# AI evidence preservation and production pack - TheAICommand artefact

Name: AI evidence preservation and production pack
Date: 2026-09-27
Source: https://theaicommand.com/library/artefacts/regulator-notice-to-produce-prompt-histories
Article: https://theaicommand.com/whs/regulator-notice-to-produce-prompt-histories
Licence: Free to use and adapt internally. Attribution appreciated. No warranty. Educational purposes only.
Disclaimer: General information and education only. Not legal, compliance, financial, or professional advice.

---

### Part A. The systems inventory

One row per system that creates a prompt, an output or an agent action.

```text
AI RECORDS SYSTEMS INVENTORY

System ID: [SHORT_STABLE_ID]

1. Name, vendor, plan tier, tenancy: [ ... ]
2. What is captured: [ ... ]
3. Where the record lives: [ ... ]
4. Retention setting today: [N] days, read [DATE] by [NAME, ROLE] in [CONSOLE]
5. Who can change it: [NAME, ROLE]. Backup: [NAME, ROLE]
6. Who can export: [NAME, ROLE] via [ROUTE] to [FORMAT]
   Route last tested: [DATE]. Volume and elapsed time: [ ... ]
7. Privilege and confidentiality flag: [ONE OR MORE PART C VALUES]
8. Owner: [NAME, ROLE].  Next check: [DATE]

Do not record a team where the template asks for a person.
Do not carry a retention figure forward without reading it again.
Do not close a row with an untested export route.
```

**Field 1. Name, vendor, plan tier and tenancy.** Tenancy means whose storage holds the record, yours or the vendor's.

A good entry reads "Shift handover assistant, [VENDOR], Enterprise plan, vendor-hosted tenancy in [REGION], contract [REF]". A bad entry is a bare brand name, because the plan tier decides which retention and export controls exist at all, and two teams on two tiers of the same product hold different records. A blank tenancy field tells you that you cannot yet say whether you produce the material or the vendor does, which is the first question a notice forces.

**Field 2. What is captured.** List the categories rather than summarising them: prompts, outputs, attachments, retrieval sources, tool calls, agent actions, and the configuration version in force.

A good entry names all of them. A bad entry says "conversations", which describes what the user saw and not the tool call that moved a permit state. A blank field tells you the row describes a product rather than a record, and the row is not finished.

**Field 3. Where the record lives.** Name the store, and name it separately from the interface. Product store, admin or compliance API, a mailbox folder reached only by eDiscovery, a log platform, or a store you built yourself.

Microsoft states plainly that messages visible in your AI apps are not an accurate reflection of whether they are retained or permanently deleted for compliance requirements. Treat that as the general rule and not a single vendor's quirk. A good entry reads "Purview retention store, hidden mailbox folder, reachable by eDiscovery only, not from the chat window". A bad entry is "in the app". A blank field tells you nobody has looked past the interface.

**Field 4. Retention setting today, in days, with the date checked.** A number, a source and a date, read from the console rather than recalled.

Three positions from three vendors show why the field is a number and not a policy. On the Anthropic API, inputs and outputs are automatically deleted on the backend within 30 days of receipt or generation, subject to stated exceptions including longer retention under the customer's control (as at 1 July 2026). OpenAI's enterprise privacy page, updated 8 January 2026, states that you control how long your data is retained for ChatGPT Enterprise, Healthcare and Edu, and that deleted conversations go within 30 days unless retention is legally required. For Microsoft's other AI apps category, which includes ChatGPT, Google Gemini and DeepSeek, prompts are captured only where a collection policy with the setting to capture content exists, so without one nothing reaches the store eDiscovery searches.

A good entry reads "30 days, backend deletion, default unchanged, read in [CONSOLE] on [DATE] by [NAME, ROLE]". A bad entry is "per vendor policy", or worse, a figure lifted from the organisation's own records retention schedule, which does not bind a vendor default. A blank field tells you the safety function is relying on a deletion date chosen by a product team.

**Field 5. Who can change it.** A name and a role, never a team and never a shared mailbox.

A good entry names a person and a backup. A bad entry says "IT", which is not somebody you can reach on a Saturday with a hold to apply. A blank field tells you that when the hold issues, nobody has the authority to suspend deletion, and the first hour will go on finding out who does.

**Field 6. Who can export, by which route and format.** Record the route, the format, the date the route was last tested, and how long the test took.

Administrators reach an audit log through the Enterprise Compliance API in one product and through eDiscovery in another. The chat window is rarely the production route. A good entry reads "[NAME, ROLE] via the compliance API, JSON, tested [DATE], [N] records in [N] minutes". A bad entry is "export to PDF from the app". A blank or untested route tells you the first person to run it will be doing so against a compliance date, on a system they have never exported from.

**Field 7. Privilege and confidentiality flag.** One or more values from Part C, applied to the source.

A blank field tells you the separation work has been deferred to the day of the notice, which is the one day it cannot be done calmly.

**Field 8. Owner and next check date.** A good entry reads "[NAME, ROLE], next check [DATE], and on any plan change or vendor migration". A blank next-check date tells you the row is a snapshot rather than a control, and it will be wrong before anyone reads it again.

