Each day, the flood of technology news hits. In an industry that always changes, those who deliver technology services need to focus on the information that matters to them. The Business of Tech podcast focuses on the news you need to know. Covering both the story and why it matters to the way s…
The Business of Tech podcast is an exceptional show that offers valuable insights into the world of technology. Featuring some of the brightest minds in the industry as guests, this podcast provides a window into their thoughts and predictions for the future. The bite-sized episodes are perfect for my morning commute, offering just the right amount of information to start my day.
What sets this podcast apart is its ability to captivate listeners with engaging topics and expert guests. There was never a moment where I felt lost or disengaged during an episode. The discussions are well-structured, informative, and empowering. The host's sense of humor adds a touch of entertainment and ensures that each episode is anything but dull.
Additionally, the podcast covers a wide range of tech-related subjects, giving listeners fresh perspectives on various aspects of the industry. The interviews provide a deep dive into current trends, challenges, and opportunities in tech. The host's ability to break down complex concepts into easily understandable language makes this podcast accessible to both tech enthusiasts and those new to the field.
One downside is that the episodes can sometimes feel outdated as they are not regularly updated. It would be great to have more recent content to stay up-to-date with the latest developments in technology. However, this does not detract from the overall value provided by the podcast's extensive archive.
In conclusion, The Business of Tech podcast is an excellent resource for anyone interested in technology and its impact on our lives. The show's informative and entertaining format, coupled with its impressive lineup of guests, makes it a must-listen for anyone working in or passionate about the tech industry. Despite occasional dated content, this podcast remains highly recommended for its ability to deliver valuable insights in an engaging manner.

Most MSPs can already tell you which of their clients' Microsoft 365 environments are misconfigured. The harder question is why so few get fixed — and what it takes to turn security visibility into security operations at scale. Dave sits down with Nick Ross, CEO of Cloud Capsule and a three-time Microsoft MVP, to talk about the operational gap MSPs can't close with assessment tools alone, and how his team is trying to close the distance between finding problems and remediating them across dozens of client tenants at once. Nick launched Cloud Capsule's Manage tier in May to move partners beyond assessment into remediation. He argues the biggest challenge in M365 security isn't visibility — it's execution: the knowledge gap around how to architect a policy, plus the manual hours to deploy it one tenant at a time. He walks through how the platform templatizes baselines, enforces desired state configuration so controls can't be quietly tampered with, and gives technicians the context to know whether flipping a control from red to green will flood the help desk with tickets. The conversation also digs into the harder business questions: whether pushing security work down to junior techs lowers the skill floor and introduces risk, how to prioritize 250+ controls without drowning in red, and the economic reality that many MSPs already know clients are misconfigured but can't get them to pay for the fix. Nick's answer leans on newer levers — the AI-readiness conversation, Copilot data governance, and cyber insurance renewals — to reframe security as table stakes rather than a hard sell. Supported by: Guardz

The core structural shift identified is budget reallocation within technology spending, as funds are redirected from legacy software, hardware refreshes, and higher-cost labor toward AI infrastructure, automation, and junior-level hiring. This resource substitution is not additive but redistributive, with spending on AI solutions and related tools coming directly from reductions in traditional IT line items. IBM's $70 billion market valuation loss and delays in large deals signal that even established vendors are affected by this reallocation, with money leaving areas they once dominated. The primary evidence is IBM's issuance of its first profit warning since the early 2000s, attributed to missed large contracts and delayed deals, which triggered a 25% drop in share value, equating to $70 billion in market cap loss. According to Dave Sobel citing Semafor, this reduction was not due to an overall decrease in technology budgets but resulted from enterprise customers reallocating funds toward hardware and AI-related infrastructure. Omnia reported a 3.6% decline in global PC shipments during the second quarter, which was also attributed to rising hardware component costs driven by AI buildouts, causing delays and cancellations in endpoint refresh cycles. Supporting developments include Ramp and Revelio Labs research showing that organizations intensively adopting AI increased headcount by 10% and entry-level hiring by 12% over two years, while CompTIA found IT unemployment fell below 3% even as tech firms cut staff. Futurism cited further labor market reshuffling, with older workers in AI-exposed roles exiting the workforce and younger, cheaper hires being amplified by automation. ConnectWise's rollout of an AI-native platform and KPMG's survey highlighting the importance of leadership accountability in AI projects reinforce that resource allocation is shifting to tools and personnel accountable for AI operation and outcomes. Operationally, this reallocation puts pricing pressure on providers focused on legacy revenue lines such as per-seat licenses, break-fix, and hardware refresh, as these budget categories are shrinking. Evidence from Service Leadership's profitability report shows providers who adopted service desk automation earlier are now earning more per wage dollar, compounding their advantage. The practical implication for MSPs and IT service providers is to identify which client budget categories are “filling” and adjust offerings toward data readiness, AI deployment, and managed accountability, rather than defending legacy categories now facing structural decline. Failure to adapt exposes firms to revenue erosion and intensifies competitive risk from providers aligned with relocated client spend. 00:00 Watch the Money Move 04:37 AI Spend Is Funded by Substitution 07:19 Your Revenue Mix Is the Bet 10:24 Why Do We Care? Supported by: Guardz ScalePad

The episode highlights a shift from technology selection to operational risk management in the AI landscape for MSPs. Service providers are being forced to navigate the fast-changing interplay between AI models, the harness software that mediates their deployment, and the financial realities of consumption-based billing. The rapid proliferation of open-source and open-weight AI models, alongside market behaviors from closed vendors and regulatory interventions, is introducing volatility and uncertainty in both cost structures and client offerings. This dynamic creates structural challenges related to margin maintenance, vendor dependency, and responsibility for AI-driven decisions. The discussion cites the release of GLM 5.2, an open-weight model from Z AI, which now rivals expensive closed models on key benchmarks at a fraction of the cost. At the same time, large-scale investments by commercial AI vendors have yet to deliver returns on expectations, with reports indicating businesses that adopted AI are not seeing projected value. Specific attention is given to operational constraints such as compute scarcity, token consumption variability, and export policy restrictions impacting AI availability. The episode notes that these pressures are driving both vendors and MSPs to reconsider the viability of reliance on expensive, closed offerings versus investigating open alternatives. Supportive examples include the proliferation of AI “harnesses” (middleware layers like Perplexity, Claude Code, and Cowork) that sit between service providers and underlying AI models, increasing both choice and complexity. Token billing models are highlighted as a source of unpredictability for MSPs, with vendors like Atera and ConnectWise experimenting with different abstractions to shield or pass through token risk to service providers. The potential for on-premises AI deployments using smaller language models is discussed as a cost-mitigation strategy, though this raises further questions about data privacy, infrastructure burden, and long-term vendor roles. Additionally, uncertainty is flagged around sustainability of leading vendors, with projections that at least one major AI player may exit or be acquired within a year due to financial vulnerability. For MSPs and IT service leaders, these structural and supporting developments translate into increased operational and financial complexity. There is a pressing need to evaluate not just which AI technologies to adopt, but how to architect solutions that can withstand rapid vendor movement, cost swings, and evolving regulatory requirements. Practical safeguards include testing open-source AI models alongside commercial offerings, exercising caution in vendor selection, and closely monitoring evolving consumption billing models. Preparing staff and clients for adaptive, process-oriented approaches—rather than fixed solutions—is positioned as a necessary step to maintain resilience as the AI adoption cycle continues to correct course. Supported by:Pax8CometBackupGuardz

Contemporary technology governance has shifted from rule-based regulation to a landscape defined by administrative leverage and directive-driven decisions. This dynamic is seen in both the cybersecurity and AI sectors, where agencies such as the U.S. Department of Defense and companies including OpenAI and Anthropic navigate obligations and approvals through administrative action rather than statutory change. As a result, MSPs and IT service providers must recognize that the durability of their offerings and client architectures increasingly hinges on how they respond to rapid, unpredictable shifts in the governing environment rather than on fixed compliance deadlines or product release dates. A notable example of this mechanism is the Department of Defense's suspension of the rollout of Phase Two of the Cybersecurity Maturity Model Certification (CMMC), as reported by Federal News Network. About 80,000 companies had been preparing for new third-party assessment requirements, but these assessments have been paused pending a 60-day review. Despite the pause, the underlying data protection requirements for defense contractors remain in force, demonstrating that while compliance deadlines can disappear overnight, fundamental security obligations persist. Additional cases amplify the trend toward directive-based governance. The U.S. Commerce Department lifted export restrictions on Anthropic's Fable 5 and Mythos 5 AI models after new safeguards were implemented, following the same pattern previously used to impose those restrictions. Similarly, OpenAI's GPT 5.6 model was released to the public only after a voluntary government review concluded, illustrating that administrative reviews, not boardroom decisions, can dictate technology availability. Concurrently, other governments such as China are employing similar tactics, with Reuters reporting that Chinese authorities have met with local AI firms to discuss restricting overseas access to advanced models. These parallel moves across geopolitical boundaries indicate a structural reliance on executive discretion rather than legislative clarity. The operational impact for MSPs, IT service providers, and technology leaders is a heightened exposure to contract risk and pricing volatility. Service commitments anchored to deadlines, default settings, or product availability are susceptible to abrupt policy reversals or administrative interventions, translating to sudden revenue shortfalls and reactive client management. The recommended response is to audit current commitments, identify those pegged to mutable triggers rather than enduring obligations, and systematically re-anchor contract language and client communication to core outcomes and standing requirements. This preparation mitigates the risk of unpaid work, scope renegotiation, and unplanned operational disruption when another directive-driven policy shift occurs. 00:00 Three Government Switches in Three Weeks 04:07 Why AI Is Governed by Leverage, Not Law 06:46 CMMC Paused — Your Obligations Didn't 09:27 Why Do We Care? Supported by: Pax8 Guardz

The episode highlights a structural shift in cybersecurity risk, moving from a reliance on human skill as both the source of attack and defense to a landscape shaped by autonomous AI agents acting as privileged entities inside client environments. This pivot is illustrated by Sysdig's discovery of an agentic ransomware attack (“Jade Puffer”) where AI software—not a human operator—managed intrusion end-to-end, adapting in real time without manual intervention. The key structural effect is a drastic reduction in the cost and skill required to mount effective attacks, while simultaneously introducing unmanaged access points in the form of AI agents with human-equivalent credentials. Supporting this shift, Sysdig found that the AI-driven “Jade Puffer” attack executed more than 600 payloads, automatically adjusted after failures, and required minimal human oversight. ZDNet reported Apple's unusually rapid patch cycle, attributed by the company to the speed of AI-driven exploit development. According to IT Pro, attackers typically remain inside networks for about two and a half weeks before detection, with nearly half of breaches only discovered after data loss. The U.S. cybersecurity agency CISA admitted to lacking an incident response playbook, improvising during a breach. These developments collectively indicate that existing human-centric security models are being outpaced by autonomous threats. Further reinforcing this thesis, The New Stack emphasized a governance gap: most organizations lack standards for assigning identity or scoping access for AI agents, which today operate using human credentials without effective monitoring or control. AvePoint's research, as cited by Dave Sobel, suggests the number of unseen AI tools inside organizations has nearly tripled, while about half of employees now use AI agents frequently. While agent-based automation expands operational efficiency, the inability to monitor or restrict these agents exposes a widening attack surface and undermines traditional governance. For MSPs and IT service leaders, the operational ramifications include increased accountability for identifying, inventorying, and scoping AI agents as privileged identities within client environments. Continuing to rely on human-centric security and pricing models risks misalignment with actual exposure. The analysis suggests treating AI agent identity management as a distinct, recurring service line—akin to user identity and multifactor authentication—with pricing linked to risk rather than labor hours. Failure to proactively address this governance gap may result in unaccounted incidents and reactive, non-strategic service delivery that affects renewal cycles and liability positions. 00:00 5 Security Alarms Ringing at Once 04:22 Why Hacking No Longer Takes Skill 06:40 Your Agents Became the New Insiders 09:14 Why Do We Care? Supported by: ScalePad

The episode highlights a structural weakness in the current cybersecurity product ecosystem, where the process of certification and lab-based product validation often fails to ensure meaningful security. The episode focuses specifically on how regulatory and certification frameworks—such as those linked to device and software security—are largely decoupled from true technical evaluation, enabling both vendors and labs to use certification badges as symbolic rather than substantive assurances of security. According to Adwait Nadkarni, this decoupling allows manufacturers to treat compliance as a liability shield, rather than as a measure of robust risk mitigation. The most consequential finding, as articulated by Adwait Nadkarni, is that many certified security products can deliberately evade both automated and human review processes, with vulnerabilities designed to look secure while quietly exposing risk. The episode references certification structures such as SOC 2 and detailed research into IoT device certification, finding that certification labs often compete on speed and convenience instead of technical rigor. This creates a situation where certified products may still contain basic, decades-old flaws, with operators and MSPs left without practical recourse when technology fails. Other related developments reinforce the risk transfer created by certification mechanisms. Vendors frequently utilize broad liability disclaimers in end-user licensing agreements, explicitly or implicitly excluding themselves from responsibility for product failures—even in scenarios involving harm or downtime. Adwait Nadkarni points to practices where smoke detectors and other security products use ambiguous language about acceptable use and warranty, further reducing vendor accountability. Labs themselves generally disclaim any responsibility for the certified products' behavior once deployed, emphasizing a system with diffuse or absent accountability. For MSPs and IT leaders, these developments underscore the need to move beyond reliance on certifications and vendor marketing. Operators should critically assess the actual language and protections embedded in contracts, focusing on enforceable liability rather than assuming technical validation from a certification badge. Absent regulatory reform or industry-wide consortia to create and uphold real minimum standards, the practical task for service providers is to minimize exposure to legal and operational risk by scrutinizing the fine print of contracts, seeking clear remedies for technology failures, and tempering trust in vendor assurances that cannot be independently verified. Supported by: GuardzCometBackup

