Are Federal Workers' ChatGPT Prompts Public Records? NARA Says It Depends

September 1, 2026

NARA says federal workers' AI prompts can become federal records depending on how they are saved and used—but record status does not mean automatic public release.

A federal worker's ChatGPT prompt can become a federal record, but it is not automatically one—and a federal record is not automatically public. New National Archives guidance says the result depends on how the prompt, answer, file, audit trail, or AI-generated summary is created, saved, circulated, and used in official business. If it becomes a record, an approved schedule controls its disposition; a separate FOIA review controls what may be released.

Watch The 30-Second Summary

Watch this video on YouTube

Research cutoff: September 1, 2026, 7:30 AM America/Chicago. This article explains current federal guidance, not the policy of every agency or legal advice for a particular record.

The U.S. National Archives and Records Administration, or NARA, issued AC 11.2026 on August 21. The accompanying Federal Records Act guidance for AI materials covers prompts, outputs, source data, audit trails, software, and other material involved in government AI use.

The guidance rejects two tempting shortcuts:

  1. “It happened in ChatGPT, so it is automatically a federal record.”
  2. “It was only an AI chat, so it can never be a federal record.”

Neither is reliable. The durable question is what role the material played in agency business.

Who This Is For

This matters most to:

State, local, tribal, and private-sector recordkeeping rules are different. NARA's memorandum addresses the U.S. Federal Records Act. It does not turn this article into a universal rule for every public employer or company.

What Is Confirmed

Using AI Does Not Automatically Create A Federal Record

NARA says the use of AI “does not, in and of itself,” create federal records. A government employee can use a commercial or agency AI system without every keystroke, intermediate answer, or abandoned experiment automatically becoming an official record.

For example, NARA describes preliminary AI research used for personal convenience that is not incorporated into a work product or circulated to anyone else. In that fact pattern, the prompts and responses are unlikely to be federal records even if the platform happens to retain a history.

That distinction matters: technical retention is evidence that a copy exists, not a legal conclusion about why the agency must preserve it.

Prompts And Answers Can Become Federal Records

NARA says AI material is likely to qualify when it is captured and saved within an agency system and used for official business. Its examples include:

The same words can therefore cross the line because their use changes. A prompt typed during casual preliminary research may be a non-record. If the answer is then circulated, relied on in a decision, saved in a case file, or captured for an investigation, the relevant material may become a federal record.

The System That Stores A Copy Is Not The Whole Test

Commercial tools such as ChatGPT or Gemini may store conversation history, and an agency may maintain device or network audit trails. NARA says mere storage does not settle record status.

An audit trail kept automatically inside a system may initially be a non-record. If the agency captures and uses that trail to conduct an investigation, it can become a record. Conversely, a worker cannot assume material is outside the Federal Records Act merely because it sits in a vendor account instead of a traditional agency document repository.

The practical test follows creation, control, use, and evidentiary value—not a label such as “chat,” “draft,” “temporary,” or “vendor data.”

Federal AI Records Cannot Be Deleted Just Because A Chat Has A Delete Button

If an AI prompt, output, or related trail is a federal record, the agency may dispose of it only under a NARA-approved records schedule. NARA explains that approved disposition authorities are mandatory.

A vendor's delete button and an agency's legal disposal authority answer different questions:

Action or rule What it controls What it does not prove
Delete a chat in an AI app The provider's handling of that account copy under its product terms That every agency, device, log, export, recipient, or case-file copy was deleted
Agency retention policy How employees should identify and manage records That the policy itself is a NARA-approved disposal authority
NARA-approved schedule Whether and when a federal record is destroyed or transferred That the record must be disclosed publicly without review
FOIA review Whether responsive agency records must be released, withheld, or redacted That every retained record will be released in full

Deleting the convenient working copy before preserving a required record can create a records-management problem. Keeping every AI interaction forever can also be the wrong answer. Agencies need a defensible classification and schedule, not a universal “save all” or “delete all” rule.

A Federal Record Is Not Automatically A Public Record

This is the most important headline caveat.

The Federal Records Act governs creation, preservation, management, and disposition. The Freedom of Information Act provides a separate right to request federal agency records. FOIA.gov says an agency searches for responsive records and then reviews what can be disclosed. Nine statutory exemptions can protect categories such as personal privacy, national security, privileged material, confidential business information, and law-enforcement interests.

So an AI prompt can be:

Record status is necessary for many FOIA questions, but it does not predetermine the disclosure result.

What Is Still Unclear

How Each Agency Will Implement The Guidance

NARA recommends that agencies adopt formal AI policies with records, legal, IT, privacy, and other stakeholders. It does not impose one universal retention period for every AI prompt or prescribe one technical architecture.

Agencies still need to map their own programs, approved tools, workflows, record series, system controls, and schedules. Two offices may use the same commercial chatbot differently enough that their recordkeeping outcomes differ.

Which Intermediate Materials Matter In A Specific Decision

An AI-assisted work product may involve a source document, prompt, retrieved passages, generated answer, human edits, comments, approvals, and an audit trail. NARA's guidance provides categories and examples, but it cannot decide which layer documents a particular agency action.

If the final decision depends on the model's reasoning path or cited material, preserving only the polished final document may omit relevant evidence. In another workflow, intermediate experimentation may never be relied upon and may remain non-record material. The agency must analyze the actual business process.

Whether A Particular Prompt Will Be Released Under FOIA

No one can answer that from the word “prompt” alone. The agency would need to determine whether it has a responsive agency record, search the correct systems and custodians, and apply the law to the content.

Sensitive personal data in a prompt may support redaction or withholding; it does not necessarily make the record disappear. Likewise, an innocuous prompt is not automatically public if it falls outside the request or another rule applies.

