Resources/AI Adoption Inside Your MSP
    AI

    AI Adoption Inside Your MSP

    Nearly every MSP uses AI. One in four runs a business around it. What closing that gap looks like at 15 people.

    GTIA research this year puts internal AI adoption across the channel at 97 percent. Only 20 percent have written governance behind that use, and only 25 percent qualify as what GTIA calls AI Driven, meaning formal adoption, governance, and a revenue strategy.

    Read that again. Nearly every MSP has AI in the building. Three out of four have no plan for it.

    That gap is not a technology problem. Your techs figured out ChatGPT on their own. Somebody in sales is running prospect research through Claude right now. The tools work. What's missing is anyone deciding what the business is trying to accomplish with them.

    GTIA's ITSP AI Implementation and Services Guide lays out a solid framework for closing that gap. I want to walk through what they got right, and where the framework needs adjusting for a 15 person shop that does not have a governance committee sitting around waiting for something to do.

    Start with what AI actually does

    Before you write a policy, before you buy a tool, before you run a pilot, you need an honest picture of what AI can and cannot do for your business.

    This sounds obvious. It gets skipped constantly.

    Owners read a headline about agents replacing service desks and go shopping. Or they watch a demo, see something impressive, and assume the impressive thing maps to their environment. It usually does not. The demo ran on clean data. Your client's SharePoint has eleven years of sediment in it.

    Here's the honest version. AI is very good at first drafts, summarization, pattern matching across large text sets, and repetitive language work. It's unreliable at anything requiring current facts it wasn't given, at math, and at knowing when it's wrong. It does not remove the need for someone competent to check the output.

    Once your leadership team understands that, every downstream decision gets easier. You stop chasing tools that solve problems you don't have.

    Governance before deployment, and yes that order is correct

    GTIA puts governance early in their sequence. Some people push back on that. They argue small firms should experiment first and formalize later.

    They're wrong, and I'll tell you why.

    The cost of no guidelines shows up in two places. First, token spend. Nobody's watching consumption, three people are running the same bloated prompts fifty times a day, and your bill triples before anyone notices. Second, and far worse, confidential information ends up in personal LLM accounts. Client data. Credentials in a pasted log file. Contract language. Once it's in someone's personal ChatGPT history, you have a disclosure problem you cannot undo.

    You do not need a forty page policy. You need answers to four questions, written down, in front of your team.

    Which tools are approved. Which accounts people use, meaning company accounts, not personal ones. What data never gets pasted into a prompt. Who to ask when someone's not sure.

    That's a one page document. Write it this week.

    The vendor side matters too. Your RMM, your PSA, your documentation platform, they're all shipping AI features. Find out what those features do with your data before you turn them on.

    Shadow AI is a security problem, not a discovery exercise

    You'll hear the argument that unsanctioned AI use is useful signal about where your team feels friction. There's something to that. Pay attention to what people reach for.

    But treat it as a security incident first. Someone running client data through an unmanaged account has created exposure regardless of how good their intentions were.

    Find it. DNS logs and endpoint monitoring will show you most of it. Then give people a sanctioned path to the same capability, because the demand does not go away when you block the tool. It just goes further underground.

    What to actually deploy first

    GTIA lists internal use cases including LinkedIn outreach automation, competitor research, SEO work, dispatch agents, legal assistant agents, internal wiki updaters, and project estimators.

    That is a menu, not a plan. A 15 person MSP that tries to run eight initiatives at once finishes zero of them.

    Pick one. One pilot, not two, not three. Pick the one where you already know the process, the process is repetitive, and a bad output is easy to catch. Documentation cleanup. Ticket summarization. First draft of client facing reports. Something where the failure mode is embarrassment, not liability.

    Run it for sixty days. Measure one number. Time saved, tickets closed, whatever fits.

    Then pick the second one.

    The hiring question

    Every owner asks it eventually. Does this mean I stop hiring?

    No. It means you slow hiring down.

    The play is not replacing people. The play is making the people you already have significantly more efficient, so the next hire happens at a higher revenue number than it otherwise would. Your senior tech spending forty minutes a week on documentation instead of four hours is worth more to you than a headcount reduction, because that tech is still there for the work only they can do.

    Tell your team that directly. AI adoption stalls fastest when people quietly believe they're automating themselves out of a job. They will not tell you that's what they're thinking. They'll just not use the tool.

    The maturity stages, condensed

    GTIA maps five stages. Awareness, preparation, adoption, optimization, growth.

    For a firm your size, the honest translation looks like this.

    You understand what the technology does and does not do. You've written down the rules. You're running one or two things in production and you know whether they worked. You've made those things standard practice instead of side projects. Then, and only then, you sell it.

    Most firms trying to sell AI services right now are skipping to the last stage. Clients can tell.

    The prerequisite nobody mentions

    Here's a detail from the GTIA guide worth sitting with. They note that even simple deployments have hidden blockers. Their example is auditing SharePoint before deploying Copilot.

    That's the whole game in one sentence.

    Copilot surfaces whatever a user already has permission to see. If your client's permissions have drifted for a decade, and they have, Copilot becomes a very efficient way for the wrong person to find the payroll folder. The tool works exactly as designed. The environment is the problem.

    Every AI deployment has a version of this. The prep work is the work. The tool is the easy part.

    Where this usually goes sideways

    Not in the technology. In the follow through.

    Owners run a pilot, see something promising, then get pulled into a client escalation and never operationalize it. Six months later the tool is still on a credit card and nobody uses it. Or the opposite, someone gets excited and rolls out four things at once with no measurement, so nobody can say whether any of it helped.

    The firms that close the gap treat this as an operations problem with a schedule and an owner, not an innovation project.

    That's the part I work on with partners. I serve as a fractional COO and CTO for MSPs in the 10 to 20 employee range, and AI is one lane of several. The work is building the operating discipline that makes any initiative stick, then applying it to the specific decisions in front of you. What to deploy, what to skip, what to charge for, and in what order.

    Talk it through

    The firms that close the gap treat AI as an operations problem with a schedule and an owner, not an innovation project. If you are somewhere in the 97 percent and want to get to the 25 percent, that is where it starts.

    Everything above is a template. Run it yourself this week and never talk to me. What I will not do is hand you a system and tell you your shop is wrong for not matching it.

    Not sure this is your actual constraint? Take the MSP Owner Reality Check. Five questions, nine minutes, and it names the two or three things quietly capping your growth. https://themsphero.com/resources/msp-owner-reality-check-assessment

    If you already know what is broken, book a 30 minute fit call at https://letschat.themsphero.com

    Mike Kolb The MSP Hero


    Source material and channel adoption data from the GTIA ITSP AI Implementation and Services Guide, produced by the GTIA Channel Development Advisory Council. Note that the original guide references a standard as NIST 43,001. The relevant frameworks are ISO 42001 for AI management systems and the NIST AI Risk Management Framework.

    I WILL NOT SELL YOU A PLAYBOOK

    Frameworks are easy to buy and easy to ignore. What changes your business is someone looking at your actual numbers, your actual team, and your actual clients, then telling you what to fix first. Start with the free read, or just book the call.