
Hosted by MSP Radio · EN

The dominant structural shift in the cybersecurity market is the relocation of value from security work to financial consequence management, driven by insurers moving directly into the managed services space. A cyber insurer's analysis of 100,000 policyholders revealed that those under constant security monitoring file 70% fewer claims. This data allows carriers to identify effective controls, leading them to offer bundled security services directly to clients and MSPs, as exemplified by Coalition's offerings for managed service providers. This shift is underscored by the commoditization of specialized security tasks. Capital One released Vulnhunter as open-source, an AI tool that finds exploitable software flaws, a function previously requiring dedicated specialists. Similarly, Deloitte is industrializing vulnerability remediation using AI, and Blackpoint Cyber deploys autonomous agents for rapid threat detection and containment. These developments signify that the "doing" of security is becoming automated and cost-effective, while the ultimate financial responsibility remains with those who bear the risk. Supporting this core shift, breaches are increasingly originating through third-party vendors, impacting numerous downstream organizations without direct attacker interaction. A software provider serving over 2,000 US hospitals experienced a breach that exposed data for thousands of its clients. This highlights how vendor security failures create cascading impacts, reinforcing the insurer's position as the party ultimately on the hook for losses and incentivizing them to directly manage or provide the preventative security. For MSPs and IT service providers, this dynamic presents a clear operational imperative. The "insurability floor"—the baseline security controls required by carriers—is rising and being set by insurers, not vendors or clients. MSPs must integrate these evolving carrier requirements into their standard operating procedures to ensure their clients remain insurable. Failure to do so risks making clients ineligible for coverage, creating liability for the MSP, and potentially leading to being bypassed by insurers who are bundling services directly. The value for MSPs now lies in operationalizing this rising floor consistently for all clients, rather than merely providing a static security stack. 00:00 They're Selling the Protection Now 03:24 Why "Secure" Stopped Being Yours 05:57 The Floor Keeps Rising 08:44 Why Do We Care? Supported by: Guardz ScalePad 💼 All Our SponsorsMSP Radio is supported by our partners: ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 · Rythmz · ScalePad · TimeZest · Transit AISupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The episode reveals a fundamental structural shift in AI deployment: the deliberate decoupling of powerful AI capabilities from accountability and human oversight. This is exemplified by incidents such as a former Mayo Clinic safety lead being fired after flagging a hospital AI tool (Maya) with a significant error rate (up to 67%) and the replacement of nurses by AI for administrative tasks at Montefiore. The trend is further driven by the increasing availability of potent, open-source AI models, like Moonshot's Kimik 3.2, which remove the traditional vendor accountability that was once inherent in software delivery. This detachment is fueled by a desire for speed and cost savings, leading to a critical "governance gap" where AI operates without a robust control layer or "harness." A primary development highlighting this shift is the reported issue with OpenAI's GPT 4.56, which allegedly deleted user files, termed an "honest mistake" by the company. This underscores how AI, even from leading developers, can cause operational damage when unsupervised. The episode points out that historically, software delivery included both vendor liability and human oversight as inherent safeguards. However, the move towards commoditized, freely accessible AI models and open-source releases is intentionally eliminating these checks. Enterprises are also rationalizing this by shifting to local AI models, severing ties with vendors who were previously points of accountability. Supporting this central theme, the episode details how the increasing accessibility of advanced AI models, such as Kimik 3.2, means frontier capabilities are no longer confined to major labs. Furthermore, studies indicate that reliance on AI advice can paradoxically reduce human accuracy and increase overconfidence in incorrect outputs, making human review less effective if not properly structured. This suggests that even human oversight, if not independently rigorous, can be compromised by the very AI it's meant to check. The core value is shifting from the AI model itself to the "harness"—the accountable judgment layer that controls and validates AI actions. For MSPs and IT leaders, this structural shift creates significant operational implications. The erosion of vendor accountability and human oversight means the "harness" is often missing, creating a liability vacuum. Clients may deploy AI without adequate checks, leading to potential errors, data loss, and reputational damage. MSPs are presented with an opportunity to address this by becoming the named, accountable "check" or harness provider. This requires shifting client conversations from AI acquisition to AI accountability, mapping existing unsupervised AI deployments, and offering oversight services as a distinct, valuable offering to mitigate risks for clients and ensure trustworthy AI integration. 