AI & Emerging Tech

Prompts and Production: Your Chatbot May Not Be Your Friend in Litigation

By Arnold D. Lee · July 30, 2026 · Originally published on Spencer Fane

Generative artificial intelligence (AI) has quietly become one of the most prolific creators of business records inside modern organizations. Employees draft memos, summarize meetings, analyze data, and brainstorm strategy by typing prompts into chatbots and large language models, and every one of those exchanges leaves a trail. What too few companies appreciate is that the trail is discoverable. As litigation over AI systems and AI-generated content matures, courts have begun treating prompts, outputs, and usage logs as electronically stored information (ESI) subject to the ordinary rules of preservation and production – so far most visibly in cases against AI developers themselves, but on reasoning that has little to do with who owns the model. The comfortable assumption that a private chat with an AI assistant is ephemeral or off the record is turning out to be wrong. For businesses, the message is direct: your chatbot may not be your friend when litigation arrives.

AI Content Is ESI, and the Old Rules Apply

The starting point is unglamorous but decisive. Courts confronting AI-generated material have not created a special exemption for it. They have applied the familiar framework of the Federal Rules of Civil Procedure. Rule 34 reaches any designated documents or electronically stored information – including “other data or data compilations” – stored in any medium from which information can be obtained, and Rule 26(b)(1) makes nonprivileged matter discoverable when it is relevant to a claim or defense and proportional to the needs of the case.1 Nothing in that text turns on whether a record was typed by a person or generated by a model. Novelty is not a shield. When a category of information bears on a party’s claims or defenses, its digital origin in a chatbot rather than an email does not remove it from the reach of discovery.

The most vivid illustration comes from the copyright litigation against OpenAI. In May 2025, a magistrate judge ordered OpenAI to preserve and segregate all output log data that would otherwise be deleted on a going-forward basis.2 That obligation did not prove permanent. On the parties’ stipulation, the court terminated the going-forward preservation requirement as of September 26, 2025, while directing OpenAI to retain the data it had already segregated and to keep preserving logs associated with a list of flagged accounts – and expressly leaving the parties’ independent obligations under Rule 37(e) untouched.3 Production was a separate fight. In November 2025 the magistrate judge ordered OpenAI to produce a sample of roughly 20 million de-identified consumer ChatGPT conversations, and in January 2026 the district judge affirmed, concluding that the reduced sample size, de-identification, and a protective order adequately answered the privacy objections.4 The broader lesson transcends that particular dispute: courts will weigh relevance against privacy and expect de-identification and protective safeguards, not wholesale exemption – and a preservation order entered early is subject to revisiting as the case narrows. If a company’s AI records are relevant, the presence of sensitive or personal content will shape how they are produced, not whether.

A caveat is worth stating plainly, because it is often blurred. The OpenAI orders concern an AI developer’s own logs of its own product, held by a defendant whose business is the model. No published decision yet holds that an ordinary business user’s internal prompts to a third-party chatbot are discoverable ESI. But that is a gap in the case law, not a distinction in the rules, and it is not one a company should plan around. Businesses should assume that when they are a party to litigation, their internal AI usage – the prompts employees typed, the outputs the model returned, and the logs the system generated – can be requested, and can be ordered produced. Treating those materials as invisible is a planning failure waiting to become a sanctions problem.

Preservation and the Spoliation Trap

The most acute risk is not production but preservation. The duty to preserve relevant evidence attaches once litigation is reasonably anticipated, well before a complaint is filed, and it extends to relevant AI-generated ESI.5 The problem is that AI tools frequently are not designed to retain data by default. Many consumer and enterprise chatbot configurations delete conversation history automatically, and some offer ephemeral or temporary sessions that vanish by design. A company that anticipates litigation and does nothing to override those defaults may find that relevant prompts and outputs have been destroyed – the classic setup for a spoliation claim.

Avoiding that trap requires affirmative steps that many legal-hold processes have not yet incorporated. When a hold is triggered, counsel must consider whether relevant employees are using AI tools, whether those tools auto-delete, and whether preservation requires disabling deletion settings or exporting conversation data. This is harder than it sounds, because AI usage is often decentralized and informal – an employee may be using a personal or unsanctioned tool that IT does not control and legal does not know about. The preservation duty does not bend to that reality; if the data is relevant and within the organization’s control, the obligation stands.

What follows from a failure to preserve is more demanding than it is often described. Rule 37(e) is triggered only if three things are true: ESI that should have been preserved in the anticipation or conduct of litigation is lost, the party failed to take reasonable steps to preserve it, and the information “cannot be restored or replaced through additional discovery.” That third predicate is the most common answer to a spoliation motion and the one most often left out of the retelling – if the same prompts and outputs can be pulled from another custodian, a backup, an export, or the other side’s files, the rule never engages. Where all three are satisfied, the court may order measures no greater than necessary to cure the loss, but only “upon finding prejudice to another party from loss of the information.” The severe remedies – a presumption that the lost information was unfavorable, an adverse-inference instruction, dismissal, or default – require a further and separate finding that the party “acted with the intent to deprive another party of the information’s use in the litigation.” That is a demanding standard, and it is not met by showing that a deletion was intentional in the sense of deliberate; routine auto-deletion knowingly left running is not the same thing as deletion aimed at depriving an opponent of evidence.6 AI logs are squarely within that regime.

Privilege Is Not Guaranteed – and Courts Are Split

Companies sometimes assume that an AI exchange conducted by or for counsel is automatically protected. It is not. Courts have begun to divide on whether and when AI prompts and outputs qualify for attorney-client privilege or work-product protection, and the emerging split should temper any confidence.

A central fault line concerns the use of public, third-party AI tools. The leading decision is United States v. Heppner, a criminal securities-fraud prosecution in which the defendant, after retaining counsel, used a consumer AI chatbot to work through his own defense across roughly thirty-one documents. The court held – it did not merely suggest – that those documents were protected by neither the attorney-client privilege nor the work-product doctrine. The privilege did not attach because the chatbot is not an attorney and the exchanges were not confidential; work-product protection did not attach because counsel neither prepared the documents nor directed the defendant to create them.7 The holding is narrower than the headlines suggested, and in a direction that matters: the court did not find that protected material lost its protection by being fed into a public model. It found the material was never protected to begin with. That distinction is the difference between a waiver problem, which careful handling can sometimes cure, and a threshold failure of the privilege elements, which it cannot. Because Heppner is a criminal case turning on one defendant’s unilateral use of a consumer tool, it should be read for that proposition and not as a general rule for civil discovery.

Two civil courts have declined to find waiver where a litigant used a public AI platform. In Warner v. Gilbarco, the court held that a pro se plaintiff’s chatbot prompts and outputs were work product and that using the tool waived nothing, because waiver requires disclosure to an adversary or in a manner likely to reach one, and a generative AI program is a tool rather than a person.8 In Morgan v. V2X, the court likewise treated a pro se litigant’s AI-assisted preparation as work product – but the decision cuts both ways, and the protective half is only half. The court refused to extend protection to the identity of the AI tool the litigant had used, holding he had not shown that naming the product would reveal his mental impressions, and it approved protective-order language barring the parties from uploading confidential material to any AI provider not contractually prohibited from using that data to train its models.9 Both cases involved pro se litigants using AI on their own behalf. Neither addressed corporate or counsel-directed AI use, and neither supplies a safe harbor for an organization. The result is genuine uncertainty. A prompt drafted by a lawyer reflecting litigation strategy may be shielded as work product in one court and exposed in another, and the analysis will turn on the particular tool, the terms under which it operates, and the purpose of the communication.

The practical consequence is that privilege cannot be assumed for AI interactions. Organizations should assume that a chatbot session is presumptively discoverable business information unless it was created under conditions genuinely designed to preserve privilege – counsel involvement, a confidential and controlled platform, and a documented legal purpose. Even then, the protection is contestable, and the safer course is to avoid placing sensitive privileged content into AI tools whose confidentiality posture is uncertain.

