Your team is already using AI, and you have no policy. Some people draft with it, one has pasted client data from the CRM into a public chatbot, and others will not touch it. You have no internal IT specialist, and you don't want to buy a system before the team can use it safely.
The answer is smaller than the problem looks: pick one low-risk, repetitive task, write three verification checks, run a two-week pilot with a named team, and measure it with counts, not moods. You don't need an IT specialist. This article is not legal advice and not a tool comparison.
The plan is not generic advice. It adapts the doctrine we ship in our AI automation work: "We never trust model output blindly. Every automation ships with deterministic verification checks, budget ceilings, and human approval gates for irreversible actions." It is grounded in two published systems — Lektobot and the content-agent platform — and it is a professional recommendation, not a measured outcome in an accounting firm.
Pick one low-risk, repetitive task to pilot
This pilot is designed to start without an internal IT specialist; obtain appropriate privacy, legal, or technical advice before sending client data to any tool your firm cannot inspect, control, and document. A task is ready for a pilot only if it passes three tests: clear inputs and outputs, no irreversible client-facing action, and a measurable result. Summarising monthly bank statements for client files passes: the input is a statement, the output is a short summary, nothing is sent to a client until a person checks it, and you can count how many summaries were accepted, corrected, or rejected. A task that fails any test — for example, anything that moves money, files a return, or communicates directly with a client without a review step — is not ready.
This is the employee-readiness front end of the same supervised-automation method we use in client work. That method keeps AI output behind checks and human approval before anything irreversible happens.
Set three verification checks and one non-negotiable data rule
Before the pilot, write down the checks every output must pass. We call this a verification gate: a fixed check an AI output must pass before a human is allowed to act on it. Three checks is enough for a first pilot. For bank-statement summaries: (1) every client name and identifier matches the source document, (2) every financial figure reconciles to the statement, (3) anything uncertain is flagged for a human rather than guessed.
One rule stands above the three: any AI output containing client identifiers — names, IDs, financial figures — must pass a human approval gate before it is used or sent. That rule is not a guideline; it is the condition for the pilot continuing.
The minimum pilot policy:
- Only the named organisation-controlled account may be used for pilot tasks.
- Client data may not be entered into personal or unapproved accounts.
- The named pilot owner decides whether a task is permitted.
- Every output requires the stated review.
- If client data is accidentally submitted, staff must report it promptly to the pilot owner for firm-specific advice and response.
There is a distinction you need because the incident in your firm probably came from a personal account. Microsoft's enterprise documentation states that its protections apply when a user is signed in with a work or school account. It follows, and we mark this as our inference from Microsoft's statements, that an employee using a consumer chatbot or a personal account has none of those documented controls. We are not recommending that product; we cite Microsoft because its enterprise statements are the clearest public illustration of the line. The operational rule is tool-agnostic: if your firm cannot inspect, control, and document where client data went, the data does not go there.
This is not a theoretical rule. Our Lektobot system applied the same gate to proofreading: on a real 31,204-word master's thesis, 400 proposals entered the funnel and 250 verified comments came out after 11 independent checks. The difference between 400 and 250 is the point: not every proposal survives the checks. The pilot applies the same principle to your client-facing output.
Write the one-page pilot plan
Don't run the pilot from memory. Fill in one page before Monday. This is the page you'll bring to the strategy call, and the same page you'll use to decide whether to continue.
| Section | What to write down |
|---|---|
| Task | Summarising monthly bank statements for client files (or your chosen equivalent). |
| Team | Two to four named people, including at least one sceptic and one enthusiast. |
| Dates | The two-week window, plus the date and time of the review meeting. |
| Allowed tool and account | Name the organisation-controlled account and its owner. Record where prompts and files are processed, who can access logs/settings, and how access is removed. If you cannot document those points, run the pilot only on synthetic or de-identified material until qualified privacy or technical advice approves a tool. |
| Three verification checks | 1. Client names and identifiers match the source. 2. Financial figures reconcile to the statement. 3. Uncertain items are flagged, not guessed. |
| Review questions | How many outputs were accepted, corrected, or rejected? What do the counts say: continue, adjust, or stop? |
The review questions are not decorative. They are the same questions you will answer from the shared log in week two.
