Guides / IT & MSP
13 questions to ask your IT provider about AI controls.
AI arrived in your business whether anyone approved it or not — inside Microsoft 365, inside your line-of-business apps, inside whatever your staff signed up for with a company email. Your IT provider manages your networks, devices, and business tenant, which makes them your essential partner in finding it and putting boundaries around it. These questions establish what they can see, what they can control, and what they can hand you when your insurer, your lawyer, or your biggest customer asks. Free, no signup, printable.
A note on fair scope, before the first question
Your provider sees what you pay them to manage — the devices they administer, the networks they run, the tenant they configure. Personal phones, home computers, and tools nobody told them about sit outside that boundary — a technical fact, not a service tier; claims of total visibility outrun what any toolset can do. These questions are not a test of omniscience. They are the agenda for deciding, together, where the boundary should sit and what it costs to move it. If a question below lands outside your current agreement, the right response isn't disappointment — it's a scope conversation. Your provider's reaction to that conversation is itself information.
Timing note: the natural moment is your next quarterly review — or the renewal notice on your business insurance, whichever arrives first.
The questions
"What AI is actually running on our managed devices and in our business tenant right now?"
Why it matters: the inventory question. Approved tools, AI features switched on inside existing software, and the unofficial layer visible on managed equipment. Expect: "we'd have to run a discovery scan for that." Fair answer once — it's the follow-through that's the data. (What lives beyond managed equipment is Q.06's territory.)
"Which of our existing subscriptions have added AI features since we bought them — and who decided whether they're on?"
Why it matters: the vendor-push question. Copilot, Gemini, AI assistants inside CRM, accounting, and help-desk tools: features arrive by product update, defaulted on, processing your data. Someone is deciding — the question is whether it's your provider, you, or the vendor's default. Any working provider has stories here; the strong answer comes with settings screenshots.
"For the AI tools we approve, what do the vendors' own terms say about our data — and what do our admin settings actually control?"
Why it matters: the data-flow question, scoped honestly: your provider can read what a vendor publishes and configure what the admin console exposes — retention, training opt-outs, tenant boundaries. They cannot see a vendor's backend, and shouldn't pretend to. For the contract-side version of this question — the one your lawyer asks the vendor directly — see our guide for AI vendor contracts.
"Do we have an AI acceptable-use policy — and if we implement one, would our staff recognize the tools named in it?"
Why it matters: a policy naming tools nobody uses, missing the ones everyone uses, is shelf-ware. The division of labor: your provider supplies the technical reality (what's actually in use, what's controllable), management writes and owns the policy from it. A provider handed a template policy to "just push out" is being asked to do management's job with IT's tools.
"Can you restrict or approve AI tools by technical policy — and what can't be controlled?"
Why it matters: the enforcement question: DNS and browser controls, endpoint policy, tenant settings, app-approval flows. This is core provider craft, and the strong answer comes with a dashboard. The honest answer also includes the limits — and the answer that includes its own limits is the one you can build on.
"If an employee uses a personal phone or home computer to put our data into an AI tool, what can anyone actually do?"
Why it matters: the boundary question, and the honest answer for most small businesses is: technically, very little — the network edge isn't a wall anymore. The real controls are upstream: which data staff can reach in the first place, what the policy says, and whether anyone's been trained. "We can't stop that, but here's what limits the blast radius" is the straight version of this answer.
"If we put AI in front of customers — a chatbot on the website, an assistant in support — who, among everyone we pay, owns the disclosure duties?"
Why it matters: disclosure obligations for AI that interacts with people are in force or arriving in multiple jurisdictions (EU from 2 August 2026; state laws on the register's map). Here's the seam: the website chatbot may have been built by your web developer or marketing agency, hosted by a SaaS vendor, and never touched by your IT provider — while the legal duty may sit with your business. This question doesn't assume your provider owns it; it asks them to help you find out who does, so it's owned on purpose rather than by accident.
Reg. (EU) 2024/1689, Art. 50(1) — applies 2 Aug 2026 · state disclosure laws per the register
"When our business insurance renews with new AI language in it, what documentation can your systems generate for us?"
Why it matters: the renewal question. Carriers have been attaching AI exclusions to commercial policies at renewal since January 2026. When the questionnaire or exclusion notice arrives, the useful things are exports a provider's systems can actually produce: the inventory, the control settings, the policy deployment records. This is documentation you can present at renewal; what it means for coverage is your broker's call.
Public carrier filings — see the record at certian.com
"If staff try to use unapproved AI tools on our managed network, do we have the visibility to know?"
Why it matters: the capability check, scoped to reality: what logging exists today, what would trigger an alert, and what additional tooling you'd need to buy to actually track that data flow. "We'd need to add a tool for that" is a legitimate answer with a price tag — and a better one than a confident claim no toolset can back.
"When you evaluate software for us, is AI part of the vetting — and what do you ask vendors?"
Why it matters: does the provider ask about training on client data, model providers, provenance marks? A provider using a real vetting list is doing invisible work worth paying for. (The register keeps a 14-question version they're welcome to use.)
"What AI questions are your other clients asking — and what should we be asking that we haven't?"
Why it matters: the humility question, and a provider-quality probe. A provider seeing thirty businesses has pattern knowledge no single client has. The answer's specificity is the tell.
"What of this is included in our current agreement, and what requires a separate project scope?"
Why it matters: inventory work, policy support, and advanced controls are often outside standard support agreements — that's legitimate; assessment work has real cost. What matters is defining the boundaries and the costs before an insurance deadline forces a rushed deployment. Clean boundaries here save both sides the renewal-season scramble.
"What do you need from us to do any of this well?"
Why it matters: the reciprocity question, and the guide's honest close: most of what's above fails without leadership sponsorship — a named internal owner, decisions about risk appetite, backing for the policy when a department head objects, and a budget that matches the ask. Your provider can't govern what you won't sponsor. A specific list back is the sign of a provider thinking in shared-responsibility terms.
What strong answers share
Real inventories over confident guesses, volunteered limits, division of labor stated plainly, scope and costs priced in the open — and questions asked back. What your provider's answers add up to is your decision. The answers travel: bring them to your broker at renewal and your counsel when AI faces customers; the public record behind the dates and duties above is kept, dated and sourced, at certian.com.
Professional register — this guide
Disclosed relationships · IT providersCertian does not provide legal advice. Professionals appearing here hold sponsored listings — flat fee, identical terms within each category, never contingent on any outcome, independent of Certian. How listings work →
IT providers & MSPs — AI controls and documentation support
No provider is currently recorded for this guide. IT providers and managed-service practices supporting AI inventory, technical controls, or renewal documentation may register interest in a sponsored listing — flat fee, identical terms within each category.