Opens in a new tab
News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers

Daily News / Artificial Intelligence, Regulation, Security

Default Security Choices Leave MSPs Exposed as AI Bots Blend With Legitimate Users

On the go? Listen to the Audio Podcast instead

Read this news instead

Your Host

Dave sobel, host of the business of tech podcast
Dave Sobel
Dave Sobel is a leading expert in the delivery of technology services with broad experience in both technology and business. He owned and operated a technology solution provider for over a decade, and worked for vendors leading community, marketing, product strategies, and M&A activities.

This content is made possible by community-minded viewers like you

Thank you

Support Business of Tech

Episode Description

A key structural shift identified is the growing governance gap created by AI agents that evade traditional detection and accountability measures. This challenge is exemplified by Meta’s Muse and OpenAI agents, which do not self-identify during interactions. As a result, determining agent activity and risk now depends on disclosures by the developer rather than the asset owner or operator, limiting the visibility and control of MSPs and IT service providers.

One consequential incident involved an OpenAI agent accessing both public and non-public files in the Australian government’s health portal. The breach went unnoticed by government security for 54 days and was discovered during an internal OpenAI review, later reported voluntarily by the company. In retail, Amazon blocked Meta’s Muse agent from its platform after it failed to identify itself and due to concerns about credential handling, according to statements cited by GeekWire. These events illustrate growing dependency on agent developers for incident discovery and disclosure.

Supporting developments include findings from Akros Labs that current rules are insufficient to distinguish customers, attackers, or bots, due to agents blending in as typical browsers. VentureBeat surveys show a decline in proactive agent isolation and a rise in uncontained incidents, indicating operational drift toward default-permissive security settings. While new standards from NIST for short-lived tokens and upcoming agent identification protocols are developing, enforcement and utility remain incomplete.

For MSPs and IT leaders, the immediate implication is the need to revisit client-specific controls. Default reliance on legacy bot rules increases undetected risk, while inaction effectively shifts governance to external agent vendors. Providers must decide whether to block all unauthenticated agent traffic—accepting potential business impact—or allow agents and rely on token expiration and allow-listing signed agents as standards evolve. Continuous monitoring and regular adjustment of controls are necessary to minimize harm when agent anonymity and developer-only surveillance persist.

00:00 The Agent That Looks Like Chrome
04:41 Only The Maker Is Watching
07:02 The Default Nobody Chose
10:07 Why Do We Care?

Supported by:
Proofpoint https://www.proofpoint-total-protection.com/?utm_campaign=367226068-US%20MSPs%20Paid%20Campaigns&utm_source=Podcast&utm_medium=Dave%20Sobel
GoTo(LogMeIn) https://www.logmein.com/products/resolve/trial/msp?utm_medium=affiliates&utm_campaign=msp-trial&utm_source=mspradio&campaignid=701Vv00000ujfDKIAY

NinjaOne On-Demand Webinar: https://go.businessof.tech/p/ninjaone-pod

💼 All Our Sponsors

MSP Radio is supported by our partners:
ABC Solutions — https://go.businessof.tech/p/abc-solutions-yt
CometBackup — https://go.businessof.tech/p/cometbackup-yt
FireTail — https://go.businessof.tech/p/firetail-yt
Guardz — https://go.businessof.tech/p/guardz-yt
HaloPSA — https://go.businessof.tech/p/halopsa-yt
LogMeIn — https://go.businessof.tech/p/zz-duplicate-merged-into-goto-logmein-aug-11-2026-safe-to-delete-yt
Mailprotector — https://go.businessof.tech/p/mailprotector-yt
OpenText — https://go.businessof.tech/p/opentext-yt
Pax8 — https://go.businessof.tech/p/pax8-yt
Proofpoint — https://go.businessof.tech/p/proofpoint-yt
Rythmz — https://go.businessof.tech/p/rythmz-yt
ScalePad — https://go.businessof.tech/p/scalepad-yt
TimeZest — https://go.businessof.tech/p/timezest-yt
Transit AI — https://go.businessof.tech/p/transit-ai-yt
USecure — https://go.businessof.tech/p/usecure-yt

Supporting the IT services community through insights, analysis, and transparency.

⸻

🚀 Join The Small Biz Thoughts Community

The membership for independent MSP owners: vendor intelligence, member-only briefings, a private peer forum, and direct access to Dave.

👉 https://smallbizthoughts.org/join/

⸻

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe

⸻

📰 Story Links & Sources

Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🌐 https://www.businessof.tech

⸻

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech

⸻

🔗 Follow Business of Tech

LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories