Professional services firms sell two things: expertise and
trust. Clients hand over their most sensitive information and expect it handled
better than they would handle it themselves. In 2026, the technology under that
promise is shifting fast.
AI moved from experiment to everyday tool in about a year.
Attackers kept getting more organized. Clients started treating their advisors
as part of their own attack surface, with questionnaires and audits to match.
And the billable model that funds most firms is running into an awkward
question: what happens when AI does the work in a fraction of the time?
For a firm with 10 to 300 people, that is a lot of pressure
on a lean IT footprint. Here are the 10 IT challenges hitting professional
services firms hardest heading into 2026 and 2027, and what separates the firms
that get ahead of them from the ones that react.
1. Shadow AI With No Governance
Adoption is not the question anymore. Organization-wide AI
use in professional services nearly doubled in a year, to 40% in 2026 from 22%
in 2025.[1]
Use is racing ahead of any structure around it.
Most firms have not put guardrails in place. In IBM's 2025
research, 63% of organizations said they had no AI governance policy to manage
AI or keep staff off unapproved tools.[7]
High levels of that shadow AI added an average of $670,000 to the cost of a
breach, and 97% of organizations that suffered an AI-related incident lacked
basic AI access controls.[8]
For a firm trusted with client data across many industries, that is
confidentiality risk you cannot see.
Where the right IT partner helps: The firms getting this right put structure
around AI before they scale it: a written usage policy, a review step before
new tools go live, and clear rules on what client data a tool may touch. A
managed IT partner can stand up that framework and give staff a safe, approved
way to use AI.
2. AI That Collides With the Billable-Hour Model
Professional services runs on billable time, and that
creates a genuinely hard question that other industries do not face in the same
way. If AI drafts, researches, and summarizes in a fraction of the hours, the
work still gets done, but the hours that used to pay for it shrink. Firms have
to rethink how they price and package value, not just how they produce it.
Most are moving without a scoreboard. Only 18% of firms say
they track the return on their AI tools, so the majority are adopting quickly
with little sense of what it does to profitability or client value.[2]
Where the right IT partner helps: A virtual chief information officer (vCIO) can build an AI roadmap that ties
tools to measurable outcomes, so AI lifts margins and client service instead of
quietly eroding both.
3. Agentic AI Acting on Client Data
The next wave is already arriving. 15% of organizations have
adopted some form of agentic AI, tools that take actions on their own rather
than just answering questions, and another 53% are planning or considering it.[3]
Software that can act, not just respond, raises the stakes on what it is
allowed to touch and on whose behalf.
An agent that can send email, move files, or update records
is only as safe as the permissions and oversight around it. Turned loose on
client data without controls, a helpful tool becomes a fast way to leak or
corrupt something that matters.
Where the right IT partner helps: Data-classification rules, least-privilege
access, and a review step before any agent goes live keep autonomous tools
inside safe boundaries.
4. Your Clients Are Auditing You
Corporate clients increasingly treat their outside firms as
part of their own attack surface. Security questionnaires, SOC 2 report
requests, and audits have become part of winning and keeping work, especially
with clients in finance, healthcare, and technology. Security is now a
business-development issue, not just an IT one.
Client expectations around AI are muddled on top of that.
40% of firms report receiving conflicting instructions from different clients,
some requiring AI on their work and others forbidding it, even as most
corporate clients say they want their firms using AI and fewer than one-third
know whether they are.[4]
Where the right IT partner helps: Documented controls, audit-ready reporting,
and a clear AI position turn a long security questionnaire from a fire drill
into a copy-and-paste exercise, and a credibility win in front of the client.
5. Rising Cyberattacks and Breach Costs
Breaches are expensive, and the trend is turning back up.
The global average cost of a data breach fell to $4.44 million in 2025 from
$4.88 million the year before,[5]
but IBM's 2026 report shows it climbing again to $4.99 million as AI-driven
attacks rose 56%.[6]
Firms that move money and hold concentrated client data are
a natural target for phishing, business email compromise, and ransomware. The
attacker does not need to breach your client if they can breach you.
Where the right IT partner helps: Behavior-based endpoint protection, a 24/7 security operations center,
advanced email security, and staff training catch the attacks that basic
antivirus misses, before they turn into an incident you have to disclose.
6. Cyber Insurance Requirements Keep Tightening
Cyber liability
coverage once felt like a form and a signature. Today it looks more
like a technical audit. Carriers now expect phishing-resistant multi-factor
authentication (MFA) on email, remote access, and cloud admin accounts, plus
endpoint detection, tested backups, and a documented incident response plan.
Firms that cannot show those controls face higher premiums, coverage
sub-limits, or outright denial.
Where the right IT partner helps: Think of security spend as the premium you
pay to keep a known risk within your policy limits. A partner who builds your
controls to match the carrier checklist, and documents them, turns a painful
renewal into a routine one.
7. Securing a Permanently Hybrid, Mobile Workforce
Hybrid work is settled, not temporary. Consultants and staff
work from home, client sites, airports, and hotels, often on a mix of firm and
personal devices. Every one of those endpoints is a door into confidential
client data, and the old idea of a protected office network no longer describes
how the firm actually works.
