# Are AI Agent Logs Discoverable? Rule 26, Spoliation, and the Record You Cannot Make Later

> Markdown mirror for AI agents, generated 2026-08-25 from the live page.
> Canonical: https://agenticrail.nz/blog/ai-agent-logs-discoverable-evidence/
> Site context: https://agenticrail.nz/llms.txt

Published 17 August 2026 · Last reviewed 23 August 2026 · AgenticRail

# Are AI Agent Logs Discoverable? Rule 26, Spoliation, and the Record You Cannot Make Later

**Generally, yes.** In US federal civil litigation, Rule 26(b)(1) sets the scope of discovery at any non-privileged matter relevant to a party's claim or defence and proportional to the needs of the case, and Rule 34 expressly provides for requests to produce electronically stored information. Records of what an AI agent did, when, and in what order sit inside that scope like any other system record. What US courts spent 2026 working out was not whether such material is reachable, but how it is treated once reached — and for records your infrastructure writes automatically, the answer is the least favourable one available.

That is the definitional answer, and it is the less interesting half. The half worth an afternoon is the shape of the obligation. Every AI governance conversation of the last two years has been organised around *deadlines*: August 2026, December 2027, August 2028. A deadline is a generous thing. It names a date, and it gives you the time before that date to get ready.

**Discovery does not work like that.** It arrives without warning and it reaches backwards, asking for records of things that already happened, on a schedule set by someone whose interests are opposed to yours. There is no preparation period, because the period you would have prepared in has already passed. The only question is whether the record exists.

This article covers

- [What discovery actually asks for](#what-discovery-asks)
- [What US courts did in 2026](#courts-2026)
- [Why a backward-looking duty changes the design](#backwards)
- [Preservation, Rule 37(e), and adverse inference](#preservation)
- [Reconstruction is a different object from a record](#reconstruction)
- [Four properties a record needs when someone hostile reads it](#properties)
- [Where AgenticRail stands, and what it does not claim](#our-position)

## What discovery actually asks for

Discovery is the pre-trial process in which parties obtain evidence from one another. In US federal civil practice its scope comes from **Rule 26(b)(1)** of the Federal Rules of Civil Procedure: non-privileged matter relevant to any party's claim or defence and proportional to the needs of the case. **Rule 34** covers requests to produce documents and electronically stored information. **Rule 26(f)** requires the parties to confer early about how electronically stored information will be preserved and produced.

Two features of that framework matter more than the rule numbers.

The first is that **relevance is decided by the dispute, not by the system owner.** You do not get to scope the request. If an agent took an action that bears on a claim, the records of that action are in play whether or not anyone anticipated they would be read by a stranger.

The second is that **the requesting party is adversarial.** This is the property that separates discovery from every audit an engineering team has designed for. An auditor arrives with a checklist and a professional interest in an orderly conclusion. Opposing counsel arrives looking for the gap, and the gap is worth money to them. A record that satisfies an audit can still be a poor witness.

## What US courts did in 2026

2026 was the year the question stopped being theoretical. Each decision below is cited with court, docket and date so it can be checked against the record rather than taken on this page's word.

- **AI prompts held discoverable as part of expert methodology.** In *Conservation Law Foundation, Inc. v. Shell Oil Company* (No. 3:21-cv-00933, D. Conn., ECF 970), Magistrate Judge Thomas O. Farrish granted a motion to compel on 18 May 2026, holding that an expert witness's methodology is fair ground for discovery and that AI-assisted culling was an aspect of that methodology. A Rule 29 stipulation covering expert notes, drafts and communications was held not clear enough to reach AI prompts. **The order was stayed on 3 June 2026** by District Judge Vernon D. Oliver pending a Rule 72(a) objection, so it is judicial reasoning to read, not settled law to rely on.
- **Protective orders written for AI specifically.** In *Morgan v. V2X, Inc.* (No. 25-cv-01991-SKC-MDB, 2026 WL 864223, D. Colo., 30 March 2026), Magistrate Judge Maritza Dominguez Braswell approved protective-order language permitting AI use on confidential discovery material only where the provider is contractually barred from storing or training on inputs, barred from disclosing them onward beyond what service delivery requires, and obliged to permit deletion on request. A party was also ordered to identify the platform it had used.
- **Sanctions for fabricated output reached the courts of appeals.** In *Whiting v. City of Athens, Tennessee* (No. 24-5918, 6th Cir., March 2026), two attorneys were sanctioned $15,000 each plus double costs and fees, and referred for discipline, over briefs containing more than two dozen fabricated citations. Similar orders followed elsewhere in 2026, including removal of appointed counsel with all compensation denied, and a public reprimand of a federal prosecutor who then resigned. This is the same defect written about elsewhere on this site — a confident account of something that did not happen — arriving in the one venue that answers it with penalties.

