AI for vCIOs: What an AI Agent Can and Cannot Do in a QBR
AI can draft the assessment, the summary and the follow-up. It cannot own the recommendation. Here is where AI fits in an MSP client review, and where it stops.
AI has arrived in the vCIO toolset fast. Most QBR platforms now advertise some form of AI: ScalePad promotes Copilot features in Lifecycle Manager X, and Strategy Overview markets its Arya assistant, which generates status, grade, risk, and solution recommendations for assessment items. General-purpose tools like ChatGPT, Claude, Copilot, and Gemini are already open in most vCIOs' browsers.
The useful question is not whether to use AI in your client reviews. It is which parts of the review AI should do, and which parts it should never own. Get that split right and AI gives your vCIOs back hours every quarter. Get it wrong and you hand a client a confident recommendation that nobody at your MSP actually made.
What AI Does Well in a Client Review
The work that takes time but not judgment
A large share of vCIO prep is assembly: pulling data, summarizing it, and turning technical detail into readable language. That is exactly what current AI tools are good at. Used well, AI can:
Summarize the quarter. Condense ticket history, incidents, and project status into a short narrative the vCIO can check in minutes instead of writing from scratch.
Draft assessment findings. Propose a status and a plain-English explanation for each item, based on the data you give it, for the vCIO to confirm or change.
Translate technical detail into business language. Turn "firewall firmware is end-of-support" into a sentence a business owner will actually read.
Draft discovery questions. Suggest questions tailored to the client's industry and recent news, which the vCIO then picks from.
Write the follow-up. Produce a first draft of the post-meeting summary and action list from the vCIO's notes.
What AI Cannot Do
The parts of the review that require accountability
Know what is not in the data. AI works from what you give it. It does not know the client just lost their largest customer, that the owner is planning to sell, or that the office manager is quietly exporting data before leaving. Discovery exists to find exactly that, and it happens in conversation.
Own a recommendation. A recommendation is a professional judgment the MSP stands behind. AI can propose one, and it can be wrong in ways that sound completely confident. The vCIO has to decide whether it is right for this client, at this price, now.
Make the call on risk. Whether a finding is Red or Yellow depends on your Standards Library and on context the data may not carry. AI can suggest a status. A person has to assign it.
Ask for the decision. Every Red or Yellow finding in the vCIO Framework ends in a funded project or a signed risk acceptance. That conversation - and the relationship it depends on - belongs to the vCIO.
A Practical Split: AI Drafts, the vCIO Decides
| Review step | AI's role | vCIO's role |
|---|---|---|
| Data pull and summary | Summarize tickets, incidents, and changes | Check accuracy and spot what matters |
| Assessment | Draft a status and explanation per item | Assign the final RYG status against the standard |
| Discovery prep | Suggest tailored questions | Choose the questions and lead the conversation |
| Recommendations | Draft options and business-language descriptions | Decide what to recommend, price it, and present it |
| Decision | None | Record a funded project or a signed risk acceptance |
| Follow-up | Draft the summary and action list | Review, correct, and send |
The rule underneath the table is simple: nothing AI produces reaches a client without a person reviewing it, and every AI draft is treated as a draft until then.
Five Guardrails Before You Put Client Data Into AI
1. Know where the data goes. Before any client data goes into an AI tool, confirm how that tool handles it - whether it is retained, whether it is used for training, and where it is stored. Business tiers and consumer tiers of the same product often differ. Check your agreements with clients too.
2. Send the minimum. Give the tool what the task needs, not the whole client record. Remove credentials, personal data, and anything covered by a compliance regime unless the tool is approved for it.
3. Label drafts as drafts. Make it obvious internally which content was AI-generated and has not yet been reviewed, so nothing slips into a client deliverable unchecked.
4. Keep the standard in charge. AI should score against your Standards Library, not its own idea of good practice. If it suggests a status, it should cite which standard item it is scoring against.
5. Keep a person accountable. Every client-facing recommendation should have a named vCIO who made it. "The AI suggested it" is not an answer a client will accept when something goes wrong.
AI Is Also on the Client's Agenda
The review is where AI advisory becomes revenue
The same question applies to your clients, and most of them are further along than they admit. Staff are already using ChatGPT, Copilot, and similar tools, often without policy, security review, or any sense of what data is being shared. That is why our QBR (TBR) template includes the discovery question: "Has anyone on your team started using AI tools - Copilot, ChatGPT, or anything similar - in their day-to-day work?"
The answer almost always surfaces findings: no acceptable use policy, overshared files that a tool like Copilot will surface to anyone with access, and no visibility into which AI tools are in use. The vCIO Framework's AI Advisory Practice module covers the services that close those gaps - an AI readiness assessment, Copilot and Gemini pre-flight checklists, an AI acceptable use policy, and shadow AI detection. Each one is a documented finding that can become a funded project, exactly like any other Red or Yellow item.
An MSP that uses AI carefully in its own reviews is also in the best position to advise clients on doing the same.
Frequently Asked Questions
Can AI run a QBR for an MSP?
AI can prepare much of a QBR - data summaries, draft findings, and follow-up - but it should not run the meeting or own the recommendations. Discovery, judgment on risk, and asking the client for a decision need a person who is accountable for the advice.
Is it safe to put client data into ChatGPT or other AI tools?
It depends on the tool, the plan, and your agreements with the client. Confirm how the tool retains and uses data before sending anything, send only what the task needs, and exclude credentials, personal data, and regulated data unless the tool is approved for it.
What is an AI vCIO agent?
Several vCIO and QBR platforms now include AI assistants that draft assessment statuses, risks, and recommendations from client data. They are useful for speeding up preparation. Their output should be treated as a draft for the vCIO to review, not as the final recommendation.
How can MSPs make money from AI?
By advising clients on adopting it safely: AI readiness assessments, Copilot and Gemini deployment preparation, acceptable use policies, and shadow AI monitoring. These surface naturally in client reviews and convert to projects like any other documented gap.
See how ready your own practice is: take the free vCIO assessment, or download the vCIO Framework v1.15, including the AI Advisory Practice module. For definitions of the terms used here, see our vCIO and MSP glossary.
From the vCIO Framework
Score Your vCIO Program
Download the vCIO Framework and get your Red/Yellow/Green methodology in one business day.
Get the Framework