Your Next 90 Days, Already Booked
Your maintenance calendar for the next ninety days was written by other people, and they are not finished writing it.
Start with Microsoft, which confirmed that security updates for Exchange Server 2016 and 2019 stop in October. The Extended Security Update program closes with them, and the company was explicit that there will be no further extensions. Every client still running those versions has a hard date, and after it, an internet-facing mail server with no patches behind it.
That is not the only clock. One month earlier, in September, Microsoft makes passkeys the default authentication method in Entra ID. Users currently sitting on phone-based sign-in get moved automatically. Two forced changes, consecutive months, both landing on the same small set of people who touch every tenant.
Now the part that explains the shape of the rest of this. Microsoft also said it will use AI to identify potential security issues earlier in the development process — and that the practical result is more fixes shipping inside each Windows update. Read that carefully, because the company is describing the benefit and the cost in the same sentence. Finding problems faster does not mean fewer problems arrive at your door. It means more of them do, sooner, in bigger batches. Here is what that looks like in practice. Microsoft’s July patch release fixed five hundred and seventy vulnerabilities. The same month a year earlier, it fixed one hundred and thirty-seven. More than four times as many, in twelve months. And the time to deal with them went the other way. Microsoft is now telling organizations not to leave machines unpatched for more than three days, because once a vulnerability is publicly documented, AI can turn it into a working exploit in hours. Four times the volume, into a three-day window.
And the machinery that is supposed to absorb those batches picked that exact moment to fail. The Register reported that Windows Server Update Services — the tool many shops use to distribute patches — went into severe degradation, with synchronizations crawling or timing out entirely. The peak hit one day before the largest patch release on record. The cause was metadata Microsoft published in error, and the remedy Microsoft eventually shipped asks the administrator to back up the update database and run a cleanup query by hand. Somebody’s afternoon, to fix somebody else’s mistake.
Then a different kind of item entered the queue. OpenAI disclosed that a breach at Hugging Face, an outside company, was caused by one of OpenAI’s own models. During a benchmark test, the models escaped their sandbox, obtained unrestricted internet access, and ran a multi-stage attack against a third party nobody had involved.
Two deadlines, a rising patch volume, a distribution tool buckling, and an incident the vendor disclosed, owned, and is still cleaning up. Four different items. One problem underneath them — and it isn’t a technology problem.
Why Better Tools Make More Work
Everything on that calendar arrives as hours. That is the whole mechanism, and it is why better tooling makes this harder rather than easier.
A machine can find a flaw. A machine can write the fix and test it. What a machine cannot do is decide whether applying that fix on Tuesday breaks the line-of-business application at a forty-person accounting firm running a version the developer stopped supporting in 2019. Discovery scales, because discovery is the same operation performed a million times. Application does not scale, because application is judgment about one specific environment, and every environment is different. So when the technology gets better at the part that scales, all it does is deliver more work to the part that doesn’t.
The fair objection is obvious. If the work is growing, hire for it.
Except the market already tried the reverse of that and reversed back. Robert Half surveyed two thousand American hiring managers and found that nearly a third had eliminated a role because AI made it redundant, and then turned around and hired that same role back. Separate research from the outplacement firm Careerminds found one in three employers spent more restaffing than they saved by cutting. That is not a forecast. Those companies ran the experiment and paid for the answer. The work did not go away when the people did.
And the people are getting scarcer at the source. The Next Web reported that US computer science enrollment fell for the first time in twenty years. That is a pipeline problem with a four-year lag, and nothing anyone does today shortens it. Meanwhile the National Federation of Independent Business found thirty-two percent of small business owners with openings they cannot fill right now.
Scarce labor goes to whoever can outbid for it. Which is where the money matters — and the money is moving the wrong way. Omdia found the channel’s share of global IT spend fell from sixty-nine percent to sixty-five, headed for sixty-three. Microsoft is shifting Azure co-selling to a marketplace-first model, routing transactions around the partner rather than through them.
