Key takeaways
- Shadow AI exists because employees access AI tools with personal credentials that bypass corporate identity controls
- 47.11% of enterprise AI conversations happen via personal rather than corporate identities, creating an identity risk most IT teams are missing (The Hacker News / enterprise AI risk research, 2026)
- 80% of employee AI tools operate without IT oversight, with small and mid-sized companies averaging 414 unsanctioned AI tools per 1,000 employees (Reco, The State of Agent Security 2026)
- 39.7% of all AI interactions involve the sharing of sensitive data; the average employee enters sensitive data into an AI tool once every three days. (Cyberhaven Enterprise AI Trends Report, 2025/2026)
- LastPass SaaS Monitoring is a SaaS discovery tool that surfaces both approved and unapproved AI/SaaS access across personal and corporate credentials. It works alongside SaaS Protect, which provides the controls to secure this access.
Nearly half of enterprise AI conversations happen through personal identities. And that’s a problem because much of the access that enables these conversations exists outside traditional controls.
And as AI agents rise in popularity, the problem grows. Agentic identities inherit permissions from the humans who deploy them. If the underlying human identity isn't governed, the agent also becomes harder to govern.
Ask yourself: Do you know which of your employees have deployed agents?
68% of your peers think they do, but 82% also said they’ve discovered unknown agents in the past year.
Governing agents is critical and something everyone’s talking about. But it all starts with identities: Without visibility into who’s accessing what AI platforms, it’s difficult to determine your exposure to agentic risk.
Why can’t IT see the AI tools employees are accessing?
Consumer AI tools don't require corporate credentials. An employee can use a personal email to sign up for ChatGPT, Claude, or DeepSeek, and upload company files into the tool without anyone the wiser.
According to research by Akamai published in The Hacker News, 47.11% of AI conversations occur through personal, rather than corporate credentials.
And while Gemini Enterprise (98.15%) and Copilot M365 (90.55%) keep most interactions inside corporate identity systems, four platforms are overwhelmingly accessed with personal logins.
These are DeepSeek (99.8%), Copilot Standard (63.92%), ChatGPT (61.36%), and Claude (61.09%).
But before you update your acceptable use policy to ban DeepSeek and personal tiers of Copilot, Claude, and ChatGPT (although this may be advisable), the problem is actually more complex than that.
The same Akamai research also found that, while 14.4% of enterprise AI chats occurred via corporate logins, they were linked to “freemium” subscriptions, not enterprise-managed licenses.
The use of extensions is also more prevalent at smaller firms: 17.7% of employees at midsized enterprises use at least one AI extension, compared with 9.53% at larger organizations.
At first glance, extensions may not seem like a meaningful threat.
But according to Akamai, nearly 75% of extensions request high or critical permissions, significantly raising SaaS security risks for any organization, regardless of size: High permission extensions are more likely to request and be given read/write access to popular workforce apps like Jira, Salesforce, Google Workspace, and GitHub.
Since these apps often contain proprietary code, customer PII, and sensitive internal communications, exposure can result in reduced brand trust, regulatory scrutiny, legal liability, and eventually, reduced revenue.
However, the problem isn't so much extensions but that the identities attached to them exist outside corporate controls.
Why is Shadow SaaS an identity problem?
Shadow SaaS is an identity problem because every SaaS interaction begins with an identity, which represents a human or non-human entity. Both entities, of course, need credentials to access SaaS resources, and this is where passwords (both personal & corporate), tokens, certificates, and API keys come in.
Many teams govern SaaS access through IdPs (identity providers) using SSO. But employees frequently adopt AI tools with personal email addresses or freemium accounts that bypass SSO.
When that happens, AI usage remains invisible to the IdP you’ve always relied on for visibility and governance.
In turn, this increases the difficulty of determining:
- What data employees are sharing with those AI tools
- What skills, hooks, or connectors are in use
- Whether access for specific tools should exist at all
The issue isn't so much the AI platform, but the unmanaged identities accumulating risk for your business.
Ultimately, if you can’t “see” the human identities in active circulation, you can't apply controls, monitor usage, or revoke access for high-risk AI or agentic usage.
It isn’t surprising, then, that 63% of breached organizations lack an AI governance policy and access controls to govern safe usage (IBM, 2025).
So, Shadow AI discovery must start with identity visibility, in particular human identities. LastPass SaaS Monitoring provides that visibility so you can govern AI access before it becomes a security or compliance risk.
What’s the scale of SaaS risk Shadow AI tools are creating?
According to a Reco report highlighted on SC Media, 79% of SaaS apps in use across corporate workflows are approved tools.
