Litigation Holds and eDiscovery: When Your AI Chat Logs Are Subpoenaed
A retention schedule tells your organization when records may be destroyed in the ordinary course of business. A litigation hold is the moment that schedule stops applying. This article starts at that moment, and asks the question most nonprofits have never worked through: when a preservation duty attaches, what exactly happens to the prompts, outputs, transcripts, retrieval indexes, and agent logs your AI tools have been quietly accumulating.

This article is general information for nonprofit leaders, not legal advice. Preservation obligations turn on the specific facts of a dispute, the forum it lands in, and the law of your jurisdiction, and every decision described here belongs to your counsel. The purpose of reading it before anything happens is narrower and more useful: so that when your attorney calls and asks what systems hold potentially relevant information, you can answer in a day rather than a month, and so that nothing has already been deleted by a setting nobody remembered was on.
We have written separately about building a retention schedule that covers AI meeting notes and chat logs, which is the routine, peacetime half of this problem: deciding which AI-generated artifacts are records, how long each category should live, and who owns the decision. That article ends where this one begins. Retention is a policy you administer on your own timetable. Preservation is an obligation imposed on you by circumstances, often before you have been sued, and it overrides the schedule entirely for the information it touches.
The reason this now needs separate treatment is that the record surface has changed shape. Five years ago, a nonprofit facing an employment claim had email, a shared drive, a database, some text messages, and paper. Today the same organization may also have a year of staff conversations inside a chatbot account, transcripts of every program meeting captured by a notetaker, a retrieval index built from internal documents, an agent that took actions in a CRM and logged them somewhere, and a vendor tenant holding most of it under a retention window the organization never chose. Courts have already begun treating AI conversation data as electronically stored information subject to preservation orders, including an order in the Southern District of New York directing a major model provider to preserve output log data that would otherwise have been destroyed under a default deletion policy.
What follows walks through when the duty attaches, what a hold notice does and who must receive it, the specific scope problems AI tools introduce, the sanctions framework in Federal Rule of Civil Procedure 37(e), how proportionality and the Rule 26(f) conference shape what you actually have to produce, the discoverability of prompts and AI drafts, the privilege complications, the vendor questions that belong in a contract rather than in a crisis, and the preparation a small organization can realistically do in advance. Two statements run through all of it. Once a hold is live, counsel directs the process. And deleting something after a trigger is the worst available outcome, worse in practice than having produced it.
The Duty Attaches Before Anyone Serves You
The most common and most expensive misunderstanding in this area is the belief that the obligation to preserve begins when a complaint arrives. It does not. The duty to preserve attaches when litigation is reasonably anticipated, and the text of the governing federal rule is written in exactly those terms. Rule 37(e) addresses information "that should have been preserved in the anticipation or conduct of litigation," which places anticipation ahead of conduct and makes clear that the obligation can exist well before a case number does. Whether the standard was met in a given situation is judged after the fact, with hindsight, against what the organization knew and when it knew it.
In practice, triggers arrive in forms that do not look legal at the time. A demand letter from an attorney representing a former employee. A credible verbal threat in an exit interview. An administrative charge filed with a state civil rights agency or the Equal Employment Opportunity Commission. A regulator's inquiry letter. A subpoena in someone else's case that reveals your organization's involvement. A serious injury on your premises or at your program, where a claim is foreseeable even if nobody has made one. An internal complaint alleging conduct that, if true, would plainly be actionable. A board member stating in a meeting that the organization intends to sue a vendor, which triggers the duty just as surely as being sued does, because a party planning to initiate litigation anticipates it by definition.
The practical difficulty for nonprofits is that these signals usually land on someone with no legal training and no mandate to escalate. A program director receives the angry email. The development associate takes the call. The HR coordinator, who may be the finance director wearing a second hat, hears something in a meeting and files it mentally under difficult conversations. Nobody tells counsel, nobody tells IT, and the organization's systems keep doing what they were configured to do, which is to delete things on a schedule. Months later, a lawyer has to explain why a conversation thread from the relevant week no longer exists.
The single highest-value piece of internal plumbing you can build, and it is genuinely cheap, is a written escalation rule: anyone in the organization who receives a demand, a threat, an agency notice, a subpoena, or a complaint of a kind the policy names must forward it the same day to one or two designated people, who contact counsel. One named path, one named recipient, no judgment required from the person who received it. The judgment about whether the duty has attached is a legal determination that belongs to your attorney, and the only thing you want your staff to do is get the information in front of someone who can make it.
Signals that commonly mean counsel needs to hear about it today
Not legal conclusions, just the escalation triggers worth naming in a policy
- A demand letter, attorney correspondence, or a credible threat to sue, including from a volunteer or participant
- Any agency charge, investigative inquiry, audit notice, or subpoena, including one in a matter involving someone else
- A serious incident where a claim is foreseeable, whether or not anyone has made one
- An internal complaint or whistleblower report alleging conduct that would be actionable if substantiated
- A decision by your own organization to pursue a claim against a vendor, funder, employee, or partner
What a Hold Notice Does, and Who Has to Receive One
A litigation hold, also called a legal hold, is a written instruction issued under counsel's direction telling specified people inside the organization that they must preserve information relating to an identified matter, and that routine deletion of that information must stop. It is not a filing, it goes to no court, and in most matters the other side never sees it. Its function is practical and evidentiary at once: it actually stops the loss of information, and it demonstrates afterward that the organization took reasonable steps, which is precisely the question Rule 37(e) asks.
A notice that works tends to share a short list of features. It identifies the matter in plain language, states the subject matter and the relevant time period concretely enough that a program coordinator can tell whether a given document is in scope, and lists the categories and systems covered rather than gesturing at relevant documents. It instructs recipients to suspend any personal deletion habits and not to edit, reorganize, or clean up anything in scope, including seemingly harmless tidying. It names a single person to ask questions of, which matters enormously in a small organization where people will otherwise guess. It requires written acknowledgment. And it stays in force until counsel releases it in writing, because an unreleased hold that everyone has quietly stopped observing is nearly as bad as no hold at all.
Who receives it is where organizations most often get the scope wrong, and AI tools make the error easier. The notice goes to the custodians who hold or generate potentially relevant information, which is the obvious cast of characters in the dispute, plus the people who administer the systems where that information lives. In a nonprofit, the second group is routinely overlooked because it is often one part-time IT contractor, a database administrator who is really the operations manager, and whoever happens to be the billing owner on the AI subscription. That last person matters more than their job title suggests: in many small organizations, the only human with the administrative access needed to suspend a retention setting or export a workspace is the person whose credit card set up the account.
Acknowledgment tracking is the unglamorous mechanical half. Counsel needs a record of who received the notice, when, who confirmed, and who was chased. Departing employees need a step in the offboarding process that preserves their accounts and devices rather than wiping and reissuing them, which is the default in most organizations and the source of a great deal of avoidable loss. New staff who inherit a role in scope need the notice too. Periodic reminders keep a hold alive through the many months a matter can take, and in a sector with high turnover and heavy use of part-time and contract staff, reissuing the notice at intervals is not bureaucratic excess. It is how you keep the hold true as the roster changes.
Custodians a small nonprofit forgets
People who hold AI-related records without being central to the dispute
- The billing or administrative owner of each AI subscription, who may be the only person able to change a retention setting
- Your outsourced IT provider, managed service vendor, or volunteer technologist
- Contractors, consultants, and fractional staff who used AI tools on your work, sometimes in their own accounts
- Board members and committee volunteers who used a notetaker or a chatbot for organizational business
- Recently departed staff whose accounts and devices are queued for deletion or reissue
The Scope Problem: Where AI Records Actually Live
Traditional eDiscovery scoping asks where the email, files, messages, and database records are. AI tools add a set of record types that are easy to miss because they do not resemble documents, are not stored where documents are stored, and are frequently held under a vendor's settings rather than yours. The Sedona Conference, whose working group commentaries are a standard reference point for practitioners in this field, has been explicit in draft guidance that the people writing hold notices and discovery agreements should treat generative AI information as a data source subject to discovery obligations rather than an afterthought.
Start with the obvious layer and keep going. Prompts and outputs in a chatbot account are the headline item, and in an organization that adopted a general assistant two years ago they may represent thousands of conversations touching personnel matters, donor questions, program decisions, and draft communications. Underneath that sit the configured system instructions and custom assistants, which are themselves potentially relevant because they show what the tool was told to do and how it was shaped. Then the retrieval layer: if you have connected a model to your document store or built a custom assistant over internal files, there is an index, often a vector store, derived from your own documents, and there may be a log of which documents were retrieved in response to which question. Meeting transcription archives are their own large category, and we have treated the ownership and access questions they raise in our article on who owns the transcript.
Then the newer layers. Agent action logs, where a tool did something in another system rather than producing text, are high-value evidence in exactly the disputes where they are hardest to find, because the log may live with the agent platform, with the target system, or in neither. Model and prompt version history matters whenever the question is why the organization got the answer it got on a particular date, since a change to a system prompt or a silent model upgrade can make an output irreproducible. The governance side of that is covered in our pieces on AI audit trails for compliance and agent governance for nonprofit boards, and both become suddenly concrete when a lawyer needs to reconstruct a decision.