The waiver question is closely tied to the terms under which a given tool operates. Enterprise AI deployments frequently include contractual commitments that customer inputs will not be used to train models and will remain confidential; consumer-grade tools often reserve broad rights to retain and use inputs. A court weighing whether confidentiality was preserved may look to exactly those terms, which means the same prompt can carry very different privilege consequences depending on which product an employee happened to open. That reality argues for channeling any AI use that might touch privileged material into vetted, contractually protected enterprise tools, and for treating public chatbots as unsuitable for confidential work. It also argues for documenting the confidentiality posture of approved tools in advance, so that a privilege claim can rest on more than an after-the-fact assertion.

Records Retention Reaches the AI Layer

Beyond preservation and privilege lies a category question that many organizations have not confronted: when does an AI output become a record the business is obliged to keep? Where employees rely on AI outputs to make decisions, or where those outputs support audit, compliance, or client-facing functions, the outputs can take on the character of business records. In regulated industries, the governing rules are generally technology-neutral, which is the point. FINRA, for example, has reminded its member firms that its supervision rule and its rule on communications with the public apply to generative AI just as they apply to any other technology, while expressly stating that the notice creates no new requirements and no new interpretations of existing ones.10 That guidance binds broker-dealers, not businesses at large, and it does not speak to recordkeeping or retention periods. Its premise, however – that existing obligations travel with the work regardless of the tool used to perform it – is not peculiar to securities regulation.

That reframing matters because it shifts AI content from an afterthought to a governed information asset. A financial services firm whose advisers use AI to draft client communications, or a healthcare organization whose staff use AI to summarize records, may find that duties it already has reach the AI layer as well – HIPAA, for instance, requires covered entities and business associates to retain required security-rule documentation for six years, and that obligation does not soften because a model helped produce the underlying work.11 Ignoring those duties creates exposure not only in civil discovery but in regulatory examinations. The organizations best positioned are those that understand how their AI systems create, retain, and delete data, and that align those practices with records-management and legal-hold processes rather than leaving AI usage in an ungoverned shadow.

The records-management lens also reframes a risk that is easy to overlook: over retention. Just as failing to preserve relevant AI data invites spoliation claims, indefinitely retaining every prompt and output builds a growing reservoir of material that can be searched, subpoenaed, and used against the organization in future disputes. A hastily typed prompt reflecting an employee’s candid assumptions, or a model output that the business declined to follow, may read very differently to a jury than it did to the person who generated it. The goal, therefore, is not maximal retention but deliberate retention – keeping what the business genuinely needs and what the law requires, for defined periods, under a policy applied consistently. A defensible retention schedule, followed in the ordinary course, is itself a form of litigation protection.

Practical Guidance for Businesses

The path forward is governance, not avoidance. Organizations should begin by inventorying how AI tools are actually used across the enterprise, including unsanctioned “shadow AI” that employees adopt on their own, because a preservation duty cannot be met for data no one knows exists. From that inventory, companies should set retention policies that make deliberate choices about what AI data is kept, for how long, and where – choices that balance operational value, storage cost, and litigation risk rather than defaulting to whatever the vendor’s settings happen to be.

Legal-hold procedures should be updated to expressly address AI ESI, with a checklist that prompts counsel to identify AI usage, suspend auto-deletion, and capture relevant prompts, outputs, and logs when a hold attaches. ESI protocols negotiated at the outset of litigation should account for AI-generated material, addressing sources, formats, search methodology, and the privacy and privilege safeguards – protective orders, anonymization, and staged production – that courts increasingly expect. Employee training and acceptable-use policies should tell workers plainly that their AI interactions are not private, may be preserved, and may become evidence, and should steer sensitive or privileged material away from tools that cannot protect it.

None of this requires abandoning generative AI, which delivers real value. It requires treating AI-generated content the way the Federal Rules already treat every other category of digital record: as ESI, governed by ordinary rules, carrying ordinary risk. The organizations that internalize that reality now – before a preservation demand or a discovery request forces the issue – will be the ones whose chatbots do not become the most damaging witnesses in their own cases.

