Are the government’s conversations with AI accessible under public records laws and FOIA?

The following article originally appeared in Communications Lawyer and is published here with permission from the American Bar Association.

By Steve Zansberg

Serving as the mayor of a city or municipality is an extremely demanding job: having wall-to-wall meetings with city councilors, lobbyists, developers, public interest groups, activists, department heads, staffers, and officials from neighboring jurisdictions; attending numerous public events; and responding to direct contacts from constituents. Anyone holding such a 24/7 position, as well as that person’s staffers, would welcome assistance from ChatGPT, Claude, Gemini, or other AI chatbots utilizing large language model learning.

In 2025, a combined reporting project between Cascade Public Broadcasting and KNKX-TV exposed that city workers, including the mayor’s staff, in two Washington cities utilized ChatGPT to write mayoral letters, generate grant applications, draft policy documents, synthesize public comments, and compose replies to citizens and the media. The joint reporting effort revealed alleged bid-rigging performed through AI prompts and responses, and that half of a letter the mayor of Bellingham sent to state authorities seeking funds for a Native American tribe was actually copied, verbatim, from ChatGPT. That reporting was enabled by the successful use of the Washington Public Records Act. Similarly, in 2025, the Texas Department of Transportation produced numerous conversations between its employees and ChatGPT in response to a records request under that state’s public records law.

Steve Zansberg
Steve Zansberg

But not all public officials have been willing to provide their AI prompts and results to requesters under state and federal public records laws. As recently reported in Wired magazine, both the “Department” of Government Efficiency and the Department of Housing and Urban Development denied Democracy Forward’s Freedom of Information Act (FOIA) requests for the AI prompts and responses used in those agencies’ crafting of official policies; HUD cited the deliberative process privilege (FOIA Exemption 5) as grounds for its withholding decision. At the state level, the City of Colorado Springs, Colorado, recently refused to provide a local television station copies of the AI chatbot interactions of that city’s mayor, citing two exemptions from disclosure in Colorado’s Open Records Act: “work product assembled for the benefit of elected officials” and “deliberative process” materials.

Various academics and government accountability groups have recently sounded the alarm over the lack of transparency regarding how the government is using AI to conduct public business, including rulemaking. No court has yet published a decision applying either FOIA or a state public records act to government officials’ “conversations” with AI chatbots. While disputes over records access percolate their way up through the courts, this article examines what the public’s right to know “what their government is up to” is when it uses generative AI to conduct public business.

Determining how state and federal public records laws apply to this relatively new technology requires following the same analytic path that courts have used for decades to determine whether records generated by prior communications platforms (e.g., chat rooms, text email, audio/video recordings, Google searches, etc.) were subject to those laws. The first step in that process is to determine whether the particular “records” being sought constitute either “public records” under state law or “agency records” under FOIA. Only if that question yields a positive response does the court need to answer the second question: whether the government has met its burden of demonstrating that one or more statutory exemptions from disclosure of those records applies.

Which records are being sought?

There are multiple records associated with a government’s use of AI technology. As one commentator has aptly stated: “With agencies adopting AI tools that generate probabilistic scores, model outputs, or real-time alerts, we must ask: What parts of an AI system constitute a “record”? Is it the input data? The model’s decision? The training dataset? The algorithmic weights? Without guidance, lawyers and agencies are left in a legal gray zone.”

The underlying algorithm(s), filters, biases, and the large language dataset from which responses to prompts are generated all are of profound interest to the public if they are to understand how important policy decisions are made. The results generated by an AI chatbot are determined by the interaction of human prompts, the large language dataset, and the algorithmic programming for processing; accordingly, the public is entitled to know all of these data points, just as they are entitled to know the identities of the humans who contribute to the formulation of public policy.

Indeed, several states have passed so-called AI Transparency legislation that mandates the disclosure of the inner workings of AI programs, regardless of whether they are utilized by public officials or nongovernmental private persons. California law requires all police and sheriff’s departments to disclose publicly whenever AI has been used to generate any portion of an incident report and to retain the first draft thereof and the audit trail for as long as the official report is retained.

While the inner workings of the particular generative AI bot used by the government is of unquestionable public interest and concern, this article will focus exclusively on records of the prompts submitted by government officials (“inputs”) and the responses that AI provides to those prompts (“outputs”).