A structural shift is occurring as employees and customers increasingly bypass sanctioned IT systems in favor of faster, unsanctioned "shadow" tools that offer comparable or "good enough" functionality with less friction. This shift is highlighted through evidence from Gartner, SparkToro, Microsoft, and reports from Altran Digital Business, which collectively show sanctioned internal and customer-facing systems losing relevance as users opt for alternative solutions that optimize convenience and efficiency over formal governance. The most consequential development referenced is Microsoft's move to replace premium OpenAI and Anthropic models in core applications like Excel and Outlook with lower-cost in-house models, as reported by Bloomberg and Channel Insider. Microsoft claims these new models offer similar accuracy with increased efficiency, reflecting a broader market trend toward solutions that meet minimal functional thresholds at drastically reduced costs. This mirrors broader enterprise behavior, where cost and sufficiency now outweigh premium features, driving a reconsideration of value in AI provisioning. Supporting developments include a Gartner survey showing consumers are about three times more likely to use general AI tools like ChatGPT than corporate chatbots, and a report from Altran Digital Business revealing that over half of employees rely on personal devices or unauthorized tools for work, with nearly a third ceasing to report IT problems entirely. Clickstream data shows that more than two-thirds of Google searches end without a click as users accept AI summary answers, bypassing source links altogether. Vendors such as N-Able and Okta are responding with new products aimed at identifying and gating shadow tool usage, but these approaches often add operational friction without actually closing governance gaps, as Kaseya data indicates most SaaS accounts remain unmanaged despite existing controls. For MSPs and IT leaders, the key implication is that additional controls and "lockdown" measures are likely to increase friction without effectively steering users back to sanctioned processes. Current market tools that focus on visibility and gating of shadow IT may exacerbate the problem by making official workflows less attractive. The practical recommendation is to map where users have already abandoned sanctioned paths and focus on improving those official workflows until they are easily usable and competitive with shadow alternatives. The effectiveness of service delivery should be measured not by control metrics, but by whether users actively choose sanctioned systems for their work. 00:00 The quiet walkout 03:49 Even Microsoft picked good-enough 06:22 Why more control backfires 09:00 Why Do We Care? Supported by: Pax8

The dominant structural shift examined is the erosion of channel-driven value creation in AI offerings, marked by the rapid commoditization of resold AI technologies and a pivot toward consumption-based pricing models. Microsoft Copilot is cited as the most commonly resold AI product by MSPs, with market data showing that 84% of productized AI services among “AI forward” firms rely on this single vendor. The resulting model accelerates value capture at the vendor level, narrowing room for differentiated service or margin at the partner level. This consolidation pressures MSPs to shift from traditional product resale to enablement and operational integration or risk disintermediation. The primary development highlighted is the widespread lack of substantive AI go-to-market offerings among MSPs. According to analyzed web positioning data, 61% of MSPs do not mention AI offerings on their sites, and among those that do, the majority use vague or unscoped “AI solutions” language without concrete services behind them. Only a small subset offers named, productized AI services. Of these, the overwhelming reliance on Microsoft Copilot underscores a lack of channel-developed solutions and points to a market structure where vendors, rather than partners, capture much of the economic value. Supporting developments reinforce both the risk and inertia present within the channel. Ryan Morris outlines that true differentiation will require MSPs to develop packaged offerings around governance, financial controls, and vertical-specific business outcomes, yet early market activity shows little movement in these directions. The discussion emphasizes the potential for cost overrun through uncontrolled AI consumption, echoing past cycles from telecommunications to cloud. Efforts by large vendors to staff direct AI engineering resources are framed as a threat only to the top enterprise tier, with the bulk of SMB delivery left to service providers—albeit within a model now driven heavily by consumption volume and efficiency calculations. Operational implications for MSPs and IT leaders include increased pricing pressure and possible margin erosion as customers optimize consumption and as vendors streamline direct monetization of AI. There is a growing need for internal and customer-facing governance structures to manage data use, financial exposure, and compliance. Channel partners that limit themselves to product resale risk commoditization, while those able to package and deliver business-integrated AI services may find more durable value. The episode underscores the urgency for MSPs to clarify and productize their AI engagement—not simply as a differentiator, but as a defensive strategy against margin compression and vendor dependency.

The core structural shift affecting MSPs and IT service providers is a market bifurcation, where the traditional middle-ground offering—an undifferentiated blend of hardware and support—no longer matches client buying behavior. Dave Sobel referenced research from Techisle, which underscores a split between buyers seeking high-touch, managed outcomes and those opting for low-cost, self-serve technology tools. This division is further exacerbated by increasing component costs and external pressures on hardware pricing, particularly the rapidly escalating prices for memory and storage. Supporting data comes from a recent analysis of approximately 3,000 MSP websites conducted by Business of Tech. The scan found that 68% of MSPs make no mention of AI in their public-facing materials, with only about 1 in 7 offering a defined AI service. Simultaneously, reporting from both Business Insider and E2E reveals that 90% of businesses already have employees using AI tools—primarily adopted independently rather than through formal provider channels. This disconnect highlights a lag in MSP market positioning relative to how technology is actually being acquired and implemented by clients. Additional market stresses are introduced by rising hardware costs linked directly to shortages in memory and storage components. Apple's price increases for Macs and iPads serve as a tangible example, justified by upstream cost spikes in DRAM, which CNBC reported has increased nearly 9x—from approximately $35 to $300 per module. Further, AI data center buildouts are projected to divert up to 20% of consumer memory manufacturing by 2027, suggesting ongoing and intensifying cost pressures for MSPs still reliant on hardware-centric business models. Most providers, as observed by Dave Sobel, remain silent or default to restating the value of external AI platforms like Microsoft Copilot. The practical implication for MSPs and IT service providers is a pressing need to reassess positioning and operational models. Providers embedded in the undifferentiated middle face rising cost risk, declining differentiation, and potential margin erosion. Viable paths require declaring and operationalizing a clear service model, either by transparently externalizing hardware and component pricing risk, or by committing to outcome-based, managed offerings where the provider takes on measurable accountability. Those who adapt agreements and marketing to clarify their role—particularly by documenting internal AI-driven efficiencies—will be better equipped to sustain margin and client relevance as market forces continue to widen the gap. 00:00 Two-Thirds of MSPs Are Silent 04:37 The Memory Shock Splitting the Market 07:05 No Buyer Left in the Middle 10:41 Why Do We Care? Supported by: CometBackup ScalePad

The episode identifies a structural decoupling of software value from licensing units, driven by the rise of agentic AI platforms that automate tasks previously executed by human users within applications. This shift is evidenced by vendors realigning away from per-seat software economics toward service and outcome-based models. Companies such as Microsoft, Amazon, and OpenAI are redirecting resources into consulting and certification initiatives, responding to changing customer usage patterns and eroding profitability of traditional license models. According to Gartner, agentic AI could impact 20% of enterprise SaaS spend by 2030, redefining how businesses allocate budgets for software and services. A notable development illustrating this shift is Notion's decision to discontinue its Notion Mail application, not for lack of adoption, but because automated AI agents had largely replaced the need for a human-operated inbox. Microsoft has committed $2.5 billion and hired 6,000 consultants to embed AI solutions directly within client environments, bypassing traditional software seat sales. OpenAI has announced a global partner program aiming for 300,000 certified consultants within a year, while Amazon is embedding similar models into its offerings. Financial disclosures reveal that OpenAI's cost structure remains unsustainable under typical software unit economics, spending $1.60 for every $1 earned as of the most recent annual report. These developments reinforce the displacement of the per-seat licensing model. Gartner's cited mechanism is arbitrage, where agentic AI completes cross-system tasks without users actively working within apps, detaching business value from app usage. Traditional consulting's move away from hourly billing, as reported by the Wall Street Journal, echoes the software industry's realignment, emphasizing fixed-fee and outcome-based pricing over labor hours. The combination of end-client optimization efforts, vendor migration to services, and changes in consulting economics demonstrates a market-wide move toward operational accountability over software resale. For MSPs and IT providers, these changes pose direct challenges to legacy revenue assumptions and operational models. Per-user or license-based pricing faces mounting contract risk as agentic agents reduce seat counts. Service providers will be evaluated on their ability to manage this transition—internally and for their clients—by documenting workflow changes, auditing tool stacks, and adapting to new consumption and outcome-based vendor models. Early adoption of these practices within one's own business is becoming a credibility benchmark, as prospective clients scrutinize whether providers have successfully navigated the same seat retirement and cost reallocation they are expected to deliver. 00:00 Software Giants Go Human 04:26 Agents Don't Buy Seats 06:58 Squeezed From Both Ends 10;12 Why Do We Care? Supported by: Guardz Pax8

The dominant structural mechanism explored in this episode centers on governance gaps in access management and the resulting liability transfer to MSPs. The discussion highlights how fragmented identity stacks, unmanaged access, and reliance on manual tracking expose MSPs to growing contractual, operational, and legal risk. Companies and technologies referenced include Microsoft 365, Google Workspace, Okta, ConnectWise, and specific access governance solutions targeting the channel. The ConnectWise 2026 Threat Report identifies credential abuse as a core attack vector, underscoring how unaddressed authorization and access drift remain a structural exposure area. The episode cites multiple indicators and supporting data. According to the ConnectWise 2026 Threat Report, credential abuse is now the primary attack vector, with attackers commonly exploiting active and orphaned accounts left unmanaged in client environments. Fragmented identity stacks complicate the onboarding and offboarding process, with onboarding often requiring 45 minutes per client as technicians navigate numerous access portals. The prevalence of shadow IT, orphaned accounts, and missed deprovisioning windows was discussed as persistent drivers of both operational overhead and increased incident risk. Supporting developments include community-documented scenarios where multi-factor authentication (MFA) was present but insufficient to prevent breaches, particularly when privilege escalation or temporary exclusions remain unaddressed. Examples such as the Reddit phishing event and Microsoft's handling of MFA via VOIP demonstrate how authentication is distinct from governance, and that temporary access or exceptions frequently become permanent, heightening exposure. Regulatory environments—including healthcare, finance, and government—were cited as adding further requirements for explicit governance controls and auditable access policies, while manual spreadsheet tracking often fails to meet these demands. The operational implications for MSPs include the need to move beyond basic practice such as MFA and endpoint protection, toward purpose-built tools and processes that provide continual visibility, auditable controls, and policy enforcement for client access. Without this, MSPs face increased administrative burden, billing discrepancies, contractual liability, and reputational risk. As regulatory audits become more demanding and clients demand clearer evidence of governance, service providers must reconcile the tradeoffs between increased process complexity and the need for automated, enforceable identity governance. This shift challenges existing pricing models, requiring MSPs to justify and potentially repackage their service offerings in the context of risk management and operational maturity.

The episode examines the ongoing shift in the IT services market from traditional managed services to “managed intelligence,” as vendors like PAX8 and ConnectWise attempt to reposition their offerings around artificial intelligence (AI). This structural change introduces increased operational complexity for MSPs who are being urged to adopt new AI-driven models, while facing evolving expectations regarding service delivery, pricing, and accountability. The mechanism at play is the transfer of risk and uncertainty from vendors to MSPs, especially as AI and usage-based billing models upend established business practices. One significant development highlighted is PAX8's call for MSPs to become “managed intelligence providers”; however, according to PAX8's own head of AI adoption, only 17 out of 600 interviewed partners currently meet that standard, up from 13 a year prior. In response to this slow uptake, PAX8 has introduced bridge services and a Managed Intelligence Program to support partners through the transition, including white-labeled AI services and a platform for tracking usage called the agent gateway. These efforts underscore that the managed intelligence model presents a steep learning curve for most MSPs, with few having yet achieved operational maturity in this area. Related market activity further illustrates these dynamics. ConnectWise has restructured its platform around an AI core, introducing predictive intelligence and shifting to ticket-based billing rather than traditional per-seat models. According to ConnectWise, this shift reduces L1-L2 ticket escalations by 86% and increases technician productivity by 30%. Meanwhile, concerns remain about data ownership and the scope of actionable information, with companies like Lexful and Enable pushing for greater integration across siloed applications. There is also ongoing debate on whether system-of-record vendors or independent AI-native platforms will ultimately control operational workflows and client relationships. For MSPs and IT service providers, these developments translate into practical concerns around vendor dependency, variable cost exposure, and pricing pressure. The move to consumption-driven models and token economics increases unpredictability, forcing providers to absorb or carefully manage AI usage costs or risk compressed margins. There are also governance and accountability questions related to client relationships, especially as more AI service layers are introduced by upstream vendors. The operational implication is a need for heightened financial diligence, risk assessment, and a clear strategy for maintaining client trust and service differentiation in an increasingly intermediated service landscape. Sponsored by: Pax8 ScalePadABC SolutionsRythmz

The dominant structural shift outlined is a transfer of liability and accountability for AI-generated errors from vendors to the entities deploying these systems—primarily MSPs and their clients. While vendors aggressively promote scalable AI tools and urge rapid adoption, the legal and operational burden of verifying and standing behind AI output falls on deployers, not on the tool providers. Recent court rulings and shifting buyer expectations are accelerating this transfer, fundamentally altering the MSP business model around AI services. Primary evidence for this shift comes from both industry behavior and legal precedent. Kaseya urged MSPs to quickly embrace AI services while revealing that only about 13% of providers are seeing significant revenue from AI, despite roughly half of clients requesting these solutions. Compounding the structural gap is a low conversion rate from proof-of-concept to production (only 20% success, per Kaseya), and high failure rates in AI-generated code—Forbes reported security and logic errors appear far more frequently in machine-produced output than in human code. Notably, courts in Germany and Canada have ruled that organizations are legally responsible for the statements and errors created by their AI, not the vendors providing the underlying tools. Supporting developments reinforce the risk and accountability mismatch. Research cited from Gartner indicates over 70% of CEOs and 75% of CIOs believe current IT operating models are unfit for the demands of the AI era, highlighting a recognized governance gap. Consumer surveys show that over half hold company leadership personally responsible for AI failures. The recurring vendor emphasis on selling tools, combined with product features that prioritize scale over individualized accountability, deepens the structural challenge for service providers. For MSPs and IT service organizations, the primary practical implication is that competitive differentiation and risk mitigation will depend less on which AI products are resold and more on documented processes for reviewing, annotating, and standing behind AI-generated output. Vendors' tools are pervasive and quickly commoditized, so market separation arises from the ability to provide tangible accountability standards—proof of human review, defined sign-off authority, and clear records for client audits and legal defense. Pricing strategies that reflect the cost of accountability, rather than simply product markup, are likely to become more sustainable as client focus shifts from features to liability management in AI adoption. 00:00 The 13% Problem 03:29 The Tool vs. The Work 05:43 The Wrong Answer's New Address 08:37 Why Do We Care? Supported by: CometBackup TimeZest

