← Back to blog

DVG Systems AI Policy

Seven Questions Ontario SMBs Should Ask Their MSP Every Time a Major AI Model Launches

8 min read
On this page

Every few weeks, a headline breaks: a new AI model is smarter than the last, or a new capability has regulators and banks convening emergency calls. By Friday afternoon, business owners across Northern Ontario are forwarding the article to their IT provider with one question attached — “are we exposed?”

Most of the time, the honest answer is: probably not today, but your exposure depends on seven things your MSP should already be watching. This post walks through all seven. Bring this list to your next IT review. If your provider can’t answer most of these clearly, that’s the finding.

Why the Questions Matter More Than the Model

The specific model that launched this month is almost never the problem. The problem is what that model quietly makes easier:

  • Chaining credentials an attacker already phished into deeper access.
  • Driving a browser on behalf of an employee who shouldn’t have been able to approve a payment alone.
  • Summarizing data an AI integration never should have been granted access to in the first place.

Frontier model releases don’t create new categories of risk so much as they surface old control gaps faster. The businesses that stay calm during each news cycle are the ones whose fundamentals — identity, data classification, vendor review, incident response — were already in order. For most Ontario SMBs, the work is the same this month as it was last month. The model launch is just the prompt to check.

The Seven Questions

1. “Which AI tools are currently authorized in our Microsoft 365 or Google Workspace tenant — and who approved them?”

Every time an employee clicks “Connect with Microsoft” or “Sign in with Google” on an AI tool, a third-party application gains persistent access to your environment through OAuth. Those grants survive staff turnover and policy changes unless someone actively revokes them.

A competent MSP should be able to produce, on request, a current list of enterprise applications in your Microsoft Entra ID tenant, the permissions each one holds, and the last time the list was reviewed. If nobody has reviewed it in the last quarter, that’s the project to start now — not after the next headline. For more on how these integrations creep in unnoticed, see our post on shadow AI in Northern Ontario businesses.

2. “What data is our Copilot or Gemini deployment actually allowed to see?”

Microsoft 365 Copilot and Gemini for Workspace inherit the permissions of the signed-in user. If an employee has access to a SharePoint site they shouldn’t — a common finding in SMBs where permissions have accumulated for years — Copilot can now surface that content in natural-language answers at machine speed.

The fix is not to disable Copilot. The fix is to clean up the underlying permissions using the principle of least privilege. Microsoft’s own deployment guidance for Copilot for Microsoft 365 treats permission hygiene as a prerequisite, not an optional step. Your MSP should have already run — or should be scheduling — a SharePoint and OneDrive access review before a broad Copilot rollout.

3. “Are we using a consumer AI tool or an enterprise one, and do we have the vendor’s data processing terms on file?”

This distinction matters more than any single model’s capabilities. Consumer-tier tools (a personal ChatGPT account, a free AI summarizer, a browser extension) typically have different data handling defaults than the enterprise versions of the same products. Enterprise offerings from Anthropic, OpenAI, Microsoft, and Google publish explicit commitments about whether customer prompts are used to train models — Anthropic’s Commercial Terms and OpenAI’s Enterprise privacy page both state that customer API and enterprise data are not used for training by default. Free consumer tiers do not make the same commitment.

Your MSP should be able to tell you, for each AI tool your staff use with business data, which tier you’re on and whether a Data Processing Agreement (DPA) is in place. This ties directly to your obligations under PIPEDA and Ontario sector-specific privacy rules.

4. “What is our data classification policy, and do staff know which data can go into AI tools?”

A policy that says “don’t share sensitive information with AI” is useless if nobody agrees on what sensitive means. Staff need a concrete, four-line rule they can apply at the moment they’re about to paste. A tiered classification — public, internal, confidential, regulated — with a one-sentence description of what belongs where, does more to prevent accidental disclosure than any technical control.

We’ve published a four-tier data classification model built specifically for AI decisions. If your MSP has never walked your staff through something similar, that’s a training gap a frontier model release only widens.

5. “What happens in our environment if an AI tool is compromised or misused?”

This is really two questions: do we have monitoring that would catch an AI-driven anomaly, and do we have a response plan if we do?

Monitoring starts with Conditional Access policies in Microsoft Entra ID that enforce device compliance, block legacy authentication, and require MFA for sensitive actions. Response starts with a written incident response playbook built for an SMB reality, not a Fortune 500 template. The point is not to prevent every incident — no security control is absolute — but to make response predictable and fast.

6. “Is any of our data leaving Canada through these AI tools, and does that matter for our industry?”

Most major AI providers process data in the United States by default. For Ontario healthcare providers under PHIPA, legal firms with solicitor-client obligations, and public-sector contractors under ministry-specific data residency requirements, this is a live compliance question — not a theoretical one. It also matters for many SMBs whose contracts with larger customers increasingly include Canadian data residency clauses.

Your MSP should know which of your current and planned AI tools offer Canadian or EU data residency options, and what the cost and capability tradeoffs are. Our overview on Canadian data sovereignty when your stack is US-hosted covers the decision framework.

7. “When should we actually change something because of a new model release?”

This is the question most business owners really want answered. The honest triggers are narrow:

  • A vendor you already use changes its data handling terms (not its model capabilities).
  • A regulator your industry answers to issues new guidance.
  • A new model is bundled into a platform you already deploy (e.g., a new Copilot capability enabled by default in your tenant) — review and adjust tenant settings before the rollout date.
  • An actual incident is publicly attributed to the model in a way that maps to how you use it.

A model being “smarter” or “more agentic” in press coverage is not, by itself, a trigger. The Canadian Centre for Cyber Security and the Information and Privacy Commissioner of Ontario both publish guidance that emphasizes control maturity over chasing individual threat headlines. Your MSP should be steering you toward fundamentals, not reacting to every announcement.

What a Good MSP Is Already Doing Between Launches

If these seven questions feel uncomfortable to ask your current provider, the gap usually isn’t malice — it’s that many smaller IT shops have not kept pace with the identity and data-governance work that AI deployment demands. A good MSP in 2026 is quietly doing the following on your behalf, whether you ask or not:

  • Reviewing enterprise application consent grants in Microsoft Entra ID on a regular cadence.
  • Maintaining Conditional Access policies that assume AI tools and human attackers look similar on the wire.
  • Keeping a living inventory of which AI tools your staff actually use — including the ones they shouldn’t.
  • Updating your AI acceptable-use policy when vendor terms or Canadian regulations change.
  • Briefing you when something real changes, and staying quiet when the news cycle is just noise.

If You Can’t Get Clear Answers

The reason to ask these questions isn’t to trap your MSP. It’s to discover — calmly, in a planned review rather than during an incident — where the gaps are, and to decide together what to fix first.

At DVG Systems, we run this exact review quarterly for our managed clients across Thunder Bay and Northern Ontario, because the model landscape moves faster than any annual plan can track. If your current provider isn’t running something equivalent, get in touch and we’ll walk through the seven questions together for your environment — no pressure, no sales pitch, just a clearer picture of where you stand before the next headline lands.


DVG Systems provides managed IT, cybersecurity, and AI governance support to small and mid-sized businesses across Thunder Bay and Northern Ontario. Our approach prioritizes identity, data classification, and incident readiness — the fundamentals that hold up regardless of which AI model is trending this week.

Ask AI

Accessibility