Two categories deserve specific attention because they create the most trouble. The first is data sitting in a vendor's tenant rather than yours. Information held by a third party is generally not in your possession or custody, yet courts widely treat cloud-hosted data as within a party's control where the party has the practical right to obtain it on request, and control is what the discovery rules turn on. It is not an answer to say that the records belong to the vendor. The second is work done in employees' personal accounts. A staff member who used a personal chatbot subscription to draft a difficult donor email, or a board member who ran a free notetaker on a committee call, has created organizational records in a place your administrators cannot see, cannot preserve, and cannot export. This is a governance failure before it is a discovery problem, and it is the strongest practical argument for the kind of written tool boundaries described in our guide to an AI acceptable use policy.
AI record categories to map
Each one needs a system, an owner, and a retention answer
- Prompts, outputs, and full conversation threads in every chatbot account
- System instructions, custom assistants, and configuration history
- Retrieval indexes and vector stores derived from your own documents
- Meeting transcripts, recordings, summaries, and action item lists
- Agent action logs, tool call records, and model or prompt version history
Where it sits, and who can reach it
Control, not ownership, is the question the rules ask
- Your own managed workspace, where an administrator can preserve and export
- A vendor tenant you can request data from but not administer directly
- A subprocessor behind your vendor, whose retention you may not be told about
- Staff, contractor, and board members' personal accounts and devices
- Free consumer tiers with no administrative console and no export path
Auto-Deletion Is a Setting Until the Day It Becomes Spoliation
Most AI tools delete things by default, and for ordinary privacy reasons that is often a sensible configuration. Short retention windows limit exposure in a breach, keep sensitive material from accumulating, and reduce the volume of stale data nobody is governing. A nonprofit that set its notetaker to purge transcripts after thirty days, or turned on a ninety-day conversation expiry in its assistant, probably made a defensible privacy decision. The problem is that the same setting, left running after a preservation duty has attached, becomes a mechanism that destroys evidence automatically, at scale, while everyone believes the organization is behaving responsibly.
The federal framework that governs what happens next is Federal Rule of Civil Procedure 37(e), amended in 2015 to replace a patchwork of inconsistent circuit standards. Its opening condition is a three-part test. The rule applies where electronically stored information that should have been preserved in the anticipation or conduct of litigation is lost because a party failed to take reasonable steps to preserve it, and it cannot be restored or replaced through additional discovery. All three elements matter. If the information was never within the preservation duty, the rule is not engaged. If the organization took reasonable steps and lost it anyway, the rule is not engaged. And if a copy exists somewhere else, in a colleague's export, in an attachment, in the output pasted into a document, the loss may be curable without any finding at all.
Where the test is satisfied, the rule splits into two very different tiers. Under subsection (e)(1), on finding prejudice to another party from the loss, a court may order measures no greater than necessary to cure the prejudice. That is a deliberately modest remedy: additional discovery at your expense, permission for the other side to present evidence about the loss, cost shifting, an adjusted schedule. Under subsection (e)(2), only on finding that the party acted with the intent to deprive another party of the information's use in the litigation, the court may presume the lost information was unfavorable, instruct the jury that it may or must presume as much, or dismiss the action or enter default judgment. The severe sanctions are gated on intent, not on carelessness, which is the single most important structural feature of the rule and the reason the Federal Judicial Center's summary of the 2015 amendment is worth ten minutes of a board member's time.
Read that structure carefully, because it tells you what to do and what never to do. An organization that discovers after a trigger that an auto-deletion setting ran for three weeks and purged some conversations is in the territory of reasonable steps, prejudice, and curative measures, which is survivable and frequently survived. An organization that turns a deletion setting on after a trigger, shortens a retention window, bulk-deletes a conversation history, or quietly reconfigures an export has moved toward the intent analysis, and that is a categorically worse place to be. There is also a criminal dimension that nonprofits specifically should know about. Two provisions of the Sarbanes-Oxley Act apply to nonprofit organizations, and one of them concerns the destruction of records in contemplation of a federal investigation or proceeding, which is why the National Council of Nonprofits treats document destruction policy and whistleblower protection as paired governance obligations rather than separate ones.
The operational lesson is simple to state and requires advance work to deliver. The moment counsel says a duty has attached, someone must be able to walk the list of AI systems and suspend deletion in each. That means knowing the list, knowing who has the administrative rights, and knowing whether suspension is even possible in each tool, which for some consumer tiers it is not. The time to discover that a product has no hold capability is during procurement, not during a dispute.
