It's getting hard to find an industry that isn't racing to adopt artificial intelligence, especially generative tools that summarize documents, search internal repositories, draft content, and speed up routine work. The business case is compelling. AI supports greater efficiency, faster access to information, and new ways to leverage existing data.
All that adoption raises a practical question many organizations have not had time to answer: what is happening to the information these tools create, retain, overwrite, delete, or leave behind? Much of it is built to disappear, or at least to survive somewhere the organization did not expect. Records management can be an admittedly unglamorous pursuit. Ignoring it, though, is an expensive one.
Organizations have traditionally divided information governance among privacy, records management, compliance, security, IT, and legal. AI makes those divisions harder to maintain because a single use case can implicate all of them at once.
Consider an enterprise generative AI assistant connected to internal contracts, policies, employee information, customer data, and business records. Employees may use the tool to ask questions, generate summaries, prepare reports, or identify recommendations. Each interaction may involve user prompts, retrieved source materials, AI-generated outputs, system logs, metadata, access controls, and potentially records of human review or approval. That is a substantial evidentiary footprint for a tool most users experience as a chat window.
We have written separately about how AI transcripts can complicate privilege, become publicly accessible through share links, and preserve unusually organized evidence of strategy and intent. The broader records management question is which parts of that footprint should exist, for how long, and under whose control.
The same deployment raises several questions at once: whether the data may be processed for the intended purpose; whether access is appropriately restricted; which prompts, outputs, logs, source references, and approval records should be retained; and what evidence is needed to demonstrate testing, authorization, human review, and ongoing oversight. These questions arise from the same AI deployment and often involve the same information assets. Treating them as separate workstreams can create gaps, inconsistency, and unnecessary risk.
One of the most significant challenges is that traditional record retention policies were built around relatively familiar assumptions about discrete documents, identifiable authors, known storage locations, and established retention schedules. AI systems are cheerfully indifferent to that model. They can generate, transform, summarize, and recombine information continuously. They often rely on data drawn from multiple repositories. They may produce outputs that influence business decisions without clearly fitting into existing record categories. And they frequently operate through vendors or cloud environments where key information is not retained by default or is retained in forms the organization does not readily control.
Many AI tools are designed to reduce data retention, limit storage, or avoid keeping prompts and outputs longer than necessary. Those design choices may support privacy, security, and data minimization goals. But they can also conflict with legal, regulatory, contractual, or litigation-driven retention obligations. So, what happens when the output that drove a business decision doesn't exist, because it was never kept in the first place? If an AI-generated recommendation later becomes relevant to an investigation, regulatory inquiry, customer dispute, employment matter, or litigation hold, an organization may need to know what was generated, what data informed it, who reviewed it, and what decision followed.
Not every prompt, output, log entry, or intermediate system event is a record that must be retained. If that information was never retained, was overwritten, or sits with a vendor under unclear access rights, the organization may face avoidable defensibility challenges. “We no longer have it” is an answer. Whether it is a defensible one depends on what happened before the sentence was spoken.
Legal, privacy, compliance, records management, security, IT, and business stakeholders should work together to evaluate how AI tools create, use, store, and dispose of information. Cross-functional governance does not require another box on the organizational chart. It requires the existing boxes to agree on what the system creates, who controls it, and when it disappears.
AI governance is often discussed in terms of models, algorithms, and regulation. Those issues matter, but governance also depends on information moving into, through, and out of the system. An organization that cannot identify what its AI tools create, where that information resides, who controls it, or whether it can be preserved does not have full visibility into the system it claims to govern.
The goal is not to retain everything. It is to make ephemerality a decision the organization can defend. Align the policies, classify the information, test the preservation process, and secure the necessary vendor rights before a dispute, investigation, or audit does the testing instead. A litigation hold is much easier to honor when there is something left to hold.
For questions about AI governance program design, records retention strategy, or information governance readiness, contact the Jones Walker Privacy, Data Strategy, and Artificial Intelligence team. Stay tuned for continued insights from the AI Law and Policy Navigator.
