Who Do You Call First? AI and the IT Service Desk

How user-adopted AI will reshape the IT service desk — and why the most disruptive AI may be the AI the service desk never sees.

A MetricNet White Paper by Jeff Rumburg, Co-founder & CEO, MetricNet  ·  August 2026

Executive Summary

For decades, the service desk has been the default destination when an employee encounters a technology problem. That model is changing. Increasingly, users are asking a large language model (LLM) before they contact IT — and many of those issues are being resolved without a ticket ever being created.

This matters because most industry discussion about AI in IT support focuses on AI deployed by the service desk: copilots, virtual agents, voice and chat bots, automated triage, knowledge retrieval, and autonomous remediation. A second transformation is occurring outside the service desk's field of view. Users are self-adopting AI as part of their own incident-resolution process.

The most disruptive AI in IT support may be the AI the service desk never sees.

This paper calls that phenomenon Invisible AI Deflection. It posits that AI will reduce the IT support workload through two simultaneous forces: fewer incidents reaching the service desk, and higher productivity on the incidents that remain. The result will not be the elimination of human support, but a smaller, more expert, more exception-oriented support organization.

Key conclusions

01   Who Do You Call First?

Who do you call first — your service desk, or your favorite LLM? For an increasing number of IT users, the answer is the LLM.

This is true for me personally. I require support perhaps a dozen times a year from Microsoft, HP, Dell, Intuit, Apple, Google, and other vendors I use in my business and personal life. Increasingly, I do not start by calling the vendor. I ask an LLM. In my experience, the LLM is typically faster, easier, and less costly than entering a conventional support queue.

Download: Who Do You Call First? — the complete white paper  (PDF)

How user-adopted AI will reshape the IT service desk — and why the most disruptive AI may be the AI the service desk never sees.

A MetricNet White Paper by Jeff Rumburg, Co-founder & CEO, MetricNet  ·  August 2026

Executive Summary

For decades, the service desk has been the default destination when an employee encounters a technology problem. That model is changing. Increasingly, users are asking a large language model (LLM) before they contact IT — and many of those issues are being resolved without a ticket ever being created.

This matters because most industry discussion about AI in IT support focuses on AI deployed by the service desk: copilots, virtual agents, voice and chat bots, automated triage, knowledge retrieval, and autonomous remediation. A second transformation is occurring outside the service desk's field of view. Users are self-adopting AI as part of their own incident-resolution process.

The most disruptive AI in IT support may be the AI the service desk never sees.

This paper calls that phenomenon Invisible AI Deflection. It posits that AI will reduce the IT support workload through two simultaneous forces: fewer incidents reaching the service desk, and higher productivity on the incidents that remain. The result will not be the elimination of human support, but a smaller, more expert, more exception-oriented support organization.

Key conclusions

01   Who Do You Call First?

Who do you call first — your service desk, or your favorite LLM? For an increasing number of IT users, the answer is the LLM.

This is true for me personally. I require support perhaps a dozen times a year from Microsoft, HP, Dell, Intuit, Apple, Google, and other vendors I use in my business and personal life. Increasingly, I do not start by calling the vendor. I ask an LLM. In my experience, the LLM is typically faster, easier, and less costly than entering a conventional support queue.

Enterprise users are discovering the same option. This behavior is not entirely new — users have searched Google for technical answers for more than two decades — but LLMs fundamentally improve the experience. Instead of interpreting search results, reading multiple articles, and translating generic instructions into a specific troubleshooting path, a user can describe symptoms conversationally, answer follow-up questions, and receive a tailored sequence of diagnostic steps.

The emerging AI-first support path. When the LLM resolves the issue, no ticket is ever created — and the enterprise never sees the demand.
Figure 1. The emerging AI-first support path. When the LLM resolves the issue, no ticket is ever created — and the enterprise never sees the demand.

02   The Service Desk Is Losing Its Monopoly on Technical Knowledge

Historically, the service desk possessed a structural advantage: it knew more about technology than the average user and had access to established troubleshooting methods. LLMs narrow that knowledge gap dramatically for common technologies.

A user can now ask, for example: "My Outlook search stopped finding older messages. I am using Windows 11 and Microsoft 365. What should I check?" The LLM can ask clarifying questions, revise its diagnosis, explain each step, and continue until the issue is resolved. In effect, the user has acquired an always-available Tier 1 troubleshooting resource.

This does not mean every incident is suitable for AI. The important distinction is the amount of proprietary context, system access, risk, and organizational knowledge required to solve the problem.

