Resources/The AI Usage Survey Your MSP Should Send
    AI

    The AI Usage Survey Your MSP Should Send

    Two surveys: one for your own team this week, one you sell to clients once your house is in order.

    Most AI policy work starts in the wrong place. Someone reads an article, decides the shop needs a policy, and writes rules for a situation nobody has measured yet.

    Skip that. Find out what your team is already doing first.

    I have yet to walk into a 15 person MSP where the answer was "nothing." The answer is always some version of "three techs are running client ticket text through a personal ChatGPT account and nobody knew." That is not a productivity story. That is a security story, and you cannot write a useful policy until you know the size of it.

    This page gives you two surveys. The first one you send to your own team this week. The second one you sell to your clients once your own house is in order.

    Credit where it belongs: GTIA published an AI Tools Usage and Goals survey template that this work builds on. Their version targets a mid-size company with a Product team, a Legal department, and an HR function. Yours has none of those. I cut what does not apply, kept the good bones, and added the questions that matter when your staff has hands inside other people's networks.


    Why the generic template fails in a small shop

    Run the stock corporate survey in a 25-person MSP and three things go wrong.

    The department question breaks. You get options like Product, Legal, and HR. Your team picks "Other" and you learn nothing.

    It never asks about client data. That is the entire risk. A marketing team pasting a blog outline into ChatGPT creates a small problem. A tech pasting a client firewall config into a free account creates a breach conversation. The generic template treats both the same way.

    It runs too long. Nineteen questions with randomized option sets works when you have a survey team and a research budget. Your techs will abandon it at question eight. The version below runs six to eight minutes.


    Decision one: anonymous or named

    Make this call before you send anything, because it changes what you get back.

    Anonymous gets you honest answers. People tell you what they actually pasted into what account. You cannot follow up with any individual, and you should not want to. You fix the problem at the policy and tooling level.

    Named gets you an account-level risk picture. You can go clean up specific exposure. You also get people quietly editing their answers to look better.

    Run your internal survey anonymous. You want the truth more than you want a name. Run the client version named, because the client is paying you for a report they can act on, and "someone in accounting" is not something they can act on.

    One warning on anonymous surveys in small shops. Role plus tenure plus location identifies a person in a 15 person company. Ask for role in broad buckets and nothing else. Do not add a tenure field. Do not add a team field. If your service desk has four people and you ask for both role and years of service, your survey is not anonymous and your team knows it.


    Part one: the internal survey

    Send this to everyone including yourself. Use whatever form tool you already pay for. Give people a deadline of one week and tell them the results go to the whole team, not just leadership.

    Intro text to paste at the top of the form

    We are building an AI policy for the company. Before we write rules, we want an accurate picture of what people are already using and what is actually helping.

    This survey is anonymous. We are not tracking who submitted what and we are not looking to get anyone in trouble. If you have been using a personal AI account for work, say so. That information is more useful to us than a clean-looking survey.

    It takes about seven minutes. Please finish it by [DATE].

    The questions

    1. Which best describes your role?

      • Service desk, tier 1
      • Service desk, tier 2 or 3
      • Projects or field work
      • Sales or account management
      • Admin, billing, or finance
      • Leadership
    2. In the last 30 days, which AI tools have you used for work? Check all that apply.

      • ChatGPT
      • Claude
      • Microsoft Copilot inside Microsoft 365
      • Copilot or an AI assistant in your browser
      • Google Gemini
      • AI features built into our PSA, RMM, or documentation platform
      • A coding assistant such as GitHub Copilot or Cursor
      • A meeting notetaker or transcription tool
      • Image or video generation
      • Something else, please list it
      • None of these
    3. For the tools you named above, whose account were you signed into? Check all that apply.

      • A free personal account
      • A paid personal account I pay for myself
      • A company account we provided
      • I am not sure
    4. How often do you use AI tools for work?

      • Several times a day
      • Daily
      • A few times a week
      • A few times a month
      • Rarely
      • Never
    5. What do you use AI for at work? Check all that apply.

      • Writing or rewriting client-facing emails
      • Writing ticket notes or resolution summaries
      • Explaining an error message or log output
      • Writing or fixing scripts
      • Researching a product, error, or vendor issue
      • Drafting documentation or SOPs
      • Summarizing meetings or calls
      • Sales or marketing content
      • Quoting, pricing, or proposal work
      • Something else, please describe
    6. This is the important one. In the last 30 days, have you put any of the following into an AI tool? Check all that apply. Nobody is in trouble for an honest answer here.

      • Client company name
      • Ticket text written by a client
      • Log output, error messages, or event data from a client system
      • Configuration files or exported settings
      • Network diagrams or asset inventories
      • Email threads involving a client
      • Screenshots of a client environment
      • Usernames, passwords, keys, or tokens
      • Personal information about a client's staff or customers
      • None of the above
    7. Have you used a meeting notetaker or transcription tool on a call that included a client?

      • Yes
      • No
      • I am not sure
    8. Where has AI actually saved you time? Be specific. If the answer is "it has not," say that.

      • Open ended
    9. If the company stopped paying for AI tools tomorrow, would you pay for one out of your own pocket to keep using it?

      • Yes, definitely
      • Probably
      • No
      • I do not use them enough to say
    10. What gets in your way when you use these tools? Check all that apply.

      • I do not know what I am allowed to put in
      • I do not trust the answers
      • It takes longer to check the output than to do the work
      • I do not know how to write a good prompt
      • I do not have access to a paid account
      • The tool does not know anything about our clients or our systems
      • It has nothing to do with my job
      • Something else, please describe
    11. Do we have a written AI policy?

      • Yes, and I have read it
      • Yes, but I have not read it
      • No
      • I am not sure
    12. How confident are you that you would catch it if an AI tool gave you a wrong answer about something technical?

      • Very confident
      • Somewhat confident
      • Not sure
      • Not confident
    13. If we could point AI at one thing to make your week easier, what would it be?

      • Open ended
    14. Would you be willing to show the rest of the team something you have figured out how to do with AI?

      • Yes
      • No
    15. Anything else we should know?

      • Open ended

    How to read the results

    Do not average anything. Look for the specific patterns below.

    Act this week

    Any response to question 6 that includes credentials, personal information, or configuration files, combined with any personal account in question 3. That combination means client data sits in a consumer account you do not control, cannot audit, and cannot wipe. You have a disclosure question to answer and possibly a contract problem.

    Yes answers on question 7. Notetakers join calls and record client conversations to a third-party service. Check whether that service is in your vendor stack, whether it retains recordings, and whether your client agreements cover it.

    Act this month

    Question 11 tells you your real policy coverage. If more than a third of your team answers "no" or "not sure," your policy does not exist in any way that matters, even if a document is sitting in your documentation platform.

    Question 3 tells you your licensing gap. Every person on a free personal account is a person you did not give a company account to. That is a purchasing decision, not a discipline problem.

    Question 10 tells you where to spend training time. "I do not know what I am allowed to put in" is a policy failure. "I do not trust the answers" is a tooling failure and usually means they are asking a general-purpose model about your specific environment, which it knows nothing about.

    Use for planning

    Question 8 and question 13 give you your first real use cases, written by the people who do the work. Question 9 tells you what has genuine value. People do not spend their own money on things that do not work.

    Question 14 gives you your internal champions. Use them. A tech showing three other techs what she figured out beats any training vendor you will hire.


    What to do next, in order

    The survey creates urgency. Here is where that urgency goes.

    Buy company accounts. Every person on a free personal account gets a company account this month. This is the cheapest fix on the list and it moves your data out of consumer accounts immediately.

    Write the policy. Keep it short enough that people read it. It needs to answer one question clearly: what can go into an AI tool and what cannot.

    Connect your systems before you buy any point solutions. This is the step most shops skip and it is the one that changes the answers. Connect your documentation platform, your PSA, and your RMM to your LLM through MCP servers. Read-only credentials. Never a shared account. Never write or delete permissions. Once the model can see your actual tickets and your actual documentation, question 10's "it does not know anything about our clients" problem goes away, and you stop shopping for six different AI point tools that each solve a sliver of it.

    Measure from the PSA. First call resolution, average time on ticket, tickets worked per day. Pull those numbers before you change anything so you have a baseline. Anything else is a feeling.

    Rerun the survey in 90 days. Same questions. The delta is your real progress report.


    Part two: the client version

    Once your own results are in hand and your policy is written, this becomes something you sell.

    Most of your clients have the same problem you just found in your own shop, and they have no way to see it. Their staff is using AI on company data through personal accounts, and their leadership genuinely believes adoption is near zero. You are the only vendor positioned to tell them otherwise, because you already hold the identity stack, the endpoints, and the network traffic.

    What changes from the internal version

    Named responses. The client is buying an actionable picture. Tell staff up front that responses are attributed and that the goal is enabling AI use, not punishing it. You will get slightly cleaner answers than the truth. Pair the survey with technical discovery to catch what the survey misses.

    Add a department question, customized to their org chart. Sales, finance, operations, and clinical or legal functions carry different data types and different regulatory exposure.

    Add a manager awareness question. Ask each respondent whether their manager knows which AI tools they use. The gap between staff usage and manager awareness is the single most effective slide in your findings presentation.

    Add a data classification question specific to their business. For a medical practice, ask about patient information. For a law firm, ask about matter details and client confidences. For a manufacturer, ask about drawings and supplier pricing. Generic phrasing gets generic answers.

    Add a spend question. Ask who is expensing AI tools. Finance usually has no idea, and the number is larger than they think.

    Drop question 9. You are not asking a client's employee whether they would spend personal money.

    How to package it

    Do not hand over a spreadsheet of survey responses. Nobody buys a spreadsheet.

    The deliverable is a findings session with the owner or the leadership team, backed by a short written report. Cover the tools in use, the accounts they run on, the data categories staff reported putting into them, and the gap between what leadership believed and what staff reported. Close with a prioritized fix list.

    Run it as a fixed-fee assessment. Pair the survey with technical discovery from tools you already own, which is where the real evidence lives. Your identity provider shows OAuth grants to AI applications. Your DNS or web filtering shows traffic to AI domains. Your Microsoft 365 tenant shows Copilot licensing and usage. Survey answers plus that data gives you a picture neither one produces alone.

    The assessment sells the remediation work. Policy development, account provisioning and licensing cleanup, staff training, and the same MCP connection work you did for yourself. That is recurring project revenue and it comes from a conversation you started with a seven-minute survey.


    The short version

    You cannot govern what you have not measured. Send the internal survey this week. Read the results against the patterns above. Fix the account problem, write the policy, connect your systems, and set a baseline in your PSA.

    Then go sell the same process to your clients.


    Talk it through

    Sending the survey is easy. Reading the results honestly and deciding what to fix first is the part owners get stuck on, because the answer is usually a purchasing decision and a hard conversation, not a tool.

    Everything above is a template. Run it yourself this week and never talk to me. What I will not do is hand you a system and tell you your shop is wrong for not matching it.

    Not sure this is your actual constraint? Take the MSP Owner Reality Check. Five questions, nine minutes, and it names the two or three things quietly capping your growth. https://themsphero.com/resources/msp-owner-reality-check-assessment

    If you already know what is broken, book a 30 minute fit call at https://letschat.themsphero.com

    Mike Kolb The MSP Hero

    I WILL NOT SELL YOU A PLAYBOOK

    Frameworks are easy to buy and easy to ignore. What changes your business is someone looking at your actual numbers, your actual team, and your actual clients, then telling you what to fix first. Start with the free read, or just book the call.