All Articles

Government Contracts & AI

Zero Data Retention Meets the Federal Record: When Deleting the Prompt Breaks the Contract

11 min readAugust 2026Attorney Advertising
By Russell Roby, Esq.Last updated August 2026

Zero data retention is one of the most effective things an AI vendor can put on a slide. It answers the first question every enterprise buyer asks — where does our data go? — with the cleanest possible response: nowhere, and not for long. No training on customer content. No durable storage of prompts or outputs. Logs that expire on a short clock.

For most commercial buyers that promise is exactly right, and the security posture behind it is real.

Federal buyers are different, and the difference is not about trust. A federal agency operates under a body of law that assumes the government can produce what it did and why. Recordkeeping statutes, audit clauses, disclosure statutes, and litigation obligations all run on the same premise: the material exists. A vendor guarantee that material will be destroyed on a fixed schedule is a guarantee that sits crosswise to that premise.

This is the second of two pieces on the contract terrain for autonomous AI in government systems. The first dealt with ownership, provenance, and liability for what the agent produces. This one deals with what happens to the record of the agent working — and why the retention term you use to win commercial deals may be the term that costs you a federal one.

What "Zero Data Retention" Actually Means

The phrase covers several distinct promises, and vendors are not consistent about which they are making. Before any of the legal analysis matters, know which of these you have committed to:

  • No training on customer content. The narrowest and least legally fraught commitment. Customer data does not enter a training or fine-tuning corpus.
  • No durable storage of inputs and outputs. Prompts and responses are processed and discarded rather than persisted.
  • Short-clock or ephemeral logging. Operational and abuse-monitoring logs exist but expire on a fixed schedule, often measured in days.
  • Customer-controlled retention. The customer sets the period, including zero.

The first is a data-use restriction. The others are destruction commitments, and destruction commitments are the ones that collide with federal obligations. Marketing collapses all four into one phrase. Contracts should not.

The Government's Records Problem

Federal records law is broader than most technology vendors expect. The statutory definition reaches recorded information made or received by a federal agency in connection with the transaction of public business and preserved — or appropriate for preservation — as evidence of the agency's organization, functions, decisions, or operations. It is format-neutral by design. Nothing turns on whether the material is a memorandum, a database entry, or a model interaction.

Contractor-held material is squarely in scope. NARA's regulation on records created or received by contractors directs that when a contractor operates a function for an agency, the agency must specify in the contract that the government owns the resulting records and that the contractor will deliver them. Material created for government use and delivered to, or falling under the legal control of, the government is treated as federal records — subject to the same retention and access requirements as anything the agency generated itself, including under the Freedom of Information Act and the Privacy Act.

Whether a particular prompt or model output is a federal record is a genuinely unsettled question, and it should be treated as one. NARA has not issued guidance specific to AI agents. The answer will not be uniform: a throwaway query is not the same artifact as the interaction that produced the code shipped into a production system, or the reasoning trace behind an action the agency later has to explain.

But the analysis does not run on the vendor's characterization of its telemetry. It runs on whether the material documents the transaction of public business. When an agent plans an approach, executes it, and delivers work product into a government system, the argument that the record of that transaction is mere operational logging gets harder the more autonomous the agent becomes. Autonomy is precisely what shifts the interaction from tooling to decision-making.

Neither the vendor nor the contracting officer should be resolving that question in a footnote to a subscription agreement.

Audit Rights Do Not Expire When Your Logs Do

Separate from records law, the standard audit clauses give the government examination rights over records generated under the contract, and FAR Subpart 4.7 sets the retention periods that make those rights meaningful. The subpart survived the Revolutionary FAR Overhaul rewrite of FAR Part 4 in streamlined form. The general period remains three years after final payment, with longer periods for certain categories.

Set that against a thirty-day log expiry and the mismatch is obvious. A vendor whose product deletes on a short clock has, by design, made itself unable to support an examination two years after performance.

