Your Agency’s AI Prompt May Be a Public Record
An official AI chat can leave four record candidates: the prompt, uploaded source file, generated draft, and vendor log. Agencies need retention and export controls before employees start using it.
August 27, 2026 · 8 min read

Take one ordinary agency workflow. A procurement analyst uploads a bid evaluation memo to an AI assistant, types “compare these vendor claims with the scoring criteria,” follows with a correction, and pastes the resulting draft into an official recommendation.
The recommendation will probably enter the agency’s document system. The rest may remain inside the assistant: two prompts, the uploaded memo, generated text, timestamps, user and conversation identifiers, model information, and perhaps a safety or moderation log held by the vendor. That split is the governance problem.
An agency cannot decide that only the final recommendation matters merely because the assistant labels everything else “chat history.” Record status turns on content, purpose, and control under the applicable law. Disclosure is a separate question, decided later under public-records law, the Freedom of Information Act, or another access regime.
The record is the transaction, not the interface
For federal agencies, the Federal Records Act defines records broadly. Under 44 U.S.C. § 3301, the definition covers:
“all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation.”
That language does not exclude a prompt because it sits in a commercial chatbot, looks informal, or was generated while an employee was exploring wording. NARA’s public guidance on records created with AI applies existing records-management duties rather than creating a special category called an AI record: inputs and outputs may qualify when they document agency organization, functions, decisions, procedures, or operations.
State and local laws use different definitions and retention schedules, so the result is jurisdiction-specific. Many follow the same functional pattern, however, asking whether recorded information concerns public business and was prepared, received, used, or retained by the agency. A chat that shapes an official evaluation can therefore matter even when no policy says “save every prompt.”
Return to the procurement analyst. The uploaded bid memo may already be a managed record elsewhere, making the chatbot copy a convenience duplicate. The first prompt may document the criteria the analyst asked the system to apply. The correction may reveal that the model omitted a mandatory factor.
The generated draft may show how language entered the recommendation, while model metadata could help identify which system produced it.
Those objects do not necessarily receive one retention period. An approved records schedule may authorize deletion of convenience copies and transitory material while requiring preservation of substantive decision records. The agency must make that classification deliberately, rather than letting a vendor’s default chat-expiration setting make it by accident.
Retention and disclosure are different controls
Retention answers how long an agency must keep material. Disclosure answers whether it must produce retained material after a valid request, subject to applicable exemptions and exclusions. A document can be a record and still be withheld in whole or part; it can also be deleted lawfully under an approved schedule before any request or legal hold requires preservation.
The distinction matters for generated drafts. Calling an AI output a draft does not automatically exempt it from disclosure. Under federal FOIA, Exemption 5 can protect qualifying privileged interagency or intra-agency material, including some predecisional and deliberative communications, but the agency still has to apply the exemption to the content and circumstances. State draft exemptions vary, sometimes sharply.
Once an agency receives a request, FOIA requires federal agencies to make “reasonable efforts to search for the records in electronic form or format,” subject to a limit involving significant interference with an automated information system. A records officer cannot search an email archive and shared drive, ignore the sanctioned assistant, and assume the search was adequate when employees conducted responsive work there.
Search quality depends on what the system exposes. A normal chat-history screen may search conversation titles but not uploaded-file text. An administrator export may include prompt text yet omit deleted threads, system instructions, attachments, or model responses blocked before display. Some enterprise products provide audit events through an application programming interface, or API, which lets another system request structured data, but an event stating that a file was uploaded is not the file itself.
The procurement chat illustrates the consequence. Searching for the vendor’s name might find the final recommendation and miss the prompt because the analyst wrote “bidder two.” Searching the uploaded memo might fail if the platform retained only a file identifier. An adequate preservation design keeps enough linkage among the conversation, attachments, user, timestamps, and resulting document to reconstruct the transaction without guessing.
Vendor custody does not erase agency responsibility
Cloud delivery adds a control question. Under federal FOIA doctrine, an agency record generally must have been created or obtained by the agency and be under agency control when the request arrives. Physical possession is relevant, but outsourcing storage does not provide a dependable escape where the agency can access and use the material for official work.
