Black-Box AI Won't Survive Client Diligence

5 min read strategy
By

Simon Chappel, CEO of Assured Data Protection, made a prediction for 2026 that reads less like a forecast and more like a procurement memo: “Organizations will no longer tolerate black-box AI.”

The interesting part is where that intolerance shows up first. Not in regulation, and not in public opinion. In vendor diligence, where it’s already happening.

The questionnaire is coming for everyone

Vendor risk assessment has a gap you could drive a truck through. Grip Security’s research found that 98 percent of organizations use SaaS applications with embedded AI, while fewer than 30 percent have any formal process for assessing AI vendor risk. For a few years that gap was invisible, because nobody was asking.

Buyers have started asking. Security questionnaires that spent a decade fixated on encryption at rest and SOC 2 scope now carry new sections: which AI models process our data, is our data used for training, who reviews AI-influenced decisions, how do we opt out. The companies sending those questionnaires mostly can’t evaluate the answers yet. That doesn’t matter. A vendor that can’t answer at all fails the smell test, and in a competitive deal, the vendor with clean answers wins the tiebreak.

This is how SOC 2 spread. Not because every buyer understood trust service criteria, but because asking for the report became free and not having one became expensive. Explainability is on the same path, moving from compliance checkbox to sales objection.

The certification wave has started

The standard emerging under this is ISO/IEC 42001, the first international management system standard for AI governance. It covers the unglamorous machinery: AI risk management, transparency requirements, human oversight, lifecycle monitoring. Certification signals that a vendor’s AI usage is documented and governed rather than improvised.

Watch who’s getting certified. Presidio, a global IT solutions integrator, announced its ISO 42001 certification on July 15, 2026. Its CISO, Greg Hedrick, framed the point precisely: the certification confirms that AI initiatives “are not ad hoc experiments” but run inside a management system.

When a company that size certifies, it isn’t chasing a plaque. It’s answering questions its enterprise customers already ask, and it’s setting the bar its competitors will be measured against. Requirements like this roll downhill. The integrator certifies, then the integrator’s procurement team starts asking its own suppliers, and within a couple of budget cycles the questionnaire lands on the desk of a 40-person MSP that has never inventoried its own AI usage.

Regulation reinforces the direction without driving it. The EU AI Act’s transparency obligations take effect in August 2026, even after the omnibus agreement deferred the high-risk system deadlines to December 2027. Any client with European customers, parents, or partners inherits those expectations early.

MSPs sit on both sides of this

For an MSP, the black-box problem cuts in two directions, and both of them are worth money.

The first direction is defensive. Your own stack is full of AI now: RMM platforms with AI features, ticket triage automation, documentation assistants, the Copilot licenses your own engineers use against client environments. When your client’s new CFO orders a vendor review, or their cyber insurer sends the renewal questionnaire, you are the vendor being diligenced. An MSP that answers the AI section with silence or hand-waving is inviting a competitor into the account.

The fix is cheap relative to the risk. Inventory the AI in your own delivery stack. Write the data-flow statement for each tool: what client data it touches, where it goes, whether it trains anything. Put human oversight in writing for anything that acts on client systems. Package it as a one-page AI transparency summary that rides along with your standard security documentation. The first time a client’s auditor asks and you hand it over the same day, you’ve converted a threat into proof of maturity.

The second direction is the revenue line. Every client you serve that sells into larger companies is about to face the same questionnaire, with less preparation than you have. The mid-market manufacturer with two AI-enabled products, the law firm quietly using a research assistant, the healthcare group whose intake team lives in a chatbot: none of them can currently answer what models they use and what data flows in.

Diligence readiness is a packageable service. AI inventory, data-flow mapping, policy drafting, questionnaire response support, and a path to ISO 42001 alignment for clients whose buyers will eventually demand it. The skills are the ones MSPs already use for SOC 2 prep and cyber insurance applications. The subject matter is new; the motion is not.

Transparency as a wedge

There’s a competitive reading of this that goes beyond defense. In any deal where you’re up against another MSP, the AI section of diligence is now a place to win.

Most of your competitors will treat AI questions the way vendors treated security questions in 2015: something to get past rather than something to lead with. If your proposal includes your AI transparency summary unprompted, names the AI in your stack, and explains the oversight around it, you’ve reframed the conversation. The prospect’s takeaway is that you run a tighter shop, and the incumbent suddenly has questions to answer it never prepared for.

Chappel’s prediction will look obvious in two years, the way “buyers will demand SOC 2” looks obvious now. The window that matters is the one before it becomes obvious, when transparency still differentiates because most vendors can’t produce it on request.

Black-box AI isn’t a technology problem for the MSP market. It’s a trust problem, and trust is the product MSPs have always actually sold. The ones that document theirs first will take deals from the ones that didn’t.

Frequently Asked Questions

What does 'black-box AI' mean in a vendor diligence context?

Any AI capability a vendor can't explain in operational terms: what models are in use, what data flows into them, where that data goes, what decisions the AI influences, and what a human can override. When a security questionnaire asks those questions and the answer is 'we're not sure, it's built into the product,' that's a black box, and increasingly it's a lost deal rather than an awkward moment.

What is ISO 42001 and why does it suddenly matter?

ISO/IEC 42001 is the first international management system standard for AI governance, covering risk management, transparency, and human oversight across the AI lifecycle. It matters now because it's showing up in procurement. Enterprise buyers are adding it to vendor requirements the way SOC 2 spread a decade ago, and service providers are getting certified to stay ahead of it. Presidio, a global IT solutions integrator, announced its certification in July 2026.

How does an MSP answer AI questions on a client's security questionnaire today?

Build the answers once and reuse them: an inventory of AI in your own stack (RMM AI features, ticket-triage automation, AI assistants your techs use), a data-flow statement for each, your acceptable-use policy, and named human oversight for anything client-facing. An MSP that can hand over a one-page AI transparency summary alongside its SOC 2 report turns a diligence risk into a differentiator.

Back to blog