### Privilege: not a split, a framework

A run of 2026 decisions reached opposite results on whether AI interactions were protected, and it is tempting to read that as courts disagreeing. **It is worth resisting, because it is the most common error in secondary writing about this area.** No court has announced a new AI-specific privilege doctrine. Every one of these applied the ordinary third-party disclosure and work-product tests and got different answers because the facts were different.

- **Not protected.** *United States v. Heppner* (No. 25-cr-00503-JSR, S.D.N.Y., oral ruling 10 February 2026, written opinion 17 February 2026), Judge Jed S. Rakoff: 31 documents a criminal defendant generated with a consumer AI assistant were covered by neither privilege nor work product. An AI platform is not an attorney; the platform's privacy policy permitted collection, model training and disclosure to government authorities, defeating any reasonable expectation of confidentiality; and the material was created on the defendant's own initiative, not at counsel's direction. The court expressly noted that an enterprise tool with contractual confidentiality guarantees might present a different analysis.
- **Protected.** *Warner v. Gilbarco, Inc.* (E.D. Mich., 10 February 2026), Magistrate Judge Anthony P. Patti: a self-represented civil litigant's AI-assisted materials *were* work product, reflecting her own mental impressions prepared in anticipation of litigation. Using a public AI platform did not waive the protection, because such programs are tools rather than persons, and disclosure to one does not automatically compromise protection unless it increases the likelihood the material reaches an adversary.
- **Protected.** *Tym v. Cerno* (No. 1:25-cv-00498-JCH-JMR, D.N.M., 22 April 2026), Magistrate Judge Jennifer M. Rozzoni: adopted the same reasoning, holding that AI interactions do not automatically compromise work-product protection.
- **Not protected.** *Shealy v. Seaside Investments, LLC* (Suffolk Superior Court, Massachusetts, 1 June 2026), Judge Debra A. Squires-Lee: AI-generated material created by a represented plaintiff's romantic partner was not work product, a partner not being a privileged representative.

Read together, two things decide these cases and neither is novel: **whether there was a reasonable expectation of confidentiality under the platform's actual terms**, and **whose mental impressions the material reflects, and at whose direction it was made.**

**The distinction most commonly collapsed: confidentiality is not privilege.** An enterprise agreement promising that your inputs will not be used for training, will not be disclosed onward, and can be deleted on request buys you confidentiality. Confidentiality is a *threshold condition* for privilege, not a substitute for it.

Material can be encrypted, contractually protected and entirely secure, and still be fully discoverable — because it was generated as an ordinary business or technical record, outside counsel's direction, reflecting nobody's legal mental impressions. The error runs in both directions: commentary that treats an enterprise tier as a shield is wrong, and commentary that treats all AI use as a waiver is wrong too. Courts have said so explicitly.

**Which matters here because agent records are the clearest case of all.** An enforcement log written automatically by production infrastructure, at machine speed, for operational reasons, is not a confidential communication seeking legal advice and does not reflect an attorney's thinking. Whatever the argument is for a litigator's chatbot session, there is no version of it that covers your gate's decision log. Those records are ordinary business records, and the sensible planning assumption is that an opposing party will one day read them.

None of that is a rule requiring anybody to log agent activity. It is something more consequential: **a set of decisions establishing that when the question is asked, the answer is produced from the records that exist.** The obligation is not created by a regulator on a schedule. It crystallises the moment a dispute does.

**The distinction, in one line:** a regulation tells you what you will need to show from a date forward. Discovery tells you what you needed to have been keeping, in the past tense, and there is no version of compliance that operates retroactively.

## Why a backward-looking duty changes the design

Most agent observability is built for debugging. That is a reasonable thing to build for, and it produces a characteristic shape: verbose traces, short retention, sampling under load, and free-form text written by the component being observed. Every one of those choices is correct for finding a bug and weak for answering a subpoena.

Built for debugging

#### Answers "what went wrong?"

Read by the team that owns the system, days after the event, to fix it. Volume is the enemy, so sampling and short retention are features. Nobody disputes the contents, because everyone reading them is on the same side.

Built for evidence

#### Answers "what happened, and can you prove it?"

Read by someone with an interest in it being incomplete, years later, under an obligation you did not set. Coverage matters more than depth. Every gap is an argument, and the party that wrote the record is the party whose word is in question.

The gap between those two columns is not a maturity gap. It is a design gap, and it does not close by increasing log verbosity. A very detailed record written by the system whose behaviour is in dispute, retained for thirty days, sampled at peak, and assembled into a narrative after the complaint arrived, has problems that no amount of additional detail improves.

## Preservation, Rule 37(e), and adverse inference

The duty to preserve attaches when litigation is *reasonably anticipated*, which is generally earlier than when it is filed. From that point, ordinary deletion cycles that touch relevant material become a problem, which is why organisations issue a litigation hold.

**Rule 37(e)** governs the loss of electronically stored information that should have been preserved. Where information is lost because reasonable steps were not taken and it cannot be restored or replaced, a court may order measures no greater than necessary to cure the prejudice. Where a court finds a party *acted with intent to deprive* another party of the information, the more serious measures become available, including instructing the jury that it may or must presume the lost information was unfavourable.

That last measure is worth pausing on, because it inverts the usual burden. A fine is a number that can be budgeted, argued down and paid. An adverse inference is a permanent instruction to the finder of fact to fill your gap with the worst available reading. You do not get to explain what the missing record would have said, precisely because it is missing.

**Where this bites for agents specifically:** a retention window chosen for storage cost is a policy decision made long before any dispute, by people optimising for something else entirely. It becomes an evidentiary posture the moment a duty to preserve attaches to a period that has already rolled off.

## Reconstruction is a different object from a record

When the request lands and the logs are thin, the natural response is to reconstruct: pull what exists from adjacent systems, correlate timestamps, and assemble an account of what the agent must have done.

That account may well be accurate. It is still a weaker object than a record, for a reason that has nothing to do with how carefully it was made: **it was created by a party that already knew what was in dispute.** Everything about its selection, framing and emphasis was chosen with the outcome visible. Opposing counsel does not have to prove it is wrong. They only have to establish when it was made, and let the sequence do the work.

A record written at the moment of the decision does not carry that problem, and cannot be made to carry it later. Its author did not know what would matter. That is not a technical property of the storage. It is a property of *when*.

**This is not hypothetical.** In *Fortis Advisors, LLC v. Krafton, Inc.* (C.A. No. 2025-0805-LWW, Delaware Court of Chancery, 16 March 2026), Vice Chancellor Lori W. Will found a breach of a $250 million earnout agreement and quoted extensively from the buyer's chief executive's AI chat logs, produced in discovery, as direct evidence that his stated justifications for terminating executives had been *manufactured after the fact*. The executive admitted at trial to having deleted relevant logs, which the court treated as going to bad faith.

Two things at once, from one set of records: the contemporaneous material contradicted the later account, and the attempt to remove it made the position worse rather than better. Worth being precise about the posture, though — this was an evidentiary finding at trial, not a Rule 37(e) sanction, and no 2026 federal decision appears to have applied Rule 37(e) specifically to AI-generated records yet.

Which is the whole argument for writing the record at the point of the decision rather than deriving it afterwards. Not because contemporaneous records are more detailed, and not because they are harder to alter. Because they were made before anybody had a reason to want them to say something.

## Four properties a record needs when someone hostile reads it

These are the questions an opposing party, or an auditor acting like one, will actually put to a body of agent records. They are worth asking of your own before someone else does.

01

Was it created at the time of the event, or afterwards?

Contemporaneous creation is the property that does the most work and the one that cannot be added later. A record written before the outcome was known was written by an author with no motive, and that is a structural fact about it rather than a claim its author makes.

**What weakens it:** any step where a human or a process selected, summarised or narrated the events after the fact. Each of those is a place to ask who chose, and when, and what they knew.

02

Is it complete, and can you show what a gap would look like?

Completeness cannot be asserted by a log, because a log can only report what it contains. Absence leaves no entry. Demonstrating completeness requires something that declared in advance what the full set should have been, so that a missing element is visible as an absence rather than invisible as a non-event.

**The practical form of the question:** if a step had been skipped, would anything in your records show it? If the honest answer is that the record would simply be shorter, the record cannot establish completeness.

03

Can a third party verify it without your cooperation?

Evidence that only its owner can validate leaves you as the sole authority on your own conduct, at exactly the moment your account is what is being questioned. Cryptographic signing helps only if the verification keys are published and the check can be performed by someone who has never contacted you.

**The follow-up that separates real answers from good ones:** who holds the signing key. A signature proves a record has not changed relative to a key. If the party whose conduct is in question holds that key, the signature establishes integrity, not independence, and a sophisticated opponent will make exactly that distinction.

04

Would alteration leave a mark?

Hash-linking each record to its predecessor means changing one record breaks the link at the next one, so a single edit is detectable by anyone recomputing the chain. This is a genuine property and it is worth stating precisely rather than expansively.

**What it does not cover:** a party holding the signing key who rewrites an entire downstream chain consistently. The chain alone does not catch that. Only a copy held by somebody else does, which is why custody, and not cryptography, is the thing to ask about.

