SELINA.ai
Sign in

Yes, Your ChatGPT Logs Can Be Subpoenaed. A CEO Just Found Out the Hard Way.

A CEO used ChatGPT to plan a corporate takeover. He deleted the logs. The court found them anyway, and they became the centerpiece of a $250 million ruling against his company. If you've been wondering whether your ChatGPT logs can be subpoenaed, the answer is no longer theoretical. Delaware just gave us the case law.

Key Takeaways

What Happened in the Delaware Earnout Case?

Krafton, the South Korean gaming company, acquired Unknown Worlds Entertainment for $500 million upfront plus up to $250 million in earnout payments. Unknown Worlds is the studio behind the Subnautica franchise. The deal left the founders and CEO of Unknown Worlds with operational control during the earnout period. Standard structure for a creative studio acquisition where the earnout depends on the success of a forthcoming title.

Then Krafton's CEO, Changhan Kim, decided he wanted more control. He used ChatGPT to develop a strategy that included firing Unknown Worlds' leadership and cutting distribution channels for Subnautica 2. The AI tool generated a plan. Krafton executed that plan. The earnout targets became harder (or impossible) to hit. The stockholders' representative, Fortis Advisors, sued, alleging Krafton had acted in bad faith to avoid paying the $250 million.

The Delaware Court of Chancery agreed. On March 16, 2026, the court found that Krafton had breached its obligations under the earnout, and the CEO's ChatGPT logs were cited as evidence of his intent.

How Did Deleted Chat Logs End Up as Evidence?

Kim admitted at trial that he had deleted some of the relevant ChatGPT conversations. This did not save him. The court's record still contained extensive ChatGPT-related evidence: strategy outputs that had been shared with colleagues, derivative documents (internally dubbed "Project X"), and trial testimony about what the chats contained.

This is worth sitting with. The CEO deleted the source material. The court reconstructed the substance from everything the source material had touched. Emails forwarding ChatGPT outputs. Slide decks built on ChatGPT recommendations. Witnesses who had seen or discussed the outputs. Deletion of the original log removed one node from the evidence graph. It did not remove the graph.

Retroactive deletion is structurally weaker than most people assume. If you've already shared an output, pasted it into a doc, or discussed it in a meeting, the log itself is just one copy among many. And the act of deleting it, once discovered, tends to look worse than the content itself.

Why Weren't the Logs Protected by Privilege?

They weren't generated through legal counsel. The CEO was using a consumer AI tool on his own, for strategic planning, not in the context of seeking legal advice. Privilege was never raised as a defense, likely because the CEO had shared the outputs with other non-lawyers inside the company. Once you share privileged material with someone outside the attorney-client relationship, the privilege is generally waived. Sharing ChatGPT's output with your operations team is sharing it with a non-lawyer. The privilege question never even got off the ground.

This is not a technicality. It is the normal operation of privilege doctrine applied to a new medium. The AI tool is a third party. The provider has its own data retention policies, its own terms of service, and in some cases, its own obligations to respond to legal process. Your conversation with it is not a conversation with your lawyer, and courts are not going to pretend otherwise.

What Did the Heppner Ruling Add?

The Delaware case was about corporate bad faith. A separate case in the Southern District of New York addressed the privilege question directly.

On February 10, 2026, Judge Jed Rakoff ruled in United States v. Heppner that a defendant's written exchanges with an AI chatbot were not protected by attorney-client privilege or work product doctrine. The defendant had used a chatbot to research legal questions related to his case. The government sought production of those exchanges. Rakoff said yes.

The reasoning was straightforward. Rakoff pointed to the AI provider's privacy policy, which disclosed that user inputs could be used for model training and could be disclosed to government authorities. The defendant had been on notice that his inputs were not confidential. You cannot claim privilege over communications you voluntarily disclosed to a third party whose own policies tell you they may share your data.

This is a first-of-its-kind ruling, and it sets a clear marker: if the AI provider's terms say they can retain, train on, or disclose your inputs, you have no reasonable expectation of confidentiality. Privilege requires confidentiality. No confidentiality, no privilege.

Is There a Contrary View?

Yes. In Warner v. Gilbarco, a court protected ChatGPT outputs as attorney work product, reasoning that generative AI is a tool, not a person, and that no disclosure to an adversary had occurred. This creates a split. Courts are reaching different conclusions depending on the facts, particularly whether the user shared the output, whether counsel was involved, and what the provider's terms say about data retention.

If you are betting your litigation strategy on the Warner side of this split, you are betting on the less conservative reading while the case law is still forming. That is a bet. Treat it like one.

Can AI Providers Be Forced to Produce Your Logs Directly?

Yes. This has already happened.

In the copyright litigation brought by the New York Times and other news publishers, a federal magistrate judge ordered OpenAI to produce 20 million de-identified ChatGPT logs to the plaintiffs. OpenAI moved for reconsideration. Denied. District Judge Sidney Stein affirmed the order in full.

