Are AI Agent Logs Discoverable? Rule 26, Spoliation, and the Record You Cannot Make Later

Generally, yes. In US federal civil litigation, Rule 26(b)(1) sets the scope of discovery at any non-privileged matter relevant to a party's claim or defence and proportional to the needs of the case, and Rule 34 expressly provides for requests to produce electronically stored information. Records of what an AI agent did, when, and in what order sit inside that scope like any other system record. What US courts spent 2026 working out was not whether such material is reachable, but how it is treated once reached — and for records your infrastructure writes automatically, the answer is the least favourable one available.

That is the definitional answer, and it is the less interesting half. The half worth an afternoon is the shape of the obligation. Every AI governance conversation of the last two years has been organised around deadlines: August 2026, December 2027, August 2028. A deadline is a generous thing. It names a date, and it gives you the time before that date to get ready.

Discovery does not work like that. It arrives without warning and it reaches backwards, asking for records of things that already happened, on a schedule set by someone whose interests are opposed to yours. There is no preparation period, because the period you would have prepared in has already passed. The only question is whether the record exists.

This article covers

What discovery actually asks for

Discovery is the pre-trial process in which parties obtain evidence from one another. In US federal civil practice its scope comes from Rule 26(b)(1) of the Federal Rules of Civil Procedure: non-privileged matter relevant to any party's claim or defence and proportional to the needs of the case. Rule 34 covers requests to produce documents and electronically stored information. Rule 26(f) requires the parties to confer early about how electronically stored information will be preserved and produced.

Two features of that framework matter more than the rule numbers.

The first is that relevance is decided by the dispute, not by the system owner. You do not get to scope the request. If an agent took an action that bears on a claim, the records of that action are in play whether or not anyone anticipated they would be read by a stranger.

The second is that the requesting party is adversarial. This is the property that separates discovery from every audit an engineering team has designed for. An auditor arrives with a checklist and a professional interest in an orderly conclusion. Opposing counsel arrives looking for the gap, and the gap is worth money to them. A record that satisfies an audit can still be a poor witness.

What US courts did in 2026

2026 was the year the question stopped being theoretical. Each decision below is cited with court, docket and date so it can be checked against the record rather than taken on this page's word.

Privilege: not a split, a framework

A run of 2026 decisions reached opposite results on whether AI interactions were protected, and it is tempting to read that as courts disagreeing. It is worth resisting, because it is the most common error in secondary writing about this area. No court has announced a new AI-specific privilege doctrine. Every one of these applied the ordinary third-party disclosure and work-product tests and got different answers because the facts were different.

Read together, two things decide these cases and neither is novel: whether there was a reasonable expectation of confidentiality under the platform's actual terms, and whose mental impressions the material reflects, and at whose direction it was made.

The distinction most commonly collapsed: confidentiality is not privilege. An enterprise agreement promising that your inputs will not be used for training, will not be disclosed onward, and can be deleted on request buys you confidentiality. Confidentiality is a threshold condition for privilege, not a substitute for it.

Material can be encrypted, contractually protected and entirely secure, and still be fully discoverable — because it was generated as an ordinary business or technical record, outside counsel's direction, reflecting nobody's legal mental impressions. The error runs in both directions: commentary that treats an enterprise tier as a shield is wrong, and commentary that treats all AI use as a waiver is wrong too. Courts have said so explicitly.

Which matters here because agent records are the clearest case of all. An enforcement log written automatically by production infrastructure, at machine speed, for operational reasons, is not a confidential communication seeking legal advice and does not reflect an attorney's thinking. Whatever the argument is for a litigator's chatbot session, there is no version of it that covers your gate's decision log. Those records are ordinary business records, and the sensible planning assumption is that an opposing party will one day read them.

None of that is a rule requiring anybody to log agent activity. It is something more consequential: a set of decisions establishing that when the question is asked, the answer is produced from the records that exist. The obligation is not created by a regulator on a schedule. It crystallises the moment a dispute does.

The distinction, in one line: a regulation tells you what you will need to show from a date forward. Discovery tells you what you needed to have been keeping, in the past tense, and there is no version of compliance that operates retroactively.

Why a backward-looking duty changes the design

Most agent observability is built for debugging. That is a reasonable thing to build for, and it produces a characteristic shape: verbose traces, short retention, sampling under load, and free-form text written by the component being observed. Every one of those choices is correct for finding a bug and weak for answering a subpoena.

Built for debugging

Answers "what went wrong?"

Read by the team that owns the system, days after the event, to fix it. Volume is the enemy, so sampling and short retention are features. Nobody disputes the contents, because everyone reading them is on the same side.

