers apps through network traffic analysis
-Discovers app activity on managed endpoints only
-Not purpose-built for SaaS or AI app discovery
 
Where enforcement happens
At login, in the browser, at the moment credentials are entered
 
At the network or proxy layer
 
On the device, after the agent is deployed. Any endpoint without the agent installed is invisible to real-time monitoring tools
 
Ability to guide employee behavior in real time
In‑browser with Allow/ Warn/ Block prompts to interrupt risky actions before data is shared
Limited real‑time guidance; primarily blocks or allows traffic based on policy
Alerts after the action has occurred; employees aren't guided at the moment of decision.
 
Deployment and operational overhead
Deploys through an existing browser extension; no agents required
 
Complex deployment, often requiring proxy configurations or endpoint agents; heavy policy tuning overhead
 
Requires agent installation on every endpoint
Fit for lean IT teams
Designed for small to midsized teams without dedicated security staff
Built for enterprises with SOC teams, strict data protection requirements, and thousands of users
Best suited for larger companies with dedicated security teams to monitor & respond to alerts
 
Time to value
Hours to first visibility; days to meaningful policy enforcement
 
Weeks to months, depending on network complexity
Full coverage depends on BYOD and contractor devices self-enrolling, something IT can’t enforce on hardware it doesn't own. In practice, coverage gaps can persist indefinitely, making the true time to value indeterminate.
 
If you’re a small firm, your most budget-conscious AI governance move is access control.
While you may be able to leverage tools like Microsoft Purview to block sensitive data from being pasted into AI coding platforms, the cost (and hassle) could override any positives.
First, you’ll need either a Microsoft 365 E5 license (listed at $60/per user per month) or an E3 license with a Purview DLP (data loss prevention) add-on.
An E3 license is listed at $39/per user per month, with the Purview suite add-on at $12/per user per month.
Source: Microsoft (note that prices may change)
However, even with copy-paste restrictions in Microsoft Purview, the most motivated vibe coders will still find workarounds.
If you don’t yet have visibility or data controls in place, start with the LastPass “Block” rule for high-risk vibe-coding platforms.
As you gain visibility into usage, shift to a more balanced approach using “Warn” rules to sustain innovation without increasing risk.

What will your auditor ask about AI tools?

Whether you're preparing for SOC 2, HIPAA, GDPR, or a cyber insurance renewal, auditors reviewing AI governance typically focus on six (6) questions.
  1. Which AI tools are in use across your environment? Auditors want a complete inventory of AI tools employees are actually logging into.
  2. Who has access to each AI tool? Access should be tied to a specific user, not shared.
  3. Are employees using personal accounts to access AI tools at work? 43% of SaaS logins occur via personal emails. Both corporate and personal logins should be tracked.
  4. Which AI tools have access to regulated or sensitive data? Any tool your employees use to process client data, payments, or customer PII is in scope for most compliance frameworks.
  5. Which tools have you blocked, and why? Documented app denials show your governance approach is proactive rather than reactive.
  6. How do you provide evidence of access controls to auditors? Access logs, authentication records, and SaaS inventory reports provide evidence of compliance.
 
Start a free trial to see every SaaS and AI app your team is accessing with both corporate & personal credentials. Start getting visibility within hours, without a complex deployment or enterprise budget.
 
 

What’s the LastPass Allow/Warn/Block model, and how does it support AI governance?

The LastPass Allow/Warn/Block model is a three-tier access control framework that lets your team apply different levels of control based on the app’s risk level. It's the practical alternative to blanket bans and expensive enterprise AI governance tools.
What does "Allow" mean in LastPass?
In LastPass, “Allow” means the tool is approved, readily accessible, and IT has visibility into who's using it and how they're authenticating.
What does "Warn" mean in LastPass?
In LastPass, “Warn” means the tool isn't prohibited, but employees get a prompt at login that reminds them of the risks before they proceed.
In-browser warnings work because they interrupt behavior at the moment a decision is being made, not after the fact. For example, a marketer about to upload a customer list to an AI chat platform sees a message about your org’s data handling policy. Most of the time, that's enough.
What does "Block" mean in LastPass?
In LastPass, “Block” means the tool is off-limits, and access is stopped at login.
Blocking should be targeted, however. Reserve it only for tools with known security vulnerabilities and high-risk data handling practices.
Compare your current approach to managing SaaS visibility with LastPass Allow/Warn/Block.
There are so many apps based off the browser now. [LastPass] SaaS Monitoring shows me where people are going and whether they’re using tools they shouldn’t be…Most users stick to the apps we give them, and I can warn them–or just talk to them–if something looks off. (Northland Communications)
 
 
Related reading:

A practical AI governance model for lean teams

Yes. In most cases, a contextual prompt at login, one that surfaces the risk and reminds employees of your corporate policy, stops a significant portion of high-risk behavior before it happens. 

Not for most small to mid-sized teams. CASBs and SSPMs deliver real value for larger enterprises with dedicated security teams.  

SSPMs, in particular, are built to audit configurations and remediate compliance drift in tools you've already approved. But they don’t intercept access in real time, which means they don’t address the login-layer risk for lean teams still grappling with SaaS sprawl. 

For such teams, the operational overhead to deploy and maintain CASBs or SSPMs often outweighs the benefits, especially when browser-based access controls can cover the highest-concentration risk with much lower overhead. 

Start by making them visible. SaaS Monitoring surfaces apps your employees log into. 

If you don’t yet have the right controls in place, use the LastPass “Block” rule to prohibit access to known high-risk vibe-coding platforms. 

From there, you can apply the “Warn” rule to lower-risk platforms, requiring that any app connecting to company data (via integrations or APIs) be registered with IT. 

The goal isn't to stop your team from building but to stay in the picture when they do.

Start with visibility. Deploy a tool that surfaces which AI apps employees are accessing through the browser.  

Once you have a Discovered Apps list, apply Allow/Warn/ Block rules to the highest-risk tools first.  

For many organizations, that can be a practical starting point for AI governance and SaaS oversight. You don't necessarily need to begin with a CASB or XDR to gain initial visibility into AI app usage. 

Share this post via:share on linkedinshare on xshare on facebooksend an email