Records, Privilege & AI Regulation

Are AI Prompts and Answers Discoverable Records,
and Do They Waive Privilege?

What disclosure law reaches, where the privilege risk actually sits, which contract clause outranks your architecture, and what a local deployment does not remove.

Built from real buyer questions in our sales meetings

Type a question into an AI tool and you have created a file. Someone may one day be entitled to read it. The claim arrives from four directions at once: a public records request, a subpoena, a privilege argument, and a clause your firm signed years ago. Executives ask us about the technology. Their counsel asks about the file.

Direct Answer

Treat anything typed into an AI tool as a record you may have to produce. In a public body that part is concrete: buyers in government repeatedly described prompts and answers as falling under public records law, and one organization had already been asked to produce transcripts of AI searches. Litigation has the same shape — material put into an AI tool is treated as discoverable.

Privilege is the part no architecture settles. Accounts of courts breaking attorney-client privilege over AI use reach us second-hand, with no case name, no court and no date. Other accounts hold that privilege breaks when material is made public and survives when it stays with a party bound to confidentiality. Buyers act on the risk of waiver rather than a settled rule. Confirm current case law with your own counsel; none of this is legal advice.

Read the contract before the architecture diagram. Buyers described client and partner agreements that restrict putting material into an AI product, some as an outright bar and some permitting dummy data only. Language about exposure and learning can be satisfied by a deployment where content never leaves your control. An absolute prohibition is satisfied only by a renegotiation.

Local execution is a risk control rather than a legal answer. Keeping content inside your boundary removes the argument that you handed material to an outside party, and Iternal builds AirgapAI to run that way. It removes neither the records question nor a subpoena of the device, and it overrides no clause. For more information visit the data-retention page and the regulated data page.

Five Exposures, and What a Local Deployment Removes

“Is it safe to put this into AI?” is five questions wearing one coat. Each has its own trigger and its own fix, and the property that answers one may do nothing for the next. The last row is the one diagrams leave out.

Exposure What it looks like in practice What a local deployment changes
Public records request Data a government body holds is public. Requests arrive asking for the prompts users typed and the answers they got. Who holds the record, never whether one exists. Disclosure law follows the file.
Discovery in litigation Material put into an AI tool is treated as discoverable, and buyers describe it taken out of context. It removes the outside custodian. Your retention and legal-hold rules now govern.
Privilege waiver Legal teams call waiver risk the immediate roadblock to using AI on matter content at all. It removes the disclosure-to-an-outside-party argument, and settles no legal question.
Contractual prohibition Client and partner agreements bar uploading their material to an AI product; some allow dummy data only. It depends entirely on how the clause is written. See below.
Recording and consent Policies restrict what may be recorded at all, and attendees decline a notetaker they never agreed to. Audio and transcript stay on the device. Asking permission stays a human step.
The device itself One buyer put it directly: the local device could still be subpoenaed. The answer in the room — then you would be in court at that point. Nothing. A subpoena reaches your own hardware, and a local file is evidence.

Local execution answers two of those rows well, one partly, and three not at all. Anyone selling it as a blanket legal shield will be corrected by counsel in the first meeting.

Privilege: One Variable, Told From Both Ends

Buyers arrive with two versions of the privilege story, and read together they point at one variable rather than two verdicts. The variable is whether the material reached a party with no obligation to protect it. Privilege survives inside the circle of people bound to keep it: a paralegal under the firm’s supervision preserves it, and a lawyer can retain a private investigator without losing it, because the investigator is supervised and contractually bound to confidentiality. It comes under attack when material passes to someone carrying no such duty, and buyers describe public cloud AI tools as exactly that kind of outside party. The alarming accounts concern content typed into a public cloud tool; the reassuring ones concern content that stayed inside a boundary. Same rule, two ends.

What the record cannot give you is a citation. The rulings reach us through retelling — no case name, no court, no filing date — so we will not assert a holding we cannot cite. Buyers also told us plainly that a cloud AI provider will not spend its resources defending a subpoena and will hand the material to the other side. Four questions turn the anxiety into a decision your counsel can sign:

Pin it down: questions for your evaluation
  • Which court, which case, and what date?
    Whether the ruling your team keeps citing is a holding you can rely on or a summary that has traveled through several retellings.
  • Does our engagement letter or an existing protective order already cover AI-assisted work product?
    Whether this is a new exposure or one your current confidentiality obligations already answer.
  • Where do the prompt, the answer and the chat history physically live, and who can read them?
    Which of your retention, legal-hold and access rules attach to the file the moment it exists.
  • If a subpoena lands, who holds the material and who responds to it?
    Whether an outside party can be served for content you consider yours, and whether they would defend it.

In a Public Body, the Prompt Is the Record

Government buyers described this exposure in almost identical language across separate organizations, and that consistency is why it is the part to plan around. Logs and data entries a government holds are public and subject to records requests, and requests already demand the prompts users typed and the answers they received. One organization had been asked to produce transcripts of AI searches before it finished evaluating the tool. The chilling effect is the operational cost: staff will not test a chatbot until they know what is being collected, and a pilot nobody uses produces no evidence to defend.

Account for what that does to the business case. On public records work the privacy argument stops carrying the pitch. If the file is disclosable wherever it sits, the value of running AI inside your boundary is staff hours saved and control of the file, rather than secrecy.

Local does not mean unrecorded. Anything a user types into AirgapAI is saved to a local database and stays in the chat history until that user deletes it, with user data and query history in the standard user-profile folders. To an auditor that is a feature; to a records officer it is a disclosable file in a known location. Both belong in your retention policy before the first request arrives.

The Clause That Outranks the Architecture

The blocker that stops the most pilots sits in a document nobody in the evaluation has read recently. Buyers described master service agreements with partners that forbid uploading anything to an AI product that could be exposed or learned from. Others are narrower and more workable: real customer data cannot be shared and only dummy data may be used; the underlying model may be used while the tool wrapped around it may not touch case data.

Sort the clauses into two piles before you evaluate anything. Language about exposure and learning describes a risk a deployment inside your own control genuinely addresses. An absolute bar on any AI product describes a permission you do not have, and no architecture converts a no into a yes. Sorting takes an afternoon and saves a quarter. For more information visit the contract portfolio page.

The Line Your Staff Will Not Cross

Buyers draw one red line harder than any other, and honoring it decides whether the deployment gets used at all. A tool that watches, scores or profiles people will not be tolerated. Staff who fear their questions are being watched stop asking what they actually want to know. A dashboard a leader uses to micromanage a team drives no usage. Analyzing an individual’s background feels invasive to the person analyzed.

Decide what you audit before you switch anything on. In AirgapAI, auditing stays local to the device, and nothing prevents an administrator pulling those logs off the devices; query history can be centralized so an administrator can review it. Application logs and user chat history are two separate things in the product, and treating them as one is how a legitimate audit becomes surveillance in the eyes of your workforce. On a paid license telemetry collection is off by default, so Iternal does not see who uses the software or how much unless a customer opts in and streams it. Publish which file you keep, who may read it and what would trigger someone looking. For more information visit the administration controls page.

AI Regulation: What Buyers Track, and What Counts as a Citable Ruling

Cite the case, the court and the date, or assert nothing. Second-hand rulings travel fast in evaluation meetings and lose their citation on the way. Hold every AI supplier, Iternal included, to that standard.

What buyers actively track, in their own words, is shorter than the rumor mill suggests. They ask what the Texas Responsible AI Governance Act requires of them, and note that Texas has new law around data sovereignty and compliance. They ask whether a court has decided that using a public model breaks a non-disclosure agreement on the theory that the model counts as a third party. They watch the EU AI literacy requirement, which binds no United States organization and signals where rules travel next.

The durable instrument is an inventory rather than an opinion. Teams that handle this well run a standing AI risk assessment: what AI is already in the building, what unsanctioned use exists, how data flows through each tool, a risk register and heat map, and alignment to a recognized AI risk framework. That artifact survives a change in the law; a memorandum about one ruling does not. Confirm current case law and statute with your own counsel. None of this is legal advice.

Answered elsewhere
FAQ

FAQ: Records, Privilege and AI Regulation

Plan on it. Buyers treat material put into an AI tool as discoverable and describe it being pulled back out and used against the person who typed it. A prompt and its answer are a file, and a file is evidence. Where the tool runs changes who holds the file and who answers a subpoena; it makes nothing disappear. None of this is legal advice.

Legal teams treat it as a live waiver risk rather than a settled rule. The accounts that reach us describe courts breaking privilege over AI use, but they carry no case name, court or date, so we will not state them as law. The variable everyone points at is whether the material reached a party with no duty to protect it: a paralegal under supervision preserves privilege, and so does an investigator bound by contract to confidentiality. Keeping content inside your boundary removes that argument at its root.

Government buyers described exactly that. Data a government holds is public, requests arrive demanding the prompts users typed and the answers they received, and one organization had already been asked to produce transcripts of AI searches. Staff will not even test a chatbot until they know what is being collected. A local deployment changes who holds the record, never whether disclosure law reaches it.

Yes, and a buyer raised precisely that point with us. The answer in the room was blunt: then you would be in court at that point. A local deployment removes the outside custodian and hands you the file — a gain in control and an obligation for retention. Anything typed into AirgapAI is saved to a local database and stays in the chat history until the user deletes it.

It depends on how the clause is written, and reading it is the first task. Agreements that forbid uploading anything which could be exposed or learned from speak to a risk a deployment inside your control genuinely addresses. Others are absolute, permit dummy data only, or allow the model while barring the tool wrapped around it. An absolute prohibition is answered by a renegotiation and nothing else.

Treat agreement as mandatory, because buyers object loudly when it is skipped: attendees do not want an AI meeting assistant present without permission, and policies often restrict what may be recorded at all. AirgapAI Transcribe is a completely local meeting note taker, so the recording and its data never leave the device, and the recording announcement can be customized to your legal requirements. Two limits stay — the recording can be legally subpoenaed, and an uncertified transcript needs certification through a court reporter.

Start With the Inventory, Then the Architecture

Every organization we work with reaches the same sequence. Find out what AI is already in the building, read the clauses that govern the material, decide what you audit, and only then choose where the software runs. Iternal runs that assessment as a standing exercise rather than a one-off memo, because statutes move and the inventory stays true.

John Byron Hanby IV
About the Author

John Byron Hanby IV

CEO & Founder, Iternal Technologies

John Byron Hanby IV is the founder and CEO of Iternal Technologies, a leading AI platform and consulting firm. He is the author of The AI Strategy Blueprint and The AI Partner Blueprint, the definitive playbooks for enterprise AI transformation and channel go-to-market. He advises Fortune 500 executives, federal agencies, and the world's largest systems integrators on AI strategy, governance, and deployment.