Delete the chat. The record survives.

An indigo chain of linked circles crosses a dark navy field with one link missing, the severed ends marked in amber, and a dashed amber line rising from the gap to a checkpoint bar above.

In March, the Delaware Court of Chancery decided a dispute over a $250 million earnout. Buried in the opinion is a sequence worth reading closely if your organization runs AI anywhere near a consequential decision.

The CEO of the acquiring company wanted out of the payment. He asked ChatGPT how to get it. The chatbot returned a staged plan, which the court described as a strategy to “contrive a corporate ‘takeover’,” covering the securing of control points and the preparation of “systematic materials for legal defense.” He formed an internal task force. He followed the plan.

Then he deleted the chat logs.

The court quoted the conversation anyway. Footnote 185 records that he “admitted at trial that he had deleted specific, relevant ChatGPT logs,” and that “this particular chat was deleted.” The substance came back through ordinary discovery, reconstructed from everything the conversation touched: the task force he stood up, the documents it produced, the testimony of people who watched the plan get executed. The court reinstated the ousted CEO of the acquired studio and extended the earnout period by the length of the ouster.

Deleting the logs worked in the narrow sense that the logs are gone, and failed in every sense that mattered. The record of what he did got assembled without him. A record assembled by the other side is never the one you would have written.

The same pattern repeats at organizational scale, and most companies are walking into it on purpose.

Nor does this stay confined to executives contriving takeovers. Prompts written in the ordinary course of business are business records, and business records are discoverable. In August 2025 a federal court in California ordered exactly that production: AI prompts and outputs from a company’s “founder, executive or managing agent” and other identified employees. Most AI use in your organization is probably that kind, produced by people doing their jobs.

Most of this is not net-new

Ask organizations whether they are investing in AI governance and they say yes, overwhelmingly. Ask whether the work is done and the number collapses.

In a survey of 525 enterprise professionals fielded in April and May 2026, Schellman found that 90 percent of organizations have allocated funding for AI governance, and 74 percent believe they could pass an AI compliance audit today. Twenty-seven percent describe their governance program as fully mature. A separate survey of 500 compliance decision-makers, run by Arctera in May 2026, found 71 percent saying they are very or extremely prepared to produce a defensible audit trail, against 19 percent who have the logging, retention, and detection controls to actually do it. Both firms sell governance tooling, so weigh the framing accordingly. The gap between the two numbers in each survey is the part that is hard to explain away.

Part of the reason for that gap is how the problem gets scoped. AI governance is usually treated as a new program to stand up, which makes it look enormous, and initiatives that look enormous tend to get funded and then deferred until there is capacity to do them properly.

Very little of it is actually new. Your organization already has a data retention schedule. It already has a process for approving tools and maintaining an acceptable-use list. It already has a way to budget, forecast, and attribute spend. Those problems were solved some time ago, for software that happened not to be AI.

The work is running AI through the risk profile those controls were already built to serve, and then updating the governance strategy to match. Which existing data classification a prompt falls under. Where the current retention schedule reaches and where it stops, once the tool on the other end is hosted by someone else. What the tool-approval process has to ask that it did not have to ask before. What changes about budgeting when consumption is metered per request rather than per seat. That is amendment work against artifacts you already own, and it is far more tractable than building a governance program from nothing.

It is still real work, and it is mostly not technical. Rewriting the acceptable-use policy so it describes decisions rather than products. Updating the litigation-hold template and the custodian interview script so they name AI tools, because a generic ESI hold will not support a spoliation argument later. Training staff, not once at onboarding but on the question they actually face, which is what they may put into a model and what has to be recorded when they do. Deciding who owns the answer when someone asks what your organization did.

None of that ships from a vendor, and it takes a quarter or two, which is why it is worth starting before the week a preservation letter arrives.

Prohibition relocates the problem

The most common failure is a policy written to be maximally restrictive, on the theory that prohibition is the safe default.

The evidence runs the other way. Schellman found 64 percent of organizations have a formal AI acceptable-use policy actively communicated to employees. In the same window, a survey of 1,250 office professionals at companies with $500 million or more in revenue, conducted by Wakefield Research for PagerDuty in April 2026, found that 66 percent had used AI tools at work despite believing they were not permitted under company policy. That rises to 72 percent at organizations with more than 1,500 employees. Thirty-nine percent said they would rather use AI without telling anyone, and at companies above $1 billion in revenue that reaches 47 percent.

