The New MSP Margin Stack: Backup, Security, and Now Sovereign AI Ops
Most MSPs are still trying to win the next decade with yesterday's stack.
Shared infrastructure got commoditized. Backup became table stakes. Security created a margin reset. Now the next layer is showing up fast: sovereign AI operations.
If you run a hosting company, dev shop, MSP, or IT services business in Europe, this is not a side quest. It is the next margin ladder.
I've spent 20+ years in hosting and infrastructure, helped scale a platform business to €240M ARR, and been through 15+ acquisitions across multiple market cycles. I've watched this movie a few times: the providers who package trust before the market has the vocabulary for it take the profit, while everyone else ends up reselling someone else's platform at thin margin.
That is where we are again.
According to Cisco, citing a February 2025 Canalys survey of more than 1,000 global B2B IT channel partners, 49% said managed services were their most important revenue opportunity and top gross-margin contributor (Cisco). That tells you the base layer is already shifting. Buyers want outcomes, not boxes.
Now add the Europe-specific pressure. Accenture found that 62% of European organizations are seeking sovereign solutions, 60% plan to increase sovereign AI investment by 2027, and in Switzerland that number rises to 64% (Accenture). At the same time, the European Commission says that at least 15 AI Factories should be operational through 2025–2026, with at least 9 new AI-optimized supercomputers that will more than triple current EuroHPC AI computing capacity (European Commission).
That combination matters.
Demand is moving up-market toward trusted AI infrastructure. European compute capacity is being built. And most MSPs are still selling infrastructure, backup, and SOC bundles like AI is a bolt-on project.
That is too small.
The Margin Stack Ladder
The cleanest way to think about the next MSP move is this four-step ladder:
- Commodity infrastructure
- Managed backup
- Managed security
- Sovereign AI operations
Each step increases three things:
- trust
- strategic dependence
- pricing power
That last step is where most providers are under-positioned.
Layer 1: Commodity infrastructure
Servers, hosting, cloud resale, admin, patching, helpdesk. Necessary. Useful. Hard to differentiate.
The trap is obvious: customers buy this on price until something breaks. Even when you deliver well, you are still too easy to compare.
I grew up commercially in hosting. I know how this ends. Once the category matures, the market stops paying for effort and starts paying for certainty. If all you sell is raw infrastructure capacity plus support hours, you are playing defense.
Layer 2: Managed backup
Backup changed the game because it converted infrastructure from a utility into risk insurance.
The customer was no longer buying disk and bandwidth. They were buying recovery time, operational continuity, and fewer sleepless nights after ransomware or human error.
That is why backup became such a strong recurring revenue layer. It translated technical plumbing into business language.
Layer 3: Managed security
Security pushed the same dynamic even further.
Now the conversation moved from uptime to resilience, exposure, auditability, and board-level risk. The provider that could monitor, respond, harden, and report was suddenly much harder to replace than the provider offering hosting plus support.
Security also taught a crucial commercial lesson: the category that wins is not the fanciest technology category. It is the one that maps directly to executive anxiety and measurable risk reduction.
That is exactly why AI operations is becoming interesting.
Layer 4: Sovereign AI operations
This is where the next margin expansion sits.
Not AI consulting. Not random chatbot projects. Not a Copilot resale page with a logo slapped on it.
Sovereign AI operations means you manage the environment where AI runs, the workflow where it creates value, and the control layer that makes it acceptable for European buyers.
That includes things like:
- approved models and routing policies
- logging and traceability for AI-assisted workflows
- data residency controls
- identity and access guardrails
- human-in-the-loop checkpoints
- usage monitoring, cost visibility, and exception handling
- packaging AI into vertical operational outcomes
That is a real managed service.
It also happens to sit exactly where the market is moving.
Why Europe changes the economics
US commentary still treats AI like a tooling race. Europe forces a different conversation.
The real European buyer question is not Which demo looks smartest. It is Can we deploy this without creating legal exposure, governance chaos, data leakage, or supplier lock-in we cannot explain to the board.
That question is gold for MSPs.
The Accenture data matters because it shows sovereign demand is not a fringe public-sector issue anymore. When 62% of European organizations are already seeking sovereign solutions and 60% plan to spend more by 2027, you are looking at a broad procurement shift, not a niche compliance edge case (Accenture).
The European Commission's AI Factory buildout matters for a different reason. More local AI compute means sovereign AI stops being an abstract policy slogan and starts becoming infrastructure the market can actually buy (European Commission).
In plain English: buyers want more control, and Europe is building more local capacity. That creates room for regional operators who know how to package, govern, and support the last mile.
That operator layer is not going to be owned entirely by hyperscalers.
What sovereign AI ops actually looks like in practice
Most MSPs overcomplicate this because they jump straight to model talk.
Start with the operating model instead.
Here's what works:
1. Pick the workflow before you pick the model
Do not lead with we offer AI. Lead with one measurable operational use case.
