Not privileged. Rarely deletable. Increasingly wired into your email, drive, and deal files. We assess exactly what your AI use exposes, then build governance that holds up in court and at renewal, alongside your counsel.
Consumer AI can retain your chats for up to five years, and a new good-faith clause lets some providers share them with law enforcement without a court order.
A federal court has held AI chats are not privileged, and the law is trending toward scrutiny. One provider was ordered to produce twenty million conversation logs over its objection.
The moment AI links to your inbox or drive, a single prompt injection can quietly exfiltrate everything it is allowed to read.
Clearing chats and reopening accounts leaves the provider's copy intact, and once litigation is foreseeable, deleting is spoliation.
A confidential questionnaire maps your entities, tools, investors, and where sensitive data actually lives.
Cloud versus local models, connected tools, retention, and the exact discovery surface your AI use creates.
A security program, AI-use policy, retention and legal-hold procedure, and communications hygiene, tailored to you.
We package findings for your attorney to finalize. We are governance advisors, not your lawyers, and never pretend otherwise.
In 2025 and 2026, AI providers rewrote their retention and disclosure terms, courts began ordering chat logs produced by the tens of millions, and insurers won regulatory approval to exclude AI from standard business policies. The rules changed. Most people's habits didn't.
Sources on request · verified against primary policy and case filingsGenerally, no. Consumer AI services retain chats (up to five years when training is enabled). In United States v. Heppner (S.D.N.Y., February 2026), a federal judge ordered a defendant's AI chats produced and held they were not privileged; other courts have since taken a fact-specific approach, and the law is unsettled. The prudent assumption is that anything typed into consumer AI is a discoverable business record.
Deleting controls your view, not the provider's copy. Deleted and incognito chats are typically retained for about 30 days, backups can persist longer, and providers have been ordered to produce logs over their own objection. Once litigation is reasonably foreseeable, deleting becomes spoliation, a second problem worse than the first.
Increasingly, not by default. In January 2026 ISO issued generative AI exclusions for commercial general liability, and regulators have since approved most carrier filings to add AI exclusions to standard business policies. New affirmative AI coverage exists, and its underwriters ask for governance evidence: acceptable-use policies, human oversight, audit logging, incident response. Chatham builds that evidence; coverage decisions belong with your broker.
No. Chatham is a governance and data-privacy advisory practice. We assess the technical exposure and build the operating controls, and every legal decision goes to your own counsel, whom we brief directly.
Family offices, emerging fund managers and syndicate leads, RIAs, angel investors, and founders holding sensitive cap tables: anyone whose AI use touches investor identities, deal terms, or their own legal questions.
Tell us where you sit and what worries you. We reply under NDA with next steps and scope. No sales sequence, no cookies, no trackers: we count visits in aggregate and keep nothing else.