ooligo
ENTRY TYPE · definition

Discovery of AI prompts and outputs

By Marius Bughiu Last updated 2026-08-29 Legal Ops

Yes. Prompts your employees type into ChatGPT, Copilot, Gemini, or Claude, and the outputs those tools return, are electronically stored information under Federal Rule of Civil Procedure 34(a)(1)(A). Rule 34 reaches “data or data compilations stored in any medium” within a party’s possession, custody, or control, and it carves out no exception for text a machine generated. If the content is relevant and proportional, it is producible on the same terms as email. Parties are already asking for it, and courts are already ordering it.

What this is not is a privilege question that resolves in your favour. The instinct that a chat window is a private scratchpad — closer to a lawyer’s notebook than to a memo — has now been tested and rejected in the consumer-tier case. It is also not the same problem as the AI vendor’s own litigation: the orders forcing OpenAI to retain and produce chat logs bind OpenAI, not you. And it is not covered by the legal hold you already issue. A hold that names email, Slack, and file shares does not reach a hidden mailbox folder or a vendor API your custodians have never heard of.

Where the data physically lives

The hold you can write depends entirely on which surface the prompt went through. Four patterns cover most enterprise estates:

SurfaceWhere prompts and outputs sitHow you reach them
Microsoft 365 CopilotA hidden folder in the Exchange Online mailbox of the user who ran itPurview eDiscovery search; Litigation Hold or eDiscovery hold on the mailbox
ChatGPT Enterprise / Team / EduOpenAI-side workspace storageCompliance API export, or admin console; third-party eDiscovery and DLP connectors
Claude EnterpriseAnthropic-side organization storageCompliance API — chats, files, projects, and Cowork / Claude Code session transcripts
Gemini app (Workspace)Google-side user activityGoogle Vault retention rules, holds, search, and export
Consumer accounts on personal loginsVendor-side, under the employee’s own accountUsually nowhere you control — see the control problem below

The Microsoft mechanism is worth understanding in detail, because it is the one most in-house teams already own and least understand. Copilot prompts and responses are copied into a hidden folder in the user’s own Exchange mailbox — a folder that is not designed to be reachable by the user or by an admin, but is searchable with eDiscovery tools. When a retention period expires, items move to a second hidden folder called SubstrateHolds, where they remain searchable until permanent deletion. Microsoft’s own documentation is blunt about the consequence: what a user sees in the Copilot window is not an accurate reflection of what is retained or deleted, so verify with eDiscovery tools rather than with the app. The timer jobs that move and purge items typically run on a one-to-seven-day cycle, which is why a policy configured to delete after one day can take roughly 16 days before the content stops appearing in eDiscovery results.

The saving grace is that ordinary hold mechanics still work. Because the data sits in an Exchange mailbox, permanent deletion is suspended whenever the mailbox is subject to a Litigation Hold, an eDiscovery hold, or a competing retention policy. If the custodian leaves, their Copilot interactions move into an inactive mailbox and stay reachable. Google’s Vault behaves the same way for the Gemini app: since June 2026 Vault supports retention rules and litigation holds there, and a hold overrides the user’s own deletion or activity settings — the conversation disappears from the user’s view and stays fully available to Vault administrators.

What courts have actually held

Three decisions do most of the work here.

Consumer-tier AI use forfeits privilege. In United States v. Heppner, Judge Rakoff (S.D.N.Y.) ruled from the bench on 10 February 2026, with a written opinion on 17 February, that 31 documents the defendant generated using Claude were protected by neither attorney-client privilege nor the work product doctrine. He treated it as a question of first impression nationwide and disposed of the privilege claim on a narrow ground: the AI is not an attorney. The work product analysis turned on facts you can change — the defendant was not acting at counsel’s direction, and the terms he accepted told him his data might be disclosed to third parties.

Attorney-directed prompts can be work product, and reliance waives it. In Concord Music Group, Inc. v. Anthropic PBC (N.D. Cal., 23 May 2025), the court held that prompts and settings counsel used in a pre-suit investigation were opinion work product, because they reflected counsel’s mental impressions and litigation strategy. But by pleading from a subset of those prompts and outputs, the publishers effected a limited waiver under the sword-and-shield principle. The court still declined to compel the rest, finding the defendant’s needs could be met with statistical data instead. The shape of the rule: prompt-crafting is strategy, and strategy is protectable until you put it at issue.

Chat logs are producible at scale. In the consolidated S.D.N.Y. copyright MDL, Judge Stein affirmed on 5 January 2026 an order requiring OpenAI to produce a sample of 20 million de-identified consumer ChatGPT logs, holding that user privacy was adequately protected by the reduced sample size, de-identification, and the existing protective order. The related preservation order — which had directed OpenAI to preserve and segregate output log data that would otherwise be deleted — was entered on 13 May 2025 and terminated in October 2025, and the plaintiffs moved for spoliation sanctions in July 2026 over deletions they say continued anyway.

How to scope a hold over it

  1. Inventory the surfaces before the matter, not during it. List every AI tool with an enterprise agreement, then survey for the shadow use — personal ChatGPT logins, browser extensions, AI features embedded in tools you did not classify as AI. The second list is the one that produces sanctions.
  2. Name AI surfaces explicitly in the hold notice. “Documents and communications” does not put a custodian on notice to stop deleting chats. Name the tools.
  3. Turn off self-service deletion where you can. A Vault hold or a Purview eDiscovery hold beats a custodian instruction, because it does not depend on the custodian complying.
  4. Confirm you have the contractual right to retrieve. Check the vendor agreement for export and preservation rights before you need them; a Compliance API you are not licensed for is not a preservation plan.
  5. Log the retention clock for each tool. Consumer ChatGPT removes deleted conversations from OpenAI systems within 30 days. That is your window, and it starts running the moment the duty to preserve attaches — which can be a demand letter, not a complaint.

Common pitfalls

  • Assuming your control extends to personal accounts. Rule 34 reaches what is in your possession, custody, or control, and an employee’s personal ChatGPT account generally is not. That does not save you: you may still owe a preservation instruction to the custodian, and courts are unsympathetic when a company’s own policy permitted the use. Guard: decide the question in policy rather than in a motion — either prohibit personal-account use for work, or require enterprise accounts and enforce it with SSO and network controls, so the “control” answer is settled before a matter starts.
  • Holding the chat and losing the derived data. Retention and hold controls are written for prompts and responses. Adjacent stores — persistent memory, indexed embeddings, agent session state — often sit outside them, so deleting a conversation does not necessarily remove what the system learned from it. Guard: ask each vendor, in writing, which stores a hold actually freezes, and confirm the answer against the deletion path rather than the marketing page.
  • Treating “it’s just a search engine” as a preservation argument. Courts have not accepted that framing, and Rule 37(e) sanctions attach to a failure to take reasonable steps once the duty triggers — negligence is enough for curative measures under 37(e)(1). Guard: write AI surfaces into the standing hold template now, so the reasonableness question is answered by a document that predates the matter.
  • Letting attorney prompts leak into the ordinary corpus. Counsel-crafted prompts can be opinion work product, but only if they are identifiable as counsel’s. Prompts run from a shared workspace account, mixed in with routine business use, are hard to segregate on a privilege log. Guard: run investigation prompting from named counsel accounts or a dedicated matter workspace, and treat the prompt set as a work product item from day one — as you would a privilege review batch.
  • Negotiating the ESI protocol without an AI term. If the protocol is silent, you are arguing about scope after collection has already shaped the record. Guard: put AI sources, custodial surfaces, and export format into the protocol alongside the eDiscovery sources you already negotiate.