Skip to content

AI Governance & Ethics

Your Agency’s AI Prompts May Be Public Records

A permit-review prompt, its attachments, model output, and staff edits can carry different retention and disclosure duties. Agencies need a retrieval workflow before the first request arrives.

Irene VaskoGovernance & Ethics Writer

October 1, 2026 · 8 min read

A permit case file beside a laptop showing an exported AI prompt, attachment list, and redaction review log.
A permit case file beside a laptop showing an exported AI prompt, attachment list, and redaction review log.

Start with one ordinary transaction: a permit analyst uploads an applicant’s spreadsheet to an approved generative AI service, asks it to identify missing fields, receives a draft deficiency notice, and edits that draft before sending it. A supervisor adds a comment explaining why one model suggestion was rejected.

Call this the permit-review packet. It may include the prompt, system instructions supplied by the agency, uploaded spreadsheet, retrieved reference material, output, model or service identifier, timestamps, reviewer comments, and final notice. Some elements may be records. Some may be duplicates or transitory material.

Some may contain information that an agency must protect even if the surrounding packet is disclosable.

The first engineering constraint is therefore capture. If the service keeps chat history for only a short period, stores it under an individual account, or offers administrators no export covering attachments and edits, staff cannot search the permit-review packet reliably after a request, audit, lawsuit, or investigation arrives.

Decide what the agency is preserving

For federal agencies, the starting point is the Federal Records Act definition in 44 U.S.C. § 3301.

It covers “all recorded information, regardless of form or characteristics,” made or received by a federal agency under federal law or “in connection with the transaction of public business,” when preserved or appropriate for preservation as evidence of agency work or because of informational value.

That language does not say “email,” “document,” or “final decision.” Recorded information can include a prompt or output if it meets the functional test. State public-records statutes use their own definitions, and local schedules may assign different retention periods, so an agency must map its workflow against the rules that govern it rather than importing the federal standard.

Record status and public disclosure are also different decisions. A prompt can qualify as a record and still contain material that may be withheld under an applicable exemption. Conversely, a vendor’s deletion setting does not decide that an item was never a record. The agency’s records officer, public-records staff, privacy team, security staff, program owner, and counsel should set those classifications; this operational workflow is not legal advice.

For the permit-review packet, write a short disposition rule before deployment. Specify which components enter the official case file, which system owns the authoritative copy, how long each component follows the relevant schedule, and whether repeated model responses count as separate evidence of the analyst’s work. If the agency concludes that discarded exploratory prompts are transitory, document that conclusion and apply it consistently rather than letting each employee decide after a request arrives.

Preserve enough context to interpret the output. A model answer without its prompt can be misleading, while a prompt without the uploaded spreadsheet may not show what information the system processed. At minimum, the retained packet should connect the user’s instruction, referenced or attached inputs, returned output, consequential staff edits, and final agency action through a stable case identifier.

Capture the packet outside the chat window

A consumer-style chat history is a poor records repository. Users rename conversations, attachments may not appear in exports, model providers apply their own retention settings, and an administrator may be able to search account metadata without searching prompt text. A screenshot is also incomplete when it omits an attachment, hidden system instruction, or the sequence of revisions.

The stronger setup writes the permit-review packet into the agency’s existing case-management or records system. An integration can save the prompt and output as text, preserve attachments in their original formats, record timestamps and service identifiers, and link the artifacts to the permit number. If automated capture is unavailable, require a structured export or a staff form that places the relevant material in the case file before the work is completed.

This costs storage, integration work, and staff time. Full telemetry, meaning detailed operational logs about each model interaction, may also collect more sensitive data than the records program needs. Do not retain every technical event merely because the vendor exposes it. Capture what supports the agency’s documented business, audit, security, and records requirements, then restrict access according to the most sensitive item in the packet.

The fallback matters. If the AI service cannot export prompts, outputs, attachments, timestamps, and account identifiers in a searchable format, limit it to tasks whose records can be captured elsewhere or do not use it for case-specific work. A promise that the vendor can help later is not a retrieval mechanism.

Search the business system and the AI service

When a request arrives, convert its wording into a search plan. A request for “AI prompts used to review permit applications” may reach case files, the AI service, email, collaboration tools, shared drives, exported logs, and notes kept by supervisors. Custodians, meaning people likely to possess responsive material, may include analysts, managers, system administrators, contractors, and records staff.

Search by more than keywords. Prompt text can omit the applicant’s name even when the attachment contains it, and a model output may refer only to a permit number. Use date ranges, user accounts, case identifiers, filenames, service identifiers, and workflow events. Record the repositories searched, query terms or filters, export method, date of collection, and known limitation, such as an admin console that indexes chat titles but not attachment contents.

Deduplicate without erasing provenance. A copy of the same spreadsheet may appear in the case system, chat export, and email, yet the surrounding metadata can show who uploaded it and when. Hashing, which generates a repeatable digital fingerprint for a file, can identify exact duplicates, but it will not treat a spreadsheet and a PDF export as identical. Keep one review copy only after preserving where each instance came from.

