01

Score the first AI automation candidate

Score the first AI automation candidate
QuestionLower-risk signalWarning signal
Is the task defined?Trigger, input, output and owner are knownThe team disagrees about the process
Is there enough volume?The same path repeats every weekThe task is rare or changes every time
Can quality be checked?A reviewer can identify correct and incorrect outcomesSuccess depends on tacit judgment with no review rule
What happens on error?The system can pause, log and route to a personA mistake immediately changes money, rights or customer access
Can access be limited?Dedicated credentials and minimum permissionsThe agent receives broad personal accounts or irreversible authority
Can value be measured?Time, backlog, error or response quality has a baselineThe only goal is to “use AI”
02

Start with a broken workflow, not an AI tool

The first useful question is where work repeatedly waits, repeats or loses context.

Map one real path from trigger to final action. Typical candidates include lead routing, support triage, onboarding checks, CRM cleanup and recurring reporting. David Dacruz’s partner page uses the same operational lens: a useful implementation has a trigger, source data, shaping steps, a destination action, logs and a fallback—not merely a prompt.[1]

Do not automate a process that nobody owns or can explain. First agree who decides, what a correct outcome looks like and which exceptions already cause trouble. Automation magnifies a stable process; it can also magnify ambiguity.

  • Write the trigger in one sentence.
  • Name every source of data.
  • Describe the action the system may take.
  • List exceptions and the current owner.
  • Record current time, backlog and error level.
Use the 90-day planning framework
03

Score value and risk separately

A high-volume task may be commercially attractive and still be unsafe to run without review.

Estimate value from frequency, minutes saved, delay removed, error avoided and capacity released. Then assess risk independently: data sensitivity, reversibility, customer effect, financial authority and the cost of a confident wrong answer. A single blended score can hide a valuable but high-risk workflow.

NIST’s AI Risk Management Framework asks organisations to define the task, roles, human-AI configuration and ongoing monitoring. Use that logic to choose the control: automatic execution for low-impact bounded steps, sampled review for reversible work, and explicit approval for actions with material consequences.[2]

04

Build governance into the workflow

The operating controls should be designed before the pilot handles real customers or sensitive data.

Use dedicated credentials with the minimum access required. Log the input, model or rule version, output, action, reviewer and exception. Define what happens when data is missing, a tool fails or confidence is too low. A manual queue is a valid fallback.

In the EU, the AI Act’s AI-literacy duty has applied since 2 February 2025, and the Commission says supervision and enforcement for that duty starts on 3 August 2026. Teams using AI need role-appropriate knowledge of opportunities, risks and possible harm; a vendor demonstration is not a training programme.[3][4]

05

Keep human review where the consequence is real

Human review must be able to change the result, not merely observe it after the action.

Require approval for refunds, account restrictions, contract commitments, hiring decisions, credit decisions, health or safety advice, and unusual customer cases. The reviewer needs enough context and time to disagree with the system.

GDPR restrictions can apply when a decision is based solely on automated processing and has legal or similarly significant effects on a person. The European Commission describes safeguards including information, human intervention and a route to contest the decision. Obtain appropriate legal and data-protection advice for the actual use case.[5]

06

Run a bounded pilot and earn the right to expand

The pilot should test the operating system, not only whether the model can produce an impressive example.

Start with historical or low-risk cases, then a limited live queue. Track completion time, first-pass accuracy, exception rate, rework, customer outcome and staff effort. Include failures and silent corrections; a faster queue is not an improvement if cleanup moved elsewhere.

Set stop, revise and expand rules before launch. Expand only when the measured gain survives normal variation, the error pattern is understood and the team can operate the review queue. Increase one dimension at a time: volume, data access, action authority or use-case breadth.

Compare AI and automation specialists
07

FAQ

Frequently asked questions

Which business workflow should be automated first?

Choose a frequent, bounded workflow with a clear trigger, known data, a checkable output and an accountable owner. Lead routing, support classification and recurring reporting often fit better than strategic or exceptional work.

Does the first automation need generative AI?

No. Deterministic rules, forms, integrations or standard workflow automation may be more reliable. Use a model only where classification, extraction, summarisation or language generation adds useful judgment.

How long should an AI automation pilot run?

Run it long enough to include normal volume and important exceptions. Define a minimum case count and decision date from the baseline rather than selecting a universal number of weeks.

What should remain human?

Keep meaningful human control where decisions affect rights, money, customer access, safety, employment or legal commitments, and wherever edge cases cannot be checked reliably.

How should a small team measure return?

Compare staff time, cycle time, backlog, error, rework and customer outcomes with the previous process. Subtract review, software, integration, maintenance and incident costs.

Is this legal advice on the EU AI Act or GDPR?

No. It is an operational starting point. Classification, documentation, data protection and human-review duties depend on the system and use case; obtain qualified advice where consequences are material.

08

Sources and further reading

Editorial method: English and Portuguese SERP patterns were reviewed on 26 July 2026. Partner pages supplied practitioner questions; factual claims were checked against the primary and official sources below. Commercial and partner material was not treated as independent proof.

  1. How to choose the first AI workflow to automate — David Dacruz

    Partner practitioner perspective on bounded AI systems, implementation components and fit. Service claims are not independent evidence.

  2. NIST — AI Risk Management Framework Core

    Primary risk-management guidance on task definition, roles, human oversight and monitoring.

  3. European Commission — AI literacy questions and answers

    Official explanation of Article 4 AI-literacy duties and application dates.

  4. European Commission — Navigating the AI Act

    Official implementation timeline and deployer guidance.

  5. European Commission — Restrictions on automated decision-making

    Official GDPR overview of solely automated decisions with legal or similarly significant effects.