A controlled legal AI pilot is a bounded test on real work with the client-identifiable material removed, a measured baseline to compare against, and a named person who signs the evaluation before the tool goes anywhere near live matters. Anything looser is not a pilot; it is unpriced risk.
Most small firms do not need a transformation programme to find out whether AI helps. They need four to six weeks, one workflow, and the discipline to say no to expanding the test halfway through. This is the sequence we use when scoping a founding pilot with a firm.
1. Pick one workflow, and pick it on volume
Choose the workflow by repetition count, not by enthusiasm. A good pilot candidate is a document type your team touches several times a week - supplier-side contract review, first-pass NDA triage, lease abstract checks - where the output is reviewed by a human anyway. A bad candidate is anything rare, bet-the-client, or politically visible. If the pilot fails, it should fail quietly and cheaply.
Decide the boundaries in writing before anything starts: which matter types are in, which are out, and who is allowed to use the tool during the pilot. Two or three named users beat "the team" every time.
2. Take the baseline before the tool arrives
You cannot prove a saving you never measured. For two weeks, have the pilot users record how long the chosen task takes now: minutes per document, documents per week, and rework loops (how often a first pass comes back for corrections). This does not need software - a shared spreadsheet is enough. Our rework calculator gives you the shape of what to capture.
3. Redact before anything touches the tool
Until your confidentiality checks are complete and the vendor's data terms are signed off, pilot documents go in redacted or synthetic. Names, counterparties, figures and anything privileged come out. The SRA's position is that your confidentiality duties apply however you process client information - the tool does not change the duty, it changes where the data goes.
4. Run four to six weeks, then stop
Set the end date on day one. During the pilot, track the same numbers as the baseline: time per document, rework rate, and a weekly note from each user on where the tool helped and where it wasted time. Do not add new use cases mid-pilot. Scope creep is how a six-week test becomes a year of vague usage nobody can evaluate.
5. The evaluation gate is a person, not a feeling
Close the pilot with a written comparison against the baseline and a named sign-off - usually the COLP or the partner who owns the workflow. Three outcomes are legitimate: adopt (with a supervision arrangement for how outputs get checked), extend (one more bounded round on a second workflow), or stop. "Everyone quite likes it" is not an outcome.
If the numbers say the tool saves less time than the checking costs, stopping is a good result. You bought certainty for six weeks of bounded effort.
What a founding pilot with Margo Legal looks like
Our founding pilot runs on exactly this shape: controlled scope, redacted documents at the start, baselines before and after, and an evaluation gate a named person signs. The first cohort is capped at three UK firms. If you want the pilot structure tailored to your workflows before committing to anything, the Workflow Value Workshop is the fixed-fee starting point, and our readiness work covers the governance questions that come before any pilot.
Evidence ledger
| Claim | Source |
|---|---|
| Confidentiality duties apply regardless of how client information is processed | SRA Code of Conduct for Solicitors, para 6.3 - https://www.sra.org.uk/solicitors/standards-regulations/code-conduct-solicitors/ |
| SRA guidance on confidentiality of client information | https://www.sra.org.uk/solicitors/guidance/confidentiality-client-information/ |
| Security is a core UK GDPR processing principle with organisational measures expected | ICO, Principle (f) integrity and confidentiality - https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/integrity-and-confidentiality-security/ |
| Systematic processing of personal data can require a DPIA before starting | ICO, Data Protection Impact Assessments - https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/ |
| Law Society guidance treats generative AI use as requiring risk assessment and supervision of outputs | Law Society, Generative AI: the essentials - https://www.lawsociety.org.uk/topics/ai-and-lawtech/generative-ai-the-essentials |
Weak-claim flags: the four-to-six-week duration and the two-to-three-user recommendation are practitioner judgement, not regulator guidance; they are framed as recommendations in the copy. Internal links: rework-calculator, legal-ai-vendor-data-security-questions, /workshop/, /readiness/. Related decision frame: /resources/fix-buy-pilot-leave-it-alone-guide/ (whether to pilot at all - this piece assumes the decision is made).