SELINA.ai
Sign in

Yes, Chatbot Logs Can Be Subpoenaed. Here's What That Means for Your Company.

Most executives treat their chatbot conversations the way they treat napkin math: useful in the moment, disposable afterward. That assumption is now demonstrably wrong. The question of whether chatbot logs can be subpoenaed has been answered repeatedly by federal and state courts over the past eighteen months, and the answer is yes. Not theoretically. Not in some edge case. In live disputes over earnout payments, copyright claims, expert testimony, and criminal liability. If your organization uses AI chat tools and has not updated its discovery protocols, you are carrying risk you probably haven't sized.

Key Takeaways

What Happened in the Cases That Changed This?

Several rulings between late 2025 and mid-2026 moved chatbot discoverability from theoretical risk to established precedent. They are worth knowing in some detail because the patterns repeat.

A $250 Million Earnout Hinged on a CEO's Chat Prompts

In Fortis Advisors v. Krafton, a Delaware Court of Chancery case, the dispute centered on whether former stockholders of an acquired video game studio were owed a quarter-billion-dollar earnout. The acquiring company's CEO had used an AI chatbot to brainstorm strategy, including forming a task force and building what the transcripts described as an "implementation roadmap." The court found that the CEO's subsequent actions closely mirrored the chatbot's suggestions and used the transcripts as evidence that the CEO's stated rationale was pretext. The chatbot wasn't a witness. It was a paper trail the CEO created voluntarily, one prompt at a time.

No Privilege Just Because You Forwarded It to Your Lawyer

In United States v. Heppner (S.D.N.Y., February 2026), a defendant in a federal criminal case argued that his AI chatbot conversations were protected by attorney-client privilege because he had forwarded the transcripts to his attorney. The court rejected that argument on three grounds: the AI itself was not legal counsel, the platform was not a confidential communication channel, and the defendant had not been directed by counsel to use it. The transcript was admitted.

The copyright litigation between the New York Times and a major AI provider produced what is probably the most consequential discovery order in AI history. A federal magistrate judge issued a broad preservation order in May 2025 requiring the provider to retain all output log data. When the provider objected, a federal judge upheld the order and ultimately required the turnover of 20 million anonymized chat logs. The forward-looking preservation obligation was later narrowed, but the logs already retained under the original order remain in the litigation record.

Think about what that means for individual users. People who had clicked "delete" or used temporary chat modes had no guarantee those choices would be honored. The Center for Democracy and Technology flagged that private conversations about health, business strategy, and personal matters could be stockpiled for a lawsuit the users were not even party to.

Does Any Privilege Protect AI Chat Content?

Not reliably, and the boundaries are actively shifting. There is no AI-specific privilege analogous to attorney-client or doctor-patient privilege. Courts treat chatbot output like ordinary business records: discoverable unless some other doctrine applies.

There is one narrow exception emerging. In an employment case, a plaintiff argued that her AI queries reflected her attorney's mental impressions, and the court agreed the material was protected under the work-product doctrine. But that protection required showing the queries were made at counsel's direction, for litigation purposes, and embodied legal strategy. The standard consumer or executive use case (brainstorming strategy, drafting communications, exploring options) does not meet that bar.

The split is real. Courts are actively disagreeing on where the line sits, which means the outcome depends heavily on jurisdiction, on how the chatbot was used, and on whether counsel was involved before the conversation happened rather than after. If you are forwarding chat transcripts to your lawyer after the fact and hoping that creates privilege, Heppner says it does not.

Can Courts Compel Disclosure of the Prompts Themselves, Not Just the Output?

Yes. A Connecticut federal court in Conservation Law Foundation v. Shell ordered disclosure of the AI prompts an expert witness used to prepare her report, not just the final work product. That decision is currently under challenge, but it signals that prompt-level discovery is now in play. This matters because prompts often reveal reasoning, intent, and framing that the polished output conceals. A prompt like "draft a memo justifying the termination of [employee name] in a way that avoids age discrimination claims" is considerably more damaging than the memo itself.

What About AI Meeting Notetakers and Transcription Tools?

Same exposure, different wrapper. The American Bar Association has issued guidance warning that cloud-based AI note-taking tools grant third-party access to confidential communications. Using one in a meeting with your attorney can inadvertently destroy privilege by introducing a non-privileged third party into what was supposed to be a confidential exchange. The transcript then becomes discoverable, and the privilege waiver can extend to the entire conversation, not just the portions the AI captured.

