Looking for a Shorter Overview?
AI Summary
Key Moments
New service marketplace for MSPs
EU AI rules create opportunities for MSPs to offer ongoing AI governance as a service.Phased introduction of the AI Act
The AI Regulation is being introduced gradually with different requirements at different times until 2028.The importance of clear boundaries of responsibility
MSPs must differentiate between technical support and legal advice in their services.Subscription models for AI monitoring
Ongoing checks and updates open up recurring revenue for MSP companies.The EU's AI regulation has entered a new phase of implementation. Pax8 sees an opportunity for MSPs to transform customers’ needs for AI governance, documentation, and risk management into recurring services. But providers need to separate technical support from legal advice.
The EU's AI regulation, the AI Act, mainly became applicable on August 2, 2026. At the same time, the EU Commission's AI Office and national authorities were given powers to monitor and enforce the parts of the regulations that are now in force.
For European companies, this means that AI governance can no longer be treated as a matter solely for the development or innovation department. Organizations need to know which AI systems they are using, what data the systems are processing and what risks come with their use.
Pax8 believes that this development is creating a new service market for managed service providers, MSPs. In a paper published on August 21, 2026, the company describes how partners can package AI governance as an ongoing service instead of a separate compliance project.
From AI inventory to ongoing monitoring
Many small and medium-sized businesses are already using generative AI, automated decision support, and AI capabilities built into cloud services. However, they often lack the personnel to map the systems and assess the risks.
According to Pax8, an MSP service for AI governance can include several parts:
- Inventory of AI systems and AI functions.
- Classification based on area of use and risk.
- Policies for permitted and prohibited uses.
- Documentation of models, suppliers and data sources.
- Division of responsibilities between IT, management and operations.
- Training and measures for AI literacy.
- Continuous monitoring, logging and reporting.
- Procedures for incidents and changes in AI systems.
- Regular risk assessments and checks.
The approach is similar to established MSP services in cybersecurity, identity management and compliance, except that AI governance also needs to address issues of transparency, human control, model behaviour and how data is used.
AI Act is being introduced in stages
The AI Regulation entered into force on 1 August 2024, but the provisions have been in force at different times. The bans on certain AI applications and the AI literacy requirements started to apply on 2 February 2025. The rules on governance and general purpose AI models followed on 2 August 2025.
The regulation essentially became applicable on 2 August 2026. At that time, the transparency requirements in Article 50 also came into effect. They include obligations related to AI-generated and manipulated content.
Following amendments through the EU AI Omnibus, certain rules for high-risk AI systems will be introduced later. Provisions for sensitive uses in Annex III will apply from 2 December 2027. For AI incorporated into regulated products, the corresponding date is 2 August 2028.
The organization's obligations depend, among other things, on whether it develops, provides, imports or uses the AI system, as well as on the system's risk classification and area of use.
Recurring revenue for the MSP market
Pax8's business case is that customers don't just need help with an initial inventory. New models, suppliers and AI features are added continuously. Even existing services can change through automatic cloud updates.
This opens up subscription-based services where the MSP company regularly checks the customer's AI environment, updates documentation and reports new risks.
For Nordic MSP companies, the service area may become particularly relevant among smaller organizations that are subject to European regulations but lack their own functions for AI governance, legal and risk management.
A possible offering could be combined with existing services within Microsoft 365, cloud security, data protection, information security and vendor management. Established frameworks such as the NIST AI Risk Management Framework can be used to structure the work around governance, mapping, measurement and management of AI risks.
Requires clear boundaries of responsibility
AI governance also introduces new risks for the service provider. An MSP should not promise that a customer will automatically comply with the AI Act simply by purchasing a technical service.
Agreements and service descriptions need to clarify:
- Which systems and areas of use are covered.
- What documentation the customer is responsible for providing.
- How often checks and reporting are carried out.
- Who makes decisions about risk acceptance?.
- When specialist legal expertise needs to be engaged.
- That technical documentation does not replace legal advice.
MSPs also need to ensure that their own use of automation and generative AI follows the same governance principles offered to customers.
Commercial but relevant channel trend
Pax8 is a commercial cloud marketplace and partner platform for MSPs, so the company has a clear business case for describing AI governance as a new revenue stream.
The message should not be considered an independent market forecast. However, it identifies a relevant channel trend: European AI regulation is creating a growing need for practical assistance with inventory, documentation, training and ongoing risk control.
For MSP market AI governance can thus develop into a service area that combines technical advice, security and business management.