Inputs and outputs connected to official conduct are “public records” under states’ laws

The application (or nonapplication) of various records laws to a particular category of record depends, in large part, on how the relevant statute defines what is a “public record.” Most state’s public records laws generally define “public records” as (1) any “writing” — usually defined broadly to include any written communication “regardless of physical form or characteristics” (2) that is created, authored, produced, generated by a government employee, or “maintained, or kept” by a government agency (meaning over which it has either physical custody or a right of retrieval and access) and (3) whose contents bear some demonstrable connection to the conduct of public business. Thus, AI inputs or prompts unrelated to any official governmental function (e.g., “purely private” matters, like a personal grocery list or plans for a family member’s birthday party) would not be “public records,” even if they are generated by a public official on government-provided communications devices during regular business hours.

Because state public records laws are considered “remedial statutes,” courts have tended to provide an expansive, pro-access interpretation to statutory text defining “public records.” As one commentator has put it, regarding Washington State’s public records law: “Courts in Washington have historically taken a wide view of what constitutes a [public] record. For instance, in Belenski v. Jefferson County (2015), the court found that automatically generated “internet access logs” — which simply tracked when an agency computer accessed the web — were public records. If a passive log is a public record, a deliberate prompt typed by a public employee to generate government content might be as well.”

ChatGPT
Credit: Pexels, Tim Witzdam

Indeed, several state courts have held that metadata associated with digitized public records is an intrinsic part of those records, thus requiring government agencies to produce such information under states’ public records laws. Under these precedents, the content of a government official’s voluntary communications to an automated recipient, as well as the content of communications from an automated sender to a public official/employee, for use in his/her conduct of official functions, would qualify as “public records.”

Although no analogy is necessary to prove this point, consider a public official, in preparing various government reports or policy recommendations, inputting numeric “raw data” into a computer program (or a calculator) and then obtaining various results/analyses therefrom (e.g., sums, averages, means, standard deviation, etc.); no one would question that both the data inputted into and the tabulations produced by that program would constitute public records. That this analogy involves only numbers, not words, is a distinction without a difference. Indeed, that AI chatbots (unlike calculators) are notoriously susceptible to factual errors, and outright “hallucinations,” makes the need for public access to both the inputs and outputs all the more critical.

Indeed, California’s Special Districts Association has notified its members that “AI-generated content used in agency business will likely fall within C[alifornia] P[ublic] R[ecords] A[ct]’s broad definition of ‘public records.’ … Agencies must be prepared not only for compliance, but for public scrutiny of how AI shapes government communications.”

Similarly, writing in Coates’ Canons, the North Carolina local government law blog, Kristi Nickodem concludes that “[i]f a state or local government official or employee is using a generative AI tool (e.g., ChatGPT, Gemini, Claude, Copilot) to carry out the duties of their role, then both the prompts the individual gives to the AI tool (records ‘made’ in connection with the transaction of public business) and the outputs the individual receives from the AI tool (records ‘received’ in connection with the transaction of public business) would be subject to North Carolina’s public records This conclusion applies, with equal force, to numerous — if not all — other states’ public records laws.

Inputs and outputs connected to agency business are “agency records” under FOIA

The federal Freedom of Information Act (FOIA) applies only to “agency records” of Executive Branch agencies. As in state public records laws, “records” are defined broadly to include “any information” in “any format, including an electronic format.” As is true under states’ public records laws, records whose content is not germane to any official functions or activities of that agency do not constitute “agency records.” But the Supreme Court has made clear that the FOIA was intended to provide public access to “the information available to an agency in its decision-making processes,” including, by way of example, “studies, trade journal reports, and other materials produced outside the agencies both by private and governmental organizations,” which agency personnel use “[i]n performing their official duties.”

Under the above precedents, records generated by federal agency employees in the scope of their duties (i.e., inputting prompts into an AI chatbot) and the records received from the chatbot and kept by that employee for use in conducting that agency’s public business constitute “agency records” subject to FOIA.

The federal government is “all in” on using AI to conduct the public’s business

On April 3, 2025, Director of the Office of Management and Budget Russell T. Vought issued Memorandum M-25-21, mandating all federal “agencies must adopt a forward-leaning and pro-innovation approach that takes advantage of [AI] technology to help shape the future of government operations … Agencies are directed to accelerate the Federal use of AI. Section 4 of that memo imposes additional monitoring and evaluation of pilot testing of AI that performs “high impact” functions: “AI is considered high-impact when its output serves as a principal basis for decisions or actions that have a legal, material, binding, or significant effect on rights or safety.”

