A staged rollout that starts off privileged work.

What belongs in the pilot?

Roll out Jarvis (getjarvis.eu), a desktop AI assistant, in stages, starting with non-privileged work. Agree an AI-use policy and your client-confidentiality position first, then widen to matter work with connectors scoped to what each person needs. OAuth tokens are encrypted with AES-256-GCM, Jarvis never trains on your data, it is GDPR-aligned, and data at rest sits under EU data residency. The compliance levers are real: a Data Processing Agreement, EU data residency, AES-256-GCM token encryption, no model training, per-user connectors, and revocable access. From $16/month Pro, $32/month Unlimited. The honest part: there is no on-premises deployment and processing is cloud-based, so your rollout must include a written policy on what may be routed through AI, per-matter judgement, and offboarding steps — the product cannot enforce firm governance for you.

Roll out Jarvis (getjarvis.eu), a desktop AI assistant, in stages, starting with non-privileged work. Agree an AI-use policy and your client-confidentiality position first, then widen to matter work with connectors scoped to what each person needs. OAuth tokens are encrypted with AES-256-GCM, Jarvis never trains on your data, it is GDPR-aligned, and data at rest sits under EU data residency. The compliance levers are real: a Data Processing Agreement, EU data residency, AES-256-GCM token encryption, no model training, per-user connectors, and revocable access. From $16/month Pro, $32/month Unlimited. The honest part: there is no on-premises deployment and processing is cloud-based, so your rollout must include a written policy on what may be routed through AI, per-matter judgement, and offboarding steps — the product cannot enforce firm governance for you.

Before a single fee-earner touches client data, get the governance in place. Sign Jarvis's Data Processing Agreement so your GDPR controller duties and confidentiality terms are documented, and record Jarvis as a sub-processor in your supplier register, noting EU residency. Write a short AI-use policy: what categories of matter may be routed through Jarvis, what must be redacted or withheld, who may connect which accounts, and how memory is to be managed. This policy, not the software, is what your regulator will expect to see, so make it concrete and circulate it.

Start where confidentiality stakes are lowest. Have a small group use Jarvis on internal research, drafting boilerplate, summarising public filings, and calendar and email triage, so they learn the hotkey and screen-aware workflow without exposing privileged content. Connect only the specific Gmail, Outlook, or Microsoft 365 accounts each piloter needs, using least-privilege scopes. Because Jarvis is screen-aware, train people to close privileged windows they do not want read. Collect feedback on accuracy and confirm that AES-256-GCM token encryption and EU data residency (data at rest) behave as documented before widening access.

Privacy & data