AI MSP INDEX

Automation Arbitrage: Why the AI-Native MSP Is a Pricing Question, Not a Margin One

The agentic pitch to MSPs is a margin story. Written the other way round, the same equation is a disintermediation story.

The AI MSP Index · Chris Hurn · 17 August 2026


The pitch

Everyone leading an MSP has now heard some version of this:

Labour is your largest controllable cost. Agents can triage tickets, investigate alerts, remediate endpoints, run onboarding, generate documentation and close routine work without a technician touching it. Monthly recurring revenue does not change. Cost to service the agreement falls. Gross Margin climbs and drops through to Net Profit.

The Math’s checks out. However there is a question hidden within that:

If the work no longer requires the MSP’s labour, and the Agents doing the work are a third party platform, what is the customer paying the MSP for?

Is there a risk that the automation sold to MSPs as a margin expansion tool, applied successfully, erodes the economic reason the MSP sits between the customer and the technology?

Will there be a disintermediation of the market?

Short answer, for anyone who wants it before the long answer.

An AI-native MSP is built around AI agents as the primary way work is acquired and delivered, rather than bolting AI onto existing operations.

Becoming one produces a real and immediate margin gain. That gain is an arbitrage rather than a structural advantage, because the capability is purchasable, competitors reach it, platform vendors ship it natively, and customers eventually access it directly.

The durable question for an AI-native MSP, or indeed any MSP exploring AI, is not how much labour it can automate. It is what remains inside its value wedge afterwards, and whether per-user pricing can still measure it.


The wedge has been narrowing for twenty years

Lets frame what an MSP sells as a wedge of value inserted between a customer and a set of technologies the customer cannot operate alone.

Customer
   |
   |  MSP value wedge
   |  advice, architecture, implementation, integration,
   |  monitoring, administration, troubleshooting,
   |  remediation, security
   |
Technology vendors

In the first era that wedge was thick, and it was built on scarcity. IT was genuinely complicated, no small business could employ every skill it needed, and the MSP aggregated expertise across a customer base. Somebody had to know how to size, install, patch and rescue an Exchange server. Very few customers could hold that knowledge internally, so they rented it.

Cloud and SaaS removed a large part of that work. Nobody needs an MSP to maintain an on-premises mail server now. On the face of it this could have been an extinction event.

It was not, because SaaS replaced one problem with another. Customers accumulated Microsoft 365, identity, endpoint management, security, backup, networking, a growing list of line-of-business applications, and compliance obligations attached to all of it. The scarce skill stopped being installation and became coordination.

So the wedge changed shape rather than disappearing. It moved from owning technical knowledge to managing fragmentation.

Clients digitised more and more of their organisation into cloud apps, creating and storing more data than ever before, data that was and is valuable. MSPs extended their wedge into the opening security gap.

MSPs have absorbed structural change to the forces changing their customers needs already and are still here. The question this piece asks is whether this shift has the same shape as the first two, or whether it acts on a different part of the business.


The stack quietly outsourced the MSP

To support the challenges of carrying ever more niche skills to manage the fragmentation and security MSPs began the introduction of tools to the stack that simplified or outsourced elements of the in-life services being provided to clients.

RMM automated monitoring. EDR vendors absorbed endpoint security expertise. Backup platforms absorbed backup expertise. Email security platforms took mail security. SOC and MDR providers took the majority of security monitoring. Documentation systems structured the knowledge that used to live in senior technicians’ heads.

Each of those decisions was individually correct. Each one was also a small transfer of expertise out of the MSP and into a vendor. The MSP stayed valuable because somebody still had to select the stack, connect it, run it, and supply the human labour moving between the systems.

Each tool being introduced was also a small transfer of expertise out of the MSP and into a vendor, leaving a fair description of the modern MSP:

A coordination layer sitting above a collection of increasingly capable specialist vendors.

Over this period revenues have kept rising, primarily from an expansion in customer demand, and customer environments kept getting more complicated. Growth is very good at concealing structural change.

Meanwhile the commercial position got harder from both directions at once:

Vendors  -->  MSP  <--  Competitors

Upstream, Microsoft, the security vendors, the PSA and RMM vendors and the distributors capture an increasing share of the economics. Downstream, a market with low barriers to entry competes the rest away. The standard response has been scale: standardise the stack, raise technician utilisation, tier the service desk, offshore where sensible, automate the repetitive work.

