Records Retention Hasn’t Caught Up to AI

Most organizations have spent years building retention schedules around a familiar set of record types: project docuents, contracts, financial records, HR files, correspondence. These schedules reflect how work used to get created. They don’t reflect how work gets created now, and the gap between the two is wider than most governance programs have acknowledged. The current state AI tools are embedded in day-to-day work across most organizations, whether or not that use is formally sanctioned. Employees draft with them, summarize with them, analyze with them, and generate first-pass output with them. Every one of those interactions creates content: prompts, draft outputs, revised outputs, chat logs, and in some cases entire training or fine-tuning datasets. None of that maps cleanly onto a retention schedule built for a pre-AI world. Most schedules have no category for an AI prompt. Few define whether a model’s output is a business record, a transitory draft, or something in between. Almost none address what happens when the same piece of content exists in three or four states: the prompt, the raw output, the edited draft, and the final version that gets used. That ambiguity doesn’t resolve itself. It just gets pushed down to whoever happens to be using the tool that day. Why an AI-generated draft isn’t the same as a human draft Traditional records management has a clear, well-established answer for drafts: they’re transitory. Once the final contract is signed, the final policy is issued, or the final report is published, earlier drafts are considered to have no ongoing business, legal, or regulatory value, and most retention policies call for them to be deleted. That’s the right approach, and it has been for decades. A human draft is evidence of a person’s thinking in progress. Once the decision is made, preserving every prior iteration of that thinking adds volume without adding value. An AI-generated draft breaks that logic in a specific way. A human draft documents a person’s judgment as it evolves. An AI-generated draft documents what a system produced, independent of any person’s judgment. Once someone edits that output into a final record, the final record shows what was decided, but it doesn’t show what the AI actually generated, how far a person had to depart from it, or whether meaningful review happened at all. That distinction matters the moment the question stops being “what did we decide” and becomes “did the AI system behave appropriately, and did a person actually exercise oversight before relying on it.” That second question is coming up more often, not less. Regulators, courts, and increasingly customers want to know whether an AI system had a hand in producing a record and whether a person reviewed its output before it became final. If the original AI-generated draft has already been deleted on the same schedule as a human’s rough draft, the organization has no way to answer that question, regardless of how sound the final record turns out to be. None of this means every AI-touched draft becomes a permanent record. It means the retention decision must be made deliberately, based on how much weight the AI’s output carried and how consequential the final decision was, rather than defaulting to the disposal timeline built for a person’s private working notes. The observation This isn’t a failure of the retention schedule itself. Most schedules are reasonably well built for the record types they were designed to cover. The gap is that AI-generated and AI-assisted content was never in scope when those schedules were written, and very few organizations have gone back to close that gap. That creates a familiar pattern for anyone who has worked in information governance: policy defines the rules, and the underlying data has moved on without it. Why this matters The implication shows up first in litigation and regulatory response. Discovery requests and regulatory inquiries increasingly ask specific questions about AI use: what tool was used, what prompt was entered, what the output was, and whether that output was reviewed before it informed a decision. Governance programs that haven’t defined AI content as a record type struggle to answer those questions consistently, because the underlying content was never captured, classified, or retained with intent. The default response tends to fall into one of two failure modes. Some organizations retain everything, because no one has made a decision about what to delete, which increases the volume of discoverable material and the associated risk. Others delete inconsistently, department by department or tool by tool, which creates exactly the kind of defensibility gap that regulators and opposing counsel look for. What to do Closing this gap doesn’t require rebuilding the retention schedule from scratch. It requires extending it deliberately. Add AI-generated and AI-assisted content as an explicit category in the retention schedule, with clear definitions for prompts, outputs, and revised drafts rather than leaving that distinction to individual judgment. Establish a standing review, ideally quarterly, between records management and whoever owns AI tool governance, so classification keeps pace as new tools are adopted. Extend legal hold and e-discovery protocols to name AI interaction logs specifically, rather than assuming existing email and document holds will capture them. Assign clear ownership for this category the same way ownership exists for financial records or HR files, so the schedule doesn’t just describe good intentions. And set a deliberate rule for AI-generated drafts tied to how consequential the decision is, rather than applying the standard human-draft disposal timeline by default, particularly for content that informs legal, regulatory, HR, or financial decisions. The information you obtain at this site, or this blog is not, nor is it intended to be, legal or consulting advice. You should consult with a professional regarding your individual situation. We invite you to contact us through the website, email, phone, or through LinkedIn.