Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

New Frontiers in Spoliation: Preserving AI Records in Litigation

By Garen S. Marshall, Ashley B. Matthews, Davis M. Walsh, Alice Moscicki & Louis O.C. Rogers on August 7, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

The explosion of generative AI in the workplace has created a new and largely unaddressed category of litigation risk. In May 2025, a federal court in the Southern District of New York ordered OpenAI to preserve and segregate all ChatGPT output log data that would otherwise be destroyed under its default 30-day deletion policy, marking one of the first judicial orders to treat AI-generated content as electronically stored information subject to legal holds (i.e., the obligation to preserve potentially relevant evidence once litigation is reasonably anticipated). The order, issued over OpenAI’s objections grounded in user privacy and regulatory compliance, signals that courts will expect litigants to preserve AI artifacts with the same rigor applied to email, documents, and structured data.

Read on for an analysis of how existing discovery rules already reach AI-generated content, the sanctions companies may face for failing to preserve it, and the practical steps clients should take now to close the gap.

I. Why Generative AI Has Outpaced Existing Retention Policies

The rapid adoption of generative AI tools across the enterprise has exposed fundamental gaps in corporate information governance. Most retention policies define “records” by reference to a specific system or format—email servers, shared network drives, structured databases—rather than by the function the underlying information performs. This definitional approach leaves AI-generated content in a regulatory blind spot. Critically, however, whether AI-generated content qualifies as a formal “record” under a company’s retention schedule is largely beside the point once litigation is reasonably anticipated: a legal hold requires preservation of all potentially relevant information, regardless of its designation in the retention schedule.

Many AI platforms apply rolling default deletion schedules that destroy data within 30 days of creation. OpenAI, for example, automatically deletes ChatGPT conversations and API inputs and outputs from its systems within 30 days of a user’s deletion request or, in some configurations, as a matter of default retention practice. As a result, content can be permanently destroyed before a company appropriately issues and applies a legal hold. That potential problem is compounded by the fact that AI outputs are frequently generated outside corporate systems entirely, through public chatbots, browser-based tools, or personal accounts, often in violation of company policy. This creates visibility gaps that traditional IT-driven retention schedules may not be designed to address yet.

II. The Scope of Discoverable “Documents” May Already Reach AI Artifacts

Federal Rule of Civil Procedure 34(a)(1)(A) defines discoverable material to include “any designated documents or electronically stored information (“ESI”)—including writings, drawings, graphs, charts, photographs, sound recordings, images, and other data or data compilations—stored in any medium from which information can be obtained.” Fed. R. Civ. P. 34(a)(1)(A). And, increasingly, litigants are relying on this Rule to seek discovery of opposing parties’ AI prompts, model outputs, conversation logs, and related data compilations.

Recent litigation confirms that at least one court has treated AI-generated content as discoverable ESI subject to preservation obligations. In the consolidated copyright litigation against OpenAI, a United States Magistrate Judge for the Southern District of New York ordered OpenAI to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis until further order of the Court.” The court’s order encompassed data “whether such data might be deleted at a user’s request or because of ‘numerous privacy laws and regulations’ that might require OpenAI to do so.” See In re: OpenAI, Inc., No. 25-md-3143 (SHS) (OTW), 2025 WL 1442678, at *1 (S.D.N.Y. May 13, 2025). The order arose after the court learned that OpenAI had been deleting output log data, which was reportedly consistent with its standard retention practices, and that “the volume of deleted conversations is significant.” Notably, the output log data at issue was directly relevant to the plaintiffs’ claims regarding how ChatGPT processes and generates content. In addition, the court’s willingness to order preservation even where the deletions appeared to follow OpenAI’s existing retention policy underscores that routine data management practices do not excuse a failure to preserve once a legal hold obligation has attached.

Rule 34 requires production of ESI within a party’s “possession, custody, or control,” without a stated exception for AI-generated or AI-processed data. Fed. R. Civ. P. 34(a)(1). Given the relatively recent advent of generative AI, it is not surprising that no provision of the Federal Rules distinguishes between data generated by human authors and data generated through interaction with an AI system. A party’s obligation to preserve and produce relevant ESI may extend to AI artifacts just as it does to any other ESI.

That said, courts might apply Rule 34 differently to companies that simply use or license AI tools for use in day-to-day work, as opposed to the OpenAI MDL, where the defendant developed, created, and owned the specific AI tool at issue. Most companies that simply license or use AI tools without substantial modification to those tools may be viewed as more distant from the necessary “possession, custody, or control” of data within an AI tool. In those more common scenarios, the OpenAI MDL may be ripe for Rule 34 distinction.