A UK case added another layer. A law firm's AI-generated correspondence contained a fabricated statutory citation. When the court investigated, the firm's own chat transcripts were produced, revealing that the chatbot had invented the statute but had actually warned the lawyer to verify it against the real text. The transcript proved the lawyer had been warned and had ignored the warning. The tool's own logs became evidence of the firm's negligence.

Why Is "Shadow AI" the Largest Unmanaged Risk?

Because you cannot preserve evidence for AI usage no one in your organization knows exists. Legal advisors are now telling companies to inventory how AI tools are actually used across the enterprise, including unsanctioned "shadow AI" on personal devices and personal accounts. The Heppner case involved a defendant's personal-device chatbot usage. The Krafton case involved a CEO's own sessions. Neither was a sanctioned enterprise deployment with managed retention policies.

Your corporate chatbot, the one you procured and configured, is probably the easier problem. You can set retention policies, issue legal holds, and manage access. The harder problem is the employee who opens a personal AI chat on their phone during a meeting, types in confidential deal terms or HR deliberations, and generates a transcript that now lives on a third-party server with its own retention policies and its own exposure to preservation orders in lawsuits your company is not party to.

You cannot issue a litigation hold on a service you do not control. You cannot produce documents you do not know exist. And when opposing counsel asks whether your organization has searched for AI-generated communications, "we didn't know our people were using it" is not a defense. It is a sanctions risk.

How Do Preservation Orders Actually Work Against Chat Logs?

A preservation order, in the context of AI chat logs, works the same way it works for email or documents. Once litigation is reasonably anticipated, you have a duty to preserve potentially relevant evidence. A court can issue an order requiring a specific party (including the AI provider) to retain data that might otherwise be deleted.

The problem specific to AI chat is the gap between user expectation and platform architecture. Users who click "delete" or select ephemeral/temporary modes reasonably believe the data is gone. But a preservation order issued to the platform provider overrides those settings. The provider retains the data pursuant to the court order, regardless of the user's preferences. The user may never be notified.

In the New York Times litigation, this dynamic played out at scale. The preservation order applied broadly and, by some accounts, retroactively. Conversations users believed they had deleted were retained. The later narrowing of the order did not undo what had already been preserved.

This is the core architectural problem. A policy-level promise ("we delete your data when you ask") can be overridden by a single judicial order. The promise was never a guarantee. It was a description of default behavior, subject to legal process.

What Should Your Organization Actually Do About This?

The practical steps are not complicated. They are just not happening at most companies yet.

If your litigation hold template does not explicitly mention AI prompts, AI outputs, AI-generated meeting notes, and chatbot transcripts, it is incomplete. This is not speculative. Spencer Fane and other firms are advising clients to update hold procedures now. The checklist should cover both sanctioned and unsanctioned AI tools, and the hold notification should instruct custodians to preserve personal AI chat history related to company business.

Inventory Your AI Usage

You need to know which AI tools are in use across the organization, who is using them, what data flows into them, and what retention policies apply. This includes personal accounts. You will not get perfect visibility, but you need a defensible process for trying. The alternative is standing in front of a judge and explaining that you never looked.

Treat AI Chat Transcripts as Business Records

If an employee uses a chatbot to draft a memo, explore a business decision, prepare for a negotiation, or summarize a meeting, the transcript is a business record. Treat it with the same retention, classification, and discovery protocols you apply to email. The courts already do.

Negotiate Your Enterprise AI Contracts with Discovery in Mind

If you are procuring AI services at the enterprise level, your contract should address data retention, litigation hold procedures, data segregation, and the provider's obligations in response to third-party subpoenas. The New York Times litigation showed that consumer-tier users had essentially no control. Enterprise contracts can create contractual obligations around retention and deletion that are harder (though not impossible) for courts to override. Segregated data stores, clear B2B terms around retention, and explicit deletion protocols are not luxuries. They are the baseline.

Educate Executives Specifically

The Krafton case involved a CEO. The Heppner case involved a defendant on a personal device. Executives are the highest-risk users because they handle the most sensitive information, they are the most likely to be named in litigation, and their communications carry outsized evidentiary weight. A five-minute briefing from counsel on the discoverability of AI chats is probably the highest-ROI risk mitigation available right now.