00:00 AI Went Free, the Checks Didn't 03:59 Forget the Model — Own the Harness 06:45 You Can't Just Watch It Anymore 10:19 Why Do We Care? Supported by: Pax8 💼 All Our SponsorsMSP Radio is supported by our partners: ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 · Rythmz · ScalePad · TimeZest · Transit AISupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Most MSPs can already tell you which of their clients' Microsoft 365 environments are misconfigured. The harder question is why so few get fixed — and what it takes to turn security visibility into security operations at scale. Dave sits down with Nick Ross, CEO of Cloud Capsule and a three-time Microsoft MVP, to talk about the operational gap MSPs can't close with assessment tools alone, and how his team is trying to close the distance between finding problems and remediating them across dozens of client tenants at once. Nick launched Cloud Capsule's Manage tier in May to move partners beyond assessment into remediation. He argues the biggest challenge in M365 security isn't visibility — it's execution: the knowledge gap around how to architect a policy, plus the manual hours to deploy it one tenant at a time. He walks through how the platform templatizes baselines, enforces desired state configuration so controls can't be quietly tampered with, and gives technicians the context to know whether flipping a control from red to green will flood the help desk with tickets. The conversation also digs into the harder business questions: whether pushing security work down to junior techs lowers the skill floor and introduces risk, how to prioritize 250+ controls without drowning in red, and the economic reality that many MSPs already know clients are misconfigured but can't get them to pay for the fix. Nick's answer leans on newer levers — the AI-readiness conversation, Copilot data governance, and cyber insurance renewals — to reframe security as table stakes rather than a hard sell. Supported by: Guardz 💼 All Our SponsorsMSP Radio is supported by our partners: ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 · Rythmz · ScalePad · TimeZest · Transit AISupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The core structural shift identified is budget reallocation within technology spending, as funds are redirected from legacy software, hardware refreshes, and higher-cost labor toward AI infrastructure, automation, and junior-level hiring. This resource substitution is not additive but redistributive, with spending on AI solutions and related tools coming directly from reductions in traditional IT line items. IBM’s $70 billion market valuation loss and delays in large deals signal that even established vendors are affected by this reallocation, with money leaving areas they once dominated. The primary evidence is IBM’s issuance of its first profit warning since the early 2000s, attributed to missed large contracts and delayed deals, which triggered a 25% drop in share value, equating to $70 billion in market cap loss. According to Dave Sobel citing Semafor, this reduction was not due to an overall decrease in technology budgets but resulted from enterprise customers reallocating funds toward hardware and AI-related infrastructure. Omnia reported a 3.6% decline in global PC shipments during the second quarter, which was also attributed to rising hardware component costs driven by AI buildouts, causing delays and cancellations in endpoint refresh cycles. Supporting developments include Ramp and Revelio Labs research showing that organizations intensively adopting AI increased headcount by 10% and entry-level hiring by 12% over two years, while CompTIA found IT unemployment fell below 3% even as tech firms cut staff. Futurism cited further labor market reshuffling, with older workers in AI-exposed roles exiting the workforce and younger, cheaper hires being amplified by automation. ConnectWise’s rollout of an AI-native platform and KPMG’s survey highlighting the importance of leadership accountability in AI projects reinforce that resource allocation is shifting to tools and personnel accountable for AI operation and outcomes. Operationally, this reallocation puts pricing pressure on providers focused on legacy revenue lines such as per-seat licenses, break-fix, and hardware refresh, as these budget categories are shrinking. Evidence from Service Leadership’s profitability report shows providers who adopted service desk automation earlier are now earning more per wage dollar, compounding their advantage. The practical implication for MSPs and IT service providers is to identify which client budget categories are “filling” and adjust offerings toward data readiness, AI deployment, and managed accountability, rather than defending legacy categories now facing structural decline. Failure to adapt exposes firms to revenue erosion and intensifies competitive risk from providers aligned with relocated client spend. 