Separately, in the same litigation, the court ordered OpenAI to stop deleting most users' deleted and temporary chats, after plaintiffs argued that users might use the delete function to hide evidence of paywall circumvention. The provider was ordered to preserve data that users had explicitly chosen to delete.

Read that again. A court ordered the provider to stop honoring delete requests. The "delete" button in a consumer AI tool is a UI element. It is not a legal guarantee. It is not a cryptographic operation. It is a request to the provider, and providers can be ordered by courts to ignore it.

What Does This Mean for Founders and Executives Using AI for Deal Strategy?

If you are using a consumer AI chatbot to think through acquisition strategy, earnout structures, employee terminations, pricing decisions, competitive positioning, or anything else that might become relevant in litigation, you are creating a discoverable record of your internal deliberation. That record lives on someone else's infrastructure, governed by someone else's terms of service, subject to someone else's data retention policies, and producible under someone else's legal obligations.

This is not a hypothetical risk. The Delaware case is a real CEO, a real $250 million ruling, and real chat logs entered into evidence.

A few specific implications:

Shadow AI is now a discovery liability. Research from Harmonic Security, analyzing over a million prompts, found that roughly one in five files employees upload to AI tools contains sensitive company data: source code, legal documents, M&A materials, financial data. Separately, KPMG research found 48% of employees admit entering sensitive company data into public AI tools. Your employees are almost certainly doing this right now, whether or not you have a policy against it. Every one of those interactions is potentially discoverable.

AI governance is a litigation-risk function, not an IT policy. The traditional framing of AI governance is about data security: preventing leaks, protecting trade secrets. The Delaware case reframes it. Ungoverned AI use generates a permanent, subpoenable paper trail of internal deliberation that opposing counsel can use to establish intent, bad faith, or knowledge. This is not the same risk as a data breach. It is the risk of creating evidence against yourself, voluntarily, in a system you do not control.

The distinction between enterprise and consumer tiers matters legally. Enterprise AI deployments typically come with data processing agreements, contractual commitments not to train on customer inputs, and more defined retention policies. Legal and compliance guidance is converging on a clear split: enterprise-tier tools with a DPA and training opt-out are the emerging standard for corporate use. Consumer-tier tools that retain inputs or train on them are the red zone. Samsung banned ChatGPT company-wide in 2023 after employees leaked source code through it, then reversed course in 2026 by rolling it out as an enterprise deployment with contractual data protections for roughly 125,000 employees. The lesson is not "don't use AI." The lesson is that the terms under which you use it determine your legal exposure.

Does Deleting Your Logs Actually Protect You?

No. Not reliably, and possibly not at all.

Kim deleted his logs. The court still had enough evidence to rule against Krafton. The deletion itself became part of the narrative of bad faith. In litigation, spoliation of evidence (destroying relevant documents after you know or should know they may be relevant to a legal proceeding) can result in adverse inference instructions, sanctions, or worse. Deleting AI logs after a dispute has arisen, or after you reasonably anticipate litigation, is not a privacy measure. It is potential spoliation.

Even setting aside the legal risk, deletion from your account does not mean deletion from the provider's infrastructure. Providers maintain backups, logs, and operational data on timelines governed by their own policies and, now, by court orders. A federal court has already told one provider to stop honoring delete requests in the context of active litigation. Your delete button is a polite request, not a technical guarantee.

What Should You Actually Do About This?

Concrete steps, in order of priority:

  1. Assume every AI interaction is discoverable. This is the baseline. If you would not write it in an email to your board knowing opposing counsel would read it, do not type it into a chatbot.
  2. Separate legal and strategic AI use from casual AI use. If you need AI assistance with something that touches legal risk (deal terms, employment decisions, competitive strategy, regulatory compliance), route it through counsel or use a tool with architectural privacy guarantees. Do not use the same consumer account you use for recipe suggestions.
  3. Establish and enforce an AI usage policy. Specify which tools are approved for which categories of data. Distinguish between enterprise-tier tools with DPAs and consumer-tier tools without them. Make the policy specific enough to be actionable: "don't put confidential stuff in ChatGPT" is not a policy. "Category A data (M&A, legal, HR) may only be processed through approved enterprise AI tools listed in Appendix B" is a policy.
  4. Audit shadow AI use. You will not know the scope of the problem until you look. One in five uploaded files contains sensitive data. Your company is probably not the exception.
  5. Evaluate tools based on architectural properties, not just policy promises. A provider's promise not to train on your data is a contractual commitment, enforceable in court but breakable by breach, acquisition, policy change, or court order. Architectural properties (encryption at rest, no vendor-side retention of prompts, private inference) are harder to circumvent. The distinction matters when the question is not "will they keep their promise" but "what happens when a court orders them to produce the data."

