Field Effect CEO: MSPs Front And Center As AI Spreads Faster Than Customers Can Secure It
Field Effect CEO Matt Holland told MSPs attending the XChange 2026 conference that AI security is becoming a major MSP revenue opportunity as customers adopt AI faster than they can govern, monitor, or protect it.
AI security is becoming a major revenue opportunity for MSPs as customers race to adopt AI faster than they can govern or secure it.
That’s the message from Field Effect CEO and Founder Matt Holland who told MSP executives attending last week’s XChange 2026 conference that most businesses are already using AI, often through a mix of formal initiatives and employee-led experimentation, leaving those businesses unsure which tools are in use, who is using them, and whether sensitive data is being exposed.
XChange 2026 is owned by CRN parent company The Channel Company.
[Related: 13 Cool New MSP Tools For AI, Security And IT Operations]
In a recent Field Effect customer survey, Holland said 69 percent of respondents identified governance gaps, 69 percent cited employee awareness problems, and 67 percent said they believed they had shadow AI on their networks. Field Effect found more than 20 AI tools in use internally when it looked beyond the obvious platforms, he said.
“Ninety percent said they were using AI,” he said. “That, from an opportunity perspective, is much larger than I’ve ever seen in my career in any industry. But I think that number probably is even higher today. This is about two months old.”
That creates a clear opening for MSPs to help customers identify AI tools, understand where they are being used, determine what data is moving through them, and build policies and controls for safer adoption, Holland said.
Boards, executives and employees are all pushing AI adoption, creating pressure that is outpacing many customers’ governance models, he said.
“This causes a lot of emotion and a lot of people to make quick decisions because they don’t want to be left behind,” he said. “So I like to look at this as, it’s the pressure and the pace of adoption that’s really causing the problem.”
The security risk is rising as businesses give AI systems access to email, files, applications and processes without enough accountability, warning that AI tools can move large amounts of data or take unexpected actions unrelated to a user’s prompt, Holland said.
“It’s these problems that are creating opportunity for the MSP community because as we go forward, there will be more and more instances of AI doing things that perhaps they’re not asked to do, or outside of the realm of what you expect them to do,” he said.
Holland said AI is becoming both an internal governance challenge and an external attack surface as businesses deploy more tools, models, agentic AI systems, and software-defined infrastructure. Attackers, he said, can also use AI to tailor attacks, speed ransomware, and automate steps that once required hands-on intrusion work.
For partners, that means AI security must extend beyond prompt security and data leakage to include controls across processes, file activity, DNS, network behavior, and cloud tenants, he said.
“You really have to approach it from a holistic perspective,” he said. “It’s the only way to secure AI, considering AI is ubiquitous across networks. And I think about how much more extensive that deployment structure is going to look like five years from now.”
Holland said MSPs may help customers adopt AI and build AI workflows, but the larger opportunity is securing AI because every business will need it. He predicted compliance frameworks will increasingly force customers to address AI governance.
“Every business will need AI security if it isn’t adopted by choice,” he said. “I don’t think it’s going to be long before compliance frameworks carve out instructions about how you have to adopt AI or things you need to be aligned with. I think that is on the horizon.”
Looking ahead, Holland said agentic AI will make the challenge more complex as AI systems act across networks and applications, creating a continuing arms race between attackers and defenders and a long-term services opportunity for MSPs.
Holland’s key message, that AI is more than a buzzword, was spot on, said Ross Feldman, chief technology officer at Better Call IT, a Charlotte, N.C.-based MSP.
“We need to be protecting our clients against misuse of AI,” Feldman told CRN. “So we need to have the right tools in place for that.”
Feldman said his company’s customer base has a mix of clients that are AI curious and are anti-AI.
“We want to educate them as best as possible,” he said. “As Holland said, the threat is ever-evolving, but basically, we’re going to take up the challenge.”