The Australian MSP market is USD $6.5 billion and growing at 6-7% per year. The US MSP and MSSP market runs to roughly USD $161 billion in annual revenue, growing 7 to 8% a year, spread across more than 80,000 providers. The market is experiencing growth and fragmentation at the same time, which is the standing precondition for the consolidation that is occurring through the roll-ups being seen by permanent capital players and Private Equity attracted by the recurring revenue.

In this consolidating market there are four pressures on MSP profitability:

  1. vendor bargaining power, particularly Microsoft’s;
  2. the cost of retaining scarce talent;
  3. rising client demands on security and compliance; and
  4. a collapse in differentiation, because most providers offer similar services with limited adjustments for those who focus on a particular vertical or technology set.

The fourth pressure is the one that matters most to this argument. If the offering is already undifferentiated, an efficiency gain available to every competitor is not a competitive position. It is a temporary lead in a race everyone is running with homogenous opportunity and resources.

Agentic AI is the next item on that list of pressure points.


The question is not whether to automate. It is where the agent sits

Picture an MSP deploying an agent that can run the full loop:

Customer request -> investigate tenant -> diagnose -> remediate -> document -> close

Early on this is excellent. The MSP owns the agent, the MSP captures the productivity gain, and the customer sees faster resolution. Nothing about that is a trap.

The question is what the chain looks like after three or four years of maturation, once the agent understands Microsoft 365, Intune, Defender, identity, endpoints and the main SaaS applications directly through their APIs.

Customer -> MSP -> Agent -> Vendor

begins to resemble:

Customer -> Agent -> Vendor

The MSP will have automated a meaningful share of the complexity that justified its position in the middle. That is the disintermediation risk, and it is not hypothetical.

Who is best positioned to build that agent?

An MSP can build a very good Microsoft 365 support agent.

But Microsoft has the product telemetry, the identity layer, the APIs, the documentation corpus, the security platform, the support case history and the Copilot surface the user already has open.

The same asymmetry repeats at every layer of the stack. Whoever owns the platform owns the data the agent learns from and the interface the agent lives in.

The effect is already visible at the security layer, where AI-native cybersecurity firms are selling directly to end customers rather than through the MSSPs that historically owned that relationship.

The technology that today lets an MSP say we can serve more customers with fewer technicians is the same technology that later lets a vendor say we can serve that customer directly, and lets the customer ask why am I paying per user for someone whose agent manages software that ships with its own agent?

The Index’s catalogue of AI tools for MSPs contains a working example from inside twelve months. zofiQ was an independent AI agent product for MSP service desks. ConnectWise acquired it, announced 20 January 2026; the domain now redirects to the ConnectWise platform and the product ships as ConnectWise AI Agents. An independent layer MSPs were evaluating as a tool became a platform vendor’s feature in a single transaction.


The counter-argument, and what the zofiQ trade tells us about it

There is a serious case that argues that the platform vendors are the ones exposed. On that reading, Kaseya and ConnectWise risk being reduced to systems of record while AI-native competitors build the intelligent interaction layer on top of them, and the value migrates upward to whoever owns that layer. Capital is arriving on exactly that thesis: IFixify and Vertice have each raised €25 million or more.

Both directions cannot be broadly true at once, and the difference is not academic. It determines who the MSP should be worried about.

The zofiQ transaction is evidence about how incumbents actually behave when they see this coming. ConnectWise did not wait to be reduced to a system of record. It bought the interaction layer roughly twelve months into the cycle and shipped it as its own product, at a price a platform vendor can pay and an MSP cannot.

That does not refute the Fortino thesis. It qualifies it in a way that matters. An independent interaction layer can absolutely be built, and it is being funded. It is also acquirable, and the acquirer holds the customer relationships, the data, the distribution and the balance sheet. The layer gets built by startups and, often enough, owned by platforms.

For the MSP the practical consequence is identical under either outcome. The capability arrives inside a platform it already pays for, and it arrives for every competitor in the market on the same day.


Temporary automation arbitrage

Here is the distinction that matters more than any other in this argument.

An MSP that moves from 30 engineers per 3,000 endpoints to 10 has not created a margin. It has created an arbitrage: the gap between prices set under the old cost structure and the new cost of delivery.