00:00 Watch the Money Move 04:37 AI Spend Is Funded by Substitution 07:19 Your Revenue Mix Is the Bet 10:24 Why Do We Care? Supported by: Guardz ScalePad 💼 All Our SponsorsMSP Radio is supported by our partners: ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 · Rythmz · ScalePad · TimeZest · Transit AISupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The episode highlights a shift from technology selection to operational risk management in the AI landscape for MSPs. Service providers are being forced to navigate the fast-changing interplay between AI models, the harness software that mediates their deployment, and the financial realities of consumption-based billing. The rapid proliferation of open-source and open-weight AI models, alongside market behaviors from closed vendors and regulatory interventions, is introducing volatility and uncertainty in both cost structures and client offerings. This dynamic creates structural challenges related to margin maintenance, vendor dependency, and responsibility for AI-driven decisions. The discussion cites the release of GLM 5.2, an open-weight model from Z AI, which now rivals expensive closed models on key benchmarks at a fraction of the cost. At the same time, large-scale investments by commercial AI vendors have yet to deliver returns on expectations, with reports indicating businesses that adopted AI are not seeing projected value. Specific attention is given to operational constraints such as compute scarcity, token consumption variability, and export policy restrictions impacting AI availability. The episode notes that these pressures are driving both vendors and MSPs to reconsider the viability of reliance on expensive, closed offerings versus investigating open alternatives. Supportive examples include the proliferation of AI “harnesses” (middleware layers like Perplexity, Claude Code, and Cowork) that sit between service providers and underlying AI models, increasing both choice and complexity. Token billing models are highlighted as a source of unpredictability for MSPs, with vendors like Atera and ConnectWise experimenting with different abstractions to shield or pass through token risk to service providers. The potential for on-premises AI deployments using smaller language models is discussed as a cost-mitigation strategy, though this raises further questions about data privacy, infrastructure burden, and long-term vendor roles. Additionally, uncertainty is flagged around sustainability of leading vendors, with projections that at least one major AI player may exit or be acquired within a year due to financial vulnerability. For MSPs and IT service leaders, these structural and supporting developments translate into increased operational and financial complexity. There is a pressing need to evaluate not just which AI technologies to adopt, but how to architect solutions that can withstand rapid vendor movement, cost swings, and evolving regulatory requirements. Practical safeguards include testing open-source AI models alongside commercial offerings, exercising caution in vendor selection, and closely monitoring evolving consumption billing models. Preparing staff and clients for adaptive, process-oriented approaches—rather than fixed solutions—is positioned as a necessary step to maintain resilience as the AI adoption cycle continues to correct course. Supported by:Pax8CometBackupGuardz 💼 All Our SponsorsMSP Radio is supported by our partners: ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 · Rythmz · ScalePad · TimeZest · Transit AISupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Contemporary technology governance has shifted from rule-based regulation to a landscape defined by administrative leverage and directive-driven decisions. This dynamic is seen in both the cybersecurity and AI sectors, where agencies such as the U.S. Department of Defense and companies including OpenAI and Anthropic navigate obligations and approvals through administrative action rather than statutory change. As a result, MSPs and IT service providers must recognize that the durability of their offerings and client architectures increasingly hinges on how they respond to rapid, unpredictable shifts in the governing environment rather than on fixed compliance deadlines or product release dates. A notable example of this mechanism is the Department of Defense’s suspension of the rollout of Phase Two of the Cybersecurity Maturity Model Certification (CMMC), as reported by Federal News Network. About 80,000 companies had been preparing for new third-party assessment requirements, but these assessments have been paused pending a 60-day