The explosion of generative AI in the workplace has created a new and largely unaddressed category of litigation risk. In May 2025, a federal court in the Southern District of New York ordered OpenAI to preserve and segregate all ChatGPT output log data that would otherwise be destroyed under its default 30-day deletion policy, marking one of the first judicial orders to treat AI-generated content as electronically stored information subject to legal holds (i.e., the obligation to preserve potentially relevant evidence once litigation is reasonably anticipated). The order, issued over OpenAI’s objections grounded in user privacy and regulatory compliance, signals that courts will expect litigants to preserve AI artifacts with the same rigor applied to email, documents, and structured data.
Read on for an analysis of how existing discovery rules already reach AI-generated content, the sanctions companies may face for failing to preserve it, and the practical steps clients should take now to close the gap.
I. Why Generative AI Has Outpaced Existing Retention Policies
The rapid adoption of generative AI tools across the enterprise has exposed fundamental gaps in corporate information governance. Most retention policies define “records” by reference to a specific system or format—email servers, shared network drives, structured databases—rather than by the function the underlying information performs. This definitional approach leaves AI-generated content in a regulatory blind spot. Critically, however, whether AI-generated content qualifies as a formal “record” under a company’s retention schedule is largely beside the point once litigation is reasonably anticipated: a legal hold requires preservation of all potentially relevant information, regardless of its designation in the retention schedule.
Many AI platforms apply rolling default deletion schedules that destroy data within 30 days of creation. OpenAI, for example, automatically deletes ChatGPT conversations and API inputs and outputs from its systems within 30 days of a user’s deletion request or, in some configurations, as a matter of default retention practice. As a result, content can be permanently destroyed before a company appropriately issues and applies a legal hold. That potential problem is compounded by the fact that AI outputs are frequently generated outside corporate systems entirely, through public chatbots, browser-based tools, or personal accounts, often in violation of company policy. This creates visibility gaps that traditional IT-driven retention schedules may not be designed to address yet.
II. The Scope of Discoverable “Documents” May Already Reach AI Artifacts
Federal Rule of Civil Procedure 34(a)(1)(A) defines discoverable material to include “any designated documents or electronically stored information (“ESI”)—including writings, drawings, graphs, charts, photographs, sound recordings, images, and other data or data compilations—stored in any medium from which information can be obtained.” Fed. R. Civ. P. 34(a)(1)(A). And, increasingly, litigants are relying on this Rule to seek discovery of opposing parties’ AI prompts, model outputs, conversation logs, and related data compilations.
Recent litigation confirms that at least one court has treated AI-generated content as discoverable ESI subject to preservation obligations. In the consolidated copyright litigation against OpenAI, a United States Magistrate Judge for the Southern District of New York ordered OpenAI to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis until further order of the Court.” The court’s order encompassed data “whether such data might be deleted at a user’s request or because of ‘numerous privacy laws and regulations’ that might require OpenAI to do so.” See In re: OpenAI, Inc., No. 25-md-3143 (SHS) (OTW), 2025 WL 1442678, at *1 (S.D.N.Y. May 13, 2025). The order arose after the court learned that OpenAI had been deleting output log data, which was reportedly consistent with its standard retention practices, and that “the volume of deleted conversations is significant.” Notably, the output log data at issue was directly relevant to the plaintiffs’ claims regarding how ChatGPT processes and generates content. In addition, the court’s willingness to order preservation even where the deletions appeared to follow OpenAI’s existing retention policy underscores that routine data management practices do not excuse a failure to preserve once a legal hold obligation has attached.
Rule 34 requires production of ESI within a party’s “possession, custody, or control,” without a stated exception for AI-generated or AI-processed data. Fed. R. Civ. P. 34(a)(1). Given the relatively recent advent of generative AI, it is not surprising that no provision of the Federal Rules distinguishes between data generated by human authors and data generated through interaction with an AI system. A party’s obligation to preserve and produce relevant ESI may extend to AI artifacts just as it does to any other ESI.
That said, courts might apply Rule 34 differently to companies that simply use or license AI tools for use in day-to-day work, as opposed to the OpenAI MDL, where the defendant developed, created, and owned the specific AI tool at issue. Most companies that simply license or use AI tools without substantial modification to those tools may be viewed as more distant from the necessary “possession, custody, or control” of data within an AI tool. In those more common scenarios, the OpenAI MDL may be ripe for Rule 34 distinction.
III. Sanctions Exposure Under Rule 37(e)
The failure to preserve AI-generated content that is (or should be) subject to a legal hold could expose litigants to sanctions under Federal Rule of Civil Procedure 37(e), which governs the loss of electronically stored information that should have been preserved in the anticipation or conduct of litigation. Rule 37(e)(1) authorizes a court to order curative measures “no greater than necessary to cure the prejudice” upon a finding that ESI “that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it” and “cannot be restored or replaced through additional discovery.” Fed. R. Civ. P. 37(e)(1).
Though courts do not appear to have yet grappled with what steps are reasonable in the AI world, some have warned against treating some inherently more temporary ESI differently than electronic records for preservation purposes. Where the court additionally finds that a party “acted with the intent to deprive another party of the information’s use in the litigation,” Rule 37(e)(2) permits more severe sanctions, including an adverse inference instruction, dismissal of claims, or entry of default judgment. Fed. R. Civ. P. 37(e)(2).