III. Sanctions Exposure Under Rule 37(e)

The failure to preserve AI-generated content that is (or should be) subject to a legal hold could expose litigants to sanctions under Federal Rule of Civil Procedure 37(e), which governs the loss of electronically stored information that should have been preserved in the anticipation or conduct of litigation. Rule 37(e)(1) authorizes a court to order curative measures “no greater than necessary to cure the prejudice” upon a finding that ESI “that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it” and “cannot be restored or replaced through additional discovery.” Fed. R. Civ. P. 37(e)(1).

Though courts do not appear to have yet grappled with what steps are reasonable in the AI world, some have warned against treating some inherently more temporary ESI differently than electronic records for preservation purposes.  Where the court additionally finds that a party “acted with the intent to deprive another party of the information’s use in the litigation,” Rule 37(e)(2) permits more severe sanctions, including an adverse inference instruction, dismissal of claims, or entry of default judgment. Fed. R. Civ. P. 37(e)(2).

Spoliation encompasses not only the active destruction of evidence but also the negligent or reckless failure to preserve information once a duty to preserve has been triggered. The duty to preserve arises when a party knows or reasonably should know that litigation is on the horizon. That duty may be triggered, for example, on receipt of a claim letter, demand, or even a cease and desist letter in certain contexts. Given the default deletion schedules employed by AI platforms, where data may be permanently destroyed within 30 days, the window between trigger of the preservation obligation and irreversible data loss is dangerously narrow. Companies that fail to intervene promptly to halt automatic deletion of AI-generated content risk a finding that they did not take “reasonable steps to preserve” that information within the meaning of Rule 37(e). When, precisely, a duty attaches and whether ensuing steps are reasonable are entirely context-driven and difficult to boil down to a pinpoint rule. By way of example, however, if a company has been notified that it is being sued for price fixing and its employees use an AI tool to develop algorithms for price modeling, it may be wise to preserve that tool’s ESI.

IV. Third-Party AI Vendors: Distinguishing What Is Actually in the Company’s Control

The “possession, custody, or control” standard of Rule 34(a)(1) extends discovery obligations beyond documents a party physically holds to include documents the party has the legal right or practical ability to obtain. Fed. R. Civ. P. 34(a)(1). This principle has direct application to AI-generated data held by, or generated and created on behalf of a company by, third-party vendors.

If a company maintains a contractual right to access, export, or retrieve its usage data from an AI vendor, that may be within the company’s “control” for purposes of its discovery obligations. The In re: OpenAI litigation illustrates the practical complexity of this issue. OpenAI represented to the court that “a fraction of ChatGPT Free, Pro, and Plus conversations … have not been retained” as a result of its “default” policy of retention. OpenAI responded by citing user privacy preferences and “numerous privacy laws and regulations throughout the country and the world” as justification for its deletion policies. Nonetheless, the court ordered preservation, signaling that a vendor’s internal deletion practices may not relieve the parties of their obligations to hold responsive data whenthat preservation duty arises in response to actual or likely litigation.

To be sure, In re: OpenAI’s lesson came in the context of a suit against the creator of ChatGPT, not a company that merely licenses it. But its lesson may well extend to the latter context. Data that resides on a vendor’s server does not fall outside the scope of a company’s preservation obligations. Where contractual terms permit data retrieval, export, or extended retention, or where a company has the practical ability to request that a vendor suspend its default deletion schedule, a court may well conclude that the data is within the company’s control. OpenAI itself acknowledged that enterprise customers and customers who choose “zero-data-retention” plans operate under different data handling frameworks where the customer controls retention. This distinction further underscores that the allocation of control is a fact-specific inquiry that turns on the contractual and operational relationship between the company and its AI vendor.

V. Practical Takeaways

In light of the developments described above, clients may consider certain steps to align information governance practices with their company’s AI usage in this ever-evolving landscape.

First, legal hold notices and company policies, including litigation hold policies, records retention policies, and records retention schedules, should be updated to establish retention standards for AI prompts, outputs, chat logs, and associated metadata. Standard hold notices that reference only email, documents, and traditional databases may fail to capture AI-generated content. Given that AI platforms such as ChatGPT automatically delete data within 30 days absent affirmative intervention, hold procedures must be designed to operate within that compressed timeline.

Second, companies should establish a comprehensive AI acceptable use policy governing employee interactions with AI tools. This policy, which may be standalone or integrated into an existing employee handbook, should specify which AI platforms are approved for business use, define the types of information that may and may not be input into AI systems, and make clear that use of unsanctioned AI tools with company data may constitute a data breach. By establishing clear guardrails, companies create an enforceable framework that supports both information security and downstream preservation obligations.

Third, companies should conduct an assessment of all AI tools in use across the organization. This assessment should catalog approved enterprise AI deployments and, to the extent possible, identify unsanctioned consumer-tier use by individual employees. Even data generated through free consumer accounts may be subject to preservation and discovery obligations, so understanding which AI tools are in use is a critical first step.

