Your AI Assistant Is Generating Discoverable Records Right Now
Companies spent two years arguing about whether employees should paste confidential material into chatbots. Almost nobody asked the follow-up question: what happens to the transcript. Prompts, outputs, retrieval traces, and agent action logs are electronically stored information — and retention policy for them is usually a vendor default nobody chose.
Why AI Logs Are Worse Than Email
Email discovery is a solved problem operationally: one system, one archive, one hold tool, custodians everyone can enumerate. AI usage is the opposite. It is spread across a sanctioned enterprise assistant, an IDE plugin, a support-desk bot, three agents wired into internal tooling, and whatever individual employees signed up for with a work address.
The result is that most organisations cannot answer the first question a court or opposing counsel asks: where does AI conversation data live, who can retrieve it, and how long does it survive by default? Not knowing is itself the finding.
What Counts as the Record
The prompt
What the employee asked, verbatim. In an employment or trade-secret dispute this is frequently the single most revealing artefact in the case, because people type things into an assistant they would never put in an email.
The output
What the model returned — including the version the employee rejected before regenerating. Where a business decision was made on model output, the output is the contemporaneous basis for the decision.
Retrieval and grounding traces
In a RAG system, which internal documents were pulled into context. This shows what information was actually in front of the decision-maker, which is often more probative than the answer itself.
Agent action logs
For agents that take actions — sending messages, updating records, executing transactions — the action log is the audit trail. If an agent did something contested, this is the only record of why.
Configuration and version history
System prompts, guardrail settings, model version, and temperature at the time. Reproducing behaviour later is impossible without them, and 'we can't reproduce it' is not a defence that lands well.
Feedback and override signals
Thumbs-down ratings, human overrides, and escalation flags are the closest thing to a contemporaneous admission that the system was getting something wrong — and they are routinely retained longer than anyone realises.
The Two Ways Teams Get This Wrong
Both failure modes are common, and they pull in opposite directions:
- Delete-everything. A short vendor-default retention window feels privacy-forward and cheap. It works until a dispute arises and the logs that would have exonerated you evaporated on schedule — or worse, kept evaporating after the duty to preserve attached, which converts a records-management decision into a sanctions question.
- Keep-everything. Retaining every prompt indefinitely because storage is cheap creates a permanent, searchable corpus of unguarded employee speculation, half-formed legal theories, and confidential material pasted in for summarisation. Every future matter gets to search it.
- The hold that misses the AI tools. The most frequent real-world failure: legal issues a hold covering email, chat, and file shares, and nobody adds the AI assistant because it is not on the systems inventory. The timer keeps running.
- Shadow AI with no admin access. Employees using personal accounts for work create records you may have a duty to preserve and no technical ability to reach.
Where Preservation and Privacy Deletion Collide
A consumer submits a deletion request under a state privacy law. Their conversation with your support bot is also within the scope of an active litigation hold. Privacy regimes generally recognise legal-obligation and legal-claim exceptions to deletion, so the hold usually wins for that specific data — but only if you can articulate the scope at the time and confine the exception to it. The organisations that get in trouble are the ones that either honour the deletion and destroy evidence, or invoke "legal hold" as a standing reason to ignore deletion requests wholesale. Both are avoidable with a written mapping between your hold scope and your deletion workflow.
A Retention Program That Survives Contact
The goal is a defensible, consistently applied schedule with a hold override that actually reaches every AI system — not the longest or shortest possible retention.
Your public AI disclosures are part of the same record
What your site tells users about AI chat, data retention, and processing is the first thing pulled when a dispute starts — and it is frequently out of date. RatedWithAI scans your public properties for those gaps. Start with a free scan.
Scan Your Site for Free →Frequently Asked Questions
When does the duty to preserve AI logs actually attach?
When litigation is reasonably anticipated — not when a complaint is filed. A demand letter, a credible internal complaint, or a regulator's inquiry can start the clock. Because AI retention windows are often short, the gap between anticipation and issuing the hold matters far more here than it does for email.
Is an AI-generated summary privileged if legal asked for it?
Privilege turns on the same analysis as any other document: was it a confidential communication for the purpose of legal advice. Routing a request through a model does not create privilege where none existed, and doing it in a shared workspace can undermine confidentiality. Treat AI-assisted legal work with the same access controls as any privileged draft.
What if the vendor says they don't retain our prompts?
Get it in writing at the contract level, with the specific retention period and any exception for abuse monitoring or trust-and-safety review, and confirm whether a zero-retention setting is actually enabled on your tenant. Marketing pages and contractual commitments frequently differ, and the exception carve-outs are where the surviving copies live.
Do we have to preserve logs from an employee's personal ChatGPT account?
Possibly, if it was used for company business — the analysis parallels personal devices and personal email, where control is assessed practically. The realistic answer is that enforcement is hard and prevention is easy: sanctioned tooling with admin access is worth more than a policy telling people not to.
Can we sample rather than preserve every conversation?
Not once a hold attaches to that category of records. Sampling is a reasonable approach to routine retention design before any dispute, but preservation obligations run to relevant records, not to a representative subset of them.