Key Takeaways
- AI is making scams more convincing, but the fundamentals of security haven’t changed. Slowing down, verifying requests through trusted channels, and following established security processes can protect users even when AI-generated content is difficult to detect.
- MSPs have an opportunity to become their clients’ trusted AI educators. Instead of leading with fear, MSPs can help clients understand how to use AI safely, where the risks are, and what guardrails they should put in place.
- Using AI effectively requires both curiosity and human oversight. Push AI tools to see what they’re capable of, but remember the key rule: If you can’t inspect the outcome, you can’t guarantee the quality.
AI is moving fast. (Groundbreaking information, we know.)
But keeping up with AI today can feel like finally figuring out what a tool can do, only to wake up three months later and discover it can now build a presentation, analyze a spreadsheet, write code, clone a voice, organize your inbox, and probably do that one task you’ve been avoiding since Tuesday.
For MSPs, that’s exciting. It’s also a little complicated.
Because while AI is creating enormous opportunities for businesses, it’s simultaneously making scams and social engineering attacks easier to personalize, automate, and scale. The advice we give people about identifying those threats has to evolve just as quickly.
That’s exactly what Empath Co-Founder, Wes Spencer, and I discussed during our recent webinar: AI Changed the Attacks. Here’s How to Change Your Defense. Plus, what that means for MSPs, and why MSPs have an opportunity to become trusted AI educators for their clients.
Here are some of the biggest takeaways.
AI Has Changed Faster Than What We’re Teaching
Remember when one of the easiest ways to spot an AI-generated image was to count the fingers?
That advice had a pretty short shelf life.
I’ve given a deepfake presentation the last few years and every year the technology has improved. Techniques people were taught just a year ago—like looking for extra fingers, strange visual glitches, or objects behaving unnaturally—can quickly become obsolete as the models improve.
That’s the bigger problem with teaching people to recognize specific signs of AI.
If your entire defense depends on spotting what AI looks or sounds like today, you’re preparing people for a threat that’s already changing.
Instead, security needs to focus on behaviors that still work regardless of how convincing the technology becomes.
Before we get to those, though, there’s another challenge MSPs need to consider.
Your clients may be further behind than you think
If you work in IT or cybersecurity, you’re surrounded by AI. You’re testing new tools, you’re hearing about agents, and you’re probably in at least one Slack channel where somebody announces a “game-changing” AI tool every 36 hours.
But your clients may be having a very different experience.
Wes shared that even some large MSPs attending a recent workshop rated themselves at zeroes and ones out of five when evaluating their client-facing AI capabilities. MSPs may be adopting AI internally, but many are still figuring out how to guide clients through it.
Meanwhile, those clients aren’t necessarily waiting around for guidance. They’re already using ChatGPT and other AI tools. Their employees are experimenting to find ways to make their jobs easier. So, the opportunity isn’t necessarily to introduce your clients to AI. It’s to help them understand how to use it safely, effectively, and with slightly more strategy than, “I pasted our entire customer database into this thing and asked it a question.”
The Biggest AI Threat Isn’t Necessarily the Tool Itself
AI is giving attackers some shiny new toys, but many of the fundamentals behind successful attacks haven’t changed much.
Attackers still rely on:
- Urgency
- Authority
- Fear
- Trust
- Personalization
- Getting someone to act before they stop and think
AI can simply make those tactics much more convincing.
During the webinar, Wes shared a story about someone he knew who received a phone call supposedly from local law enforcement. The caller claimed there was a warrant out for the person’s arrest because they’d failed to report for jury duty. They knew the person’s name, business information, address, and other details. They referenced supposed local laws and statutes. They sounded legitimate and, most importantly, they created urgency.
The victim ultimately sent a significant amount of money. For a small business owner with roughly 15–20 employees, the financial impact was severe enough to set the business back months.
Publicly available information was already out there. Impersonation scams and social engineering aren’t new tactics, but AI makes it increasingly easy to assemble information, personalize an attack, and create something believable at scale.
So, not only is it harder to “spot a fake” but we are also being threatened more frequently than before, which means there’s even more opportunities for human error.
The Best Defense Against AI Scams is Surprisingly Low-Tech
For all the sophisticated technology involved in modern cyberattacks, some of the most effective defenses remain incredibly boring. (I mean that as a compliment.)
If your bank calls you about something suspicious, hang up. Go to the bank’s official website and call the number listed there.
Establish a family verification word that can’t be found by scrolling through your family’s facebook profiles so that if a family member suddenly calls saying they’re stranded somewhere and desperately need money, you can easily verify it’s them.
I suggest something random and memorable, like “purple hippo.”
Sure, “purple hippo” might not sound like a cutting-edge cybersecurity solution, but if it prevents Grandma from wiring $5,000 to Fake You, “purple hippo” has earned its place in the security stack.
The same principle applies to businesses.
If someone requests a wire transfer, follow the company’s approval process. Contact the supposed requester through a known channel and get the required second approval. Take the extra five minutes.
As we pointed out during the webinar, many instances of financial fraud could be prevented if organizations simply had clear policies that humans actually follow.
You don’t necessarily need to determine how the scam is being done, you just need to know that it is a scam, even if it looks or sounds extremely real.
When Someone Creates Urgency, Slow Down
Attackers want you reacting instead of thinking.
That’s why you see messages like:
- PAY THIS INVOICE IMMEDIATELY.
- YOUR ACCOUNT WILL BE DELETED IN 30 MINUTES.
- THE CEO NEEDS $8,000 IN APPLE GIFT CARDS AND APPARENTLY THIS IS COMPLETELY NORMAL.
