A small business can begin using AI in 30 days by choosing one repetitive, measurable and low-risk workflow; naming one accountable owner; testing one approved tool against real examples; training the people who will use it; and comparing the results with a baseline. Do not begin by buying several tools, connecting AI to every system or allowing it to make customer, financial, employment or legal decisions without meaningful human review.
What you should have by Day 30
- One named AI owner and one accountable business sponsor.
- A short list of approved and prohibited AI tools and data types.
- One selected workflow with a baseline for time, cost, quality and error rate.
- A tested prompt, process or automation with clear human checkpoints.
- A small evaluation set covering normal, edge and failure cases.
- A trained pilot group and a simple way to report mistakes or concerns.
- Evidence showing whether the pilot should stop, improve or scale.
- A 90-day roadmap for the next controlled step.
Why start with one workflow?
AI use is rising quickly, but breadth is not the same as depth. The Office for National Statistics reported in July 2026 that 28% of UK businesses with 0 to 9 employees used at least one AI technology, compared with 49% of businesses with 250 or more employees. Among AI-using businesses, the average number of AI technologies had risen only modestly since 2023. This suggests that many organisations are experimenting without yet redesigning how work is done.
The same ONS analysis identified difficulty finding use cases, cost and lack of expertise as recurring barriers. DSIT research also found that businesses often begin with informal trials, while productivity is reported more frequently than revenue growth. A focused pilot gives a small company a better chance of identifying real value before cost and complexity spread.
Before Day 1: decide whether this plan fits your project
This 30-day plan is suitable for internal productivity, research, drafting, summarisation, classification and low-risk workflow support. It is not a substitute for legal, security, data-protection, financial, employment or sector-specific advice.
| Green: suitable first pilots | Amber: stronger controls needed | Red: do not make this the first pilot |
|---|---|---|
| Drafting internal meeting summaries; reformatting approved content; creating first-pass research tables; categorising non-sensitive enquiries. | Customer-facing answers; recommendations; personal-data processing; automated external messages; actions that change records or systems. | Hiring or dismissal decisions; credit or insurance decisions; legal or medical advice; autonomous payments or refunds; safety-critical control; unrestricted access to confidential company systems. |
| Human reviews every output before use. | Named expert reviews outputs, data flows and failure cases; permissions are limited; rollback is available. | Use qualified specialists, formal governance and appropriate legal or regulatory assessment before any deployment. |
Five rules for the entire 30 days
- One accountable owner. AI may assist the work, but a named person owns the result.
- Minimum necessary data. Do not give a tool more information, access or retention than the pilot requires.
- No invisible external action. A person approves anything sent to a customer, published publicly or used to change money, rights, employment or contractual records.
- Test before trust. Evaluate the system using representative examples, difficult cases and deliberate failure cases.
- Measure against a baseline. Time saved is not value if quality falls, review work increases or risk becomes unacceptable.
The 30-day plan at a glance
| Day | Focus | Required output |
|---|---|---|
| 1 | Define the business outcome | A one-sentence success statement |
| 2 | Map repetitive work | Workflow inventory |
| 3 | Score opportunities | Ranked opportunity list |
| 4 | Choose one pilot | Signed pilot choice |
| 5 | Record the baseline | Baseline sheet |
| 6 | Review data and risk | Data/risk decision |
| 7 | Shortlist tools | Tool decision and go/no-go |
| 8 | Set up the approved workspace | Controlled account and access |
| 9 | Write temporary AI rules | Pilot policy |
| 10 | Design the process | Prompt/workflow v1 |
| 11 | Build an evaluation set | Test cases and expected outcomes |
| 12 | Test normal cases | Normal-case results |
| 13 | Test edge and failure cases | Failure log and controls |
| 14 | Run a pilot rehearsal | Readiness decision |
| 15 | Launch with a small group | Pilot live |
| 16 | Log every use | Usage and issue log |
| 17 | Review output quality | Quality score |
| 18 | Check privacy and security | Control review |
| 19 | Improve the human hand-off | Revised workflow |
| 20 | Train the pilot users | Completed team training |
| 21 | Hold the midpoint review | Continue, pause or change decision |
| 22 | Fix the largest failure | Corrective change |
| 23 | Automate only stable steps | Controlled automation or manual decision |
| 24 | Test capacity and consistency | Volume test |
| 25 | Measure costs and value | ROI estimate |
| 26 | Check transparency and customer impact | Disclosure and fairness review |
| 27 | Create fallback and incident steps | Incident plan |
| 28 | Document the operating procedure | SOP and owner list |
| 29 | Make the scale decision | Stop, improve or scale decision |
| 30 | Create the next 90-day roadmap | Prioritised roadmap |
Week 1: Choose the problem and set the boundaries
The first week prevents the most common failure: purchasing a tool before deciding what business problem it must solve.
Day 1: Define the business outcome
Write a single outcome using this structure: “Reduce [current problem] for [team or customer] while maintaining [quality or control].” Good examples include reducing the time needed to prepare a weekly sales summary or improving the consistency of first-pass product descriptions. Avoid vague outcomes such as “become an AI company”.
Day 2: Map repetitive work
List recurring tasks across administration, marketing, sales, customer support, finance and operations. Capture frequency, minutes per occurrence, people involved, source information, final output, current errors and the person who approves the result. Do not assume a frustrating task should be automated; first check whether it should be simplified or removed.
Day 3: Score the opportunities
Score each candidate from 1 to 5 for frequency, time burden, quality inconsistency, measurability and availability of approved inputs. Subtract points for personal data, customer impact, legal sensitivity, system access and difficulty reversing mistakes. The best first pilot is normally frequent, boring, bounded and easy to review.
Day 4: Select one pilot
Choose one workflow, one group of users and one output. Write what is in scope and out of scope. A customer-support pilot might draft internal answer suggestions but must not send replies automatically. A marketing pilot might generate first drafts from approved product facts but cannot invent prices, testimonials or claims.
Day 5: Record the baseline
Measure the current process before AI is introduced. Record average handling time, total monthly volume, review time, correction rate, missed deadlines, direct cost and a simple quality score. Use at least five representative examples; ten to twenty is better when the workflow varies.
Day 6: Review data, people and legal risk
List every data type entering the workflow and where it will go. Separate public, internal, confidential, personal and special-category data. Check the selected provider’s account controls, retention, training, security and subprocessors. Consider whether a data protection impact assessment or specialist review is required. The ICO’s AI guidance is risk-based and covers accountability, transparency, lawfulness, fairness, accuracy, security and data minimisation.
Day 7: Shortlist tools and make the first gate decision
Compare no more than three tools. Start with AI already available under an approved business account before creating a new technology stack. Compare task fit, output quality, data controls, administration, integrations, export, pricing, usage limits, accessibility and vendor support. Stop the pilot if no option can meet the minimum controls.
Week 2: Build and test the pilot
The second week turns the selected idea into a repeatable process. Do not invite the full team yet.
Day 8: Create the controlled workspace
Use a business-managed account where possible. Turn on multi-factor authentication, assign an administrator, restrict unnecessary connectors and create a pilot folder containing only approved files. Document who can access the workspace and how access will be removed.
Day 9: Publish temporary AI rules
Write a one-page pilot policy: approved tool, approved users, permitted data, prohibited data, required human checks, prohibited actions, incident contact and review date. Ask every pilot user to acknowledge it.
Day 10: Design the process, not just the prompt
Document the input, instruction, context, output format, human review, correction method and final destination. Include a stopping rule for missing or conflicting information. A good process tells the model what not to do and tells the human what must be checked.
Day 11: Build a small evaluation set
Choose examples from the baseline: common cases, difficult cases, incomplete inputs, contradictory information, requests outside scope and an example containing prohibited data. Write the expected behaviour for each. The expected result may be a refusal or escalation rather than an answer.
Day 12: Test normal cases
Run the ordinary examples using the same inputs and settings. Score factual accuracy, completeness, format, tone, compliance with instructions and review time. Record failures rather than quietly correcting them.
Day 13: Test edge cases and deliberate failures
Test ambiguity, outdated data, prompt injection, unsupported claims, sensitive information, conflicting policies and unavailable tools. Check whether the workflow fails visibly and safely. Add constraints, access limits or human gates rather than relying only on stronger wording.
Day 14: Rehearse the full workflow
A person who did not build the process should complete the task from start to finish. Observe confusion, hidden steps and undocumented knowledge. The pilot is ready only when users can identify the correct input, run the process, review the result and recover when it fails.
Week 3: Use AI in real work
The third week is a limited production pilot. Keep the number of users and the range of cases small enough to review every material output.
Day 15: Launch with a small pilot group
Select two to five users who understand the original workflow. Explain that the pilot is an evaluation, not a requirement to accept every output. Provide the policy, process, examples, escalation route and a simple issue log.
Day 16: Log every use
Record date, user, task type, input category, AI output, review time, corrections, final outcome and any incident. A lightweight spreadsheet is enough. Do not measure only the number of prompts; measure completed business work.
Day 17: Review quality as a group
Sample outputs and compare them with the baseline. Look for recurring omissions, confident errors, inconsistent tone and hidden review burden. Separate model limitations from poor inputs, vague instructions and weak source material.
Day 18: Recheck privacy, security and access
Confirm that users followed the data rules, no unauthorised connectors were enabled and outputs were stored in the right location. Review provider settings and access logs where available. The NCSC recommends treating security as a lifecycle requirement, including secure design, deployment, operation and maintenance.
