Security1 distinct publisher3 min readPublished
Washington Post reporters found chatbot transcripts cited in 12 court cases in two years. The disclosure numbers behind those cases put employee prompts in a third-party evidence store your retention policy does not reach.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Custody, not hacking, is what puts these prompts at risk. A prompt typed into a consumer account sits on the vendor's servers under the vendor's retention schedule, and the vendor is the party that receives the subpoena or the preservation order. In two of the cases Malwarebytes summarized from the Washington Post reporting, the user opened the door himself: a student who had asked ChatGPT whether anyone would work out that he damaged 17 cars in a campus lot then consented to a police search of his phone [6], and a teenager suing large technology firms over social media addiction saw his own ChatGPT history pulled into discovery [7]. No adversary had to breach anything. And unlike a conversation with counsel or a physician, none of it carries privilege [5].
Retention promises are the weaker link. In the New York Times copyright case against OpenAI, a judge ordered the company to preserve chat logs, including logs users had asked it to erase [8]. OpenAI said users were "forced to forgo the privacy protections OpenAI has painstakingly put in place" [9], and it kept the data despite having agreed to delete it under GDPR and California privacy law [10]. That is an operational fact: a deletion right you rely on can be suspended by a hold in litigation you are not party to.
Now the scale. Twelve cited cases across 24 months is roughly one surfacing every two months [17], which is small, and worth saying plainly. The disclosure line is the one that moves. More than 80 accounts' content disclosed in the last six months of 2025 [3] is about 13 accounts a month, against roughly 3 a month in the second half of 2024 [18], since the reported figure was more than four times the earlier period [4] and implies something near 20 accounts then [16]. Both numbers reach us through the Post's reporting rather than an audited transparency report [2], so treat them as a trend line, not a census.
The trend has precedent in older data types. Google, Meta and Apple handed over details of 3.16 million US accounts between 2014 and 2024, rising year over year [13]. Police subpoenaed Amazon Echo audio in a 2019 Florida murder case [14]. Facebook gave prosecutors a mother and daughter's private messages in a 2022 abortion investigation [15]. Each new store gets discovered once litigants learn it exists.
There is also a path that skips legal process. OpenAI's policy lets reviewers refer conversations to law enforcement when they see an "imminent and credible risk of harm to others" [11], and the company contacted police over a Palm Beach County user who repeatedly described plans to harm an ex-girlfriend [12]. That trigger is the vendor's judgment, on the vendor's timetable, with no notice to an employer.
The cheap controls are contractual and clerical. Put chatbot use on an enterprise tenancy with stated retention and hold handling, name prompts in the records schedule, and train responders to keep incident detail out of personal accounts. That costs a procurement cycle, and it is far cheaper than the alternative: reconstructing who typed what into a chatbot after a hold has already landed, which costs a discovery fight.
Ranked by verification strength, evidence, and original report placement.
A Washington Post article highlighted several cases in which people discussed sensitive information with AI systems including Claude and ChatGPT, and their conversations were later obtained by prosecutors or opposing lawyers.
Washington Post reporters found chatbot logs cited in 12 court cases in the past two years, as summarized by Malwarebytes.
OpenAI disclosed the content of more than 80 user accounts in the last six months of 2025, according to statistics the Washington Post found.
OpenAI's disclosure of more than 80 accounts' content in the last six months of 2025 was more than four times as many as in the second half of 2024.
Chatbot conversations with services such as ChatGPT are not privileged in the way conversations with a lawyer or a doctor are, so lawyers can obtain them.
A university student asked ChatGPT in a panic whether people might work out that he had damaged 17 cars in a campus parking lot, and then handed his phone over to police for a search.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
The nationalization argument is really a vendor-continuity memo1 distinct publisher
product
Incogni ranks 13 AI assistants by privacy risk: bigger is worse, except ChatGPT1 distinct publisher
invest
Scalable Capital puts ChatGPT, Claude and Grok inside the European order ticket2 distinct publishers
product
OpenAI shipped a teen ChatGPT. The over-65 cohort doubled to 23% and got nothing.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific, secondhand, unverified here
Every hard number in this story — the 12 cases, the 80-plus accounts, the 3.16 million platform disclosures — comes from a Washington Post investigation that Malwarebytes summarises rather than checks. The facts are precise and the underlying reporting is named, but no docket number, transparency report or filing is put in front of the reader, and the one direct quote from OpenAI is lifted from its own court objection. Nothing is doubtful; nothing is independently confirmed either.
Real, documented, still small
This is not a hypothetical: transcripts have been cited in court, one plaintiff's own history was pulled into discovery, OpenAI has volunteered a referral to police, and a judge has already frozen deletion. Those are concrete events with dates and places. But the volumes are modest — one case surfacing every couple of months, roughly 13 accounts a month at the 2025 rate — and the story gives no denominator against which to read them.
Growth rate outruns the base
'Quadrupled' is doing more work than the underlying counts justify. Four times a very small number is still a small number: fewer than two dozen accounts in late 2024, fewer than a hundred a year later, against a user base in the hundreds of millions that this story never mentions. Malwarebytes is careful with the facts and honest that older platforms have been handing over far more data for a decade — 3.16 million accounts is the real baseline — but the alarm in the framing is calibrated to the trend line rather than the exposure.
Advice column with a download button
Two interests shape what a reader sees. Malwarebytes closes a piece about legal discovery by asking you to install its product, which favours a fear-of-exposure framing over a dry read of the numbers. And the only words OpenAI contributes — that its users are 'forced to forgo the privacy protections OpenAI has painstakingly put in place' — were written to persuade a judge, and land here as a defence of the company's privacy record.
One relay, no primaries
The direction of travel is safe to believe — disclosures are rising, transcripts are in evidence, deletion is not absolute. The specifics deserve more caution: a single publisher, a single upstream investigation, no primary documents, and open questions on enterprise tiers and total request volumes that would change how big any of this actually is.