The MSP AI Governance Brief: Issue 03
Every two weeks, we filter AI governance news down to what actually matters for MSPs: the laws, insurance changes, incidents, and platform shifts that change client risk — and the service line each one creates.
This is Issue 03.
The theme this cycle is evidence.
A cyber carrier is measuring AI governance from telemetry instead of an annual questionnaire. IBM put numbers behind the cost of unmanaged AI. A federal court allowed wiretap claims against an AI notetaker to proceed.
The common thread: saying a control exists is becoming less important than being able to prove it.
For MSPs, that is a meaningful shift.
A cyber carrier is now scoring AI governance from telemetry, not a form
Cowbell has documented three AI-specific factors inside its Cowbell Factors rating model:
- AI Exposure: whether an organization can identify the AI models and applications in use, understand their reach, and assess what decisions they influence.
- AI Vulnerability: risks including hallucination, bias, prompt injection, data leakage, IP exposure, adversarial robustness, and upstream dependencies.
- AI Assurance: documentation, testing, lifecycle management, access controls, policy enforcement, auditability, and alignment with frameworks including NIST and ISO/IEC 42001.
The important part is how Cowbell gets the data.
Its AI Connectors collect telemetry rather than relying entirely on answers entered into an application once a year. As Cowbell co-founder and chief product officer Rajeev Gupta put it: “Watching what the AI did produces evidence.”
That changes the cyber-insurance conversation.
AI governance is moving from an annual yes-or-no question toward a posture that can be observed between renewals. If a client claims to have controls that the carrier’s own telemetry contradicts, the evidence becomes more important than the checkbox.
And much of that evidence comes from systems the MSP manages.
The move: package AI discovery and governance evidence around the same categories carriers are beginning to measure.
Start with an inventory: what AI exists, who uses it, what data it reaches, and what controls surround it. Map the resulting evidence to a recognized framework such as the NIST AI Risk Management Framework or ISO/IEC 42001.
Then make discovery continuous. A clean assessment today does not prove the same environment exists six months from now.
That turns AI readiness from a one-time consulting project into an ongoing managed service.
Shadow AI showed up in 43% of breached organizations studied by IBM
IBM released its 2026 Cost of a Data Breach Report on July 29.
The research covered 602 organizations across 16 countries and 17 industries, based on breaches occurring between March 2025 and February 2026.
Among the findings:
- 43% of breached organizations had security incidents involving shadow AI, up from 20% the prior year.
- 68% had no AI governance policy in place.
- Among organizations suffering an AI-related breach, 92% lacked proper AI access controls.
- Across the full breached population, only 40% applied access controls to AI models and data.
The dollar figures are large — IBM reports an average $5.39 million cost for breaches involving shadow AI — but MSPs should use that number carefully.
The sample is enterprise-weighted. IBM does not publish a small-business cut, so $5.39 million should not be presented as the expected loss for a 40-seat client.
The governance findings are more useful.
The recurring pattern is not simply “employees used AI.” It is that organizations did not know what was being used, had no governing policy, and lacked controls over what AI could access.
Those are all manageable problems.
The move: use discovery to create the remediation project.
Find the unauthorized tools, OAuth grants, browser extensions, desktop applications, and AI services employees are actually using. Then show the client which access controls, policy changes, and enforcement measures are missing.
The assessment finds the exposure.
The remediation is what you bill to fix.
The monitoring is what keeps it fixed.
AI notetakers are now a litigated exposure
On August 13, 2026, Judge Eumi K. Lee granted in part and denied in part Otter.ai’s motion to dismiss in In re Otter.AI Privacy Litigation.
Several claims survived, including claims under the federal Wiretap Act, California’s Invasion of Privacy Act, and Illinois biometric privacy law.
That does not mean the court found Otter.ai liable. The allegations remain unproven.
But it does mean AI meeting transcription has moved from theoretical privacy concern to active litigation.
A second case pushes the issue further.
Chamberlain v. Granola, Inc., filed July 30, targets a different type of notetaker: one that captures system audio and microphone input locally instead of joining the meeting as a visible participant.
That distinction matters operationally.
There may be no bot in the participant list for an administrator to see or remove.
The complaint includes claims under the federal Wiretap Act and California privacy statutes and seeks statutory damages under CIPA of the greater of $5,000 per violation or treble damages. Those allegations are also unproven.
The vendor itself can create another layer of exposure.
On August 4, a security researcher disclosed an issue affecting meeting-notetaker tl;dv that exposed conference metadata across accounts. tl;dv acknowledged a vulnerability involving access to specific conference metadata and said corrective measures were taken.
For MSPs, these incidents point to three separate controls:
- Can you identify which meeting-recording and transcription tools employees are using?
- Has the client decided which tools are sanctioned and under what consent policy?
- Has anyone evaluated what the vendor stores, where it stores it, and how long it keeps it?
A salesperson, recruiter, attorney, accountant, or executive assistant can install one of these tools without involving IT.
That makes the problem part software inventory, part privacy governance, and part vendor risk.
The move: offer a meeting-recording and AI notetaker governance review.
The deliverable can include:
- Endpoint discovery for installed transcription applications
- Browser-extension discovery
- Microsoft 365 and Google Workspace OAuth review
- A list of sanctioned and prohibited tools
- Recording and consent procedures
- Calendar-invite and verbal notice language
- Data-retention requirements
- Model-training settings
- DPA or BAA review for regulated clients
- Ongoing discovery for newly introduced tools
Give employees one approved way to solve the problem rather than relying solely on prohibition.
Then monitor for everything else.
Not legal advice. Confirm applicability with counsel.
