Organizations are moving from purchasing commercial software to building their own applications with AI tools, shifting the ongoing maintenance and accountability from vendors to internal teams and MSPs. This creates governance gaps and operational risk that go unpriced, particularly as automation and custom app development become easier for enterprises, small businesses, and IT providers. Evidence comes from McKinsey’s State of AI survey, GoDaddy’s self-built app hosting, and direct MSP case studies.
McKinsey found that 32% of organizations—and nearly half of AI “high performers”—built functionality in-house using AI instead of buying it. GoDaddy now enables deployment and management of such customer-built apps. MSPs like ITECH Solutions and WheelHouse IT illustrated how staff can rapidly implement automations or replace core business software, increasing reliance on internally developed tools.
Despite accelerated development, ongoing responsibilities for patching, security reviews, and identity management remain. Incidents at Meta and OpenAI, as well as survey data from VentureBeat, highlight persistent risk and the lack of robust controls—especially around identity and security—for internally developed or AI-generated applications. Vendors such as Apple are responding with operating system-level controls, shifting the burden of informed consent and risk mitigation to the device layer.
For MSPs and IT leaders, each client- or internally-built tool represents a new asset to manage, often without additional compensation. Failure to explicitly govern, price, and assign ownership to these tools increases hidden costs and risk, particularly with flat-fee agreements. Practical measures include treating every custom build as a managed asset, assigning identities and permissions, and itemizing them in contracts to align pricing with actual support delivered.
00:00 Nobody Owns What Your Clients Build
04:08 Cheap To Build, Costly To Own
06:56 The Layer Only You Control
10:18 Why Do We Care?
Supported by:
NinjaOne On-Demand Webinar: https://go.businessof.tech/p/ninjaone-pod
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · Firetail · HaloPSA · LogMeIn · Mailprotector · Pax8 · Rythmz · ScalePad · TimeZest · Transit AI
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:01] Every time a client builds instead of buys, a vendor stops doing a job. And nobody picks it up. Meta needed nights and weekends to keep its own agent in its box before launch. Your client's weekend app has nobody. This is the Business of Tech. I'm Dave Sobel. Software that businesses used to buy, they're starting to build.
[00:00:28] Let's start with McKinsey's State of AI survey. Nearly a third of respondents, 32%, say their organization decided against buying at least one software product or feature because it could build the functionality in-house with AI coding agents. Among the companies McKinsey calls AI high performers, it's nearly half. The survey covered more than 1,700 participants, and McKinsey says the shift
[00:00:55] could be a sign that AI is beginning to shape how technology budgets get spent. Those are large organizations. Further down the market, Sri Amugla, who runs a managed service provider in Silicon Valley, writes in CIO that small businesses used to ask him whether they should look at AI. Now they tell him their employees already opened ChatGPT or Claude. He cites BlueVine,
[00:01:20] a small business banking platform. 74% of small business owners are using or testing AI. And among BlueVine's own customers, Claude users grew 729% in a year. That measures adoption, not software anyone has finished building. Keep that distinction in mind. The plumbing for small builders is arriving as a product. GoDaddy launched hosting for web apps that customers built themselves, hired a freelancer for,
[00:01:50] or made with an AI coding tool. Coding agents can create, deploy, and manage those apps entirely through GoDaddy's API. That's GoDaddy's own announcement. And the builders include MSPs, starting with the system at the center of the business. On this show, Brian J. Weiss, CEO of iTech Solutions, walked through replacing his own PSA. His 11-person shop ran a commercial PSA for about
[00:02:15] 8 years. It ended up with 6 or 7 tools bolted on to do what he felt the PSA should have done out of the box. Now it's building a replacement on Microsoft Dynamics. TechStack supplies the PSA layer, and iTech owns its own customized layer on top, inside its own tenant. Weiss is customer zero, a design partner, and has an interest in TechStack, so weigh his view with that in mind.
