On this page

Summarize with AI
Open this article in your favorite AI assistant for a quick summary.
I spent a week in rooms with MSPs, first at MSP World Connect in Chicago and then at an MSPAlliance Inspire peer group meeting in Toronto.
A lot of the value was in the conversations between the formal sessions: at breakfast, between sessions, over dinner, and in the parking lot where our Toronto host set up an outdoor barbecue and axe throwing.
In those informal settings, MSP owners spoke more candidly. This is the value of getting together in person that you just can't replicate with virtual events.
The group included larger firms and MSPs with app development or resale businesses. They worked with all different vendor stacks and customer sizes.
Nonetheless, five themes kept coming back.

1. AI has moved from experimentation to monetization
For roughly two years, most MSP conversations about AI stayed in the trial stage.
People were curious, cautious, and still trying to decide what the technology meant for their own companies. In both Chicago and Toronto, MSPs had moved on to a practical question: where does AI fit in the service catalog, and how do we get paid for the work?
The discussion centered on consulting rather than choosing an AI tool to resell.
Clients already have access to products such as Microsoft Copilot, but access does not tell them which business process to improve, which data the system should be allowed to use, or how an employee should check the output before it reaches a customer.
The license is just one line item. The work begins with questions such as:
- Which repetitive work is a good candidate for AI?
- What data can the tool access?
- Who reviews its output?
- What business result would make the project worth doing?
- How will the client measure that result?
Vertical knowledge matters because an MSP that understands a law firm, manufacturer, healthcare practice, school, or financial services company can discuss the work itself, not merely the software. The same Copilot license will not produce the same value in every industry.
This work can lead to consulting revenue, implementation projects, and a larger managed services relationship. It also asks the MSP to move further into business-process advice than many providers have gone before. That will not suit every MSP, and it may require new hires or outside expertise. Each firm still needs to decide how far it wants to go.
2. Surprise AI bills are exposing a governance gap
A few MSPs described clients who experimented with AI without setting limits, generated more token usage than expected, and received an unexpected bill. The client had not agreed on usage rules, ownership, or a budget.
A sensible AI rollout needs financial, technical, and process controls. That can include approved tools, access rules, spending thresholds, usage monitoring, data restrictions, security review, and a clear approval process for new use cases. It also needs someone who will review those controls as usage changes.
MSPs can put these controls in place before an experiment becomes an unplanned expense or sensitive information reaches the wrong system.
The first client workshop should answer:
- What can employees use AI for today?
- What data must stay out of public AI tools?
- Who can approve a new tool or use case?
- How will the company monitor consumption and cost?
- What happens when an employee or system breaks the rules?
An MSP can package those decisions as an advisory and management service covering policy, identity, security, data protection, budgeting, and ongoing monitoring. The provider already knows the client's identities, systems, security requirements, and technology budget.
3. Compliance work is moving beyond technical control mapping
Compliance came up repeatedly in the same way AI did: clients are bringing the problem to their MSP.
A customer may need help preparing for a SOC 2 audit, understanding CMMC, or implementing NIST Cybersecurity Framework controls. Translating the MSP's existing security tools into a list of controls is only one part of the work. Clients also need policies, procedures, documentation, workflows, and operating habits that keep those controls working.
The MSP may need to help answer questions such as:
- Who owns the control inside the client's company?
- What evidence will show that the control is working?
- How does the control fit into the client's supply chain?
- Which responsibility belongs to the MSP, and which stays with the client?
- What process keeps the evidence current after the first review?
An MSP with experience in the client's industry has an advantage because the conversation is already tied to real business pressures. The provider knows which systems matter, how people work, where documentation usually breaks down, and which requirements customers or regulators are likely to ask about.
In both the AI and compliance conversations, clients are saying, "I need you to help me." They are asking the MSP before they go elsewhere because the MSP fought to become the trusted adviser and already understands the environment.
The MSP can build the capability in-house or stay involved while a qualified third party delivers part of the work. Building everything internally will not make sense for every firm. A trusted adviser can still help the client find the right answer and coordinate the technical work that follows.
4. MSPs are voting with their feet when vendors and events stop earning their time
MSPs used to change ticketing, RMM, backup, and other core platforms less often because migrations were expensive and disruptive. Many stayed with a familiar tool even when it no longer fit.