Arbitrages close. The sequence is well established in technology markets and there is no reason to expect this one to behave differently:

  1. Early adopters automate and capture the gap. Gross margin improves sharply.
  2. Competitors reach the same capability, because the capability is purchasable rather than invented.
  3. Price competition pushes prices toward the new cost to serve. The gap narrows.
  4. Platform vendors ship equivalent capability natively, at a fraction of the price, or included.
  5. Customers realise a large part of what they were buying is now directly accessible.

Steps one and two are a business improvement. Steps three to five are a change in what the business is.

The critical judgment is that step one is not evidence against steps three to five. It is the first stage of them. An MSP measuring its margin in month nine of a five-year sequence will read the arbitrage as a permanent structural gain, and will price, hire and plan accordingly.

This is also where the standard adoption advice quietly misleads. Fortino splits MSP AI adoption into two tiers. Tier one is internal workflow and sales improvement: limited technical requirement, mostly a change management exercise, returns showing up as cost efficiency and output per employee. Tier two is new service lines, demanding real upskilling in both technical and commercial capability, including an understanding of what drives the customer’s revenue, cost and risk.

As a description of difficulty that is accurate. As a description of strategy it understates the position, because the two tiers do not have the same shelf life.

Tier one is the arbitrage. It is easy precisely because it is available to everybody, and its returns decay on the schedule above. Tier two is the wedge. It is hard precisely because it cannot be purchased, which is the only reason it lasts.

An MSP that completes tier one and stops has not adopted AI strategically. It has improved its cost base in a market where every competitor is improving the same cost base on the same timeline, using the same vendors.

There is a paradox sitting underneath this, and it is worth stating plainly.

The better an MSP becomes at agentic automation, the more convincingly it demonstrates to its own customers that much of its historical value proposition was automatable.

The demonstration is the problem. Every case study about tickets resolved without human intervention is also a public argument that the human intervention was not the thing worth paying for.


Two shapes are already testing this in the market

The most useful evidence is not vendor marketing. It is the small number of businesses that have built agentic capability and then made a structural decision about what to do with it. All figures below are company or investor stated and independently unverified, which is the ceiling on evidence in this category today. See ains-it-services-research.

Shield Technology Partners built two agentic products. Sentinel analyses support tickets and routes each to the best-equipped engineer. Spectre resolves certain issues autonomously. Roughly 60% of tickets across its portfolio are processed by automation, with median time to resolution on those tasks reduced by more than half.

Shield does not sell either product. It bought the MSPs instead: 60 to 90% stakes in nine providers, keeping their brands and leadership, reaching a combined $100m-plus in annual revenue across 1,500-plus organisations. Launched June 2025 by Thrive Holdings and ZBS Partners with over $100m in initial funding, a further $100m raised in February 2026, with OpenAI itself joining as an investor in December 2025.

That is the copilot and autopilot distinction expressed as a business decision rather than a definition. Given a working agent, Shield concluded the higher-value position was owning the service, not licensing the tool to the people who own the service.

Treeline took the opposite route to the same place. A $25m Series A led by Andreessen Horowitz, announced 31 March 2026, building a software-first alternative to traditional MSPs rather than acquiring any. It reports 98% of customer requests augmented or directly resolved by AI, and employee onboarding reduced from 20 minutes to two.

Read that 98% carefully. “Augmented or directly resolved” blends two very different claims, and the word augmented is carrying substantial weight. Grading claims like that one is precisely the job this Index exists to do, and it does not change the direction of travel: a venture-funded entrant is competing for MSP customers on the explicit basis that the labour layer is largely unnecessary.

Titan completes the picture, raising $74m led by General Catalyst in August 2025 and immediately acquiring RFA, a 35-year-old financial services MSP. The projected 3x increase in net margins attached to that deal is an investor’s underwriting assumption, not a reported result, and should never be repeated as one.

Roll-up and greenfield are different strategies. Both are capitalised on the same premise: that the labour between the customer and the platform is compressible, and that whoever compresses it captures the economics.


The barbell

If the middle of the wedge is compressible, the strategic question is what sits at the ends.