There is a narrower version of this problem that catches vendors who think they have solved it. Retention obligations attach to records generated under the contract. A vendor may reasonably conclude that its inference logs are its own operational data rather than contract records — and may be right. But the same vendor typically also relies on those logs to substantiate its invoices, its performance representations, its security attestations, and its defense if the agent's work is later challenged. Deciding the material is not a contract record does not make it unnecessary. It only means you destroyed it without anyone requiring you to.

You Cannot Attest to What You Did Not Keep

The provenance regime described in Part 1 depends on evidence.

Federal software carries a secure-development framework built on NIST SP 800-218, OMB self-attestation requirements, and the CISA attestation form signed by a company officer. Those instruments ask the vendor to affirm facts about how software was produced. When an autonomous agent contributed to production, the facts being affirmed include what the agent did and what it drew on.

A zero-retention architecture is, from this angle, an architecture that destroys the evidence supporting your own signature. The attestation does not become easier because the underlying data is gone. It becomes an assertion the officer signing it cannot substantiate — and an unsupportable attestation is the classic route to False Claims Act exposure, the same mechanism that makes an overstated CMMC affirmation dangerous.

The emerging technical standards are moving in the opposite direction from ephemerality. NIST's Center for AI Standards and Innovation launched an AI Agent Standards Initiative in February 2026, and related work at the National Cybersecurity Center of Excellence proposes treating agents as distinct non-human identities with their own authentication, authorization, auditing, and non-repudiation. Non-repudiation is the concept that matters here, and it is definitionally incompatible with deleting the evidence. Where that work lands is not yet settled, and vendors should be careful about designing to a draft. The direction, though, is not ambiguous: agent actions are expected to leave a durable, attributable trail.

Litigation Hold Overrides Your Retention Schedule

Every retention schedule yields to a preservation duty. Once litigation or an investigation is reasonably anticipated, the obligation to preserve relevant material attaches regardless of what the contract, the policy, or the product architecture says.

For electronically stored information, the federal rules provide that where ESI that should have been preserved is lost because a party failed to take reasonable steps, and it cannot be restored or replaced, a court may order measures to cure the prejudice — and, on a finding that a party acted with intent to deprive another party of the information, may presume the lost information was unfavorable, instruct the jury it may so presume, or dismiss or enter default judgment.

"Our product is designed to delete it" is not a safe harbor. It may be worse than no answer at all, because a purpose-built destruction mechanism invites the argument that the loss was not inadvertent. Automated deletion that cannot be suspended is the specific failure mode. A retention architecture with no legal-hold override is a spoliation exposure waiting for a trigger.

The Other Direction: Retention Creates Exposure Too

None of this is an argument for keeping everything. The opposite failure is real and it lands on the government.

Material under the agency's legal control is reachable under FOIA. Material containing personal information maintained in a system of records implicates the Privacy Act. Prompts are unusually likely to carry personal information, because people write to a model conversationally and include context they would never put in a form field. An agency that accepts unlimited retention of agent interactions has taken on a disclosure and privacy inventory it may not have scoped, budgeted, or scheduled.

The right posture is not maximum retention. It is deliberate, tiered, contractually specified retention, with the parties having decided together what each category is for and how long it needs to live.

How to Draft It

The workable answer separates commitments that marketing keeps in one bucket:

  • Split data use from data retention. Commit hard on training — customer content does not enter a training or fine-tuning corpus, full stop. That is the commitment buyers actually care most about, it is cheap to keep, and it is not in tension with anything in this article. Treat retention as a separate, negotiable term.
  • Tier the material. Model interactions that produce a deliverable or drive an action are not the same as ephemeral operational telemetry. Define the categories in the contract and give each its own period. A single global retention number is what creates the conflict.
  • Put the clock in the customer's hands. Customer-configurable retention with a defined floor lets an agency meet its own obligations without asking the vendor to guess at them. It also moves the records determination to the party that has to make it.
  • Build a legal-hold override that actually works. A documented mechanism to suspend automated deletion, with defined triggers, an owner, and a tested procedure. If your architecture cannot suspend deletion, you do not have a retention policy; you have a destruction guarantee.
  • Say who decides the records question. The contract should state which party determines whether particular material constitutes a federal record, what happens on delivery or disposition, and how a disagreement gets resolved. Leaving it unaddressed does not make it go away; it defers it to the moment when someone needs the material and it is gone.
  • Provide deletion evidence. Where material is destroyed on schedule, generate a certificate or log establishing what was deleted and when. Ephemerality is defensible. Undocumented ephemerality is not.

Privilege and the Prompt

One further point, aimed at counsel rather than at vendors.

Where in-house or outside counsel uses an AI system in the course of providing legal advice, the resulting interactions raise unsettled questions about privilege and work product. Courts are only beginning to address whether and when material generated through a third-party AI system retains protection, and the analysis will turn on familiar factors — confidentiality, the purpose of the communication, and whether disclosure to the provider waived anything.

That uncertainty cuts in both directions on retention. Material that is preserved may have to be logged, reviewed, and fought over. Material that is destroyed cannot be produced but also cannot be used to establish what advice was given or when. Neither is obviously the safer position, which is a reason to make the choice consciously rather than inheriting it from a product default.

The Point

Zero data retention is a good answer to a question federal buyers are also asking. It is not an answer to the questions federal law asks alongside it.

A vendor that treats retention as a fixed product property will eventually meet a contracting officer who cannot accept it, an auditor who needs material that no longer exists, or an attestation it cannot support. A vendor that treats retention as a negotiated contract term — tiered, documented, suspendable, and matched to what each category of material is actually for — keeps the security posture and the deal.

Both articles in this series come down to the same discipline. The value of an autonomous system is that it moves faster than the process around it. The legal exposure does not move faster. It arrives on the ordinary schedule, and it asks what you kept.

Practice Tip: Before signing a federal deal with a retention commitment, walk the term through four checkpoints: does it survive a FAR Subpart 4.7 audit window, can a legal hold actually suspend the deletion, can your officer still sign the secure-development attestation with the evidence that remains, and does the contract say who decides the federal-records question? If any answer is no, the term needs to be renegotiated before award, not after the material is gone.

Frequently Asked Questions

Are AI prompts and outputs federal records?

Sometimes, and the question is unsettled. Federal records law reaches recorded information made or received by an agency in connection with the transaction of public business, and it is format-neutral. NARA has not issued guidance specific to AI agents. A throwaway query is a different artifact from the interaction that produced code shipped into a production system. The analysis turns on whether the material documents the transaction of public business, not on how the vendor classifies its telemetry — and the more autonomously the system acts, the harder it is to characterize the record of its actions as incidental logging.

Does a zero-retention term conflict with FAR contractor records retention?

It can. FAR Subpart 4.7, retained in streamlined form in the FAR overhaul, generally requires retention for three years after final payment for records generated under contracts containing the audit and records clauses, with longer periods for some categories. A short log expiry is in tension with that. A vendor may conclude its inference logs are its own operational data rather than contract records, but the same logs typically substantiate its invoices, representations, and defenses — so destroying them solves a legal question at the cost of an evidentiary one.

Can we promise never to train on customer data and still meet federal obligations?

Yes, and this is the commitment worth making unconditionally. A no-training term is a restriction on data use. It does not require destroying anything, and it does not conflict with recordkeeping, audit, or preservation obligations. The conflicts come from destruction commitments. Separate the two in the contract even if marketing keeps them together.

What happens to automated deletion when litigation is anticipated?

The preservation duty overrides the schedule. For electronically stored information, the federal rules allow curative measures where ESI that should have been preserved is lost because a party failed to take reasonable steps, and permit adverse-inference instructions, dismissal, or default judgment on a finding that a party acted with intent to deprive another party of the information. An automated deletion mechanism that cannot be suspended is a specific and foreseeable exposure. Build a legal-hold override, document it, and test it.

Isn't longer retention always safer?

No. Material under an agency's legal control is reachable under FOIA, and personal information maintained in a system of records implicates the Privacy Act. Prompts are unusually likely to contain personal information because people write to a model conversationally. Unlimited retention hands the agency a disclosure and privacy inventory it may not have scoped. The defensible position is tiered retention that the parties chose deliberately, not the maximum or the minimum.

How should a retention term actually be drafted?

Separate data use from data retention. Tier the material by function rather than setting one global period. Make retention customer-configurable with a defined floor. Build and document a legal-hold override. State in the contract which party determines whether material is a federal record and what happens on disposition. Generate deletion evidence for material destroyed on schedule. Ephemerality is defensible; undocumented ephemerality is not.

Sources

Federal records statutes (44 U.S.C.) and NARA regulations on contractor records; FAR Subpart 4.7 and the audit and records clauses (as retained in the Revolutionary FAR Overhaul); the Freedom of Information Act; the Privacy Act; Fed. R. Civ. P. 37(e); Executive Order 14028; NIST SP 800-218; OMB M-22-18 and M-23-16; CISA Secure Software Development Attestation Form; NIST CAISI AI Agent Standards Initiative; NCCoE work on AI agent identity. Last reviewed August 4, 2026 — adoption of the overhauled FAR text varies by agency and effective date, and several questions addressed here remain unsettled; confirm the current state of the authorities before relying on them.

Related reading: this is Part 2 of a two-part series — Part 1, When the Agent Ships the Code, covers ownership, data rights, provenance, and liability for what the agent produces. For the other attestation with False Claims Act teeth, see The CMMC Affirmation Trap.

Negotiating AI retention terms into a federal contract, or trying to reconcile a product default with an agency's obligations? Attorney Advertising. This article is provided for general informational purposes only, is based solely on public, publicly available sources, and does not constitute legal advice or create an attorney-client relationship. I am licensed to practice law only in Maryland. The authorities discussed — including the federal records statutes and NARA regulations, FAR Subpart 4.7 and the audit and records clauses, the Freedom of Information Act, the Privacy Act, and the Federal Rules of Civil Procedure — are subject to change and interpretation, adoption of the overhauled FAR text varies by agency and effective date, and several questions addressed here remain unsettled. Schedule a consultation to discuss your specific situation.

Related Articles

When the Agent Ships the Code: Ownership, Data Rights, and Liability for Autonomous AI in Federal Systems

Autonomous coding agents don't suggest — they act. That shift lands three unsettled legal questions at once: who owns what the agent produced, what happens when its output is contaminated, and who answers for it when it breaks. Updated for the 2026 Revolutionary FAR Overhaul, which rewrote FAR Part 27 and stripped the counterweights vendors relied on. Part 1 of 2 on the contract terrain for autonomous AI in government systems.

A Federal Court Just Held the NFA's Registration Scheme Unconstitutional for Untaxed Firearms. Here Is What the Ruling Actually Does — and Doesn't Do.

The Jensen and Silencer Shop rulings are a genuine landmark, but the internet's version is running well ahead of the court's own words. The injunction is party-specific, stayed for seven days, and almost certainly headed to the Fifth Circuit. Suppressor and SBR owners should understand the scope limits before changing anything about how they buy, build, or possess.

The Final Comment Window Is Closing on ATF's 34-Rule Package. Here's What Happens Next.

ATF's April 2026 deregulatory package is one of the broadest coordinated regulatory packages ATF has issued — stabilizing braces, Form 20 travel approval, CLEO notification, spousal registration, interstate transport, and more. With the public comment periods now closing, the package enters the phase most gun owners have never seen up close: comment response, final rules, effective dates, and near-certain litigation. None of the proposed changes discussed below is effective yet.

Have Questions About Your Situation?

A 30-minute consultation can save you years of headaches — and keep your family out of legal trouble.

Free Consultation

Responds within ~1 business day