720-891-1663

Litigation Readiness in the Era of AI

The Issue, in Plain Terms

When a company gets sued, it has a legal duty to preserve and hand over records relevant to the case — emails, documents, and increasingly, anything generated using AI tools. That duty applies the moment litigation is reasonably expected, not just after a complaint is filed.

AI tools create a new kind of problem for this process. Employees across the company may be using different AI tools — some approved, many not — in different ways, often without IT’s knowledge. If litigation hits, we may have no reliable way to know who used what tool, for what purpose, or whether anything relevant to a case passed through it. That is a real legal and financial risk, not a hypothetical one.

Why “We Didn’t Know” Is Not a Safe Answer

Courts do not expect any company to preserve everything, everywhere, instantly. What they do expect is a reasonable, good-faith effort — proportionate to the size of the company and what it could realistically have controlled. Two things determine how we look in that situation:

  • Whether we had any visibility at all. A company with a known list of approved AI tools and some sense of who uses them is in a strong position. A company that genuinely has no idea what’s in use looks negligent, even if no one acted in bad faith.
  • Whether we acted promptly once litigation was anticipated. Waiting until a lawsuit is filed to start asking “what AI tools does anyone use?” is far riskier than already having an answer on file.

In short: the goal is not perfect control. It’s being able to show, credibly, that we took reasonable steps.

Recommended Actions

1. Build a simple inventory (low effort, high value)

  • Identify which AI tools are officially sanctioned for company use (e.g., a company OpenAI or Claude account) and who has access.
  • Ask department heads to flag any other AI tools their teams use regularly, even informally — this doesn’t need to be exhaustive on day one, just a starting point.
  • Keep this list current. A short quarterly refresh is enough; this is not a large ongoing project.

2. Set one simple ground rule for employees

  • Sensitive, confidential, or potentially litigation-relevant material should only go through company-approved AI tools — never personal AI accounts.
  • This one rule does more to reduce risk than any amount of after-the-fact investigation, because it keeps relevant material inside systems we actually control.

3. Know our vendor’s data retention terms

  • For IT: confirm, in plain terms for the rest of us, how long each approved AI vendor keeps our data by default, and whether we can request longer retention or a legal hold if needed. This does not require renegotiating contracts — most vendors already publish this.
  • For leadership: the short version is that vendors typically keep this data for a limited window (often around 30 days) unless we take action. That means once litigation is anticipated, time matters.

4. Have a preservation step ready to go

  • If litigation is ever reasonably anticipated, we should immediately: (a) notify our AI vendor(s) in writing, referencing anticipated litigation and asking them to preserve relevant data, and (b) export/preserve anything in our own accounts before it ages off automatically.
  • This doesn’t need a new department. It can be a short checklist our legal counsel or outside counsel triggers the moment a dispute looks likely.

5. Scope realistically, don’t try to boil the ocean

  • If a dispute arises, focus preservation efforts on employees actually connected to the facts of the case, not the entire company. This is how legal holds already work for email and files, and it applies the same way here.

What This Is Not

This is not a proposal to ban or restrict AI tools, and it is not a large IT project. It is a modest, mostly non-technical housekeeping exercise: know what’s in use, set one clear rule about sensitive data, and have a short checklist ready if litigation ever becomes likely. The cost of doing this now is small. The cost of having no answer during a lawsuit is not.

This may seem daunting, and it can be, but it also can be done cost effectively with a good AI governance program. Managing the data that AI has access to is part of that program. Contact us for assistance.

Facebooktwitterredditlinkedinmailby feather

Leave a Reply

Your email address will not be published. Required fields are marked *