RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 2, 2026

Your AI Assistant Is Generating Discoverable Records Right Now

Companies spent two years arguing about whether employees should paste confidential material into chatbots. Almost nobody asked the follow-up question: what happens to the transcript. Prompts, outputs, retrieval traces, and agent action logs are electronically stored information — and retention policy for them is usually a vendor default nobody chose.

ESI
Prompts and outputs are ordinary electronically stored information
Hold > policy
A preservation duty overrides your routine auto-delete schedule
Both ways
Deleting too fast risks spoliation; keeping everything creates a discovery liability

Why AI Logs Are Worse Than Email

Email discovery is a solved problem operationally: one system, one archive, one hold tool, custodians everyone can enumerate. AI usage is the opposite. It is spread across a sanctioned enterprise assistant, an IDE plugin, a support-desk bot, three agents wired into internal tooling, and whatever individual employees signed up for with a work address.

The result is that most organisations cannot answer the first question a court or opposing counsel asks: where does AI conversation data live, who can retrieve it, and how long does it survive by default? Not knowing is itself the finding.

What Counts as the Record

The prompt

What the employee asked, verbatim. In an employment or trade-secret dispute this is frequently the single most revealing artefact in the case, because people type things into an assistant they would never put in an email.

The output

What the model returned — including the version the employee rejected before regenerating. Where a business decision was made on model output, the output is the contemporaneous basis for the decision.

Retrieval and grounding traces

In a RAG system, which internal documents were pulled into context. This shows what information was actually in front of the decision-maker, which is often more probative than the answer itself.

Agent action logs

For agents that take actions — sending messages, updating records, executing transactions — the action log is the audit trail. If an agent did something contested, this is the only record of why.

Configuration and version history

System prompts, guardrail settings, model version, and temperature at the time. Reproducing behaviour later is impossible without them, and 'we can't reproduce it' is not a defence that lands well.

Feedback and override signals

Thumbs-down ratings, human overrides, and escalation flags are the closest thing to a contemporaneous admission that the system was getting something wrong — and they are routinely retained longer than anyone realises.

The Two Ways Teams Get This Wrong

Both failure modes are common, and they pull in opposite directions:

  • Delete-everything. A short vendor-default retention window feels privacy-forward and cheap. It works until a dispute arises and the logs that would have exonerated you evaporated on schedule — or worse, kept evaporating after the duty to preserve attached, which converts a records-management decision into a sanctions question.
  • Keep-everything. Retaining every prompt indefinitely because storage is cheap creates a permanent, searchable corpus of unguarded employee speculation, half-formed legal theories, and confidential material pasted in for summarisation. Every future matter gets to search it.
  • The hold that misses the AI tools. The most frequent real-world failure: legal issues a hold covering email, chat, and file shares, and nobody adds the AI assistant because it is not on the systems inventory. The timer keeps running.
  • Shadow AI with no admin access. Employees using personal accounts for work create records you may have a duty to preserve and no technical ability to reach.

Where Preservation and Privacy Deletion Collide

A consumer submits a deletion request under a state privacy law. Their conversation with your support bot is also within the scope of an active litigation hold. Privacy regimes generally recognise legal-obligation and legal-claim exceptions to deletion, so the hold usually wins for that specific data — but only if you can articulate the scope at the time and confine the exception to it. The organisations that get in trouble are the ones that either honour the deletion and destroy evidence, or invoke "legal hold" as a standing reason to ignore deletion requests wholesale. Both are avoidable with a written mapping between your hold scope and your deletion workflow.

A Retention Program That Survives Contact

The goal is a defensible, consistently applied schedule with a hold override that actually reaches every AI system — not the longest or shortest possible retention.

Inventory every AI system that stores prompts or outputs, including plugins and agentsEssential
For each, record the default retention window, admin export path, and who owns the accountEssential
Add AI systems to the litigation-hold checklist as named custodial sourcesEssential
Verify you can technically suspend auto-deletion per system — test it before you need itEssential
Set retention by use case, not one global timer: support transcripts and agent action logs are not the same recordPolicy
Map the privacy-deletion workflow against active hold scopes so both are honouredPrivacy
Capture model version, system prompt, and configuration alongside the transcriptEvidence
Close off shadow AI with sanctioned tooling — you cannot preserve what you cannot reachGovernance
Document the retention rationale in writing, before any dispute existsDefensibility

Your public AI disclosures are part of the same record

What your site tells users about AI chat, data retention, and processing is the first thing pulled when a dispute starts — and it is frequently out of date. RatedWithAI scans your public properties for those gaps. Start with a free scan.

Scan Your Site for Free →

Frequently Asked Questions

When does the duty to preserve AI logs actually attach?

When litigation is reasonably anticipated — not when a complaint is filed. A demand letter, a credible internal complaint, or a regulator's inquiry can start the clock. Because AI retention windows are often short, the gap between anticipation and issuing the hold matters far more here than it does for email.

Is an AI-generated summary privileged if legal asked for it?

Privilege turns on the same analysis as any other document: was it a confidential communication for the purpose of legal advice. Routing a request through a model does not create privilege where none existed, and doing it in a shared workspace can undermine confidentiality. Treat AI-assisted legal work with the same access controls as any privileged draft.

What if the vendor says they don't retain our prompts?

Get it in writing at the contract level, with the specific retention period and any exception for abuse monitoring or trust-and-safety review, and confirm whether a zero-retention setting is actually enabled on your tenant. Marketing pages and contractual commitments frequently differ, and the exception carve-outs are where the surviving copies live.

Do we have to preserve logs from an employee's personal ChatGPT account?

Possibly, if it was used for company business — the analysis parallels personal devices and personal email, where control is assessed practically. The realistic answer is that enforcement is hard and prevention is easy: sanctioned tooling with admin access is worth more than a policy telling people not to.

Can we sample rather than preserve every conversation?

Not once a hold attaches to that category of records. Sampling is a reasonable approach to routine retention design before any dispute, but preservation obligations run to relevant records, not to a representative subset of them.

Related Guides

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.