Does Architecture Actually Solve This, or Just Shift the Problem?

Architecture does not make you immune to subpoenas. Nothing does. But architecture determines what exists to be subpoenaed.

If your AI provider retains full conversation logs on its servers, those logs exist and can be ordered produced. If your provider operates on a short retention window for operational metadata and encrypts content at rest, the surface area is smaller. If file transfers are zero-knowledge encrypted, the provider literally cannot produce plaintext even under compulsion.

This is the difference between a policy promise and a structural guarantee. A policy says "we will delete." A structure says "we cannot read." Courts can override policies. They cannot override mathematics.

We built Selina with this distinction in mind. Memory is encrypted at rest (not end-to-end encrypted, because a slice of each request reaches a frontier provider at inference). Files and transfers via SelinaSEND are zero-knowledge encrypted. Operational metadata is kept for a short retention window. The design goal is straightforward: minimize what exists, encrypt what must exist, and make deletion real.

None of this makes chatbot conversations undiscoverable in all circumstances. If a court orders you to produce your own copies of conversations, you still must comply. But the architecture determines whether a third party can produce your conversations without your knowledge, whether "delete" means gone or means hidden, and whether the provider itself has the technical ability to comply with a broad preservation order against your data.

What Is the Regulatory Direction?

Multiple states passed chatbot-related legislation in 2026. Iowa's SF 2417 requires conversational AI services to disclose to users that they are interacting with AI rather than a human. Georgia's SB 540 and California's SB 243 add further compliance requirements. These laws focus primarily on disclosure and companion-bot safety rather than discovery, but they add another layer of regulatory exposure. An organization that fails to disclose AI usage in customer interactions may find that nondisclosure itself becomes a litigation issue, with the undisclosed chatbot's logs subpoenaed as evidence of the violation.

The trajectory is clear. More regulation, more litigation, more discovery. The window for treating chatbot conversations as disposable small talk is closed.

The Uncomfortable Bottom Line

Every prompt you type into an AI chatbot is potentially a business record. Every response is potentially evidence. The chatbot is not your confidant. It is not your lawyer. It is not a sealed room where you can think out loud without consequence. It is a third-party service that stores your text on servers you do not control, subject to retention policies you probably have not read, vulnerable to preservation orders in lawsuits you may never hear about.

The executives and counsel who adjust to this reality now will have defensible processes when discovery hits. The ones who keep treating chatbot conversations as ephemeral will learn the hard way that nothing typed into a cloud service is truly disposable.

If you want an AI assistant where content is encrypted at rest, file transfers are zero-knowledge, and deletion is structural rather than aspirational: start a free 7-day trial, no card required.

Frequently Asked Questions

Can chatbot conversations actually be subpoenaed in legal disputes?

Yes. Courts have treated chatbot transcripts as ordinary electronically stored information (ESI), subject to the same discovery rules as email or Slack messages, and multiple federal and state cases over the past eighteen months have compelled their production.

Does forwarding a chatbot transcript to my attorney make it privileged?

No. In United States v. Heppner, the court rejected that argument because the AI was not legal counsel, the platform wasn't a confidential channel, and the defendant hadn't been directed by counsel to use it, so the transcript was admitted.

If I delete a chat or use a temporary/ephemeral mode, is that conversation really gone?

Not necessarily. A preservation order issued to an AI provider can override user deletion settings, as shown when a court forced retention of 20 million chat logs, including conversations users believed they had erased.

Can courts get access to the prompts I typed, not just the AI's response?

Yes, prompt-level discovery is now possible. In Conservation Law Foundation v. Shell, a Connecticut federal court ordered disclosure of an expert witness's actual prompts, not just the final report, though that ruling is currently under challenge.

What is 'shadow AI' and why is it considered a major risk?

Shadow AI refers to employees using personal AI accounts to discuss work matters outside company control, meaning the organization cannot issue litigation holds or manage retention on services it doesn't know exist, which creates significant sanctions risk in discovery.

Sources & References

Michael C.

Michael C.

Founder & Principal Engineer, Selina Labs

Michael builds Selina, a privacy-first AI that remembers you across conversations. He ships security-sensitive AI in production — real attacks, real fixes, measured in minutes and dollars — and writes about privacy, security, and LLMs from that seat. Top Rated Plus and expert-verified on Upwork.

Learn more about Selina.ai