MSP AI Disclosure — The Standing Answer Sheet
Audience: managed service providers (MSP / MSSP) who want to answer the AI-governance questions before a client, auditor, or insurer asks them.
Why this exists. Your clients are starting to ask what AI is running in their environment, who it reports to, and what happens when it misfires — and the questions arrive first through cyber-insurance renewals, then audits, then regulation. Fixing this client-by-client means re-papering a whole book of agreements. This is the way around that: one standing AI Disclosure, filled in once and refreshed quarterly, that your service agreement references by incorporation. New contracts carry the reference from day one; existing ones pick it up at renewal. One artifact instead of two hundred amendments — and handing it over unprompted during procurement makes you look categorically different from a provider who has to go find out.
How this pairs. This is the answer artifact. The MSP AI Trust Questionnaire is the assessment instrument your clients use — the ten questions this document answers in advance. Each section below is tagged with the client question it resolves.
How to use this — for providers
- Fill every field with your real, current facts. Where a control isn't in place yet, say so plainly and note the plan — an honest "not yet, here's the compensating control and the date" reads better than a dodge.
- Make each answer inspectable. A claim resolves to a control, an artifact, a named owner, and a date. "We have a kill switch" is not an answer; the procedure, its scope, the authorized owner, the time-to-effect, and the last-tested date is.
- Reference it from your service agreement by incorporation ("Provider's current AI Disclosure, published at <URL>, is incorporated into this agreement"). Refresh it quarterly and whenever your platform vendor ships a material AI change.
- Hand it over during procurement. Unprompted. It's a trust asset, not a compliance chore.
Honest limits: completing this Disclosure is not a certification and does not by itself make you or your client compliant; it is a transparency and accountability artifact. It is not legal advice — have counsel review the incorporation language.
The disclosure
Provider: [ legal entity name ] Version / date: [ vX.Y · YYYY-MM-DD ]
1. AI features active in client environments
answers client question 1
Strong disclosure: distinguishes AI features from ordinary automation, and states how you learn when your platform vendor turns a new one on.
2. Change control over platform-vendor AI releases
answers client question 2 · non-negotiable
Strong disclosure: for cloud-delivered platforms, states plainly whether releases arrive automatically, and what control you do or don't have over them.
3. Approval process — and where the client enters it
answers client question 3
4. Per-client / per-endpoint vs. global controls
answers client question 4
Strong disclosure: if per-client scoping isn't available yet, say so and name the compensating control.
5. Evidence artifacts you produce
answers client question 5
6. Human review before execution
answers client question 6
7. "Kill switch" — scope, time, owner, last tested
answers client question 7 · non-negotiable
Strong disclosure: a switch that only stops future invocations — or one that can only be thrown platform-wide — is disclosed as such, not called a per-client kill switch.
8. Data egress — recipients, terms, retention, training
answers client question 8 · non-negotiable
9. Breach notification — in hours
answers client question 9
Strong disclosure: gives a number, not "promptly." The client's own regulatory clock runs regardless of the vendor→provider→client relay.
10. Named accountable owner
answers client question 10
Right to decline
If you are a security provider (MSSP) — autonomy inventory
How to incorporate this by reference
Add a clause to your service agreement rather than restating this document inside it, for example:
Provider maintains a current AI Disclosure describing the AI operating in
Client environments, published at <URL> and refreshed no less than quarterly.
That AI Disclosure is incorporated into this Agreement by reference. Provider
will notify Client of material changes to it.
Have your counsel review and adapt the wording. New agreements carry the reference from day one; existing agreements pick it up at renewal.
Guardrails honored
- Not a certification — publishing this Disclosure attests transparency, not compliance or safety.
- No guarantee of outcome. It records what you disclose; it does not warrant a result.
- The subprocessor list, example artifact, and by-reference addendum are good practice to adopt — describe your real, current state, and note where something isn't in place yet.
Sources
- OWASP GenAI Security Project, *OWASP Top 10 for Agentic Applications (2026)* (ASI01–ASI10) — https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
- Cloud Security Alliance, *The Agentic Trust Framework* (Feb 2, 2026) — https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents
- Cunningham, C. *Agentic Zero Trust* v3.0 (May 2026), Cequence — https://www.cequence.ai/agentic-zero-trust/
- NIST, *AI Risk Management Framework (AI RMF 1.0)* — https://www.nist.gov/itl/ai-risk-management-framework