review. Despite the pause, the underlying data protection requirements for defense contractors remain in force, demonstrating that while compliance deadlines can disappear overnight, fundamental security obligations persist. Additional cases amplify the trend toward directive-based governance. The U.S. Commerce Department lifted export restrictions on Anthropic’s Fable 5 and Mythos 5 AI models after new safeguards were implemented, following the same pattern previously used to impose those restrictions. Similarly, OpenAI’s GPT 5.6 model was released to the public only after a voluntary government review concluded, illustrating that administrative reviews, not boardroom decisions, can dictate technology availability. Concurrently, other governments such as China are employing similar tactics, with Reuters reporting that Chinese authorities have met with local AI firms to discuss restricting overseas access to advanced models. These parallel moves across geopolitical boundaries indicate a structural reliance on executive discretion rather than legislative clarity. The operational impact for MSPs, IT service providers, and technology leaders is a heightened exposure to contract risk and pricing volatility. Service commitments anchored to deadlines, default settings, or product availability are susceptible to abrupt policy reversals or administrative interventions, translating to sudden revenue shortfalls and reactive client management. The recommended response is to audit current commitments, identify those pegged to mutable triggers rather than enduring obligations, and systematically re-anchor contract language and client communication to core outcomes and standing requirements. This preparation mitigates the risk of unpaid work, scope renegotiation, and unplanned operational disruption when another directive-driven policy shift occurs. 00:00 Three Government Switches in Three Weeks 04:07 Why AI Is Governed by Leverage, Not Law 06:46 CMMC Paused — Your Obligations Didn't 09:27 Why Do We Care? Supported by: Pax8 Guardz 💼 All Our SponsorsMSP Radio is supported by our partners: LogMeIn · Opentext · Transit AI · Guardz · Pax8 · ABC Solutions · Rythmz · ScalePad · CometBackup · TimeZest Supporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The episode highlights a structural shift in cybersecurity risk, moving from a reliance on human skill as both the source of attack and defense to a landscape shaped by autonomous AI agents acting as privileged entities inside client environments. This pivot is illustrated by Sysdig’s discovery of an agentic ransomware attack (“Jade Puffer”) where AI software—not a human operator—managed intrusion end-to-end, adapting in real time without manual intervention. The key structural effect is a drastic reduction in the cost and skill required to mount effective attacks, while simultaneously introducing unmanaged access points in the form of AI agents with human-equivalent credentials. Supporting this shift, Sysdig found that the AI-driven “Jade Puffer” attack executed more than 600 payloads, automatically adjusted after failures, and required minimal human oversight. ZDNet reported Apple’s unusually rapid patch cycle, attributed by the company to the speed of AI-driven exploit development. According to IT Pro, attackers typically remain inside networks for about two and a half weeks before detection, with nearly half of breaches only discovered after data loss. The U.S. cybersecurity agency CISA admitted to lacking an incident response playbook, improvising during a breach. These developments collectively indicate that existing human-centric security models are being outpaced by autonomous threats. Further reinforcing this thesis, The New Stack emphasized a governance gap: most organizations lack standards for assigning identity or scoping access for AI agents, which today operate using human credentials without effective monitoring or control. AvePoint’s research, as cited by Dave Sobel, suggests the number of unseen AI tools inside organizations has nearly tripled, while about half of employees now use AI agents frequently. While agent-based automation expands operational efficiency, the inability to monitor or restrict these agents exposes a widening attack surface and undermines traditional governance. For MSPs and IT service leaders, the operational ramifications include increased accountability for identifying, inventorying, and scoping AI agents as privileged identities within client environments. Continuing to rely on human-centric security and pricing models risks misalignment with actual exposure. The analysis suggests treating AI agent identity management as a distinct, recurring service line—akin to user identity and multifactor authentication—with pricing linked to risk rather than labor hours. Failure to proactively address this governance gap may result in unaccounted incidents and reactive, non-strategic service delivery that affects renewal cycles and liability positions. 