How to Stifle Open Source Without Banning It
Benedikt Langer
6 Min. Read The sharpest argument against China’s top open AI comes from a man at OpenAI. Dean Ball, ...
9 min read · Published: 04/23/2026
Managed Services have undergone a significant transformation over the past five years, a shift that many supervisory boards have yet to incorporate into their governance frameworks. What was once viewed merely as a cost-cutting option has evolved into a strategic instrument. In 2026, the landscape will shift once more as AI budgets become significantly tighter, forcing boards to reassess their Build-Buy-Manage strategies. Executives who fail to grasp their organization’s contractual logic will make suboptimal decisions in upcoming board meetings, failing to capitalize on opportunities the situation presents.
What is a Managed Service in an enterprise context? A Managed Service refers to IT services where a specialized provider is responsible for defined processes or platforms in continuous operation, while control and strategy remain with the client company. Typical areas include Security Operations, cloud infrastructure, compliance reporting, network operations, and increasingly AI inference platforms. The difference from classic outsourcing lies in the continuous delivery responsibility including SLAs, KPIs, and audit rights.
The usual defense of Managed Services in boardrooms revolves around cost arguments. This argument still held in 2020. The reality of 2026 looks different. The primary driver for the return to managed models is not price, but access to scale effects and expertise that can no longer be built internally. For most companies, there is a lack of personnel depth in AI infrastructure, security, and compliance to even begin to keep pace with providers like Microsoft, Google, or AWS. This is not a failure of individual IT leadership. It is a structural change in the market.
In parallel, the products are changing. A Managed Service for Security Operations in 2020 meant: external SOC analysts, Tier-1 alerts, 24×7 shifts. In 2026, the same service means: AI agents that pre-sort incidents, apply playbooks, and route escalations to internal teams. The output remains comparable, the price per incident decreases, and the requirements for the provider increase. Anyone who negotiates a new framework agreement today and copies the old SLA metrics is buying a product from the penultimate generation.
The third shift concerns liability. With the EU AI Act, NIS2, and DORA, responsibilities are cemented in management bodies. Managed Services are not an outsourcing of liability, but a redistribution of operational power. Executives who implement managed models without a new contractual regime create a dual structure: formal responsibility in-house, but actual control with the provider. This will not work in the long run in regulated industries.
A sober board-level perspective establishes three axes before an architectural decision reaches the board. The first axis is differentiation. Which capabilities form part of our competitive advantage? Those with proprietary data, proprietary models, and proprietary customer interfaces build in-house. Those who need to operate generic infrastructure, general security operations, or standard compliance obligations buy or outsource. The question may sound trivial, but it’s rarely asked systematically because many IT landscapes have grown historically and have never withstood an honest portfolio review.
The second axis is competency availability. A board must clearly distinguish between temporary gaps and structural gaps. Temporary gaps are closed through reskilling or interim roles. Structural gaps lead to the managed model because the market has already decided the competition for talent. Those who still believe in 2026 that they can recruit twelve experienced Kubernetes platform engineers in-house are burning time. This is not capitulation but a resource allocation decision.
The third axis is contractual rationality. Managed services succeed or fail based on the contractual framework. Those who last set up their framework agreements in 2022 now face two risks: first, a pricing logic that grossly underestimates AI workloads. Second, the termination clauses are too short and don’t properly represent true exit scenarios. The next contract round belongs on the supervisory board’s agenda, not just in the purchasing department. Those who delegate this are delegating liability to a body without committee mandate.
The path is clearer in practice than the subject matter suggests. It begins with a clean portfolio review. A list of all critical IT services, mapped along three axes: differentiation, competence, and contract readiness. This list must not get lost in the feature jungle. Forty to sixty items are sufficient, sorted by business contribution and risk. The CIO and CFO are jointly responsible for the list because the classification affects investment questions. The supervisory board receives a summary with clear recommendations for each service.
The second step deals with contract architecture. Managed services require three regulatory frameworks that were not as sharply defined in 2020. First, an AI workload appendix with transparency about used models, training data origin, and hallucination budgets. Second, an exit clause that guarantees recurring data transfer in structured form. Third, a human-in-the-loop provision that defines when the provider may make autonomous decisions and when not. Those who do not have these three appendices in their standard contract will negotiate from a defensive position in 2026.
