Resources/The MSP AI Policy
    AI

    The MSP AI Policy

    What belongs in a one page AI policy for a small MSP, what to leave out, and how to get it signed.

    Your techs already use AI. Some of them pay for it out of pocket. At least one has pasted a client's network details into a free chat tool to close a ticket faster. You don't know who, because nobody ever wrote down a rule.

    That's problem one.

    Problem two is bigger and it belongs to you whether you want it or not. Your clients are doing the same thing, across every department, with zero guidance. When something goes wrong, they call their IT provider. That's you.

    This page fixes both. Part one is the internal policy for your team, with language you copy straight into your own document. Part two turns that same work into something you charge for.

    Set aside an afternoon. Not a quarter.

    Part One: The Internal Policy

    An AI policy is six decisions written down and signed. Most owners stall because they think they need a legal review and a 40 page document. You don't. You need six answers your team can actually follow.

    Make each decision. Use the sample language. Sign it.

    Decision 1: Which tools you approve

    Pick two. Maybe three. Name them by product, not by category, and say whether you pay for the business tier.

    The reason this matters is simple. Paid business tiers come with a data processing agreement, admin controls, and a contractual promise that your prompts don't train the model. Free tiers usually don't, and the setting that controls it lives three menus deep where nobody looks.

    Copy this into your document:

    Approved AI tools at [Your Company] are [Tool A] and [Tool B], on company-provisioned licenses only. Log in with your [Your Company] account through SSO. Do not use personal accounts for company work. Do not use free tiers of any AI tool for client or company data.

    If you want to use a tool that isn't on this list, submit a request to [Name] before you use it. Not after.

    Decision 2: What data never goes in

    This is the section your team will actually reference, so make it concrete. Vague instructions like "protect confidential information" mean nothing to a tech at 4:45pm on a Friday.

    Never put the following into any AI tool:

    1. Credentials of any kind. Passwords, API keys, tokens, certificates, connection strings.
    2. Client network diagrams, firewall rules, or configuration files that identify the client.
    3. Protected health information, cardholder data, or any data covered by a client's compliance obligations.
    4. Client contracts, pricing, or anything under an NDA.
    5. Employee records, payroll, or performance documentation.
    6. Security findings tied to a named client before you remediate them.

    These are fine:

    1. Generic technical questions with client identifiers stripped out.
    2. Public vendor documentation and error messages.
    3. Script and automation logic that doesn't reference a specific client environment.
    4. Your own internal documentation and marketing copy.

    When you're unsure, strip the names and the IPs first. If it still works as a question, ask it. If it doesn't, bring it to [Name].

    That last line does more work than the six rules above it. Give people a test they can run in their head.

    Decision 3: What gets human review before it leaves the building

    AI writes a confident ticket response that's wrong. A client reads it, acts on it, and now you own the outcome. Draw the line clearly.

    Any AI-generated content that reaches a client carries a human owner. Before you send it, you read it, you verify the technical claims, and you put your name on it. This applies to ticket responses, client emails, documentation, scripts, security recommendations, and proposals.

    Never run an AI-generated script in a production environment without reading every line first.

    Decision 4: Who approves new tools, and how fast

    Slow approval creates shadow AI. If a request takes three weeks, your team stops asking and starts using their personal accounts. Put a clock on it.

    [Name] owns AI tool approval. Submit requests to [email]. You get an answer within five business days.

    A tool gets approved when it meets all of these: a data processing agreement is in place, prompts and uploads are excluded from model training, the vendor supports SSO and admin controls, and we know what country the data sits in.

    Decision 5: What you tell clients

    Decide this before a client asks, because one of them will. There's no single right answer, but there's a wrong one, which is having no answer while a client stares at you on a QBR call.

    Most MSPs land somewhere near this:

    We use AI tools to help draft documentation, summarize tickets, and research technical issues. A qualified engineer reviews everything before it reaches you. We do not put your credentials, your protected data, or your identifiable configuration details into any AI system.

    If your contract with us or your compliance framework restricts AI processing, tell us and we'll document the exception.

    Put a version of that on your website. It answers the question once instead of forty times.

    Decision 6: What happens when someone breaks it

    A policy with no consequence is a suggestion. Keep it proportionate and keep it honest.

    First violation: a conversation and a refresher. Repeated violations: standard disciplinary process. Credentials or client protected data placed into an unapproved tool: this is a security incident. Report it to [Name] immediately and we run our incident response process. You will not be punished for reporting quickly. You will be punished for hiding it.

    That last sentence matters more than the rest. You want to hear about it in ten minutes, not ten months.

    Sign It and Roll It Out

    Print it. Sign it. Date it. One page if you can manage it.

    Then run a twenty minute all hands. Read the six decisions out loud, take questions, and have everyone acknowledge it in your HR system or ticketing tool so you have a record. Add it to onboarding that same week.

    Put a recurring calendar reminder for a quarterly review. Tools change, vendors change their terms, and the version you signed in March goes stale by September. Fifteen minutes a quarter keeps it current.

    That's the internal policy. Now the part that makes you money.

    Part Two: Turn It Into a Client Offer

    You just built the thing your clients need and can't build themselves. Their staff are pasting customer lists into free chat tools right now. Their leadership knows it's happening and has no idea what to do about it.

    Here's how you get paid for solving it.

    Start with your own contracts

    Pull your MSA. Search it for the word "AI." For most MSPs, that search returns nothing.

    That's a gap in two directions. You have no documented permission to use AI tools on client data, and your clients have no defined obligation around the AI tools they bring in themselves. Get an amendment drafted that covers both. Your attorney handles this in an hour or two, and it protects every agreement you sign afterward.

    While you're at it, look at your cyber insurance renewal application. Insurers have started asking about AI governance. Having a signed policy in hand makes that conversation short.

    Find the shadow AI before you pitch

    Nothing sells a client engagement like showing an owner what's already running in his environment. You can pull most of this with tools you already own.

    1. Check OAuth grants and enterprise applications in their identity provider. Every AI tool a user connected to their work account shows up there.
    2. Run a software inventory through your RMM and look for AI desktop clients and browser extensions.
    3. Ask their bookkeeper for a list of recurring software charges under $100 a month. That's where the personal subscriptions hide.
    4. Pull sign in logs for the major AI domains if their firewall or DNS filtering gives you that visibility.

    Walk into the meeting with a list. The conversation changes immediately.

    The engagement

    Package it in stages so a client can start small and grow into the recurring piece.

    Stage one is an assessment. You document what is in use, who is using it, and where their exposure sits against whatever compliance framework applies to them. Fixed fee, banded by seat count, $3,500 to $8,000, two to three weeks.

    Stage two is the policy. You adapt the six decisions above to their business, their tools, and their industry. You deliver a signed document and you run the all hands training session yourself. Fixed fee.

    Stage three is standardization. You move them onto licensed business tier tools, kill the personal accounts, wire up SSO, and set conditional access rules that block the unapproved tools. This is real project work and it prices like real project work, normally $5,000 to $15,000 scoped off the assessment findings.

    Stage four is governance, and this is the one you want. Quarterly policy reviews, new tool evaluations, onboarding and offboarding for AI accounts, and a standing report on usage. Recurring line item on the invoice, every month, forever. Price it at $8 to $20 per seat per month depending on how hard regulation bites.

    Price stages one through three as fixed fee projects. Price stage four per seat per month and add it to the existing agreement. Don't give any of it away as a value add. The moment you make governance free, you've taught the client it's worthless.

    What makes this different from every other MSP pitch

    You are not selling them AI. Half their vendors are already doing that and their inbox is full of it.

    You're selling the thing that has to exist before AI is safe to use. That's a much easier conversation, because the client already feels the risk and nobody has offered to take it off their plate.

    What Comes After the Policy

    The policy is the easy part. You can finish it this week using what's on this page, and plenty of MSPs will do exactly that and stop there.

    The harder question is what AI does to your business over the next two years. How you package it. What you charge for it. Which services get commoditized and which ones get more valuable. Whether your techs get faster or just get replaced by the client's own tooling. That's a go to market problem, not a policy problem, and it doesn't solve itself in an afternoon.

    Talk it through

    The policy is the easy part and you can finish it this week. The harder question is what AI does to your business over the next two years. How you package it, what you charge for it, which services get commoditized and which get more valuable. That is a go to market problem, not a policy problem, and I work on it with owners as a fractional COO and CTO.

    Everything above is a template. Run it yourself this week and never talk to me. What I will not do is hand you a system and tell you your shop is wrong for not matching it.

    Not sure this is your actual constraint? Take the MSP Owner Reality Check. Five questions, nine minutes, and it names the two or three things quietly capping your growth. https://themsphero.com/resources/msp-owner-reality-check-assessment

    If you already know what is broken, book a 30 minute fit call at https://letschat.themsphero.com

    Mike Kolb The MSP Hero

    I WILL NOT SELL YOU A PLAYBOOK

    Frameworks are easy to buy and easy to ignore. What changes your business is someone looking at your actual numbers, your actual team, and your actual clients, then telling you what to fix first. Start with the free read, or just book the call.