The AI supportability spectrum. The more proprietary context, system access, and risk a problem carries, the more it depends on enterprise knowledge and human expertise.
Figure 2. The AI supportability spectrum. The more proprietary context, system access, and risk a problem carries, the more it depends on enterprise knowledge and human expertise.

03   Invisible AI Deflection

Even support desks that have not yet deployed any AI technology may experience declining ticket volumes as users solve more problems independently. The challenge is measurement. If a user asks an external or personal LLM, resolves the issue, and never opens a ticket, the enterprise has no conventional deflection event to count. Traditional self-service analytics observe behavior inside the support ecosystem: knowledge searches, portal sessions, chatbot conversations, and abandoned ticket submissions. Invisible AI deflection occurs outside that ecosystem. From the service desk's perspective, demand simply disappears.

The few support organizations I am aware of that have attempted to measure this phenomenon have done so through surveys. The relevant questions — often embedded in a more conventional customer satisfaction survey — ask whether the respondent has used an LLM for technical support, how often, and what their estimated resolution rate is when they do. As imperfect as this is, it is the only data we have so far. The results, albeit from a small sample, suggest that Invisible AI Deflection ranges from a low of 2% of total ticket volume to a high of 15%. This is not insignificant, and it will only grow.

Visible deflection happens inside the support ecosystem, where it can be measured. Invisible deflection happens outside it — no portal visit, no ticket, and no enterprise telemetry.
Figure 3. Visible deflection happens inside the support ecosystem, where it can be measured. Invisible deflection happens outside it — no portal visit, no ticket, and no enterprise telemetry.

A service desk can experience AI-driven ticket deflection without deploying a single AI technology of its own.

04   AI Changes Both Demand and the Cost of Supply

The workforce impact of AI is frequently discussed as a productivity story: analysts receive better knowledge, faster diagnostics, automated documentation, triage, and eventually autonomous remediation. That is only half of the equation.

AI also reduces demand by enabling users to resolve incidents before they enter the service desk. These two effects are additive because they operate at different points in the support chain: user-initiated LLMs reduce the number of contacts that arrive, while AI used by service desk analysts reduces the labor required to resolve the contacts that remain. For example, if user-initiated AI reduced incoming contacts by 15%, and AI-assisted analysts required 20% fewer labor hours per remaining contact, total support labor would fall to 65% of the original baseline — a 35% reduction. These percentages are illustrative assumptions, not forecasts; the purpose is to show how the combined effect of AI both inside and outside the service desk can dramatically reduce the cost of support.

05   The Right Policy: AI Where Appropriate

Should enterprises encourage users to ask AI before contacting the service desk? In many cases, yes — but not indiscriminately. An unrestricted AI-first policy can introduce security, privacy, compliance, and operational risks. Users may disclose sensitive information, receive an incorrect answer, or make a configuration change that conflicts with enterprise standards.

The better policy is to explicitly classify support scenarios. Routine, public-knowledge questions can be encouraged for AI self-service. Enterprise configuration issues can be permitted with guardrails. Security incidents, data loss, privileged access, major outages, and proprietary systems should enter formal support channels immediately.

A practical policy framework for user-initiated AI support. Routine questions are encouraged for self-service; sensitive and high-risk scenarios enter formal support channels immediately.
Figure 4. A practical policy framework for user-initiated AI support. Routine questions are encouraged for self-service; sensitive and high-risk scenarios enter formal support channels immediately.

06   Bring the LLM Inside the Tent

The limitation of a general-purpose LLM is not intelligence so much as context and authority. It may know a great deal about Windows or Microsoft 365 but nothing about a company's custom claims application, yesterday's production change, a user's entitlements, or an internal outage.

That boundary moves when an enterprise AI assistant receives controlled access to approved internal knowledge: application documentation, knowledge articles, known errors, incident history, change records, service maps, telemetry, configuration data, and remediation procedures.

The next step is action. An AI agent can move beyond recommending a fix to checking telemetry, validating service health, resetting credentials, reinstalling approved software, repairing configuration, confirming recovery, and documenting the outcome. At that point the industry moves from AI-assisted support to AI-delivered support.

07   The Service Desk Becomes an Exception-Handling Organization

The future service desk will not disappear. Its workload will change. Routine questions and repeatable requests are the most obvious targets for self-service and automation. Human effort will become concentrated in ambiguous, risky, novel, cross-functional, and business-critical situations.