Built for evidence

Answers "what happened, and can you prove it?"

Read by someone with an interest in it being incomplete, years later, under an obligation you did not set. Coverage matters more than depth. Every gap is an argument, and the party that wrote the record is the party whose word is in question.

The gap between those two columns is not a maturity gap. It is a design gap, and it does not close by increasing log verbosity. A very detailed record written by the system whose behaviour is in dispute, retained for thirty days, sampled at peak, and assembled into a narrative after the complaint arrived, has problems that no amount of additional detail improves.

Preservation, Rule 37(e), and adverse inference

The duty to preserve attaches when litigation is reasonably anticipated, which is generally earlier than when it is filed. From that point, ordinary deletion cycles that touch relevant material become a problem, which is why organisations issue a litigation hold.

Rule 37(e) governs the loss of electronically stored information that should have been preserved. Where information is lost because reasonable steps were not taken and it cannot be restored or replaced, a court may order measures no greater than necessary to cure the prejudice. Where a court finds a party acted with intent to deprive another party of the information, the more serious measures become available, including instructing the jury that it may or must presume the lost information was unfavourable.

That last measure is worth pausing on, because it inverts the usual burden. A fine is a number that can be budgeted, argued down and paid. An adverse inference is a permanent instruction to the finder of fact to fill your gap with the worst available reading. You do not get to explain what the missing record would have said, precisely because it is missing.

Where this bites for agents specifically: a retention window chosen for storage cost is a policy decision made long before any dispute, by people optimising for something else entirely. It becomes an evidentiary posture the moment a duty to preserve attaches to a period that has already rolled off.

Reconstruction is a different object from a record

When the request lands and the logs are thin, the natural response is to reconstruct: pull what exists from adjacent systems, correlate timestamps, and assemble an account of what the agent must have done.

That account may well be accurate. It is still a weaker object than a record, for a reason that has nothing to do with how carefully it was made: it was created by a party that already knew what was in dispute. Everything about its selection, framing and emphasis was chosen with the outcome visible. Opposing counsel does not have to prove it is wrong. They only have to establish when it was made, and let the sequence do the work.

A record written at the moment of the decision does not carry that problem, and cannot be made to carry it later. Its author did not know what would matter. That is not a technical property of the storage. It is a property of when.

This is not hypothetical. In Fortis Advisors, LLC v. Krafton, Inc. (C.A. No. 2025-0805-LWW, Delaware Court of Chancery, 16 March 2026), Vice Chancellor Lori W. Will found a breach of a $250 million earnout agreement and quoted extensively from the buyer's chief executive's AI chat logs, produced in discovery, as direct evidence that his stated justifications for terminating executives had been manufactured after the fact. The executive admitted at trial to having deleted relevant logs, which the court treated as going to bad faith.

Two things at once, from one set of records: the contemporaneous material contradicted the later account, and the attempt to remove it made the position worse rather than better. Worth being precise about the posture, though — this was an evidentiary finding at trial, not a Rule 37(e) sanction, and no 2026 federal decision appears to have applied Rule 37(e) specifically to AI-generated records yet.

Which is the whole argument for writing the record at the point of the decision rather than deriving it afterwards. Not because contemporaneous records are more detailed, and not because they are harder to alter. Because they were made before anybody had a reason to want them to say something.

Four properties a record needs when someone hostile reads it

These are the questions an opposing party, or an auditor acting like one, will actually put to a body of agent records. They are worth asking of your own before someone else does.

01
Was it created at the time of the event, or afterwards?

Contemporaneous creation is the property that does the most work and the one that cannot be added later. A record written before the outcome was known was written by an author with no motive, and that is a structural fact about it rather than a claim its author makes.

What weakens it: any step where a human or a process selected, summarised or narrated the events after the fact. Each of those is a place to ask who chose, and when, and what they knew.

02
Is it complete, and can you show what a gap would look like?

Completeness cannot be asserted by a log, because a log can only report what it contains. Absence leaves no entry. Demonstrating completeness requires something that declared in advance what the full set should have been, so that a missing element is visible as an absence rather than invisible as a non-event.

The practical form of the question: if a step had been skipped, would anything in your records show it? If the honest answer is that the record would simply be shorter, the record cannot establish completeness.

03
Can a third party verify it without your cooperation?

Evidence that only its owner can validate leaves you as the sole authority on your own conduct, at exactly the moment your account is what is being questioned. Cryptographic signing helps only if the verification keys are published and the check can be performed by someone who has never contacted you.

The follow-up that separates real answers from good ones: who holds the signing key. A signature proves a record has not changed relative to a key. If the party whose conduct is in question holds that key, the signature establishes integrity, not independence, and a sophisticated opponent will make exactly that distinction.

04
Would alteration leave a mark?

Hash-linking each record to its predecessor means changing one record breaks the link at the next one, so a single edit is detectable by anyone recomputing the chain. This is a genuine property and it is worth stating precisely rather than expansively.

What it does not cover: a party holding the signing key who rewrites an entire downstream chain consistently. The chain alone does not catch that. Only a copy held by somebody else does, which is why custody, and not cryptography, is the thing to ask about.

Where AgenticRail stands, and what it does not claim

AgenticRail is a deterministic sequence-enforcement gate. An agent calls it before each step. The gate checks the step against the sequence the caller itself declared, and returns ALLOW or DENY before the step runs. A denied step does not run. Every decision, permitted or refused, produces a signed receipt written at the moment of the decision.

Three things follow from that design which are relevant to everything above.

The record is contemporaneous by construction. The receipt is not derived from logs afterwards; it is the artefact of the decision itself, written before the step executes and before anyone knows what will turn out to matter. There is no later assembly step in which a party with knowledge of a dispute selects what to include.

Completeness has a referent. Because the caller declares its step order in advance, a step that was skipped is a positive fact in the record rather than a silence, and a denial is recorded as a decision rather than as nothing having happened. That is the difference between a log that can only report what it contains and a record against which absence is measurable.

Verification does not require us. Receipts are signed with Ed25519 and the public keys are published. The JSON verification report carries the raw signature, the exact byte string that was signed, and the public keys inline, so verification runs offline with no call back to AgenticRail, no key and no account. Each receipt is hash-linked to its predecessor, so altering one breaks the chain detectably at the next link, and a sealed sequence cannot be reopened without leaving that break.

What it does not establish
  • It does not prove when. The timestamp is signed, so it cannot be altered after signing without breaking verification. It is supplied by the caller and bounded — the gate refuses anything more than 300 seconds from its own clock — but it is asserted, not established against an independent time authority. A record of when is not proof of when, and the two should not be conflated in any setting where the distinction can be tested.
  • It does not assert that the action succeeded. A receipt records that the enforcement decision was ALLOW, meaning the step was permitted. It does not claim the downstream action ran, completed, or produced a correct result. AgenticRail is an enforcement layer, not an execution runtime, and the executor's outcome is not signed into the receipt.
  • AgenticRail holds the signing keys. The service is hosted, and that key custody is a real residual. It is narrowed by a separately credentialed archive copy held under different credentials, which raises the cost of a consistent rewrite without eliminating it. Closing it fully is a custodial arrangement, not an engineering change.
  • It holds no certifications. Not SOC 2 audited, not ISO 27001 or ISO/IEC 42001 certified, and no certification is claimed anywhere on this site.
  • There is no AI in it. No language model sits anywhere in the decision path and no model is consulted. The same payload against the same sequence state yields the same verdict every time, which is what makes a decision reproducible by someone else rather than re-generated.

Stating those limits on a page about litigation is deliberate rather than modest. A documented limitation is something you produce; the same limitation discovered by the other side is something that happens to you. Anything claimed here that could not survive being tested would be worth less than saying nothing.

You can check the mechanism rather than take any of it on trust. Paste a sequence ID into report.agenticrail.nz/report and it returns the per-step enforcement log, signature and hash-link verification for every receipt, and, once a sequence is sealed, the comparison against the independently held archive copy. A demo sequence needs no key at all.

The live demo lets you attempt the failures directly: replay a nonce, skip a step, act on a sealed sequence. Each attempt returns a denial and a receipt recording it.

There is a version of this whole argument that a carver already knows. A chisel has no undo. The cut is the record, made at the moment of the cut, by someone who did not yet know how the piece would turn out. Everything written afterwards about what you intended is commentary, and everyone can tell the difference.

This article is general information about how discovery and preservation obligations interact with system design. It is not legal advice, it does not create any professional relationship, and it does not describe the law of any particular jurisdiction as applied to any particular set of facts. Rules of civil procedure, preservation duties and sanctions doctrine vary between jurisdictions and change over time. Cases are cited with court, docket number and date so that any of them can be checked against the record rather than taken on this page's word, and where an order has been stayed that is stated. A decision described here is one court's reasoning on one set of facts, not a settled rule. Anyone with an actual or reasonably anticipated dispute should take advice from a qualified lawyer in the relevant jurisdiction.