Pricing guide · Updated August 31, 2026

How to Price Managed AI Governance

What to sell, what to charge, and how the margin works. One recommended offer: a free AI risk assessment that opens the door, a one-time onboarding fee, and a recurring per-device service with the quarterly review included. No menu, no ladder, nothing to design.

The figures on this page are ShadowLock's editorial estimates and are offered as resale guidance for your own rate card. ShadowLock does not set or require what partners charge their clients. There is no published benchmark study for most of these deliverables; we built the ranges from observed MSP list pricing for adjacent services plus standard channel markup. Test them against your own cost model before you quote. Not legal advice.

Get the MSP sales kit

This is the pricing companion to the MSP AI governance sales kit. Start there for the full motion, from the opening conversation through to the client's decision. Come here when you need the numbers.

The short version

Three things every MSP should take away

Demand is validated but under-monetized

Kaseya's 2026 State of the MSP Report (1,000+ MSPs) found 48% of clients now rank AI/automation as their #1 need, ahead of security (42%) and backup (36%), yet only 13% of MSPs earn meaningful revenue from it. That gap is the opportunity, and it sits inside your existing base where new-customer acquisition is hardest.

Give the assessment away

The assessment is acquisition, not revenue. It costs you a scan and a thirty-minute meeting, and it produces the one thing that makes the recurring service an easy yes: a list of the AI tools running in the client's own environment. Charging for it slows the motion down to protect the smallest number in the deal.

Sell one service, priced per device

A one-time onboarding plus roughly $3 to $5 per device per month, with the quarterly review included. One SKU you can add to an agreement tomorrow beats a six-option practice you never launch. Regulated verticals support the top of the range because the compliance work is genuine.

The offer

Sell one thing, in three parts

Free assessment, one-time onboarding, recurring per-device service. That is the whole commercial structure. An MSP who has to pick from six service lines before quoting anything never gets to the first quote.

Step one · acquisitionNo charge

Free AI Risk Assessment

The door opener. A read-only scan across the client's machines that inventories installed AI applications, AI browser extensions, AI-site browsing history, browser AI settings, and the AI apps granted OAuth access to Microsoft 365. It needs no admin rights, takes about fifteen minutes per machine, and leaves nothing installed. You present the resulting AI Exposure report whether or not they buy.

  • Costs you a scan and one thirty-minute findings meeting
  • Produces the specific evidence the proposal is built on
  • Delivered regardless of outcome, which is why clients agree to it
  • Charge for it if you prefer; the recommended motion is free
Step two · one-timeOne-time fee

Onboarding and setup

Scoped to the size of the estate. This is the work that turns the assessment findings into a running program, and it is where the written deliverables the client can hold get produced.

  • Write and agree the AI acceptable-use policy
  • Baseline their exposure from the assessment findings
  • Deploy and configure controls across endpoints and browsers
  • Set the policy cascade and per-client overrides in the platform
Step three · recurring~$3–$5 / device / month

Managed AI Governance

The revenue. One recurring line on the agreement, billed per device like any other managed service, with the quarterly AI Risk Review included rather than sold separately.

  • AI usage visibility across every endpoint and browser
  • Policy enforcement on the endpoint, including personal accounts
  • Sensitive-data guardrails on what can be pasted or uploaded
  • Oversight of AI apps, extensions and Microsoft 365 OAuth grants
  • Governance reporting for auditors and insurers
  • Quarterly AI Risk Review, included

At a glance

Example economics at the $4 anchor

Worked at $4 per device per month, the middle of the recommended range, and excluding the one-time onboarding fee. Your own margin is the gap between the client price and your per-device platform cost, which drops as total device count grows across your whole book, so it is not a fixed number we can print. See partner pricing for the cost side.

ScopeClient pays / monthClient pays / yearNote
25 devices$100$1,200Typical small-business client. Onboarding often exceeds year-one recurring.
100 devices$400$4,800The size where the recurring line starts to matter on its own.
250 devices$1,000$12,000Usually bundled into a security tier rather than line-itemed.
10 clients × 100 devices$4,000$48,000Your platform cost drops as total device count grows across the book.

Illustrative arithmetic at one price point, not a quote or a revenue projection.

Where the premium is

Positioning by vertical

Same offer, same structure. What changes is which pressure you lead with and where in the range you price.

Healthcare

HIPAA

Highest urgency. The modernized HIPAA Security Rule shifts to "show me the evidence," and PHI pasted into public AI is a textbook exposure. Business Associates (including MSPs) face more scrutiny. Price at the top of the range.