But 80% of employee AI tools (which includes extensions and MCP connections) operate outside IT oversight.
Small to mid-sized organizations have high amounts of shadow SaaS: There are about 414 unsanctioned AI tools per 1,000 employees on average.
The Hacker News research adds a dimension specific to SaaS app security: 16.31% of AI browser extensions contain known CVE vulnerabilities, compared to 10.80% of regular browser extensions.
A vulnerability in an AI extension isn't an isolated risk. The extension operates inside a user’s trusted browser session, where it can potentially access prompts, sensitive web pages, clipboard content, and proprietary data.
Case in point: A July 2025 browser extension campaign that reached eight (8) million+ users. The extension exfiltrated their private conversations across eight (8) AI platforms to a third-party server that sells them to advertisers.
Meanwhile, a similar campaign in January 2026 found 900,000 enterprise installs of extensions exfiltrating conversation histories to attacker-controlled domains every 30 minutes, despite claiming to only collect “anonymous, non-identifiable analytics data.”
Every statistic above starts with a root cause: Unmanaged human identities.
How Shadow AI tools compound the SaaS risk you already have
When an employee logs in to a consumer AI tool with a reused password, an unmanaged access path is created and connected to a credential that may already be compromised.
If that credential surfaces in a breach, the account and whatever business data it holds is exposed alongside it.
A second risk running in parallel is the data risk.
According to Cyberhaven's analysis of enterprise AI usage, 39.7% of all AI interactions involve the sharing of sensitive data.
In fact, the average employee enters sensitive data into an AI tool once every three days.
Sales and GTM data accounts for nearly 30% of sales team AI inputs, while source code and technical assets are the primary input category for developer AI tools.
Neither exposure appears in your logs when IT has no record of the session.
And as mentioned, there’s a newer dimension of SaaS risk: Agentic AI.
MCP servers, the layer that connects AI agents to external tools, are themselves becoming a Shadow IT surface: 50% of MCP servers enable shell command execution, 82% permit local file read/write privileges, and 40% combine all three: shell access, file access, and outbound network calls.
Without visibility into your current human identities, it becomes more of a challenge to govern a layer of autonomous AI agents running on top of it.
The risk isn’t theoretical. Consider the Hugging Face experiment, where 1,200 agents that were supposed to be isolated from each other began communicating on an unauthorized message board, established by one of the agents.
The group of agents were then able to exchange more than 70,000 messages & files there. In all, 700 agents participated in the Hugging Face attack.
Specifically, the agents exploited a zero day in Artifactory (a package repository OpenAI used for its agents) to get internet access, and when they found exposed Hugging Face credentials, began posting them on the board. Seeing this, fellow agents proceeded to sign up for accounts in order to request private datasets.
Suffice it to say that as organizations adopt more agentic workflows, identity governance becomes critical, because agents ultimately inherit access from their human owners. Visibility must start with human access.
How is SaaS app security affected with AI in the mix?
With SaaS adoption accelerating and embedded AI features now customary, the inventory problem intensifies another: Compliance.
The EU AI Act classifies AI use in areas such as education, critical infrastructure, and law enforcement as high-risk, requiring monitoring, human oversight, and documented risk controls.
If you have unsanctioned AI tools in your stack (that you have no visibility into), it’s impossible to review their data residency and processing policies, which means you have no idea what regulatory exposure you’re dealing with.
A second challenge is emerging in a growing area: AI-assisted app creation.
Historically, employees introduced SaaS risk by adopting unapproved apps.
But AI has quickly and quietly changed that model.
Increasingly, employees can use AI coding assistants and low-code platforms to build custom business tools and agents with minimal effort. And with financial motivation high on the list of reasons why, the popularity of platforms like Base44, Lovable, and Replit will only grow. A work experiment can quickly evolve into a business-critical app connected to customer records, internal documents, and custom code.
This creates a new category of shadow SaaS.
Instead of employees signing up for an app, they can just build one themselves using AI.
The larger concern is which identity powers these vibe-coding accounts.
Many AI-built tools connect to SaaS platforms through personal credentials, API keys, browser extensions, or agents operating outside established identity controls.
Whether employees adopt software or build it themselves, the governance problem starts with identity.
Why blocking AI backfires
An IT policy that bans AI without sanctioned alternatives almost always pushes AI usage to channels where IT has no visibility.
The implication for governance is that a policy is most effective when employees have somewhere to go.
Organizations that deploy friction before establishing approved alternatives are less likely to stop the behavior that facilitates Shadow AI.
Real-time observability and enforcement are what gives you actual leverage over SaaS risk.