00:00 5 Security Alarms Ringing at Once 04:22 Why Hacking No Longer Takes Skill 06:40 Your Agents Became the New Insiders 09:14 Why Do We Care? Supported by: ScalePad 💼 All Our SponsorsMSP Radio is supported by our partners: LogMeIn · Opentext · Transit AI · Guardz · Pax8 · ABC Solutions · Rythmz · ScalePad · CometBackup · TimeZest Supporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The episode highlights a structural weakness in the current cybersecurity product ecosystem, where the process of certification and lab-based product validation often fails to ensure meaningful security. The episode focuses specifically on how regulatory and certification frameworks—such as those linked to device and software security—are largely decoupled from true technical evaluation, enabling both vendors and labs to use certification badges as symbolic rather than substantive assurances of security. According to Adwait Nadkarni, this decoupling allows manufacturers to treat compliance as a liability shield, rather than as a measure of robust risk mitigation. The most consequential finding, as articulated by Adwait Nadkarni, is that many certified security products can deliberately evade both automated and human review processes, with vulnerabilities designed to look secure while quietly exposing risk. The episode references certification structures such as SOC 2 and detailed research into IoT device certification, finding that certification labs often compete on speed and convenience instead of technical rigor. This creates a situation where certified products may still contain basic, decades-old flaws, with operators and MSPs left without practical recourse when technology fails. Other related developments reinforce the risk transfer created by certification mechanisms. Vendors frequently utilize broad liability disclaimers in end-user licensing agreements, explicitly or implicitly excluding themselves from responsibility for product failures—even in scenarios involving harm or downtime. Adwait Nadkarni points to practices where smoke detectors and other security products use ambiguous language about acceptable use and warranty, further reducing vendor accountability. Labs themselves generally disclaim any responsibility for the certified products’ behavior once deployed, emphasizing a system with diffuse or absent accountability. For MSPs and IT leaders, these developments underscore the need to move beyond reliance on certifications and vendor marketing. Operators should critically assess the actual language and protections embedded in contracts, focusing on enforceable liability rather than assuming technical validation from a certification badge. Absent regulatory reform or industry-wide consortia to create and uphold real minimum standards, the practical task for service providers is to minimize exposure to legal and operational risk by scrutinizing the fine print of contracts, seeking clear remedies for technology failures, and tempering trust in vendor assurances that cannot be independently verified. Supported by: GuardzCometBackup 💼 All Our SponsorsMSP Radio is supported by our partners: LogMeIn · Opentext · Transit AI · Guardz · Pax8 · ABC Solutions · Rythmz · ScalePad · CometBackup · TimeZest Supporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

A structural shift is occurring as employees and customers increasingly bypass sanctioned IT systems in favor of faster, unsanctioned "shadow" tools that offer comparable or "good enough" functionality with less friction. This shift is highlighted through evidence from Gartner, SparkToro, Microsoft, and reports from Altran Digital Business, which collectively show sanctioned internal and customer-facing systems losing relevance as users opt for alternative solutions that optimize convenience and efficiency over formal governance. The most consequential development referenced is Microsoft’s move to replace premium OpenAI and Anthropic models in core applications like Excel and Outlook with lower-cost in-house models, as reported by Bloomberg and Channel Insider. Microsoft claims these new models offer similar accuracy with increased efficiency, reflecting a broader market trend toward solutions that meet minimal functional thresholds at drastically reduced costs. This mirrors broader enterprise behavior, where cost and sufficiency now outweigh premium features, driving a reconsideration of value in AI provisioning. Supporting developments include a Gartner survey showing consumers are about three times more likely to use general AI tools like ChatGPT than corporate chatbots, and a report from Altran Digital Business revealing that over half of employees rely on personal devices or unauthorized tools for work, with nearly a third ceasing to report IT problems entirely. Clickstream data shows that more than two-thirds of Google searches end without a click as users accept AI summary answers, bypassing source links altogether. Vendors such as N-Able and Okta are responding with new products aimed at identifying and gating shadow tool usage, but these approaches often add operational friction without actually closing governance