AI Prompt Discovery in 3M Litigation Signals New Governance Challenges
Share
The Watson Grinding litigation involving 3M has highlighted a critical emerging risk for enterprises adopting generative AI: the potential for AI chat histories to become discoverable legal evidence.
During the litigation, an engineering expert retained by 3M used ChatGPT to assist with his analysis. The resulting discovery process revealed specific prompts, including one instructing the system to “show how 3M is 0% at fault.” While there is no evidence that 3M directed the expert to use the AI or enter that specific prompt, the incident underscores how AI interactions can move beyond the finished report to become a central part of a legal inquiry.
In one instance, a deposition went off the record following demands for the underlying prompts, resulting in the production of more than 350 pages of previously undisclosed ChatGPT material.
Beyond Input Protection
For much of the current AI era, enterprise risk management has focused on input security. Organisations have implemented strict controls to prevent employees from uploading proprietary code, sensitive customer data, or personally identifiable information (PII) into public AI models.
However, the 3M case suggests that protecting inputs only addresses part of the governance challenge. AI interactions also create a record of the decision-making process itself. This includes the assumptions made, the alternatives rejected, and the lines of inquiry pursued by a user to reach a preferred outcome.
The American Bar Association has already noted that AI chat histories are an emerging source of discovery material. These conversations can preserve abandoned theories and reasoning that never appear in a final, polished document, yet remain highly relevant during investigations or litigation.
Implementing Consequence-Based Governance
The shift in focus moves the conversation from simple acceptable-use policies toward comprehensive information lifecycle management. This involves deciding when to retain AI interactions, who owns the resulting records, and how they are governed.
Rather than attempting to archive every prompt—which would create significant privacy, security, and operational risks—organisations may need to adopt a consequence-based approach to governance. The level of oversight should scale with the risk associated with the task.
For low-risk activities, such as refining the tone of an email, minimal documentation may be necessary. However, for high-consequence work, such as safety analyses, audits, or significant employment decisions, organisations may require the ability to reconstruct the entire process. This provenance would include the material prompts, the specific AI system used, and evidence of meaningful human review.
Effective governance will require coordination between CIOs, legal, compliance, and records management teams. The goal is to ensure that if a decision is challenged in the future, the organisation can establish what information was available and the exact role the AI played in reaching that conclusion.
As cybersecurity professional Josh Copeland noted regarding the accountability risks of AI, “AI won’t testify for you; it won’t do jail time for you; it won’t pay your fines; but it will absolutely testify against you.”




Leave a Reply