        Business outcomes, governance, risk ownership,
        architecture, accountability, change
                        ^
              defensible MSP value
        ------------------------------------
              agentic commodity layer
          M365 administration, monitoring,
          troubleshooting, patching, basic
          security operations, documentation,
          provisioning
        ------------------------------------
              defensible MSP value
                        v
        Networking, devices, sites, physical
        security, infrastructure

Upward, the work an agent cannot absorb because it is not a technical task: understanding what the customer’s business actually does, owning risk, taking accountability for outcomes, holding vendors to account, designing workflow, and steering technology decisions over multi-year horizons. An agent can execute a change. It cannot be the party responsible when the change is wrong.

Downward, the work where physical reality still applies. Sites, cabling, devices, hardware failure and the fact that somebody has to be in the building.

The uncomfortable observation is what the middle band contains: most of what traditional managed services currently invoices for.

The industry already has a name for the upward half. Pax8 calls it the Managed Intelligence Provider, an MSP that helps clients implement, manage and adopt AI across their workflows rather than only managing the infrastructure sitting underneath them. It is a good description of the destination.

Fortino attaches a constraint to it that deserves considerably more attention than it usually receives: MSPs “won’t be able to compete across all AI domains”, and the realistic opportunities are the ones adjacent to services they already deliver and capabilities they already hold.

Adjacency is a real limit, and it has an unwelcome implication. It rules out most of what an MSP would need to become to operate as a genuine AI consultancy, which means the new wedge starts narrower than the wedge being lost. The barbell is not a like-for-like revenue replacement. It is a smaller and more defensible position, and a smaller position only works if it is priced differently, which is the subject of the rest of this piece.

It is also not an empty market waiting to be entered. Accenture reported $2.6 billion in generative AI services revenue in the first half of 2025 alone. The top of the barbell is already a large business being built by firms with different economics, a different sales motion and existing relationships with the decision makers an MSP would need to reach.


Which brings the argument to pricing

Per-user pricing was a good model because it tracked a real relationship:

More users -> more tickets -> more technician labour -> more cost

Price the thing that drives the cost. Simple to quote, simple to audit, simple for both parties to understand. A customer with 73 employees pays for 73. They hire five, the bill goes up. That clarity is the reason it won.

Agentic automation is a deliberate attempt to break the middle of that chain. If it works, the relationship becomes:

More users -> more tickets -> more technician labour -> more cost

The chain breaks at exactly the link the pricing model was built on. Three consequences follow.

First, the correlation between users and cost weakens. A 100-user customer at $200 per user per month is $20,000 MRR. If agents resolve 70 to 90% of routine requests, the 101st employee generates almost no incremental cost to serve. Early on this is a gross margin improvement. Then it becomes a question the customer asks out loud: why does the bill rise by $200 every time we hire somebody, when nothing on your side changes?

Second, headcount is becoming a worse proxy for complexity. Compare a 100-person professional services firm running Microsoft 365 and six SaaS applications with a 40-person business running multiple sites, regulatory obligations, complex identity, dozens of integrations, legacy systems and 24x7 operations. The second requires far more capability and, under per-user pricing, pays less than half as much.

Agentic customers make this stranger again. A 30-person business may run 200 agents, dozens of automated workflows and a considerably larger digital attack surface than it had at 100 employees. What counts as a user in that environment, and why is it the billing unit?

Third, and worst, per-user pricing puts the MSP’s commercial interest directly against its customer’s strategy. If the MSP helps a customer automate a department:

100 employees x $200 = $20,000 MRR
 60 employees x $200 = $12,000 MRR

The MSP creates significant value and is paid 40% less for it. A business model that is structurally dependent on the customer employing more humans cannot credibly sell that customer an AI strategy. Those two positions are incompatible, and customers will work it out.

The pricing signal is backwards. The environment got more consequential and more difficult to govern, and the invoice went down.


What replaces it, and what does not

The obvious alternative is consumption pricing: charge per ticket, per agent action, per remediation, per API call. It is the wrong answer for two reasons. It reintroduces bill volatility, which is precisely what customers moved away from when they left break-fix. And it gives the MSP a direct financial incentive not to eliminate the demand it is billing for, which is the same misalignment in a new costume.

