Define the pilot's data before selecting files
A legal team may describe its pilot as contract review while the files also contain employee contact details, signatures, bank information, and correspondence about a dispute. Inventory what is actually present rather than assigning one sensitivity label to the folder.
Datatilsynet's material on AI and privacy is a useful starting point for privacy-focused design. The inventory below is an operational proposal. The team's privacy and legal reviewers should determine the applicable requirements and whether the proposed use is appropriate.
Map inputs, intermediate data, and outputs
| Category | Questions to answer |
|---|---|
| Uploaded files | What personal or confidential information is included? |
| Prompts | Will users add facts beyond the approved documents? |
| Extracts and drafts | What new records will the tool generate? |
| Operational records | What logging, support access, or backup processing occurs? |
| Exports | Who receives them and where will they be stored? |
Identify a source for each answer, such as the vendor agreement, configuration, or tested behaviour. Mark an unanswered question as open.
Choose a test set that is useful and proportionate
Use only the material needed to evaluate the task. If a synthetic contract can test the first pass, it may be a useful starting point. When real documents are necessary, follow the organisation's approval and information-handling process before including them.
For example, a pilot about renewal terms may not need an employee's identity documents attached to a supplier email. Separate unnecessary material instead of uploading the whole mailbox export. If redaction or pseudonymisation is used, check the resulting files and remember that context can still reveal identities.
Test controls alongside the legal output
Check who can access the pilot workspace, how outputs are shared, and what the user can export or delete. Review vendor evidence for processing that cannot be observed from the interface. A successful delete button test does not by itself explain backups or third-party retention.
Inspect whether users can accidentally attach additional documents or send sensitive facts in follow-up prompts. Write practical instructions for those moments. Record any gap between the approved workflow and actual behaviour, then decide whether to change the settings, training, or pilot scope.
Close the pilot with a data-handling decision
At the end of the pilot, reconcile the inventory with the files and outputs actually created. Apply the approved retention and deletion plan, preserving only the evaluation evidence the organisation needs. Assign ownership for any remaining vendor or contractual questions.
For rollout, state which data categories and tasks are approved, who can use them, and what changes require reassessment. A successful extraction test should not become permission for every matter type. Keep the inventory current as the team adds integrations, new sources, or different kinds of legal work.
Sources and next steps
This is an editorial workflow guide for legal professionals. The suggested checks are our practical recommendations, not a statement that a regulator requires a particular software workflow.
Explore Document Review and Review Matrix, or review Judicio's regional coverage and limitations. Check the underlying source and your organisation's approved process before relying on an output.