2026 AI in Managed IT Report: what providers actually deliver, and what it costs when governance lags
Buyer demand for AI has outrun provider delivery. Small-business AI use has more than doubled in two years, 48% of managed IT providers say AI is now their clients' top need, and 13% earn meaningful revenue from it. This is what the gap looks like in numbers.
Published 8 August 2026 · Best IT MSP Research · Free to read, every figure sourced
In brief
In 2026, 48% of managed IT providers say AI and automation is their clients' top need, but only 13% earn meaningful revenue from AI services. Providers use AI heavily inside their own operations and rarely sell it. The costly gap is governance: 92% of organisations with an AI-related breach lacked AI access controls.
Providers use AI heavily inside their own operations and sell it rarely, while ungoverned AI has become one of the most expensive line items in breach economics.
Buyers moved first. Small-business AI use went from 23% in 2023 to roughly 59% in 2025 (U.S. Chamber of Commerce).
Providers are behind their own customers. Only about half of MSPs feel prepared to guide small businesses on AI, down from 90% a year earlier (OpenText).
Governance, not the model, is what costs money. 92% of organisations with an AI-related breach lacked proper AI access controls (IBM).
Defensive AI pays, when it is actually deployed. Extensive use of AI and automation in security saved USD 1.93 million per breach and cut 65 days off the lifecycle, yet only 36% use it that way (IBM).
The headline finding: demand is mainstream, revenue is not
The single clearest number in this year's data is a gap. In Kaseya's 2026 State of the MSP Report, a survey of more than 1,000 managed service providers published in April 2026, 48% of providers ranked AI and automation as the top client need for 2026. In the same survey, only 13% said they were generating meaningful revenue from AI services.
That is a roughly four-to-one gap between what providers say buyers want and what providers are actually able to sell. It is the defining feature of the managed IT market this year, and it explains most of the other findings below.
Share of managed service providers, n = 1,000+. Source: Kaseya, 2026 State of the MSP Report (April 2026).
Buyers moved first, and they moved fast
The demand side is not speculative. The U.S. Chamber of Commerce's Empowering Small Business research, published in August 2025, found that almost 60% of small businesses now use artificial intelligence for business operations, up from 40% in 2024 and 23% in 2023. Within that, 58% self-identified as using generative AI specifically.
Two supporting figures matter for anyone selling to this market. 82% of small businesses using AI increased their workforce over the past year, which undercuts the assumption that small-business AI adoption is primarily a headcount-reduction play. And 77% of small businesses using AI said limits on the technology would negatively affect their growth, which tells you how central it has become to their operations in a short period.
Share of U.S. small businesses using AI for business operations. Light bars show the full scale to 100%. Source: U.S. Chamber of Commerce, Empowering Small Business (published August 2025).
Where managed IT providers actually run AI today
AI in managed IT is overwhelmingly an internal efficiency story, not a product story. OpenText Cybersecurity's 2025 Global Managed Security Survey of 1,019 providers across the United States, United Kingdom and Canada found providers using AI internally to build expertise: 67% for customer support, 66% for technical support and ticket triage, and 58% for threat detection and response.
Kaseya's data lines up. 53% of providers are already using AI to automate ticketing, patching and monitoring. But the same report notes that more than half have automated only about a quarter of their workload, which is the honest measure of how early this still is.
Top three bars: OpenText Cybersecurity 2025 Global Managed Security Survey, n = 1,019 MSPs (US, UK, Canada). Bottom bar: Kaseya 2026 State of the MSP Report, n = 1,000+.
The readiness gap is widening, not closing
This is the finding that should concern buyers most. OpenText reports that 92% of providers are experiencing growth driven by AI interest and 96% expect that to continue. Yet only about half feel prepared to guide small and mid-sized customers in adopting AI tools, citing limited resources, tool sprawl and the difficulty of standardising services across customer environments.
A year earlier, 90% of providers said they felt ready to meet AI-related security needs. A drop from 90% to roughly 50% in twelve months is not a market getting more competent. It is a market discovering how much it did not know. OpenText also found that fewer than half have built or deployed AI cybersecurity agents for their small-business customers.
The commercial consequence is already visible in what buyers value. OpenText found AI expertise is now the third most important attribute small businesses look for in a provider, behind threat prevention and 24/7 support.
92%
of MSPs report business growth driven by AI interest
~50%
feel prepared to guide SMBs on adopting AI, down from 90% a year earlier
3rd
most important provider attribute to SMBs is now AI expertise
Source: OpenText Cybersecurity, 2025 Global Managed Security Survey (September 2025), 1,019 MSPs sized 1 to 500 employees.
AI changed the threat side of the ledger first
While providers debate how to package AI, attackers have already operationalised it. IBM and the Ponemon Institute's Cost of a Data Breach Report 2026, the 21st edition of the study, found AI-driven attacks increased 56% over the previous year, with more than one in four organisations that experienced a malicious attack reporting it was AI-driven. AI deepfake impersonation and AI-enabled malware drove the highest volume of those incidents, and AI-driven attacks added an average of USD 1 million per breach.
