Practical guides

Before you commission a project

How to scope a first AI automation pilot for a small business

A practical UK small-business checklist for choosing one AI workflow, setting data and approval boundaries, testing the result and understanding ongoing costs.

Start with one business decision or repeated task

Describe the current trigger, the information a person checks, the output they produce and the next action. Record how often the task happens and where delays or mistakes occur. A useful pilot might prepare an enquiry summary or a reply draft; “run the business with AI” is not a testable scope.

Check whether fixed rules are enough

Use ordinary automation for predictable steps such as saving a valid form, sending a receipt or assigning a standard follow-up. Add AI only where interpreting language or retrieving approved knowledge is genuinely useful. This keeps the first system easier to test, explain and pause.

Define the approved information and data boundary

List the documents, records and fields the assistant may use. Exclude information it does not need, identify who may see the output and decide how long logs should be kept. If personal data is involved, assess the privacy risks and obtain appropriate data-protection advice before using real customer records.

Keep authority with a named person

State which outputs are drafts and which actions require approval. Prices, contractual commitments, submissions, payments and sensitive decisions should not become autonomous simply because a model can produce a confident answer. Name the person who reviews exceptions and can pause the workflow.

Write acceptance checks before implementation

Prepare examples with complete information, missing facts, conflicting prices, an out-of-scope request and an unavailable external service. Agree what a correct draft must contain, what must be flagged and what the system must refuse. Keep a manual route when the model or an integration fails.

Separate build cost from running cost

Ask for the implementation scope, model usage, integration fees, hosting, monitoring and support to be shown separately. Confirm who controls the accounts, source, prompts, approved knowledge and exports. A low setup quote can still create an expensive or difficult-to-move workflow if those responsibilities are unclear.

Run a bounded pilot before widening access

Start with a limited set of cases and review the outputs against the agreed checks. Record corrections, failures, review time and actual usage cost. Expand data access or external actions only when the evidence supports it. A successful demonstration is not yet proof that a workflow is safe for every case.

Further reading: Information Commissioner’s Office: artificial intelligence guidance and risk resources.