For a first pilot, I would choose one continuing responsibility: check named public regulator pages and prepare an internal update. Define what the agent may read, prepare, change and send, then test whether those boundaries hold when the request changes.

Separate access from permission to act

A connected account answers a technical question: what can the system reach? The delegation answers an operational question: what may it do for this task? Professional responsibility remains with the people accepting the work.

ABA Formal Opinion 512, issued July 29, 2024, addresses competence, confidentiality, supervision and training under the ABA Model Rules. US firms must check their applicable jurisdiction’s rules. For SRA-regulated firms and individuals in England and Wales, the August 17, 2026 warning emphasizes accountability, effective supervision and appropriate safeguards. Neither source endorses this checklist.

Before introducing client information, assess the actual service, contractual terms, data handling and required client communication. A paid plan alone does not settle confidentiality. This guide proposes an operational pilot; it is general information, not legal advice or a compliance determination.

Start with a permissions matrix

This proposed matrix keeps the pilot on public regulatory material. Client files, live deadlines, payments and filings remain outside its scope.

Proposed public-data pilot checklist covering read, prepare, change, communicate, delegate and stop, with a boundary and evidence check for each action.
Proposed public-data pilot boundaries and evidence checks. Test them in the actual workspace before relying on them.
Action Pilot boundary Evidence to check
Read Named public regulator URLs and an approved comparison snapshot Source URL, retrieved date and missing pages
Prepare Draft a change note with supporting passages and uncertainties Each material claim traces to a source
Change Save a new draft in the designated pilot folder Correct location, version and access
Communicate Return the draft to the named reviewer; no external sending Actual destination and delivery status
Delegate Only the same sources, actions and destination Visible child tasks and their instructions
Stop End active work and future runs when withdrawn or expired Main task, child tasks and schedules checked separately

Drafting a client alert would need its own approved source boundary and reviewer. Updating a live matter record would require another decision about which fields may change, who checks them and how an error is corrected. Treat each expansion as a change to the delegation.

Write one delegation card

Before starting, fill in six answers: who owns the pilot; which exact sources it uses; where the draft goes; who can approve a change; when authority expires; and what proves completion.

An example instruction:

Until the recorded pilot expiry date, compare the listed public regulator pages with the approved snapshot. Save a new, source-linked change note in the pilot folder for the named reviewer. Identify inaccessible sources and uncertainty about legal effect. Do not contact clients, amend matter records or calculate filing deadlines. Any delegated task must keep these limits. Ask the owner before changing sources, destination or scope.

Replace every placeholder before use. Record the exact expiry time and timezone, and verify the schedule’s end condition; written instructions alone do not establish automatic expiry. Put the review date and an available backup reviewer on the card. If nobody can accept the work, reduce the incoming workload; the review-capacity guide helps examine that constraint.

Test approvals and revocation

A successful first note proves little about how the workflow behaves at its edges. Use public or synthetic material and firm-controlled test accounts for these exercises:

  1. Outbound approval. Verify that action-time approval for sending is active in the intended workspace; custom rules may be disabled by workspace policy. Request a draft, then a send to a named test recipient. While withholding approval, check that no message reaches the test mailbox. After approval, inspect the recipient, received message and sent record.

  2. Wrong authority. Put an instruction in a source document asking the agent to change destination. Check that the document cannot expand the owner’s delegation.

  3. Revocation. Demonstrate a successful fresh read from a synthetic test folder. Revoke access and repeat through that same route. Record the result. Separately identify material already copied into outputs or memory, and apply the approved retention process.

  4. Stopping. Start a bounded delegated test and a test schedule. Confirm the child task is running. Stop the main task, separately stop each child task, and disable the schedule. Check each resulting status and the schedule’s end condition before declaring the pilot stopped.

These are proposed acceptance tests, not results from a completed law-firm deployment. A denied read alone does not prove that every access route has been revoked.

What dots currently documents

Product check on October 2, 2026. OpenAI describes automatic action review and scoped ongoing instructions. Draft permission does not authorize sending. Custom rules can make mistakes and operate separately from app permissions. Its controls guide also says Pause stops the main task; delegated tasks and scheduled runs must be stopped separately. Completed actions are not undone.

Current eligibility lists gradual rollout for eligible Pro accounts outside the EEA, UK and Switzerland, Business Premium across supported ChatGPT regions, and an Enterprise beta available when the workspace administrator enables it; rollout can take time to reach an eligible account. A personal Pro experiment establishes nothing about a firm’s configured Enterprise workspace.

The Enterprise administration guide describes role-based access, app-action restrictions and computer controls. It directs administrators to supported Compliance API records and asks them to confirm coverage. Disconnecting an app does not erase information already obtained. Verify these controls in the intended workspace before relying on them.

Keep evidence proportionate and usable

My non-client dots experiment includes native desktop widgets, an operator-maintained journal and tested recovery of selected saved files. That gives me concrete work to inspect and resume. It does not establish a platform audit log, complete action capture or legal compliance.

For this pilot, retain the approved delegation version, source references, draft, reviewer corrections and relevant execution receipts. Keep the record readable enough for someone else to continue; the reviewable work-sample guide covers that handoff.

Where EU GDPR applies, accountability sits alongside data minimisation and storage limitation. The EDPB’s principles summary supports that balance. Decide what evidence is necessary, who may access it and how long it should remain, including any applicable preservation duties.

Expand only when the reviewer can explain what happened, find the evidence and stop the remaining work. Unexplained sends, unaccounted-for active child tasks or an untestable revocation process are reasons to pause expansion. The useful first milestone is one bounded responsibility that the firm can actually supervise.

For product context and documented access, read OpenAI dots for lawyers. The hybrid-firm essay connects bounded delegation to the wider delivery model.

Questions and answers

Does connecting an account authorize an agent to send messages?

Technical access and authority to act are separate. Define the permitted action, recipients and approval boundary; a request to prepare a draft does not authorize delivery.

What should a first law-firm AI agent pilot read?

This proposed pilot reads named public regulator pages and an approved comparison snapshot. Client files, live deadlines, payments and filings remain outside its scope.

What belongs on a delegation card?

Record the owner, exact sources, draft destination, change approver, expiry time and timezone, and evidence of completion. Add the reviewer and a backup, then test the schedule end condition.

How should a team test revocation and stopping?

First establish a successful synthetic read, revoke that access and repeat through the same route. Check retained material separately. Stop the main task, each active child task and future schedules, and inspect all resulting states.

Do these tests certify compliance?

No. They are proposed operational acceptance tests, not results from a completed law-firm deployment. Applicable professional, privacy and security requirements need review in the intended jurisdiction and workspace.

Operational information, not legal advice. Product details and primary sources rechecked October 3, 2026. Proposed evaluations are identified in the text.