The wider breach picture deteriorated alongside it. The global average cost of a data breach reached a record USD 4.99 million, up 12%, which IBM frames as roughly USD 1,100 per hour. Detection and escalation plus lost business made up 63% of that total. The United States average hit USD 11.5 million, up from USD 10.22 million. Mean time to identify and contain rose to 247 days, a 2.5% uptick that reversed a five-year decline.
Verizon's 2026 Data Breach Investigations Report, covering incidents from November 2024 through October 2025, adds the access picture: 31% of breaches now start with software vulnerabilities, overtaking stolen passwords as the leading way in, and 48% of all breaches involve ransomware. Verizon also flags mobile as the emerging soft spot, with 40% higher click rates than on desktop.
Breach economics, 2026 vs 2025
Measure
2026
Prior year
Global average breach cost
USD 4.99M
USD 4.44M
United States average
USD 11.5M
USD 10.22M
Canada average
USD 5.20M
USD 4.84M
Mean days to identify and contain
247
241
Ransomware among breached organisations
39%
34%
Shadow AI incidents among breached organisations
43%
20%
Source: IBM and Ponemon Institute, Cost of a Data Breach Report 2026 (602 organisations, 17 industries, 16 countries and regions, breaches occurring March 2025 to February 2026).
The expensive part is governance, not the model
The most useful finding in this year's data for a small business is that the cost driver is not which AI you chose. It is whether anyone put controls around it.
IBM found that among organisations that suffered an AI-related breach, 92% lacked proper AI access controls. Only 40% of organisations reported using access controls on AI models and data at all. IBM's own description of the root causes is blunt: compromise of connected APIs, applications and cloud misconfigurations, indicating governance failures rather than model risk.
Shadow AI, meaning staff using unapproved AI tools with company data, is now the clearest example. Incidents involving shadow AI more than doubled to 43% of breached organisations, from 20% the year before, and those breaches cost USD 5.39 million on average against USD 4.63 million a year earlier. Despite that, 68% of breached organisations had no governance in place to manage AI or detect shadow AI, slightly worse than the 63% reported the previous year. The encouraging counter-signal is that 33% said they were developing governance policies, up from 22%.
Attacks aimed at the models themselves are the most expensive category of all. IBM put the average cost of a model inversion attack at USD 6.07 million and a prompt injection attack at USD 5.89 million, both well above the global average.
Share of breached organisations. Source: IBM and Ponemon Institute, Cost of a Data Breach Report 2026.
Where AI measurably pays back
The same report that prices the risk also prices the return, and the return is large and specific. Organisations using AI and automation extensively across the security lifecycle shortened breach times by 65 days and lowered average costs by USD 1.93 million compared with organisations using none.
The catch is adoption. Only about one third (36%) of breached organisations said they used these tools extensively across prevention, detection, investigation and response, and their use in prevention lagged behind detection and investigation. The saving is available; most organisations are not collecting it.
Agentic AI shows the same lopsided pattern. 50% of breached organisations said they deploy AI agents in their security operations centre, and more than half of those focus on threat hunting, response and containment. But only 18% applied AI agents to vulnerability scanning and management, which is precisely where the emerging frontier-model threat is aimed. IBM's executive summary singles out an April 2026 announcement of a frontier model that found thousands of high-severity vulnerabilities, including in every major operating system and web browser, as a warning to security teams.
Share of breached organisations. Source: IBM and Ponemon Institute, Cost of a Data Breach Report 2026.
Spending intent has shifted sharply in response. IBM found that 64% of organisations said they would increase security spending after experiencing a breach, and that figure rose to 85% once they learned of new frontier AI model threats. More than half plan to invest in AI security and governance tools after a breach, an 88% increase over the prior year.
What this means for the economics of a managed IT provider
The AI gap is landing on providers during a harder commercial year, which is why so few have productised it. Kaseya's data shows 71% of providers name acquiring new customers as their top challenge, and deal sizes are compressing: 41% report typical customer spending above USD 25,000 annually, down from 75%. 19% report difficulty demonstrating value to prospects, close to double the prior year, and 16% report difficulty hiring skilled technicians, up from 9%.
Against that, the services that are growing are the security-adjacent ones: 71% of providers reported year-over-year revenue growth in cybersecurity and 50% in business continuity and disaster recovery. Read together with the IBM data, the commercial logic is clear. The most defensible AI offer a provider can make right now is not a chatbot. It is governed AI security: access controls on AI models and data, shadow AI detection, non-human identity management, and agentic assistance in the SOC.
OpenText's buying-behaviour data supports the same conclusion. 44% of providers cite strength of security solutions as the leading factor in purchasing decisions, against just 8% citing price.71% of small businesses prefer all-in-one prevention, detection and response bundles. And customers naming cost savings as their primary challenge fell from 28% in 2023 to 17% in 2025. This is a market that is buying capability, not discounts.
Ten questions to ask a managed IT provider about AI
Most AI claims in this market are unfalsifiable as written. These questions are designed so that a capable provider can answer them in writing and an unprepared one cannot.
Where does AI touch our data? Ask for a list of systems, not a philosophy.
Does any of our data train a model? Get the answer in the contract, including for subprocessors.
