Built for MSPs · Free

Sell AI Governance to Your Clients

The MSP AI Governance Sales System. Five steps that turn shadow AI risk into a recurring line on the agreement.

Read-only, runs through your RMM, no agent rollout. The kit is free either way.

The system

How can MSPs sell AI governance?

In five steps, using a free assessment you run through your own RMM to do the convincing.

01

Start the conversation

Lead with the pressure the client already feels, not with the phrase "AI governance".

02

Prove the exposure

Run a read-only assessment through your RMM. No agent rollout.

03

Sell the fix

One service on your rate card, not a practice you have to design first.

04

Put the rules in writing

A written policy is the thing the client can hold, and the thing auditors ask for.

05

Get a decision

Yes or not yet. What it never ends with is "okay, let us know".

01 / 05

Start the conversation

Need a reason to bring it up? Pick one.

Lead with the pressure they already feel, not with the software.

Steal this emailCold, or into your next QBR agenda.

Subject: Quick AI exposure check

We're starting to look at AI exposure across our client base. We can run a free, read-only assessment that shows which AI tools are actually being used in your environment and whether there are any obvious risks. Nothing gets installed, nobody there has to do anything, and we run it from our end. Want me to send the assessment over?

02 / 05

Prove the exposure

Don't argue about whether shadow AI exists. Show them theirs.

Run it through the RMM you already have. No agent rollout, and nobody at the client has to do anything.

  1. 1Create the assessment
  2. 2Run it through your RMM
  3. 3Present the report

Shadow AI Audit Report

AI Exposure Assessment

Prepared for

Acme Manufacturing

Prepared by

Your MSP

Risk level

High Risk

Risk tierHIGH

Executive summary

Acme Manufacturing shows significant shadow AI exposure. Our scan found 17 distinct AI tools across 8 endpoints, and built-in browser AI features (Chrome Gemini / Edge Copilot) are unrestricted by enterprise policy. The combination of unmanaged AI tools and unrestricted browser AI creates a path for sensitive business data to be shared with unvetted AI services.

Endpoints assessed

8 / ~10

Reported in this collection window

AI desktop apps

11

Across all assessed endpoints

Browser extensions

9

AI extensions installed

AI sites visited

14

Distinct domains in history

Top AI tools detected

Desktop AI applications installed on scanned devices

  • ChatGPT Desktop36%
  • Claude27%
  • Cursor18%
  • Ollama10%
  • Copilot9%

AI sites visited

Domains with the most browser visits this scan

DomainVisitsLast
chatgpt.com486Aug 28
claude.ai213Aug 28
gemini.google.com97Aug 27
perplexity.ai64Aug 26

Installed AI applications

DeviceApplicationVersionPublisher
FIN-LT04ChatGPT Desktop1.2026.4OpenAI
ENG-WS02Cursor0.49.1Anysphere Inc.
OPS-LT11Claude1.4.2Anthropic
ENG-WS02Ollama0.6.2Ollama Inc.

Chrome Gemini & Edge Copilot policy state

DeviceBrowserState
FIN-LT04ChromeAllowed (no policy)
OPS-LT11EdgePartially blocked
ENG-WS02ChromeAllowed (no policy)
Sample report for a fictional client. Layout matches the report ShadowLock generates; the figures are illustrative.

What the assessment observed

AI apps, browser extensions, AI browsing, developer tools and browser AI policy, per endpoint.

What that implies

A path for company data to reach unvetted services. Exposure, not a proven leak.

What ShadowLock sees once deployed

What was pasted or uploaded, which sign-ins were personal, which AI apps hold M365 grants.

The assessment is the door opener.
The managed service is the revenue.

The assessment
Free, read-only, through your RMM.
Managed AI Governance
Monitoring, enforcement, reporting, management.

03 / 05

Sell the fix

Sell one thing: Managed AI Governance

One SKU you could add to your catalog tomorrow, answering what the assessment just showed them.

Recommended service

Managed AI Governance

$3–$5

per device / month, suggested resale

Initial rollout

One-time onboarding fee

  • AI exposure baseline from the assessment findings
  • A written AI acceptable-use policy, agreed with the client
  • Policy configuration for their tools, data types and exceptions
  • Silent deployment of the agent and managed browser extension via your RMM

Ongoing

Recurring, billed per device

  • AI usage monitoring across every endpoint and browser
  • Sensitive-data controls on what can be pasted or uploaded into AI tools
  • Oversight of AI websites, desktop apps and browser extensions
  • Microsoft 365 AI OAuth visibility and control on the client tenant
  • Client-ready governance reporting under your logo
  • A quarterly AI Risk Review, included

What one client is worth

250 devices × $4 per device / month

$1,000

MRR

× 12 months

$12,000

ARR from one client

10 similar clients = $120,000 ARR

Before onboarding fees, and before your platform cost is deducted.

How should an MSP price managed AI governance?