As AI absorbs routine work, human support concentrates on exceptions that require judgment, context, risk management, and accountability.
Figure 5. As AI absorbs routine work, human support concentrates on exceptions that require judgment, context, risk management, and accountability.

This changes the skills profile of the organization. Fewer people may be required, but the remaining roles become more valuable: problem solvers who understand business context, systems integration, security, automation, knowledge engineering, and AI governance.

08   What Happens to Headcount?

Current industry dogma often begins with a correct observation — there will always be incidents that require human expertise — and then draws an incorrect conclusion: therefore AI will have little impact on IT support headcount.

I disagree. Human support will remain, but the amount of human labor required to deliver support will decline dramatically. In a related whitepaper two years ago, I predicted that worldwide IT support headcount could shrink by up to 80% within ten years. That prediction may never be provable because the invisible AI is almost impossible to measure. But the mechanism for labor cost reduction is increasingly clear: invisible deflection reduces incoming demand while AI and automation reduce the labor required for the demand that remains.

Headcount reductions are unlikely to occur primarily through layoffs. More probable mechanisms include attrition without replacement, reduced entry-level hiring, consolidation of support tiers, smaller outsourcing contracts, broader spans of responsibility, and redeployment into engineering, security, automation, problem management, and AI governance.

The early impact of AI may not be today's technician. It may be tomorrow's open position.

09   A Warning About the Data

Service desk leaders should be cautious when interpreting declining ticket volumes. Historically, lower volume might be attributed to improved reliability, better problem management, stronger knowledge management, training, or conventional self-service. Those explanations remain valid, but user-adopted AI introduces a new variable.

If AI removes the easiest incidents before they reach the desk, the remaining ticket population also becomes more complex. Average handle time may rise. Cost per ticket may rise. First-contact resolution may decline. Escalation rates may increase. Those movements could look like deterioration even while the overall support model is becoming more efficient.

For that reason, organizations should supplement traditional ticket metrics with measures such as total support demand, estimated invisible deflection, human intervention rate, AI resolution rate, cost per user supported, and agent-assisted support minutes per user per month. The objective is no longer simply to process tickets efficiently; it is to minimize the amount of human intervention required while preserving reliability, security, and user experience.

10   Where This Is Going

The strategic question for service desk leaders has changed. "How should we use AI?" is no longer sufficient. Leaders must also ask how their users are already using AI, which incidents should be deliberately shifted to AI, which must remain inside controlled support channels, and how enterprise knowledge can be connected safely to AI systems.

Over time, the boundary will continue moving. Public-knowledge support will become predominantly self-service. Enterprise AI will absorb increasingly context-rich work. Autonomous agents will perform more remediation. Human support will move upward toward judgment, risk, novelty, coordination, and accountability.

This evolution also suggests that traditional tier structures will blur. Rather than routing every issue through Tier 1, organizations will increasingly route routine work directly to AI and reserve human queues for cases that have already survived an automated resolution attempt or that are too sensitive to automate.

11   Conclusion

There will still be IT support ten years from now. Systems will fail. New technologies will create new problems. Proprietary applications will behave unpredictably. Security incidents and major outages will require investigation, coordination, judgment, and accountability.

But the service desk of the future will look very different from the service desk of today. The first wave of automation made technicians more productive. The second wave expanded self-service. The emerging wave is fundamentally different: users themselves now possess technology capable of bypassing the service desk for a growing share of routine support. Behind that wave is an even more consequential one: enterprise AI agents that will not merely explain how to solve a problem, but will diagnose and remediate it autonomously.

The service desk is not disappearing. Its role is being redefined — from the default destination for every technical problem to the expert destination for the problems AI cannot, should not, or must not solve.

The organizations that recognize this shift early will have an opportunity to redesign support deliberately: establish sensible AI guardrails, integrate enterprise knowledge, rethink workforce requirements, modernize performance metrics, and invest human expertise where it creates the greatest value.

About the Author

Jeff Rumburg — Co-founder & CEO, MetricNet

Jeff Rumburg is winner of the Ron Muns Lifetime Achievement Award and was named to HDI's Thought Leaders Hall of Fame. As co-founder and CEO of MetricNet, Jeff has been retained as an IT Service and Support expert by some of the world's largest corporations, including American Express, Meta, Lowe's, and AT&T.

He was formerly CEO of the Verity Group and Vice President of Gartner. Jeff received his MBA from Harvard University and his MS in Operations Research from Stanford University.