Run the two-week pilot with a named team
Name two to four people. Do not make the whole firm the pilot team. At least one should be sceptical about AI and at least one enthusiastic. The sceptic gets a defined role: they verify outputs against the three checks and approve or reject each one. That gives reluctant staff a way to participate without being asked to like the tool. The enthusiast gets a bounded task: run the same inputs each day and log what happens, rather than trying the tool on everything.
Keep the daily volume small — for example, one batch of statements per person — and record the preparation and review time in the shared log so the review meeting can assess the pilot’s actual time cost. Use the tool you already have; the checks and the log matter more than the product.
Keep one shared log. For every AI output, record the input processed, the output produced, and whether it was accepted, corrected, or rejected. The log is what turns week two's review into a decision instead of an argument.
Reality check: our published case studies describe our AI automation method as supervised agent systems with verification gates and human approval. That is the practice this pilot adapts, but the pilot plan itself is a professional recommendation, not a measured outcome in an accounting firm. We shipped the verification pattern in Lektobot — 400 proposals in, 250 verified comments out, after 11 independent checks — but your pilot’s log is the evidence that matters here.
Measure the pilot with counts, not moods
At the review meeting, look at the log. Three numbers decide: inputs processed, outputs accepted, outputs corrected or rejected. If most outputs are accepted with no corrections, you have a candidate for a real workflow. If many are corrected, the task or the checks need adjustment. If any output containing client identifiers left the pilot without a human approval gate, stop and fix the rule before anything else.
Pilot time and cash budget
We have no substantiated planning estimate for staff preparation or review time, or for incremental cash spend, so this article does not provide one. The pilot log's recorded time and any tool spend are the figures for the review meeting.
The reason we insist on counts is our published value, Math Over Mood: "We don't care if a campaign feels right. We care if the numbers prove it works." The same applies to an AI pilot. Our content-agent platform runs 14 stages and 15 deterministic validators and produces a sourced article at $0.37; one day of cost engineering took the same run from $8.40 to $0.37. Those figures are evidence from shipped work that verification and cost control can coexist.
Know the legal baseline: the EU AI Act and GDPR
Two legal points matter for a firm that uses AI, and one belongs to your advisers. The EU AI Act (Regulation (EU) 2024/1689) was adopted on 13 June 2024, published in the Official Journal on 12 July 2024, and is in force; the consolidated version we reviewed is current as of 27 July 2026. The Act has been amended once since adoption, by Regulation (EU) 2026/1744; we have not quoted Article 4 here, and the wording should be checked against the consolidated text before you rely on it.
Firm-specific GDPR questions — which tool may process client data under which safeguards, and what you must document — belong with a data-protection officer or legal counsel. We are not giving legal advice here.
Bring the completed plan to Niro Digital
After the pilot, you have the one-page plan, the shared log, and the counts. The next step is to write to us with three things: the chosen task, the team size, and what the pilot measured. That lets us scope the first digitalisation step from a real problem rather than from a pitch.
We are NiroDigital d.o.o., a digital agency founded in late 2023 by Nino Djordjević, a university-educated theoretical mathematician; Rok Goropevšek joined as CTO in 2025. We serve primarily the Slovenian market and are registered at Ulica Ruđera Boškovića 9, 40315 Mursko Središće, Croatia — a Slovenian-market agency registered in Croatia, not a Slovenian company.
Write to info@nirodigital.com or call +386 70 630 880, or book a strategy call with the one-page plan in front of you.
Sources
- 01Data, Privacy, and Security for Microsoft 365 Copilot | Microsoft Learnlearn.microsoft.com
- 02Consolidated TEXT: 32024R1689 — EN — 27.07.2026eur-lex.europa.eu
- 03Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance) — via aiact-info.euaiact-info.eu
- 04learn.microsoft.com
- 05Microsoft 365 Copilot Chat Privacy and Protections | Microsoft Learnlearn.microsoft.com
- 06Data protection when using Microsoft 365 Copilot Chat for work or school | Microsoft Supportsupport.microsoft.com