Start with a real matter

An EU legal department may use the same subscription to summarise supplier contracts, prepare internal advice, and assess litigation documents. Recording only the product name hides the differences between these tasks. Begin with a representative matter and follow the output to the person who acts on it.

Write the intended purpose in operational terms: extracting renewal dates for a lawyer to check is a clearer inventory entry than improving legal efficiency. Separate proposed uses from those already approved.

Capture inputs and recipients

For each task, identify document types, personal data, confidentiality restrictions, languages, and the source of the material. Record who uploads it, who sees the result, and whether the result leaves the legal team. A board paper and an internal research scratchpad have different recipients even if both start as summaries.

Include the workspace and access group used. Do not assume that an organisation-wide licence means every matter may be placed in the same shared library.

Keep classification as a recorded decision

The inventory supports a legal assessment; it does not make the assessment automatically. Add fields for the applicable framework, the assessor, the reasoning, and any unresolved questions. The Commission's AI Omnibus announcement is a current starting point for checking the AI Act timetable, while the enacted text controls the legal analysis.

Avoid a single platform-wide label such as compliant AI. Record the role and use being assessed, the version of the legal source, and the date on which the conclusion was reached.

Test a change in purpose

Suppose a contract-summary workflow is later used to rank employees mentioned in investigation files. The original entry no longer describes the actual use. Route the proposed change back through privacy, employment, and AI governance review before extending the workflow.

Useful triggers include new personal-data categories, automated distribution, a new recipient group, or reliance on an output without the original human check. Ask the business owner to report these changes rather than relying only on an annual questionnaire.

Publish a usable approval record

Give users a short record stating the permitted task, allowed inputs, required reviewer, and escalation route. Link it to the fuller assessment and approved instructions. In Judicio, shared workflows can support repeatable tasks, but approval remains an organisational decision.

Close the inventory review by testing whether a new team member can tell which use is permitted. If the answer depends on unwritten exceptions known only to the pilot team, the record is not ready for wider use.

Worked example and decision record

Illustrative EU department inventory: a team begins with public-law research and later asks the same workspace to summarise staff grievance files. The vendor account has not changed, but the inputs, purpose, affected people and access decisions have. Keep separate inventory rows rather than extending the first approval silently.

FieldPublic researchProposed grievance summary
PurposePrepare a lawyer-reviewed research noteOrganise an internal case file for counsel
InputsPublic legislation and judgmentsPersonal information and confidential allegations
RecipientsAssigned research lawyerNamed employment team only
Decision boundarySource verification before reliancePrivacy, confidentiality and access review before upload

A third proposed use, ranking people for an employment decision, needs its own assessment. Neither of the first two rows approves it. The inventory is useful precisely because it makes that change visible without assuming that one regulatory classification applies to every use of a platform.

Run a reviewable workflow

Interview the person doing the task, then trace one sample input through preparation, upload, processing, review, export and deletion. Record systems outside the AI service too: an exported memo in an email attachment changes the recipient map even if the platform itself has tightly limited access.

Use a short purpose statement, a named owner and an explicit status: proposed, approved with conditions, suspended or retired. Ask the legal assessor to add the applicable framework and source version. The Commission’s AI Omnibus announcement is a route to checking legislative changes; do not copy a historic timetable from an old procurement slide.

  1. Separate confidential client material from public input in the inventory.
  2. State who can act on the output and which review must happen first.
  3. Document the actual service configuration and plan purchased.
  4. Attach privacy and professional-responsibility questions to the specific activity.
  5. Set a review trigger for new data, recipients, purpose or service processing.

Ask a colleague to reconstruct the allowed use from the row alone. If they still need the original owner to explain whether a particular file may be uploaded, the approval conditions need clearer wording. Keep a dated copy of the decision rather than replacing it when the use changes.

Checklist and acceptance criteria

Use this checklist at handover. Record the reviewer, date, source version and unresolved items beside each answer; a tick without evidence does not close the issue.

  • Describe the task in a sentence that identifies the output and user.
  • Map inputs, affected people, processing and recipients.
  • Record the legal assessment separately from the inventory.
  • State upload restrictions and required human review.
  • Reassess when purpose, data, recipients or service configuration changes.

Download the editable build an eu legal ai use-case inventory checklist (Markdown). It includes blank fields for your matter record and can be opened in a text editor or copied into your team’s document system.

Approve a row only when the permitted activity is understandable and the evidence owners have closed their conditions. “Legal uses only” is not a useful boundary when the department handles tasks with materially different data and consequences.

Sources and next steps

This is an editorial workflow guide for legal professionals. The suggested checks are our practical recommendations, not a statement that a regulator requires a particular software workflow.

Explore Custom Workflows and Collaboration, or review Judicio's regional coverage and limitations. Check the underlying source and your organisation's approved process before relying on an output.