General
8 min read

Why Your IT Provider Should Be Using AI in 2026, and What to Ask Them About It

More than half of IT providers now use AI to monitor systems and handle tickets. Here is what that actually means for your business, what should never run without a human, and the questions to ask your provider.
Written by
Matt Truster
Published on
September 18, 2026

Ask an IT provider in 2026 whether they use AI and you will get a yes. Ask what it actually does and the answers get vague fast.

That gap matters, because AI in managed IT is no longer a pitch. It is running in the background of most providers right now, making decisions about your systems. Some of those decisions are excellent. A few of them should worry you.

Here is a plain look at what is real, what works, and what to ask.

Most providers already use it

Kaseya surveyed more than 1,000 managed service providers for its 2026 State of the MSP Report, published in April. It found that 53 percent already use AI to automate ticketing, patching and monitoring. A separate survey of 195 providers by Lansweeper put AI use in IT monitoring at 67 percent.

So this is mainstream. But the same Kaseya report found most providers have automated only about a quarter of their workload, and just 13 percent earn meaningful revenue from AI services.

Read those numbers together and the honest picture appears. Using AI is common. Using it well is not.

What it actually does

Strip away the marketing and AI in an IT environment does four things reliably today.

It watches. Monitoring tools use machine learning to spot patterns a human would miss. A drive that is failing slowly. A server that is behaving differently at 3am than it did last week. A login from a location that does not fit the person. This is the most mature use and the least controversial.

It sorts. When tickets come in, AI categorizes them, routes them to the right technician, and pulls up similar past issues. This saves real time and nobody gets hurt if it is wrong.

It summarizes. After a remote session or a long ticket thread, AI writes the notes. Documentation is the thing technicians skip when they are busy, and AI does not get busy.

It drafts. Scripts, patch risk assessments, customer replies. A technician still reviews before it runs or sends.

Notice what is not on that list. Actually fixing things on its own is a much smaller slice than the marketing suggests, and there is a good reason for that.

The part nobody wants to talk about

On 19 July 2024, CrowdStrike pushed an automated update to its security software. A defect in a single content file took down roughly 8.5 million Windows machines worldwide. Flights stopped. Hospitals went to paper. Banks froze.

The bad file was live for about ninety minutes before rollback. By then millions of machines had already pulled it down automatically. Parametrix later estimated 5.4 billion dollars in direct losses to US Fortune 500 companies alone, with healthcare taking the worst of it.

Nobody did anything wrong in the moment. The system worked exactly as designed. That is the point.

There is a second version of this problem that is closer to home. Remote management tools, the software providers use to reach into client systems, are a high value target precisely because they touch many businesses at once. ConnectWise ScreenConnect has had a run of serious vulnerabilities since 2024, including one rated 10 out of 10 that attackers used to push ransomware into managed environments. Another was added to the federal known-exploited list this month.

The lesson is not that automation is bad. The lesson is that anything designed to act across many systems at once is, by design, a single point of failure.

Where the line should sit

A provider using AI well draws a clear line between watching and acting.

On the watching side, automate freely. Detection, alerting, pattern analysis, ticket sorting, documentation. If the AI is wrong here, a human notices and corrects it. The cost of a mistake is a wasted minute.

On the acting side, be careful in proportion to what can break. Restarting a stuck print spooler is low risk and fine to automate. Isolating a server, killing a service, or pushing a kernel level patch to a hypervisor is not. Those need a person who understands your environment to say yes.

The major platforms mostly agree. NinjaOne's patch intelligence tool flags risky updates but states plainly in its own documentation that it cannot stop a deployment on its own and that administrators keep approval. That is the right instinct.

Some tools do go further and resolve routine tickets end to end. Password resets, account unlocks, standard requests. That is legitimate and useful, and it should come with an audit trail showing exactly what ran and why.

What good looks like

A provider handling this properly does a few specific things.

They start with detection and add automation slowly, one runbook at a time, beginning with the safest and most repetitive work.

They test automation somewhere safe before it touches your systems. The CrowdStrike failure was a global push with no staged rollout.

They scope automation per client rather than switching something on everywhere at once. Your environment is not identical to anyone else's.

They keep an audit trail. Every automated action logged with what it did and why, readable after the fact.

They put limits in place. A cap on how many automated fixes can fire in a short window, so a false positive cannot cascade.

They tell you what is automated. You should not have to find out during an incident.

Questions worth asking

If you want to know where your provider actually stands, these get you there quickly.

What runs automatically on our systems without anyone approving it first? Ask for the list.

Who reviews automated actions, and how fast? Can we see the log?

What happens when the automation is wrong? Is there a rollback, and is there a limit on how far a mistake can spread?

Is automation scoped to us, or does one change hit all your clients at once?

Does your AI touch our data, where is it processed, and is any of it used to train a vendor's model?

Can you explain, after the fact, exactly what an automated action did?

A provider who has thought about this will answer directly. One who has not will talk about their platform instead.

If you handle regulated data

Two things apply to a lot of Cincinnati businesses that do not think of themselves as regulated.

If you handle protected health information, your IT provider is a business associate under HIPAA and needs a signed agreement. So does any AI vendor in the chain behind them. Federal regulators proposed an update in January 2025 that specifically addresses AI as a risk factor and would require it to be included in your risk analysis. Enforcement has been active, with fines in 2025 running from 25,000 dollars to 3 million, almost all for failing to do a proper risk analysis.

If you are a non bank financial institution, and the federal definition is far wider than most people assume, the FTC Safeguards Rule requires you to oversee your service providers in writing. Adding AI tools without updating those agreements is a gap.

Neither of these is a reason to avoid AI. Both are reasons to ask where your data goes.

The short version

AI in managed IT is real, it is widespread, and used properly it means problems get caught earlier and resolved faster. Leading providers report meaningful gains in resolution time and technician capacity.

But the value is in the watching, not the acting. A provider who automates detection aggressively and automates action carefully is doing this right. One who cannot tell you where that line sits has not thought about it hard enough.

Networx IT Solutions is the West Chester managed IT provider serving Cincinnati, Northern Kentucky, and Dayton since 2006. We are independently owned and have never been acquired. If you want a straight answer about what runs automatically in your environment and what does not, that is a conversation we are happy to have.

Weekly newsletter
No spam. Just the latest releases and tips, interesting articles, and exclusive interviews in your inbox every week.
Read about our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.