ai-compliancetrade-pressNewsThe Broadside2 min read

NARA: AI use alone doesn't trigger records retention

The line is whether the output feeds an official decision, not whether a model touched it.


TL;DR

The National Archives and Records Administration told agencies this month that using AI doesn't automatically create a federal record. Retention obligations kick in when agencies rely on AI outputs in decision-making, circulate them to others, or incorporate them into agency systems. Personal-convenience use (unused query results, private meeting notes, unmodified commercial tools like ChatGPT or Gemini) is carved out. NARA puts the burden on each agency to determine what crosses the line, with case-by-case guidance available on request.

NARA: AI use alone doesn't trigger records retention
Editorial illustration · drawn by The Broadside

NARA's memo resolves a question that's been quietly nagging federal records officers since AI tools entered the workplace: does the act of prompting a model create a record? The answer is no, not by itself. The trigger is downstream use. If an agency relies on AI output in a procurement decision, circulates a model's summary internally, or folds generated code into a government system, retention duties attach. If a procurement officer asks ChatGPT to rephrase an email and never uses the result, that's "personal convenience" and it doesn't need to be kept.

The distinction matters because agencies are already deep into AI adoption. The General Services Administration's OneGov AI deals had over 3.4 million users across government as of May, with bulk contracts for ChatGPT, Gemini, and Claude. Those deals expire at the end of September, but GSA has signaled extensions and new vehicles are coming. The volume of AI material sloshing around agencies is large and growing.

NARA's framework is deliberately not prescriptive. "Each agency has principal responsibility for determining whether an AI material is a federal record, based on its business needs and practices," the memo says. Agencies are told to build formal AI policies with legal, IT, and other stakeholders, and to reach out to NARA for case-by-case guidance. The memo also carves out data not owned by the government and unmodified commercial software, meaning the default ChatGPT or Gemini interface, as-is, doesn't produce records through routine use.

The practical pressure point is that the records determination is backward-looking by nature. You don't always know at the moment of prompting whether an output will later become the basis for a decision. The memo doesn't solve that tension, it names it and leaves agencies to manage it. For the records officer, the takeaway is to define the retention boundary before the FOIA request arrives, not after.


Published ·Deep Fathom