Spoliation encompasses not only the active destruction of evidence but also the negligent or reckless failure to preserve information once a duty to preserve has been triggered. The duty to preserve arises when a party knows or reasonably should know that litigation is on the horizon. That duty may be triggered, for example, on receipt of a claim letter, demand, or even a cease and desist letter in certain contexts. Given the default deletion schedules employed by AI platforms, where data may be permanently destroyed within 30 days, the window between trigger of the preservation obligation and irreversible data loss is dangerously narrow. Companies that fail to intervene promptly to halt automatic deletion of AI-generated content risk a finding that they did not take “reasonable steps to preserve” that information within the meaning of Rule 37(e). When, precisely, a duty attaches and whether ensuing steps are reasonable are entirely context-driven and difficult to boil down to a pinpoint rule. By way of example, however, if a company has been notified that it is being sued for price fixing and its employees use an AI tool to develop algorithms for price modeling, it may be wise to preserve that tool’s ESI.
IV. Third-Party AI Vendors: Distinguishing What Is Actually in the Company’s Control
The “possession, custody, or control” standard of Rule 34(a)(1) extends discovery obligations beyond documents a party physically holds to include documents the party has the legal right or practical ability to obtain. Fed. R. Civ. P. 34(a)(1). This principle has direct application to AI-generated data held by, or generated and created on behalf of a company by, third-party vendors.
If a company maintains a contractual right to access, export, or retrieve its usage data from an AI vendor, that may be within the company’s “control” for purposes of its discovery obligations. The In re: OpenAI litigation illustrates the practical complexity of this issue. OpenAI represented to the court that “a fraction of ChatGPT Free, Pro, and Plus conversations … have not been retained” as a result of its “default” policy of retention. OpenAI responded by citing user privacy preferences and “numerous privacy laws and regulations throughout the country and the world” as justification for its deletion policies. Nonetheless, the court ordered preservation, signaling that a vendor’s internal deletion practices may not relieve the parties of their obligations to hold responsive data whenthat preservation duty arises in response to actual or likely litigation.
To be sure, In re: OpenAI’s lesson came in the context of a suit against the creator of ChatGPT, not a company that merely licenses it. But its lesson may well extend to the latter context. Data that resides on a vendor’s server does not fall outside the scope of a company’s preservation obligations. Where contractual terms permit data retrieval, export, or extended retention, or where a company has the practical ability to request that a vendor suspend its default deletion schedule, a court may well conclude that the data is within the company’s control. OpenAI itself acknowledged that enterprise customers and customers who choose “zero-data-retention” plans operate under different data handling frameworks where the customer controls retention. This distinction further underscores that the allocation of control is a fact-specific inquiry that turns on the contractual and operational relationship between the company and its AI vendor.
V. Practical Takeaways
In light of the developments described above, clients may consider certain steps to align information governance practices with their company’s AI usage in this ever-evolving landscape.
First, legal hold notices and company policies, including litigation hold policies, records retention policies, and records retention schedules, should be updated to establish retention standards for AI prompts, outputs, chat logs, and associated metadata. Standard hold notices that reference only email, documents, and traditional databases may fail to capture AI-generated content. Given that AI platforms such as ChatGPT automatically delete data within 30 days absent affirmative intervention, hold procedures must be designed to operate within that compressed timeline.
Second, companies should establish a comprehensive AI acceptable use policy governing employee interactions with AI tools. This policy, which may be standalone or integrated into an existing employee handbook, should specify which AI platforms are approved for business use, define the types of information that may and may not be input into AI systems, and make clear that use of unsanctioned AI tools with company data may constitute a data breach. By establishing clear guardrails, companies create an enforceable framework that supports both information security and downstream preservation obligations.
Third, companies should conduct an assessment of all AI tools in use across the organization. This assessment should catalog approved enterprise AI deployments and, to the extent possible, identify unsanctioned consumer-tier use by individual employees. Even data generated through free consumer accounts may be subject to preservation and discovery obligations, so understanding which AI tools are in use is a critical first step.
Fourth, companies should review their contractual relationships with AI vendors to determine whether they possess the legal right to retrieve, export, or direct the preservation of their usage data. Where such rights exist, the company’s preservation obligation likely extends to that vendor-held data under the “possession, custody, or control” standard of Rule 34(a)(1). Companies may also consider the inclusion of their standard data retention policies in contracts with AI vendors so as to ensure company-wide consistency in preservation. Even beyond AI-specific vendors, companies should review their broader vendor agreements to ensure appropriate protections are in place, including provisions prohibiting vendors and their personnel from inputting company data into unapproved AI platforms, which could constitute a data breach and create additional preservation complications.
Finally, companies should provide employees with AI training, which may include specific guidance regarding how AI work product may fall within the scope of a legal hold. Employees should understand that conversations with AI chatbots, prompts submitted to AI assistants, and outputs generated by those systems may constitute discoverable ESI that must be preserved when a hold is in effect.
Courts have demonstrated a willingness to order preservation of AI output data even over objections grounded in privacy law, platform design, and practical burden. Companies that fail to adapt their preservation practices to the realities of generative AI risk possible sanctions, from adverse inferences, to the loss of otherwise meritorious claims or defenses.
VI. Conclusion
In light of these developments, companies may consider: (1) reviewing existing retention policies and legal hold procedures to analyze whether they adequately account for AI-generated content; (2) establishing a comprehensive AI acceptable use policy governing employee interactions with AI tools; (3) conducting an assessment of AI tools in use across the organization to identify preservation risks; (4) evaluating contractual rights to retrieve or preserve data held by third-party vendors; and (5) providing employees with targeted training on how AI-generated work product may fall within the scope of a legal hold.
McGuireWoods’ AI Practice Group is available to assist clients with any questions regarding preservation obligations for AI-generated data, updates to records retention and legal hold procedures, or vendor contract review.
The authors thank McGuireWoods summer associate Destiny Washington for assistance preparing this article. She is not licensed to practice law.