I’ve never seen a legitimate use case for disabling autocomplete, but have been prevented from using my password manager on many occasions, resulting in me having to either modify the source code via developer tools, type a very long password, or copy and paste it. Both of the last two cases increase the attack surface for passwords via key logging or clipboard snooping.
The one case that has come close to being legitimate is shared computers, but that should be handled by security controls on the endpoint.