Examples:
- service desk triage with human escalation
- proposal drafting with approved knowledge sources
- document classification for regulated teams
- ticket summarization across support queues
- internal knowledge retrieval with audit logs
- sales-assist workflows for account teams that cannot leak CRM data externally
That is how you get to 30 days to proof.
2. Wrap governance around the workflow, not around the theory
Most companies have policies. Very few have operational guardrails.
The difference matters.
A real sovereign AI service should specify:
- which data can enter the system
- which models can process which classes of data
- where prompts, outputs, and logs are stored
- when human review is mandatory
- how exceptions get escalated
- how usage and quality get reviewed monthly
That is much more valuable than an AI strategy workshop.
3. Sell the control plane, not just the implementation
Anyone can spin up an LLM workflow now. The durable value is in the control plane.
Who manages access? Who monitors drift? Who tracks output quality? Who contains prompt leakage risk? Who shows the customer what is running, where, and why?
If you answer those questions, you are not selling a project. You are selling an operating layer.
4. Package vertically
Horizontal AI offers sound modern and sell poorly.
Vertical packaging sounds boring and closes deals.
Examples:
- legal intake and matter triage for law firms
- claims and document workflows for insurers
- service desk copilots for MSP customers
- knowledge and quoting automation for industrial distributors
- secure internal AI assistants for PE-backed portfolio companies
The point is not to become a software company overnight. The point is to turn repeatable delivery patterns into managed-service SKUs.
The proprietary framework: Margin Stack Ladder
Here is the practical framing I'd use with any MSP leadership team.
The Margin Stack Ladder is not about abandoning your current business. It is about moving customers up one trust layer at a time.
Step A: Stabilize the base
Make sure your infrastructure, backup, and security offers are packaged cleanly. If the first three layers are messy, sovereign AI ops becomes a promise you cannot support.
Step B: Choose one regulated or trust-sensitive customer segment
Do not launch across the entire customer base. Pick a segment where control and auditability already matter.
Good targets:
- financial services
- healthcare-adjacent providers
- industrial and manufacturing firms with sensitive IP
- public-sector-adjacent suppliers
- PE-backed companies under pressure to modernize without creating governance mess
Step C: Productize one AI workflow with one control pattern
One workflow. One playbook. One review model.
This is where most providers win or lose. If you build five different pilots for five different customers, you have an agency problem, not a managed service.
If you build one repeatable deployment pattern, now you have leverage.
Step D: Expand from workflow to operating system
Once one workflow proves value, expand into usage monitoring, governance reviews, model policy, cost control, and rollout support across more teams.
That is the jump from implementation revenue to recurring operating revenue.
Where most MSPs will screw this up
Three predictable mistakes:
Mistake 1: Selling AI as a feature instead of a managed outcome
If the offer is we can help you use AI tools, margin dies quickly.
If the offer is we run a governed AI workflow for this sensitive business process with reporting, oversight, and support, now you have something the buyer can defend internally.
Mistake 2: Treating sovereignty as marketing copy
European buyers can smell fake sovereignty in seconds.
If your answer is just the data center is in Europe, that is not enough. They want clarity on jurisdiction, access, model handling, logs, controls, and vendor dependencies.
Mistake 3: Waiting for the perfect stack
You do not need the final architecture to start. You need one credible, controlled service that solves one painful workflow.
The market rewards shipped proof, not slide decks.
The commercial case
Let's keep this simple.
Commodity infrastructure compresses. Backup holds. Security expands. AI operations can compound.
Why? Because the value is closer to business process ownership.
The more your service touches governance, workflow execution, and operational reporting, the harder it becomes to rip out. That does not just improve margin. It improves retention, deal stickiness, and strategic relevance inside the account.
This is also the hidden door for smaller European operators. You are not going to outspend hyperscalers on compute. You do not need to. You need to own the trust layer they are structurally bad at localizing.
That means:
- local commercial relationships
- local regulatory context
- sector-specific packaging
- clear operational controls
- fast deployment without enterprise theater
That is enough to build a serious wedge.
If I were running an MSP growth plan right now, I would not ask, How do we sell more AI?
I would ask, Which customer workflow can we govern, host, monitor, and support better than anyone else in our region?
That is the right question.
The 90-day move
If you want to turn this into something real, here is the move:
- audit your current customers for trust-sensitive workflows where AI could help but governance is the blocker
- pick one vertical and one use case
- build a controlled deployment pattern with logging, review, access rules, and support
- price it as a recurring operating service, not a one-off experiment
- use the first deployment as the proof asset for the next five
That is how you climb the ladder.
The MSPs that win the next phase will not be the ones shouting loudest about AI. They will be the ones who package sovereign AI operations the way the last generation packaged backup and managed security: boring enough to trust, operational enough to scale, valuable enough to renew.
That is where the real margin lives.
If you want a blueprint for how to package that offer, the thinking is the same one we use in our AI operating approach and in hands-on deployment work with European operators.