A handful of concrete examples exemplify the general trend. In July 2025, the Environmental Protection Agency publicly touted that it had, as of that date, documented 103 instances of agency employees’ “AI use or planning,” and its administrator declared, “At EPA, we’re embedding innovation into our systems, not resisting it. From AI tools that speed up environmental reviews to smarter monitoring and emissions tracking …” In September 2025, the Federal Communications Commission (FCC) publicly proclaimed its “commitment to accelerate Federal use of AI.” Indeed, in its first publicly released “AI Use Cases” in February 2026, the FCC reported that it had licensed Microsoft Copilot, for between 101–1,000 agency users, for the purpose of “[g]enerating first drafts of documents, briefing, or communication materials using AI.” In February 2026, the Department of Justice reported 315 instances of AI use in 2025, including, controversially, “using AI to predict rates of recidivism for current inmates and sex offenders.” And in July 2026, the Department of Veterans Affairs announced that “VA GPT is an on-network generative AI chat interface that employees are using to assist with basic administrative tasks (drafting emails, summarizing documents, summarizing meeting notes, etc.) [, … with] over 95,000 users onboarded.”

Under existing caselaw, all “writings” in agencies’ possession, custody, or control that document, or are utilized in conducting official agency business, constitute “agency records” subject to FOIA. And an executive order entered at the end of the first Trump administration dictates that “Agencies shall be transparent in disclosing relevant information regarding their use of AI to appropriate stakeholders, including the Congress and the public, to the extent practicable and in accordance with applicable laws and policies.”

Logistical hurdles to accessing public records and agency records

Merely because a document or record is covered by a state’s public records law or FOIA does not mean you can obtain a copy of it. A group of researchers, led by Alex Spangher at Stanford University, is engaged in a systematic survey of both state and federal agencies and their use of AI chatbots in performing public business. In April 2026, the group submitted 24 FOIA requests to various federal agencies and 81 requests to state and local governments across the nation under states’ public records laws. Those requests sought records showing how widespread their use of generative AI is, the policies they have in place governing such use, and records of the actual AI chatbot conversations of public employees.

The group’s preliminary findings have cataloged deployments of AI by 53 federal agencies, all 50 states, and 77 local governments. The group also has assembled the first corpus of government AI chatbot logs, comprising 3,216 chat threads, between 2023 and 2026. The study’s authors report that the two most frequently encountered barriers to accessing AI chatbot conversations are (1) the agencies’ claim/assertion that they have “no records responsive to the request,” and (2) the exorbitant costs being assessed as the condition for providing the responsive records. The state of Colorado, for example, asked the researchers for $9 million to produce records responsive to the group’s requests.

Both of these barriers — (1) inadequate records retention and (2) prohibitive costs imposed on requesters for search and retrieval — have thwarted public access to digitized and cloud-based records, even before the advent of generative AI. While solutions to these two significant roadblocks to public access are beyond the scope of this article, advocates for the public’s right to know must focus their efforts on requiring AI-related records retention and challenging exorbitant fees that pose an insurmountable barrier to accessing those records.

Notably, on point (1) above, the U.S. Army has issued an AI Compliance Memorandum that expressly requires all system owners to “ensure that all user interactions, including prompts and AI-generated content, are properly identified, retained and secured as official records” and to “provide access to AI prompts and content classified as government records and maintain them to support timely FOIA responses.” Similarly, the Department of Homeland Security has contracted with OpenAI to process and maintain all communications with the department as federal records that may be subject to FOIA requests.

Statutory exemptions most likely to be asserted in response to requests to access AI chatbot conversations with public employees

Records subject to either state public records laws or the federal FOIA are subject to various exemptions from disclosure. Among them are personnel files, investigatory files of criminal law enforcement, trade secrets, confidential commercial data, privileged records, and various other expressly itemized exceptions.

This article will not survey all the statutory exemptions that governments may assert as grounds to withhold AI chatbot conversations. Instead, it will focus on the statutory exemptions most likely to be asserted as grounds for nondisclosure.

