SELINA.ai
Sign in

Are ChatGPT Logs Discoverable in Court? What the Delaware Chancery AI Ruling Means for Enterprise Users

A CEO used a consumer chatbot to plan how to dodge a $250 million earnout payment. The court found the logs, read them, and used them as evidence of bad faith. If you have been wondering whether are chatgpt logs discoverable in court, the answer from Delaware Chancery is now unambiguous: yes. And the implications run deeper than most founders realize, because the informal scratch space you treat as ephemeral is, legally, a corporate record.

Key Takeaways

What happened in Fortis Advisors v. Krafton?

Krafton, the South Korean gaming conglomerate, acquired Unknown Worlds Entertainment (the studio behind Subnautica) for $500 million plus up to $250 million in contingent earnout payments tied to post-closing performance. When the earnout appeared likely to trigger, Krafton's CEO turned to a consumer AI chatbot for advice on how to avoid the payout.

The chatbot told him the earnout would be "difficult to cancel." So he asked for a path forward. The bot suggested forming an internal task force to either negotiate the earnout away or execute a "takeover" of the studio. It even generated a formal response strategy for a no-deal scenario.

Discovery revealed that Krafton subsequently followed most of the chatbot's recommendations in the months that followed. Vice Chancellor Lori W. Will found breach, ordered the ousted CEO restored with operational control, extended the earnout period by 258 days, and left money damages still to be determined.

Why did the court treat chatbot logs as evidence of intent?

Because they are exactly that. The court cited the CEO's extensive AI chat history as evidence of bad faith, treating the transcripts the way it would treat internal emails or strategy memos. The logic is straightforward: if you type your plan into a text box, and that text is stored on a server you do not control, it is a document. Documents are discoverable.

A separate Reuters report on the case framed the takeaway bluntly: a CEO's chatbot conversations became important evidence of corporate strategy and intent. The medium does not create privilege. The content determines relevance.

There is an additional dimension that makes chatbot logs more dangerous than email. People type more candidly to a bot than to a colleague. No one cc's legal on a prompt. No one pauses to consider whether the phrasing looks bad in deposition. The informality is precisely what makes the evidence so damaging.

Is this ruling an outlier, or part of a pattern?

It is part of a pattern. Four legal decisions across roughly three months in 2026 addressed AI tools and privilege, signaling that courts are rapidly developing doctrine in this space.

In United States v. Heppner (S.D.N.Y., February 2026), the court held that a defendant's use of a consumer AI chatbot did not qualify for attorney-client privilege or work-product protection. Separate rulings in Warner v. Gilbarco (E.D. Mich.) and Morgan v. V2X (D. Colo.) offered slightly more protection in limited contexts, particularly for self-represented litigants. But the direction is clear: consumer-tier chatbot conversations carry minimal privilege protection.

Meanwhile, a January 2026 order in the OpenAI copyright litigation required production of a reduced, de-identified sample of 20 million chat logs. The court used de-identification and a protective order to balance user privacy with discovery needs. The scale of that order is worth sitting with. Twenty million conversations, compelled by a single ruling.

Does an enterprise agreement change anything?

It can. The same OpenAI copyright case explicitly carved out enterprise and contractual arrangements with shorter retention windows from the preservation order. That distinction matters. If your provider retains your prompts and outputs on their servers under default consumer terms, those logs exist and can be compelled. If you have negotiated a contract with meaningfully shorter data retention, the data may not exist to be produced.

The operative word is "may." Retention policy is not a privilege claim. It is a factual question about whether the data still exists at the time of the subpoena. Architecture and contracts determine that, not assumptions.

What does this mean for litigation holds?

Your next litigation hold should cover AI chat logs. That is not my opinion; it is the argument made by litigation counsel writing in Law360 in May 2026. The duty to preserve AI chat logs and prompts begins when a party reasonably anticipates litigation, not when a complaint is filed.

Think about what that means operationally. If your GC sends a litigation hold notice to the company, that notice now needs to cover every AI tool where employees might have discussed the matter. Which tools? You probably do not know. Because your employees are pasting sensitive information into consumer chatbots you have not sanctioned, tracked, or even inventoried.

Why is shadow AI worse than shadow IT?

Shadow IT was bad because unsanctioned SaaS tools created security and compliance gaps. Shadow AI is worse because the data flowing into those tools is conversational, unstructured, and often shockingly candid. And as the Krafton ruling demonstrates, it is now treated as a corporate record.

Recommended practice is inventorying how AI tools are used across an enterprise (including unsanctioned usage), setting deliberate retention policies rather than defaulting to vendor settings, and updating legal-hold checklists to expressly cover AI-generated electronically stored information.

Consider the typical pattern. An employee is working on a sensitive negotiation. They paste the term sheet into a consumer chatbot and ask for analysis. They paste an HR complaint and ask how to respond. They paste competitive intelligence and ask for a strategy memo. Each of those interactions is now a document that lives on a third-party server, subject to that provider's retention policy, subpoena-able in litigation, and almost certainly not covered by your existing data governance framework.

Can attorney-client privilege protect AI chat logs?

Almost certainly not, at least under current doctrine for consumer tools. The Heppner court's reasoning is instructive: attorney-client privilege requires communication with an attorney for the purpose of obtaining legal advice. A chatbot is not an attorney. The communication is not privileged.

Work-product doctrine fares slightly better in narrow circumstances, but only when the user is genuinely preparing for litigation and the AI tool is being used as part of that preparation. A CEO asking a chatbot how to avoid paying an earnout is not litigation preparation. It is business strategy, and it is fair game.

The Harvard Law School Forum analyzed this question directly: AI legal chats by non-lawyer officers and directors are generally discoverable. The forum noted that the privilege analysis turns on the identity of the communicator and the purpose of the communication, not the sophistication of the tool.

What makes AI transcripts more damaging than email?

Three things compound the risk.

First, candor. People talk to chatbots the way they talk to themselves. The Krafton CEO did not email his board saying "help me find a way to avoid this $250 million payment." He typed it into a chat window, probably late at night, probably alone, probably thinking no one would ever see it. That kind of unfiltered intent is exactly what opposing counsel dreams about in discovery.

Second, specificity. The chatbot did not just receive a vague question. It generated a detailed response strategy, including forming a task force and executing a takeover. And the company followed most of those recommendations. So the transcript is not just evidence of intent. It is a roadmap, with timestamps, showing the evolution from "I want to avoid this payment" to "here is exactly how to do it" to execution.

Third, persistence. Emails get deleted, but users rarely think to delete their chatbot history. And even if they do, the provider may retain the data on their servers. The question of whether data exists is a question about the provider's infrastructure, not the user's browser history.

How does the regulatory environment compound this risk?

It is tightening on multiple fronts simultaneously. In a two-week window ending in late June 2026, 19 new AI laws were enacted across 11 states and Congress, including chatbot transparency mandates. The legislative velocity is notable.

Beyond discoverability, businesses using AI tools in all-party-consent states (Delaware, California, Massachusetts, and others) face potential criminal liability for recording conversations without proper consent. If your AI tool is transcribing calls or processing voice data, the recording-consent layer sits on top of the discoverability layer. Two separate legal risks, one tool.

What should enterprise teams do right now?

The governance response breaks into three immediate actions and one architectural decision.

Audit your AI exposure

Map every AI tool in use across your organization, sanctioned and unsanctioned. This is the same exercise companies did a decade ago with shadow SaaS, except the data flowing through these tools is conversational, contextual, and often contains exactly the kind of strategic thinking that becomes exhibit A in litigation. Spencer Fane's guidance on this is practical: inventory usage, set deliberate retention policies, update legal-hold checklists.

Update your litigation hold procedures

Your litigation hold template needs a line item for AI chat logs. Every litigation hold, going forward, should require custodians to identify and preserve any AI chatbot conversations related to the matter. If you do not ask, they will not tell you. And if the logs are destroyed after a hold obligation attaches, you have a spoliation problem.

Train your executives on the "assume it is discoverable" rule

The same discipline lawyers have applied to email for twenty years now applies to AI chat. Do not type anything into a chatbot that you would not want read aloud in a courtroom. This is not paranoia. It is what happened in Fortis Advisors v. Krafton, and the court's opinion is public.

Choose tools where retention is an architectural property, not a policy promise

The distinction between "we promise not to look at your data" and "the data does not exist on our servers in a form we can produce" is the difference between a policy and an architecture. The OpenAI copyright case drew this line explicitly: enterprise agreements with shorter retention windows were carved out from the mass production order. What your provider retains determines what a court can compel.

This is where we think about things differently at Selina. Content is encrypted at rest. Non-content operational metadata is kept for a short retention window. Files and transfers via SelinaSEND are end-to-end encrypted. The point is not to make data invisible to us for marketing reasons. The point is that data that does not exist in readable form on a third-party server cannot become exhibit A in someone else's lawsuit.

How should founders think about this ruling long-term?

The Krafton case is a leading indicator, not a one-off. The combination of increasing AI adoption, candid user behavior, broad provider retention defaults, and courts that treat chatbot logs as ordinary business records creates a compounding risk surface.

If you are a founder using AI tools for strategy, fundraising analysis, competitive research, or deal structuring, every one of those conversations is a potential discovery target. Not hypothetically. The Van Ness Feldman analysis of the ruling puts it plainly: AI in the courtroom and the boardroom are no longer separate topics.

The practical question is not whether AI chat logs are discoverable. That question has been answered. The practical question is whether the logs exist, what they contain, and who controls them. Those are architectural decisions you make today that determine your litigation exposure years from now.

Your prompt history is a corporate record. Treat it like one.

If you want an AI assistant built with that assumption from the start, start a free 7-day trial, no card required.

Frequently Asked Questions

Are ChatGPT logs actually discoverable in court?

Yes. The Delaware Chancery Court in Fortis Advisors v. Krafton treated a CEO's AI chatbot transcripts as direct evidence of intent to breach a $250 million earnout obligation, and several other 2026 rulings have followed the same approach.

What happened in the Fortis Advisors v. Krafton case?

Krafton's CEO used a consumer AI chatbot for advice on avoiding a $250 million earnout payment tied to its acquisition of Unknown Worlds Entertainment, and the bot suggested forming a task force and executing a takeover. The company followed most of these recommendations, and the court found breach, restored the ousted CEO, and extended the earnout period by 258 days.

Does attorney-client privilege protect AI chatbot conversations?

Almost certainly not for consumer tools, since privilege requires communication with an attorney for legal advice and a chatbot is not an attorney. In United States v. Heppner, the court held that using a consumer AI chatbot did not qualify for attorney-client privilege or work-product protection.

Can enterprise AI agreements reduce legal exposure compared to consumer tools?

Yes, to some extent. The OpenAI copyright litigation order carved out enterprise and contractual arrangements with shorter retention windows from its preservation requirements, meaning data with negotiated shorter retention may not exist to be produced, though this depends on architecture and policy rather than assumptions.

How do litigation hold obligations apply to AI chat logs?

The duty to preserve AI chat logs begins when litigation is reasonably anticipated, not when a complaint is filed, meaning litigation hold notices now need to cover AI tools employees may have used, including unsanctioned 'shadow AI' tools that companies often haven't inventoried.

Sources & References

Michael C.

Michael C.

Founder & Principal Engineer, Selina Labs

Michael builds Selina, a privacy-first AI that remembers you across conversations. He ships security-sensitive AI in production — real attacks, real fixes, measured in minutes and dollars — and writes about privacy, security, and LLMs from that seat. Top Rated Plus and expert-verified on Upwork.

Learn more about Selina.ai