## Where AgenticRail stands, and what it does not claim

AgenticRail is a deterministic sequence-enforcement gate. An agent calls it before each step. The gate checks the step against the sequence the caller itself declared, and returns ALLOW or DENY before the step runs. A denied step does not run. Every decision, permitted or refused, produces a signed receipt written at the moment of the decision.

Three things follow from that design which are relevant to everything above.

**The record is contemporaneous by construction.** The receipt is not derived from logs afterwards; it is the artefact of the decision itself, written before the step executes and before anyone knows what will turn out to matter. There is no later assembly step in which a party with knowledge of a dispute selects what to include.

**Completeness has a referent.** Because the caller declares its step order in advance, a step that was skipped is a positive fact in the record rather than a silence, and a denial is recorded as a decision rather than as nothing having happened. That is the difference between a log that can only report what it contains and a record against which absence is measurable.

**Verification does not require us.** Receipts are signed with Ed25519 and the public keys are published. The JSON verification report carries the raw signature, the exact byte string that was signed, and the public keys inline, so verification runs offline with no call back to AgenticRail, no key and no account. Each receipt is hash-linked to its predecessor, so altering one breaks the chain detectably at the next link, and a sealed sequence cannot be reopened without leaving that break.

What it does not establish

- **It does not prove when.** The timestamp is signed, so it cannot be altered after signing without breaking verification. It is supplied by the caller and bounded — the gate refuses anything more than 300 seconds from its own clock — but it is asserted, not established against an independent time authority. A record of when is not proof of when, and the two should not be conflated in any setting where the distinction can be tested.
- **It does not assert that the action succeeded.** A receipt records that the enforcement decision was ALLOW, meaning the step was permitted. It does not claim the downstream action ran, completed, or produced a correct result. AgenticRail is an enforcement layer, not an execution runtime, and the executor's outcome is not signed into the receipt.
- **AgenticRail holds the signing keys.** The service is hosted, and that key custody is a real residual. It is narrowed by a separately credentialed archive copy held under different credentials, which raises the cost of a consistent rewrite without eliminating it. Closing it fully is a custodial arrangement, not an engineering change.
- **It holds no certifications.** Not SOC 2 audited, not ISO 27001 or ISO/IEC 42001 certified, and no certification is claimed anywhere on this site.
- **There is no AI in it.** No language model sits anywhere in the decision path and no model is consulted. The same payload against the same sequence state yields the same verdict every time, which is what makes a decision reproducible by someone else rather than re-generated.

Stating those limits on a page about litigation is deliberate rather than modest. A documented limitation is something you produce; the same limitation discovered by the other side is something that happens to you. Anything claimed here that could not survive being tested would be worth less than saying nothing.

You can check the mechanism rather than take any of it on trust. Paste a sequence ID into [report.agenticrail.nz/report](https://report.agenticrail.nz/report) and it returns the per-step enforcement log, signature and hash-link verification for every receipt, and, once a sequence is sealed, the comparison against the independently held archive copy. A demo sequence needs no key at all.

The [live demo](https://agenticrail.nz/demo/) lets you attempt the failures directly: replay a nonce, skip a step, act on a sealed sequence. Each attempt returns a denial and a receipt recording it.

There is a version of this whole argument that a carver already knows. A chisel has no undo. The cut is the record, made at the moment of the cut, by someone who did not yet know how the piece would turn out. Everything written afterwards about what you intended is commentary, and everyone can tell the difference.

This article is general information about how discovery and preservation obligations interact with system design. It is not legal advice, it does not create any professional relationship, and it does not describe the law of any particular jurisdiction as applied to any particular set of facts. Rules of civil procedure, preservation duties and sanctions doctrine vary between jurisdictions and change over time. Cases are cited with court, docket number and date so that any of them can be checked against the record rather than taken on this page's word, and where an order has been stayed that is stated. A decision described here is one court's reasoning on one set of facts, not a settled rule. Anyone with an actual or reasonably anticipated dispute should take advice from a qualified lawyer in the relevant jurisdiction.

Related [Procedural hallucination: when an agent reports a step it never ran →](https://agenticrail.nz/blog/procedural-hallucination-agent-skipped-steps/) [Why self-signed evidence fails an auditor →](https://agenticrail.nz/blog/self-signed-evidence/) [AI agent audit logs: what to record and why →](https://agenticrail.nz/blog/ai-agent-audit-log-best-practices/) [What AgenticRail is, in one page →](https://agenticrail.nz/product/)

[Back to AgenticRail](https://agenticrail.nz/) · [API documentation](https://agenticrail.nz/docs/) · [FAQ](https://agenticrail.nz/faq/)