A preservation notice or legal hold can require material to remain available beyond an ordinary deletion cycle. Once the agency receives a request, complaint, audit notice, or litigation trigger, the responsible officials should decide whether routine deletion must pause. The AI administrator needs a tested way to suspend deletion for identified accounts or export the relevant permit-review packets into a controlled repository.

Review sensitive material at the field level

The uploaded spreadsheet is likely to carry the greatest disclosure risk. It may contain personal contact details, confidential commercial information, security-sensitive data, or fields that the analyst never needed to send to the model. The prompt can repeat those details. The output may infer or restate them, and reviewer notes may reveal internal deliberation or legal communications.

Minimize before submission. A workflow can remove unnecessary columns, replace direct identifiers with case numbers, or route especially sensitive cases away from a hosted model. That lowers exposure, but it does not eliminate the need to preserve the agency’s actual record when the submitted version influenced official work.

For federal FOIA processing, exemptions can protect categories including personal privacy, certain confidential commercial information, privileged interagency or intra-agency material, law-enforcement interests, and information protected by another statute. Those exemptions are not automatic labels for every AI prompt. Under 5 U.S.

C. § 552(a)(8), an agency generally may withhold only when it “reasonably foresees that disclosure would harm an interest protected by an exemption” or disclosure is prohibited by law.

Federal FOIA also requires release of “[a]ny reasonably segregable portion of a record” after exempt portions are removed. That makes field-level review important. Withholding the entire permit-review packet because one spreadsheet column contains protected information may fail to account for releasable prompt text, model output, or metadata. State law can impose different exemptions, tests, and deadlines.

Use a review copy that preserves the original. Mark proposed redactions, link each one to the governing authority, and have the appropriate reviewer approve close calls. Text extraction and automated detection can help locate Social Security numbers, email addresses, or account numbers, but scanned files, spreadsheet formulas, hidden tabs, comments, and model-generated paraphrases still require human review.

Leave receipts for what was withheld

The final release file should not be the only record of the decision. Keep a review log that identifies the document or component, page or field, withholding authority, harm rationale where required, reviewer, decision date, and released version. Avoid copying protected content into the log more than necessary.

This is where the permit-review packet becomes manageable. The agency can release the analyst’s instruction and portions of the output, redact protected cells from the attachment, withhold a privileged supervisor comment if the governing law supports that decision, and explain each omission without claiming that “the AI record” was categorically exempt.

Test the workflow with a mock request before launch. Ask staff to retrieve one permit-review packet, verify that attachments open, search it by permit number and analyst account, produce a redacted copy, and reconcile the result with the original. If the exercise depends on an employee remembering which chat contained the spreadsheet, the agency does not yet have a records workflow.

Questions people ask

Is every prompt sent by a public employee a government record?

No. The answer depends on the governing definition, the prompt’s connection to public business, and the applicable retention schedule. A prompt that documents analysis behind a permit decision presents a stronger preservation case than an unrelated personal query, but the responsible records officials must classify it under the agency’s rules.

Can an agency delete prompts under its normal retention settings?

Only if those settings match an approved disposition rule and no preservation duty has intervened. A vendor’s default deletion period is a product setting, not a records determination; requests, audits, investigations, or litigation may require the agency to pause deletion or export affected material.

Can the agency withhold an entire

AI conversation because it contains private data?

Not necessarily. Under federal FOIA, the agency must consider applicable exemptions, foreseeable harm, and whether reasonably segregable portions can be released. A prompt, attachment, output, and review note may require separate treatment, while state public-records laws may apply different standards.

What should an agency require from an AI vendor?

Require searchable exports that include prompt text, outputs, attachments, timestamps, account identifiers, and links between related events. The contract and technical configuration should also address retention controls, deletion suspension, administrator access, audit logs, data location, and what happens to records when the service ends.

ShareFacebook
ai governanceai observabilityprivacy and data rightsai governancepublic recordsrecords managementgovernment aidata privacy

One story a day

The story of the day, in your inbox

One real story about AI each morning — no hype, no alarm, just company for the road.

Read next

Laptop showing a declined credit application beside a policy table with the code RC-DTI-OVER-LIMIT.

AI Governance & Ethics

A Chatbot Denial Needs a Reason Code, Not More Words

A fluent explanation is useless if it cannot be traced to the rule that produced a denial. Reason codes make chatbot language reviewable before it reaches a customer.

Irene Vasko · 8 min read

A laptop displaying an applicant record beside a printed data map linking a résumé, model output, score, and recruiter note.

AI Governance & Ethics

A Data-Access Request Can Reach Your AI’s Hidden Scores

Prompts and profile fields may be only part of the record. AI-generated labels, rankings, and summaries can also relate to a person and may need to be found, reviewed, and disclosed.

Irene Vasko · 8 min read