### Part B. The hold instruction

A retention policy runs on a timer and does not know a notice exists. A hold overrides it, in writing, to named people, on the day.

```text
AI EVIDENCE PRESERVATION HOLD

Issued by: [NAME], [ROLE]
Issued at: [DATE], [TIME], [TIMEZONE]
Trigger: [NOTICE DATED ... / INSPECTOR ENTRY ON ... / INCIDENT REF ...]
Matter: [PLAIN DESCRIPTION OF THE WORK, LOCATION AND PERIOD]
Period covered: [START DATE] to [END DATE OR ONGOING]
Systems in scope, from the inventory: [LIST SYSTEM IDS]

Required actions, completed by [DATE] and confirmed in writing:
1. Suspend automated deletion, retention expiry and archive jobs for the
   listed systems and periods.
2. Suspend end-user deletion for the listed accounts, or export a preserved
   copy where suspension is not available in the product.
3. Preserve the configuration in force during the period, including system
   prompts, tool permissions, model version and any change log.
4. Record the exact method used to suspend deletion, and who applied it.
5. Confirm whether any in-scope material was already deleted, and on what date.

Named holder responsible for confirming, per system: [NAME, ROLE]
Hold remains in force until released in writing by: [NAME, ROLE]

Do not delete, edit, re-run, regenerate or overwrite any in-scope record.
Do not export in-scope material to a personal device or personal account.
Do not use an AI tool to summarise or rewrite in-scope material before
production.
Do not release the hold on a verbal instruction.
```

Item 2 carries a fallback because in-product suspension of end-user deletion is not always available. Where it is not, export a preserved copy and record that you did.

Item 3 exists because the state that mattered was produced by a system prompt, a tool permission set and a model version, and all three change. A transcript without the configuration that governed it proves less than it appears to.

Item 5 asks whether material was already deleted, and the answer belongs in writing on day one. Deletion before a notice is a fact you disclose. Deletion after one is a position you must defend, and the Act's answer to non-production is section 155(5) or section 171(6), with section 188 making intentional obstruction of an inspector an offence.

A good confirmation names the method: "Retention job [ID] disabled in [CONSOLE] at [TIME] by [NAME, ROLE], verified by re-reading the setting". A bad confirmation is the single word "done", which records nothing a reviewer can test and nothing you can produce. A hold with no confirmations against it is not a hold, it is a sent email.

### Part C. The privilege and confidentiality flag

Flag every source now, with one or more of four values. A source can carry several.

The flag tells you where separation work will be needed and roughly how much. It does not excuse production. Only section 269 does that, and only for privileged material.

- **Legal privilege claimed.** Section 269 of the Commonwealth Act provides that nothing in the Act requires production of a document that would disclose privileged information, and section 155 of the Occupational Health and Safety Act 2004 (Vic) is to the same effect while also naming client legal privilege. The claim is made per document, not per system, so a mixed store means somebody separates documents against a deadline.
- **Personal information.** Production is still compelled. Section 271 governs what the regulator may then do with it. Flagging changes your handling, not your obligation.
- **Worker health information.** A different requester gets a different answer. Under section 68(3) a health and safety representative is not entitled to a worker's personal or medical information without consent. This flag stops a legitimate internal request becoming a disclosure nobody can undo.
- **Third-party confidential.** Vendor material, another client's data, or contractor records. It rarely stops production, but it decides who you notify and when.

A good flag is specific and dated: "Legal privilege claimed on the incident review channel only, from [DATE]. Personal information throughout. Owner [NAME, ROLE]". A bad flag is the single word "privileged" applied to an entire system, which collapses the first time it is tested and consumes the days you needed for the separation. A blank flag tells you the sorting has not started, and sorting is the slowest step in any production.

### Part D. The production log

One entry per item, written at the time and never reconstructed afterwards.

```text
AI EVIDENCE PRODUCTION LOG

Entry: [N]
Item reference and description: [ ... ]
Source system: [SYSTEM ID FROM PART A]
Export route: [ ... ]        Format: [ ... ]
Date range covered: [START] to [END]
Filters or search terms applied: [EXACT STRINGS, NOT A DESCRIPTION]
File count: [N]   Total size: [ ... ]   Hash of the export: [ ... ]
Produced to: [NAME, AGENCY]        Date and time produced: [ ... ]
Power relied on: [SECTION 155 NOTICE / SECTION 171(2A) NOTICE /
  INSPECTOR REQUIREMENT ON ENTRY / VOLUNTARY PRODUCTION]
Authorised by: [NAME, ROLE]
Privilege or confidentiality claimed: [OVER WHAT, ON WHAT BASIS, BY WHOM]
Items withheld and why: [ ... ]
```

Filters and search terms belong in the log because they define what you did not produce. A regulator can ask why an item is missing, and the answer is either a recorded search or a shrug.

The hash exists so the copy you produced can be shown to be the copy you preserved. Record it at export, not later.

The power relied on matters, so name it rather than writing "requested". Section 155(3) requires a notice to state the section, warn that failing to comply without reasonable excuse is an offence and, where it seeks information, documents or answers, explain the effect of sections 172 and 269 and state that the person may attend with a legal practitioner. If a notice does not do those things, record that in the log at the time.

One line to keep out of the log. Section 172(1) removes the privilege against self-incrimination as a ground for refusing to answer or produce, and the use immunity in section 172(2) operates only where the person is an individual. What a body corporate produces is admissible against it. Do not write the log as though an immunity protects the organisation, because it does not.

### What stays a human decision

Four decisions, and no model makes any of them.

- What falls inside the notice.
- Whether privilege is claimed, and over what.
- Whether a reasonable excuse exists, remembering that section 155(6) puts the evidential burden of establishing it on the accused.
- The decision to produce.

A model can list candidates, cluster them and draft an index. It does not sign the covering letter, and it is not run across in-scope material before production, which is why that prohibition sits inside the hold itself.
