For millions of smaller companies, the first serious response to workplace AI risks may not come from an internal security team or an AI vendor. It may come from the outside technology provider already managing their email, devices and Microsoft 365 accounts. Inforcer’s $50 million funding round is a bet that these managed service providers will become the operational front line of AI governance.
An employee opens an AI chatbot during the workday and pastes in a customer email, a sales proposal or a piece of internal code. The act may take only a few seconds. It may even feel harmless. There is no security incident siren, no locked door and no obvious sign that company information has left the organization.
But for a small business without a dedicated technology or security department, that moment can create a difficult question: Who is supposed to notice, assess and respond?
The answer is increasingly likely to be an outside IT provider.
London-based Inforcer is building its business around that shift. The company sells software to managed service providers, or MSPs, that administer Microsoft 365 environments for many business customers at once. On July 30, 2026, TechCrunch reported that Inforcer had raised a $50 million Series C led by Insight Partners.
The round brings the company’s fundraising over the past 18 months to $110 million across three rounds. Inforcer said its business has grown 300% year over year and that its valuation doubled between its Series B and Series C, although it did not disclose the valuation figure.
The money itself is notable. But the larger story is what investors appear to believe a company managing Microsoft 365 should do next.
An IT-management vendor was once mainly concerned with keeping accounts configured, devices connected and software working. Now, Inforcer is adding tools intended to identify unauthorized employee use of artificial intelligence and detect emerging security threats. Its founders argue that AI is changing the risk profile of small and medium-size businesses in two directions at once: workers can expose company information by using unapproved AI services, while attackers can use AI to make their campaigns faster, more convincing and easier to scale.
That combination is turning AI governance from a specialized corporate concern into an everyday administrative problem.
And because smaller businesses often rely on outsourced technology providers, the people responsible for managing this problem may not work for the company facing it.
The AI problem arrives before the policy
Large companies can respond to new technology with committees, compliance teams, legal reviews and dedicated security personnel. A small business may have a different arrangement. Its Microsoft 365 environment, user accounts, device policies and security monitoring may all be handled by an MSP that serves dozens or hundreds of customers.
That structure has advantages. A company can obtain expertise without hiring a full internal department. It can outsource routine maintenance and gain access to systems that would otherwise be too expensive or complicated to operate. For many businesses, an MSP is not merely a contractor. It is the practical extension of the company’s IT function.
The same structure also creates a dependency. When new risks emerge, the business may not have the time or knowledge to develop a response on its own.
Generative AI has moved quickly enough to expose that gap. Employees can find and begin using AI services without waiting for a formal procurement process. In many workplaces, the tools are available through a browser, require little training and can produce an immediate benefit. A worker might use one to summarize documents, draft marketing copy, translate a message, analyze a spreadsheet or generate software code.
The convenience is precisely what makes the activity difficult to control.
Traditional corporate software often leaves recognizable footprints. A new application may require a purchase, an installation or an administrator’s approval. Web-based AI services can enter through normal internet access, and employees may use personal accounts rather than company-managed ones. The technology can therefore become part of a company’s workflow before anyone has decided whether it belongs there.
This is the environment Inforcer’s Shadow AI detection product is designed to address. The tool is intended to identify employees using unauthorized AI services on company devices. The name refers to technology being used outside the organization’s approved systems and policies, much as “shadow IT” once described employees adopting unsanctioned cloud applications.
The challenge is not simply discovering that an AI tool was opened. An organization also needs to determine what happened next. Was sensitive information entered? Was the service used for a low-risk task? Is the employee relying on an unapproved tool because the company has not supplied a suitable alternative? Should the response be education, a policy change, technical blocking or a formal investigation?
Detection is only the first step. But without detection, the rest is impossible.
Why smaller companies are especially exposed
Small and medium-size businesses are not necessarily less careful than large enterprises. They often operate with fewer layers between decision-makers and customers, and a single security incident can carry an especially heavy cost. The difference is that they frequently have fewer people available to manage expanding technology risks.
A large organization might assign separate responsibilities to a chief information officer, a security operations team, a data protection officer and a legal department. In a smaller company, those functions may be divided among a handful of employees whose primary jobs have little to do with cybersecurity.
Outsourcing helps solve the staffing problem, but it changes the shape of accountability. The company still owns the consequences of a data leak or compromised account, while its MSP may be the party best positioned to see what is happening across devices and cloud services.
That makes MSPs an attractive channel for AI-security products. Instead of selling a separate tool to every small company, a vendor can sell software to the provider already serving many of them. A single platform can then be used to administer multiple customers, apply policies and monitor activity across a broader portfolio.
Inforcer’s older 365 Manager product was priced per client, according to the company. Its newer security product is pushing the business toward per-user pricing. Future AI-related products could use consumption- or token-based pricing, Inforcer says.
Those pricing changes reveal something about how AI governance may develop commercially. Traditional IT administration is often tied to the existence of a customer account or environment. AI activity is more fluid. It can be measured by users, events, workloads or the amount of processing involved. A company may eventually pay not just for the number of employees covered, but for the amount of AI use being monitored or analyzed.
