Back to Blog

Is Your IT Provider Ready for AI? 6 Questions to Ask Them This Quarter

For twenty years, the checklist for judging an IT provider barely changed. Response times, security posture, backup testing, how the phone gets answered at 2am. All of that still matters. But over the past two years, AI has quietly added a new column to the scorecard, and a lot of businesses haven't updated their expectations to match.

Here's why it's worth doing now rather than later. Your employees are already using AI, whether anyone approved it or not; research from 2026 puts unapproved AI use at 98% of organizations. New tools are billing by usage instead of by license, which is a cost model most businesses have never managed. And the gap between companies using AI well and companies fumbling it is starting to show up in real productivity numbers. Every one of those is an IT problem in the sense that matters: someone needs to own it, and for most small businesses, the natural owner is the IT provider.

So the fair question isn't whether your provider is good. It's whether they've retooled for the part of the job that didn't exist when you hired them. These six questions will tell you, and to be clear about the spirit of this: plenty of capable providers are mid-transition on AI right now. The point isn't to play gotcha. It's to find out whether yours is moving.

1. "What should our AI policy be?"

This is the softest opener and the most revealing one. A provider who's been thinking about AI will have an answer within a beat, and it will sound something like: publish an approved tool list, get business data onto business accounts, set spending controls on anything usage-billed, and skip the outright bans because they just push usage underground.

What you're listening for is whether they have a point of view at all. "We can look into that" is an acceptable answer from a provider about an obscure line-of-business app. About the biggest workplace technology shift in a decade, it means the thinking hasn't started. And the policy vacuum has real consequences: only 18% of organizations currently have a formal AI security policy, while employees at nearly all of them are already using the tools. We covered what happens in that gap in our post on employees adopting AI ahead of the business.

98% of organizations have employees using AI tools IT never approved
18% have a formal AI security policy in place
89% drop in unauthorized AI use when an approved tool is provided

2. "Where does our data go when employees use AI tools?"

Every prompt an employee types into an AI tool is company data leaving your environment. On personal accounts, there's no contract governing where it's stored, how long it's kept, or whether it trains someone's model. On business-tier accounts, there is. Moving people from one to the other is a straightforward, well-understood job, for a provider who's done it.

A ready provider can answer this concretely for the tools your team actually uses, and can tell you which of your current AI use they can even see. If the answer amounts to "we block what we can," ask the follow-up: blocked tools with no approved alternative don't reduce AI use, they hide it. The 89% number in the box above is the reason substitution beats prohibition, and a provider working with current information will know it.

3. "Can you set up and monitor spending controls on usage-billed AI?"

This one separates providers who read about AI from providers who operate it. Tools like Microsoft's Copilot Cowork bill by consumption, with no ceiling unless someone configures one. The caps, alerts, and per-user limits all exist, and all of them are opt-in. Somebody has to know they're there, set them before rollout, and check the reports monthly.

That's not exotic work. It's exactly the kind of unglamorous, recurring operational task MSPs were built for. Which is why it's telling if your provider can't describe how they'd do it. If they can walk you through where the controls live and what sensible starting limits look like, they've done this. If the response is a pause, they haven't, and you'd be the practice client.

4. "What AI do you use in your own shop?"

Fair is fair: if a provider recommends AI adoption to clients, their own operation should show evidence of it. Ask how they use AI in their helpdesk, their documentation, their monitoring. The specifics matter less than whether specifics exist.

A provider who's put AI to work internally will have opinions formed by experience, including things they tried that didn't work, which is arguably the most valuable knowledge they can bring you. A provider whose own shop runs exactly like it did in 2023 is going to be learning on your time and your invoice.

5. "If our team builds something with AI, how would you review it before it touches real data?"

Sooner or later, someone on your team will use AI to build an app, an automation, or a workflow that works impressively well, and that touches customer data. This is happening in businesses of every size, usually without anyone deciding it should. Research from 2026 found security flaws in roughly 38% of AI-generated code, so "just let it run" isn't a plan, but neither is "absolutely not," because that response drives the next build underground.

The answer you want has a middle: a lightweight review process, a clear line about what needs checking before production, and enthusiasm for the fact that your team is building things at all. A provider who treats employee-built AI purely as a threat will alienate exactly the people creating the most value with it.

6. "What's your AI recommendation for us, specifically?"

The final question is the sum of the others. Not "is AI important," which every provider will affirm, but: given our business, our team, and our budget, what should we do in the next six months? A ready provider can sketch a real answer: which roles would benefit first, what it would cost, what controls go in before anything launches, and what they'd measure to decide whether it's working.

That kind of answer is what separates a provider who manages AI from one who merely permits it. It's also, not coincidentally, the entire job description of the managed AI services we described in an earlier post: tool selection, data protection, spend control, and someone accountable for the whole layer.

Scoring It Honestly

If your provider handled four or more of these with specifics, you're in good hands, and you should tell them so, because providers who've retooled for AI are still the minority. If they were candid about being mid-transition, telling you "here's what we have today, here's what we're building," that's a fine answer too. Honesty about the gap beats a confident bluff.

Where you should pay attention is a pattern of shrugs. Not because your provider is bad at what they do, but because the job has grown, and a provider who hasn't noticed the growth will keep delivering 2023's service into 2027. The businesses that get AI right over the next few years will mostly be the ones whose IT partner treats it as part of the job rather than an add-on conversation. You deserve to know which kind you have, and one meeting's worth of questions will tell you.

Common Questions About IT Providers and AI

How do I know if my IT provider is ready for AI?

Ask them six things: what your AI policy should be, where your data goes when employees use AI tools, whether they can set up and monitor spending controls on usage-billed AI, what AI they use in their own shop, how they would review anything your team builds with AI, and what they recommend for your business specifically. Specific, confident answers to four or more is a good sign.

Should my IT provider manage our AI tools?

For most small businesses, yes. Someone has to own the AI layer, including approved tools, data protection, and spend controls, and the natural owner is the IT provider you already trust with your network and security. That ongoing management is exactly what managed AI services cover.

What should I do if my IT provider isn't ready for AI?

Candor about being mid-transition is a fine answer; a pattern of shrugs is the warning sign. If the job has grown and your provider hasn't noticed, it is worth getting a second opinion on where your business stands on AI and what to do first, before the gap starts costing you.

Didn't love the answers you got?

CNI would be glad to give you ours: a straight assessment of where your business stands on AI, what we'd do first, and what it would cost. No pitch, no pressure.

Talk to CNI  

Sources: Second Talent, 2026 (98% of organizations with unapproved AI use); Red Team Partner, 2026, citing the Salesforce 2026 Workforce AI Survey (18% with a formal AI security policy); Healthcare Brew survey, 2026 (89% reduction in unauthorized use when an approved tool is provided); Arnica, 2026 (security flaws in ~38% of AI-generated code samples); Microsoft 365 Blog: Copilot Cowork general availability (usage-based billing and cost controls).