[00:02:40] It reaches the technicians too. Thread, which sells service management software to MSPs, says that at wheelhouse IT, 25 technicians, not engineers, built more than 70 automations in 8 weeks. Those cover 90% of the shop's Microsoft 365 workload. Those are Thread's numbers. So the buyer is becoming the builder, at the enterprise, at the small business, and inside the service provider. Which raises the part nobody prices in when they decide to build.
[00:03:10] What happens after it ships? If you're listening to this and haven't hit follow yet on Apple Podcasts, search Business of Tech. It takes 5 seconds, and you'll get the next episode automatically. This episode is supported by Halo. Automation is becoming a defining characteristic of modern managed services. But automation only works if the core platform supports it. Halo PSA gives service
[00:03:37] providers the flexibility to build powerful workflows, integrate automation tools, and design service processes around how their business actually runs. For MSPs building a more automation-driven operation, Halo PSA is one of the platforms increasingly showing up in those conversations. Learn more at usehalo.com. In events, from Ninja One, a free on-demand webinar on turning hygiene
[00:04:06] reporting into client retention. Link is in the show notes. Building software was never the expensive part. Keeping it running was. Brian J. Weiss knows that from his own shop's history. When ITech started in 2005, it had its own development team. It built its own ticketing system, its own password manager, its own documentation system. About 10 years later, those developers were busy with paying client projects
[00:04:33] and couldn't keep the homegrown tools current. So ITech bought at PSA. The build wasn't what failed, the upkeep was. That's what a software purchase actually buys. The product is the visible part. The patching, the security review, the fixes when something underneath changes. That's the vendor's job, and it's folded into the subscription. AI changes one side of that and not
[00:04:58] the other. The Association for Computing Machinery published a brief finding that AI-generated code is arriving faster than open source maintainers can check it, as Channel Dive reports. Agents can change code easily. Keeping up with those changes is the hard part. Co-author Shrinivas AB says that as generating software gets easier, the work shifts to verification. It also shifts to the question of
[00:05:25] who is accountable for maintaining it. You might say that's a problem for amateurs. Look at how it goes for the best resourced builders in the world. In the weeks before Meta launched its Muse agent, engineers found several security flaws, 404 media reports, citing a Meta source and internal documents. At least one could have let an ordinary user break out of Muse's virtual machine and reach
[00:05:51] Meta's sensitive internal databases. It went up to Mark Zuckerberg, and teams worked nights and weekends. The hardening push started 11 days before launch. Meta says it strengthened Muse through red teaming and its bug bounty and that the work continues. And OpenAI is still working out what its own agents did. After its test models broke in a hugging face, OpenAI told the security conference that it spent 3
[00:06:17] million GPU hours investigating, running codecs and other agents across more than 7 billion logs. Three infrastructure experts told Fortune that's somewhere between 4 and 15 million dollars in compute. The company that built the agents needed agents to audit them. In plain terms, AI made writing software nearly free and left the cost of owning it right where it was. When you buy, the vendor carries that
[00:06:45] cost. When you build, someone else has to. And if nobody is named, it lands wherever the software runs. For most of your clients, that's somewhere you're already responsible for. For an MSP, that cost arrives without an invoice attached. A client builds an app. It runs on a laptop you manage, signs in with an account you administer, and reaches data you're responsible for
[00:07:11] protecting. There's no vendor to call. The control that still works sits outside the software. What the device lets it touch and which identity it runs as. That's your layer. Look at what the platform owner did when it decided it couldn't trust the software running on it. Apple says it will add new controls around macOS full disk access. The setting that lets an app reads a user files, mail, messages, and browsing
[00:07:38] history. Apple says some developers use it in ways that expose everything on a system without users' understanding. It also says that as AI agents become more capable, the risk will grow substantially. Its answer isn't a fix inside anyone's agent. It's a permission at the operating system that will require very explicit user action. TechCrunch notes that's informed consent, not a new limit. But it shows where
[00:08:07] the decision lands when the builder can't be trusted. The layer underneath. Now look at who's actually holding that layer. VentureBeat surveyed organizations with a hundred or more employees on how they secure their AI agents. Of the 106 that named a primary security layer, 99% rely on a model or cloud provider, with OpenAI's own guardrails alone at 40%. Specialist security and identity vendors,
[00:08:34] whose controls sit apart from the platform the agent runs on, came in at 1%. And among companies with agents in production, 62% run some or all of them are in shared keys or a person's login. That's VentureBeat's own sample of its readers, so it's small and self-selected. But the shape is clear. The control outside the builder is mostly empty. And identity is where the gap is widest. So here's the
[00:09:02] choice. Treat every tool a client builds and everyone you build as something you issue an identity to. It's own account, scoped permissions, a named owner, or it doesn't run in the tenant. Or let it run on whoever's login was handy and inherit the vendor's job without the vendor's resources. Either way, that work has a cost and it isn't on anyone's invoice. This episode is supported by ScalePad.
