Pick the one task your team repeats most often, buy ten licences rather than a hundred, and measure the error rate for a month before you decide anything. That is the whole starting method. It sounds too modest to be a strategy, which is precisely why it works: Boston Consulting Group’s September 2025 research found about 5% of companies generating AI value at scale while 60% reported hardly any material value despite substantial investment. The difference was rarely the model they picked.

Start with one task and one month
Resist the urge to run a survey of every department. Instead, find the task that is high volume, low judgement and already annoying: sorting the shared inbox, drafting the same six replies, pulling totals out of supplier invoices, summarising a call log. Those have a measurable before-state, which is the only thing that makes the after-state meaningful.
Then set the pilot up so it can fail cheaply. Ten people, one month, a human reviewing every output before it leaves the building, and a tally of how often the review had to change something. If the correction rate is one in twenty, you have found something useful. If it is one in three, you have found a task that needs standardising before any software touches it.
- Write down the current cost: hours per week, and how often the output needs rework.
- Ten licences, not a department-wide rollout. You are buying evidence, not capability.
- Every output reviewed by a person for the first four weeks, with corrections logged.
- A go or no-go decision on a fixed date, with the correction rate as the deciding number.
What AI costs now, and why that changed everything
The reason this is worth your attention in 2026 and was not in 2022 is price. Stanford’s AI Index 2025 recorded the cost of querying a model scoring at GPT-3.5 level on the MMLU benchmark dropping from USD 20 per million tokens in November 2022 to USD 0.07 by October 2024, a reduction of more than 280 times in roughly eighteen months. The capability that needed a research budget now sits inside a per-seat subscription.
That has a second consequence worth knowing: the marginal cost of usage is now so low that almost all of your spend is the licence, not the compute. So the question stops being “can we afford to run this” and becomes “how many people genuinely need a seat”. Those are very different procurement conversations, and the second one is the one that saves money.
The use cases that actually pay for small teams
Eurostat’s December 2025 extraction is the most useful guide to what businesses are actually doing, as opposed to what gets demonstrated at conferences. Text mining — analysing written language — led at 11.75% of EU enterprises. Generating pictures, video and audio followed at 9.55%, and generating written or spoken language at 8.76%. The reading is clear: understanding text you already hold beats producing new text you did not need.
Scale matters too, and it is encouraging if you are small. Eurostat put AI use at 17% of small EU enterprises in 2025, 30.36% of medium ones and 55.03% of large ones. Large companies are further ahead, but they are also slower to change a process, which is the actual constraint. A ten-person team can standardise a workflow in a fortnight.
- Support triage. Classify and route incoming messages, and draft a first reply for a human to approve. Highest-volume, lowest-risk starting point for most firms.
- Document extraction. Pull line items, dates and totals out of invoices, delivery notes or contracts into your accounting system.
- Internal search. Answer questions from your own policies, manuals and past quotations rather than from the open internet.
- Meeting and call summaries. Cheap, immediately useful, and low consequence when it gets a detail wrong — provided a human still writes the actions.
- Drafting repetitive copy. Product descriptions, standard clauses, job adverts. Always edited, never published raw.

