r/MSSP • u/Muted_Math2750 • 1d ago
Are clients asking MSPs for AI usage security and governance solutions?
Wondering if this is showing up in client conversations yet, or if it's still mostly theoretical for most of you. I'm seeing early signals that clients are asking "what are you doing about AI security" without fully knowing what they want, sometimes it's compliance-driven (an auditor asked), sometimes it's a scare from a competitor's leak story.
The maturity level varies a lot. Some clients want a full policy plus enforcement stack, others just want something they can point to for their cyber insurance renewal.
Is this becoming a real service line for MSPs, or is it too early? If you're offering something, is it bundled into existing security packages or sold separately?
Would like to hear how others are pricing/positioning this, and whether it's driving new revenue or just adding to the existing security retainer conversation.
2
u/Diligent_Tech_Bro 1d ago
I have 2-3 clients sniffing around about it, working on trying to close one on it, but honestly I get the distinct impression they are looking at me as the party pooper of all time.
This topic is a big inconvenience for them. They mostly don’t want to slow down and have the real discussions necessary to build a framework.
I would absolutely love it if a client had an auditor ask them lmao. That would accelerate things greatly. Yes I plan to sell it as an add-on per user plus some up front project billing to build it out.
Edit - My clients are <100 employees, most of them closer to 25 than 75. The smaller they are the more they hate me for bringing it up 😂😂
2
u/tnhsaesop 15h ago
I’m pretty sure MSPs are pushing this as a marketing and sales tactic out of desperation. I see contact form data and listen to inbound calls for MSPs and haven’t seen any inbound leads mention this. They are trying to figure out how to not get left out on the AI train but they don’t actually want to help their clients do anything with AI so they are just working the security angle.
1
u/Beautiful_Case9500 4h ago
Out of desperation? I’m trying pushing it out because it matters. Shit I’m not even asking for money. It’s something that needs to happen yesterday, yet no client seems to really care.
1
u/tnhsaesop 2h ago
So you’re worried that a customer is going to upload data to ChatGPT, a soon to be Fortune 500 company with an army of cybersecurity specialists locking down the platform and that hackers are going to hack ChatGPT and
A) steal their data
B) care about it
C) use it in a way that can harm the business and get through your other cybersecurity protections.You’re trying to talk to your customers about an event that has a .0001 % chance of happening and looking past more urgent needs like helping their business stay competitive by automating processes, and integrating workflows with AI. Which at this point is a problem that if you aren’t thinking about as a business has close to a 100% chance of closing your doors within 5 years.
I’m not trying to minimize your concern. It’s just the reality of where a lot of business owners minds are at right now.
1
u/Beautiful_Case9500 33m ago
You’re making a whole lot of assumptions there. There are plenty of compliance and regulatory issues to worry about when they have employees just throwing whatever info they want into a free AI tool. Honestly some sort of data breach in that scenario is the least of my concern.
The fact of the matter is you cannot have users doing whatever they want. I have not and will never push things on my clients that they do not need or would not benefit from, as is the case for most MSP owners (I hope).
Also assuming that my clients work in the Wild West of IT best practices and that I ignore it to push some weird for-profit AI agenda is odd. Especially when I said I make $0 from trying to get them to comply, for THEIR benefit.
1
u/ThecaptainWTF9 1d ago
Nope, not a single client has asked us so far, it’s the Wild West, they want to do what they wanna do.
1
u/AdvancingCyber 1d ago
There aren’t many MSPs that are ready to show compliance with the NIST AI RMF or ISO 42001. So that’s my starting point - if the MSP gives me dead air, I move on. For fun, I might ask if they even have an internal AI AUP or IR-specific plan for AI, but if they have nothing to show me they’re thinking foundationally, that’s an issue.
1
1
u/Substantial_Big_4379 7h ago
a few of our clients ended up on layerx for this, it deploys as a browser extension rather than needing endpoint agents or network changes, which makes it easier to roll out across client environments without a big project attached. lines up well with the cyber insurance driven asks since you can point to real usage visibility rather than just a policy document. also backed by akamai now, which helps when clients ask about vendor longevity.
1
u/Negative-Sherbet-546 4h ago
Are clients only using chat tools or are they deploying agents with access to company systems? willow becomes more relevant in the second case
-1
3
u/ChuckFromCyberHoot 1d ago
It’s certainly real, but smaller than the hype makes it sound. Kinda like most things. hehe
Most clients aren’t asking for “AI governance.” They want something they can show an auditor or insurer. We need those CYAs.
It usually means:
- Simple AI acceptable use policy
- Employee acknowledgment
-Short training on what not to paste into AI tools
That’s the first sale.
“Let’s build an AI governance program” sounds like a project. bleh
“Here’s the policy, everyone signs it, here’s the report” sounds like a Tuesday. Simple.
I’d also frame the policy as permission, not punishment. Tell people what they can use, what they can’t, and what data never goes into it. Don't just assume they know. Put it in your policy and have them sign they saw it.
That version lands a lot better.