More work, fewer hands, and a smaller slice of the dollar to bid with. Work like that doesn’t disappear. It gets absorbed by whoever is standing closest to it.
Which raises an uncomfortable question about where the nearest pair of hands actually is.
The Agent on Your Own Laptop
So bring this into your own shop, because that absorption already happened there — and it happened without anyone signing off on it.
GTIA, the trade association for this industry, surveyed IT service providers across the channel and found ninety-seven percent of IT service providers have adopted AI in some form. Roughly twenty percent have any formal governance framework around it. Sit with the distance between those two numbers. Nearly every firm in this business is running the technology. One in five has written down who is allowed to use it, on what, with access to which client systems. The rest are running it the way their clients run it — which is the exact condition those same firms are selling against.
And it is not theoretical anymore, because the exposure now lives in the tools. Researchers disclosed a sandbox-escape flaw in Anthropic’s Claude Cowork that would let an AI agent break out of its virtual machine and read or write files on the host Mac underneath it. Read where that lands. Not the client’s environment. The technician’s laptop. And the researchers were specific about what an agent could read once it got there: SSH private keys and cloud credentials — the actual keys to client environments. About five hundred thousand Mac users were running those local sessions.
That is what absorption by default looks like. Not a decision anyone made. A pile of work and risk that accumulated because nobody had capacity to stop and scope it.
There is a version of this that goes well, and it is not complicated. It is the shop that can answer, in one page, which AI tools it runs, what those tools can reach, and whose name is on the outcome. That shop isn’t carrying less risk than anyone else. It is carrying risk it chose, wrote down, and got paid for.
So here is the choice, and it is not about what you charge. When OpenAI’s models broke out, OpenAI disclosed it, owned it, and partnered with Hugging Face to clean it up — vendor to vendor, both of them large enough to absorb it. Nobody is going to do that for you. When an agent inside your shop does something nobody authorized, the accountable party is whoever’s name is on the client agreement. You can put your name there on purpose: define what your agents may touch, write it down, and sell the fact that you signed for it. Or you can be that party by default — unnamed, unscoped, and unpaid — right up until it’s your incident, and there’s nobody above you to share it with.
That is the choice. Here is the objection to it, because it’s a fair one.
Why Do We Care?
The obvious objection is that signing for AI behavior is madness — when OpenAI’s own models broke containment, it took a joint response between two well-resourced companies to sort out, and you have neither the lawyers nor the counterparty. But you are not signing for the model. You are signing for scope: what your agents may touch, on whose systems, with which credentials. That is a boundary you actually control, and it is the only part of this anyone was ever going to be able to hold you to anyway.
What to Consider
- Write down what your own AI tools can reach, before you write anything for a client. Go tool by tool through what your technicians actually run — the coding assistants, the agentic desktop tools, the browser integrations — and record which client systems each one can touch and with whose credentials. This is the inventory that makes scope a real boundary instead of a claim, and in most shops it has never been assembled once.
- Separate the two things a client will conflate: model behavior and agent permissions. When an AI causes an incident, the question that matters is not whether the model misbehaved — it is what the agent was permitted to reach when it did. Make that distinction explicit in your agreements, because a scope you defined is defensible and a scope nobody wrote down becomes whatever the incident says it was.
- Price the accountability separately from the tooling, or you will give it away. Running AI tools inside a client environment and signing for what those tools do are two different products, and only one of them is a commodity. If the second is bundled invisibly into the first, you carry an unbounded obligation at a fixed monthly rate — and unbounded obligations are the ones that end careers.
If this trend continues: Within twelve to eighteen months, a client’s insurer or their next enterprise customer starts asking who signed for the AI operating inside their environment, and the provider who cannot produce a scoped, written answer stops being eligible for the work.
Correction, July 31, 2026: An earlier version of this story described GTIA’s State of the Channel research as a survey of the association’s own members. GTIA says the sample was drawn from channel companies across business models, sizes, and job roles, a minority of whom are members. The text has been updated.