The dominant structural shift underlined in this episode is the removal of the pricing floor for undifferentiated, repeatable IT work due to agentic AI adoption, especially in IT services and MSP operations. As described by Dave Sobel, this shift is not about wholesale job elimination but about AI absorbing routine, predictable execution, leaving human operators responsible for judgment and oversight. This change is illustrated by organizations such as OpenAI, where 97.9% of employees use AI agents, and by sector-wide hiring data tracked by SignalFire, revealing that software engineers—previously considered vulnerable—remain the largest share of new hires. The most consequential development is the clear division between executional work and judgment-based roles. Data from SignalFire shows that software engineers make up 55% of new tech hires, contrary to predictions of their displacement by AI. Similarly, ISC2's Cybersecurity Workforce Survey, reported by Dark Reading, finds entry-level cybersecurity roles are evolving rather than disappearing, with AI taking over routine triage and increasing demand for higher-level judgment skills. OpenAI's near-universal internal AI adoption supports the notion that employees are adapting their roles rather than being replaced outright. Further supporting developments include evidence from SplashTop, which measured that 53% of IT team capacity is spent on endpoint maintenance and repetitive tasks, areas highly susceptible to automation. The effect is heightened by macro trends—cited from Axios Macro and the NFIB—showing small businesses are actively reducing hiring plans and seeking solutions that remove the need for headcount growth. New MSP offerings, such as managed support teams available within 30 days, are scrutinized for repackaging traditional labor models vulnerable to rapid automation. For MSPs and IT service providers, the operational implication is the urgent need to reevaluate service lines, staffing, and pricing models. Services based on predictable, repeatable execution now face competition from AI-driven agentic work that operates with negligible marginal cost, eroding the business case for labor arbitrage and body-shopping models. The path to defensibility shifts toward services that require human judgment, oversight, and outcome-based delivery, with increased risk for firms reliant on commoditized execution. Sorting offerings by their exposure to automation and focusing investment in non-automatable, judgment-driven roles becomes a practical risk mitigation approach. 00:00 The Most-Hired Casualty 04:19 Which Half It Eats 07:06 The Rent-a-Team Trap 09:47 Why Do We Care? Supported by: Pax8 Sign up for the SMB Online Conference: www.smbonlineconference.com

The dominant structural shift addressed is the increasing operational dependency on Microsoft Intune for endpoint management across organizations of all sizes, which is exposing gaps between Microsoft's native capabilities and the practical needs of managed environments. This shift is creating new pressure points for service margins, as IT service providers find themselves compensating for visibility limitations and inconsistencies in Intune's deployment mechanisms. Vendors such as Recast Software have positioned themselves as companions that address these shortfalls, acknowledging that Microsoft routinely incorporates previously “companion” features into its own ecosystem. The primary evidence cited is the identified lack of comprehensive fleet visibility and inconsistent application deployment within Microsoft Intune environments. According to Recast Software's Chief Product Officer, Jake Mosey, customer feedback repeatedly points to insufficient information about device states—especially during hybrid or co-managed transitions from Microsoft Configuration Manager to Intune—and challenges with application deployment timing, patching, and third-party app management. These operational gaps create environments in which service providers must employ supplemental tools to maintain efficiency and consistency across client environments. Supporting developments include lessons learned from similar dynamics in the Apple-Jamf ecosystem, where continual vendor evolution (“Sherlocking”) forced channel vendors to focus on speed, specialization, and building direct community relationships. Jake Mosey emphasized that effective community-driven product development relies on discerning the needs of the wider user base, not just the loudest voices, and maintaining a focused strategy. The discussion also highlighted persistent fragmentation in multi-platform environments, meaning MSPs must often manage diverse device fleets with varying visibility and control requirements—a complexity heightened during prolonged hybrid migration states. Operationally, MSPs and IT leaders face practical implications including increased vendor dependency, the need for multifaceted visibility tools, and a requirement to plan for ongoing hybrid environments rather than clean migration end-states. Service providers are urged to prioritize automation where possible but must also recognize that full migration to a single endpoint platform remains impractical for many. Failure to address these gaps increases risk to client productivity and end-user satisfaction, particularly when patching, application deployment, or security controls are inconsistently applied. The expectation is that meaningful improvements will depend more on inventory and visibility capabilities than solely on automation or AI.

The dominant structural shift highlighted is margin pressure and business model viability for MSPs due to workforce reduction driven by AI automation. This is exemplified by Microsoft's introduction of Agent365—an enterprise product licensing AI agents rather than human users—and industry reports forecasting that 30–50% of white-collar jobs may be replaced by AI technologies, according to publication summaries referenced during discussion. The shift fundamentally threatens the per-seat managed services pricing model that has anchored MSP revenue. Evidence of mounting financial risk is provided by the scenario where clients may halve their seat counts within a two-to-three-year window. As stated, this adjustment would immediately cut monthly recurring revenue (MMR) for MSPs. The discussion connects this trend to Microsoft's evolving licensing model and notes an industry-wide consensus reflected in a Capterra survey, which found all surveyed MSPs in 2024 facing significant increases in local competition. The implication is that margin pressure from both automation and intensifying competition is occurring simultaneously. Additional developments reinforce the risks to stability. Security complexity and associated liability are increasing, as non-specialist teams—originally tasked with legacy IT functions—are now expected to take responsibility for security operations without adequate expertise. This burden is heightened by the emergence of unmanaged AI adoption at client organizations, creating new avenues for data exposure and regulatory risk. Surveyed business owners are considering exit or consolidation, citing inability or unwillingness to restructure business models to accommodate these changes. Peer group participation is recognized as widespread but not a direct countermeasure to these structural challenges. For MSPs and IT service providers, the practical implications are clear: reliance on the per-seat model is a growing contract risk, with revenue volatility linked to workforce automation outpacing both the speed of traditional service adaptation and client technology adoption. Accountabilities around AI risk, security governance, and compliance are expanding—often without a corresponding increase in compensable scope or staff capability. Operators must assess vendor dependency (especially in rapidly shifting software licensing models), realign service portfolios towards advisory, compliance, and security, and prepare for sustained market turbulence marked by shrinking margins and rising operational complexity. Supported by: Small Biz Thoughts Community Sign up for the SMB Online Conference: www.smbonlineconference.com

A structural repricing of memory and silicon components is forcing a shift in the economics of hardware resale for managed service providers (MSPs) and IT service providers. This shift is driven by concentrated demand for memory components from AI infrastructure build-outs, as evidenced by data from IDC and remarks from companies including Apple, Micron, SK Hynix, and Samsung. The episode highlights that memory costs have quadrupled in a year, and that both endpoint devices and servers are experiencing durable price inflation due to component scarcity and intensified competition for supply. The most consequential development cited is Apple's acknowledgment—confirmed by Tim Cook to the Wall Street Journal—that device price increases are now “unavoidable” because the cost of memory can no longer be absorbed. Memory manufacturers' share prices rallied on this signal, reinforcing an investor consensus that higher component costs will persist. IDC data showed AI-focused, non-x86 servers using Nvidia's ARM chips generated $58.7 billion—or nearly 48% of all server revenue—up 107% year over year, while x86 server revenue declined due to DRAM and NAND shortages. This dynamic indicates that AI infrastructure is bidding up component costs at the expense of standard business hardware. Secondary developments further reinforce this mechanism. The market's response to U.S. government announcements regarding Intel chip capacity expansion demonstrates that relief from the silicon crunch remains years away, not months. Channel partners—according to industry reporting—were already pivoting from hardware resale to services prior to these price shocks, with thinning hardware margins preceding the current pressure. The combination of fixed-fee hardware contracts and rising component costs now places providers in a position where they are “short silicon,” having unknowingly absorbed inflation risk they cannot pass on under existing contractual terms. For MSPs and IT leaders, the principal operational implications center on contract structure, exposure to component price volatility, and diminished hardware margins. Providers with fixed monthly agreements or hardware-as-a-service contracts based on last year's component costs are at an increasing risk of margin erosion, as their ability to reprice is contractually limited. Practical mitigation steps include auditing all fixed-fee agreements for exposure, amending contracts to include component index or price adjustment clauses, and separating hardware as a transparent, pass-through line item. Failing to adapt contract terms or refresh timing may compound both financial risk and the security profile of client endpoints. 00:00 Not the Tokens 03:31 An Auction for the Parts 05:46 Short Silicon 07:44 Why Do We Care? Supported by: Pax8 ScalePad Sign up for the SMB Online Conference: www.smbonlineconference.com

The episode reveals a structural shift where “AI powered” has moved from a selling point to a source of liability and customer distrust. Surveys from WordPress VIP, the Pew Research Center, and Carnegie Mellon University indicate that both consumers and professionals increasingly see visible AI in products and services as a negative attribute, eroding trust rather than adding perceived value. This trend impacts MSPs directly, as their role in advising clients on technology adoption now brings increased accountability for customer experience outcomes tied to AI-driven automation. According to a WordPress VIP survey, 60% of US consumers are deterred by the term “AI” in brand marketing, and 86% do not fully trust AI-delivered information, preferring original sources. The Pew Research Center found that, while 49% of US adults now use AI chatbots, 40% believe AI will worsen society and 67% distrust regulatory oversight. A Carnegie Mellon study of working visual artists reported 99% disapproving of generative AI and 85% refusing to use it. These quantified findings underscore a broad disconnect between AI adoption and public trust. Additional research reinforces this skepticism and clarifies operational risks. AnswerConnect's survey of 6,000 consumers across the US, UK, and Canada found that 85% prefer human service over bot interactions, 57% lose trust in brands using AI for support, and 73% exhibit greater loyalty to businesses maintaining human involvement. Data from Fractal and Search Engine Land shows that the share of consumers who say heavy AI use would decrease their trust in a brand nearly doubled in a year, rising from 20% to 39%. Furthermore, 84% desire businesses to disclose AI use, yet only 20% of businesses consistently do so. These patterns suggest tangible declines in customer loyalty and increased expectation for transparency surrounding AI deployment. For MSPs and IT service providers, visible AI in customer-facing areas introduces pricing risk and trust liabilities. Delegating key customer interactions to AI without clear disclosure can erode brand equity and disrupt client retention metrics. The operational recommendation is to segment human-in-the-loop service as the standard premium offering, with fully automated AI positioned as a disclosed, lower-tier alternative. Writing these distinctions explicitly into contracts and statements of work—pairing them with actual client retention data—enables more defensible pricing and clarifies accountability, helping avoid unintended consequences tied to silent automation. 00:00 The Turn-Off 03:39 Reading the Motive 05:25 The Loyalty Account 08:35 Why Do We Care? Supported by: Pax8 ScalePad Sign up for the SMB Online Conference: www.smbonlineconference.com

Vendor channel consolidation, specifically through peer and family-owned acquisitions, is driving a fundamental shift in the operational landscape for MSPs. This episode analyzes the case of NetSciences, an MSP based in New Mexico, which was acquired by Qual IT—a family-owned operator with over two decades in the space. The MSP market now includes multiple buyer categories: peer acquisitions, roll-ups, and private equity (PE) players, each with distinct approaches to valuation, integration, and operational continuity. The transition of NetSciences to Qual IT illustrates that smaller MSPs increasingly face decisions about optimal sale pathways. According to Joshua Liberman, roll-up buyers and PE investors often introduce rapid shifts in deal terms and operational models, with PE offers described as subject to abrupt valuation changes (drops up to 67% noted by Liberman), creating a higher risk profile for sellers seeking stability and legacy preservation. By contrast, the peer acquisition model (as executed through platforms such as ASCII's peer-to-peer review process) is allowing some MSPs to complete sales with greater continuity and cultural alignment, though post-sale integration often defaults to the acquirer's systems and standards rather than blending best practices. Secondary developments reinforcing this shift include persistent market focus on monthly recurring revenue (MRR) metrics and the operational tradeoffs of pursuing high MRR percentages. Liberman maintained a 50–60% MRR intentionally, arguing that chasing 80%+ MRR metrics can distort business health and does not universally suit all MSP models. Discussion of cybersecurity underscores the need to reposition technical services as business outcomes—security is described as foundational, permeating every operational and client decision, yet is often misunderstood or negotiated away to the detriment of risk posture. Operationally, these trends imply that MSPs must be highly selective about both client and acquirer fit, balancing growth trajectories against risk aggregation and cultural alignment. Attempts to homogenize client environments and enforce consistent security baselines are necessary but limit scale and acquisition appeal. Failure to assess how integration will shift toolsets, processes, and staff autonomy can result in loss of operational maturity and control post-sale. Additionally, the unchecked adoption of tools such as AI—without oversight or documented process—exemplifies emerging areas of governance risk that technology leaders cannot overlook. Supported by: ScalePadTimeZest Sign up for the SMB Online Conference: www.smbonlineconference.com

