LearnMicrosoft 365 Copilot › 7 · Security & compliance

Retention for AI interactions

Prompts and responses are a NEW record class, and Purview retention has a location aimed at it. Pick the stance deliberately — the default is 'kept indefinitely by inertia', which is a decision too, just nobody's.

The mechanics

Purview retention targets Copilot interactions as their own location (the Teams-retention model, AI edition — policy family, retain/delete actions, the same multi-day deletion pipeline and the same principles-of-retention conflict resolution). Holds trump everything, as ever. What makes THIS class interesting is the stance question, because the record is qualitatively new: half-formed thoughts, bad drafts, questions people would never put in email.

The three defensible stances

  1. Align with chat (common default): interactions retained like Teams chats — consistent story ('ephemeral working conversation'), simple to explain, and investigations keep a useful window.
  2. Shorter than chat: treat prompts as scratch thinking — reduces the discovery surface and the chilling effect ('everything I ask the AI is kept forever' measurably suppresses honest usage). The trade: shorter investigation memory; insider-risk teams should sign the choice.
  3. Longer/regulated: where records rules capture AI-assisted work product, or where early AI governance boards demand full history. Budget the review implications — long retention of high-volume conversational data is exactly what makes future eDiscovery expensive.

The indefensible stance, as with web grounding: not knowing which one you're in. Write it down, with the works-council conversation attached.

Interplay to design around

Copilot-CREATED artifacts (Pages, drafts in files) are file-side records under file retention — one session can produce an interaction record AND a document with different clocks (apps module's two-artifact model); transcripts feeding meeting AI have their own retention (Teams curriculum) — deleting transcripts amputates recap/Copilot memory of meetings, a UX effect of a records decision; and stance 2's short clocks meet holds constantly in litigious estates — the pipeline behaves, but brief legal on WHY deleted-for-most content persists for custodians.

What to watch (proofs)

  • The stance as config: the retention policy on the AI location, exported and dated — plus simulation/report data on volumes it governs.
  • The pipeline measured: your tenant's real latency from expiry to purge for this class (the Teams retention concept's test, re-run here — one number legal will ask for).
  • Chilling-effect signal: usage trends after the retention comms — a visible dip says the message landed badly; adoption and governance co-own the fix.
  • Cross-artifact consistency: one session's interaction record vs its Page vs the meeting transcript, each with its clock — the worked example that keeps the records map honest.

PowerShell for this concept

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.