Guide / IT & MSP
AI controls in a managed IT environment: twelve topics.
Recorded 18 July 2026. Facts in this guide are as of that date, or of the date stated beside them.
Corrected 28 September 2026 — this guide previously said carriers had been attaching AI exclusions at renewal since January 2026. Effective dates differ by state, as recorded in the AI Insurance Filings Index. Reworded on the same date: it was published as thirteen questions for a business to ask its IT provider, and is now a description of the topics.
This page describes twelve topics that arise between a business and its IT provider about AI use. It records what each topic covers and cites a public source where one exists. It makes no recommendation to any business or provider; legal and insurance questions are for counsel and a licensed insurance professional.
Scope of an IT provider
An IT provider administers the devices, networks and business tenant named in its agreement. Personal phones, home computers and tools the provider has not been told about sit outside that boundary. Which of the topics below fall inside a given agreement is set by that agreement.
The topics
Inventory of AI in use on managed devices and in the business tenant
Covers approved tools, AI features switched on inside existing software, and unofficial tools visible on managed equipment. Producing an inventory generally requires a discovery scan of the managed environment. Tools on unmanaged equipment are covered under topic 06.
AI features added to existing subscriptions
Software vendors have added AI features to existing products by update, among them assistants in office suites, CRM, accounting and help-desk tools. Whether such a feature is enabled is determined by the vendor’s default or by an administrator’s setting.
Vendor data terms and administrator settings
A vendor’s published terms state how it handles customer data. An administrator console exposes settings such as retention, training opt-outs and tenant boundaries. An IT provider can read the former and configure the latter; neither shows a vendor’s internal processing. The contract itself is a matter for counsel.
AI acceptable-use policy
An acceptable-use policy names approved and prohibited tools and sets data-handling rules. The policy is set by the business. Information about which tools are in use and which can be controlled comes from the systems the provider manages. Elements such policies commonly include are listed in FAQ Q.36.
Technical controls on AI tools
Common control categories are DNS and browser filtering, endpoint policy, tenant settings and application-approval workflows. Each applies only to the devices, networks and accounts it is configured on.
Personal devices and home computers
Controls applied to managed devices and networks do not reach personal phones or home computers. Measures that apply regardless of device include limits on which data staff can reach, the acceptable-use policy, and staff training.
Disclosure duties for customer-facing AI
Article 50(1) of the EU AI Act, applicable from 2 August 2026, requires AI systems that interact directly with people to be designed so that those people are informed they are interacting with AI, unless that is obvious from the context. A customer-facing chatbot may be built, hosted and operated by different parties: a web developer or agency, a software vendor, the business itself. Which party holds a duty in a given case is a legal question.
Regulation (EU) 2024/1689, Article 50(1) · applies 2 Aug 2026
Documentation at insurance renewal
AI exclusion endorsements have been filed with state regulators, with effective dates that differ by state, and they generally attach at renewal. Records that managed systems can export include an AI inventory, control settings and policy deployment records. What any policy covers is determined by its own terms, which this register does not read.
AI Insurance Filings Index, as of 28 Aug 2026
Visibility of unapproved AI use on the managed network
Detecting unapproved AI use depends on the logging and alerting in place. Some detection requires additional tooling, at additional cost.
AI in software vetting
Software evaluations can include questions on whether a vendor trains on customer data, which model provider it relies on, and whether its outputs carry provenance marks.
Agreement scope
Inventory work, policy support and additional controls may fall outside a standard IT support agreement. The agreement sets which are included and which are separately scoped.
Responsibilities of the business
Decisions on risk appetite, ownership of the acceptable-use policy and budget sit with the business. The provider implements technical controls within the agreed scope.
What this page records
Topics, not recommendations. The dated public records behind the facts above are the AI Insurance Filings Index and Regulation (EU) 2024/1689.