The episode highlights a structural shift in IT and security governance driven by the proliferation of autonomous AI agents inside enterprise environments. This shift is characterized by a mismatch between the visibility and control frameworks that organizations possess versus the scale and autonomy of AI deployments. Microsoft's introduction of Agent365—a control plane designed for agent governance—and policy statements from its security leadership illustrate the growing gap between the number of AI agents and the traditional IT administrators tasked with managing them, raising questions about the effectiveness and scalability of legacy governance mechanisms. A consequential development described is the growing risk stemming from AI agents operating with inherited credentials and unrestricted lateral access, often without comprehensive oversight or tracking. Both Microsoft and Zero Networks are referenced as addressing this problem but propose different architectural solutions. Microsoft's model emphasizes governance at the identity and endpoint layers, exemplified by Agent365, while Zero Networks promotes network-layer enforcement. The latter approach seeks to restrict lateral movement before it leads to a breach. Data points referenced include insider reports of numerous agents running undetected in enterprise workflows, and observations that most organizations lack accurate inventories or controls corresponding to their AI agent exposure. Supporting stories reinforce the structural shift and associated risk, with Chris Boehm emphasizing the speed and scope of AI agent deployment compared to previous technology waves such as mobile and cloud. The emergence of agents capable of rapidly scanning and connecting across systems further complicates standard prevention and detection postures. Credential governance is described as insufficient on its own, since privileges and exceptions tend to accumulate and enable unaudited access, particularly as agent proliferation accelerates. The episode also references the challenge of building reliable behavioral baselines due to the dynamic, ephemeral nature of modern agents, making static or manual approaches impractical. For MSPs and IT service providers, the operational implications include increased risk associated with governance gaps, margin pressure from the need to adopt new security layers, and greater complexity in maintaining policy enforcement. Existing security stacks are often fragmented, with consolidation complicated by the addition of new solutions that promise automation and scalability but also require integration into varying infrastructure maturity levels. Effective containment of breaches is increasingly tied to minimizing lateral movement rather than relying solely on detection speed. As agent-driven access becomes ubiquitous, the ability to dynamically segment and restrict access based on observed behavior, rather than static credentials alone, is highlighted as a practical safeguard in limiting breach impact and maintaining service continuity. Supported by:Zero Networks https://zeronetworks.com/

The episode centers on persistent margin pressure and operational discipline as the dominant structural mechanisms in the managed services sector. Data from the Service Leadership Index (SLI), managed by ConnectWise under Peter Kujawa, reveals that best-in-class MSPs continue to target aggressive profit growth—specifically, a 34% increase in profit dollars on only 10.6% revenue growth—despite already sustaining a six-year average of 19% adjusted EBITDA. The discussion highlights that achieving these targets relies less on rapid revenue growth and more on cost control, particularly around SG&A (Selling, General and Administrative Expenses), and highlights the influence of financial discipline often seen in private equity-backed firms. The analysis is grounded in quantitative benchmarking. According to the SLI's 2026 profitability report, while best-in-class EBITDA performance has been sustained, recent years show a widening gap between budget targets and attainment. Specifically, in 2023, MSPs overshot their profit budget by 31%, but in 2024 and 2025, performance dropped to 81.9% and 89.4% of budget respectively. The report explicitly calls current profit targets “ambitious,” given recent misses. Scale thresholds were also referenced, notably the operational risks between $6M and $10M in annual revenue, with Peter Kujawa citing stalls in growth and compressed margins as common in that band. The episode further introduces the first iteration of an Automation Index intended to quantify financial and operational impact of AI adoption on MSPs. Metrics such as service multiple of wages, revenue per employee, and service gross margin are emphasized, but findings show that automation is not delivering uniform benefit. Top-tier MSPs increase efficiency and retain pricing discipline, while bottom quartile firms see little or no improvement in core metrics. The report also notes that private equity-backed providers are investing significantly in AI, though organic growth and acquisition costs remain similar across provider types. Operational implications for MSPs include heightened accountability for realistic forecasting and disciplined budgeting. Failure to match projections with operational realities risks unnecessary cost expansion, especially around headcount and tool adoption. For firms in key scale thresholds, owner delegation and leadership investment are essential to avoid stagnation and margin erosion. Additionally, automation and AI adoption provide efficiency opportunities but deliver benefit only to those with strong management practices; undisciplined adoption or margin givebacks through pricing discounts negate potential gains. MSPs must therefore focus on data-driven decision-making, careful cost control, and ongoing evaluation of both financial and operational KPIs to navigate increasing complexity, vendor dependency, and persistent margin pressures.

The core structural shift highlighted in this episode is the commoditization of AI model platforms and concurrent consolidation at the vendor and platform layer, forcing Managed Service Providers (MSPs) to move their value proposition above reselling models to orchestrating, governing, and verifying AI outputs. The discussion references the rising concentration and valuation of platforms such as NinjaOne—a founder-led, profitable RMM platform with a $12.3 billion valuation and 70% year-over-year growth—and Pax8 building business toolkits that draw more operational functions onto their rails. At the same time, major AI developers like OpenAI are entering the channel more directly by launching partner programs aimed at MSPs and consultants. The most consequential development is the confirmed shift from reselling AI models to managing their outputs and risks. Glean surveyed 6,000 digital workers and found that while AI delivers approximately 11 hours of weekly time savings, nearly 6.4 hours are reclaimed by “bot sitting”—the human intervention required to supply context, verify, and correct AI outputs. This hidden labor raises a risk scenario: two-thirds of workers admit to releasing unchecked AI outputs, and Ivanti found that only 42% of IT environments actually have a named owner for each AI agent, despite 85% claiming so—a 43-point gap in accountability. Asana and Deloitte further reinforce the issue, reporting frequent cost overruns and unmanaged autonomous AI deployments among enterprise and SMB environments. Supporting developments underscore this governance and accountability gap. TechCrunch cited that ChatGPT's AI market share has dropped below 50% as the field becomes more interchangeable and less differentiated by underlying model. Vendors such as Anthropic and OpenAI, recognizing model commoditization, are seeking revenue through high-volume partner channels, blurring the lines between vendor and channel competitor. According to Asana, more than 80% of UK IT leaders encountered unplanned AI costs, and over half reported business harm from autonomous AI actions, shifting operational and liability risks squarely onto MSPs and IT service providers. Operationally, these trends compel MSPs to take explicit ownership of the orchestration and governance layer, rather than relying on tool reselling. The transcript advises mapping every AI-driven decision or output that reaches client endpoints and identifying who verifies these outputs before customer exposure. Failing to address these governance blanks does not avoid work but shifts it to unbilled, post-incident cleanup, often with financial, legal, or compliance consequences. Effective MSPs will need to price, document, and regularly review their verification, orchestration, and risk assumption, positioning these as standalone, billable services to manage risk and maintain margin as AI platforms commoditize and vendor dependencies rise. 00:00 Bigger Platforms, Unwatched AI 03:44 The Vendor Walks Into the Channel 05:56 Govern It or Absorb It 08:52 Why Do We Care? Supported by: ScalePad Sign up for the SMB Online Conference: www.smbonlineconference.com

A pronounced infrastructure dependence on third-party AI models has emerged across the MSP ecosystem, largely due to the rapid adoption and integration of AI-powered features within vendor products. This structural shift is increasingly opaque, as providers are sold features rather than transparent access to underlying models, leaving MSPs exposed to changes in technologies and policies enacted upstream by vendors or regulators. The episode highlights how this dependency extends to delivery teams and end clients, with operational continuity tightly linked to decisions and actions outside the MSP's direct control. The most consequential development referenced is Anthropic's release and rapid withdrawal of its Fable 5 AI model following a directive from the U.S. Commerce Department, which ordered a cutoff of model access to foreign nationals within 72 hours of public launch. According to published benchmarks, Fable 5 surpassed GPT 5.5 in performance, but the government-mandated suspension exposed how quickly model access can be rescinded. The policy move immediately impacted any MSP or client with offshore or nearshore staff relying on AI features invisibly powered by that model. Further supporting the central theme, companies such as PAX8, Enforcer, and CloudRadio are embedding AI capabilities into platforms used by MSPs to manage Microsoft 365 environments, automate ticketing, and support scalable client operations. In parallel, vendors like Proofpoint are integrating compliance solutions directly with AI model APIs, further entwining risk management tools with the same core AI infrastructures. A Netrio survey cited in the episode found that while 82% of mid-market IT leaders have AI in production, only 26% report organization-wide governance, highlighting an accountability and visibility gap. Operationally, MSPs face heightened contract and vendor risk. Most lack an accurate inventory of which AI models underpin their services and how rapidly these dependencies can be affected by regulatory directives or vendor shifts. The discussion underscores the need for explicit procurement protocols, delivery mapping, and outage runbooks that account for opaque model dependencies. As clients seek greater transparency and contractual assurances regarding model use and continuity, MSPs who anticipate and document these dependencies may be positioned to reduce exposure and establish clearer accountability. 00:00 Switched Off 03:19 Painted Over 05:20 Govern or Absorb 08:41 Why Do We Care? Supported by: Pax8 Sign up for the SMB Online Conference: www.smbonlineconference.com

The episode highlights a structural shift from automation that suggests actions to automation that executes actions autonomously, thereby transferring substantial operational risk and accountability to technology vendors and their AI-driven platforms. This transition is exemplified by Atera's deployment of their autonomous AI agent, Robin, which is positioned to handle a significant proportion of Tier 1 and complex Tier 2 IT tickets for managed service providers (MSPs). The company's commercial strategy, including performance guarantees, signals an increased expectation that AI can assume core IT operational responsibilities that were traditionally reserved for human engineers. Atera has introduced a policy wherein Robin is guaranteed to autonomously close at least 50% of all Tier 1 and complex Tier 2 tickets within 90 days of onboarding, or fees are waived. According to Atera, this commitment is supported by a backend analysis of MSP tickets and live demonstrations using historical data. The company asserts that Robin's mean time to repair is approximately 120 seconds, that onboarding is managed collaboratively, and that the rollout is more akin to hiring and training a human engineer than a standard software deployment. This approach is backed by patent filings and a business model integrating AI as the foundation rather than an add-on. The episode further examines the implications of mandatory AI bundling in Atera's redefined RMM and PSA platform offering. The company has faced pushback from segments of the MSP community dissatisfied with bundled AI services and associated pricing changes, particularly from those wishing to maintain control over their technology stack. Atera responds by describing a re-conceptualization of their platform as inherently AI-driven, distinguishing between “platform AI” and the autonomous Robin agent, and clarifying that preexisting AI users would not incur additional costs. There is also discussion around the impact of automation on human roles and the need for new approaches to training and accountability, particularly for junior staff. For MSPs and IT service providers, these developments signal an increase in infrastructure dependency on vendor-managed AI agents, as well as new layers of contract risk linked to performance guarantees and platform integration. The operational reality described involves a significant reduction in required headcount, a shift in staff responsibilities from routine incident response to higher-order business and security tasks, and the necessity for designated internal management of AI tools. There remain unresolved concerns about skill degradation and the long-term risks of over-automation, including the narrower pathways through which junior personnel may acquire foundational experience. Sponsored by: ScalePad https://scalepad.com/dave/ Nerdio https://nerdio.co/MSP-Radio Sign up for the SMB Online Conference: www.smbonlineconference.com

Vendors supplying AI-driven technologies are experiencing sustained margin pressure from high operational costs and underwhelming business-level returns, leading to the rapid creation of new product categories that are pushed into the MSP channel. Companies such as Atomic Work, Silverfort, and Guards are releasing governance tools for managing AI agents, while Connect Secure is offering patch management products targeted at MSPs. These launches are not indicators of competitive differentiation, but of structural cost challenges being passed from vendors to their partners. Business media reports and internal industry data reveal that while individual productivity from AI implementations increases—for example, by accelerating engineer output—the promised business-level gains in productivity, revenue, and profit have not materialized to the extent vendors projected. According to analysis cited by Dave Sobel, high operational costs are forcing large firms like Microsoft, Google, Amazon, and Uber to restrict or cap AI usage internally, reflecting an industry-wide retreat from premium pricing models due to an unclear return on investment at the organizational level. Additional developments reinforce this margin-driven shift. The federal Cybersecurity and Infrastructure Security Agency (CISA) has mandated 72-hour patching of high-risk vulnerabilities, underscoring heightened compliance requirements. Simultaneously, vendors are accelerating the rollout of governance, identity, and patch velocity tools. However, a study analyzing over 13,000 US MSPs found that those surpassing $1 million in revenue are distinguished by market positioning, online visibility, and business maturity, not by the breadth or novelty of their toolsets. For operators, the implication is clear: stacking up new vendor products is now a baseline requirement rather than a path to competitive advantage. Firms that rely solely on vendor frameworks and toolsets risk absorbing more complexity without improving margin or differentiation. Practical separation will come from owning the "judgment layer"—defining, governing, and pricing how AI functions within client environments—rather than reselling tools. Positioning, documented governance, and clear operational standards will be more defensible than investing exclusively in vendor-driven offerings. 00:00 Manufactured Urgency 03:58 The Cost Confession 06:09 Out-Buy vs. Out-Position 08:35 Why Do We Care? Supported by: Nerdio Sign up for the SMB Online Conference: www.smbonlineconference.com

