AI for MSPs: Shadow AI, the Revenue Gap, and How to Lead the Conversation Your Clients Are Already Having

Key Takeaway: AI for MSPs is not a product decision. It is a positioning decision. The MSPs that figure this out early will own the AI conversation with their clients for the next decade.

AI for MSPs is not a product decision. It is a positioning decision. The MSPs that figure this out early will own the conversation with their clients for the next decade. The ones that treat AI as another line item in the stack will watch their clients get that conversation from someone else.

The numbers are stark. Kaseya’s 2026 State of the MSP Report found that 48% of SMB clients want AI services from their IT provider. Only 13% of MSPs are selling them. That gap is not a market condition. It is a choice. And it is a choice that is costing MSPs revenue, relevance, and client relationships they do not know they are losing.

This hub collects everything Rewired MSP has published on AI, from the language gap between what MSPs say and what clients hear, to the legal liability that comes from getting AI governance wrong, to the shadow AI problem that is already inside your clients’ businesses whether you are managing it or not.


The AI Language Gap: Why MSPs and Clients Are Not Having the Same Conversation

When an MSP talks about AI, they often mean a specific category of technology, generative AI, large language models, agentic workflows, deterministic automation. When a client talks about AI, they usually mean something simpler: tools that make their work faster, smarter, or less repetitive.

The gap between those two conversations is where most MSP AI strategies fail. MSPs lead with the technology. Clients want to hear about the outcome. An MSP that opens an AI conversation with a taxonomy of model types has already lost the room. An MSP that opens with “here is what your employees are already doing with AI, here is what that costs you, and here is how we can make it work safely” has the client’s full attention.

The language gap is not just a communication problem. It is a trust problem. Clients who do not understand what their MSP is recommending cannot evaluate whether the recommendation is in their interest. That uncertainty breeds skepticism, and skepticism is the enemy of the advisory relationship.

Shadow AI: The Problem Already Inside Your Clients’ Businesses

Your clients’ employees are already using AI. They are pasting client data into ChatGPT to draft proposals. They are uploading financial spreadsheets to free AI tools to build models. They are using AI coding assistants that send proprietary code to external servers. They are doing all of this without IT approval, without security review, and without any understanding of where their data goes.

Research cited across multiple industry sources suggests that 80% of employees use AI tools that their IT department has never approved. That is not a future risk. It is a current exposure. Every piece of client data that leaves the organization through an unapproved AI tool is a potential breach, a potential compliance violation, and a potential liability.

The MSP’s role is not to ban AI. Banning AI does not work. It just drives usage further underground. The role is to build the governance framework that allows employees to use AI productively while protecting the data that the business is responsible for. That means an acceptable use policy, approved tool lists, training on what is and is not appropriate to share with AI systems, and monitoring for shadow AI activity.

AI Governance: What Every MSP Should Be Building for Clients

AI governance is the set of policies, processes, and controls that determine how AI is used within an organization. It is not a technology problem. It is a leadership problem. And it is one that most SMB leaders are not equipped to solve without help.

A basic AI governance framework for an SMB client includes four components. First, an acceptable use policy that defines what AI tools are approved, what data can be shared with them, and what the consequences are for violations. Second, a data classification framework that helps employees understand which information is sensitive enough to require protection. Third, training that goes beyond a one-time module, employees need to understand the specific risks of the tools they are using, not just the general concept of data privacy. Fourth, a review process that keeps the policy current as the AI landscape changes.

MSPs that build this framework for clients are not just managing a risk. They are demonstrating a level of strategic leadership that most clients have never received from an IT provider. That is a retention driver and a differentiation driver simultaneously.

AI Legal Liability: What MSPs Need to Know

The legal landscape around AI is moving faster than most MSPs are tracking. The case of US v. Heppner established that AI-generated content used in professional contexts can create liability for the professional who submitted it, even if they did not know the content was inaccurate. The implication for MSPs and their clients is significant: AI tools that generate reports, proposals, compliance documentation, or client communications create a liability exposure that did not exist before those tools were in use.