Only if the architecture supports it. Privilege requires that the communication be made in confidence, for the purpose of seeking or providing legal advice, between a client and an attorney (or their agent). Using a consumer AI tool introduces a third party (the provider) whose own terms may disclaim confidentiality. Heppner held that this breaks privilege. Warner held that it doesn't, at least for work product. The split is real and unresolved.

If you want to preserve privilege over AI-assisted legal work, the safest path is: involve counsel directly, use a tool whose terms do not claim rights over your inputs, ensure the tool does not train on your data, and do not share the outputs with anyone outside the privilege circle. Even then, you are operating in unsettled legal territory. The conservative move is to treat AI-generated legal analysis as non-privileged until the case law matures, and plan accordingly.

How Does This Change the Risk Calculus for M&A Specifically?

The earnout context makes this particularly sharp. Earnouts are inherently adversarial: the buyer wants to minimize the payout, the seller wants to maximize it. Courts scrutinize buyer conduct during the earnout period for good faith. If a buyer's CEO uses ChatGPT to plan actions that undermine the earnout, and those logs are discoverable, the court has a timestamped record of the buyer's intent. That is exactly what happened in Fortis v. Krafton.

For founders on the sell side: if your acquirer's executives are using AI tools to strategize about your earnout, those conversations may be discoverable in litigation. This is a new source of evidence that did not exist five years ago.

For executives on the buy side: your AI chat history is now part of your litigation risk surface. If you use ChatGPT to think through whether to fund a product line, replace a management team, or restructure a subsidiary during an earnout period, you may be building the plaintiff's case for them.

The Structural Problem

The deeper issue is that consumer AI tools were not designed for high-stakes corporate deliberation. They were designed for broad accessibility, with data retention policies optimized for model improvement, not for the user's litigation posture. When you type a strategy into one of these tools, you are depositing a record of your thinking into a system that (a) the provider controls, (b) the provider may be compelled to produce, (c) the provider may train on, and (d) you cannot reliably delete from.

This is a mismatch between the tool's architecture and the use case. The tool is fine for summarizing articles or drafting marketing copy. It is structurally unsuited for anything where the content of your prompt could become adverse evidence. The fix is not to stop using AI. The fix is to use AI infrastructure whose privacy guarantees are architectural rather than promissory.

We built Selina around this principle. Memory is encrypted at rest. Files and transfers via SelinaSEND are zero-knowledge encrypted. The account is protected. We run on a stack of frontier models, routed per task, via API. We are not going to tell you our architecture solves every legal risk in this article, because it doesn't, and no tool does. But the question of whether your AI tool's operator can be compelled to produce your conversations is a question about architecture, not about intention. And architecture is something you can evaluate before you type.

If you want an AI assistant built with that calculus in mind: start a free 7-day trial, no card required.

Frequently Asked Questions

Can ChatGPT conversation logs really be subpoenaed in litigation?

Yes. In Fortis Advisors v. Krafton, the Delaware Court of Chancery used a CEO's ChatGPT logs as direct evidence of bad-faith intent in a $250 million earnout dispute, showing this is no longer a theoretical risk.

If I delete my ChatGPT logs, am I safe from discovery?

No. In the Krafton case, the CEO deleted some logs, but the court reconstructed his strategy from shared outputs, derivative documents, and trial testimony, since deleting the original log doesn't remove the copies made when it was shared or discussed.

Are conversations with AI chatbots protected by attorney-client privilege?

Generally not, according to Judge Rakoff's ruling in United States v. Heppner, which held that AI chatbot exchanges are not protected by attorney-client privilege or work product doctrine because the AI provider is a third party whose policies allow use or disclosure of user inputs. There is a contrary ruling in Warner v. Gilbarco, which protected ChatGPT outputs as work product, creating a split in the case law.

Can courts force AI companies like OpenAI to hand over user chat logs directly?

Yes. In copyright litigation brought by the New York Times and other publishers, a federal magistrate judge ordered OpenAI to produce 20 million de-identified chat logs, a decision affirmed by the district judge, and the court also ordered OpenAI to stop deleting users' deleted and temporary chats.

What should founders and executives take away from these rulings about using AI for deal strategy?

Using consumer AI tools for deal strategy, internal deliberation, or legally sensitive matters creates a discoverable paper trail stored on the provider's infrastructure and governed by its own retention and disclosure policies, so AI governance should be treated as a litigation-risk issue, not just an IT or data-security concern.

Sources & References

Michael C.

Michael C.

Founder & Principal Engineer, Selina Labs

Michael builds Selina, a privacy-first AI that remembers you across conversations. He ships security-sensitive AI in production — real attacks, real fixes, measured in minutes and dollars — and writes about privacy, security, and LLMs from that seat. Top Rated Plus and expert-verified on Upwork.

Learn more about Selina.ai