Vendor channel consolidation continues to restructure the MSP landscape, with private equity-backed rollups driving both market concentration at the top and increased deal volume. This episode centers on the sale of Worksighted, a 25-year-old, $27 million revenue MSP with strong vertical focus in healthcare and construction, to Thrive in a 35-day close. The structural mechanism at play is an increasing market segmentation where larger MSPs systematically acquire or merge with similarly sized providers, often leaving a gap for smaller operators as larger entities move upmarket. Primary evidence for this consolidation includes direct transaction data and workflow. According to Abraham Garver, his team handled 132 vetted buyer candidates for Worksighted, resulting in eight competitive offers after 76 signed NDAs. Thrive, having completed 27 MSP acquisitions, was able to accelerate the deal's timeline due to deep experience and preparation by both buyer and seller. The trend is further supported by Q2 market updates indicating 22 U.S. MSPs likely to come to market in 2026 and over 120 M&A transactions in Q1 alone, as reported by Drake Star. Related developments highlight the bifurcation of deal opportunities by provider size and the associated liquidity for MSPs. Private equity buyers increasingly favor acquisitions with a minimum of $3 million in revenue and $500,000 in EBITDA, while smaller MSPs are more commonly left to pursue peer-to-peer mergers or organic growth strategies. The episode also addresses the operational pitfalls of optimizing solely for high recurring revenue percentages, with evidence suggesting buyers offer premiums for organic growth and new client acquisition rather than rigid recurring revenue thresholds. For operators, these dynamics generate clear tradeoffs and risks. Larger MSPs face the challenge of integrating acquired firms and potentially divesting smaller clients who do not meet their revised minimums. Smaller MSPs may find opportunity by acquiring divested clients or targeting niche segments that fall beneath larger consolidators' thresholds. For all providers, the importance of thorough preparation, clean financials, and strategic clarity on post-transaction roles emerges as a key safeguard against value loss and disruption. Rigid adherence to target metrics not grounded in buyer behavior—such as focusing excessively on monthly recurring revenue—carries the risk of reduced flexibility and diminished exit prospects. Sponsored by:ScalePad ABCS Sloutions LLC

Platform vendors are transferring liability and delivery responsibility for AI services onto MSPs by building structured AI practice frameworks, training programs, and service delivery methodologies. This approach is motivated by mounting economic pressures on vendors, as seen with large-scale infrastructure investments and the need for sustainable revenue models. PAX8, Ingram Micro Cloud, ConnectWise, and others are formalizing AI partner programs that enroll MSPs to deliver vendor-defined services, while shifting operational complexity and accountability downstream. The episode highlights PAX8's Managed Intelligence initiative, aimed at helping small and midsize MSPs deliver AI services to SMB clients with minimal prior expertise. PAX8 cites its own research, which notes that 62% of SMBs view AI as essential for competitiveness and 74% plan to increase AI spending in the coming year. The economics of AI scaling are underscored by data on projected data center buildout costs—up to $15 trillion by 2030 and requiring $1.75 trillion annually just to maintain. OpenAI's public offering, with an $850 billion valuation and $180 billion in funding, is attributed to the need for capital that private markets can no longer supply, prompting vendors to leverage channel partners for both revenue generation and market validation. Supporting developments include expanded programs at the distribution and platform levels: a PAX8-Nocdoc partnership providing managed NOC/SOC services for smaller MSPs, Ingram Micro Cloud's collaboration with PartnerStack to formalize AI service delivery infrastructure, and ConnectWise's introduction of an AI-native platform for predictive and autonomous IT operations. Research from Omnia and the IBM Institute for Business Value indicates underutilization of vendor market development funds and widespread deployment of AI frameworks despite only 11% of tech leaders feeling prepared—demonstrating the gap between vendor offerings and operational readiness. The implications for MSPs are significant. By enrolling in these vendor-driven AI programs, providers take on delivery risk, contractual accountability, and potential liability for AI outcomes they did not design. The structural split is clear: MSPs can either create and govern their own AI methodologies—pricing accountability as a service—or become vehicles for vendor frameworks, absorbing complexity without full compensation or control. Practical recommendations include updating service agreements for AI-related risks, building internal governance around AI deployments, and not allowing vendor or community consensus to substitute for explicit accountability for outcomes. 00:00 Channel AI Shift 03:59 Enrollment, Not Enablement 06:55 Methodology vs. Liability 10:01 Why Do We Care? Supported by: Zero Networks CometBackup

The episode identifies a growing governance gap as a central structural issue for MSPs and IT service providers, driven by rapid AI adoption through subscription-based tools and platforms. Rather than being introduced as controlled, IT-led initiatives, AI services are entering organizations piecemeal—often through end users and business units—undermining established accountability and management practices. This dynamic is exemplified by ConnectWise's dismantling of its ASIO platform in favor of a new AI-native operating layer designed to unify PSA, RMM, security, and automation functions, and by clients independently layering on AI-powered tools without centralized oversight or cost control. A primary example of ungoverned risk involves unsustainable AI cost exposure. According to Axios and TechCrunch, an enterprise amassed around $500 million in a single month on Anthropic's Claude due to unlimited, unmonitored usage. Freshworks' survey of over 12,000 IT professionals quantifies the industry's operational friction, finding mid-market companies waste about 25% of AI budgets on complexity, for a total of $16 billion in annual waste. Despite 89% of respondents planning to increase AI spend, only 15% have actively integrated these tools into daily workflows—revealing widespread governance lag behind adoption. Supporting developments highlight the breadth and persistence of this governance deficit. Organizations such as the Linux Foundation have responded by forming the Tokenomics Foundation to standardize AI cost tracking. Meanwhile, AI tool adoption is occurring outside IT, leading to agent sprawl, unclear permissions, and cost scaling linked to agent behavior rather than headcount. Roll-up strategies in adjacent sectors—such as Thrive Holdings' $1 billion commitment to consolidate accounting firms under an AI operational platform—demonstrate capital's move toward operationally governed, AI-enabled service models, suggesting a parallel risk for IT providers. For MSPs and IT leaders, these trends underscore the urgency of operationalizing AI governance as a billable, contractual service rather than an informal or embedded support task. Risks include absorbing liability for unmanaged AI usage, exacerbated operational complexity, and relinquishing margin to platform or capital entrants. Practical steps involve conducting AI tool audits, inventorying agent access and spend, instituting usage controls, and reframing account segmentation around governance and liability exposure. MSPs who define, price, and contract for governance can mitigate inherited risk and avoid being displaced by vendors or capital-backed consolidators. 00:00 ConnectWise Rebuilds 03:59 Ungoverned Agents 06:06 Roll-Up Warning 09:38 Why Do We Care? Supported by: Moovila ScalePad

A central structural mechanism highlighted in this episode is the exposure and amplification of technical and organizational weaknesses by enterprise AI initiatives, particularly as organizations pursue rapid AI adoption without adequate investment in data and process fundamentals. The episode draws on findings from an MIT Media Lab report, which found that 95% of enterprise AI pilots had no measurable impact on profit and loss, despite $30–40 billion in investment. Michael Privat, representing the healthcare technology firm Availability, discusses the consequences for organizations that apply “thin” AI overlays on top of unaddressed legacy data infrastructure and processes. The most consequential data point centers on AI's amplifying effect. According to the MIT Media Lab report cited by Michael Privat, 74–75% of companies expect revenue growth from AI, but only 20% are realizing gains. The root cause identified is not AI itself, but foundational failures: organizations use pilots as procurement exercises rather than outcome-driven initiatives and neglect to address data consistency and process integrity. Pilot projects, in many cases, simply accelerate the visibility and scale of existing dysfunctions rather than creating new value. Further evidence is provided through discussion of operational methodologies and organizational approaches. Michael Privat details a shift from pre-AI process benchmarks, such as DORA metrics focused on predictability and velocity, toward new models that account for AI's speed and amplification risks. He points to increasing investments in engineering capacity—in particular, tripling headcount in India—while emphasizing that efficiency gains from AI only materialize where discipline, standardization, and solid engineering “plumbing” is already in place. Both the need for audit trails and rigorous governance, especially in regulated sectors like healthcare, are flagged as structural safety requirements rather than optional layers. Operationally, the implications for MSPs and IT leaders include the risk of exposing latent deficiencies when implementing AI-driven offerings, particularly when layering automation and analytics atop fragmented or inconsistent infrastructure. Key areas of impact are the need for robust governance frameworks—especially with agentic AI, where dynamic system behaviors require ongoing accountability and auditability—and the risk that AI investments made without process and data “spring cleaning” can actually accelerate failure modes. For IT service providers, the material risks are in unexamined process debt, tool misalignment, and the temptation to prioritize velocity over resilience, ultimately increasing operational and contractual exposure. Supported by:NerdioScalePad

The current structural shift centers on the transfer of accountability for AI risk from vendors and regulators to managed service providers (MSPs). Vendors such as Anthropic and Microsoft are expanding their enterprise-focused AI channel programs and services tracks, while regulators pull back from enforcement, leaving MSPs as the de facto accountable parties for AI deployments. Reports and data indicate that vendor-driven channel expansion and regulatory laxity are converging to make service providers the liable layer in AI delivery. Anthropic is broadening its CLAUDE partner network from around 100 to several thousand partners, organized in tiers with outcome-based incentives and a dedicated services track targeting MSPs and system integrators. Microsoft, responding to low Copilot adoption rates (reported at 3.3% of eligible users), is allowing full removal of Copilot from systems. An IDC/Expereo survey of 800 companies found 70% are budgeting for AI, but investment is driven more by competitive anxiety than proven results. Additionally, a concentrated group—top 5% of users—accounts for the bulk of enterprise AI-related risk, according to a separate analysis. Supporting developments include the emergence of Lemhi, an early-stage platform aimed at enabling MSPs to package and sell AI transformation as a recurring service, and warnings from lawmakers about cuts to CISA that undermine federal cyber defense capacity. The episode also highlights a consistent theme: government agencies such as the White House and NIST are shifting toward voluntary measures and measurement frameworks, declining to create enforceable accountability standards for AI in production environments. For MSPs and IT leaders, these developments translate to increased contract and operational risk. Without renegotiated agreements specifying usage ceilings, approval workflows, and liability terms, providers may inherit unpredictable financial exposure and compliance gaps. The absence of effective governance requirements from both vendors and authorities places the operational burden on MSPs to define, monitor, and enforce safe use of AI, including recurring governance services such as data boundary enforcement and audit evidence. Failure to address these issues may result in MSPs acting as uninsured support for unmanaged AI deployments they cannot fully control or price. 00:00 MSP AI Play 04:24 AI's Accountability Gap 06:50 MSP Risk Transfer 09:49 Why Do We Care? Supported by: ScalePad Moovila

The episode examines a structural shift in the MSP business model driven by the introduction of AI-linked consumption-based pricing layered on top of traditional per-seat fees. This emerging mechanism, typified by Microsoft's E7 license, adds variable AI consumption charges to otherwise predictable monthly service costs. Vendors are restructuring partner payment models, with Microsoft's move closely watched by others, signaling a wider potential for volatility in the recurring revenue foundations of MSPs, according to analysis from Jay McBain and recent channel data. The most consequential development is Microsoft's E7 pricing, which explicitly adds an AI consumption cost to the standard per-seat license. This move introduces variability at “machine speed,” in contrast to previous examples such as cloud storage, where consumption remains predominantly human-driven and thus more predictable. Analysts note that similar micro-consumption models—charging per conversation, process, or API call—are being adopted by hundreds of companies. Market data from Omnia and referenced industry research places the global IT spend at $6 trillion in 2026, with two-thirds delivered by channel partners and a rapid shift from fixed, subscription models toward micro-consumption billed at a granular, usage-based level. Supporting evidence includes the lack of sufficient vendor-provided controls for variable consumption, leaving MSPs exposed to unplanned cost spikes. While large enterprises are introducing robust FinOps practices and loading up cloud credits, smaller MSPs serving SMB customers are not prepared with similar governance structures. There is also vendor-led encouragement for AI adoption—such as persistent in-app assistants—that drive up consumption before adequate controls or cost-passing mechanisms are established. The sustainability of current pricing models is further questioned by the fact that providers like OpenAI and Anthropic are themselves subsidizing significant portions of token usage, distorting true costs throughout the value chain. For MSPs and IT service leaders, these developments mean greater exposure to unpredictable costs, potential margin pressures, and increased contractual risk tied to AI consumption. Operators cannot rely on vendors to provide spend caps or consumption governance today; failure to build internal controls or pass-through mechanisms may result in absorbing unpaid liabilities. Accountability for AI-driven actions, remediation, and configuration changes will rest with the MSP, elevating both operational complexity and liability exposure. The current environment requires building governance, audit trails, and spend management capabilities now, ahead of broader market adoption of AI consumption models. Supported by: CometBackup

Outcome-based managed security and attached vendor warranties are driving a new form of coverage-based vendor lock-in for MSPs and IT service providers. Vendors such as Intezer and SPECTRA are introducing performance guarantees, SLAs, and cyber resilience warranties that require MSPs to fully standardize on their architectures. This evolving model shifts accountability for enforcement and risk management from the individual MSP to the vendor's operating model, thereby altering the independent role of the MSP within client environments. A notable example is Intezer's Amplify Partner program, which asserts that its platform can process 100% of security alerts while escalating fewer than 2% for human review—claims the company frames as outcomes rather than product specifications. SPECTRA's use of certification-linked warranties, distributed via Ingram Micro, establishes channel-distributable assurance products with explicit conditions attached at every level. According to a Check Point report, while 77% of organizations report having adopted AI for cloud security, only 26% feel capable of enforcing those strategies, revealing a gap between security intent and operational ability. This structural shift is further illustrated by Merlin Cyber's FedRAMP managed service offering, Lumen's MDR enhancements targeting mid-market MSPs, and Trustlogix's addition of intent-based authorization controls. The FBI's announcement regarding Microsoft 365 OAuth token hijacking and recent vulnerabilities in widely used platforms like ConnectWise Automate underscore the real-world risks of automation platforms being targeted. These developments collectively point to growing operational complexity, rising compliance burdens, and the need for MSPs to separate their commitments from upstream vendor claims. For operators, the trend demands increased scrutiny of warranty terms, claim denial conditions, and SLA language before making any client-facing assurances. MSPs risk absorbing liability if they repeat vendor marketing claims without contractual clarity or operational control. Effective governance now requires independently produced, audit-ready evidence that documents compliance and enforcement separate from vendor portals. As assurance sales proliferate, the operational gap between acting as an underwriter versus a reseller will drive market differentiation, affecting both pricing structures and eligibility for vendor-backed coverage. 00:00 Channel-Ready Security 03:41 Policy vs. Reality 05:59 MFA Isn't Enough 09:12 Why Do We Care? Supported by: ScalePad Moovila

A fundamental structural shift underway is the movement of AI from isolated features to operationalized, production-level workloads in MSP tooling and client environments. This transition is not primarily about the capabilities of individual AI models but about their integration into existing operational platforms and workflows. Companies such as PDQ, Senteon, Domotz, and Zoom are incorporating AI agents directly into management layers, endpoint automation, and workflow orchestration, thereby increasing both the scope and complexity of AI impact. The locus of value is shifting from features to workflow control and integration, creating new demands for governance, consumption monitoring, and exit strategies. The most consequential development referenced is the transition in AI billing and operational models from static user or seat licenses to variable, usage-based consumption. He cites TechCrunch's coverage of GitHub Copilot's move to token-based billing and Semafor's reporting of Uber's rapid exhaustion of its 2026 AI budget in four months due to unbounded consumption by generative tools. F5's State of Application Strategy report is referenced to confirm that multi-cloud and parallel model operations are now common, with significant instances of AI-related security incidents already reported. Secondary developments reinforce this structural realignment of risk and accountability. PDQ, for instance, is expanding multi-tenant management and integration capabilities, while Senteon enables endpoint hardening and drift control directly in Rewst's platform. Domotz's MCP server allows AI agents to operate across 40,000 networks globally, and Zoom is packaging AI context protocol features for workflow automation. Each of these changes is designed to increase operational efficiency, but also expand the surface area for unintended consequences, elevated operational complexity, and potential budget overruns. For MSPs and IT leaders, the operational implications center on governance, spend control, and clear accountability over AI-driven tools and workflows. The risk is that without adequate monitoring, policy setting, and contractual clarity—especially around data portability and exit costs—MSPs may face liability for unplanned consumption, misconfigured automation, or governance gaps. The evidence indicates the need to proactively audit AI integrations, set usage thresholds, instrument logging and budgeting controls, and renegotiate vendor contracts to ensure service boundaries and oversight mechanisms are in place before workflows become too deeply embedded. 00:00 MSP Stack Resets 04:09 AI Needs Governance 06:45 Govern AI or Pay 09:22 Why Do We Care? Supported by: Nerdio Zero Networks

Forced arbitration clauses have become embedded as a dominant mechanism in technology vendor contracts, shifting legal risk and accountability away from large vendors and reducing recourse options for managed service providers (MSPs) and IT service firms. This structural change, present in agreements with RMM and PSA vendors as well as hyperscalers such as Microsoft, Amazon, and Google, establishes a private dispute resolution system that operates beyond the traditional court system and is typically non-negotiable for smaller partners. The shift is evidenced by data and case studies outlined by Brendan Ballou. According to supplied figures, while consumers win in 89% of small claims court cases, their success rate drops to between 20% and 30% in arbitration, and even less—sometimes as low as 0.2%—for certain arbitration providers. Arbitration clauses are enforced even in extreme cases, as illustrated by a notable instance involving Disney, in which a forced arbitration clause was applied following a consumer's prior account registration. Legal precedent as far back as the 2011 Supreme Court decision referenced by Brendan Ballou has broadened the Federal Arbitration Act well beyond its 1925 origins, further entrenching this system. Additional developments reference increased litigation in the 1980s, often cited as justification for expanding arbitration, though he attributes much of the legal caseload surge to government actions rather than consumer or employee lawsuits. The technology industry's broad adoption of arbitration, especially in contracts where MSPs have little or no room to negotiate, further cements these power imbalances. Alternatives such as mediation are discussed as potentially less risky, but their adoption remains limited. The operational implications for MSPs, IT service providers, and IT leaders include heightened contract risk and reduced leverage in vendor disputes. Arbitration clauses limit access to open legal processes, restrict discovery rights, and are prone to bias in favor of vendors with repeat arbitrator relationships. For MSPs reliant on large platforms and suppliers, this creates ongoing exposure and complicates risk management. Mitigating measures—such as leveraging peer coordination for "mass arbitration" or negotiating for post-dispute mediation rather than pre-dispute forced arbitration—require proactive planning but may remain unavailable in standard vendor agreements. Supported by:MoovilaHaloPSA

The structural shift highlighted in this episode is a move from simple AI enablement to a managed service model centered on agent governance, enforcement, and workflow automation within IT environments. The episode identifies unmanaged AI agents as a source of escalating risk, citing vendors like Scalepad shifting from remote monitoring to SaaS and AI usage discovery, and referencing research and audits from SNCC and Verizon that identify tangible security flaws and unapproved AI activity within organizations. Managed service providers are increasingly positioned as the operational layer that defines and enforces governance over automation systems, rather than simply deploying AI tools. The primary evidence for this shift is found in audit findings and market reports. SNCC's audit of 4,000 AI agent skills showed over a third had at least one security flaw, while Verizon's data cited by The Register noted a fourfold increase in employees using unauthorized generative AI, with 28% of data loss prevention violations involving code or proprietary data submitted to AI platforms. Gartner, as reported by The Register, predicts 40% of organizations will demote or remove AI agents due to failed governance efforts—attributing the problem to all-or-nothing approaches that lead to operational and compliance failures. Secondary developments reinforce the move toward operationalized governance. Scalepad and Watchguard are bringing AI and SaaS governance capabilities to the MSP channel, with product releases focused on real-time discovery, policy enforcement, and automation control. Incidents like Anthropic's leak of its full source code for Claude Code, exposing permission and sandboxing details, illustrate how transparency in AI agent operations can also create attack vectors—emphasizing the need for robust operational controls and ongoing auditability. The market is shifting to sell "coherence"—packaging identity, permissions, and workflow automation—rather than just technological capability. Operationally, the consequences for MSPs include increased responsibility for defining and enforcing permission boundaries, approval rules, and evidence collection. Failure to address agent governance will expose providers to operational ambiguity, unpriced liability, and recurring support burdens. The guidance is to move beyond AI enablement projects and toward agent operation retainers that include clear workflows, permission maps, execution logs, and contractual clarity on responsibility and incident management. MSPs that cannot prove and control agent behavior risk inheriting the complexity and fallout from system failures or misuse. 00:00 Shadow AI Surge 05:01 Context Is Infrastructure 07:46 Agent Control Plane 11:16 Why Do We Care? Supported by: JumpCloud TimeZest

The episode reveals a growing governance gap as the central structural shift in the IT services sector, driven by accelerated AI adoption and increasing automation. Companies such as OpenAI, Anthropic, Veeam, and Auvik are reframing their market positions around the operational risks and requirements introduced by AI agents, data automation, and new service delivery models. This evolution is underscored by the rising number of AI agents—projected by IDC to reach 2.3 billion by 2030—operating largely outside of current oversight and frequently with excessive or inappropriate permissions. The principal development discussed is Veeam's announcement of its Data AI Command Platform. According to Dave Sobel and Rich Freeman, this platform is intended to address data-centric failures beyond traditional ransomware or accidental deletion. Veeam's platform is designed to handle issues such as AI-generated data hallucinations, inappropriate data exposure, and policy enforcement failures. The platform's architecture builds on the acquisition of Security AI, combining data security posture management with backup, compliance, and governance capabilities, although, as of now, key remediation features are only available for Microsoft 365, with further expansion expected over the coming months. Supporting developments include Auvik's expansion of automated network management based on a large historical dataset and the simultaneous entrance of OpenAI and Anthropic into direct services for mid-market clients, backed by billions in private capital from entities such as Goldman Sachs and Blackstone. Both companies now embed applied AI engineers at client sites, bypassing traditional channel partners. Channel operator feedback, reflected in research by Techisle and discussions at vendor conferences, indicates a lack of MSP readiness and a slow response to developing governance and compliance services, despite evidence from end-user data pointing to significant unmet demand and risk exposure. Operationally, MSPs face a growing liability trap where the speed and delegation of decisions to AI systems increase the potential for unnoticed errors or breaches. There is a disconnect between customer demand for governance, compliance, and data controls, and the preparedness of MSPs to deliver those services. This exposes providers to heightened contractual, operational, and reputational risk, particularly as vendors and large AI companies move directly into the mid-market service delivery space. Practical safeguards, clear accountability frameworks, and objective benchmarks for automation and governance effectiveness will be required to mitigate exposure and support safe, durable service offerings. Supported by: CometBackup HaloPSA Moovila

The dominant structural shift highlighted is the increasing systematization and formalization of vendor-to-MSP growth channels, where vendors now dictate partner engagement through structured programs, marketplaces, and packaged offers. According to Dave Sobel, this trend is driven by vendors such as Microsoft, NinjaOne, GoTo (LogMeIn), and Forcepoint, each advancing formal partner networks and explicit funding paths. The episode contends that these programs operate less as genuine strategies for MSPs and more as distribution mechanisms, shifting operational and support burdens downstream to service providers. Primary supporting evidence comes from the 2026 Microsoft Partner Global Benchmark and Success Index from Maven Collective Marketing, which analyzed over 185,000 data points. The report found that 87% of partners exist on at least one Microsoft Marketplace, with 60% having transactable offers and 58% receiving leads sourced by Microsoft. Moreover, partners with dedicated Microsoft management support are three times more likely to secure funding from Microsoft. This data illustrates how tightly partner success is coupled to marketplace discoverability, direct purchasing offers, and vendor-provided leads and funding. Secondary developments reinforce this mechanism. Other vendors—such as NinjaOne, GoTo, and Forcepoint—have instituted similar programs, with explicitly defined partner journeys for integration, service delivery, and mutual success. Additionally, economic factors such as historically low consumer sentiment, supported by University of Michigan data, and persistent IT resourcing gaps, as identified by the Linux Foundation survey and reported by SmarterMSP, are further sharpening buyer demands for packaged, defensible IT outcomes. In parallel, reports like the 2026 Kaseya State of the MSP emphasize misaligned demand and revenue in AI/automation, and research from RCR Wireless highlights operational burdens that can fall back onto MSPs in vendor weak-support scenarios. For MSPs and IT service providers, the operational implications center on risk absorption, margin erosion, and increased dependency on vendor-defined models. Without internal discipline to clearly define, price, and standardize offers—especially for complex new demands like AI and automation—MSPs risk turning complexity into unpaid labor and operational drag. The key accountability remains with the provider to package and govern vendor-aligned services in a manner that remains robust regardless of shifting vendor incentives or support. Failure to do so leads to “MSP-owned friction,” where ticket volumes, support expectations, and inconsistent delivery increase without corresponding profit. 00:00 Partner Programs Formalized 04:31 Packaged or Passed 08:14 Priced or Absorbed 11:58 Why Do We Care?

The episode details a tightening regulatory environment driven by new enforcement timelines for Cybersecurity Maturity Model Certification (CMMC), altering how MSPs and IT service providers are expected to deliver both compliance and operational services for U.S. defense contractors. Structural pressure stems from the Department of Defense making CMMC Level 2 compliance a contractual mandate for approximately 300,000 defense contractors, shifting risk and accountability towards providers who manage compliance workflows, technical environments, and client behaviors. C3 Integrated Solutions and their dual CMMC Level 2 certifications exemplify this transition, with clear implications for co-ownership of compliance outcomes and increased scrutiny on provider practices. The most consequential development is the substantial gap between compliance requirements and the current readiness of the defense contractor base. As of early 2026, only around 8% of contractors have obtained CMMC Level 2 certification, despite enforcement being implemented in contracts starting in November of the same year, according to Dave and Jason. Challenges arise from cost, organizational bandwidth, and complexity, with MSPs serving as pivotal partners to small subcontractors lacking in-house resources for process documentation and change management. Assessment scheduling bottlenecks and insufficient documentation are delaying certifications, increasing risk that many contractors and their service partners will miss the rapidly approaching deadlines. Related developments reinforce the central issue of operational risk and governance complexity. Jason Tierney illustrates the difference between technical compliance and true assessment readiness, citing real-world examples where insufficient evidence and poor understanding of process details lead to significant assessment delays. The rise of compliance-as-a-service offerings, enclave computing environments, and specialized governance tooling are attempts to address those gaps, but also introduce new layers of pricing, platform selection, and accountability concerns, especially when third-party tools fail to meet strict requirements such as FedRAMP moderate for handling sensitive data. For MSPs and IT leaders, the shift imposes higher barriers to entry, increased legal and contractual exposure, more rigorous documentation and process controls, and the need for customized delivery models that support both technical defenses and organizational behavior change. Providers must navigate conflicting requirements between specialized regulatory environments and multi-tenant tooling, manage escalating costs for both themselves and clients, and clarify responsibility boundaries in shared compliance scenarios. The requirement for human oversight—particularly in automated or AI-assisted compliance tooling—remains non-negotiable, reflecting the ongoing gap between technical implementation and credible assessment outcomes. Supported by:CometBackupMoovilaHaloPSA

The structural shift outlined in this episode is the rapid evolution of search and productivity interfaces from static query tools to agentic platforms capable of autonomous action, oversight, and automation. Companies such as Google are redesigning search at the interface level, integrating multimodal input and agentic workflows powered by AI models like Gemini 3.5 Flash. The dynamic is not competition at the model level, but rather a pivot toward which provider can offer policy enforcement, cost controls, compliance, and documented governance over increasingly complex agent-driven environments. The most consequential development is Google's redesign of its search box for the first time in 25 years, transitioning to an AI-powered, chatbot-style interaction that can process longer prompts, images, files, and monitor tasks directly within the browser. According to New York Times and Channel Life New Zealand, this change embeds AI agents as defaults in the workflow, underpinned by Google's commercial growth—ad clicks up by 6%, cost per click up 7%, with profits over $132 billion since 2022. The shift is visible in adoption data as well: ChannelDive reports Anthropic's Claude overtook OpenAI's GPT suite for business usage, while Gartner forecasts $2.59 trillion total AI spending in the year, but only $33 billion is model-specific. Supporting developments reinforce risk and operational complexity as AI transitions into core business processes. Channel-focused reports note that vendors are offering managed agent services, operational sandboxes, and white-label security operations to simplify agent deployment and lower entry barriers. OpenAI pitching “buy before you try” guarantees, and launches like Acronis Cyber Freight — promised as “predictable” and “protected by default” — reflect client demand for reliability over raw capability. Across these moves, partners and IT providers are being drawn into defining, monitoring, and governing the new automation layers, with increasing requirements for documentation, provenance, and workflow auditing. For MSPs and technology leaders, the operational implications are direct and substantive. The work now centers on defining governance frameworks—inventorying systems that can act autonomously, classifying authority and registration requirements, building audit trails, and delineating contractual boundaries for automation responsibility. Providers who approach this as standard support risk carrying unpriced operational and compliance burdens, especially in environments where unauthorized automations or unregistered connectors proliferate. The emergent requirement is to treat agent governance as a managed service, pricing it separately, and establishing clear evidence and escalation protocols to avoid absorbing blame and liability for automation-driven incidents. 00:00 Beyond Blue Links 04:30 Predictability Wins 06:39 Govern or Absorb 09:19 Why Do We Care? Supported by: Moovila ScalePad

Security operations for MSPs are undergoing a structural shift from simply deploying additional tools to establishing a liability-focused accountability model, where the ability to provide operational evidence of controls is becoming as critical as the tools themselves. This shift is catalyzed by corporate insurance, procurement, and third-party verification structures—such as those cited by WatchGuard, Assurix, and the NIST AI cybersecurity overlays—demanding verifiable security outcomes and alignment with external standards, rather than relying on provider assertions alone. Survey data referenced from Cybersmart and Beta News reveals that 75% of MSPs experienced at least one breach in the past year, while 54% endured multiple incidents; concurrently, SMB buyers state security is a top priority, but only 13% of microbusinesses operate proactively. According to WatchGuard's global survey of 842 professionals, 94% of clients using dedicated MSPs feel adequately protected, yet 58% indicate intent to change providers within three years—highlighting a disconnect between perceived and delivered value. The emergence of Assurixs' live MSP Trustmark, based on 64 operational controls, further formalizes evidence requirements as market prerequisites. These dynamics are reinforced by shifts in insurer behavior and regulatory alignment. Huntress and Acrisure are collectively rolling out a cyber insurance package contingent on adoption of Huntress's managed detection and response, explicitly tying coverage eligibility to verifiable provider-side controls. The maturing of NIST's AI cybersecurity overlays introduces new standardized control checklists likely to become operational requirements. Additionally, reports from Omdia and MSP Channel Insights note that vendor ecosystems are now rewarded for integrating security as an outcome with automation and multi-tenant integration—reflecting market demand for reliable, defensible evidence of controls. For MSPs and IT leaders, these developments drive the need to restructure contracts to clearly delineate evidence obligations, manage liability exposure, and price evidence production as a formal deliverable rather than as unreimbursed support. Failing to do so risks absorbing unfunded post-incident evidence work, margin erosion, and loss of control over the security value conversation. Operationally, maintaining live accreditations, standing up a formal evidence management function, and explicitly excluding unmanaged SaaS, identity, and AI workflows from baseline service tiers are becoming necessary to maintain profitability and accountability. 00:00 Breach, Then Switch 04:52 SaaS Blind Spot 07:16 Prove or Pay 10:24 Why Do We Care? Supported by: Zero Networks HaloPSA

The dominant structural shift highlighted in this episode is the migration of AI from experimental tools into directly embedded workflows within widely used small business platforms. Vendors like Anthropic, with its Claude for Small Business connectors to QuickBooks, HubSpot, Canva, Google Workspace, and Microsoft 365, are abstracting away technical complexity by offering concrete, prebuilt automations that address specific business processes. This embedding moves operational risk and ambiguity from model selection to the permissions layer, where control, oversight, and accountability become central concerns for providers supporting these environments. A key supporting development is Anthropic's rapid market penetration, with the VentureBeat-cited Ramp AI Index reporting 34.4% business adoption of Claude in the US—outpacing OpenAI's 32.3%. The implication, reinforced by research from the Global Technology Industry Association, is that AI service revenue is rising sharply, but only 30% of IT service providers in the UK and Ireland report fully integrating AI into their models. Simultaneously, governance gaps are being exposed: The Register notes user data may be employed for model training unless privacy settings are proactively changed, leaving operational risk exposed through default configurations. Additional developments reinforce the risk and accountability shift. OpenAI has established a subsidiary focused on direct deployments and implementation, seeking to guarantee quality and consistency in enterprise integration. CIO Dive references Palo Alto Networks research indicating 77% of CIOs claim AI risk management confidence, yet only 30% have real usage visibility, and 62% cite rogue agent concerns. The discussion connects these risks back to routine SMB operations, where AI-enabled workflows can act on core business data, increasing MSP proximity to liability and making explicit who controls connectors, permissions, and incident response documentation. For MSPs and IT service firms, the operational consequence is that supporting AI-enabled platforms now obligates them to establish and document governance, inventory, data access, and approval processes. Risk shifts from abstract model performance to concrete operational exposure, especially as AI systems interconnect with finance, identity, communication, and other high-stakes subsystems. Providers lacking scoped service definitions and contractual clarity face unpriced liability, while those that implement billable AI governance frameworks—such as audit templates, privacy reviews, and incident-ready contracts—are positioned to address demand from clients, auditors, and insurers. Neglecting these steps is likely to result in exposure to vendor-driven terms and diminished operational standing. 00:00 Workflow Takeover 04:20 Readiness Crisis 06:24 Govern or Expose 11:13 Why Do We Care? Supported by: NerdioScalePad

The episode highlights a structural transition from software systems that record tasks to platforms that actively participate in business decisions, particularly through agentic AI in procurement. This shift is anchored in the adoption of AI-driven SaaS solutions by mid-market organizations, as seen with Procurify, which reports managing over $100 billion in organizational spend. The mechanism moves beyond basic automation, assigning software agents responsibilities that were traditionally human—such as flagging compliance breaches or routing approvals—directly within operational workflows. According to Chad Gaydos, current deployments of such agentic AI commonly automate tasks like invoice detail verification, policy enforcement, and contract compliance. These developments are most prominent in mid-market environments, where limited staffing—sometimes with no dedicated procurement analysts—drives greater reliance on platforms to perform core operational functions. The focus is not on completely replacing personnel but on supplementing constrained teams and ensuring repeatable enforcement of controls, with organizations leveraging these systems to gain efficiency in both cost and process governance. Additional points discussed reinforce the central shift, such as the distinctive pace of adoption among mid-market firms compared to enterprises. He identifies that smaller organizations often approach these technologies with greater agility and willingness to accept risk, while also displaying heightened dependency on system trust and governance frameworks. The episode also references "frontier firms" co-defined by Microsoft and Procurify, characterized by their forward-leaning adoption of AI and structured standards for technological governance. Variability in governance, auditability, and trust across different organization sizes underlines the operational diversity in adopting agentic platforms. For MSPs and IT leaders, these shifts raise practical concerns around governance design, accountability for software-driven actions, and operational dependency on vendor platforms. Effective risk mitigation requires establishing audit trails, clear standards for automation versus human oversight, and robust compliance controls. Providers supporting mid-market clients should anticipate requests for prescriptive guidance on data and process governance, while also preparing for greater operational reliance on systems that automate, not merely record, business decisions.

The core structural shift described in this episode is the integration of AI as an active workflow actor within managed service environments, not simply as an isolated tool. This mechanism alters the governance and accountability requirements for MSPs, as AI now interacts directly with core business platforms and operational data. Companies like Microsoft are embedding AI features—such as Copilot and a legal AI agent—across productivity and security environments, while reports from Axios Future of Cybersecurity and The Register highlight that AI activity is increasingly touching managed identity, email, data, and security infrastructures. The episode's primary evidence centers on the adoption of AI-driven productivity and legal tools within Microsoft 365, with broad rollout timelines targeting early June. Microsoft's deployment of legal AI agents in Word—as outlined by The Register and Thoreau—demonstrates that AI is being implemented to review contracts, draft language, and check citations, embedding itself into sensitive business workflows. Additionally, Proofpoint's formation of an MSP business unit around 365 security further reflects this shift, consolidating risk and workflow management where client data, identity, and security converge. Supporting developments reinforce this trend of workflow centralization and accountability ambiguity. Vendors are introducing dashboards—such as Anthropic's Claude code agent view—that offer improved visibility into AI-driven processes; however, as noted, visibility alone does not constitute governance. The emergence of platforms like Halo PSA and features from JumpCloud exemplify the market response, where vendors and MSPs are being forced to tighten control and monitoring around AI-driven work, including automation, ticketing, and remediation workflows. The episode notes that unmanaged automation creates governance risks that operators must close. The practical implication for MSPs is a set of new operational burdens: rising margin pressure from unpriced AI governance work, contract risk if responsibilities for AI-generated actions remain undefined, and new demands for auditability, evidence retention, and workflow documentation. Providers must build inventories not only of AI tools but also the workflows they touch, define explicit service scope, and establish pricing models for governance functions. The operational tradeoff is an increasing need for infrastructure and process maturity, as the expectation of transparent, accountable AI-driven work is now a baseline for client trust and risk management. 00:00 Managed AI Risk 03:50 Scope or Absorb 06:03 Four MSP Pressures 08:35 Why Do We Care? Supported by: MoovilaHaloPSA JumpCloud

The central structural shift identified is the acceleration and scaling of cyber risks due to artificial intelligence, which turns formerly expert-driven security processes into repeatable, rapid workflows. Major threat intelligence units, including Google's Threat Intelligence group, are now documenting the use of AI in both identifying and weaponizing software vulnerabilities. The landscape is further shaped by the proliferation of AI-generated and AI-assisted online content, contributing to an environment where traditional verification and control mechanisms are less reliable. The episode presents concrete evidence: Google reported criminal hackers leveraging AI models—explicitly noting the use of non-Google technology—to discover a previously unknown zero day, while The Verge and Wired highlighted AI-assisted attempts to bypass multi-factor authentication and the impact of synthetic content even within cybercrime forums. Research covered by 404 Media documented that by mid-2025, a third of newly published websites were AI-influenced. These observed changes drive threat intelligence teams to treat AI as a working hypothesis in live investigations. Additional supporting developments reinforce the broadening security and operational impact. Tools such as Proofpoint's Prism Investigator and OpenAI's Daybreak show the push toward automated threat detection, investigation, and reasoning pipelines, altering expectations from detection to defensible reconstruction and evidence generation. Analysis of supply chain compromises—such as tampered software installers and malware leveraging already-exposed cloud systems—demonstrates how automation reduces defender response windows while increasing operational pressure on providers. Reports from Small Biz Trends and channel Life show significant implementation gaps, with only a minority of small businesses deploying password managers, and a wide disparity between optimism and readiness for AI-powered security. For MSPs and IT leaders, these trends tighten operational accountability. The tradeoff shifts from focusing on technology stacks to delivering concrete evidence of patch application, identity verification, data retention, and audit support. Providers face increasing pressure to standardize verification workflows, reduce patch validation cycles, and make evidence retention a default process. The operational complexity intensifies—either the MSP develops controls to govern automation and evidentiary rigor, or becomes the default risk absorber for ambiguous, fast-moving attack paths shaped by both client and attacker use of automation. 00:00 Zero-Day 04:06 Speed Gap 06:25 Prove It 10:27 Why Do We Care? Supported by: Moovila Zero Networks

AI systems are increasingly embedded as non-human participants within managed environments, driving a structural shift in operational responsibility and exposure for MSPs. This shift is characterized by the integration of AI-powered tools—such as note takers, copilots, connectors, and agents—into core business workflows and SaaS platforms. Companies like Google, Microsoft, and ServiceNow are formalizing AI governance with platform features such as agent registries, policy enforcement gateways, and cross-platform audit trails. Reports from industry sources, including Wired, Rubrik, and regulatory bodies in the EU, substantiate these developments and highlight changing expectations for accountability and control. A key finding, according to security research by Red Access and covered by Wired, is that over 5,000 publicly exposed AI-generated web apps were found on the open web, with about 40% leaking sensitive data ranging from medical records to corporate strategy documents. Rubrik's Zero Lab survey of over 1,600 IT and security leaders further reports that 86% expect AI agents will surpass existing security controls within a year, while only 23% feel they have full visibility into these agents' activities. The New York Times and legal organizations note increasing legal and evidentiary risks posed by AI transcription tools in business meetings, warning that ungoverned AI outputs may be subject to discovery in litigation and could compromise attorney-client privilege. Additional developments reinforce the governance and risk gap. Platform vendors are building more granular control and auditing features, but most client environments still include unregulated AI tools, third-party connectors, and manual overrides outside these native boundaries. Regulatory frameworks are evolving to place explicit bans on specific AI outputs and to delay implementation of high-risk AI oversight, as seen in the EU's provisional AI Act. The integration between Black Kite and Sayari exemplifies how vendors are seeking to connect risk intelligence across supply chains, but operator-level exposure often remains distributed and ambiguous. For MSPs and IT leaders, the practical implication is an immediate requirement to inventory and classify AI participants and outputs within managed domains, clarify contractual scope, and establish evidence-ready policies for audits, incidents, and legal review. Relying solely on vendor platform controls is insufficient, as clients and auditors will expect clear documentation of AI activity, data access, and policy enforcement. Many agreements are not priced or structured for AI governance and may require explicit scope adjustments, upcharges for AI inventory and policy services, and contractual exclusions for unmanaged AI activity to avoid unpriced liability. 00:00 Agents Unchecked 04:49 Control the Bot 06:58 AI Audit Risk 10:38 Why Do We Care? Supported by: Nerdio TimeZest