MSPs that are helping clients adopt AI without addressing the liability question are not delivering complete advisory. They are delivering half the picture. The complete picture includes: what the tool does, what data it uses, where that data goes, what the output is used for, and who is responsible when the output is wrong.

AI Washing: How to Spot Vendors Who Are All Hype

The AI vendor landscape in 2026 is saturated with products that claim AI capabilities they do not actually have. AI washing. The practice of labeling conventional automation or rule-based systems as “AI-powered”, is widespread enough that MSPs need a framework for evaluating vendor claims before recommending products to clients.

The questions that cut through the hype are specific. What model does the product use, and is it proprietary or a wrapper around a public API? What data does the model train on, and does client data contribute to that training? What is the specific use case, and what is the measurable outcome? Can the vendor provide a reference client who has achieved that outcome?

Vendors who cannot answer those questions specifically are selling marketing, not capability. MSPs who recommend those products to clients are putting their advisory credibility at risk.

The AI Revenue Gap: How to Close It

The 35-point gap between client demand for AI services (48%) and MSP delivery of AI services (13%) is not primarily a technical gap. Most MSPs have the technical capability to deliver basic AI governance, AI tool management, and AI strategy advisory. The gap is a positioning gap. MSPs have not figured out how to package, price, and present AI services in a way that clients understand and value.

The path to closing the gap starts with the conversation, not the product. MSPs that lead with “we offer AI services” get blank stares. MSPs that lead with “we know your employees are already using AI tools, and we can help you make that safe and productive” get immediate engagement. The entry point is the problem the client already has, not the solution the MSP wants to sell.

From that conversation, the service offering builds naturally: an AI audit to identify what tools are in use, an acceptable use policy to govern them, approved tool recommendations to replace the risky ones, and ongoing monitoring to keep the environment current. That is a service clients will pay for, because it solves a problem they already know they have.

AI and the MSP’s Own Operations

The AI conversation is not only about clients. MSPs that are not using AI to improve their own operations are falling behind on efficiency, and that inefficiency will eventually show up in their pricing and their service quality.

The highest-value AI applications for MSP operations are in documentation, ticket triage, and client communication. AI tools that generate first drafts of documentation from ticket notes, that categorize and prioritize incoming tickets, and that draft client-facing summaries of incidents are not replacing technicians. They are giving technicians back the time they currently spend on low-value administrative work, time that can go toward the high-value work that clients actually pay for.

Frequently Asked Questions

What AI services should MSPs be offering in 2026?

The highest-demand, most defensible AI services for MSPs are governance-focused: AI acceptable use policy development, shadow AI auditing, approved tool management, and AI security risk assessment. These services address problems clients already have, require no new technical infrastructure, and position the MSP as a strategic advisor rather than a product vendor.

How do you explain AI risk to a client who is not technical?

Use the data analogy. Ask the client whether they would be comfortable with an employee emailing sensitive client data to a stranger’s personal email account. Most clients say no immediately. Then explain that pasting that same data into an unapproved AI tool has a similar risk profile. The data leaves the organization, goes to a server the business does not control, and may be used in ways the business did not authorize. That framing lands.

What is an AI acceptable use policy?

An AI acceptable use policy is a written document that defines which AI tools employees are permitted to use, what categories of data can be shared with those tools, what the approval process is for new AI tools, and what the consequences are for violations. It is the AI equivalent of an acceptable use policy for internet access. A governance document that sets expectations and creates accountability.

How do you stay current on AI developments as an MSP?

The AI landscape changes faster than any individual can track comprehensively. The practical approach is to focus on the categories that affect your clients most directly: data privacy and governance, security risks from AI tools, and the specific tools your clients are most likely to use. Following CISA guidance, monitoring vendor security bulletins, and maintaining a relationship with a legal advisor who tracks AI liability developments covers most of what matters operationally.

About Brent Lacy: Brent Lacy is a technology advisor and the voice behind Rewired MSP. He helps MSPs operate with greater maturity and helps business owners make IT choices that make them more secure and more efficient. He is the author of Rewired MSP: Mastery, Scalability & Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.

Go Deeper: Every AI Article on This Site

Sources