The more defensible direction is away from per-user and toward pricing the environment, the complexity, and the accountability. Illustratively, and these numbers are a worked shape rather than market data, the same $20,000 might be constructed as:

ComponentMonthlyWhat it prices
Managed technology platform$8,000Governance, platform management, automation, monitoring, standard security, reporting, service accountability
Environment complexity$5,000Sites, tenants, applications, integrations, regulatory scope, infrastructure
Human support capacity$3,000A support capacity band rather than a headcount
Strategy and transformation$4,000Technology planning, AI adoption, workflow design, systems evolution

The total is unchanged. What changed is the denominator. Automating 20 roles no longer removes $4,000 of revenue by default, and a customer that replaces headcount with a more sophisticated automated environment has increased what the MSP is responsible for, not decreased it.

The growth equation moves with it. From:

customers x seats x ARPU

to something closer to:

customers x complexity x responsibility x value created

Which changes the operating question from how many seats can we manage per technician to how much customer technology can we take responsibility for per unit of human intervention. The second is an AI-native economic model. The first is a headcount business wearing an agent.


The metric worth tracking

Technician efficiency is about to become a poor measure of health, because it will improve right up until the moment it stops mattering. A more honest one:

What percentage of what this customer pays us for could they buy directly from an increasingly agentic vendor ecosystem within 36 months?

An MSP that can answer that per customer, per service line, knows which revenue is arbitrage and which is a position. Very few can currently answer it at all.


The comfortable answer, and what it leaves open

There is a settled industry position on all of this, and Fortino states it cleanly: the winning model combines the speed and scale of AI with the judgement and reliability of experienced operators, because environments are complex, systems are mission critical, and somebody has to be accountable when it goes wrong.

That is very likely correct. It is also not an answer to the commercial question, and it is doing a lot of reassuring for a sentence that settles nothing.

Judgement and accountability are genuine, durable and hard to automate. They are the top of the barbell. But nothing in that statement establishes how much revenue they support, whether they can be sold at current prices, or whether they can be invoiced per user. “Humans remain necessary” and “the current business model remains viable” are different claims, and the industry is treating the first as though it proves the second.

The MSP that survives on judgement and accountability is a materially different company from the one that bills 100 seats at $200. Smaller, possibly more profitable, almost certainly structured differently, and selling to a different person inside the customer.


The fork

The thesis is not that agentic technology inevitably narrows the MSP value wedge. Stated that way it depends on predicting that MSPs disappear, which is both unlikely and unnecessary to the argument.

Stated more precisely:

Agentic technology will substantially narrow the MSP’s existing value wedge unless the MSP deliberately builds a new one.

Which produces three paths, not one.

Automate and stay where you are. Capture the arbitrage, hold the pricing model, watch the margin improvement get competed away and then absorbed by the platform vendors. This is the path that feels best for the first eighteen months.

Do not automate. Structurally uncompetitive against operators running at a fraction of the cost to serve. This one ends sooner.

Automate, and reinvest the capacity dividend into a value wedge that the agentic layer cannot absorb. Governance, risk ownership, accountability, business architecture, and the physical work at the other end of the barbell. Harder, slower, and the only version where the MSP is stronger at the end than at the start.

The wolf was never AI. It is the eighteen months of very good margin reports that arrive before the question does, and the fact that the technology producing those reports is simultaneously teaching customers they may not need the company producing them.

Efficiency gains are worth having. They are just not the thing to measure.


Sources and evidence grade

Every figure attributed to Shield Technology Partners, Treeline and Titan is company-stated or investor-stated and independently unverified: evidence_level: Public info, the same ceiling applied to entries in the Index. Full source list and the claim-by-claim assessment in ains-it-services-research. The zofiQ acquisition record and the redirect evidence are in tools-backfill-notes. Category framing, including the copilot and autopilot distinction, draws on research-sources.

Market sizing, the four profitability pressures, the two-tier adoption framework, the system-of-record prediction, the Managed Intelligence Provider term (which Fortino credits to Pax8) and the Accenture and startup funding figures come from AI is reshaping the MSP industry: what are the opportunities?, Fortino Ventures, 9 September 2025, stated as drawing on 50-plus conversations with founders and MSP operators.

Apply the same discount to it that this Index applies to any venture publication. Fortino is an investor in this sector, actively seeking deal flow in it, and the piece closes by inviting founders to get in touch. That does not make the analysis wrong, and several of its observations are sharper than anything published from inside the channel. It does mean every framing in it is compatible with the bet the firm is placing, which is the same caveat recorded against the TEN13 whitepaper in research-sources.

The pricing table is an illustrative construction, not observed market pricing. No survey data underlies it.