Day 19: Improve the human hand-off
Reduce friction between AI output and accountable human action. Add a checklist, source links, confidence labels, required fields or a structured output. Do not remove review merely because users find it slow; improve the format and focus the review on the highest-risk elements.
Day 20: Train for judgement, not only tool use
Teach users how to identify unsupported claims, protect confidential data, verify sources, correct outputs, report incidents and decide when not to use AI. Use examples from the first pilot days.
Day 21: Hold the midpoint review
Compare early results with the success thresholds. Continue if quality and control are acceptable. Pause if risks are not contained. Change the scope if the task is too broad. A pilot that is stopped before harm or wasted spend is a useful result.
Week 4: Measure, document and decide what scales
The final week converts observations into an operating decision. Do not scale because users enjoyed the tool; scale only when the whole process produces acceptable outcomes.
Day 22: Fix the largest failure first
Choose the issue with the greatest combination of frequency and severity. It may require better source data, a smaller task, a different tool, a mandatory field or a human approval gate. Retest the affected cases and keep the previous result for comparison.
Day 23: Automate only stable steps
Separate deterministic steps from judgement. File naming, format conversion, routing and notification may be easier to automate than factual decisions. Keep manual approval before external communication, irreversible system changes or actions affecting money, rights or customers.
Day 24: Test capacity and consistency
Run a representative batch. Check latency, costs, rate limits, duplicate work, quality drift and review capacity. A workflow that succeeds on three examples may fail when twenty arrive at once.
Day 25: Calculate a simple value estimate
Estimate monthly value as: hours saved × loaded hourly cost, plus incremental gross profit and avoided cost, minus tool, integration, training, review and rework costs. Report a range rather than false precision. Include quality and risk as separate decision criteria.
Day 26: Review transparency, fairness and customer impact
Check whether customers or employees should be told AI is involved. The CMA states that businesses remain responsible for what AI agents do and should train, monitor and refine customer-facing systems with appropriate human oversight. Review complaints, misleading outputs, vulnerable users and routes to a human.
Day 27: Create the fallback and incident process
Write how users should stop the workflow, revert to the manual process, preserve evidence, notify the owner, correct affected outputs and decide whether external notification is needed. Test the fallback once.
Day 28: Turn the pilot into an operating procedure
Document purpose, owner, users, inputs, prohibited data, approved tool, prompt or workflow version, review checklist, storage, metrics, failure handling, access removal and next review date.
Day 29: Make the stop, improve or scale decision
Stop when the use case is unnecessary, quality is unreliable, risk is disproportionate or costs exceed value. Improve when the problem is solvable but evidence is incomplete. Scale when results are repeatable, controls are working and ownership is clear.
Day 30: Build the next 90-day roadmap
Prioritise stabilising the first workflow before adding another. Set dates for access review, policy review, tool review, quality sampling and ROI review. Add a second use case only if the first has an owner and sufficient support capacity.
Good first AI use cases by business function
| Function | Suitable first pilot | Required human check | Do not allow initially |
|---|---|---|---|
| Administration | Summarise approved meeting notes into actions and owners. | Confirm decisions, names, dates and assigned actions. | Creating commitments or sending actions automatically. |
| Marketing | Create first drafts from an approved product-fact sheet and style guide. | Verify claims, prices, rights, sources and brand tone. | Inventing testimonials, discounts or performance claims. |
| Sales | Turn CRM notes into an internal account brief. | Check customer facts, next steps and confidentiality. | Sending outreach or changing CRM stages without approval. |
| Customer service | Draft suggested replies using approved policies. | Confirm the customer’s facts, rights and promised remedy. | Making refund, cancellation or complaint decisions autonomously. |
| Finance | Classify non-sensitive expense descriptions for review. | Accountant or finance owner confirms coding and exceptions. | Approving payments, tax treatment or credit decisions. |
| Operations | Convert recurring reports into a structured summary. | Operational owner checks anomalies and source data. | Changing stock, schedules or supplier commitments automatically. |
| HR | Draft neutral job-description language from approved requirements. | HR checks accuracy, accessibility, fairness and legal compliance. | Screening, scoring or rejecting candidates as a first pilot. |
Use-case scoring model
Score each factor from 1 (low) to 5 (high). Add the value factors and subtract the risk factors. The score is a prioritisation aid, not approval.
| Value factors: add | Risk factors: subtract |
|---|---|
| Frequency; staff time; avoidable delay; quality inconsistency; ease of measurement; approved data availability. | Personal or confidential data; customer or employee impact; legal sensitivity; irreversible action; broad system access; difficulty detecting an error. |
Copyable pilot brief
Copyable prompt and workflow structure
Human output-review checklist
- Is every material factual claim supported by an approved source?
- Did the system omit, distort or overstate anything important?
- Does the output contain personal, confidential or prohibited information?