Meanwhile 43 percent had entered work correspondence into public AI tools, 34 percent customer data, and 31 percent financial information or confidential company documents.

Read those together and the mechanism is plain. A policy strict enough to be unusable does not reduce AI use. It relocates it, from accounts you administer onto personal accounts you cannot see, from tools you could instrument onto tools you cannot. The behavior continues. What disappears is your visibility into it.

Which is the Delaware case again, one level up. The CEO deleted his record and the substance surfaced anyway, in a form he did not control. An organization that writes policy people route around does the same thing to itself at scale. It destroys its own record while the underlying activity carries on, and leaves the reconstruction to somebody else.

The design goal is maximum coverage. A policy people can actually follow, applied to a path you can actually see, produces a better record than a stricter policy that pushes half the traffic into the shadows.

Write policy that outlives the tool list

The second failure is subtler and it has a shorter fuse. Most AI policies name products. Approved: these three assistants. Prohibited: everything else.

Maintaining an approved-tool list is a discipline most organizations already have, and the mechanics carry over intact. What does not carry over is the refresh rate. That policy is obsolete on a predictable schedule. Model families turn over. Clients get replaced. Teams adopt a second assistant to check the first, which is a good practice and not one your policy anticipated. Every rewrite takes weeks of review, and the interval between rewrites is exactly where undocumented usage accumulates. Even the reference frameworks move: NIST’s AI Risk Management Framework, built on the four functions of Govern, Map, Measure, and Manage, is itself under revision.

The durable version says nothing about product names. It governs three things instead: what categories of data may leave the organization, what must be recorded when they do, and who has to be able to verify that record. Those hold when the model list changes, because they are statements about decisions and evidence rather than about vendors.

A policy at that altitude only works if something enforces it at that altitude. Otherwise you have written a principle and left every team to implement it differently, which is how you end up with six partial records and no answer. We have written before about where that leads: “The problem is rarely one reckless tool. It is many reasonable tools, each adopted for a good reason, with nothing common sitting underneath them.”

What a record has to do to be worth keeping

Most logging fails the moment it is contested, because the party being audited controls the log.

A record that holds up does four things. It is immutable on write, so entries cannot be quietly revised. It is independently verifiable, so someone other than you can check it without taking your word for anything. Deletion shows as deletion, so a gap is itself evidence rather than an absence of evidence. And it holds fingerprints rather than content, so proving a record is intact does not require exposing what it says. That last property is what keeps a governance record from becoming its own liability, because nobody should solve a discovery problem by building a permanent searchable archive of everything an employee ever typed.

Constellation Gate AI is a gateway. Your AI tools point at it instead of pointing straight at providers, and because it already sits in the request path, the record writes itself. There is no SDK to add and no traces to wire up. Every request emits a structured audit event. Removing one is visible rather than silent, so a gap in the record is itself evidence. The record is anchored to Constellation’s Digital Evidence layer, which is what makes it checkable by someone who does not trust you and does not trust us. And it holds cryptographic fingerprints, never prompt or response content.

It also covers the tools teams already run, including Claude Code, Codex, Cursor, OpenCode, OpenClaw, and Gemini, with one click each and no change to the subscriptions or tokens you already pay for. That is what makes a durable policy enforceable. The client list changes and the layer does not.

This gets oversold across the category, so let me be precise about scope. Gate keeps a tamper-evident, independently verifiable record of the AI activity routed through it. That is not a claim about what any court will admit, and it does not cover traffic sent straight to a provider. Coverage is a deployment decision, and it is the honest limit on every audit claim in this category, including ours.

The quiet part is ending

Article 12 of the EU AI Act requires high-risk systems to automatically record events across their lifetime so their operation can be traced, an obligation deferred to December 2027 for standalone high-risk systems. And as far as I can find, no court has yet sanctioned a company for failing to preserve AI logs. The litigation-hold guidance is out, the doctrine is in place, and the first corporate spoliation ruling has not landed.

Both of those say the same thing. There is still time to do this deliberately. The organizations that use it will be rewriting policy, retraining staff, and putting a record in place while the stakes are hypothetical. The rest will do the identical work later, faster, under a deadline set by someone else, and with a record assembled by the other side.

Gate screens every request, redacts secrets and PII on the way out, caps what agents can spend, and keeps a record of all of it that outlives whichever tool made the call. Free to start.

Gate puts injection screening, secret redaction, spend caps, and a tamper-evident record in front of every agent you run. Free to start.