AI Didn't Remove the Work. It Just Moved It.

Rodney Hall, COO

An overflowing inbox tray tips its papers into a second tray shaped like a mechanical gearbox.

AI is not removing operational overhead at most MSPs, it is relocating it. New survey data shows the hours saved on frontline ticketing are being reabsorbed by model fine-tuning, integration upkeep, and manual output review, so total workload keeps climbing even where AI is hitting its return targets.

Why Is Workload Rising Even When AI Meets ROI Targets?

Because the return and the workload are being measured in different places. SolarWinds surveyed more than 800 IT professionals for its 2026 State of ITSM report and found 84 percent say AI has met or exceeded ROI expectations, with real time savings on core service management tasks. In the same survey, 52 percent say their overall workload has increased since adopting AI, and only 7 percent say the cost of adoption matched what they had planned for.

Those two findings are not a contradiction. AI genuinely cuts the time spent on the tasks it replaces, first-line ticket triage, routine classification, initial response drafting. What the ROI number leaves out is the new work that shows up once the tool is running in production: tuning the model as your environment changes, keeping integrations working as vendors update their APIs, and reviewing outputs before they reach a client. SolarWinds found teams have been running AI in their ITSM environment for about 16 months on average, and most are still managing that overhead rather than past it.

Where Does the New Overhead Actually Live?

It lives in three places your original automation business case probably did not price out. Model fine-tuning is ongoing, not a one-time setup cost, because ticket patterns, client environments, and product catalogs keep shifting under the model. Integration maintenance is recurring because every vendor endpoint, permission model, or data schema change on the other side of an API can quietly break a workflow you already counted as automated. Manual review is the biggest one, because most providers still have a person checking AI-drafted client communications and AI-suggested remediations before they go out, and that review time does not disappear just because the draft got faster to produce.

None of that is a reason to slow down automation. It is a reason to budget for it correctly. A rollout plan that only counts the hours an AI tool saves on tickets, without also counting the hours it adds back in tuning, integration babysitting, and review, will always look better on paper than it performs in the first year of live operation.

Think about what happens to a technician who used to spend twenty minutes closing a routine ticket by hand. AI can cut that drafting and triage time to a few minutes. But that same technician now spends part of the time saved checking the AI's classification, correcting a wrong root-cause guess, or fixing a client-facing message that reads slightly off. The net time saved is real, but it is a fraction of the headline number, and the fraction shrinks further every time an integration breaks or a model needs retraining against a new client environment.

Who Actually Feels This Gap First?

Your first-line managers, not your leadership team. SolarWinds' 2026 IT Trends Report found 41 percent of first-line managers say AI has increased expectations without reducing workload, more than double the 18 percent of C-suite respondents who say the same. That gap matters operationally: the people closest to the actual queue are absorbing the new overhead before it shows up in any dashboard leadership is looking at.

If your own reporting only tracks tickets closed or automation coverage percentage, you are measuring the exact layer where the gap is smallest. The overhead is visible first at the shift-lead level, in complaints about review queues backing up or integration breakage eating into the day, well before it shows up as a missed SLA or a margin number that needs explaining.

That lag matters because SLA risk and client retention are downstream of exactly this gap, not separate from it. A team quietly absorbing extra review and integration-fixing hours has less slack left for the next incident, the next after-hours escalation, or the next client asking for a status update. By the time that shows up as a missed response-time target, the root cause is usually months old and already baked into how the shift has been running.

Shadow AI Adds a Second, Quieter Overhead Tax

Unsanctioned AI use inside your own operation or a client's environment adds oversight work nobody assigned to anyone. Verizon's 2026 Data Breach Investigations Report, built with original research alongside Anthropic, found frequent AI tool use by employees surged from 15 percent to 45 percent in a single year, and that 67 percent of employees accessing AI tools do so from non-corporate accounts on corporate devices. Every one of those unsanctioned sessions is a gap in whatever governance process your operation is counting on to keep client data controlled.

That is not a hypothetical risk sitting in a slide deck. It is a live operational fact: someone on your team, or on a client's staff, is already using a consumer AI tool you have not vetted, on a device you are contracted to secure. The overhead here is not the tool itself, it is the ongoing work of finding, evaluating, and either sanctioning or blocking whatever shows up next, on a cadence that never really ends.

For an MSP holding a managed services agreement with data handling and security obligations written into it, that gap is not abstract risk either. A client employee pasting sensitive account data into an unsanctioned AI tool on a device your team is contracted to secure and monitor sits squarely inside the scope of what you agreed to manage, whether or not anyone flagged it as an incident.

What Should MSPs Actually Do About This?

Name the three overhead categories in your own operation and assign an owner to each, the same way you would assign an owner to patch management or backup verification. Fine-tuning, integration maintenance, and manual review are not incidental tasks that get absorbed into whoever has time. Left unowned, they get done inconsistently, or not at all, until a client notices an AI-drafted message that should have been caught in review.

Overhead categoryWhat it actually requires
Model fine-tuningA recurring calendar slot, not a one-time setup task
Integration maintenanceMonitoring for vendor-side API and schema changes
Manual reviewA named reviewer and a defined review standard, not an ad hoc check

Second, separate your automation coverage metric from your total workload metric, and report both. A rising automation coverage number next to a rising total workload number is the SolarWinds finding playing out inside your own shop, and it is far better to see that pairing on your own dashboard than to hear about it first from a burned-out shift lead. This is exactly the kind of operational discipline built into how Catalyst structures onboarding and ongoing AI-driven service delivery, so the overhead categories above get assigned and tracked rather than absorbed silently into everyone's day.

Third, treat shadow AI governance as a standing line item, not a project with an end date. A quarterly review of what AI tools staff and client employees are actually using, sanctioned or not, is cheaper than discovering the gap during an incident postmortem. It does not need to be elaborate to be effective. A short checklist reviewed at the same cadence as patch compliance, covering which AI tools are sanctioned, which devices have accessed unsanctioned ones, and who owns the follow-up, closes most of the exposure without adding a full-time role to your headcount.

Fourth, budget the three overhead categories into every new AI rollout before you sign off on it, not after the first quarter of live use surprises you. If you are trying to see where AI-related overhead is already concentrated across your own current stack, running it through the stack builder is a fast way to surface which services carry the heaviest ongoing maintenance load relative to what they are actually saving your team, so the next rollout gets priced with the real cost included instead of just the advertised one.

The tools that reduce real operational overhead are the ones built to carry the maintenance, integration, and review burden themselves, not just the ticket volume. Actiforge's full product catalog is packaged around that distinction rather than around raw automation counts.

See the full stack to see how each tool handles its own upkeep instead of quietly handing it back to your team.

Sources: SolarWinds 2026 State of ITSM Report | SolarWinds 2026 IT Trends Report | Verizon 2026 Data Breach Investigations Report (research conducted with Anthropic).