MSSPs, MSPs, and vCISOs

Clients are asking "what do we do about AI?": an answer for MSSPs

Sources verified Sanitized Ai Team

The short answer

Answer with a program, not a yes or a no. Find out which AI tools staff already use, agree on a short policy, sanction the tools the client will pay for, put data-level controls in the browser where prompts are typed, and report on it every month. Each step maps to frameworks the client may already track, such as the NIST AI RMF and ISO/IEC 42001.

The situation

The quarterly business review is nearly over when the client's managing partner, or CFO, or clinic director, asks the question: "Half our staff are using ChatGPT. What should we be doing about it?" Some people have a Microsoft Copilot licence. Others use free accounts on their phones and in a second browser tab. There is no written policy, or there is a one-page memo nobody has read since it was sent.

The client is not asking for a lecture on large language models. They want to know whether they have a problem, what a reasonable organization does about it, and what it will cost. The firewall, endpoint protection and email security you already manage were not built to see what someone types into a prompt box, so "we have you covered" is not an honest answer. If the client needs a primer first, what shadow AI is is a useful starting point.

This guide gives you a structured answer you can deliver in that meeting and then turn into a scoped engagement.

What the rules actually say

For most private-sector clients in Canada, no single law says "do this about generative AI". What exists is a set of frameworks and guidance that describe what reasonable looks like, sitting on top of the privacy and professional duties the client already carries. Tell the client which of these are binding and which are voluntary.

  • NIST AI Risk Management Framework. The AI RMF 1.0, released in January 2023, is voluntary and written for organizations that design, develop, deploy or use AI, not only for developers. Its Govern function includes an inventory of AI systems (GOVERN 1.6), AI risk training for personnel and partners (GOVERN 2.2), policies for risks from third-party AI and data (GOVERN 6.1), and ongoing monitoring and periodic review (GOVERN 1.5). NIST's Generative AI Profile (July 2024) lists data privacy, including leakage and unauthorized disclosure, and intellectual property among the risks particular to generative AI.
  • ISO/IEC 42001. Published in December 2023, ISO/IEC 42001 sets requirements for establishing and maintaining an AI management system in organizations that develop, provide or use AI. It is voluntary.
  • Canadian privacy regulators. The federal, provincial and territorial privacy commissioners issued joint principles on generative AI in December 2023. They are not binding, but they suggest organizations prefer de-identified information in prompts and enter personal information only where authorized.
  • Canadian Centre for Cyber Security. Its generative AI awareness guidance recommends that organizations set policies on how AI is used and that staff avoid entering personal or proprietary business information.

The duties that bind are the ones the client already has: privacy law such as PIPEDA or Quebec's Law 25, sector regulation, and professional codes for lawyers, accountants and clinicians. Encourage the client to confirm the specifics with counsel or its regulator.

Why policies and bans fall short

A policy on its own is a document. It tells people what not to do, but it does not act at the moment someone is about to paste a client spreadsheet into a chatbot at six in the evening. According to IBM's 2025 Cost of a Data Breach Report, 63% of organizations had no AI governance policy at all, so writing one is a real step. It is just not the last one.

Blocking AI sites at the firewall has the opposite problem. Staff move to personal accounts, phones and home networks, which removes the little visibility the client had. Category blocking also cannot tell the difference between a harmless request and one that carries a client's financial records.

Neither approach deals with irreversibility. Once content is submitted to a public AI tool, it cannot be recalled. It becomes subject to the provider's terms, which can permit retention, sub-processing and in some cases training. A control that only reports after the fact leaves the client with an incident, not a prevented one.

What a practical control looks like

Present the answer as five steps the client can see and budget for.

  1. Discovery. Spend two to four weeks finding out which AI tools are actually in use and by which teams. Combine DNS or proxy data, SaaS discovery, a short staff survey and browser-level telemetry. This is the inventory the NIST AI RMF points to.
  2. Policy. Agree on a short acceptable-use policy: approved tools, the data types that never go into a public tool, and who to call after a mistake. The AI acceptable use policy generator is a reasonable draft to adapt.
  3. Sanctioned tools. Help the client choose the enterprise AI tools it will pay for, and review their data terms as part of third-party risk. Staff need an approved path, or they will find their own.
  4. Data-level controls at the browser. Most AI use happens in a browser tab. Put a control there that coaches people at the prompt, and redacts or blocks sensitive data before submission, on sanctioned and unsanctioned tools alike.
  5. Monthly reporting. Report which tools are in use, what was caught, which teams need coaching, and what to change next. A sample client AI risk report shows what that can contain.

Add an incident path alongside these: when someone reports that sensitive data was submitted, who assesses it and how the client's privacy obligations are handled.

Sanitized Ai is one way to deliver step four and feed step five. It is a browser extension for Chrome, Edge and Firefox that detects sensitive data (client names and identifiers, personal information, health and financial data, source code, deal terms) in AI prompts and file uploads, then redacts or blocks it before submission. The person sees a plain-language explanation of what was flagged and why, so each near-miss becomes a short piece of training. Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) that never shows prompt content, which gives you audit-ready records for the monthly review without reading anyone's prompts.

If you want to discuss using Sanitized Ai with your clients, get in touch through the intake form.

Frequently asked questions

Is there a Canadian law that requires a private business to have an AI governance program?

Not a general one. The proposed Artificial Intelligence and Data Act was part of Bill C-27, which did not pass before Parliament was prorogued in January 2025. Existing privacy law, sector rules and professional codes still apply to what staff put into AI tools, so the client should confirm its obligations with counsel.

Does the client need ISO/IEC 42001 certification?

Usually not to get started. ISO/IEC 42001 is a voluntary management-system standard, and certification is a business decision for clients whose own customers or regulators ask for it. Most clients get more value from using its structure as a checklist while the basic controls are put in place.

The client already bought Microsoft Copilot or ChatGPT Enterprise. Is that enough?

A sanctioned tool is a good step because it gives staff an approved option with contractual terms. It does not stop someone from pasting client data into a personal account in another tab, and it does not by itself tell the client what sensitive data is being shared. Data-level controls and reporting cover that gap.

Does monitoring AI use mean reading employees' prompts?

It does not have to. A control that records event metadata (which tool, what type of data, which policy, when) gives the client evidence without anyone reading what staff typed. The client should still tell staff what is recorded and check employee monitoring rules in its province with counsel.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

Standards that apply

Related guides

Further reading