Which decisions does AI make without a human? Ticket routing is low risk. Patch approval and firewall changes are not.
How is an AI-generated change logged, attributed and reversed? This is the single best test of operational maturity.
Do you apply access controls to AI models and data? Only 40% of organisations do, so treat a yes as a differentiator and ask for evidence.
How do you detect shadow AI in our environment? 68% of breached organisations had no way to.
Do you secure non-human identities? IBM found fewer than half of organisations do, and agent sprawl makes this urgent.
Do you use AI agents for vulnerability management, or only for alert triage? Only 18% do the former.
What is your service level when the AI is wrong? A provider that has thought about this has a rollback plan and a human escalation path.
What this means if you are choosing a provider now
Three practical conclusions follow from the data.
Do not pay a premium for the word AI. With 48% of providers naming it as the top client need and 13% earning real revenue from it, the label is far more common than the capability. Ask the ten questions above and buy on the answers.
Weight governance over novelty. The measurable costs in 2026 came from missing access controls, undetected shadow AI and unsecured non-human identities, not from choosing the wrong model. A provider that can implement an AI use policy, access controls and monitoring is worth more than one with a flashier assistant.
Ask about prevention, not just detection. The USD 1.93 million saving goes to organisations using AI and automation extensively across the whole lifecycle, and IBM notes prevention is where use lags. Ask specifically what runs before an incident.
Methodology and sources
This report aggregates published findings from five independent primary studies. Best IT MSP did not conduct original fieldwork for this edition; every figure is attributed to the organisation that produced it, and every source is linked so readers can verify the number in context. Where two studies measure similar things with different samples, both are cited rather than blended, because their populations and definitions differ.
Figures are reported as published. Where a source reported a percentage change and an absolute pair that imply slightly different rounding, the absolute values are used. Currency is US dollars as published by the source.
Kaseya, 2026 State of the MSP Report (April 2026). Survey of more than 1,000 managed service providers. kaseya.com
OpenText Cybersecurity, 2025 Global Managed Security Survey (September 2025). 1,019 managers, executives, security professionals and customer relationship managers at MSPs in the US, UK and Canada, at firms of 1 to 500 employees. opentext.com release (PDF)
IBM and Ponemon Institute, Cost of a Data Breach Report 2026 (21st annual edition). 602 organisations breached between March 2025 and February 2026, across 17 industries and 16 countries and regions, with 3,558 interviews; breaches ranged from 2,590 to 115,380 compromised records. ibm.com/reports/data-breach
Verizon, 2026 Data Breach Investigations Report. Incidents occurring 1 November 2024 to 31 October 2025. verizon.com
U.S. Chamber of Commerce, Empowering Small Business: The Impact of Technology on U.S. Small Business (published August 2025), U.S. Chamber Technology Engagement Center. uschamber.com
NIST AI Risk Management Framework and CISA Artificial Intelligence guidance, referenced for the governance recommendations. nist.gov · cisa.gov
Best IT MSP is an independent directory. We do not sell IT services, and no provider paid to be included in or excluded from this analysis. Organic ranking across the directory is earned on rating and verified data; paid placement is always labelled.
Frequently asked questions
Are managed IT providers actually using AI in 2026?
Yes, but mostly internally. 53% of providers use AI to automate ticketing, patching and monitoring (Kaseya), and 67% use it for customer support, 66% for ticket triage and 58% for threat detection and response (OpenText). Selling it is rarer: only 13% report meaningful revenue from AI services.
Does AI make a managed IT provider more secure or less secure?
Both, depending on governance. Extensive use of AI and automation in security cut breach costs by USD 1.93 million and shortened breach lifecycles by 65 days. But breaches involving shadow AI averaged USD 5.39 million, and 92% of organisations with an AI-related breach lacked proper AI access controls. The control layer decides which side you land on.
What is shadow AI and why does it matter to a small business?
Shadow AI is staff using unapproved AI tools with company data. Incidents more than doubled to 43% of breached organisations in 2026, up from 20%, and 68% of breached organisations had no governance to manage AI or detect it. The practical fix is a written AI use policy plus access controls and monitoring, all of which a competent provider can implement.
What should I ask an MSP about its AI capabilities?
Ask where AI touches your data, whether your data trains any model, which decisions AI makes without a human, how AI-generated changes are logged and reversed, whether non-human identities are secured, and what the service level is when the AI is wrong. The ten questions above are written so an unprepared provider cannot answer them in writing.
How fast are small businesses adopting AI?
Small-business AI use rose from 23% in 2023 to 40% in 2024 and to roughly 59% in the U.S. Chamber of Commerce's 2025 research, with 58% using generative AI specifically. Demand is running ahead of provider readiness, which is this report's central finding.
Is AI replacing managed IT jobs?
The available data points the other way in the small-business segment. 82% of small businesses using AI increased their workforce over the past year (U.S. Chamber). On the provider side, 16% of MSPs report difficulty hiring skilled technicians, up from 9%, so the binding constraint is still talent supply rather than displacement.
Find a provider that runs these controls
Best IT MSP ranks managed IT providers city by city on verified rating and company data. If AI governance is now part of your buying criteria, use the questions above on the shortlist for your market.