The third step is about control. The traditional sourcing department is considered too small for managed services portfolios in 2026. It needs reinforcement through a provider governance path that bundles technical, contractual, and economic figures monthly. This path reports to the CIO but has a direct line to the CFO and accountability to the supervisory board for approvals above a defined threshold. Without this structure, managed services control remains a gut feeling.
Those who want to properly establish this topic for 2026 should work with a 12-month perspective. The following milestones have proven to be a viable framework in board discussions.
Companies taking Managed Services seriously in 2026 need to have three conversations in their next board meeting. The first conversation is a position assessment. What services do we have, who is responsible for them, and when do which contracts expire? The answers must be documented, not just presented verbally. Those without a list have no control.
The second conversation is about goal setting. What direction should the service portfolio take by 2028? More managed services, more in-house operations, more buy solutions? The answer isn’t a percentage figure but a narrative that reflects in the business model. A board that thinks in percentages will be persuaded by providers using percentages.
The third conversation is about responsibility assignment. Who decides on managed services procurement above which threshold? Who approves AI workload additions? Who is accountable to the supervisory board for service failures? The clarity of these answers determines how robust the organization is when an incident occurs in the fourth quarter that internal IT cannot resolve alone. Robust organizations have formulated their answers by the second quarter. They make faster decisions because they don’t first need to painstakingly clarify internal responsibilities and external escalation paths.
In discussions with supervisory boards, three misunderstandings appear particularly frequently. The first is the assumption that managed services are primarily a cost issue. This may still apply to individual standard processes, but it is outdated in the broader context. Those who exclusively use price comparisons as a decision basis almost always choose the wrong solution. The decision basis should be quality per euro, not price per hour.
The second misunderstanding concerns control. Many executives assume that managed services relieve the IT organization. The opposite is true: The IT organization needs its own people to manage the provider, verify performance evidence, and develop contracts further. A managed model without its own orchestration capabilities creates dependencies, not relief. The rule of thumb is: Every major managed contract requires at least one dedicated internal control role.
The third misunderstanding is the most difficult because it is embedded in corporate culture. It essentially says: Whoever outsources services loses control and thus status. This misunderstanding affects IT leadership and is rarely openly expressed. The result is that managed service decisions that could be well justified rationally are not implemented internally. Supervisory boards can break this cycle if they don’t delegate the discussion to IT management but take a position themselves. A statement from a supervisory board that managed models are the strategic direction for certain services can resolve many debates within weeks.
Traditional outsourcing focused on cost reduction through personnel relocation. Managed Services in 2026 aim for quality and speed improvements through provider scale effects, particularly in AI, security, and compliance. The price advantage is a side effect, not the main driver. Governance requirements are higher because accountability remains in-house.
Based on our observations, the break-even point is at approximately 500 employees or a €50 million IT budget. Below this threshold, Managed Services are often addressed on a case-by-case basis. Above this, the governance effort, contract architecture, and control structure are justified by efficiency gains and risk reduction.
Transparency about deployed foundation models, origin of training data, hallucination budgets with escalation thresholds, human-in-the-loop provisions, audit rights for the compliance department, a well-defined exit clause with data portability guarantee, and liability limits for autonomous agent decisions.
From annual CapEx planning to rolling OpEx windows with quarterly forecasts. This requires a different alignment between CIO and CFO because deviations become more visible and need to be discussed more quickly. Many supervisory boards now demand a monthly drill-down.
Hyperscalers provide infrastructure scale effects, while specialized MSPs offer industry knowledge and regulatory expertise. The most attractive arrangement is often a hybrid model where a DACH MSP manages the regulated interface to the company and a hyperscaler provides the underlying infrastructure. Contracts should clearly define this interface.
Three metrics suffice as a core KPI set: Time-to-Resolution for relevant incidents, budget forecast accuracy compared to actual costs, and audit finding rate during regulatory examinations. Those who maintain all three metrics stable or improved have made a robust decision. Those who see any of these metrics decline have a control problem, not a procurement problem.
IT Outsourcing 2026: Nearshoring, AI or In-house?
IT Resilience 2026: Why DORA, NIS2 and ISO 22301 Belong in One Framework
Cloudmagazin: Mac Studio M5 for DevOps and Cloud Workloads
Source Cover Image: Pexels / Mikhail Nilov (px:8847198)