And, as noted above, both the City of Colorado Springs and the “Department” of Government Efficiency have denied public access to public officials’ AI prompts and responses, asserting they are subject to two related state-law exemptions: “work product … assembled for the benefit of elected officials” (an exclusion from Colorado’s definition of “public records”) and the deliberative process privilege. How might those related statutory exemptions fare when asserted as grounds for withholding government employees’ AI chatbot prompts and responses under state and federal records laws?

Government offices assert that when an elected official, or other government employee, jots down preliminary thoughts on a paper pad or (using a laptop, phone, or other digital device) prepares a draft of a speech or a proposed policy, such writings constitute “work product assembled for the benefit of an elected official” or deliberative process material. Assuming, for present purposes, that is correct, why should the transmittal of those drafts to an AI chatbot (or to Google, Meta, Verizon, or Microsoft) transform those writings into something not protected by those exemptions? If an AI chatbot performs the same functions as a human staffer or outside consultant, e.g., proposing revisions or actually generating the “first draft” of an agency policy, how are such writings any different from those generated by a human, in terms of privilege? To respond to these questions, we must consider the underlying purposes of those related privileges/exemptions.

Are humans required at both ends of the “conversation”?

A creature of the common law, the deliberative process privilege serves to shield from public view pre-decisional communications among government employees (and/or outside consultants), particularly recommendations, advice, and subjective opinions of subordinates to higher-ranking superiors — so that the person transmitting such views will not be “chilled” from offering frank and candid advice. The privilege “serves to assure that subordinates within an agency will feel free to provide the decisionmaker with their uninhibited opinions and recommendations without fear of later being subject to public ridicule or criticism.”

But does this rationale make any sense when the recommendations or “advice” come not from a human being, but from an inanimate machine or computer program? AI chatbots are programmed to generate responses to prompts automatically, regardless of the identity or rank/position of the human who submits them, the nature of the prompt, or the purpose to which the response is to be used. Thus, the principal rationale for the so-called privilege — to avoid “chilling” the transmission of candid recommendations, opinions, or advice from subordinates to their superiors — seems completely inapposite to information provided by a computer program.

As John Davisson, deputy director of enforcement at the Electronic Privacy Information Center, has stated: “If there is a deliberative process, occurring between human beings that work for [a federal] agency, where the material is both pre-decisional and leading up to some sort of decision, that might be a justifiable assertion of deliberative process privilege there,” but “AI systems, computers are not entitled to candor.” In other words, being notified that its responses to prompts will be disclosed to the public is not going to “chill” a computer program from processing the prompt(s)and generating responses as dictated by its programming.

However, federal courts applying Exemption 5 have not required two human participants sharing views, opinions, or thoughts on contemplated agency action. For example, two courts have held that the exemption applies to computer programming used to process selected data input by a government employee or a retained outside expert.

Indeed, Exemption 5 even has been applied to a government official’s own writing, not shared with any third party, generated for his/her own benefit, i.e., in preparing a “working draft” or notes for future consideration in formulating agency policy. Why is that? Because in addition to the “avoid chilling candid communications” rationale, the deliberative process privilege also serves “to protect against premature disclosure of proposed policies before they have been finally formulated or adopted; and to protect against confusing the issues and misleading the public by dissemination of documents suggesting reasons and rationales for a course of action which were not in fact the ultimate reasons for the agency’s action.”

So, at least some courts have held that two humans exchanging communications is not a prerequisite for asserting that AI inputs and outputs are subject to the deliberative process privilege. Accordingly, whether the invocation of that privilege will be sustained must turn on the particular factual context of each case: How “deliberative” in nature are the AI chatbot communications, and how relevant is that content to an actual policy-making decision? Of course, pre-decisional materials that form the basis of actual agency action (and are incorporated into that policy or decision) are not subject to the deliberative process privilege; but it may be difficult, without an audit trail, to determine which portions of AI chatbot outputs were so incorporated.

Does conversing with an AI chatbot waive all claims of privilege?

For purposes of this discussion only, let’s assume that certain prompts submitted to an AI chatbot, in a particular factual context, would ordinarily constitute “deliberative process” material. Like all others, the deliberative process privilege can be waived through voluntary disclosure to third parties. So, does the “sharing” or disclosure of those prompts to an AI chatbot waive that privilege?

One federal court has applied the privileges routinely asserted as grounds for withholding “documents” from discovery in litigation to AI chatbot inputs and outputs, finding that neither attorney-client privilege nor the work product doctrine applies, while two other federal courts have ruled that such conversations by pro se litigants can qualify for protection under the work product doctrine.

In March 2026, Judge Jed Rakoff, of the Southern District of New York, found that an AI user’s prompts to the AI chatbot Claude (by Anthropic) were not subject to either of those doctrines. The party asserting those privileges, Bradley Heppner, was a criminal defendant, charged with securities fraud and other crimes. He claimed he had used Claude to prepare outlines of defense strategies for his attorneys, although it was undisputed that his attorneys had not requested him to do so. Judge Rakoff categorically denied Heppner’s assertion of privilege with respect to “the AI documents.” Not only is Claude “not an attorney,” and therefore incapable of providing legal advice, but more importantly, the AI communications were not “confidential” because “the written privacy policy to which users of Claude consent provides that Anthropic collects data on both users’ ‘inputs’ and Claude’s ‘outputs,’ that it uses such data to ‘train’ Claude, and that Anthropic reserves the right to disclose such data to a host of ‘third parties,’ including governmental regulatory authorities … The policy clearly puts Claude’s users on notice that Anthropic … may ‘disclose personal data to third parties in connection with claims, disputes[,] or litigation.’ … [Accordingly,] Heppner could have had no ‘reasonable expectation of confidentiality in his communications’ with Claude.”

Under Judge Rakoff’s ruling in Heppner, it would appear that sharing information with an AI chatbot waives any claim to confidentiality, or at least it might. Heppner’s ruling is limited to that case’s particular facts. It is far from clear that the same would be true if the operative facts were different. Suppose, for example, that the government employee’s prompts were input into an AI chatbot that did not utilize user prompts to train it, and the chatbot was contractually bound to not disclose either inputs or outputs to any third party. In the dispute mentioned above between a television station and the City of Colorado Springs, the City maintains that the two AI chatbots the mayor used to help him draft speeches and correspondence are not trained on user prompts and are contractually bound not to share any information it receives or provides with any third party. Thus, the City asserts, no waiver of any privilege has occurred.

Recall, too, that two federal courts have distinguished Heppner, in a markedly different procedural and factual context, and have held that pro se litigants submitting prompts to AI chatbots to aid them in preparing court filings did not waive their claim to the “attorney work product” doctrine applicable in civil discovery disputes.

So, here too, the outcome of future lawsuits challenging denials under state and federal records law of AI chatbot conversations of government employees is likely to turn on the particular circumstances under which those writings are generated and shared.

Conclusion

Agencies and officials at all levels of government have widely embraced generative artificial intelligence in conducting public business. AI is the latest in a long line of technological innovations that facilitate human communications: the written word, printing press, telegraph, telephone, radio, audio/video recording, email, text messaging, web-based chatrooms, Zoom. As Judge Rakoff has stated, while technology advances at breakneck speed, legal principles remain unchanged. Public records laws, including FOIA, were enacted to enable the citizenry to monitor the work of, and thereby hold accountable, everyone in government, i.e., those constitutionally bound to serve the interests of We the People.

AI chatbots are designed by humans and are “trained” using massive amounts of human-generated text, images, and audio. Unlike all the other communications media listed above, generative artificial intelligence independently creates content and, in doing so, based on its programming, inevitably introduces certain biases, distortions, and outright factual errors into the conversations in which it participates. This justifies an even greater public interest in knowing (1) which AI chatbot(s) are being utilized to formulate public policy and otherwise conduct public business, (2) who is using AI chatbots, (3) what algorithms and datasets are utilized by those chatbots, (4) what are the actual prompts that government officials submitted to those chatbots, (5) what are the responses generated by the chatbots, and (6) how are those responses thereafter put to use in conducting public business.

Practically all of these data points are automatically documented in digitized records made, maintained, or kept by government offices that utilize AI chatbots. And all of those writings are quite appropriately subject to public scrutiny under state and federal public records laws. AI use by government has quickly become the rule, not the exception, and (as is true outside government) will soon be practically ubiquitous. Without access to those writings, the public will not be able to understand what its government is up to.

Steve Zansberg is a Denver-based media and First Amendment attorney. He is president of the Colorado Freedom of Information Coalition.

Subscribe to Our Blog

Loading