Choose a relevant and bounded problem
The first use case should be frequent enough, understandable to the business and suitably bounded. Risk and exceptions need to remain manageable.
A clear problem statement describes the current constraint and desired work outcome without prescribing a particular technology.
Document the current state as a baseline
The workflow, participants, systems, data, common case types, exceptions and current quality controls are recorded. Without this basis, later assessment cannot reliably show what the pilot changed.
- objective and business owner
- input and expected output
- representative normal and exceptional cases
- existing controls
- known risks and dependencies
Design the smallest suitable solution
Not every step needs generative AI or an agent. Rules, existing software, search, RAG and human decisions are combined to handle the bounded use case transparently.
Data access, permissions, approvals, fallback and success criteria belong in the design from the outset.
Validate with real cases and criteria set in advance
The pilot handles representative cases in a controlled environment. Business owners assess outcome quality, error types, necessary rework, controllability and possible effects.
One successful example is insufficient; missing data, conflicting sources and undesirable actions are tested as well.
Make a deliberate go, adjust or stop decision
Value, risk, operating effort and organisational prerequisites are reviewed together after the pilot. Scaling follows only when ownership, operation, security measures and ongoing evaluation are viable.
Stopping or choosing simpler automation is a valid outcome where the criteria are not met.
Source note
The approach follows Govern, Map, Measure and Manage in the voluntary NIST AI RMF together with BSI's use-case-specific risk perspective. Primary sources reviewed on 11 August 2026.
Primary sources
Official sources, editorially checked on 11 August 2026.
- AI Risk Management FrameworkNational Institute of Standards and Technology (NIST)
- Generative AI Models: Opportunities and Risks for Industry and AuthoritiesBundesamt für Sicherheit in der Informationstechnik (BSI)