Roughly $3 to $5 per device per month on top of a one-time onboarding fee, with $4 a reasonable anchor.

Suggested resale for your own rate card. ShadowLock does not set or require what you charge your clients. See partner pricing and the pricing playbook.

We'll show you how AI is actually being used, put guardrails around your sensitive data, enforce your AI policy on every endpoint, and review it with you each quarter.
Say it like this

04 / 05

Put the rules in writing

Turn recommendations into actual company policy.

A policy without enforcement is just paperwork. Customize the free template, have them adopt it, then make every line of it real.

AI Acceptable Use Policy

Effective date: [DATE] · Owner: [POLICY OWNER] · Review cycle: Annual

4. Approved AI Tools

Only the tools listed in this section may be used with company data. Requests for additional tools go through the exception process in section 10.

5. Prohibited Data

Customer records, credentials, contracts, source code and regulated data must never be entered into an AI tool.

7. Personal Accounts

Company work must be done in company AI accounts. Personal accounts are out of scope of our controls and our agreements.

8. Monitoring

AI use on company devices is monitored, and prohibited data is blocked before submission.

Policy says it. ShadowLock enforces it.

The policy saysThe control does

Only approved AI tools may be used for company work.

Allow, warn or block per AI website and per desktop AI app.

Never paste customer records, credentials or contracts into an AI tool.

Classify the content of a paste and block it before it is submitted.

Company files may not be uploaded to AI services.

Intercept file uploads to AI sites and apply the file-upload policy.

Use company accounts, not personal ones.

Detect personal-account sign-ins to AI tools and flag or block them.

AI apps may not be connected to company email and files.

Inventory Microsoft 365 OAuth grants to AI apps and control which are allowed.

Violations are recorded and reviewed.

Every allow, warn and block is an event you can report on and export.

Enforcement sits on the endpoint and in the browser, so it holds on personal accounts. How the controls work.

05 / 05

Get a decision

Every assessment ends with a decision.

They fix the risk or they accept it on the record. Never "okay, let us know."

YES

Implement Managed AI Governance

Under thirty minutes of platform work to onboard.

  1. Day oneEnable Continuous Governance on the assessment and it becomes the client organization.
  2. Week onePolicy agreed, controls configured, agent and browser extension pushed through your RMM.
  3. Every quarterAn AI Risk Review, in the same report format they already recognise.

NOT YET

Document the accepted risk

A dated, signed record of a business decision. Not a waiver, and it does not remove your obligations.

AI Risk Acceptance Form

To be completed when a recommended control is declined

ClientAcme Manufacturing

Identified exposure11 unmanaged AI apps across 8 devices

Recommended controlManaged AI Governance

DecisionRisk accepted

Accepted by

Date

Review date

The assets

The AI Risk Assessment Kit

Two you present under your own brand, two for your team. Free either way.

Co-brandable education deck

PPTX

Client-facing. The pre-assessment briefing on where AI data leaks. Your logo, your name.

Assessment runbook

PDF

For your team. The motion end to end, from opening hook to signed agreement.

Client leave-behind

PDF

Client-facing. A plain-English primer to hand over with the report. Your document, not ours.

MSP close kit

PDF

For your team. Framing, proposal language, and the six objections you will actually hear.

Get all four assets

Tell us where to send updates and we'll unlock the downloads.

No spam. We'll only use this to send updates and helpful resources.

Answers

Questions MSPs ask before the first assessment

How can an MSP start an AI governance conversation?

Lead with the pressure the client is already under rather than with AI governance as a topic. If they think in dollars, run the shadow AI risk calculator on their headcount. If an audit or a new state law applies to them, send that specific regulation. If a cyber-insurance renewal is close, show them the AI questions carriers now ask. If they believe AI risk is hypothetical, send one sourced incident from their industry.

How can MSPs sell AI governance?

In five steps. Start the conversation with the pressure the client already feels: cost, regulation, a cyber-insurance renewal, or a real incident in their industry. Prove their exposure with a free read-only AI risk assessment run through your own RMM, with no agent deployment. Sell one recurring Managed AI Governance service rather than a menu. Put the rules in a written AI acceptable-use policy backed by enforcement on the endpoint and in the browser. Then get a decision: clients who say yes move to onboarding, and clients who say not yet sign a risk acceptance form that records the decision and a review date.

What is an AI risk assessment for an MSP client?

An AI risk assessment inventories the AI tools actually in use across a client's endpoints: installed AI applications, AI browser extensions in Chrome, Edge, Brave and Firefox, AI-site browsing history, AI developer tools and MCP server configurations, and whether the browsers' built-in AI is restricted by enterprise policy. ShadowLock's runs read-only through the MSP's existing RMM, with no agent deployment and no involvement from the client's staff, and leaves nothing installed. It produces a risk-tiered AI Exposure report the MSP presents to the client.