Urgency shortens the amount of time you have to question what’s happening.
A super basic but very effective recommendation that Wes recommended during the webinar was this: when that pressure hits, pause and think through what actually happens if you don’t act immediately.
If someone claiming to be law enforcement says you’ll be arrested unless you send money right now, stop the interaction. Verify it independently.
If your “CEO” needs a wire transfer in the next four minutes or the entire company will somehow implode, call them.
Breaking the attacker’s sense of urgency gives your brain time to catch up, which is a security behavior that doesn’t become obsolete when the next AI model launches.
AI Risk Can Come From Inside the Business, Too
There’s another side of AI security your MSP needs to help clients understand.
Not every AI-related data breach starts with a hacker in a hoodie furiously typing in a dark room. Sometimes it’s Steve from accounting trying to be productive.
Employees are being encouraged to use AI to work faster. That’s not inherently a bad thing, and in many cases, it’s exactly what businesses should be encouraging.
It’s a problem though when employees don’t understand what information they’re giving these tools or where that information can go.
During the webinar, we discussed scenarios where employees upload sensitive company information into AI environments without understanding how those environments are configured or who else might have access.
That’s why “don’t use AI” isn’t a useful policy. For one, people are going to use it anyway.
Instead, businesses need guidance around questions like:
- What information can employees share with AI tools?
- What information should never be uploaded?
- Which AI tools are approved?
- Who can access shared workspaces?
- Which AI-generated outputs need to be verified by a human?
- When should an employee stop and ask someone before proceeding?
The goal isn’t to scare people away from AI. It’s to make sure “work smarter, not harder” doesn’t accidentally become “upload the company’s most precious data and hope for the best.”
MSPs Have an Opportunity to Become AI Educators
This was one of the biggest themes of the entire conversation.
You don’t have to know everything about AI. Good news! Nobody does. You just need to know enough to help your clients take the next step.
Wes described education as an opportunity for MSPs to build trust and relevance with their clients. That can mean keeping up with what’s happening in AI, talking about both the opportunities and the risks, creating newsletters, speaking at local events, conducting assessments, or simply bringing new ideas into regular client conversations.
You don’t have to (and shouldn’t) walk into a QBR and announce:
“Greetings. I am now your Artificial Intelligence Thought Leader.”
You can simply say:
“Here’s something new we’re seeing. Here’s why I think it matters to your business. Here’s what you might want to consider doing about it.”
That’s education.
And it creates an opportunity for MSPs to become the person clients call before making technology decisions instead of the person they call afterward to clean them up.
If you don’t have the AI conversation, somebody else might.
Wes shared an example of an MSP that learned this lesson the hard way.
One of its clients decided to adopt an “AI-first” philosophy and found another provider to lead its AI strategy. That provider would then find the necessary technical support to implement it.
The MSP’s response was essentially, “Wait, we could have helped you with this.”
Unfortunately, by then, the client had already moved on.
Clients aren’t necessarily separating “AI strategy” from “technology strategy.” So, if another provider becomes the trusted advisor for one, they may eventually become the trusted advisor for both.
Two Rules for Getting Better at AI
I have two final pieces of advice that are useful whether you’re an MSP, business owner, technician, marketer, developer, or person who occasionally asks ChatGPT to rewrite an email so you sound less annoyed.
1. Get comfortable asking for more
AI tools are evolving so quickly that you can’t assume their limitations today are the same limitations they had three months ago.
So experiment. Ask the tool to do something you’re not sure it can do and then ask for more. Then ask it to improve what it gave you and question why it made the decisions it did.
Curiosity itself is becoming a skill, because you’ll never know where the limit is unless you keep pushing against it.
2. If you can’t inspect the outcome, you can’t guarantee the quality
AI can generate an answer remarkably quickly, but it doesn’t mean the answer is remarkably correct.
The amount of scrutiny required should depend on the consequences of getting it wrong.
Ask AI who won the World Series in 1987 and it gets the answer wrong? Annoying, sure. But not the end of the world.
Ask AI to analyze your financials and it accidentally double-counts something before you make a massive business decision? Much bigger problem.
As I said in the webinar, if you don’t have the ability to inspect the outcome, you don’t have the ability to guarantee the quality.
AI doesn’t eliminate the need for expertise. In many situations, expertise is what allows you to determine whether the incredibly confident answer AI just handed you is brilliant or complete nonsense.
You Don’t Need an Entire AI Strategy to Start
If all of this sounds like another enormous thing you now have to figure out, there’s good news.
Your first step is simple. Call one client, friend, relative, or other person you trust and ask:
How are you using AI right now?
That’s it.
Find out what they’re doing, ask what they think AI could do for their business, ask what they’re worried about, ask where they’re struggling, then see if there’s one useful thing you can teach them.
You don’t need to walk into the conversation with a 47-page 2027 Artificial Intelligence Strategic Transformation Roadmap™.
Have conversations and repeat them across your client base. You’ll start getting a much clearer picture of where your clients actually are—and where you can help.
Be the Person Helping Clients Make Sense of AI
AI is going to keep changing. The things we thought AI couldn’t possibly do will become things we’re annoyed it doesn’t do faster.
You don’t need to predict every development, but as an MSP, you have an opportunity to help clients understand what’s happening around them, experiment safely, establish sensible guardrails, verify what matters, and prepare for what’s next.
And that’s ultimately what we kept coming back to throughout the webinar.
Don’t lead with fear. Lead with education.
You don’t need every answer. You just need to keep learning, and help your clients do the same.
Want the full conversation? Watch the webinar to hear us dive deeper into AI, cybersecurity, client education, and what all of this means for MSPs.