That could create a more flexible business model for vendors. It could also make costs harder for customers to predict.
If AI governance becomes another subscription layered onto email, endpoint protection, identity and backup services, the small-business technology stack may grow more expensive and more difficult to understand. MSPs will have to explain not only what a tool does, but why it is necessary and how its pricing relates to the risks it is meant to control.
The two-sided risk of workplace AI
Inforcer’s argument rests on two related but distinct problems.
The first is internal misuse or accidental exposure. Employees may send confidential information to an AI service without understanding how the information will be handled. They may copy in a contract to obtain a summary, upload a database error to get help with code or ask a chatbot to rewrite a document containing personal information.
The worker’s intention may be constructive. The risk comes from the mismatch between the task and the organization’s ability to control the data once it leaves approved systems.
This is not an entirely new problem. Employees have long used personal storage accounts, consumer messaging applications and unauthorized productivity tools. AI makes the issue more immediate because the tools are designed to accept natural-language instructions and information. Their value often increases when users provide more context.
The second risk comes from outside the organization. Attackers can use AI to automate reconnaissance, generate variations of phishing messages and make fraudulent communications sound more natural. A convincing email no longer requires an attacker to write perfectly in the target’s language or manually tailor every message. AI can help produce more attempts, with more customization, at lower cost.
That does not mean AI has made cyberattacks unstoppable. It does mean that small businesses may face a higher volume of plausible threats while lacking the staff to review every alert. A weakly written phishing email can be easy to spot. A message that resembles a supplier’s tone, refers to a real project and arrives at the right time is more difficult for a busy employee to dismiss.
The result is a security environment in which the old distinction between “human error” and “technical attack” becomes less useful. Employees are making decisions inside systems that attackers are actively shaping. The company needs technology, training and policies that work together rather than treating each incident as an isolated mistake.
Inforcer’s threat detection and response product is aimed at identifying security risks as they emerge. The company is positioning that capability alongside Shadow AI detection, suggesting that AI governance should be part of a broader security operation rather than a separate compliance exercise.
That positioning matters. Companies do not experience risks in neat categories. An employee who uses an unauthorized AI service may also have an account protected by weak settings. A phishing message may lead to a compromised Microsoft 365 identity. A stolen account may then be used to access files or send further messages. The most useful systems will need to connect these events rather than merely record them.
Why Microsoft 365 is the center of the bet
Inforcer remains focused on Microsoft’s ecosystem. Its reasoning, as described by the company, is that Microsoft is strongly oriented toward larger enterprises, leaving room for specialists serving smaller businesses.
Microsoft already offers a wide range of identity, productivity and security products. That creates an obvious question for any independent provider: If the platform owner can build a capability itself, why should a customer need another layer?
For smaller companies, the answer may be less about the existence of Microsoft’s features than about how they are configured, combined and maintained. A security setting that exists in a console is not necessarily a security program. Someone still has to decide which policies apply, monitor alerts, handle exceptions and explain the results to a customer.
MSPs can serve as the translation layer between large vendors and small businesses. They can turn a complicated collection of platform controls into a repeatable service. In theory, that allows a small company to benefit from enterprise-grade tools without hiring enterprise-sized staff.
The approach also gives an independent vendor a specific place in the market. Rather than competing to become the main workplace platform, Inforcer is trying to become infrastructure for the companies that manage those platforms on behalf of others.
This is a familiar pattern in technology. When software becomes widespread, a secondary market develops around implementation, monitoring, customization and support. The value may shift from selling the original application to helping customers operate it safely and efficiently.
AI governance could follow the same path. The companies that make AI systems may provide controls, but the day-to-day work of enforcing those controls could be distributed among identity providers, security vendors, consultants and MSPs.
Shadow AI as a new managed-service category
Shadow AI could become a distinct category within managed services, similar to endpoint security or identity management. Whether it does will depend on how persistent the problem becomes and whether customers are willing to pay for ongoing oversight.
There are reasons to expect demand. AI tools are spreading across departments faster than many formal technology approval processes can adapt. Employees are likely to continue experimenting, especially when the tools improve productivity in visible ways. At the same time, companies face pressure to demonstrate that they know where sensitive data is going and who is using it.
But detection alone may not be enough to support a durable category. A tool that produces a list of unauthorized AI applications without helping a company make decisions could quickly become another source of noise. MSPs already manage large numbers of alerts. Adding more notifications will not necessarily improve security if no one has the time to investigate them.
The strongest products will likely need to support a complete workflow. They may help providers identify the application, determine which user accessed it, understand whether company data was involved, apply a policy and document the response. They may also need to distinguish between acceptable experimentation and genuinely dangerous behavior.
That last point is important because an overly restrictive approach can undermine the reason employees adopted AI in the first place. If a company blocks every unfamiliar tool, workers may find ways around the controls or use AI through personal devices. If it permits everything, it may lose visibility into sensitive activity. Governance has to negotiate between productivity and protection.