The episode reveals a structural shift in the technology landscape: artificial intelligence is becoming a new layer of managed consumption, with measurable impact on infrastructure, contract terms, and operational accountability. This shift is illustrated by leading technology platforms explicitly metering AI usage through compute tokens, storage footprints, and local model deployments. Companies such as Alphabet, Amazon, Microsoft, and Google are integrating AI not only as features but as quantifiable workload layers, leading to economic and governance questions regarding who controls consumption and who assumes the risk of overage or misuse. The most consequential development discussed is the rapid, capital-intensive scaling of AI infrastructure by leading hyperscalers. Alphabet raised its 2026 capital expenditure guidance to a possible $190 billion; Amazon's AWS revenues rose 28% year-over-year to $37.6 billion, with quarterly capital expenditures reaching $44.2 billion— both moves directly tied to AI infrastructure investments. At the same time, endpoint and storage vendors, such as Apple and Backblaze, are experiencing elevated demand from AI workloads. On the software side, companies like Anthropic are explicitly raising API rate limits and deploying features to formalize the measurement and orchestration of AI-driven processes. Supporting developments include the migration of management and control functions into enterprise platforms and endpoint environments. Microsoft Agent 365 is now broadly available, offering admins centralized policy controls over AI agents across cloud and local machines, with integration into Intune for granular restriction and monitoring. Google's Chrome browser now automatically downloads 4GB Gemini Nano models to support local AI functions, raising new operational considerations around storage, policy management, and user approval. These developments anchor the thesis that AI is no longer a passive toolset but a consumption and policy domain that requires active oversight. Operationally, MSPs and IT service providers face heightened exposure to contract and governance risk. The presence of invisible AI consumption— in the form of storage expansion, token overages, unauthorized agent actions, or degraded endpoint performance— requires explicit clauses in client agreements and new monitoring capabilities. Providers unable to demonstrate control over AI usage, policy enforcement, and exception handling may inherit both support burdens and unresolved liability. The practical implication is clear: future margins and contract viability will increasingly depend on the ability to meter, document, and govern AI-related activities, rather than simply enabling client access. 00:00 AI Infrastructure Surge 04:17 Control Layer Wins 06:41 MSP Liability Shift 10:50 Why Do We Care? Supported by: ScalePad CometBackup Moovila

The episode highlights a structural shift from traditional software licensing towards consumption-based AI billing, transforming AI adoption into a source of direct financial exposure and accountability. This mechanism is illustrated by Microsoft's new administrative controls for Copilot in Windows 11 and platform-wide integration efforts from vendors such as Apple and Amazon. The primary concern is no longer simply enabling access to AI tools, but managing their consumption, controlling costs, and clarifying responsibility for both outputs and consequences. The most consequential development centers around rapidly escalating AI costs and the difficulty organizations face in quantifying usage. According to reporting from The Information, companies such as Uber exhausted their 2026 AI budgets within months, with some daily usage costs reaching approximately $1,000 per user. Simultaneously, The Register cites a survey indicating that a majority of U.S. employees are skeptical about their employers adopting Microsoft's AI bundles, and many believe alternative tools suffice. Additionally, Apple's acceptance of a $250 million settlement regarding misleading AI claims signifies a shift from reputational to monetary accountability. Supporting developments further expose operational and governance challenges. Microsoft's 2026 Work Trend Index, cited by CNET and GeekWire, identifies a disconnect between employee pressure to use AI and leadership's lack of defined, standardized practices. Apple's movement toward a third-party extensions model and Amazon's integration of managed agents into Bedrock are designed to address platform coherence, yet they introduce dynamic complexity in model choice and cost accountability. Gartner's projections of rising IT spend tied to data center investments further reinforce the infrastructure burden associated with widespread AI adoption. For MSPs and IT service providers, these developments underscore the risks of treating AI as a standard application rather than a managed operational layer. Legacy service agreements rarely specify how AI-driven costs, data exposure, or automation errors are governed. Providers now face new expectations to separate access and licensing from governance, usage auditing, and policy enforcement. Those who adapt by offering discrete AI management services—covering monitoring, cost controls, workflow approvals, and incident review—can align compensation with responsibility, while others risk absorbing escalating vendor complexity and unreimbursed accountability within flat-rate agreements. 00:00 AI Bill Due 03:31 Culture Blocks AI 05:49 AI Accountability Gap 09:16 Why Do We Care? Supported by: Moovila HaloPSA

The dominant structural shift addressed is the move of platform vendors away from competing on feature sets toward controlling the governance and billing layer that underpins managed services. This is evident in moves by Microsoft, AWS, and Kaseya, specifically with Microsoft's new licensing tier combining per-seat fees with consumption-based AI add-ons, AWS redefining managed services around agents, and Kaseya introducing action-based pricing for IT management. Analysts noted that these developments collectively place a consumption meter on previously flat-rate services, reconfiguring how MSPs and IT providers will be billed and held accountable. Primary evidence for this shift includes data from Omdia's channel media report and tracked M&A activity within the MSP sector. The report counted 169 MSP acquisitions in 2025, mirroring prior years' activity, yet identified that one acquirer—Evergreen Services Group—accounted for 47 deals, illustrating a concentration in acquisition strategies. Notably, 69% of publicly announced deals involved private equity, with the remainder pursued by independent operators. The North American channel media landscape saw significant contraction, with titles dropping from 29 to 18, despite stability in the global outlet count—attributed to both industry consolidation and AI-driven changes in content discovery. Supporting developments include growing use of AI in content production, leading to declining traffic for B2B publications as audiences increasingly access information through automated tools rather than direct visits. The rise of engagement-focused business models and shifts in acquisition criteria—such as Evergreen targeting founder-led MSPs—underscore evolving buyer strategies. Additionally, platform vendors are restructuring their product and pricing models around agent-driven and action-based billing, while shifting their external positioning to emphasize AI, intelligence, and cyber resilience. Operationally, MSPs and IT leaders face increased pricing and margin variability driven by emerging consumption-based licensing and AI service models. The historical per-user, per-month bundle is at risk as vendors experiment with new billing constructs, exposing providers to cost unpredictability and complicating client contracts. Providers lacking internal engineering or acquisition frameworks may be especially exposed, while consolidation and vendor dependency raise governance and accountability stakes. MSPs pursuing higher margin services, such as compliance or cyber resilience offerings, must prepare for new cost structures and intensifying pressure from both customers and vendors regarding efficiency, pricing, and service outcomes.Supported by: Zero Networks Moovila Upcoming event: The Pivotal Point of IT: Building Services for the AI-First Era Date: May 13 at 1p.m. EDT Register: https://go.acronis.com/davesobelaiera

The episode identifies a structural shift in how AI adoption is being managed within IT environments: control and accountability are now central concerns, overtaking simple discussions of AI usage or feature deployment. Shadow AI—unmanaged or improperly governed AI agents—has emerged as a tangible risk vector. Government entities, such as the White House, and technology vendors including Microsoft, Cisco, and OpenAI are framing AI not only as a productivity tool but increasingly as a source of operational and security liabilities that demand more robust oversight. A key example comes from an incident reported by TechRepublic in which an AI agent within a coding workflow deleted both a production database and its backups, resulting in a prolonged, business-impacting recovery from a three-month-old backup. In parallel, the Hacker News highlighted findings from scans of one million exposed AI services, characterizing the market's current AI security posture as lacking, with many endpoints widely reachable unintentionally. Microsoft's public transition of Agent365 from preview to release was directly tied to fears over the risks associated with shadow AI, indicating industry recognition of autonomous agents as a new attack surface requiring governance. Supporting developments further validate this trend. Cisco's open sourcing of AI Bill of Materials (BOMs) tools, Wiz's tracking of non-human identities tied to AI workloads, and OpenAI's rollout of advanced account security all signal a growing industry emphasis on making AI deployments auditable and restrictable. Practices such as phishing-resistant authentication—driven by token theft campaigns analyzed by Microsoft—and continuous permission monitoring, as advocated by Material Security, are now increasingly viewed as necessary safeguards rather than optional enhancements. Providers like Enforcer and products such as Copilot Manager are explicitly focused on surfacing shadow AI usage and enforcing credential discipline, underlining the growing demand for proof-of-controls. MSPs and IT service providers now face greater operational complexity and contract risk tied to AI automation. Client expectations are shifting from baseline AI access to demonstrable governance—requiring non-human identity inventories, documented permission boundaries, and validated recovery frameworks for AI-powered workflows. Token harvesting and persistent OAuth grants increase the likelihood that MSPs will be held responsible not just for prevention, but for rapid containment, rollback, and producing evidence during security incidents. Failure to meet tightened SLAs around backup immutability, authentication protections, and agent visibility could soon become a material contract exposure. 00:00 Agents Gone Rogue 03:50 Govern the Agent 06:24 MSP at Risk 09:54 Why Do We Care? Supported by: CometBackup ScalePad Upcoming event: The Pivotal Point of IT: Building Services for the AI-First Era Date: May 13 at 1p.m. EDT Register: https://go.acronis.com/davesobelaiera

The dominant structural shift identified is the emergence of agentic AI as a direct operator within multi-system business environments, triggering a governance and accountability gap. Vendors and cloud platforms—including AWS, Stripe, and Cloudflare—are enabling AI agents not only to recommend actions but also to directly access payment rails, provision infrastructure, and execute transactions. This movement turns automation into an operating model issue rather than a feature deployment, as the identity, authority, and accountability of non-human actors become central operational questions. Primary evidence is drawn from a range of industry signals. According to an AMD-commissioned IDC report, 81% of enterprises are engaged in AI PC adoption and 61% are embedding AI into workflows. AWS has expanded managed agent packaging for AI deployments, Stripe has launched the Link wallet allowing AI agents to process payments on users' behalf with controls on payment credentials, and Cloudflare has demonstrated agents autonomously provisioning cloud resources with enforced monthly spend limits. While these statistics carry vendor-driven optimism, the combined actions of these companies confirm a shift from advisory AI to operational AI. Related developments reinforce this trajectory. The SolarWinds survey reported by Computer Weekly finds 71% of IT workers experiencing higher demands due to AI, with only 19% noting reduced cognitive load, reflecting operational burdens rather than efficiencies. Similarly, Forrester data cited by The Register highlights a change in CIO responsibilities from system building to outcome governance as agentic AI exposes gaps in decision rights and process completeness. Security risks are elevated, as the Kela report counts 2.86 billion stolen credentials in a year, indicating that agent-driven credentials can trigger machine-speed purchases and changes, compounding the challenge of oversight and recovery. Operational implications for MSPs are significant. Without explicit governance, spend limits, approval paths, and audit trails, MSPs face increased liability and support burden when AI agents initiate actions across client systems. The episode underscores that automation is not just a technical project but a contract and service design issue; if accountability is not clearly defined, MSPs bear the risk and cost of unauthorized transactions and exception handling. To mitigate exposure, there is a need to formalize agent governance as a priced, intentional service encompassing identity management, financial controls, and documented operational guardrails before agentic AI is deployed in client environments. 00:00 Agents Take Over 04:39 Who's Accountable? 06:48 Who Owns This? 09:58 Why Do We Care? Supported by: NerdioScalePad Upcoming event: The Pivotal Point of IT: Building Services for the AI-First Era Date: May 13 at 1p.m. EDT Register: https://go.acronis.com/davesobelaiera

The core structural shift identified is the reconfiguration of managed service pricing and accountability due to the integration of AI and platform metering into standard IT offerings. Large vendors—including Microsoft and AWS—are shifting the economics of IT delivery: traditional flat-rate bundles are being rendered structurally unsafe as AI-driven workloads introduce unpredictable consumption costs and financial exposure. This change is catalyzed by vendors attaching metered billing models and embedding AI agents directly into enterprise platforms, which fundamentally shifts risk and cost variability onto MSPs and service providers. The most consequential development is Microsoft's introduction of Microsoft 365 E7, described as a new bundle combining seat licensing with consumption-based AI fees. According to company statements and Computer Weekly reporting, Microsoft is explicitly positioning the suite as a license-plus-consumption model with measured AI usage, tracked similarly to Azure. Gartner's latest IT spending forecast, cited via CIO.com, anticipates global IT spend reaching $6.31 trillion by 2026, with a 55.8% jump in data center infrastructure spending, largely driven by AI adoption. Secondary developments echo this trend. AWS has expanded its managed agent offerings on Amazon Bedrock, integrating OpenAI models and presenting agents as standardized, enterprise-ready managed services; pricing is identified by analysts as a tipping point. Cloudflare's collaboration with Stripe highlights infrastructure that enables agents to provision accounts and handle finances with minimal human input, using protocol-based authorization and spending controls. Vendors like AvePoint release governance tools that focus not on offering more AI, but on operationalizing policy control and audit management across multi-tenant environments. These illustrate increasing platform vendor jurisdiction over layers historically managed by MSPs. For MSPs and service providers, the practical consequences are increased exposure to contract risk, margin compression, and operational complexity. Flat rate contracts that fail to track AI consumption or bundle AI support risk being underpriced and absorbing both spend and support variance. The shift towards platform-managed governance, identity, and audit controls requires providers to separate governance from operational support in agreements, implementing new monitoring, reporting, and cost-tracking tooling. Failure to address these shifts could result in lost accounts, failed renewals, and loss of insurability, as insurers and auditors demand provable oversight and policy enforcement. 00:00 Seats Meet Meters 05:39 Bundles Break Here 08:32 Cleanup Costs You 11:49 Why Do We Care? Supported by: Acronis Moovila Zero Networks Upcoming event: The Pivotal Point of IT: Building Services for the AI-First Era Date: May 13 at 1p.m. EDT Register: https://go.acronis.com/davesobelaiera