Sentinel Vault
← All field notes
· April 28, 2026

When Your MSP Becomes the Weak Link: Shadow AI Threats in Managed Services

When Your MSP Becomes the Weak Link: Shadow AI Threats in Managed Services

When Your MSP Becomes the Weak Link: Shadow AI Threats in Managed Services

When Your MSP Becomes the Weak Link: Shadow AI Threats in Managed Services

At 11:47 on a Tuesday night, the controller at a 60-person manufacturing shop in Riverside watches a ransomware notification scroll across his ERP system. He calls his MSP. The on-call tech, three time zones away, picks up on the second ring and starts working the ticket.

To save time, he opens ChatGPT. He pastes the customer's network diagram, the affected server's hostname, the names of the production databases, and three lines of error log. The model returns a debug path. Crisis handled by 1 a.m.

Nobody at the shop knew that some of their internal infrastructure now lives in OpenAI's training queue. Nobody at the MSP filed a disclosure. Nobody on either side has a contract clause that addresses what just happened.


The Blind Spot You Didn't Buy

You signed an MSP contract because running IT yourself was a risk. The contract probably covers SLAs, response times, ticket categories, escalation paths, password handling, and breach notification. It almost certainly does not cover what your MSP's techs paste into a public AI tool during the course of supporting your account.

That gap is now a serious exposure category. Public-LLM data submission is the fastest-growing source of accidental data exfiltration in 2025 and 2026, and your MSP has more sensitive data on you than most of your employees do.


What Your MSP Has That You Don't Track

When you outsource IT, you give the vendor a level of access that almost no internal employee outside your CFO and CIO can match:

  • Admin credentials to your domain
  • A complete map of your internal network
  • Direct access to your customer database, since in most SMBs the MSP is also running the backup
  • Visibility into PII fields your front-of-house staff never see
  • Contract terms, vendor lists, and payroll if they manage M365 or Google Workspace
  • Your security tooling configurations, including the gaps

A single tech, on a single ticket, has paste-access to most of that. He doesn't have to be malicious. He has to be in a hurry.


What Actually Gets Pasted

Three workflows where MSP techs reach for a public AI tool, every day:

  • Debugging a script. The tech has 200 lines of PowerShell that crashes on production. Faster to paste it into ChatGPT than read the stack trace. The script contains hardcoded server names, user names, and sometimes credentials.
  • Rewriting a customer-facing email. Internal email is hard to write at midnight. The tech pastes the original ticket thread, the customer's name, the issue summary, and asks for a clean version. That thread had your internal escalation phone tree in it.
  • Solving a vendor error message. The error has a unique code that isn't in the documentation. The tech pastes the entire trace, including object names and a snippet of the data that triggered it. Your customer record schema is now sitting on a server in Mountain View.

None of these techs woke up planning to leak your data. All three did.


The Compliance Reality

If you're in healthcare, HIPAA already makes you responsible for what your business associate does with PHI, including pasting it into a public model that retains submissions for training. If you process card data, PCI-DSS treats the AI submission as an unauthorized destination. SOC 2 Type II audits in 2025 began flagging vendor AI usage as a control gap. Cyber insurance carriers are starting to ask about it on renewal.

The legal posture is clear. Your MSP's slip is your incident. And accountability runs upward to the leadership team that signed the contract.


A Five-Step Checklist Before Your Next MSP Renewal

You don't need to audit every prompt your vendor types. You need contractual scaffolding and a few technical guardrails. None of this costs more than $100 a month.

  • Add an AI-use clause to the MSP contract. The language is short. "Vendor will not submit Customer data to public AI services without written consent. Vendor will maintain a log of approved AI tools and their data-handling certifications." That's it.
  • Require a vendor questionnaire annually. Three questions: which AI tools do your techs use, which tier (free, paid, business), what is your data-retention setting?
  • Reduce what the MSP can see. Most MSP techs don't need standing access to customer databases. Use just-in-time access tools so admin credentials check out only when a ticket is open.
  • Turn on outbound DLP at the network layer. Modern SMB firewalls from Sophos, Fortinet, and Palo Alto can flag outbound traffic to known public-AI endpoints. The list is short and it doesn't change often.
  • Build a tear-out. Your MSP relationship is a marriage. Your data is not. Make sure your offboarding clause forces the vendor to confirm in writing, within 30 days of termination, that no customer data remains in any AI tool of theirs.

Why This Matters Now

Through 2025, "shadow AI" was a story about employees pasting sales pipelines into ChatGPT. That risk is real and it's well-covered. The risk that hasn't been covered is the same behavior, one degree out, by the vendor you pay to run your stack.

Your MSP is a force multiplier for everything good and bad about your operation. They scale your IT. They scale your blast radius. The first mass MSP-to-AI data leak is going to happen before mid-2026, and it is going to be a small business that finds out from a security researcher rather than from their vendor.


The Point

You have a relationship of deep trust with people you've never met, who have full access to data your insurance carrier expects you to protect. They are pasting some of that data into a free tool because their workflow demands it. None of your existing controls catch it. None of your existing contracts forbid it.

The five-minute Sentinel Vault Cyber Checkup looks at vendor AI exposure as one of its modules. If you outsource IT and you don't know whether your MSP has an AI-use policy, that is the fastest way to find out where you stand.

The phishing email lands in your employee's inbox. The shadow AI leak lands in your vendor's browser tab. Both end up on your balance sheet.

About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end — the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.