NARA’s contractor records rules require agencies to address records created or received by contractors while performing agency business and to specify how records are managed and delivered. Enforcement comes from records law, approved schedules, contracts, system configuration, and agency procedure. NARA guidance can explain those duties; it does not by itself guarantee that a chatbot vendor’s export contains every required field.
The contract therefore needs operational answers. The agency should know whether administrators can export complete conversations in a usable format, retrieve attachments, preserve records beyond the ordinary deletion window, suspend deletion for a legal hold, and recover data after an employee account closes. It also needs to know which logs belong to the agency, which logs the vendor keeps for security or abuse monitoring, and whether subcontractors store another copy.
A promise that customer prompts are not used to train a general model addresses one data-use risk. It says little about retention, search, export, deletion, or legal holds. Likewise, a vendor may advertise zero retention for some API traffic, which can reduce exposure but conflict with an agency workflow that needs the prompt-response exchange as evidence of how official work was performed.
Keeping everything forever is not the answer. It expands review costs, stores sensitive material longer, and can bury responsive records in low-value telemetry. The stronger design maps each retained object to a schedule and purpose, then deletes it consistently when authorized.
What to preserve before the first official chat
Start with the workflow rather than a generic AI policy. For the bid-evaluation assistant, the agency can identify the official account, permitted source files, expected outputs, approval point, and system that holds the final decision. Records staff and counsel can then decide whether prompts and responses are substantive records, temporary working material, or a mixture requiring classification.
Next, test the export with a realistic conversation. Upload a sample file, issue a prompt, correct the output, rename the thread, delete it through the user interface, and close the test account. The resulting administrator export should show whether the agency can recover prompt and response text, attachment contents or durable references, timestamps, user identity, conversation identifiers, and deletion events. A screenshot is a poor fallback because it loses structure, may omit attachments, and scales badly during a records search.
Route retained material into a recordkeeping system rather than treating the assistant as the archive. That may mean an automated export, a connector to an enterprise repository, or a required manual filing step for a narrow pilot. Automation costs integration work and storage; manual capture costs staff time and fails when employees forget. For high-volume official use, the manual option usually creates an audit gap too large to justify its lower setup cost.
Finally, configure deletion only after retention and hold behavior has been verified. Access logs should show who exported or deleted records, while permissions should prevent ordinary users from defeating a hold. If the vendor cannot produce complete chats and attachments, the agency can restrict the assistant to nonrecord brainstorming, deploy a separate capture layer, or decline the product for that workflow.
That decision belongs before the procurement analyst uploads the bid memo. Once the vendor’s short deletion window closes, a policy written afterward cannot recreate the correction that showed why the model’s first draft was wrong.
Questions people ask
Is every government employee’s AI prompt a public record?
No. Record status depends on the applicable law, the prompt’s content, its connection to public business, and the agency’s retention schedule. A substantive prompt that directs analysis for an official decision is more likely to matter than a test message, but agencies should classify workflows rather than rely on employees to make ad hoc judgments.
Can an agency delete
AI chats under its normal retention schedule?
Potentially, if an approved schedule authorizes deletion and no request, legal hold, audit, investigation, or other preservation duty applies. The risky setup is letting the vendor delete chats automatically before the agency has classified them or captured records that must remain in an official repository.
Does a draft become exempt from disclosure because AI generated it?
No. AI authorship does not create an exemption. A federal agency may apply FOIA exemptions, including protections for qualifying privileged or deliberative material, while state rules differ. The agency must evaluate the draft’s content and role, preserve it when required, and release any reasonably segregable nonexempt material under the governing law.
What should an agency require from an AI vendor?
Require documented retention settings, complete exports, attachment recovery, searchable metadata, legal-hold support, deletion records, account-closure procedures, and clear terms for contractor and subcontractor copies. Test those capabilities with a sample conversation before official use; a contractual promise is less useful when the administrator export omits the uploaded file.
One story a day
The story of the day, in your inbox
One real story about AI each morning — no hype, no alarm, just company for the road.



