Built for MSPs · Free
Sell AI Governance to Your Clients
The MSP AI Governance Sales System. Five steps that turn shadow AI risk into a recurring line on the agreement.
Read-only, runs through your RMM, no agent rollout. The kit is free either way.
The system
How can MSPs sell AI governance?
In five steps, using a free assessment you run through your own RMM to do the convincing.
Start the conversation
Lead with the pressure the client already feels, not with the phrase "AI governance".
Prove the exposure
Run a read-only assessment through your RMM. No agent rollout.
Sell the fix
One service on your rate card, not a practice you have to design first.
Put the rules in writing
A written policy is the thing the client can hold, and the thing auditors ask for.
Get a decision
Yes or not yet. What it never ends with is "okay, let us know".
01 / 05
Start the conversation
Need a reason to bring it up? Pick one.
Lead with the pressure they already feel, not with the software.
Subject: Quick AI exposure check
We're starting to look at AI exposure across our client base. We can run a free, read-only assessment that shows which AI tools are actually being used in your environment and whether there are any obvious risks. Nothing gets installed, nobody there has to do anything, and we run it from our end. Want me to send the assessment over?
02 / 05
Prove the exposure
Don't argue about whether shadow AI exists. Show them theirs.
Run it through the RMM you already have. No agent rollout, and nobody at the client has to do anything.
- 1Create the assessment
- 2Run it through your RMM
- 3Present the report
Shadow AI Audit Report
AI Exposure Assessment
Executive summary
Acme Manufacturing shows significant shadow AI exposure. Our scan found 17 distinct AI tools across 8 endpoints, and built-in browser AI features (Chrome Gemini / Edge Copilot) are unrestricted by enterprise policy. The combination of unmanaged AI tools and unrestricted browser AI creates a path for sensitive business data to be shared with unvetted AI services.
Endpoints assessed
8 / ~10
Reported in this collection window
AI desktop apps
11
Across all assessed endpoints
Browser extensions
9
AI extensions installed
AI sites visited
14
Distinct domains in history
Top AI tools detected
Desktop AI applications installed on scanned devices
- ChatGPT Desktop36%
- Claude27%
- Cursor18%
- Ollama10%
- Copilot9%
AI sites visited
Domains with the most browser visits this scan
| Domain | Visits | Last |
|---|---|---|
| chatgpt.com | 486 | Aug 28 |
| claude.ai | 213 | Aug 28 |
| gemini.google.com | 97 | Aug 27 |
| perplexity.ai | 64 | Aug 26 |
Installed AI applications
| Device | Application | Version | Publisher |
|---|---|---|---|
| FIN-LT04 | ChatGPT Desktop | 1.2026.4 | OpenAI |
| ENG-WS02 | Cursor | 0.49.1 | Anysphere Inc. |
| OPS-LT11 | Claude | 1.4.2 | Anthropic |
| ENG-WS02 | Ollama | 0.6.2 | Ollama Inc. |
Chrome Gemini & Edge Copilot policy state
| Device | Browser | State |
|---|---|---|
| FIN-LT04 | Chrome | Allowed (no policy) |
| OPS-LT11 | Edge | Partially blocked |
| ENG-WS02 | Chrome | Allowed (no policy) |
What the assessment observed
AI apps, browser extensions, AI browsing, developer tools and browser AI policy, per endpoint.
What that implies
A path for company data to reach unvetted services. Exposure, not a proven leak.
What ShadowLock sees once deployed
What was pasted or uploaded, which sign-ins were personal, which AI apps hold M365 grants.
The assessment is the door opener.
The managed service is the revenue.
- The assessment
- Free, read-only, through your RMM.
- Managed AI Governance
- Monitoring, enforcement, reporting, management.
03 / 05
Sell the fix
Sell one thing: Managed AI Governance
One SKU you could add to your catalog tomorrow, answering what the assessment just showed them.
Recommended service
Managed AI Governance
$3–$5
per device / month, suggested resale
Initial rollout
One-time onboarding fee
- AI exposure baseline from the assessment findings
- A written AI acceptable-use policy, agreed with the client
- Policy configuration for their tools, data types and exceptions
- Silent deployment of the agent and managed browser extension via your RMM
Ongoing
Recurring, billed per device
- AI usage monitoring across every endpoint and browser
- Sensitive-data controls on what can be pasted or uploaded into AI tools
- Oversight of AI websites, desktop apps and browser extensions
- Microsoft 365 AI OAuth visibility and control on the client tenant
- Client-ready governance reporting under your logo
- A quarterly AI Risk Review, included
What one client is worth
250 devices × $4 per device / month
$1,000
MRR
$12,000
ARR from one client
10 similar clients = $120,000 ARR
Before onboarding fees, and before your platform cost is deducted.
How should an MSP price managed AI governance?
Roughly $3 to $5 per device per month on top of a one-time onboarding fee, with $4 a reasonable anchor.
Suggested resale for your own rate card. ShadowLock does not set or require what you charge your clients. See partner pricing and the pricing playbook.
