A forensic expert hired by 3M used ChatGPT to craft his analysis in a product liability case involving the Watson Grinding explosion, including at least one prompt instructing the system to "show how 3M is 0% at fault." When opposing counsel questioned the expert during his deposition, the session paused while the plaintiffs' attorney demanded access to the underlying AI conversations. Roughly three hours later, more than 350 pages of previously undisclosed ChatGPT material were handed over. The incident, detailed in a CSO Online analysis by cybersecurity governance expert, reveals that companies focused on preventing sensitive data from entering AI tools may be overlooking a second risk: the permanent record those interactions create.
For years, corporate AI governance has centered on inputs—blocking employees from uploading proprietary code, customer information, personally identifiable data, or intellectual property into public AI platforms. That approach protects confidential material from leaving the organization but ignores what happens to the conversation itself. An engineer could use an AI assistant to compare two technical approaches while repeatedly adjusting assumptions until the preferred option appears superior. A procurement analyst might ask the system to build the strongest case for a vendor who's already been informally selected. A manager could generate documentation for an employment decision after the fact, or a compliance officer might keep revising prompts until a control weakness reads as less severe. None of these scenarios require the AI to malfunction—the technology performs exactly as designed while capturing assumptions, rejected alternatives, and lines of inquiry that never surface in the polished final output.
The author notes that a single prompt taken out of context can mislead, since people often use AI to test arguments or challenge their own thinking. But the full interaction history can provide evidence about how an analysis evolved that the finished document alone doesn't reveal. The American Bar Association has already examined AI chat histories as emerging discovery material, in part because those conversations preserve questions and abandoned theories that never reach the final work product. According to the analysis, most organizations haven't decided when to retain AI interaction evidence, who owns it, or how to govern it. Even basic features like ChatGPT shared links—which allow anyone with the URL to view the associated conversation—illustrate how information created in what feels like a private workspace can become accessible elsewhere through standard product functions.
The report argues that organizations shouldn't preserve every AI prompt indefinitely, which would create its own privacy, security, and operational risks. Instead, the consequence of the work should drive the governance level. An employee asking AI to clarify an email shouldn't face the same scrutiny as an engineer using AI for safety analysis, an auditor evaluating controls, or an executive relying on AI for major business decisions. For higher-risk uses, organizations may need to retain enough provenance to reconstruct what happened: the material prompts and outputs, the AI system used, evidence of meaningful human review, and sufficient context to understand how AI shaped the final decision. That requires clear ownership across technology, records management, legal, security, and compliance teams—not just IT or legal working in isolation.
The analysis recommends that organizations think backward from a future investigation: if a decision were challenged six months or a year later, could the company establish what information was available, what role AI played, what the human accepted or rejected, and who ultimately owned the decision? A New York court recently rejected an effort to obtain a litigant's ChatGPT records, finding the material was protected legal research—but that uncertainty shouldn't encourage companies to ignore the issue. The report concludes with a test question every organization using AI in consequential work should answer: if this decision were challenged a year from now, could we reconstruct how it was actually made? The governance challenge is no longer confined to whether someone used an approved model or entered prohibited data—companies also need to understand what evidence the interaction itself can create. For most enterprises, the gap between their data-loss prevention policies and their AI conversation retention practices represents an unmanaged liability that litigation or regulation will eventually force into the open.

