Federal employees’ conversations with ChatGPT and other generative AI systems may be subject to the Freedom of Information Act when agencies obtain, retain or use them for official work, even though no reported federal appellate decision has directly resolved the status of AI chat histories.

The emerging legal question turns on FOIA’s established definition of an “agency record,” rather than on whether a document was produced by a person or an AI model. Under the Supreme Court’s test in U.S. Department of Justice v. Tax Analysts, material generally falls within that category if an agency created or obtained it and controlled it when the records request was submitted.

That framework could cover prompts, model responses, uploaded documents, conversation histories and usage logs. Relevant considerations include whether officials relied on the material, whether it was incorporated into agency files, and whether the government can retrieve, manage or dispose of it. An AI response used to analyze a proposed regulation, summarize public comments, compare policy options or prepare an official draft would present a stronger case for treatment as an agency record than a conversation that was never used or retained.

Records generated through an agency-managed AI service are particularly likely to raise FOIA obligations. Government access to conversation histories, administrative logs and export tools can indicate control, as can agency rules governing retention. The case becomes clearer when an employee saves an output to a government drive, includes it in an email, shares it with colleagues or incorporates it into a memorandum or decision.

Existing litigation over other forms of digital information offers guidance but not a definitive answer. In Cause of Action Institute v. Office of Management and Budget, the U.S. Court of Appeals for the D.C. Circuit found that automatically created browser histories were not agency records under the circumstances because the agencies had not relied on or integrated them into their files, while employees largely controlled their deletion and retention. AI exchanges used deliberately in government work could differ from such passively generated data.

Using a personal ChatGPT account would not necessarily place an official conversation beyond FOIA. The D.C. Circuit previously rejected the idea that work-related communications are categorically excluded merely because they reside in a private email account. Whether an AI chat is retained, retrievable and used for agency business could therefore matter more than the account on which it was created.

Material held only by an outside AI provider presents a more difficult issue. Supreme Court precedent generally does not require an agency to acquire privately held records that it never obtained. Contracts between agencies and AI vendors could become important in that analysis, particularly if they give the government access to logs, conversation exports or retention controls.

The issue has begun moving from theory into public-records disputes. A federal FOIA lawsuit filed in 2025 by Democracy Forward requested categories that included generative AI searches, instructions, inputs, outputs, recommendations and reports related to alleged agency use. The case had not produced a reported merits decision establishing whether those materials were agency records.

State proceedings are also beginning to test similar questions under state transparency laws. In January 2026, Pennsylvania’s Office of Open Records treated some individual, unshared ChatGPT exchanges as exempt personal working papers. It did not accept the same blanket treatment for every conversation shared or reviewed during an agency AI pilot, instead applying record-specific and exemption-specific analysis. Public-records requests in Washington have also reportedly led to the release of thousands of pages of municipal officials’ ChatGPT histories connected to government work.

Classification as an agency record does not guarantee public release. Existing FOIA exemptions may still shield material involving internal predecisional deliberations, attorney-client communications, attorney work product, personal privacy, confidential business information, classified information or law enforcement. Agencies may therefore need to search and review responsive AI records while withholding or redacting protected portions.

As government adoption expands, agencies’ technical and administrative choices will help shape the outcome of future requests. Enterprise account controls, retention schedules, employee policies and vendor contracts can determine whether conversations remain available and whether an agency exercises sufficient control over them. Until an appellate court addresses generative AI records directly, those facts and traditional FOIA principles will govern the analysis.

Sources: AI regulation