Latest News & Blogs - cubesys

Your provider is running AI against your data. Now go and read your contract

Written by Paul Heaton | Aug 17, 2026, 11:33:33 PM

 

We reviewed our own master services agreement last week for any mention of artificial intelligence. There wasn’t one. Not AI, not machine learning, not automated decision-making. Nothing — in a contract governing a service that points AI at a client’s data from day one.

That is not an oversight we can blame on paperwork. It is the industry’s current position, written down.

Across the managed services market, providers have spent eighteen months adding AI to what they deliver — Copilot deployments, agents, automation, retrieval over client data — while the legal instrument underneath the relationship still describes a world of servers, patching and uptime. The service changed. The contract did not.

 

The waiver reflex

The industry’s first instinct, where it has an instinct at all, has been the waiver. Go to the client, say we are nervous about your use of AI, ask them to sign something releasing us from liability. That behaviour is common enough that it has already been named in the channel press as the losing move, in contrast with providers who instead sell a governed AI service and take responsibility for it.

I want to go a step past that critique, because “waivers are bad” is the easy part. The harder claim is this: a waiver is not a risk transfer. It is a hope.

Risk moves between two parties only when it is defined, scoped, priced and formally accepted by the party taking it on. A general release attached to an AI-silent agreement does none of those things. It does not define which AI systems are in scope. It does not say what the provider is monitoring and what it is not. It does not record what the client was told and chose not to act on. When something goes wrong — an agent surfaces data it should not have, an output is wrong in a way that costs money, a client’s staff feed confidential material into an unapproved tool through infrastructure you manage — an undefined release is exactly the document you do not want to be relying on.

And there is a second problem, which is the one that ought to worry providers more. Once you are genuinely operating at the front of AI, you can see your clients’ risks. You cannot then argue you did not know. If I can see the exposure and say nothing because the client has not bought a governance service from me, that is not a defensible position — legally or commercially.

 

What “seeing it” actually looks like

This is not abstract. In one mid-sized client this month — around 250 staff — a straightforward look at their environment produced the following picture: a single site holding 57% of all files (roughly 206,000 files and 878 GB); 367 guest accounts drawn from 119 external organisations, of which 106 had never once signed in; 16 Teams with no owner at all; and 13 open for any staff member to join, including live client engagements.

None of that was created by AI. All of it was harmless-ish while the only way to reach a document was to know it existed and go looking for it. Retrieval-based AI removes that requirement. It will cheerfully surface whatever it is permitted to read, to whoever asks, in seconds. Twenty years of accumulated over-permissioning stops being latent and starts being operational.

Their own explanation of how they got there is the most common story in the mid-market: “when this business was very small, the philosophy was everyone has access to everything. We’re many times the size now, but we still have this core central document library that everyone’s got access to.”

Here is where the boundary sits, and it is worth being precise about it, because this is the line between an MSP and something else. We can show you the position, and we can configure whatever you decide. We cannot tell you which roles in your business should see what. That judgement is yours and it always was. What we can do is refuse to leave you unaware of it.

 

Govern it, or transfer it properly

So the honest position, and the one we have adopted, has two branches and no third option.

Either the provider governs the risk — defines the AI in scope, monitors it, reports on it, and prices that work openly — or, where a client declines governance services, the risk is formally acknowledged and accepted by the client in writing, specific to what was actually disclosed. We are either governing the risk or explicitly documenting its transfer. What we are not doing is leaving it unnamed in a contract and calling that a position.

There is a reason this is uncomfortable to publish. Most providers are the ones handing out waivers, so critiquing the practice indicts them. And clients are not always keen either — as one client executive said to me this month, cutting through the whole subject: “policy can safeguard from people suing you, but it’s not going to solve your operational problem.” He is right, and that is the point. Contract language is the floor, not the answer. It buys you a defensible position; it does not buy you a governed environment.

Which is why the proof has to be external. We are putting our AI management system through ISO 42001 certification rather than writing our own assurances about ourselves (Stage 1 mid-August 2026, Stage 2 September 2026). This standard is growing quickly, but an AI search this week found fewer than 500 organisations worldwide are reported to hold it, and only about 30 in Australia. That scarcity is the point: it is currently a real differentiator rather than a box, and it will not stay that way.

 

The question to ask this week

If you are a business leader with an incumbent provider, you can settle most of this in a single afternoon. Open your managed services agreement and search it for the words “artificial intelligence.” Then ask your provider three questions: which AI systems are in scope of our agreement; what are you monitoring on my behalf and what are you explicitly not; and if my staff put confidential data into an unapproved tool tomorrow, through infrastructure you manage, whose problem is that?

If the answers arrive as a waiver, you have learned something useful. If they arrive as a scope, a monitoring position and an honest line about where your judgement takes over from their configuration, you have the beginnings of a real arrangement.

We are amending our own agreements this month. Not because a client demanded it, and not because a regulator has arrived — but because we can already see the risks, and once you can see them, silence is a choice.