We'll show you how AI is actually being used, put guardrails around your sensitive data, enforce your AI policy on every endpoint, and review it with you each quarter.
04 / 05
Put the rules in writing
Turn recommendations into actual company policy.
A policy without enforcement is just paperwork. Customize the free template, have them adopt it, then make every line of it real.
AI Acceptable Use Policy
4. Approved AI Tools
Only the tools listed in this section may be used with company data. Requests for additional tools go through the exception process in section 10.
5. Prohibited Data
Customer records, credentials, contracts, source code and regulated data must never be entered into an AI tool.
7. Personal Accounts
Company work must be done in company AI accounts. Personal accounts are out of scope of our controls and our agreements.
8. Monitoring
AI use on company devices is monitored, and prohibited data is blocked before submission.
Policy says it. ShadowLock enforces it.
Only approved AI tools may be used for company work.
Allow, warn or block per AI website and per desktop AI app.
Never paste customer records, credentials or contracts into an AI tool.
Classify the content of a paste and block it before it is submitted.
Company files may not be uploaded to AI services.
Intercept file uploads to AI sites and apply the file-upload policy.
Use company accounts, not personal ones.
Detect personal-account sign-ins to AI tools and flag or block them.
AI apps may not be connected to company email and files.
Inventory Microsoft 365 OAuth grants to AI apps and control which are allowed.
Violations are recorded and reviewed.
Every allow, warn and block is an event you can report on and export.
Enforcement sits on the endpoint and in the browser, so it holds on personal accounts. How the controls work.
05 / 05
Get a decision
Every assessment ends with a decision.
They fix the risk or they accept it on the record. Never "okay, let us know."
YES
Implement Managed AI Governance
Under thirty minutes of platform work to onboard.
- Day oneEnable Continuous Governance on the assessment and it becomes the client organization.
- Week onePolicy agreed, controls configured, agent and browser extension pushed through your RMM.
- Every quarterAn AI Risk Review, in the same report format they already recognise.
NOT YET
Document the accepted risk
A dated, signed record of a business decision. Not a waiver, and it does not remove your obligations.
AI Risk Acceptance Form
ClientAcme Manufacturing
Identified exposure11 unmanaged AI apps across 8 devices
Recommended controlManaged AI Governance
DecisionRisk accepted
Accepted by
Date
Review date
The assets
The AI Risk Assessment Kit
Two you present under your own brand, two for your team. Free either way.
Co-brandable education deck
PPTXClient-facing. The pre-assessment briefing on where AI data leaks. Your logo, your name.
Assessment runbook
PDFFor your team. The motion end to end, from opening hook to signed agreement.
Client leave-behind
PDFClient-facing. A plain-English primer to hand over with the report. Your document, not ours.
MSP close kit
PDFFor your team. Framing, proposal language, and the six objections you will actually hear.
Get all four assets
Tell us where to send updates and we'll unlock the downloads.
Everything the system uses
- Step 1Shadow AI Risk Calculator
- Step 1AI Regulation Tracker
- Step 1Cyber Insurance & AI Tracker
- Step 1Shadow AI Incident Library
- Step 1State of Shadow AI 2026
- Step 2AI Risk Assessment Kit
- Step 2ShadowLock for MSPs
- Step 3Pricing Managed AI Governance
- Step 3ShadowLock partner pricing
- Step 4AI Acceptable Use Policy template
- Step 4How the policy is enforced
- Step 5AI Risk Acceptance Form
Answers
Questions MSPs ask before the first assessment
How can an MSP start an AI governance conversation?
Lead with the pressure the client is already under rather than with AI governance as a topic. If they think in dollars, run the shadow AI risk calculator on their headcount. If an audit or a new state law applies to them, send that specific regulation. If a cyber-insurance renewal is close, show them the AI questions carriers now ask. If they believe AI risk is hypothetical, send one sourced incident from their industry.
How can MSPs sell AI governance?
In five steps. Start the conversation with the pressure the client already feels: cost, regulation, a cyber-insurance renewal, or a real incident in their industry. Prove their exposure with a free read-only AI risk assessment run through your own RMM, with no agent deployment. Sell one recurring Managed AI Governance service rather than a menu. Put the rules in a written AI acceptable-use policy backed by enforcement on the endpoint and in the browser. Then get a decision: clients who say yes move to onboarding, and clients who say not yet sign a risk acceptance form that records the decision and a review date.
What is an AI risk assessment for an MSP client?
An AI risk assessment inventories the AI tools actually in use across a client's endpoints: installed AI applications, AI browser extensions in Chrome, Edge, Brave and Firefox, AI-site browsing history, AI developer tools and MCP server configurations, and whether the browsers' built-in AI is restricted by enterprise policy. ShadowLock's runs read-only through the MSP's existing RMM, with no agent deployment and no involvement from the client's staff, and leaves nothing installed. It produces a risk-tiered AI Exposure report the MSP presents to the client.
Do I have to deploy the ShadowLock agent to run an assessment?
No. That is the point of it. The assessment runs through the RMM you already use, across the client’s Windows endpoints, without deploying the ShadowLock agent and without involving anybody at the client. The agent comes later, as part of Managed AI Governance, once the client has seen the findings and decided to buy. Find the problem before you ask them to buy the solution.
How do MSPs prove shadow AI risk?
By assessing, not arguing. A lightweight read-only assessment, pushed through the MSP’s own RMM, inventories the AI applications, browser extensions and AI browsing already present across the client’s Windows endpoints, and the results come back as a risk-tiered AI Exposure report naming the client’s own tools and endpoints. A vendor statistic invites a debate; an inventory of their own environment moves the conversation to what to do about it.
What does the client’s staff have to do?
Nothing. The assessment runs unattended through your RMM, so there is no scheduling, no coordination and no employee-by-employee setup. It is read-only, installs nothing, and leaves nothing behind.
What does the assessment collect, and what does it deliberately not collect?
It collects the AI footprint of each endpoint: installed AI applications, AI browser extensions, visits to AI domains, AI developer tools, and whether the browsers’ built-in AI is restricted by enterprise policy. It does not collect passwords, cookies, tokens, form data, page content, full browsing URLs or user names, and non-AI browsing never leaves the machine. This is usually the first question a client’s IT lead asks, so it is worth being able to answer it flatly.
Is there a way to run it without an RMM?
Yes, two, though the RMM run is the one to reach for. You can share a download link with whoever is doing the work, which covers as many machines as you like, or you can email invitations to up to ten people who each run it themselves. Email is the narrowest of the three and is not a way to cover a fleet. All three feed the same assessment, and each machine is counted once however it arrived.
Is the AI risk assessment really free to run?
Yes, and we recommend you offer it free. It is read-only, runs through your own RMM, installs nothing and leaves nothing behind, so it costs you a few minutes rather than a project. The assessment is how you acquire the client rather than how you earn from them: you hand over the AI Exposure report whether or not they buy the governance service, and Managed AI Governance is where the recurring revenue is. Some MSPs charge for the assessment. That is your call, but a free one converts more conversations.
What should an MSP include in a managed AI governance service?
A one-time onboarding covering the AI acceptable-use policy, an exposure baseline, policy configuration and deployment; then a recurring service covering AI usage monitoring, sensitive-data controls, oversight of AI sites, desktop apps and extensions, Microsoft 365 AI OAuth visibility, client-ready reporting, and a quarterly AI Risk Review. Keep it to one service. An MSP that has to design a practice from six options never launches one.
How should an MSP price managed AI governance?
Price it per device per month on top of a one-time onboarding fee, and bill it like any other managed line. A workable client-facing range is roughly $3 to $5 per device per month, with $4 a reasonable anchor, plus onboarding scoped to the size of the estate. That is resale guidance for your own rate card, not a price ShadowLock sets. Your margin is the gap between that and your per-device platform cost.
What should an MSP do if a client declines recommended AI controls?
Document the decision and set a date to revisit it. The AI Risk Acceptance Form records the identified exposure, the control you recommended, the person who decided, their rationale, and a review date. It is a record of a business decision, not a waiver, and it does not remove your obligations. It keeps the conversation open and gives you a specific reason to reopen it next quarter.
What happens to the assessment once the client says yes?
Enable Continuous Governance on the completed assessment and it becomes a managed client organization, either a new one created from the company name or an existing one, and takes you to the deployment page. Assessed machines are not devices and are not billed; a device exists only once you deploy the agent to it.
What is in the AI Risk Assessment Kit?
Four assets: a co-brandable education deck (PPTX) that sets up the problem, a step-by-step assessment runbook for your team, a client leave-behind that explains the findings in plain English, and an MSP close kit with objection handling and the recommended package. The deck and leave-behind carry your branding; the runbook and close kit are for your team.
Can I put my own logo on the client-facing material?
Yes. The education deck and the leave-behind are built for you to co-brand: the deck has logo, company-name and contact placeholders, and ShadowLock appears only as a small credit. The AI Exposure report supports white-label partner logos too. To the client it reads as your service.
How long does the whole motion take?
First conversation to a signed agreement is typically one to three weeks. The assessment itself is a job you queue in your RMM and a report you collect afterwards, not a project: you set how long collection stays open, from a few hours to a couple of weeks. The findings review is a single thirty-minute meeting, and the proposal follows from what the assessment found.
Do I need to buy ShadowLock before I can run an assessment?
You need a partner account to create assessments and generate the AI Exposure report, which the free trial covers. You do not need to have deployed anything to a client. The kit itself is free and yours to keep either way.
Last updated September 1, 2026.
Try it on one client this week.
Pick a hook, push the assessment through your RMM, and bring the report to your next meeting. The system is free. ShadowLock is what runs the assessment and enforces what you sell.
Keep reading
Related reading
- Pricing managed AI governanceExample economics and margin once the client says yes.Read →
- AI acceptable use policy templateThe concrete deliverable the client receives in month one.Read →
- AI risk acceptance formFor the clients who decline: record the decision and a review date.Read →
- ShadowLock for MSPsThe multi-tenant platform that delivers the report and enforces the controls.Read →