The criterion
Transparent to clients. Clients consent to the use of AI based on clear information about how it’s used. They know which actions are AI-driven, which are human-reviewed, and what data goes to which models. This gets disclosed at onboarding and updated as tooling changes. Not buried in terms of service.
What has to be disclosed
The criterion has three parts, and MSPs commonly satisfy the first while ignoring the other two.
- Which actions are AI-driven. Not the fact that AI is used somewhere, but which categories of work an agent performs, and which of those it performs unattended.
- Which are human-reviewed. The client should be able to tell the difference between an agent that drafts for approval and an agent that executes against their environment.
- What data goes to which models. Which providers process client data, what categories of data reach them, whether that data is retained or used for training, and in which jurisdiction the processing happens.
Timing and placement are part of the criterion rather than incidental to it. Disclosure happens at onboarding, in a form the client reads, and it is updated as tooling changes. A clause added to a master services agreement two years ago, in a document signed once and never re-read, is not what this criterion describes. Nor is a change of model provider that nobody was told about.
The regulatory floor
For MSPs with clients or operations in the European Union, the AI Act's obligations for general-purpose AI have been phasing in since 2024, with further application dates through 2026, and they establish a baseline for disclosure that did not previously exist in contract law. MSPs serving regulated clients in other markets face the same pressure through their clients' own obligations rather than directly: a bank or a hospital that must document its processors will ask its MSP for exactly this information whether or not the MSP's own jurisdiction requires it.
The index does not assess legal compliance and is not qualified to. What we take from the regulatory direction is simpler: disclosure is becoming a procurement question, and an MSP that cannot answer it in writing will lose deals to one that can. Any MSP relying on this for its own obligations should take its own advice on what applies to it.
Why it belongs in the criteria at all
It would be easy to read transparency as a governance nicety attached to a list of operational capabilities. It is in the list because it is the criterion that decides whether the rest of the model survives contact with a client's risk function.
There is a commercial reading as well. The argument in Automation Arbitrage is that the durable question for an AI-native MSP is what remains inside its value wedge once the automation is purchasable by anyone. Being the party that can account for how AI touches a client's estate, in writing, is one of the few positions in that wedge that a platform vendor selling to the client directly cannot easily occupy.
The failure mode worth naming is the opposite of secrecy. Over-disclosure, in the form of a fourteen-page appendix nobody reads, satisfies a lawyer and fails the criterion, because the criterion is about the client understanding what happens, not about the MSP having said it somewhere.
How the index assesses it
We ask to see the artefact the client actually receives, redacted as needed. We look for the three parts above in language a non-technical client can act on, and for a stated mechanism that triggers an update when the tooling changes.
We also ask what a client can decline. Meaningful consent implies at least one thing the client can say no to, whether that is autonomous execution against production, a particular model provider, or the processing of a sensitive data category. Where nothing can be declined, the disclosure is a notification, and we record it as such.
Signals and anti-signals
| Signal | Anti-signal |
|---|---|
| A client-facing document listing AI-driven actions, reviewed actions and data flows | A single clause in the master services agreement mentioning AI in general terms |
| Model providers and data categories named, with retention and training stated | We use industry-leading AI, with no provider or data flow identified |
| An update is issued when tooling or providers change | Disclosure written once at onboarding and never revisited |
| At least one thing the client can decline, with a stated consequence | Consent is assumed by continued use of the service |
Related criteria
- AI ticket resolutionClosing five per cent of tickets with AI is an improvement. Closing most of the Tier 1 volume is a different business model. This criterion is about which one you are running.
- AI-first ticketingThis criterion is about order of operations, not outcomes. Whatever the channel, the first thing that touches the ticket is an agent.
- Margin and headcountAn MSP where the numbers are indistinguishable from a conventional shop is a conventional shop with better marketing.
All seven are listed on the criteria hub, and summarised on What is an AI-Native MSP?