MSPs are positioned to help with that negotiation because they often understand both the technical environment and the customer’s operating constraints. They may know which employees handle financial records, which teams work with customer data and which systems are essential to daily operations. A generic security product cannot easily supply that context on its own.
The provider’s role could therefore expand from administrator to advisor. It may be expected to help customers establish acceptable-use rules, select approved AI services, train staff and review incidents. That is a more valuable relationship than simply installing a monitoring agent, but it also requires more judgment and responsibility.
The coming debate over who governs AI
Inforcer’s funding points to a broader question: Should AI governance be handled primarily by the companies that build AI systems, the platforms where those systems are accessed or the organizations that use them?
There is no single answer.
AI vendors can design privacy controls, data-retention settings and administrative dashboards. Cloud and workplace platforms can determine how accounts, devices and permissions are connected. Customers can set policies based on their own legal obligations and business risks. MSPs can operate those policies for companies that lack internal resources.
The distributed model may be unavoidable. No single provider can understand every customer’s data, workflow or tolerance for risk. A general-purpose AI vendor cannot know whether a particular document is commercially sensitive. Microsoft cannot determine every small company’s acceptable use policy. An MSP may know the customer’s environment but not control the behavior of every external AI service.
The danger is that distributed responsibility can become unclear responsibility. When an unauthorized tool is detected, who decides what to do? When an AI-generated phishing campaign succeeds, who is accountable for the failure? When a customer asks an MSP to monitor employee AI use, what limits should apply?
These questions reach beyond software features. They involve workplace privacy, employee trust and the balance between managerial oversight and individual autonomy. A company may have a legitimate reason to know which services are being accessed from its devices. That does not automatically mean it should inspect every prompt an employee writes or create a permanent record of every interaction.
A responsible AI-governance service will need to make those distinctions visible. It should clarify what is collected, how long it is retained, who can access it and under what circumstances it can be used in an employment decision. Small businesses may need more guidance in this area precisely because they have fewer internal legal and compliance resources.
The market opportunity is real, but so is the risk that governance becomes synonymous with surveillance.
What investors are seeing
Insight Partners’ leadership of Inforcer’s Series C indicates confidence in a market that is still taking shape. The company’s reported growth and valuation increase suggest that investors see demand not just for traditional Microsoft 365 administration, but for security services attached to the rapid adoption of AI.
The financing also reflects a broader investment thesis. The future of enterprise AI may not be defined only by the companies building the largest models. It may be shaped by a less visible layer of businesses that manage access, permissions, security and compliance around those models.
That layer can be commercially significant because AI adoption is uneven. A multinational corporation may negotiate directly with a major software vendor and maintain an internal AI office. A small manufacturer, accounting firm or professional-services company may depend on a local or regional MSP to decide what needs to be enabled, restricted or monitored.
If those providers become the channel through which AI security reaches smaller businesses, they could influence adoption as much as the underlying vendors do. They may determine which products are recommended, which risks receive attention and what customers consider normal operating practice.
Inforcer is not alone in pursuing the broader security market, and its funding does not establish that Shadow AI will become a dominant category. It does, however, offer a concrete example of how expectations are changing. A company that once helped providers manage Microsoft 365 environments is now being valued partly for its ability to help them manage the consequences of AI use.
That is a subtle but important transition. The management layer is moving closer to the behavior of individual employees and the tactics of individual attackers.
From software feature to everyday responsibility
The most consequential part of this story may not be the $50 million round or the prospect of token-based pricing. It is the redistribution of responsibility.
AI vendors will continue to improve their own safeguards. Microsoft will continue to build security and administration features into its ecosystem. Yet many smaller businesses will still need someone to configure those controls, interpret their warnings and decide how to respond when technology meets human behavior.
That work is unlikely to happen in a laboratory. It will happen in the ordinary routines of businesses: when a new employee receives an account, when a finance worker experiments with a chatbot, when a suspicious message reaches an inbox or when an owner asks whether an AI tool can be used with customer information.
MSPs are already present in those routines. Their opportunity is to turn AI governance into a practical service rather than a collection of abstract warnings. Their challenge is to avoid selling fear without delivering clarity.
For employees, the outcome should not be a workplace where every interaction with an AI system is treated as evidence of misconduct. For business owners, it should not be a false promise that a dashboard can eliminate all risk. And for technology providers, it should be an acknowledgment that security depends as much on policies and decisions as on detection engines.
The rise of Shadow AI may therefore resemble the earlier evolution of endpoint security and identity management. What begins as an unfamiliar threat becomes a routine part of operating a business. Over time, customers stop asking whether the category exists and start asking what level of service they need.
Inforcer is betting that this transition has already begun, and that managed service providers will be the ones carrying it into the small-business market. If the bet succeeds, AI governance will become less about a single company controlling artificial intelligence and more about a network of providers quietly shaping how it is used.
That may be the practical future of AI security: not one dramatic barrier around every model, but a series of everyday decisions made by the people who keep smaller companies connected, productive and, ideally, aware of what their technology is doing.