gaps, as Kaseya data indicates most SaaS accounts remain unmanaged despite existing controls. For MSPs and IT leaders, the key implication is that additional controls and "lockdown" measures are likely to increase friction without effectively steering users back to sanctioned processes. Current market tools that focus on visibility and gating of shadow IT may exacerbate the problem by making official workflows less attractive. The practical recommendation is to map where users have already abandoned sanctioned paths and focus on improving those official workflows until they are easily usable and competitive with shadow alternatives. The effectiveness of service delivery should be measured not by control metrics, but by whether users actively choose sanctioned systems for their work. 00:00 The quiet walkout 03:49 Even Microsoft picked good-enough 06:22 Why more control backfires 09:00 Why Do We Care? Supported by: Pax8 💼 All Our SponsorsMSP Radio is supported by our partners: Transit AI · Guardz · Pax8 · ABC Solutions · Rythmz · ScalePad · CometBackup · TimeZestSupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

The dominant structural shift examined is the erosion of channel-driven value creation in AI offerings, marked by the rapid commoditization of resold AI technologies and a pivot toward consumption-based pricing models. Microsoft Copilot is cited as the most commonly resold AI product by MSPs, with market data showing that 84% of productized AI services among “AI forward” firms rely on this single vendor. The resulting model accelerates value capture at the vendor level, narrowing room for differentiated service or margin at the partner level. This consolidation pressures MSPs to shift from traditional product resale to enablement and operational integration or risk disintermediation. The primary development highlighted is the widespread lack of substantive AI go-to-market offerings among MSPs. According to analyzed web positioning data, 61% of MSPs do not mention AI offerings on their sites, and among those that do, the majority use vague or unscoped “AI solutions” language without concrete services behind them. Only a small subset offers named, productized AI services. Of these, the overwhelming reliance on Microsoft Copilot underscores a lack of channel-developed solutions and points to a market structure where vendors, rather than partners, capture much of the economic value. Supporting developments reinforce both the risk and inertia present within the channel. Ryan Morris outlines that true differentiation will require MSPs to develop packaged offerings around governance, financial controls, and vertical-specific business outcomes, yet early market activity shows little movement in these directions. The discussion emphasizes the potential for cost overrun through uncontrolled AI consumption, echoing past cycles from telecommunications to cloud. Efforts by large vendors to staff direct AI engineering resources are framed as a threat only to the top enterprise tier, with the bulk of SMB delivery left to service providers—albeit within a model now driven heavily by consumption volume and efficiency calculations. Operational implications for MSPs and IT leaders include increased pricing pressure and possible margin erosion as customers optimize consumption and as vendors streamline direct monetization of AI. There is a growing need for internal and customer-facing governance structures to manage data use, financial exposure, and compliance. Channel partners that limit themselves to product resale risk commoditization, while those able to package and deliver business-integrated AI services may find more durable value. The episode underscores the urgency for MSPs to clarify and productize their AI engagement—not simply as a differentiator, but as a defensive strategy against margin compression and vendor dependency. 💼 All Our SponsorsMSP Radio is supported by our partners: Transit AI · Guardz · Pax8 · ABC Solutions · Rythmz · ScalePad · CometBackup · TimeZestSupporting the IT services community through insights, analysis, and transparency. 🚀 Join Business of Tech PlusGet exclusive access to investigative reports, vendor analysis, leadership briefings, and more.👉 https://businessof.tech/plus 🎧 Subscribe to the Business of TechWant the show on your favorite podcast app or prefer the written versions of each story?📲 https://www.businessof.tech/subscribe 📰 Story Links & SourcesLooking for the links from today’s stories?Every episode script — with full source links — is posted at:🌐 https://www.businessof.tech 🎙 Want to Be a Guest?Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:💬 https://www.podmatch.com/hostdetailpreview/businessoftech 🔗 Follow Business of Tech LinkedIn: https://www.linkedin.com/company/28908079YouTube: https://youtube.com/mspradioBluesky: https://bsky.app/profile/businessof.techInstagram: https://www.instagram.com/mspradioTikTok: https://www.tiktok.com/@businessoftechFacebook: https://www.facebook.com/mspradionews Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.