- Are prices, dates, rights, policies and commitments current?
- Could a customer, employee or supplier reasonably be misled?
- Has the correct accountable person approved external use?
- Is the final version stored with enough information to reproduce or audit the decision?
A simple starter AI policy
- Use only tools and account types approved by the business.
- Do not enter customer, employee, financial, health, legal, authentication or confidential information unless the specific workflow has been reviewed and approved for it.
- Treat AI output as unverified until an accountable person checks it.
- Do not use AI to make final decisions affecting employment, customer rights, prices, refunds, contracts, credit, health, legal matters or safety without appropriate specialist controls.
- Do not represent generated material as researched fact when its sources have not been checked.
- Report significant errors, data exposure, harmful outputs and unauthorised tool use immediately.
- Keep prompts, workflows and source files versioned for recurring business processes.
- Review the approved-tool list, access permissions and policy at least quarterly and after material product or legal changes.
How to measure whether the pilot worked
| Dimension | Baseline measure | Pilot measure | Decision question |
|---|---|---|---|
| Time | Minutes per completed task and review. | Minutes per completed task, including correction. | Did total handling time fall? |
| Quality | Error rate or scored sample. | Same test and scoring method. | Did quality stay within the threshold? |
| Capacity | Tasks completed per week. | Tasks completed with the same team. | Did useful capacity increase? |
| Cost | Labour and existing software cost. | Tool, integration, training, review and rework cost. | Is value greater than total cost? |
| Risk | Incidents, complaints and high-severity errors. | Same measures plus new AI-specific failures. | Are failures detectable, reversible and acceptable? |
| Adoption | Current process usage. | Active pilot users and successful completed tasks. | Are people using it correctly rather than merely trying it? |
What not to do in the first 30 days
- Do not buy several overlapping AI subscriptions before selecting a workflow.
- Do not use a personal free account for confidential company work.
- Do not connect AI to the full email inbox, CRM, drive or finance system for convenience.
- Do not measure success by prompts, generated words or employee enthusiasm alone.
- Do not automate a process that is undocumented, unstable or already unnecessary.
- Do not remove human review before failure patterns and operating limits are understood.
- Do not imply that an AI provider’s security features remove your own responsibilities.
- Do not publish customer-facing claims, advice or decisions without the appropriate accountable review.
Your next 90 days
| Period | Main objective | Recommended actions |
|---|---|---|
| Days 31–60 | Stabilise the first workflow. | Fix recurring errors; improve source quality; formalise access; sample outputs weekly; update training; calculate actual cost and value. |
| Days 61–75 | Decide whether to expand usage. | Add users only when support and review capacity exists; test new user groups; review provider and integration changes. |
| Days 76–90 | Add one adjacent use case or deeper integration. | Repeat the opportunity score; reuse governance and evaluation methods; avoid broad system access; set the next quarterly review. |
Common questions
Frequently asked questions
Clear answers to the practical questions readers ask most often.
How much should a small business spend on its first AI pilot?
Spend only enough to test one valuable workflow under the required controls. Start with an approved business account or an existing software feature when it can meet the task. Include staff time, review and training in the cost, not only the subscription.
Which department should start first?
Choose the workflow, not the department. Administration and marketing often contain frequent, reviewable language tasks, but the right starting point is the process with clear inputs, a measurable baseline and low consequence if the AI is wrong.
Should a small business start with AI agents?
Usually not. Begin with an assistant or controlled workflow. Introduce an agent only when the task requires multiple steps or tools, the permissions can be limited, the outputs can be monitored and consequential actions remain behind explicit human approval.
Can staff use free AI tools?
Free access is not automatically unsuitable, but consumer accounts may have different administration, data, retention, training and support terms. A business should approve the account type and permitted information before staff use it for work.
Do we need an AI policy before experimenting?
You need at least temporary rules before business data is used. The first version can be one page, but it should identify approved tools, prohibited information, required review, prohibited decisions and the incident contact.
How often should the business review an AI workflow?
Review it after material tool, model, integration, data, policy or legal changes. For a new workflow, sample outputs frequently. Once stable, set a recurring quality, access and value review at least quarterly.
What does human in the loop mean?
It means a person has enough information, authority, time and expertise to detect and correct a problem before the consequential action occurs. A nominal approval button is not meaningful oversight if the reviewer cannot understand or challenge the result.
What if the pilot does not save time?
Check whether review burden, poor source data or a badly chosen task caused the problem. Stop the pilot when the process does not create sufficient value or control cannot be made proportionate. Learning what not to scale is a successful pilot outcome.
The practical next step
Name one owner and ask them to map ten recurring workflows tomorrow. By the end of the first week, choose one low-risk task and record how it works today. The strongest small-business AI strategy is not the one with the most tools. It is the one that repeatedly turns a real business problem into a measured, reviewable and accountable improvement.