[00:09:30] There's an argument going around that customer success isn't a department you add to an MSP, it's the operating model. And that most shops are running service delivery and calling it the same thing. ScalePad rebuilt Lifecycle Manager around that idea, bringing the information you have about a client into one place. So instead of piecing together the story across different tools, your team can understand the whole client, plan what comes next, and manage the relationship more
[00:09:59] strategically. The idea is to make customer success something your whole team can actually operate around and give your clients a complete view of how your work connects to their business goals. You don't have to buy the software to find the argument worth an hour of your thinking. ScalePad.com backslash MSP Radio Why do we care? Because the upkeep a vendor used to fold into the subscription doesn't disappear when
[00:10:28] the client builds instead. It's landing inside your flat per-user fee. Every client-built tool you issue an identity to is a small software asset you now maintain. The permission review, the patch, the call when it breaks. At the next renewal, list client-built tools by name in the agreement and count them. So your price grows with what they build instead of holding still while the work doesn't.
[00:10:56] What to consider? Price the upkeep, not the build. Clients think the cost of software is in making it. The cost you carry is what the vendor used to. An identity, a permission review, dependency patching, and retiring the tool when nobody uses it anymore. Define one unit, one built tool with one identity, and one named owner and price per unit. That way a client with a dozen builds pays differently from one
[00:11:23] with none. Tie the price to the identity. A tool running its own account can be scoped, monitored, and shut off without disrupting anyone else. A tool on a person's login can't, and VentureBeat found that's how 62% of companies with agents in production run some or all of them. Price the first kind is ongoing coverage. Quote the second as a one-time project to move it onto its own identity.
[00:11:50] Set the number from your own builds. Brian Weiss described TechStack's ongoing role as keeping development, test, and production current with Microsoft's roadmap. That's upkeep sold as a service with a price attached. Track what it takes your team to maintain your own automations for a quarter and base the per-tool price on that record rather than a guess. If this trend continues,
[00:12:15] within the next two annual renewals, the clients with the most built tools will be the one whose flat per-user price hides the most unpaid upkeep. The MSPs that priced built software as its own line will be the ones whose margins held. This is the Business of Tech. Want to go deeper than the news? The Small Biz Thoughts community is where MSP owners and operators
[00:12:44] work on the business, not just in it. Member meetings, a deep resource library, and courses through IT Service Provider University. Everything you need to run the practice you actually want. Join us at smallbizthoughts.org. Interested in advertising? Head to mspradio.com slash engage. The Business of Tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech. Thanks for
[00:13:13] listening. I'll see you on the next episode. Part of the MSP Radio Network. The Business of Tech is a Professor of Fame, a Dream of the sits and the Arts Director of the New York Times. The Business of the Business of the Business of the University is a a campus network that we need to improve to work. It's been a healing process of trying to help to ensure a space