Do I have to deploy the ShadowLock agent to run an assessment?

No. That is the point of it. The assessment runs through the RMM you already use, across the client’s Windows endpoints, without deploying the ShadowLock agent and without involving anybody at the client. The agent comes later, as part of Managed AI Governance, once the client has seen the findings and decided to buy. Find the problem before you ask them to buy the solution.

How do MSPs prove shadow AI risk?

By assessing, not arguing. A lightweight read-only assessment, pushed through the MSP’s own RMM, inventories the AI applications, browser extensions and AI browsing already present across the client’s Windows endpoints, and the results come back as a risk-tiered AI Exposure report naming the client’s own tools and endpoints. A vendor statistic invites a debate; an inventory of their own environment moves the conversation to what to do about it.

What does the client’s staff have to do?

Nothing. The assessment runs unattended through your RMM, so there is no scheduling, no coordination and no employee-by-employee setup. It is read-only, installs nothing, and leaves nothing behind.

What does the assessment collect, and what does it deliberately not collect?

It collects the AI footprint of each endpoint: installed AI applications, AI browser extensions, visits to AI domains, AI developer tools, and whether the browsers’ built-in AI is restricted by enterprise policy. It does not collect passwords, cookies, tokens, form data, page content, full browsing URLs or user names, and non-AI browsing never leaves the machine. This is usually the first question a client’s IT lead asks, so it is worth being able to answer it flatly.

Is there a way to run it without an RMM?

Yes, two, though the RMM run is the one to reach for. You can share a download link with whoever is doing the work, which covers as many machines as you like, or you can email invitations to up to ten people who each run it themselves. Email is the narrowest of the three and is not a way to cover a fleet. All three feed the same assessment, and each machine is counted once however it arrived.

Is the AI risk assessment really free to run?

Yes, and we recommend you offer it free. It is read-only, runs through your own RMM, installs nothing and leaves nothing behind, so it costs you a few minutes rather than a project. The assessment is how you acquire the client rather than how you earn from them: you hand over the AI Exposure report whether or not they buy the governance service, and Managed AI Governance is where the recurring revenue is. Some MSPs charge for the assessment. That is your call, but a free one converts more conversations.

What should an MSP include in a managed AI governance service?

A one-time onboarding covering the AI acceptable-use policy, an exposure baseline, policy configuration and deployment; then a recurring service covering AI usage monitoring, sensitive-data controls, oversight of AI sites, desktop apps and extensions, Microsoft 365 AI OAuth visibility, client-ready reporting, and a quarterly AI Risk Review. Keep it to one service. An MSP that has to design a practice from six options never launches one.

How should an MSP price managed AI governance?

Price it per device per month on top of a one-time onboarding fee, and bill it like any other managed line. A workable client-facing range is roughly $3 to $5 per device per month, with $4 a reasonable anchor, plus onboarding scoped to the size of the estate. That is resale guidance for your own rate card, not a price ShadowLock sets. Your margin is the gap between that and your per-device platform cost.

What should an MSP do if a client declines recommended AI controls?

Document the decision and set a date to revisit it. The AI Risk Acceptance Form records the identified exposure, the control you recommended, the person who decided, their rationale, and a review date. It is a record of a business decision, not a waiver, and it does not remove your obligations. It keeps the conversation open and gives you a specific reason to reopen it next quarter.

What happens to the assessment once the client says yes?

Enable Continuous Governance on the completed assessment and it becomes a managed client organization, either a new one created from the company name or an existing one, and takes you to the deployment page. Assessed machines are not devices and are not billed; a device exists only once you deploy the agent to it.

What is in the AI Risk Assessment Kit?

Four assets: a co-brandable education deck (PPTX) that sets up the problem, a step-by-step assessment runbook for your team, a client leave-behind that explains the findings in plain English, and an MSP close kit with objection handling and the recommended package. The deck and leave-behind carry your branding; the runbook and close kit are for your team.

Can I put my own logo on the client-facing material?

Yes. The education deck and the leave-behind are built for you to co-brand: the deck has logo, company-name and contact placeholders, and ShadowLock appears only as a small credit. The AI Exposure report supports white-label partner logos too. To the client it reads as your service.

How long does the whole motion take?

First conversation to a signed agreement is typically one to three weeks. The assessment itself is a job you queue in your RMM and a report you collect afterwards, not a project: you set how long collection stays open, from a few hours to a couple of weeks. The findings review is a single thirty-minute meeting, and the proposal follows from what the assessment found.

Do I need to buy ShadowLock before I can run an assessment?

You need a partner account to create assessments and generate the AI Exposure report, which the free trial covers. You do not need to have deployed anything to a client. The kit itself is free and yours to keep either way.

Last updated September 1, 2026.

Try it on one client this week.

Pick a hook, push the assessment through your RMM, and bring the report to your next meeting. The system is free. ShadowLock is what runs the assessment and enforces what you sell.