Managed Services und KI Tools

AI Tools and Managed Services – now more than ever!

Artificial intelligence has definitely made its mark in the business world – including among SMEs. Microsoft Copilot helps with drafting emails and meeting minutes, whilst AI-powered tools analyse sales data, automate routine tasks or independently answer customer enquiries – 24/7, of course. The possibilities are impressively diverse – what sounded like a pipe dream not so long ago is now available and affordable for many SMEs.

What does the integration of AI tools mean for IT infrastructure? The fact is: as AI tools are adopted, the demands on IT operations and security are quietly increasing. AI does not make the IT infrastructure any simpler; on the contrary, it makes it even more complex. This is where a topic comes into play that, at first glance, has nothing to do with AI: the use of managed services. After all, anyone wishing to use AI productively whilst ensuring security, data sovereignty and regulatory compliance absolutely needs an IT infrastructure that can support and handle this. Managing this alone is often a challenge for SMEs.

AI tools must not be stand-alone solutions

Getting started in the world of AI sounds straightforward: buy a licence, activate the tool, and get going. In practice, however, things often turn out differently. Tools such as Microsoft Copilot access company data directly – emails, documents, calendars and Teams messages. This always requires that this data is clearly structured, stored correctly and securely, and assigned the appropriate access rights.

In many SMEs, however, this is precisely not the case. User rights have often grown ‘unchecked’ over the years and have never been streamlined. Documents are scattered across various locations, making them difficult to find. Outdated systems and unupdated software are running in parallel, creating security vulnerabilities that suddenly become far more significant with the use of AI tools.

A Managed Service Provider (MSP) ensures that the IT infrastructure is in order – and monitors it continuously, not just once during the initial setup: proper user rights management, structured data storage, and systems that are always up to date with the latest updates. These are not luxury considerations that can be overlooked. They are essential for the secure and profitable use of AI.

Data protection and compliance: AI processes data. But who is responsible?

AI tools process data – often highly sensitive data. Customer information, internal strategy documents and HR records, to name but a few. The crucial question that many SMEs have not yet asked themselves is: Where is this data processed? Where is it stored? Who has access to it? And, above all: Does all of this still comply with current data protection requirements?

When it comes to AI tools running in the cloud, this is a legitimate and serious question. This is because the major cloud providers – Microsoft Azure, Google and AWS – on whose infrastructure leading AI providers such as OpenAI and Anthropic rely, are all US companies and are therefore subject to the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018). This law obliges US companies to hand over customer data at the request of US authorities – regardless of whether the data is stored on servers in Switzerland, Europe or elsewhere. The server location therefore offers no protection. This creates a legal grey area that may conflict with the requirements of the revDSG.

An experienced MSP is familiar with these regulatory requirements and can help set up AI tools in such a way that they can be used in compliance with data protection regulations. This includes defining clear usage policies, using secure servers, choosing the right deployment options, and providing the documentation that may be required during an audit. For an SME without its own legal or compliance department, this represents enormous added value.

New tools, new vulnerabilities

With every new tool, a company’s attack surface also grows. Every additional interface, every new integration and every cloud connection is a potential point of entry for cybercriminals.

This threat must be taken seriously, as AI is, of course, not only used by businesses – attackers are also making extensive use of it. Phishing emails are now almost impossible to spot, attack patterns are automated and adapted in real time, and social engineering attacks are becoming increasingly convincing. For an SME that is in the process of introducing new AI tools whilst neglecting its security infrastructure, this is definitely a risk.

Nowadays, an MSP offering state-of-the-art security solutions relies on AI-powered threat monitoring – systems that do not simply search for known patterns, but detect anomalies in network behaviour before they cause any damage. This is a level of protection that an SME would struggle to establish and, above all, maintain on its own without external support.

Not just tools, but also guidelines

AI tools are transforming the way businesses operate. Whilst this brings efficiency gains, it also presents a challenge that is often underestimated: employees are frequently unsure about what they are and are not permitted to do with these tools. Am I allowed to enter customer data into an AI tool? Which information remains internal, and which leaves the company? Who is liable if an AI-generated statement is incorrect?

Without clear guidelines, grey areas arise that create both legal and security risks. A good MSP not only assists with the technical implementation but also with the development of usage guidelines (so-called AI Use Policies) that provide clarity for the company and its employees. This is not an additional administrative burden with no direct added value – it is the difference between controlled and uncontrolled use of AI.

The MSP as a bridge between IT and business strategy

AI projects in SMEs rarely fail because of the technology itself – rather, they fail because the IT infrastructure is inadequate or because the roll-out is not properly supported, either technically or in terms of staff training. A tool that is not properly integrated adds no value. Worse still, it causes frustration and creates extra work.

An experienced managed service partner thinks beyond mere IT operations. They understand their clients’ business processes and can assess which AI tools are appropriate, how they should be integrated, and what requirements need to be met. This strategic support is particularly crucial for SMEs that do not have their own IT department.

Conclusion: Implementing AI – a smoother process with the right support

The introduction of AI tools presents a real opportunity for SMEs to become more efficient and free up resources. However, it also places greater demands on the underlying IT infrastructure, data protection, security and the organisation’s expertise.

Any organisation that continues to manage its IT in-house as a side project risks losing precisely this foundation – and seeing the opportunity presented by AI quickly turn into a risk. A managed service provider ensures that the IT infrastructure not only runs smoothly, but is also ready for whatever comes next. And in the age of AI, experience shows that the next big thing arrives very quickly.

David Papale Primetrack AG
David Papale

Head Business Development
+41 61 500 04 10
david.papale@primetrack.ch

icon_datalynxgroup_colored-1png
Supplementary services of the Datalynx Group