Where the right IT partner helps: Managed, encrypted endpoints, enforced MFA,
and secure remote access let your team work anywhere without turning mobility
into your biggest exposure. That means more advanced endpoint protection like
Endpoint Detection and Response (EDR) and Managed Detection and Response (MDR),
stricter access controls, advanced email security, regular security awareness
training, and more.
8. Client Data Sprawl and Weak Information Governance
Knowledge work scatters data. Client files, project
workspaces, email threads, and duplicate copies spread across cloud drives,
SaaS tools, and personal devices. Different clients' data ends up mingled, and
sensitive material lingers long after an engagement closes.
Without a clear information governance policy, most firms
cannot quickly answer a simple question: what client data do we hold, where is
it, and who can see it?
Where the right IT partner helps: A structured approach to data
classification, retention, access control, and reliable backup shrinks both
your storage bill and the blast radius of any single incident.
9. Downtime That Erodes Utilization
For a professional services firm, downtime hits the one
number the whole business runs on: utilization. When systems are down, billable
people sit idle, deliverables slip, and client deadlines do not move to
accommodate an outage. A few hours can quietly cost a week of margin.
Backups are supposed to be the safety net, but they only
help if they survive an attack and actually restore. A backup you have never
tested is a backup you cannot count on.
Where the right IT partner helps: Proactive maintenance prevents most outages,
and tested backup and disaster recovery makes the rest survivable, so a bad day is
measured in hours instead of weeks.
10. Stretched or Nonexistent Internal IT
Most firms in this range run lean: one overloaded IT person,
an office manager who inherited the job, or no dedicated IT at all. That works
until it does not, and it leaves the firm one resignation or one sick week away
from a gap. Meanwhile the tool stack keeps growing and the security and
compliance bar keeps rising, which is more than a single generalist can carry.
The gap shows up most in the work that never feels urgent
until it is: patching, backup testing, security training, and incident response
planning.
Where the right IT partner helps: A co-managed model gives a solo IT person a
full team of specialists across security, cloud, and strategy, and gives a firm
with no IT a single accountable partner. The goal is to strengthen your team,
not replace it.
The Bottom Line
The through-line across all 10 is that technology stopped
being a back-office concern for professional services firms and became a
client-trust, revenue, and risk issue all at once. AI, cyber insurance, client
audits, and the economics of billable work all point the same direction: firms
are expected to manage technology deliberately, document what they do, and
prove it on demand.
The firms that treat IT strategically, with proactive
management, a real security posture, and a roadmap tied to how they actually
serve clients, will spend 2026 and 2027 competing on their work. The ones that
stay reactive will spend it explaining incidents and chasing questionnaires.
Framework IT is a Chicago-based managed IT
services firm that works with professional services organizations
across the country. We specialize in IT support, strategy, and security for
growing firms, with a team of more than 40 professionals, most of them
engineers based in the Chicagoland area.
Schedule a
conversation with our team to see what managed IT can look like for your firm: frameworkit.com/discoverycall
About the Author
Adam Barney is President and Managing Partner of Framework
IT, a Chicago-based managed IT services firm he's helped lead for more than 15
years. He and his team of 40+ professionals specialize in IT support, strategy,
and cybersecurity for small and mid-sized businesses. Adam's insights on
business technology have been featured in the Harvard Business Review, the
Washington Post, and Fox 32 Chicago.
Citations
Every
statistic above is sourced to a live page that states it. Verify links are live
before publishing.
[1] Organization-wide AI use in professional
services nearly doubled to 40% in 2026, from 22% in 2025. Thomson Reuters
Institute, 2026 AI in Professional Services Report.
https://www.thomsonreuters.com/en-us/posts/technology/ai-in-professional-services-report-2026/
[2] Only 18% of respondents say their organization
tracks the ROI of AI tools. Thomson Reuters Institute, 2026 AI in Professional
Services Report.
https://www.thomsonreuters.com/en-us/posts/technology/ai-in-professional-services-report-2026/
[3] 15% of organizations have adopted some form of
agentic AI, and an additional 53% are planning or considering it. Thomson
Reuters Institute, 2026 AI in Professional Services Report.
https://www.thomsonreuters.com/en-us/posts/technology/ai-in-professional-services-report-2026/
[4] 40% of firm respondents received conflicting
client instructions on AI use; a majority of corporate clients want their firms
to use AI, yet fewer than one-third know whether they do. Thomson Reuters
Institute, 2026 AI in Professional Services Report. https://www.thomsonreuters.com/en-us/posts/technology/ai-in-professional-services-report-2026/
[5] Global average cost of a data breach was $4.44
million in 2025, down from $4.88 million the prior year. IBM, 2025 Cost of a
Data Breach Report.
https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
[6] IBM's 2026 report shows the global average cost
of a data breach reached $4.99 million, with AI-driven attacks up 56%. IBM,
Cost of a Data Breach 2026 (as stated on IBM's 2025 report analysis page).
https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
[7] 63% of organizations report having no AI
governance policies to manage AI or prevent shadow AI. IBM, 2025 Cost of a Data
Breach Report (Ponemon Institute research).
https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
[8] High levels of shadow AI added an average of
$670,000 to breach cost; 97% of organizations that had an AI-related security
incident lacked proper AI access controls. IBM, 2025 Cost of a Data Breach
Report. https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai