By Andy Syrewicze, Principal MSP Advocate & Security Evangelist, Proofpoint’s MSP Platform. Proofpoint’s MSP Platform won ‘Best SaaS Product for Cybersecurity’ at the 2026 SaaS Awards.

Artificial intelligence has moved from the edge of business strategy to the center of day-to-day operations. Teams use it to write, summarize, search, classify, automate, and support customers. It now touches email, collaboration, software development, analytics, and increasingly the security stack itself.

That shift creates a new kind of challenge for managed service providers. The question is no longer whether customers will use AI, as they already are. The real question is whether they understand where AI is connected to sensitive data, identities, business decisions, and operational workflows.

That is where the risk lives.

Too often, conversations about AI security focus on the model itself. People ask whether the model is accurate, whether the output is useful, or whether it can be trusted. Those are important questions, but they are not the most important ones. The deeper issue is what happens when AI is connected to the business without clear governance.

An AI system does not need to be malicious to create a security problem. It only needs access to the wrong data, the wrong permissions, or the wrong workflow.

The Expanding AI Attack Surface

Every major technology shift expands the attack surface before organizations have time to adapt their controls. AI is no different. In practice, the most serious AI security threats tend to fall into three overlapping categories.

First, there are threats against AI systems themselves. Prompt injection, model manipulation, data poisoning, and unsafe agent behavior can all undermine how AI tools make decisions or interact with other systems.

Second, there are threats that AI enables. Attackers are already using generative AI to produce more convincing phishing emails, localize lures, create deepfake audio and video, and automate reconnaissance at scale. This is already changing the tempo and quality of attacks.

Third, there are adoption risks created by the way organizations deploy AI. Shadow AI, over-permissioned access, weak logging, unclear ownership, and poor data classification can expose sensitive information even when no attacker is present.

That third category is the one many businesses underestimate. In many cases, AI reveals weaknesses that already existed in the organization’s data, identity, or access model. For example, if a user can retrieve information they should never have been able to see, the model is not inventing the problem. It is surfacing it.

AI threat detection

MSPs are in a unique position to close the gap

Managed service providers (MSPs) are now operating in a more strategic role than ever before. Customers still rely on MSPs for uptime, support, and operational consistency, but they also expect guidance on cybersecurity, compliance, recovery, and now AI adoption.

That matters because most organizations do not have the time or internal expertise to govern AI properly on their own. They need someone who can help them make practical decisions about what tools are approved, what data they can access, what safeguards should exist, and what should happen when something goes wrong.

This is where MSPs can create real value. Apart from just managing technology, they are helping customers build a defensible operating model for how technology gets used. In the AI era, that means bringing structure to questions such as:

  • What data can AI touch?
  • Who can approve access?
  • What happens if an AI assistant is connected to email, shared documents, or workflow tools?
  • How do we prevent sensitive information from being shared too broadly?
  • How do we verify the outputs before a system acts on them?

Those are governance questions, but they are also security questions. For MSPs, the ability to answer them clearly can become a differentiator.

Governance has become the new perimeter

In cloud environments, the old perimeter disappeared long ago. AI is making that even more obvious. Security teams now have to protect not just devices and networks, but identities, permissions, documents, conversations, and automated actions. AI can sit on top of all of those layers and accelerate whatever is already there, whether that is discipline or disorder.

That is why governance is becoming the new perimeter. Good governance starts with visibility. Organizations need a complete inventory of where AI is in use, which vendors are involved, what data flows through those tools, and what each tool can actually do. Can it read, write, summarize, retrieve, send, or trigger an action? If the answer is unclear, the risk profile is unclear too.

From there, businesses need classification. Not every AI use case deserves the same level of scrutiny, but not every use case deserves the same level of trust either. Public content is not the same as regulated data. Customer records are not the same as internal summaries. Payment information is not the same as a draft marketing memo.

The stronger the sensitivity of the data, the tighter the controls should be. Least privilege matters here more than ever. AI agents, connectors, service accounts, and integrated applications should only have access to what they truly need. If an agent can access a mailbox, a document store, and a workflow engine, then each of those permissions needs to be justified. Otherwise, the blast radius of a mistake becomes far too large.

AI security also means preparing for human behavior

It is tempting to think of AI risk as a purely technical issue. It is not.

Human behavior still drives many of the failures. Employees may adopt unauthorized AI tools because they are convenient. Teams may paste sensitive information into unapproved systems because they are trying to move quickly. Users may trust outputs that sound polished but are wrong. Finance teams may be pressured by realistic voice impersonation. Help desks may respond to requests that appear urgent and legitimate.

This is why security awareness still matters. In fact, it matters more now. Organizations should not rely on annual training or a single policy document buried in a shared folder. They need short, ongoing, relevant education that helps people understand the new risks around AI-powered phishing, deepfakes, prompt manipulation, and data leakage. Users need to recognize the warning signs and know when to pause.

That includes teaching people how to verify requests, how to report something suspicious, and when to seek human approval before acting on a request that changes money, access, or information.

AI developer community

Resilience still matters when prevention fails

No security strategy is complete if it assumes everything will be blocked at the front door. That is especially true with AI-driven threats, which can move quickly across email, chat, collaboration tools, and workflow systems. Prevention should be layered, but recovery should be ready as well.

If an account is compromised, if ransomware disrupts operations, or if an AI-connected workflow makes a damaging decision, the organization needs a plan to restore data, recover access, and continue operating. Backup and recovery are not separate from cybersecurity. They should be seen as a core part of it.

The same applies to email protection, permissions control, and user validation. A modern security model should combine detection, governance, awareness, and recovery into one coherent approach. That is how organizations reduce both the likelihood and the impact of AI-related and other cyber incidents.

For MSPs, platforms that unify these capabilities can help simplify the operational load. In practice, that may include AI-driven email analysis, recipient validation, policy enforcement, awareness training, permissions oversight, and backup and recovery in one managed framework. The value arises both from having the controls and from being able to run them consistently across tenants without adding unnecessary complexity.

What customers really need from their MSP

When customers ask about AI, they are often asking a broader question: Are we safe to move forward?

They want innovation, but they do not want chaos. They want productivity, but they do not want leakage. They want automation, but they do not want loss of control.

MSPs are uniquely positioned to give them confidence, but only if they lead with governance rather than enthusiasm alone. That means helping customers answer a few practical questions before AI adoption accelerates further:

  • Which AI tools are approved?
  • What data can they access?
  • Who owns the risk?
  • What happens when outputs are wrong?
  • How do we detect misuse?
  • How do we recover when something breaks?

These questions are the foundations of secure AI adoption.

The opportunity ahead

AI is not a reason to slow down, but it is a reason to become more disciplined.

Organizations that treat AI as a governance issue as much as a technology issue will be better prepared for the risks and better positioned to capture the benefits. MSPs that help customers build that discipline will become more valuable, not less.

The opportunity is clear. The future belongs to providers who can combine operational clarity, security judgment, and practical AI controls in a way that customers can actually sustain.

In that sense, the AI conversation is not really about AI at all. It is about trust, accountability, and the ability to move quickly without losing control. That is where MSPs can lead.

About the Author: Andy Syrewicze

Andy is a 20+ year IT Pro specializing in M365, cloud technologies, security, and infrastructure. By day, he's a Security Evangelist for Hornetsecurity, leading technical content. By night, he shares his IT knowledge online or over a cold beer. He holds the Microsoft MVP award in Security.