Fourth, companies should review their contractual relationships with AI vendors to determine whether they possess the legal right to retrieve, export, or direct the preservation of their usage data. Where such rights exist, the company’s preservation obligation likely extends to that vendor-held data under the “possession, custody, or control” standard of Rule 34(a)(1). Companies may also consider the inclusion of their standard data retention policies in contracts with AI vendors so as to ensure company-wide consistency in preservation. Even beyond AI-specific vendors, companies should review their broader vendor agreements to ensure appropriate protections are in place, including provisions prohibiting vendors and their personnel from inputting company data into unapproved AI platforms, which could constitute a data breach and create additional preservation complications.

Finally, companies should provide employees with AI training, which may include specific guidance regarding how AI work product may fall within the scope of a legal hold. Employees should understand that conversations with AI chatbots, prompts submitted to AI assistants, and outputs generated by those systems may constitute discoverable ESI that must be preserved when a hold is in effect.

Courts have demonstrated a willingness to order preservation of AI output data even over objections grounded in privacy law, platform design, and practical burden. Companies that fail to adapt their preservation practices to the realities of generative AI risk possible sanctions, from adverse inferences, to the loss of otherwise meritorious claims or defenses.

VI. Conclusion

In light of these developments, companies may consider: (1) reviewing existing retention policies and legal hold procedures to analyze whether they adequately account for AI-generated content; (2) establishing a comprehensive AI acceptable use policy governing employee interactions with AI tools; (3) conducting an assessment of AI tools in use across the organization to identify preservation risks; (4) evaluating contractual rights to retrieve or preserve data held by third-party vendors; and (5) providing employees with targeted training on how AI-generated work product may fall within the scope of a legal hold.

McGuireWoods’ AI Practice Group is available to assist clients with any questions regarding preservation obligations for AI-generated data, updates to records retention and legal hold procedures, or vendor contract review.



The authors thank McGuireWoods summer associate Destiny Washington for assistance preparing this article. She is not licensed to practice law.

Tags: AI
Photo of Garen S. Marshall Garen S. Marshall

Garen Marshall is a partner in McGuireWoods’ Government Investigations and White Collar Litigation Department and leads the firm’s Artificial Intelligence Practice Area. A former Assistant United States Attorney in the Eastern District of New York and Navy special operations veteran, he represents corporations…

Garen Marshall is a partner in McGuireWoods’ Government Investigations and White Collar Litigation Department and leads the firm’s Artificial Intelligence Practice Area. A former Assistant United States Attorney in the Eastern District of New York and Navy special operations veteran, he represents corporations, executives, and boards in government and internal investigations, regulatory enforcement matters, and complex civil litigation, with a practice that extends to AI governance, AI-related enforcement and litigation risk, and corporate compliance issues involving artificial intelligence.

Read more about Garen S. MarshallEmail
Show more Show less
Photo of Ashley B. Matthews Ashley B. Matthews

Ashley advises retailers and financial institutions with respect to consumer financial services, privacy and security, and governance matters.

Read more about Ashley B. MatthewsEmail
Photo of Davis M. Walsh Davis M. Walsh

Davis M. Walsh is a trial lawyer who focuses on high-stakes litigation for public and private companies, along with advising clients on the legal and litigation risks surrounding the adoption of artificial intelligence. Davis is known for taking on cases that are critical…

Davis M. Walsh is a trial lawyer who focuses on high-stakes litigation for public and private companies, along with advising clients on the legal and litigation risks surrounding the adoption of artificial intelligence. Davis is known for taking on cases that are critical to clients — from bet-the-company product liability trials to complex mass tort litigation — and for bringing the kind of creative, jury-focused strategy that wins them.

Read more about Davis M. WalshEmail
Show more Show less
Photo of Alice Moscicki Alice Moscicki

Alice is an associate in the firm’s Labor & Employment Department. She is experienced with counselling clients on compliance with a variety of local, state, and federal employment laws, with a focus on reputational risk management. Alice is heavily involved with McGuireWoods’ emerging…

Alice is an associate in the firm’s Labor & Employment Department. She is experienced with counselling clients on compliance with a variety of local, state, and federal employment laws, with a focus on reputational risk management. Alice is heavily involved with McGuireWoods’ emerging, cross-functional artificial intelligence practice.

Read more about Alice MoscickiEmail
Show more Show less
Photo of Louis O.C. Rogers Louis O.C. Rogers

Louis focuses his practice on representing publicly traded and private companies in the energy, transportation, construction, and manufacturing sectors facing complex environmental and mass-tort litigation—particularly cases arising from catastrophic incidents—in both federal and state courts.

Read more about Louis O.C. RogersEmail
  • Posted in:
    E-Discovery, Privacy and Cybersecurity, Technology and AI
  • Blog:
    Subject to Inquiry
  • Organization:
    McGuireWoods LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo