For most SMBs, AI risk isn't the agent—it's the personal chatbot

A practical, MSP-centric guide to governing shadow AI—the sensitive data employees quietly paste into chatbots—with policy, sanctioned accounts, and Okta SSO.

Bottom Line Up Front

For most SMBs, the AI risk that's live today isn't an autonomous agent—it's shadow AI: employees pasting sensitive company data into personal ChatGPT or Claude accounts, into tools the business can't see, audit, or control. Banning AI only drives it underground. The better move (for now) is the one MSPs already make with every other category of software—govern it: a plain-language use policy, a sanctioned company-governed AI account, and access placed behind Okta SSO with clean deprovisioning. Right-size it to each client and apply extra discipline where data is regulated.

Key Takeaways
  • The AI risk most SMBs face today isn't rogue agents, it's shadow AI: employees pasting sensitive data into personal chatbots, with no policy, visibility, or oversight.
  • Banning AI backfires; governing it works. A plain-language use policy, a sanctioned company AI account, and access through Okta SSO with automatic deprovisioning turn invisible use into managed use.
  • Right-size the response: most clients don't need a dedicated "AI security" platform. Apply the same playbook with more discipline for regulated clients.

The dominant AI conversations right now are about autonomous agents—software that acts on its own across a company's systems. MSPs recognize that for most SMBs, that's still a future consideration: real agent deployments remain concentrated in large enterprises, and even there they run in tightly scoped, closely supervised roles. The more common scenario for your SMB clients simply involves an employee and a free chatbot.

You know how it goes: someone on staff opens a personal ChatGPT or Claude account to speed up a deliverable. To get a useful answer, they paste in a client contract, a customer list, a patient roster, or a block of proprietary source code. In that instant, confidential data belonging to your client—or to their customers—has left the building, into a service the business doesn't control, can't audit, and never approved.

This is "shadow AI"—the AI equivalent of shadow IT, where employees adopt tools without approval or oversight. And for the typical SMB it's the AI risk that's easiest to overlook, precisely because no one ever specifically evaluated and allowed it. It isn't a rogue agent going off-script; it's an ordinary person trying to do their job faster with the easiest tool at hand. And it's neither rare nor hypothetical: Verizon's 2026 Data Breach Investigations Report found that employee use of unapproved shadow AI tripled over the year, to 45%, and identified it as a growing source of data leakage.

Why "just ban it" backfires

One instinct might be to block AI tools outright. This kind of approach rarely works. Bans just push usage underground, where you lose the one thing you most need—visibility—while forfeiting the genuine productivity gains employees are chasing. Block it and people won’t stop using AI; they’ll just stop telling you about it.

The better posture is the one MSPs already apply to every other category of software: govern it. Give people a sanctioned path that's easier than the risky one, and wrap it in the same identity controls that you'd put around any business app. This is where you add real advisory value—and, conveniently, where the same Okta platform you deploy for everything else does the work.

The practical playbook MSPs can deliver

Most of your clients need the same handful of guardrails. None of them require exotic tooling, and all of them apply just as well to your own shop.

1. Write a plain-language AI acceptable-use policy. Spell out which tools are approved, and—more importantly—what data must never be pasted into a public AI tool: client-confidential information, regulated data (PHI, PII, cardholder data), credentials, and proprietary code. Keep it short so people read it.

2. Provide a company-governed AI option. The reason employees reach for personal accounts is that no sanctioned alternative exists. Stand up business or enterprise-tier AI accounts that offer administrative control and data protections—crucially, settings that keep company inputs out of model training. When the approved tool is as capable as the personal one, the incentive to go rogue largely evaporates.

3. Put AI tools behind SSO and lifecycle management. Provision approved AI applications through Okta like any other app. That gives you consistent, phishing-resistant MFA on access, a clear record of who's entitled to what, and—critically—automatic deprovisioning. When an employee leaves, their access to the company AI tool dies with their Okta account, in the same offboarding action that revokes everything else. No orphaned logins, no lingering access to a tool full of company prompts.

4. Lock down—and review—the OAuth connections AI tools request. Many AI tools don't need a password to reach company data; they ask the user to "Allow" access to Microsoft 365, Google Workspace, or Salesforce, and that click creates a standing OAuth grant that lets the tool read data and act on the user's behalf—often with broad, long-lived permissions no one in IT ever approved. Treat those grants like the privileged access they are: grant the narrowest scope that does the job, and periodically review what users have authorized in the admin consoles of the platforms you already manage for them—Microsoft 365, Google Workspace, Salesforce—revoking anything unsanctioned or over-scoped. Those consent screens are exactly where shadow AI acquires its access, so reviewing them turns "we hope nobody's doing this" into "we can see who has."

5. Log and review. Keep an eye on access and usage the same way you would for any sensitive application. Governance isn't a one-time policy document; it's an ongoing habit.

Right-size the response

For most SMBs, that playbook is the strategy: a clear policy, a governed AI account, SSO with lifecycle management, and least-privilege access reviews. Most clients simply aren't at the point where they need a dedicated "AI security" platform, and part of being a trusted advisor is telling them so. Matching the control to the real risk builds far more credibility than upselling a SKU nobody needs yet.

But "most" isn't "all", and the stakes aren't the same for every client.

Regulated clients raise the stakes, not the complexity

Many of your clients operate where data carries legal weight—startups and biotech protecting IP, healthcare and finance under privacy and sector rules, SaaS vendors bound by their own customer contracts, law firms holding privileged information. In every one of these, AI tools have tended to arrive the same way: department by department, often as a feature that simply exists inside software the business already uses. This produces an obvious gap: no approved tool, no vendor review, and no record of which AI is touching sensitive data.

The reassuring part for these clients is that the fix isn't heavier; it's the same playbook applied with more discipline. A clear policy that names what can never go into a public tool. A sanctioned, governed account so people don't improvise with personal ones. SSO and clean, rapid user deprovisioning so access is provable and revocable. And visibility into what's connected. For a regulated SMB, that combination is what turns "we think we're fine" into something you can show an auditor—without standing up enterprise-grade governance machinery a small business could never run.

A note on AI agents

A small number of clients will eventually integrate AI agents into their systems—software that holds its own credentials and acts across apps and data. Most SMBs, though, won't get there by building agents; they'll first meet them embedded inside the SaaS they already run, where an unreviewed agent looks a lot like the shadow AI above. The enterprise-grade tooling for governing agents as first-class identities (Okta for AI Agents) exists, and ZeroTek can support an MSP whose client genuinely needs it—but for the overwhelming majority you serve today, it's neither necessary nor economical, and the playbook above is the most practical.

Where the MSP adds value

Your job here isn't to pick a side in the AI hype cycle. It's to meet each client where they are. For nearly all of them, that means turning ungoverned, invisible AI use into sanctioned, identity-governed AI use with policy, a company account, and SSO—applied with extra rigor where the data is regulated. Identity is the through-line, and it's the layer you're already managing for them through Okta.

Start the conversation before an employee starts it for you.

Talk to the ZeroTek team about governing AI access for your clients—and for your own team.

See ZeroTek in Action

See how the platform works for your specific use cases

No slides. No script. Our team will walk you through the platform on a 30-minute call and answer any questions you have about your specific use cases.

Talk to our team →
Featured Case Study
Element Technologies
Managed Service Provider · 50+ Okta orgs managed
Challenge

Element needed a repeatable way to deploy a consistent Okta baseline across dozens of clients without manual checklists.

Outcome

ZeroTek centralized management across clients. ZeroConfig standardized their baseline and cut tenant setup from hours to minutes.

22x
Faster to identify config drift
30%
YoY increase in managed users
See It Live

See how 100+ MSPs are building
high-margin identity practices

A 30-minute demo will show you exactly how ZeroTek fits your stack, your team, and your client base. No pressure. No prep required.