Now MSPs switch more often. Migration may be easier than it was ten or twenty years ago, but that is only part of the explanation. Providers are also less willing to stay with a vendor that has stopped investing in its product, integrations, support, or roadmap.
MSPs are weighing price and migration effort alongside:
- Whether the product continues to improve
- Whether integrations match the way the MSP operates
- Whether support can resolve real problems
- Whether the vendor understands managed services
- Whether the platform still fits the MSP's direction
A large, flashy event does not make up for a product that has stalled. MSPs notice the difference between a vendor investing in the tool and a vendor investing in the appearance of momentum.
MSPs are tired of low-value events
The same standard is showing up in conferences and peer groups. There are more MSP events than most people can attend, and owners are tired of giving up days for an agenda that leaves too little room for honest conversation.
MSPs repeatedly asked for more time with other MSPs. They want to compare decisions, hear how a provider in a different "weight class" handled a problem, and talk without every conversation being organized around a vendor's tool set.
Events earn the time when they protect that MSP-to-MSP connection. If the agenda leaves little room for it, many owners will choose another event or stay home.
5. Customers are asking MSPs to prove their maturity
The final conversations focused on the profession itself. "Managed services" has grown beyond a label for outsourced IT. Customers, policymakers, insurers, regulators, and people in regulated industries increasingly treat the MSP as part of the client's security, compliance, resilience, and business operations.
That recognition comes with scrutiny. Customers are moving from "Are you an MSP?" to "Can you prove it?"
A credible answer may include the provider's credentials, documented processes, security posture, service responsibilities, operational maturity, and ability to support a client's business outcomes. The MSP label alone gives a customer or regulator little evidence.
Clearer standards make it easier to distinguish an MSP with documented operations from a company using the name without accepting the responsibilities that come with it. Credentials and evidence give customers something more useful than the label alone.
Acquisition churn is creating openings for independent MSPs
The conversations also touched on private equity and MSP rollups. MSPs described clients leaving rollups that acquired companies without carefully integrating service and customer relationships. They were also careful not to treat every private-equity-backed provider the same way.
Independent MSPs in both cities said they were winning some of that business after clients became dissatisfied with service following an acquisition.
The decision in front of MSP leaders
The conversations in Chicago and Toronto were optimistic. Owners were deciding how to turn new client needs into work they could deliver responsibly.
For MSP leaders, the next planning session could start with five questions:
- Which AI and compliance conversations are clients already bringing to us?
- Which parts can we deliver well with the team we have?
- Where do we need training, new staff, or a qualified outside specialist?
- What controls and evidence would prove that our own operation is mature?
- Which vendors and events are still earning our time and money?
MSPs can choose which capabilities to build and which to coordinate with qualified specialists. When a client asks for help, a useful answer keeps the MSP involved in the work instead of sending the client elsewhere without guidance.
The original MSP Zone episode includes the full discussion from the road, along with the parts that do not fit neatly into five headings.
Frequently asked questions
What AI services can an MSP offer today?
MSPs can offer advisory and implementation services now. That work can include selecting use cases, mapping AI to a business process, configuring access, protecting data, training users, reviewing output, and monitoring usage. A license by itself does not answer those questions.
How can an MSP help control unexpected AI costs?
Set financial and technical guardrails before broad adoption. Define approved tools and users, spending thresholds, usage monitoring, data rules, security reviews, and an approval process for new use cases. Review the controls as the client's usage changes.
Why does industry specialization matter for AI consulting?
Industry knowledge helps an MSP identify useful AI projects, recognize sensitive data and compliance constraints, and judge whether a proposed workflow will save time or create another problem.
What does compliance advisory include beyond security tools?
It includes policies, procedures, evidence, documentation, ownership, workflows, and ongoing review. The MSP can connect technical controls to those business practices while making clear which responsibilities belong to the provider and which remain with the client.
What should an MSP evaluate before switching a core platform?
Evaluate price and migration effort alongside product investment, integration quality, support, roadmap, data portability, security, and whether the vendor still understands the MSP's operating model. A difficult migration can still be the better choice when the cost of staying keeps rising.
What does it mean to prove that a company is a mature MSP?
The evidence will vary by customer and market, but it can include recognized credentials, documented service and security processes, clear responsibility boundaries, repeatable operations, staff competence, and records that show the company does what its contracts promise.