Key Takeaways
- Prompts, outputs, and usage logs from generative AI are treated as electronically stored information (ESI) and are subject to the same preservation and production rules as emails or documents.
- Courts have already ordered the preservation and production of millions of AI‑generated logs (e.g., the OpenAI copyright case), showing that novelty does not shield AI data from discovery.
- The greatest litigation risk is failure to preserve relevant AI data; auto‑deleting chatbot sessions can trigger spoliation sanctions under Fed. R. Civ. P. 37(e).
- Attorney‑client privilege is not automatic for AI exchanges; protection depends on the tool’s confidentiality terms, whether the interaction occurs on a vetted enterprise platform, and the purpose of the communication.
- When AI outputs inform decisions, compliance, or client‑facing work they may constitute business records with their own retention and supervision obligations.
- Organizations should inventory all AI use (including unsanctioned “shadow AI”), update legal‑hold checklists to capture prompts and logs, adopt deliberate retention schedules, and train employees that AI interactions are not private and may become evidence.
AI Content Is ESI, and the Old Rules Apply
Courts confronting AI‑generated material have not created a special exemption for it. Instead, they apply the familiar framework of the Federal Rules of Civil Procedure, treating prompts and outputs as electronically stored information (ESI) that is discoverable when relevant and proportional to the needs of the case. As the article notes, “The comfortable assumption that a private chat with an AI assistant is ephemeral or off the record is turning out to be wrong.” This means that a company’s internal AI usage—what employees type, what the model returns, and the logs the system generates—can be requested and ordered produced in litigation. Treating those materials as invisible is a planning failure that can quickly become a sanctions problem.
Preservation and the Spoliation Trap
The most acute risk is not production but preservation. The duty to preserve relevant evidence attaches once litigation is reasonably anticipated, well before a complaint is filed, and it extends to relevant AI‑generated ESI. Many consumer and enterprise chatbot configurations delete conversation history automatically, and some offer ephemeral or temporary sessions that vanish by design. If a company anticipates litigation and does nothing to override those defaults, relevant prompts and outputs may be destroyed—the classic setup for a spoliation claim. Under Rule 37(e), a party that fails to take reasonable steps to preserve ESI it should have kept can face curative measures, and where the loss was intentional, severe sanctions including adverse‑inference instructions. The article warns, “Avoiding that trap requires affirmative steps that many legal‑hold processes have not yet incorporated.”
Privilege Is Not Guaranteed – and Courts Are Split
Companies sometimes assume that an AI exchange conducted by or for counsel is automatically protected. It is not. Courts have begun to divide on whether and when AI prompts and outputs qualify for attorney‑client privilege or work‑product protection. A central fault line concerns the use of public, third‑party AI tools. Some courts suggest that feeding otherwise‑protected material into a public model can jeopardize protection because disclosure to an outside system undercuts confidentiality; this reasoning has surfaced most sharply in the criminal context. Other courts, in civil matters, have declined to find waiver merely because a litigant used a public AI platform, analogizing the tool to ordinary software rather than to disclosure to an adversary. The result is genuine uncertainty. As the text observes, “A prompt drafted by a lawyer reflecting litigation strategy may be shielded as work product in one court and exposed in another.” Organizations should therefore assume that a chatbot session is presumptively discoverable business information unless it was created under conditions genuinely designed to preserve privilege—counsel involvement, a confidential and controlled platform, and a documented legal purpose.
AI Output as a Business Record
Beyond preservation and privilege lies a category question that many organizations have not confronted: when does an AI output become a business record with its own retention obligations? Where employees rely on AI outputs to make decisions, or where those outputs support audit, compliance, or client‑facing functions, the outputs can take on the character of business records. In regulated industries, AI‑generated content that informs communications, marketing, or operational decisions may trigger the same documentation, supervision, and retention requirements that apply to other records. The article cites FINRA Regulatory Notice 24‑09, which confirms that existing recordkeeping, supervision, and communications rules apply to member firms’ use of generative AI. Ignoring those duties creates exposure not only in civil discovery but in regulatory examinations. The organizations best positioned are those that understand how their AI systems create, retain, and delete data, and that align those practices with records‑management and legal‑hold processes rather than leaving AI usage in an ungoverned shadow.
**The path forward is governance, not avoidance. Organizations should begin by inventorying how AI tools are actually used across the enterprise, including unsanctioned “shadow AI” that employees adopt on their own, because a preservation duty cannot be met for data no one knows exists. From that inventory, companies should set retention policies that make deliberate choices about what AI data is kept, for how long, and where—choices that balance operational value, storage cost, and litigation risk rather than defaulting to whatever the vendor’s settings happen to be. Legal‑hold procedures should be updated to expressly address AI ESI, with a checklist that prompts counsel to identify AI usage, suspend auto‑deletion, and capture relevant prompts, outputs, and logs when a hold attaches. ESI protocols negotiated at the outset of litigation should account for AI‑generated material, addressing sources, formats, search methodology, and the privacy and privilege safeguards—protective orders, anonymization, and staged production—that courts increasingly expect. Employee training and acceptable‑use policies should tell workers plainly that their AI interactions are not private, may be preserved, and may become evidence, and should steer sensitive or privileged material away from tools that cannot protect it.
Conclusion
None of this requires abandoning generative AI, which delivers real value. It requires treating AI‑generated content as what the courts have already decided it is: ordinary ESI, governed by ordinary rules, carrying ordinary risk. The organizations that internalize that reality now—before a preservation demand or a discovery request forces the issue—will be the ones whose chatbots do not become the most damaging witnesses in their own cases.
This article was written by Arnold D. Lee, an attorney in the Phoenix, Arizona office of Spencer Fane. For more information, visit spencerfane.com.
https://www.spencerfane.com/insight/prompts-and-production-your-chatbot-may-not-be-your-friend-in-litigation/