Finance

GLBA / FTC Safeguards / PCI

Documented risk assessments and data-handling controls are mandatory, and AI governance slots directly into existing Safeguards obligations. Strong willingness to pay for attestation and evidence.

Legal

Confidentiality & privilege

Uncontrolled AI use is an existential risk, and document-heavy workflows mean both high adoption and high exposure. Small firms rarely have internal expertise, so the governance reporting carries most of the value.

Objection handling

The six you will hear, and how to answer them

"We don’t use AI."

Counter with evidence, not argument: run the free scan. Every environment shows ChatGPT, Copilot or Gemini traffic and embedded-AI SaaS. Employees adopt tools faster than policy. PagerDuty’s 2026 survey found 66% of AI-using workers used it despite believing it violated policy. The scan makes denial untenable and moves the conversation to facts.

"It’s just a policy template."

The billable value is enforcement and audit-ready evidence, not boilerplate. A policy without a control is a wall with no gate. You are selling the recurring enforcement plus the reporting, which no template replicates. Say so before you name a price.

"That’s another per-device charge."

Anchor against what it replaces: an incident, a failed insurance warranty, or a compliance finding. At roughly $4 per device per month, a 100-device client is paying $4,800 a year to have a documented answer to the AI questions their auditor and their carrier now ask. Fold it into a security tier rather than line-iteming a novel SKU, which reduces price sensitivity and churn.

"If the assessment is free, is it any good?"

It is free because it is fast and automated, not because it is shallow. The scan reads the same registry, browser and Microsoft 365 sources a paid audit would, and it produces a report naming their tools and accounts. What you charge for is fixing what it finds and keeping it fixed.

"We don’t have the tooling or expertise."

AI governance is an extension of existing security and compliance work, not a new discipline. A multi-tenant platform handles discovery and enforcement across your whole book, and the sales motion is documented end to end in the MSP sales kit. You are not building a practice; you are adding a line.

"Why would clients trust us on AI?"

Run it on your own environment first. Your own AUP, your own staff, your own scan. That gives you a real case study, de-risks the rollout, and means the first client demo is something you have already lived through.

Frequently asked

Pricing AI governance, answered

How should an MSP price managed AI governance?

Price it per device per month on top of a one-time onboarding fee. A workable client-facing range is roughly $3 to $5 per device per month, with $4 a reasonable anchor, and onboarding scoped to the size of the estate. Fold it into a premium security tier rather than line-iteming a novel SKU. These are suggested resale figures for your own rate card; ShadowLock does not set what you charge.

Should an MSP charge for a shadow-AI assessment?

ShadowLock recommends giving it away. The assessment is acquisition, not revenue: it costs a read-only scan and a thirty-minute findings meeting, and it produces the specific evidence that makes the recurring service an easy yes. Charging for it slows the motion down to protect the smallest number in the deal. MSPs who prefer to charge can, but the recommended default is free.

What should an MSP include in a managed AI governance service?

A one-time onboarding covering the AI acceptable-use policy, an exposure baseline and control deployment; then a recurring service covering AI usage visibility, policy enforcement on the endpoint, sensitive-data guardrails, oversight of AI apps and Microsoft 365 OAuth grants, governance reporting, and a quarterly AI Risk Review. One service, not a menu.

Can MSPs make money from AI governance?

Yes, and it is a near-term line rather than a someday play. Kaseya's 2026 State of the MSP Report found 48% of clients rank AI/automation as their top need while only 13% of MSPs earn meaningful revenue from it. At roughly $4 per device per month, ten clients averaging 100 devices is about $48,000 a year in recurring revenue on top of onboarding fees.

Which verticals pay the most for AI governance?

Regulated verticals: healthcare (HIPAA), finance (GLBA and FTC Safeguards), and legal (confidentiality and privilege), because the compliance work is genuine and audit- or insurance-driven. Vertical-focused MSPs generally price 20–40% above generalist peers. Healthcare typically carries the highest urgency, which makes it the natural first vertical to template.

How do I launch this without building a practice?

Run the assessment on your own environment, then on three to five clients from your existing base using the free scan. Present each AI Exposure report, quote the same one-time onboarding plus per-device recurring fee every time, and attach it at the next renewal. The motion is documented step by step in the MSP sales kit; there is no practice to design.

Add one line to the agreement

The sales kit is the motion. ShadowLock is the platform that delivers the assessment and enforces what you sell.