The hierarchy of outcomes, worst last
Why a prompt, imperfect preservation effort beats a tidy one
- Best: deletion suspended across every AI system within days of the trigger, with the steps documented
- Recoverable: some loss to a default setting before anyone realized, disclosed promptly to counsel
- Difficult: no hold issued at all, systems left running on their default retention for months
- Worst: anything deleted, shortened, or cleaned up after the trigger, by anyone, for any stated reason
- If you think something may already have been lost, that is a conversation to have with counsel immediately, not a problem to solve quietly
Rule 26(f), Proportionality, and the Conversation About Your AI Tools
Preservation is broad on purpose, because at the moment a duty attaches nobody yet knows what will matter. Production is narrower, and the mechanism that narrows it is the discovery process itself. Under Federal Rule of Civil Procedure 26, the parties confer early about the case, and the 2006 amendments specifically direct that conference to address discovery of electronically stored information. The scope rule in Rule 26(b)(1) then limits discovery to nonprivileged matter relevant to a claim or defense and proportional to the needs of the case, a formulation the 2015 amendments made explicit so that relevance alone would no longer settle the question.
Proportionality is the provision that matters most to small organizations, and it is worth understanding what it does and does not do. It weighs the importance of the issues, the amount in controversy, the parties' relative access to information, their resources, the importance of the discovery to resolving the issues, and whether the burden or expense outweighs the likely benefit. A nonprofit with a three-person administrative team and a modest budget facing a claim over a few months of employment is not in the same position as a corporate defendant, and that asymmetry is a legitimate subject for the Rule 26(f) discussion. What proportionality does not do is reduce the duty to preserve. It shapes what must be searched, reviewed, and produced after preservation, and arguing burden is your counsel's job, done on the record, not a reason to let a retention setting keep running.
AI records put several concrete items on the agenda for that early conference. Which AI systems the organization used in the relevant period, and which are even capable of being searched or exported. Whether prompts and outputs will be produced in native form, as exported threads, or as some agreed extraction, since a conversation is not a document and the format question has real consequences for cost and readability. Whether a retrieval index or vector store needs to be addressed at all, given that it is derived from source documents that are themselves being produced and may be duplicative in substance while being enormously burdensome in form. Whether transcripts and recordings are both in scope or one stands in for the other. How metadata will be handled for records whose timestamps live in a vendor's system. And whether anything is reasonably inaccessible, a category the rules recognize and which can genuinely apply to log data a vendor retains in a form nobody can usefully query.
None of this is something a nonprofit executive negotiates personally. The value in understanding it is that these discussions go much better when the client can answer basic factual questions quickly and accurately. An organization that hands its counsel a current list of AI systems, what each holds, who administers it, what its retention setting is, and whether it can export, has given its lawyer the raw material to make a proportionality argument. An organization that cannot describe its own tooling will find the scope being set by someone else's assumptions, and those assumptions are rarely generous.
Facts to have ready for counsel
The answers that make a proportionality argument possible
- Every AI tool in use during the relevant period, including trials, free tiers, and tools used by contractors
- What each one stores, for how long, and under whose settings
- Whether each tool can suspend deletion, search by date or user, and export in a usable format
- Which records duplicate material already available in email, files, or your database
- An honest account of your staffing and budget constraints, with specifics rather than general pleading
Are Prompts and AI Drafts Business Records?
Staff often assume that a chatbot conversation is more like thinking out loud than like writing a memo, and that assumption shapes behavior in ways that matter later. People type things into a prompt box they would never put in an email: candid assessments of a colleague, speculation about why a grant was pulled, blunt descriptions of a participant, half-formed theories about an incident. The mental model is a scratchpad. The legal model is closer to a document stored on a company system, which is what it is.
Discoverability does not turn on whether your retention schedule calls something a record. It turns on whether the material is nonprivileged, relevant to a claim or defense, within your possession, custody, or control, and proportional to the needs of the case. A prompt in which a manager describes an employee's performance in terms that contradict the written evaluation is relevant in an employment dispute whether or not anyone ever classified chatbot conversations as records. An output the organization relied on in making a decision is relevant to how that decision was made. A thread showing that a draft donor communication was generated and then altered may be relevant to a misrepresentation claim. Courts have shown no particular difficulty treating this category as electronically stored information, and the 2026 litigation over model providers' own conversation logs has made the point in public.
There are harder questions underneath the easy one, and they are genuinely unsettled rather than merely unfamiliar. Whether a retrieval index that encodes your documents in numerical form is itself discoverable, or whether producing the underlying documents suffices, is the kind of issue that will be worked out in ESI protocols and motions over the next several years. Whether a model's intermediate reasoning, where a tool exposes it, is a record of anything the organization did is similarly open. Whether an output nobody ever read or relied on is relevant in the same way as one that drove a decision is a question of fact in each case. These are not questions a nonprofit answers unilaterally, and the appropriate posture is to preserve broadly and let counsel argue scope later, rather than to resolve the ambiguity in your own favor by deleting.
The practical consequence is a training point rather than a technical one, and it should be in every organization's AI onboarding. Anything typed into an organizational AI tool should be written as though it may be read later by someone adverse to you, because it may be. That is not a reason to use AI less. It is the same discipline every competent professional already applies to email, extended to a surface where the informality of the interface has misled people into dropping it. Our article on AI notetakers in nonprofit meetings makes a parallel argument about transcripts, where the gap between what people think is being captured and what is actually being captured verbatim is even wider.
What makes an AI artifact discoverable
The test is the discovery rules, not your internal classification
- It is relevant to a claim or defense in the matter, which is a low bar in practice
- It is nonprivileged, or privilege over it has been waived or was never properly established
- It is within your possession, custody, or control, including data a vendor holds that you can request
- Producing it is proportional to the needs of the case, which is where burden arguments live
- Whether you labeled it a record, a draft, or a scratchpad is not part of the test
Privilege and Work Product When a Model Touched the File
This is the area where a well-intentioned efficiency move does the most damage, and it happens in nonprofits constantly because legal budgets are tight and staff are resourceful. An executive director receives a letter from counsel analyzing a personnel problem and pastes it into a chatbot to get a plain-language summary for the board. A finance director uploads an attorney memo about a contract dispute and asks for a list of risks. A program manager puts an incident narrative that was prepared at counsel's request into a tool and asks it to tighten the prose. Each action is understandable. Each may have handed privileged material to a third party.
The doctrinal concern is straightforward in outline. Attorney-client privilege depends on confidentiality, and disclosing a privileged communication to a third party can waive it. Entering the contents of a privileged communication into a public generative AI service, where terms permit the provider to retain or use the content, is the kind of disclosure that creates waiver exposure. Work product protection, which covers material prepared in anticipation of litigation, operates on a different waiver standard and is generally lost only through disclosure to an adversary or in a manner that substantially increases the likelihood that an adversary will obtain it, which gives it somewhat more tolerance. Neither protection is self-healing once the content has left the circle of confidentiality, and the analysis depends heavily on the specific terms governing the tool, the configuration of the account, and the jurisdiction.
The professional guidance here has been developing quickly. The American Bar Association's Formal Opinion 512, issued in 2024, addresses lawyers' use of generative AI with confidentiality and informed consent at its center, and bar associations have since published further analysis of how privilege and work product interact with AI tools. That guidance is directed at lawyers, but the practical implication for a nonprofit client is immediate: raise your own AI usage with your counsel rather than assuming it is irrelevant to them, and ask explicitly which tools, if any, are acceptable for material that originated with or was prepared for your attorney.
There is a second, narrower privilege problem that arises during the hold itself. Once a matter is live, people will be tempted to use AI tools to help them think about it, summarize the hold notice, draft a response to a demand, or organize what happened. Those conversations may themselves be in scope, and if they are conducted in a consumer tool they may be both discoverable and outside any protection. The practical rule to put in writing is that matter-related work goes through the channel counsel designates, and that nobody uses an AI tool on the substance of a live dispute without asking first. The surrounding governance question, which tool is approved for what category of information, is the subject of our article on building a data governance policy for AI, and privilege is the clearest example of why the distinctions in such a policy need to be real rather than aspirational.
Privilege hygiene worth writing into policy
Decisions for your counsel, but these are the questions to put to them
- Which AI tools, if any, counsel considers acceptable for material that came from or was prepared for them
- A plain instruction that attorney correspondence does not get pasted into a consumer tool
- A rule that AI use on the substance of a live matter is cleared with counsel first
- Disclosure to counsel of any past instance where privileged material went into a tool, early rather than late
- A review of which account tiers and contract terms govern retention and use of your inputs
The Vendor Problem: Can They Actually Hold and Export?
Here is the question that decides whether everything above is theory or practice. When your counsel tells you to suspend deletion in your AI tools and produce the relevant conversations, can your vendors actually do it, and does your contract say they must? For a meaningful share of the tools nonprofits use, the honest answer is no, and the answer is only discovered under time pressure, which is the worst possible moment.
The failure modes are specific and recognizable. A consumer tier with no administrative console, where each user controls their own history and the organization controls nothing. A product whose retention is a global account setting rather than a per-matter hold, so the only way to preserve one conversation is to preserve everything, and the only way to stop deletion is a change that affects the whole workspace. An export that produces a format nobody can review usefully, a wall of unsegmented text with no reliable per-message timestamps, no user attribution, and no way to filter by date. A vendor whose support pathway for a legal request is a general contact form answered in a week. A subprocessor relationship where your vendor genuinely does not control the retention of the underlying model logs. And a contract that says nothing at all about preservation, legal holds, export, or cooperation with discovery, which describes most nonprofit AI agreements signed to date.
All of this is cheap to address at contracting time and expensive to address later, which puts it squarely in the procurement conversation rather than the legal one. The questions are not exotic, and a vendor who cannot answer them clearly has told you something useful. Can the organization place a legal hold that suspends deletion for specified users, date ranges, or the whole workspace, and how quickly does it take effect. Who inside the vendor can act on a request, and what is the committed response time. What does an export contain, in what format, with what metadata, and can we see a sample before signing. How is a subpoena served on the vendor for our data handled, and will we be notified before anything is produced. Where do the records sit, including any subprocessors, and whose retention policy governs them. What happens on termination, and is there a period during which we can still retrieve data. Our nonprofit AI vendor evaluation checklist covers the broader diligence frame, and our piece on AI vendor contract management goes into the terms themselves.
One related point is easy to miss. A subpoena may go to your vendor rather than to you, in a matter you are not even a party to, and whether you hear about it before your data is produced depends on what your contract says about notice. That provision costs nothing to negotiate and is almost never in a standard nonprofit software agreement. Ask for it. It is the difference between participating in a decision about your own records and learning about it afterward.
Preservation questions for the procurement stage
Ask before signing, because the answers are not negotiable afterward
- Can we suspend deletion for named users, date ranges, or the full workspace, and how fast does it apply
- What exactly does an export contain, in what format, with which metadata, and may we see a sample
- Who handles a legal preservation request, through what channel, within what committed time
- Will you notify us before producing our data in response to a subpoena served on you
- Which subprocessors hold any part of this data, and whose retention policy governs each
- On termination, how long can we still retrieve our data, and in what form
HR and Whistleblower Matters, Where the First Hint Is Internal
Most nonprofit disputes are not commercial litigation. They are employment matters, discrimination and retaliation claims, wage and hour disagreements, contested terminations, and allegations raised internally about financial or programmatic conduct. These have a characteristic shape that makes AI records particularly exposed: the first signal arrives inside the organization, often weeks or months before anything formal, and the people who receive it are the same people who are most likely to have discussed the underlying situation in an AI tool.
Consider the sequence that plays out routinely. A staff member raises a concern about a manager. The executive director, working alone at night with no HR department to consult, opens a chatbot and asks how to handle it, describing the people and the situation. Over the following weeks there are more conversations in the same thread as the matter develops: how to word a performance improvement plan, whether a reassignment looks retaliatory, how to document a decision that has already been made. A notetaker captures the leadership meeting where it is discussed. Four months later the employee files a retaliation charge, and all of that is potentially relevant evidence about what the organization knew, when it knew it, and what it was thinking. The AI thread is not a side artifact in that matter. It may be the most candid record of decision-making that exists.
Two consequences follow. The first is that internal complaint handling has to be connected to the preservation escalation path. A complaint that would be actionable if substantiated is exactly the circumstance where counsel should assess whether a duty has attached, and the assessment should not wait for a filing. The second is that the people handling such matters need to understand before the fact that the tool they use to think is generating records. That is not an argument for handling sensitive personnel matters without support, which is a real and serious need in understaffed organizations. It is an argument for getting that support through channels designed for it, and for being deliberate about what goes into a general-purpose tool. We have written about the specific dynamics of handling whistleblower reports when AI is in the mix, and about the broader personnel picture in AI in nonprofit human resources.
Whistleblower matters carry an additional layer for nonprofits. The federal whistleblower retaliation and document destruction provisions that apply to nonprofit organizations mean that mishandling records after an internal report is not purely a civil procedure question. Retaliation exposure and records destruction exposure arrive together, which is why many sector governance frameworks pair a whistleblower policy with a document retention and destruction policy and treat the pair as a basic board responsibility. If your organization has those two policies but neither mentions AI tools, they are both out of date, and bringing them current is a modest piece of work with an outsized protective effect.
Where internal matters and AI records intersect
The sequence that creates the most exposure in small organizations
- Leaders use AI as a substitute HR department, describing real people and real situations in detail
- Notetakers capture leadership discussions of personnel matters verbatim, often without anyone deciding they should
- The complaint intake process has no link to the preservation escalation path
- A departing employee's accounts are wiped on a standard offboarding timetable
- Existing whistleblower and retention policies predate the organization's AI tools entirely
The Work to Do Before You Need It
Everything that makes a hold go badly is a thing that could have been prepared in advance, cheaply, in a quiet month. The preparation is not a project with a steering committee. For a small organization it is a few documents, kept current, that convert a frightening legal event into an administrative sequence.
Start with a data map, which is a plain inventory rather than anything grander. One row per system. What it is, what it holds, who administers it, which account tier, where the data sits, what the retention setting is today, whether deletion can be suspended and by whom, whether it can export and in what format, and the vendor contact for a legal request. Include the AI tools people actually use rather than the ones you approved, which means asking honestly and not punishing the answers. Include free tiers, trials, and tools contractors bring. A two-page version of this document, genuinely current, is worth more than a sophisticated one that was accurate eighteen months ago. Our guide to a nonprofit AI footprint audit walks through how to find what is really in use.
Next, a custodian list keyed to roles rather than names, so it survives turnover: who holds program records, who holds personnel records, who holds financial records, who administers each system, who is the AI subscription owner. Then a draft hold notice template, prepared with counsel while nothing is pending, with blanks for the matter, the subject, the date range, and the systems. Drafting it in advance is worth the small legal fee because it is the thing you will otherwise be writing at speed on a bad afternoon. Alongside it, a simple acknowledgment tracker, which can be a spreadsheet, and a written procedure for the first seventy-two hours: who calls counsel, who suspends deletion in each system, who pauses offboarding and device reissue, who issues and tracks the notice.
Finally, scoping and search preparation. When a matter arrives, counsel will need to search a defined population, and that search is usually built from a keyword list, a date range, a custodian set, and increasingly a set of concepts rather than exact terms, because AI conversations use natural language and the words that matter are often not the words a lawyer would guess. Knowing in advance which systems can be searched, by whom, with what filters, and which require a full export followed by review outside the tool, determines whether scoping takes two days or six weeks. The organizational knowledge that makes this fast, where things live and what they are called internally, is the same asset described in our work on retention schedules for AI records, which is why the two documents should be maintained together and reviewed on the same cycle.
Five documents that change how a hold goes
Prepared in a quiet month, used on a bad day
- Data map: one row per system, including the AI tools people actually use
- Custodian list: keyed to roles so it survives turnover, with system administrators named
- Hold notice template: drafted with counsel in advance, with blanks rather than guesses
- Escalation and first-72-hours procedure: who calls counsel, who suspends deletion, who pauses offboarding
- Acknowledgment tracker: a spreadsheet is fine, as long as someone chases the blanks
AI on the Other Side of the Problem: Assisted Review
There is a pleasing symmetry in the fact that the technology creating this discovery problem is also the technology the discovery industry has used for more than a decade to manage document volume. Technology-assisted review, also called predictive coding, has been judicially recognized since Judge Andrew Peck's 2012 opinion in Da Silva Moore v. Publicis Groupe in the Southern District of New York, the first decision to approve computer-assisted review, in a matter involving millions of documents. In the years since, assisted review has moved from novel to routine in large matters, and the practical debate has shifted from whether it is permissible to how it should be validated and documented.
For a nonprofit, the relevance is usually indirect but real. Most nonprofit matters are small enough that review is manual, and the sensible default for a modest employment dispute is not to build a review workflow. But the population is not always small. An organization that turned on a notetaker across every meeting for two years, or that has three years of staff chatbot history in a managed workspace, can find itself with a document population large enough that linear review by a small legal team becomes disproportionate on cost grounds alone. In that situation, counsel may use assisted review, in their platform, under their validation protocol, and the client's job is to understand enough to discuss cost and scope intelligently rather than to operate it.
It is also worth understanding what assisted review does, because the shape of it clarifies the limits. The tools prioritize and classify a population for likely relevance and likely privilege, so that human attention goes where it will matter most, and so that clearly irrelevant material can be set aside with a defensible, documented methodology. That is triage. It is not adjudication. The boundary that must never blur is privilege: an AI relevance or privilege prediction is a prioritization signal, and the determination that a document is privileged and will be withheld is an attorney's judgment, made document by document on anything the tool flags, with a privilege log that an attorney stands behind. A production that waives privilege because a model's confidence score was treated as a decision is a serious harm, and it is the client's interest at stake, not the vendor's.
Courts have also begun issuing cautions about careless use of AI in the discovery and filing process itself, which is a reminder that the methodology has to be defensible and documented rather than merely fast. The practical takeaways for a nonprofit client are modest. Ask your counsel how review will be conducted and what it will cost under each approach. Expect any assisted process to come with a validation story. And accept that privilege review will be slower and more expensive than relevance review, because it has to be. The adjacent question of how AI handles your organization's own contract and document review in normal operations is covered in our article on AI contract review for nonprofits, where the same principle applies in a lower-stakes setting: the tool narrows the pile, a person makes the call.
What assisted review does well
Triage of a population, under a documented protocol
- Prioritizes likely relevant material so human review time lands where it matters
- Groups near-duplicates and threaded conversations, which AI transcripts produce in volume
- Surfaces concepts and paraphrases that a keyword list would miss in natural-language chat
- Flags candidates for privilege review so an attorney can examine them first
What stays with a lawyer
Decisions no confidence score substitutes for
- Every privilege determination and every entry on the privilege log
- Whether the duty to preserve has attached, and what its scope is
- What the hold notice says, who receives it, and when it is released
- Any proportionality or inaccessibility position taken with the other side or the court
- The decision that something is out of scope and need not be produced
The Lines, Stated Plainly
Three statements belong in your written procedure in roughly these words, because they are the ones people get wrong under pressure.
Once a hold is live, counsel directs the process. Not the executive director, not the IT contractor, not the board chair who has done this before at a previous organization. What the duty covers, how broadly to preserve, what gets searched, what gets produced, what is withheld, and when the hold is lifted are legal determinations. The organization's job is to execute promptly, document what it did, and tell counsel immediately when something cannot be done or has already gone wrong. Internal improvisation in this area, however well intentioned, creates the problems that turn a manageable matter into a sanctions dispute.
Deleting anything after a trigger is the worst available outcome. Worse than producing something embarrassing. Worse than a large and burdensome production. Worse than a privilege fight. Rule 37(e) reserves its severe measures, the adverse inference instruction, dismissal, default judgment, for a finding of intent to deprive, and post-trigger deletion is precisely the conduct that invites that inquiry. This applies to tidying, to reorganizing, to clearing a chat history because it felt cluttered, and to letting a known auto-deletion setting continue running once you have been told to stop it. If something has already been lost, that goes to counsel the same day rather than becoming a quiet hope.
An AI relevance call never replaces attorney review for privilege. Assisted review is a triage instrument that makes human attention go further. It does not make privilege determinations, and treating a model's output as a decision rather than a signal is how organizations waive protections they were entitled to. This is also the clearest illustration of the general principle running through this site's legal and compliance coverage, and set out at more length in our article on AI and litigation risk for nonprofits: AI is excellent at reducing a large pile to a reviewable one, and has no business making the judgment at the end.
A fourth point sits slightly outside those three but matters just as much for small organizations. None of this preparation requires a legal department. A data map, a custodian list, a template notice, an escalation rule, and a seventy-two hour procedure are within reach of a three-person administrative team working with an hour or two of counsel's time. The organizations that come through a hold well are not the ones with the most sophisticated systems. They are the ones where someone, at some point, wrote down where everything lives.
Conclusion
A retention schedule is a decision your organization makes about its own records on its own timetable. A litigation hold is the moment that discretion ends. The duty attaches when litigation is reasonably anticipated rather than when a complaint arrives, and from that moment the settings you configured for sound privacy reasons become mechanisms that can destroy evidence while nobody is watching. The distinctive problem AI introduces is not a new legal standard. It is that the record surface has expanded into places most nonprofits have never inventoried: prompt histories, system instructions, retrieval indexes, transcript archives, agent logs, version history, vendor tenants, and staff members' personal accounts.
The legal framework around that expansion is more forgiving than nonprofit leaders usually fear, and less forgiving of one specific thing than they usually expect. Rule 37(e) asks whether you took reasonable steps, and reserves its serious sanctions for intent to deprive. An organization that moved promptly, acted in good faith, documented what it did, and lost some material anyway is in the territory of curative measures. An organization that deleted something after the trigger, or let a known deletion setting run after being told to stop it, is somewhere much worse. The asymmetry is enormous, and it points in one direction: preserve broadly, fast, and let counsel argue scope afterward.
Almost everything that determines which of those positions you end up in is work that can only be done before anything happens. Knowing which AI tools are in use, including the ones nobody approved. Knowing whether each can suspend deletion and who holds that access. Having asked your vendors the preservation questions at contracting time, when they were still trying to win your business. Having a one-page escalation rule so the demand letter reaches counsel the day it arrives rather than the week it is remembered. Having a hold notice template drafted while nothing was pending. Having the data map on two current pages instead of in three people's heads.
This is general information rather than legal advice, and the determinations it describes belong to your attorney. What belongs to you is the preparation, and it is unusually cheap relative to what it protects. Most nonprofits will never face a serious eDiscovery dispute. The ones that do will divide sharply into organizations that spent an afternoon on an inventory and organizations that did not, and the difference will be visible in the first week.
Know Where Your AI Records Live Before Someone Asks
We help nonprofits map their AI footprint, document retention and preservation capability system by system, and build the vendor questions and internal procedures that make a litigation hold an administrative task rather than a crisis. Your counsel makes the legal calls. We make sure they have something to work with.