This article was written by Arnold D. Lee, an attorney in the Phoenix, Arizona office of Spencer Fane. For more information, visit spencerfane.com.

The views expressed are those of the author alone and do not represent the views of Spencer Fane LLP or its clients. This article is for general informational purposes only and is not legal advice.

  1. Fed. R. Civ. P. 34(a)(1)(A), available at source; Fed. R. Civ. P. 26(b)(1), available at source. ↑
  2. In re OpenAI, Inc. Copyright Infringement Litigation, No. 25-md-3143 (SHS) (OTW) (S.D.N.Y.) (May 13, 2025 preservation order), available at source; consolidated docket available at CourtListener. ↑
  3. Stipulation and Order to Terminate OpenAI’s Ongoing Obligations Under the Preservation Order at ECF 33, The New York Times Co. v. Microsoft Corp., No. 1:23-cv-11195 (SHS) (OTW), ECF No. 922 (S.D.N.Y. Oct. 9, 2025) (terminating the going-forward preservation obligation as of September 26, 2025; requiring continued preservation of previously segregated data and of logs associated with identified domains; and stating that the stipulation “does not purport to waive, modify, or otherwise affect the parties’ obligations under Federal Rule of Civil Procedure 37(e)”), available at source. ↑
  4. Order, In re OpenAI, Inc. Copyright Infringement Litigation, No. 1:23-cv-11195, ECF No. 734 (S.D.N.Y. Nov. 7, 2025) (ordering production of a de-identified sample of consumer ChatGPT conversations), available at source; Opinion and Order of Stein, J. (S.D.N.Y. Jan. 5, 2026) (overruling OpenAI’s Rule 72(a) objections and affirming the production order), available at source. ↑
  5. Fed. R. Civ. P. 37(e) advisory committee’s note to 2015 amendment (explaining that the rule rests on the common-law duty to preserve relevant information when litigation is reasonably foreseeable), available at source. ↑
  6. Fed. R. Civ. P. 37(e) (requiring that the ESI “is lost because a party failed to take reasonable steps to preserve it, and it cannot be restored or replaced through additional discovery”; permitting curative measures under subdivision (e)(1) only “upon finding prejudice to another party from loss of the information”; and permitting the presumption, adverse-inference instruction, dismissal, or default judgment under subdivision (e)(2) “only upon finding that the party acted with the intent to deprive another party of the information’s use in the litigation”), available at source. ↑
  7. United States v. Heppner, 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026) (Rakoff, J.) (criminal prosecution; holding that a defendant’s exchanges with a consumer AI tool were protected by neither the attorney-client privilege nor the work-product doctrine, because the tool is not an attorney, the exchanges were not confidential, and the documents were not prepared by or at the direction of counsel). ↑
  8. Warner v. Gilbarco, Inc., 2026 WL 373043 (E.D. Mich. Feb. 10, 2026) (Patti, M.J.) (pro se plaintiff’s own use of a consumer AI tool; work-product protection applied and was not waived, because waiver requires disclosure to an adversary or in a manner likely to reach an adversary). ↑
  9. Morgan v. V2X, Inc., 2026 WL 864223 (D. Colo. Mar. 30, 2026) (Dominguez Braswell, M.J.) (pro se plaintiff’s own use of an AI tool; declining to extend work-product protection to the identity of the tool and approving protective-order language barring uploads of confidential material to AI providers not contractually restricted from using the data for model training). ↑
  10. FINRA Regulatory Notice 24-09 (June 27, 2024) (reminding member firms that FINRA rules, including Rule 3110 (Supervision) and Rule 2210 (Communications with the Public), continue to apply when firms use generative AI, and stating that the notice “does not create new legal or regulatory requirements or new interpretations of existing requirements”), available at source. The notice addresses supervision and communications; it does not address recordkeeping or retention periods, and FINRA rules apply to member firms rather than to businesses generally. ↑
  11. 45 C.F.R. § 164.316(b)(2)(i) (requiring covered entities and business associates to retain required documentation for six years from the date of its creation or the date when it last was in effect, whichever is later), available at source. ↑