What the licences cost at list price
Prices move, so treat the table below as a snapshot: these are Microsoft’s published list prices as we read them in October 2026, before tax, and the add-on requires a qualifying Microsoft 365 business or enterprise plan. We use Microsoft here because it publishes clear per-seat pricing; the same comparison discipline applies whichever vendor you are weighing.
| Plan | Paid yearly (per user/month) | Paid monthly (per user/month) | What it is |
|---|---|---|---|
| Microsoft 365 Copilot Business (add-on) | $18.00 | $25.20 | AI assistance added to an existing Microsoft 365 plan; listed as reduced from $21.00 |
| Microsoft 365 Business Standard with Copilot | $23.50 | $28.20 | The Business Standard productivity apps with Copilot included |
| Microsoft 365 Business Premium with Copilot | $32.00 | $38.40 | Business Premium, which adds device management and data protection, with Copilot included |
Two things fall out of those numbers. First, flexibility has a price: on those list prices the monthly option costs 40% more per seat than the annual commitment for the add-on, and 20% more for the two bundled tiers. A short pilot is therefore more expensive per head, and that is simply the cost of the evidence. Second, bundling changes the arithmetic — if you were going to upgrade your productivity plan anyway, compare against your current invoice rather than against zero.
On sizing the first purchaseTen seats for three months is a cheap experiment. A hundred seats for a year is a budget line you will be defending in April.
Keeping your data out of trouble
This is the part small companies skip and then regret. IBM’s 2026 Cost of a Data Breach Report found that one in four malicious breaches were AI-enabled, a 56% increase on the previous year, and that those breaches cost around USD 6 million on average against a global average of USD 4.99 million. More than 20% of organisations reported a breach targeting their AI models or applications.
The governance gap is wider than the technical one. IBM’s 2025 report found 63% of breached organisations either had no AI governance policy or were still developing one — while the same research showed organisations using AI and automation extensively across security operations saved an average of USD 1.9 million in breach costs. The technology is not the risk. Unmanaged use of it is.
- Decide what must never be pasted in. Customer identifiers, card data, health information, unreleased financials, anything under a client NDA.
- Use the business tier, not the free one. Check in writing whether your prompts are used for training, and where the data is processed.
- One sanctioned tool. Shadow usage is what creates the breach path; it is driven by people needing a tool and not being given one.
- Log the administrative access. Who can change the configuration, and who reviews that list when someone leaves.
- Keep a human on anything customer-facing. Not forever, but until the measured correction rate says otherwise.
Governance that fits on one page
You do not need an AI policy framework. You need one page that a new starter can read in five minutes. The NIST AI Risk Management Framework is a useful free structure to borrow from if you want a reference point, and it maps neatly onto a single sheet for a company of forty people.
- Approved tools. Name them. Everything else needs a conversation first.
- Data that never goes in. A short, specific list, not a vague principle.
- Review rules. Which outputs a human must check before they leave the company, and who that human is.
- Disclosure. When you tell a customer that AI was involved. If you sell into the EU, check how the AI Act’s timetable applies to your use case.
- Owner and review date. One named person, one date in the diary.

How to tell whether it worked
Judge it on three numbers and nothing else. Time: hours per week on the task, measured the same way before and after. Quality: the share of outputs that needed correcting, tracked weekly so you can see whether it improves as people learn the tool. Cost: licences plus the setup plus the training time, against the hours you recovered.
Expect the correction rate to be unflattering in week one and better by week four, because most of the improvement comes from people learning what to ask for rather than from the model changing. If it has not improved by the end of the month, stop and write down why. That note is the most valuable output of a failed pilot, and it is what keeps you from buying the same idea again next year. Digital Transformation Without the Buzzwords sets out the same measurement habit for technology projects generally.
Where this sits in a wider plan matters too. If you are weighing AI against other calls on the same budget, Which Emerging Technologies Are Worth Your Investment? triages the options, and Working With a Remote IT Services Partner: What to Expect describes how an outside team runs a pilot like this without anyone travelling.

Eudora sets these pilots up remotely: we define the task, configure the tooling in your own tenancy, train the first group over video, and hand you the measurement sheet along with the configuration notes. The full list of what we cover is on our services page. If you need on-site work in Sri Lanka, that is our sister business at eudora.lk.
Frequently asked questions
Do we need a data scientist?
Not for any of the use cases above. You need someone who can define the task precisely, someone who will check the outputs honestly, and an administrator who can configure the tool inside your own tenancy. A data scientist becomes relevant when you want to train on your own data, which is a much later problem than most vendors imply.
Is our data safe in these tools?
It depends entirely on the tier you buy and what the contract says. Business and enterprise tiers generally commit not to train on your content; consumer tiers often make no such promise. Get it in writing, check where processing happens if data residency matters to you, and keep a short list of data that never goes in regardless.
What should we budget for a first pilot?
Ten seats for three months plus a few days of configuration and training. On Microsoft’s October 2026 list prices, the Copilot Business add-on is $18.00 per user per month paid yearly or $25.20 paid monthly, so the licence element of a short pilot is modest against the hours you are trying to recover.
How do we stop staff pasting customer data into free tools?
Give them a sanctioned tool and say clearly what is off limits. Shadow usage is almost always a symptom of an unmet need rather than carelessness. IBM’s 2025 research found 63% of breached organisations had no finished AI governance policy, which is the gap that turns ordinary helpfulness into an incident.
When should we widen the rollout?
When the correction rate has been stable and acceptable for a month, the people in the pilot would complain if you took it away, and you can name the hours recovered. If any of those three is missing, extend the pilot instead of expanding it.
Have one repetitive task in mind and want it piloted properly, with numbers rather than enthusiasm? Describe it to us and we will scope a one-month trial. Get in touch with Eudora Technology to talk about your project.
Sources
- AI Index 2025: the state of AI in 10 charts
- Use of artificial intelligence in enterprises
- Microsoft 365 Copilot plans and pricing
- The Widening AI Value Gap
- One in four malicious breaches are AI-enabled, costing companies $6 million on average
- Average global data breach cost now $4.44 million
- AI Risk Management Framework



