All Blogs
Shadow AI

What one MSP learned about shadow AI visibility before most of its customers did

Harmeet Sahni
March 9, 2026
9 mins
Book a Demo

Most Managed Service Providers have experienced some version of the same conversation. A customer asks about AI maybe it's ChatGPT, maybe it's Microsoft Copilot, maybe it's a new AI feature embedded inside an application they already use. The question usually sounds simple: "Is this safe?"

The challenge is that the answer rarely is, not because AI is inherently unsafe, but because most organizations have very little visibility into how AI is actually being used. Employees adopt tools independently, departments experiment without formal approval, and applications introduce AI features automatically. By the time leadership starts asking questions, AI is often already woven into daily operations.

This reality is forcing MSPs to confront a new challenge: how do you govern what you cannot see? One MSP, CBTech Support, recognized this challenge early and began looking for ways to improve visibility into AI activity before Shadow AI became a larger problem.

The new visibility problem facing MSPs

For years, MSPs have helped customers improve visibility across increasingly complex environments — cloud services, remote work, SaaS applications, mobile devices, distributed users. Artificial intelligence introduces another layer of complexity, and the difference is that AI adoption is moving significantly faster than many previous technology shifts.

Unlike a cloud migration project, AI often doesn't require formal planning. Employees simply start using it, a browser, a personal account, a productivity boost is often all it takes. The result is a growing gap between AI adoption and AI governance. Many organizations cannot answer basic questions such as which AI tools employees are using, how often they're being used, what information is being shared, whether company policies are being followed, and what AI-related risks exist today. Those questions are becoming increasingly difficult for MSPs to ignore.

Related Reading: → Shadow AI: The Hidden Threat Already Inside Your Organization

Why traditional visibility is no longer enough

Historically, MSPs have relied on a combination of endpoint monitoring, network visibility, security tools, and operational dashboards to understand customer environments. Those tools remain important. However, AI introduces a new challenge, many AI interactions appear completely normal. An employee opening a browser, a user interacting with a SaaS application, a developer using a coding assistant, nothing necessarily looks malicious. Yet significant risk can still exist: sensitive information may be shared, AI policies may be violated, governance requirements may be overlooked.

The challenge is not identifying malware. The challenge is understanding behavior. This is one reason many MSPs are discovering that AI governance begins with visibility, without it, every other governance discussion becomes speculative.

Related Reading: → Why Traditional Cybersecurity Tools Can't Protect Against AI Threats

The challenge CBTech identified

CBTech Support serves small and mid-sized businesses that rely on the company to simplify technology, improve security, and provide operational clarity. As AI adoption accelerated, CBTech saw a familiar pattern emerging: customers understood that AI was becoming important, and many agreed that AI needed to be secured — but few understood how much AI activity might already exist within their environments.

According to CBTech, one of the challenges was helping customers move beyond viewing AI as a future concern and recognize that AI governance needed to become part of everyday operational conversations. This created a difficult problem: before discussing governance, policies, or risk management, they first needed visibility. They needed to understand where AI was being used.

Shadow AI is often larger than organizations expect

One of the most consistent findings across AI assessments is that AI adoption is rarely limited to a single application. Organizations often focus on tools such as ChatGPT, Claude, Gemini, and Copilot, but AI usage extends much further. Embedded AI capabilities increasingly exist inside collaboration platforms, CRM systems, productivity suites, marketing tools, development environments, and business workflows.

This is why Shadow AI has become one of the most important AI governance challenges. The issue is not simply unauthorized AI — it's invisible AI. Employees may not even realize they're interacting with AI-powered systems, and leadership often has even less visibility.

Related Reading: → Four AI Risks Every SMB Should Understand Before Deploying AI

From visibility to governance

One of the most important lessons emerging from early AI adopters is that governance should not begin with restrictions, it should begin with understanding. Organizations often rush to create AI policies before they understand existing AI usage, data exposure risks, user behavior, and governance gaps. That approach creates friction without necessarily reducing risk.

A more effective strategy starts with visibility. Once organizations understand where AI exists, they can begin answering more meaningful questions: which activities are acceptable, what information should be restricted, which tools should be approved, and what controls should be implemented. This creates a governance framework grounded in evidence rather than assumptions.

Related Reading: → Why Blocking AI Doesn't Work: A Better Approach to AI Governance

Why this matters to MSPs

CBTech's experience highlights a broader trend across the MSP community. Customers increasingly expect guidance around AI, not because they want to stop using it, but because they want to use it responsibly. This creates a significant opportunity for MSPs to help with Shadow AI discovery, AI governance, policy development, visibility, risk management, and security monitoring.

These services build naturally on capabilities many MSPs already provide. The difference is that the conversation shifts from infrastructure management to AI governance and business risk. For MSPs willing to develop expertise in this area, AI creates an opportunity to become even more strategic advisors.

Related Reading: → How MSPs Can Turn AI Governance Into a New Revenue Stream

What forward-thinking MSPs are doing today

The most successful MSPs are not waiting for AI incidents to force action. They're proactively helping customers:

  • Understand Existing AI Usage — Visibility comes before governance.
  • Identify Shadow AI — Organizations cannot manage risks they cannot see.
  • Develop AI Policies — Governance creates consistency and accountability.
  • Monitor AI Activity — AI adoption is dynamic and requires ongoing oversight.
  • Enable Responsible AI Adoption — The goal is safe AI adoption, not AI avoidance.

This approach allows organizations to benefit from AI while maintaining security, compliance, and operational control.

Conclusion

The most important lesson from the early stages of AI adoption is surprisingly simple: visibility matters. Organizations cannot govern AI they cannot see, cannot manage risks they don't understand, and cannot create effective policies without understanding how AI is already being used.

For MSPs, this creates both a challenge and an opportunity. The challenge is helping customers navigate a rapidly changing technology landscape. The opportunity is becoming the trusted advisor who helps them do it safely. As AI adoption continues to accelerate, visibility will increasingly become the foundation of responsible AI governance.

FAQs

Find answers to the most common questions about AI detection and response (AIDR), how it works, and why it matters for modern MSPs.

What is Shadow AI?
Why is AI visibility important?
Why are MSPs focusing on AI governance?
How can MSPs identify Shadow AI?
What is the first step in AI governance?

Become your clients' trusted AI advisor

Help customers embrace AI confidently with governance, visibility, and protection, all while building a new category of managed services.
Book a demo