STRAIGHT TO THE POINT
Prompts, outputs, and files submitted to artificial intelligence tools, particularly large language models (LLMs), may become part of the evidentiary record in litigation, investigations, and audits. The critical distinction is between content generated by the tool and the record created by the user: an AI-generated answer may be unreliable as proof of an external fact, while the interaction history may shed light on what the user knew, sought, considered, or intended to do. The answer is not a blanket prohibition, but a governance framework that protects sensitive information, manages the records these tools create, and reduces inappropriate use, including the risk that consequential decisions may be based on carelessly framed prompts or unverified outputs. We conclude with practical measures companies can adopt to promote the responsible use of these tools.
Brazilian law already applies to these records
- There is no need to await AI-specific legislation before prompts, outputs, and logs (records of user activity and access) may be treated as evidence. The Brazilian Code of Civil Procedure recognizes means of proof not expressly enumerated by statute and governs the use of electronic documents. As with any form of digital evidence, their evidentiary weight will depend on lawful collection, authenticity, integrity, and the context in which they were created.
- In criminal matters, the collection and use of these records are also subject to specific rules governing the admissibility of evidence and the preservation of the chain of custody. Similarly, in investigations of various kinds, electronic records may be requested, preserved, collected, and examined by the competent authorities within the scope of their statutory powers. An interaction stored in a corporate account, on a company device, or through an internal integration should not be regarded as invisible or ephemeral merely because it occurred through an AI tool.
- In addition to records maintained internally, the tool provider may itself hold information from which evidence can be obtained. Privacy policies and terms of use may indicate whether, and under what circumstances, interaction data may be disclosed to authorities, subject to the limitations imposed by applicable law.
- Not every prompt – that is, the request or instruction submitted by the user – is self-explanatory or sufficient to establish wrongdoing. AI records may be incomplete, contain inaccurate responses, or reflect nothing more than the exploration of a hypothesis. Their evidentiary weight will depend on the chain of custody, attribution to a particular user, the version of the tool, the files submitted, and, above all, consistency and convergence with other evidence and information.
- Although storage in a corporate account, device, or system may facilitate the preservation and attribution of these records, it does not, by itself, authorize unrestricted access or monitoring. The lawfulness of collection will depend, among other factors, on the policies communicated to users, the purpose and proportionality of the measure, applicable data protection, privacy, and confidentiality requirements, and, where appropriate, judicial authorization. The implementation of controls and monitoring mechanisms should be coordinated with privacy, human resources, and information security teams, particularly within corporate groups subject to multiple employment and data protection regimes.
The critical distinction: machine-generated content and user conduct
- A recent decision by Brazil’s Superior Court of Justice (STJ), apparently the first to address generative AI as evidence, helps frame the issue. In HC No. 1,059,475/SP, the Fifth Panel ordered the exclusion of a report produced using generative AI tools, without adequate human validation, that purported to establish facts relevant to a criminal proceeding. The decision concerns the reliability of AI-generated output when offered as a substitute for technical or expert analysis.
- A separate question is the evidentiary significance of the interaction history itself. An AI-generated answer may be unreliable as proof that a particular event occurred. A prompt drafted by the user, however, is a recorded human statement: it may indicate what information the user possessed, what questions the user sought to resolve, what hypotheses the user considered plausible, what objectives the user pursued, and what line of reasoning preceded a particular decision.
- That evidentiary trail may extend well beyond a single question. The sequence of interactions may reveal the development of a strategy, the alternatives tested in succession, the responses rejected, the prompt revisions made to obtain a particular result, and the degree of direction exercised by the user. Documents and data uploaded or transcribed may also be relevant, as may references to specific individuals, competitors, customers, or transactions; instructions to alter tone or conceal particular information; and follow-up requests intended to convert the output into a communication, recommendation, or action plan.
- Depending on the tool and its configuration, the interaction may also be associated with metadata such as the user’s identity, the account used, date and time, the device or corporate environment through which access occurred, files uploaded, outputs generated, and edit history. These elements will not necessarily be available in every case, and their significance will depend on the integrity, authenticity, and context of the records. When assessed together with emails, messages, internal documents, data, and subsequent conduct, however, they may help reconstruct the decision-making process, illuminate the knowledge and intent of those involved, and place the facts under investigation in context.
What the early foreign decisions suggest
- In United States v. Heppner[1], federal agents seized documents reflecting the defendant’s interactions with the Claude platform. The court rejected claims of attorney-client privilege and work-product protection over the platform output. The queries had been initiated by the user, without counsel’s direction, on a public platform whose terms did not support a reasonable expectation of confidentiality. Sending the material to counsel after the fact did not retroactively cloak with privilege a communication that was not privileged when created.
- Heppner should not, however, be read to mean that every use of AI necessarily defeats all forms of legal protection. Subsequent U.S. decisions have taken a more flexible approach to materials prepared in anticipation of litigation, particularly where use of the tool did not materially increase the likelihood that an adversary could gain access. The analysis may turn on the nature of the protection asserted, the purpose of the interaction, the involvement or supervision of counsel, and the technical and contractual conditions governing the tool. The law remains emerging and unsettled.
- In Fortis Advisors v. Krafton[2], the Delaware Court of Chancery relied on queries submitted by Krafton’s chief executive to ChatGPT to reconstruct the strategy adopted in a dispute involving an earn-out obligation. The issue was not whether the tool’s legal guidance was correct. Rather, the interaction history helped explain the buyer’s rationale for removing the founder-executive, assuming operational control of the acquired company, and implementing the measures that later became the subject of litigation. As a remedy, the court ordered the executive’s reinstatement and equitably extended the earn-out period for the duration of the exclusion.
- Although these decisions are not binding in Brazil and arise under distinct regimes of discovery, attorney-client privilege, and work-product protection, they foreshadow issues that may soon arise before Brazilian courts and authorities.
- The tool selected also matters. Public accounts, enterprise environments, and internally deployed solutions may be subject to materially different terms concerning retention, model training, administrator access, and data sharing. Although there is no settled view that the use of an enterprise solution is, by itself, sufficient to preserve confidentiality or privilege, these features may bear on whether the user had a reasonable expectation of confidentiality and whether the interaction amounted to disclosure to a third party.
CONFIDENTIALITY: THE WARNING FROM MUNIR
In the United Kingdom, Munir v. Secretary of State for the Home Department principally concerned a representative’s submission of fabricated authorities generated by an AI tool – so-called hallucinations. Alongside that central issue, the Upper Tribunal warned that submitting confidential documents to a public AI tool may breach duties of confidentiality and jeopardize attorney-client privilege. The decision distinguished such use from closed enterprise solutions subject to contractual restrictions on model training and data processing.
Accordingly, the use of public tools or inadequately contracted solutions may jeopardize confidentiality and complicate the assertion of legal protections. The consequences, however, must be assessed in light of the solution’s architecture, its data-processing terms, and the Brazilian rules governing professional secrecy and legal privilege.
For Brazilian companies, the operational lesson is straightforward: before using AI with sensitive materials, determine where the data are stored, the purposes for which they are used, and who may access them.
CAUTION: Sharing an interaction with the legal department after the fact does not necessarily make it privileged if the content was created without legal direction or outside a confidential environment.
Why this matters in investigations, including internal investigations
15. Although there is not yet a settled body of law addressing the evidentiary weight of prompts, outputs, and AI interaction histories, public authorities and internal investigative teams routinely examine electronic records to reconstruct events, decisions, and information flows. The use of AI in the workplace adds a new documentary source to that record.
16. An interaction in which an employee submits sensitive information, tests alternative courses of conduct, or seeks recommendations regarding a particular decision may be relevant not because the machine’s answer was correct, but because of what the user disclosed, the hypotheses the user considered, and the subsequent use of the output. Standing alone, such a record will rarely be conclusive. It may nevertheless become significant when assessed together with emails, messages, internal documents, and other elements of the investigation.
17. From an antitrust perspective, the closest analogy is the well-established practice of Brazil’s competition authority, CADE, of relying on messages exchanged through applications such as WhatsApp and Telegram as evidence in cartel investigations. In principle, CADE’s powers to request documents, conduct inspections, and seek search-and-seizure measures may extend to other corporate records, just as they extend to other forms of electronic communication and documentation, subject to the applicable legal requirements.
What companies should do now
18. The corporate response should not be a blanket ban on AI tools, which is generally unrealistic and difficult to enforce. The objective should instead be to reduce informal, uncontrolled, and insufficiently considered use, recognizing that each interaction may implicate confidentiality, information security, data protection, regulatory compliance, and evidentiary risk.
19. AI use should therefore be integrated into the company’s existing governance framework, with clear rules on approved tools, permitted information, access to records, retention, and human oversight. The following measures are particularly important:
- Map and classify the tools in use, including personal accounts, enterprise solutions, embedded AI features, and API integrations. Identify the business functions, use cases, and categories of information involved.
- Define permitted and prohibited uses in an acceptable-use policy that identifies approved use cases and information that may not be submitted, including privileged materials, personal data, trade secrets, competitively sensitive information, and content subject to contractual confidentiality obligations.
- Set specific rules for legal and investigation-related uses, including when AI must be approved, directed, or supervised by the legal department or outside counsel. An intention to seek legal advice later may not be sufficient to protect the material.
- Review contracts and technical settings, including retention, model training, data location and transfer, administrator access, security, exportability of interaction histories, audit trails, and responses to government requests. Heppner illustrates the point: the provider’s reservation of a right to disclose data to regulators was central to the court’s analysis.
- Separate personal and corporate accounts and, where feasible, block unauthorized AI tools on company devices and networks.
- Control access and consequential decisions by defining who may use each tool, who may review interaction histories, and when human validation is required. Business, legal, financial, and personnel decisions should not rely solely on AI-generated content.
- Integrate AI records into the company’s records-management framework, with predefined retention periods, consistent deletion criteria, and holds when a preservation obligation arises in connection with an investigation, audit, dispute, or internal proceeding.
- Train higher-risk functions using concrete examples, covering what may be submitted, how prompts are framed, the risks created by sequential interactions, output verification, and channels for reporting misuse or incidents.
- Establish monitoring and incident-response mechanisms, including periodic reviews, reporting channels, and procedures for improper submissions of confidential information, personal data, or other sensitive content.
20. We hope you found this update insightful. If you have any questions, feedback, or would like to discuss any of these topics further, please feel free to reach out. Thank you for reading.