Colorado’s AI rules have no small-business floor
On August 11, 2026, the Colorado Department of Law filed proposed rules implementing SB 26-189, the Automated Decision-Making Technology Act, and HB 26-1263, the Chatbot Safety Act.
Both laws take effect January 1, 2027.
The rulemaking hearing is scheduled for October 26, 2026.
For MSPs serving SMBs, one detail matters immediately: SB 26-189 does not contain an employee-count or revenue threshold for deployers.
The statute defines a deployer as a person doing business in Colorado that deploys a covered automated decision-making technology.
That means “we’re too small for AI regulation” is not a safe assumption.
Applicability instead turns on whether the business uses covered automated decision-making technology in consequential decisions involving Colorado consumers, including areas such as employment, housing, lending, and healthcare.
The proposed rules also introduce operational requirements around human review.
A request for review must be acknowledged within 10 days and completed within 45 days, and the reviewer must provide reasons specific to the evidence presented rather than simply restating the system’s logic.
This is not primarily about the firewall or endpoint-security stack.
The exposure is more likely to be hiding inside applicant tracking, tenant screening, lending, HR, insurance, or patient-management software.
That means many clients may already be using covered technology without calling it “AI.”
The move: sell an ADMT inventory before selling compliance.
Identify every system influencing consequential decisions. Record what it does, who owns it, which people it affects, what vendor provides it, and where human review enters the process.
For clients in scope, the resulting project can include:
- Point-of-interaction notices
- Adverse-outcome notification templates
- A named human-review process
- Ticketing workflows for the 10-day and 45-day deadlines
- Required record retention
- Vendor documentation
- Governance ownership
Put October 26, 2026 and January 1, 2027 on the QBR calendar for affected clients now.
Not legal advice. Confirm applicability with counsel.
Agentic AI is now part of the Microsoft 365 governance surface
Microsoft published CVE-2026-59118 on August 6 against Copilot Cowork, the agentic layer that reached general availability in June.
The vulnerability carried a CVSS 3.1 score of 9.3.
Microsoft said the issue had already been fully mitigated, was not publicly disclosed or known to be exploited, and required no customer action.
So this is not a patch-management story.
It is a governance story.
Cowork is enabled administratively. Microsoft says admins decide when to enable it and who receives access.
That means an autonomous AI capability can appear inside a tenant because someone changed a configuration setting — not because an MSP deployed a new application.
The same problem extends beyond Cowork.
Agents can operate through Copilot Studio, OAuth grants, service accounts, and other credentials that let software act across Microsoft 365 data.
Traditional inventory asks:
What software is installed?
Agent governance increasingly asks:
What software is allowed to act?
That is a different question.
It also matters to cyber insurance.
Recent industry commentary has raised an unresolved coverage question: what happens when an AI agent performs damaging actions using credentials it was legitimately given?
That is not settled policy or case law. Coverage depends on the actual policy language.
But it makes execution evidence more valuable.
The move: add agent enablement to the Microsoft 365 tenant review.
For each tenant:
- Is Cowork enabled?
- Who has access?
- What data is available to it?
- Which agents or Copilot Studio flows exist?
- What OAuth grants or service accounts support them?
- Are spending limits and usage alerts configured?
- Is agent-level activity being logged and retained?
- Who approved the enablement decision?
At renewal, ask the client’s broker one additional question in writing:
Does an AI agent acting through valid credentials meet this policy’s definition of unauthorized access or a covered cyber event?
Do not predict the answer.
Keep the answer.
That written record is part of the governance evidence.
The trackers behind this issue
We keep three running resources updated so MSPs do not have to reconstruct this landscape from scratch:
- AI Regulation Tracker for MSPs — filterable by state and sector
- Cyber Insurance and AI Tracker
- Shadow AI Incidents — a sourced running incident list
All three were refreshed on August 17, 2026.
The filter for this Brief is intentionally narrow.
An item needs to materially change how AI creates risk, and it needs to matter to MSPs serving small and mid-sized organizations.
If AI is incidental to the story, or the development has no realistic downstream impact on your clients, it stays out.
Frequently Asked Questions
What is the MSP AI Governance Brief?
The MSP AI Governance Brief is a recurring roundup of AI laws, cyber-insurance changes, security incidents, and platform developments that create new risk — or new service opportunities — for MSPs and their clients.
Every item is translated into three questions:
What happened? What changes for the client? What can the MSP actually do about it?
Enterprise-only AI news is deliberately left out.
Are AI meeting notetakers illegal?
Not categorically.
The issue is consent, privacy, data handling, and the laws applicable to the participants in the conversation.
Federal litigation is now testing how wiretap and biometric privacy statutes apply to AI notetakers, but the cases discussed above remain at an early stage and the allegations are unproven.
For clients, the practical response is to sanction specific tools, establish recording and consent procedures, define retention requirements, and monitor for unauthorized alternatives.
Confirm legal applicability with counsel.
Does Colorado’s AI law apply to small businesses?
The statute does not contain an employee-count or revenue threshold for deployers.
Whether a business falls within scope instead depends on whether it deploys covered automated decision-making technology affecting Colorado consumers in consequential decisions.
That can include employees and job applicants.
Confirm applicability with counsel.
Is this legal or insurance advice?
No.
The Brief and the trackers behind it are plain-English resources designed to help MSPs identify emerging AI governance issues, understand where they may affect clients, and recognize the operational work those issues create.
Confirm legal applicability with qualified counsel and coverage questions with the client’s insurance broker.
Not legal advice. Confirm applicability with counsel before acting on anything above.
Stop shadow AI before it becomes a liability
ShadowLock detects and blocks unauthorized AI tool usage across every endpoint. Free 14-day trial.
Start Free Trial →