Most MSPs think about AI as a service they might eventually sell. There is a more urgent version of the same opportunity sitting in front of every client right now: nobody is watching what employees are already doing with AI tools, and that gap is a security and compliance problem an MSP is uniquely positioned to close.

The Gap Is Bigger Than Most MSPs Realize

Employees are not waiting for permission. Three in five workers (59%) say they use AI tools that have not been approved by their company, and the average enterprise employee now uses 4.7 AI tools a week, only 1.2 of which are IT-approved, according to IBM‘s research on shadow AI. Zylo’s 2026 SaaS Management Index found that 77% of IT leaders discovered AI-powered features or applications operating without their awareness.

The gap between perception and reality is just as stark: 78% of executives believe they have a clear picture of AI usage inside their organization, while the real figure from employee surveys is closer to 23%, per Palo Alto Networks cyberpedia research.

The Real Risk Is Data, Not the Tools Themselves

According to a Cisco study cited in the same research, 27% of employees have pasted sensitive company data into public AI tools, and 38% acknowledge sharing sensitive work information with AI tools without employer permission. This is not hypothetical: three Samsung semiconductor engineers leaked proprietary data by pasting source code, meeting transcripts, and chip yield test sequences into ChatGPT within a single month.

Every client an MSP already supports has this exposure today, whether anyone has looked for it or not.

Why This Is an MSP Opportunity, Not Just a Risk

MSPs already own the security conversation, the backup conversation, and the compliance conversation for their clients. AI governance is the same category of ownership, and right now almost nobody is claiming it. There is no single industry-standard AI compliance certification yet, the way there is for security frameworks, which means an MSP that builds a clear, defensible AI usage policy for clients today is defining what responsible AI use looks like in that relationship before anyone else does.

The fix does not require blocking AI outright. Research on shadow AI adoption has found up to an 89% drop in unauthorized AI usage once employees are given approved, sanctioned alternatives, meaning the solution is substitution and policy, not prohibition.

What an MSP Can Do About It This Quarter

  • Audit what AI tools and browser extensions are already installed across client endpoints
  • Draft a simple, plain-language AI usage policy: what is safe to use it for, what is off-limits (client PII, financial data, source code), and what requires approval first
  • Offer one or two approved, sanctioned AI tools as an alternative to the unapproved ones already in use
  • Make AI governance part of the standard QBR conversation, the same way backup and patching already are

Frequently Asked Questions

Do MSPs actually need to become AI experts to do this?
No. Governance is a policy and process problem first, an MSP already knows how to build a policy and enforce it on managed endpoints.

Isn’t this just another version of a security policy?
Structurally, yes, which is exactly why it fits the MSP model. It is the same discipline applied to a new category of tool.

What happens if a client says they don’t have an AI problem?
The data says otherwise for almost every organization. The honest answer is usually that nobody has looked yet, not that the exposure doesn’t exist.

Sources: IBM, What Is Shadow AI; Palo Alto Networks, What Is Shadow AI.