What A Vendor Deleted Or Retained Elsewhere

NARA's document expressly says it addresses Federal Records Act requirements, not privacy, security, e-discovery, or ethical use. It does not audit ChatGPT, Gemini, Copilot, Claude, or another provider's retention systems.

An agency still needs to understand:

Records classification and vendor data mapping should be connected, but they are not the same exercise.

The RECORDS Check Before Using AI For Federal Work

Federal personnel should follow their agency's approved policy and contact their records officer. The following RECORDS check is a practical way to identify the questions that policy needs to answer.

R — Role In Official Business

Ask whether the AI material supports a decision, case, policy, investigation, transaction, meeting, or other agency function. The stronger the official role, the less defensible it is to treat the material as disposable personal convenience.

E — Evidence And Reliance

Document whether anyone relied on the output, circulated it, approved it, or incorporated it into another work product. Save enough context to explain what evidence influenced the result.

C — Copies And Custodians

Map where copies can exist: AI account, agency repository, browser, device, email, collaboration system, export, audit log, ticket, recipient inbox, and vendor support system. One delete action rarely covers every location.

O — Official System And Approved Tool

Use only the AI service, account, data classification, and storage location the agency authorizes. “Private AI” is not a substitute for authority to send government data to a service.

R — Retention Authority

Identify the applicable NARA-approved schedule and record series. A product setting, employee preference, or informal cleanup routine is not disposal authority.

D — Disclosure Review

Keep Federal Records Act classification separate from FOIA, Privacy Act, privilege, classification, controlled-information, litigation, and investigation reviews. Each has its own questions.

S — Stop And Ask

If the workflow handles sensitive, classified, controlled, personal, investigative, procurement, legal, health, or personnel information, stop before submitting it and ask the agency's records, security, privacy, legal, or program office. Do not repair an uncertain recordkeeping decision after the prompt has already left the approved boundary.

What This Does Not Mean

NARA's guidance does not mean:

The guidance is about applying existing records law to a new type of material. It is not a loophole for evading oversight and not a command to preserve every token forever.

Where OpenVeil Fits—And Where It Does Not

OpenVeil is a hosted, privacy-focused AI workspace for adults. Normal chat history is stored in the user's browser rather than as a normal server-side chat-history record. OpenVeil still maintains the account, billing, security, abuse-prevention, and operational data needed to run the service, and active prompts, files, searches, voice, images, selected local history, and requested features still require processing by OpenVeil and necessary providers.

That can be a useful privacy boundary for an authorized personal or professional workflow that does not require a conventional provider-side conversation archive. It does not make an official-business record a non-record, satisfy an agency's approved-system requirements, supply a NARA schedule, prevent device or browser collection, block a legal preservation duty, or decide a FOIA request.

Do not use OpenVeil—or any hosted AI service—for federal information unless the relevant agency authorizes the service and the data. Browser-local history changes where a normal chat-history copy is kept; it does not change who owns an official record or what law requires.

For authorized non-government work where the documented boundary fits, adults can try OpenVeil with a one-time 10-action preview that does not require a card. Before sending sensitive information, read What Browser-Local Chat History Means In An AI App and What To Check Before Trusting Any AI Privacy Claim.

Frequently Asked Questions

Are Federal Employees' ChatGPT Prompts Public Records?

Sometimes—but the correct first term is federal record, not automatically public record. NARA says record status depends on how the prompt is created, maintained, and used. If it is a federal record, public release still requires a separate FOIA or other disclosure analysis.

Is Every AI-Generated Draft A Federal Record?

No. A draft used only for preliminary personal convenience and never relied upon or circulated may be a non-record. A draft can become a record when it documents official business, supports a decision, is circulated, or is captured in a recordkeeping system.

Can A Federal Agency Delete AI Chats?

It can delete non-record material under agency policy. A federal record may be disposed of only under an applicable NARA-approved schedule and any preservation obligations. The AI provider's delete button is not the legal authority.

Can A FOIA Request Get Government AI Prompts?

Potentially. The agency must possess or control responsive agency records, conduct an appropriate search, and review the content. FOIA has nine exemptions, so a responsive prompt may be released, redacted, or withheld depending on the facts.

Does An AI Audit Log Count As A Federal Record?

Not merely because it exists. NARA says an automatically retained audit trail may be a non-record, but it can become a federal record if the agency captures and uses it for official business, such as an investigation.

Does Browser-Local AI History Avoid Federal Records Rules?

No. Storage location does not control the legal classification. If browser-local material documents official business and meets the federal-record definition, keeping the copy on a device does not make the obligation disappear.

Can A Worker Use A Personal AI Account To Keep Prompts Off The Record?

No. Moving official business to a personal or unapproved system is not a reliable way to avoid the Federal Records Act and may violate agency security, privacy, acceptable-use, or records policies.

Does NARA's Guidance Apply To State And Local Employees?

No. AC 11.2026 interprets federal records requirements for federal agencies. State and local public-records laws, court rules, and employer policies can differ.

Bottom Line

NARA's new rule is not “all government AI chats are public” and not “AI chats do not count.”

An AI prompt, answer, file, summary, or audit trail can become a federal record when the agency captures and uses it to conduct official business, support decisions, circulate information, document meetings, or investigate activity. A personal-convenience experiment that is not relied upon may remain a non-record.

If the material is a federal record, an approved schedule governs its disposition. If someone requests it, FOIA review separately determines what is responsive and what may be released, redacted, or withheld.

The safest operational rule is simple: decide the approved tool, official purpose, record series, retention path, and disclosure boundary before a worker submits the prompt. A chat interface does not erase the recordkeeping consequences of the work performed inside it.

Sources

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.