What SaaS discovery and access controls do
SaaS Monitoring is a SaaS discovery tool that runs continuously in the background via the LastPass browser extension.
It surfaces both approved and unapproved apps accessed with both personal and corporate credentials.
The added benefit is, unused apps are flagged automatically when 30 days pass without a login, reducing the accumulation of abandoned accounts that drive up SaaS spend.
Your SaaS inventory builds in real time without manual effort from your IT team.
For each app in the discovered footprint, you can set one of three policies:
- Allow: The app is sanctioned and employees can access it without friction
- Warn: The app is permitted but flagged at login. Employees get an in-browser message explaining the tool sits outside IT oversight, with an option to redirect to a sanctioned alternative.
- Block: Access is restricted, with a clear explanation at the point of access.
Together, SaaS Monitoring and SaaS Protect provide the foundation for SaaS app security that scales with how your people work: Visibility first and then enforcement at the point of access.
Both capabilities are included in LastPass Business Max, the same plan that covers credential security, Dark Web Monitoring, and phishing-resistant MFA.
Start here: your shadow AI governance checklist
If you don't have a current inventory of AI tools in use across your organization, here are some questions to explore first.
|
Question
|
Why it matters
|
|
Can your security tools detect AI logins with personal credentials?
|
Personal identities are often the starting point for Shadow AI activity.
|
|
Have approved SaaS products introduced AI features in the last six (6) months?
|
New AI capabilities can create additional governance requirements.
|
|
Do you know which browser extensions are used for AI workloads?
|
Risky extensions can become a pathway for compromise.
|
|
Does your offboarding process cover AI tools your employees signed up for independently?
|
Unknown, unmanaged accounts that persist can create risk, long after an employee leaves.
|
After you’ve determined answers to the above questions, try LastPass Business Max, which is specifically built for small to mid-sized teams.
It’s one platform covering SaaS app security without requiring a dedicated security team to run. To see your shadow SaaS footprint within days, start your free trial now.
Sources
Netskope. Shadow AI and Agentic AI 2025
Infosecurity Magazine: Unchecked AI Agents Cause Cybersecurity Incidents at Two Thirds of Firms (2026)
FAQ: Shadow AI is an identity problem
Can I see which employees signed up for AI tools using a personal email address?
Yes, you can. With LastPass SaaS Monitoring, you get a continuous view of SaaS & AI access right in the browser. So, as each employee logs in to an AI platform, this access activity is continually visible to you.
How do I stop employees signing up for software on a personal credit card?
While employee use of personal credit cards can’t be entirely prevented, you can put a mechanism in place to let you know when employees are accessing certain apps.
LastPass SaaS monitoring gives you a continuous view of SaaS & AI app access in the browser.
Once you know who’s accessing what, you can use that insight to begin a conversation about business requirements, data handling practices, and approved alternatives.
Ultimately, a productive discussion is focused on solutions, and LastPass provides the visibility to promote it.
What's the difference between SaaS Monitoring and SaaS Protect for SaaS access control?
SaaS Monitoring provides visibility into the SaaS & AI tools your employees access in the browser.
SaaS Protect provides the controls that let you govern SaaS access, enforced in the browser at the point of login. SaaS Monitoring answers, “What tools are running?" while SaaS Protect answers, "What should we do about it?"
Island vs LastPass: Do I still need SaaS and AI monitoring if I already have an enterprise browser?
Yes. Enterprise browsers like Island and Secure Access Providers like LastPass actually serve complementary functions.
1. Two separate control planes
- Island enforces DLP, prompt controls, session security, and extension governance.
- LastPass SaaS Monitoring and SaaS Protect operate at the app-access layer, surfacing which SaaS and AI apps employees are accessing and then applying controls to ensure safe access.
- Both are complementary: Island controls what users do once inside; LastPass governs which apps users access and how credentials are managed.
2. Coverage for credential/identity lifecycle management
- Enterprise browsers like Island identify risky behavior but don't provide a vault for managed sharing or credential lifecycle management.
- LastPass fills this gap with secure password generation, storage, sharing, recovery, and provisioning.
3. Non-SSO and Shadow SaaS coverage
- Many SaaS and AI tools employees adopt are never federated through SSO. Island can see the traffic but doesn't manage the passwords used to access those apps.
- LastPass SaaS Monitoring surfaces SaaS and AI apps employees access through the browser, so you can know who’s accessing what and can take action accordingly.
This doesn't have to be an either/or decision. Island can govern interactions within supported AI sessions, while LastPass can manage shared-access workflows and browser-based SaaS and AI logins (with both personal and corporate credentials).
Note: Island versus LastPass comparison is accurate as of August 2026.



