A user deletes a Microsoft 365 Copilot conversation and legal asks whether it disappeared from eDiscovery. Security wants to know which document grounded the answer, while privacy asks how long the prompt remains. These questions look similar but belong to three layers: visible history, the compliance copy and audit metadata. Microsoft Purview treats them separately. Governance cannot begin with “we retain Copilot chats for 30 days” until the organization defines chat, viewer and whether the statement concerns content or an event log.

One interaction creates several distinct traces

The prompt and response are interaction content. For retention they are stored in a hidden area of the user’s Exchange Online mailbox that ordinary Outlook does not expose. An audit record instead captures the event: user, time, workload and references to files, sites or resources used by Copilot. A file uploaded to Copilot Chat can live in the user’s OneDrive; Copilot Pages can live in a user-owned SharePoint Embedded container. A single question can therefore have different lifecycles for conversation text, audit metadata, upload and output artifact.

Deletion in the interface does not define compliance state

When a user deletes a message before its retention period ends, a copy moves into the hidden SubstrateHolds folder where eDiscovery can still find it. Timer jobs are not immediate. Microsoft documents typical processing windows of one to seven days, at least one day in the hold folder and then another job before permanent deletion. If another retention policy or eDiscovery hold applies, retention principles take precedence. The visible chat is therefore weak evidence that the compliance copy exists or has been destroyed.

New retention locations separate classes of AI applications

New Purview retention policies no longer treat Copilot only as an extension of Teams chats. Documentation distinguishes Microsoft Copilot experiences, Enterprise AI apps and Other AI apps. The first includes Microsoft 365 Copilot, Security Copilot, Copilot in Fabric and Copilot Studio. Enterprise AI apps include Entra-registered AI apps and ChatGPT Enterprise; Other AI apps include consumer services such as ChatGPT, Gemini or DeepSeek when captured by a collection policy. Each location therefore needs explicit scope and ownership.

The traces behind one interaction
TraceQuestionControl
Prompt and responseWhat did the user ask and receive?Purview retention and eDiscovery
Audit eventWho, when, where and which resources?Purview Audit
Referenced contentWhich document version grounded the answer?SharePoint/OneDrive, labels and eDiscovery
Uploaded fileWhat was supplied directly to chat?OneDrive retention and DLP
Output artifactWhat was created or shared next?Policies of the destination workload

Audit Standard already includes Microsoft Copilot

Microsoft applications including Microsoft 365 Copilot are logged automatically in Audit Standard when auditing is enabled; that baseline does not require pay-as-you-go. Records identify user, time, workload and references to sources. Audit Standard provides 180-day searchable retention for common plans. Audit Premium adds longer defaults for selected records, custom retention policies, intelligent insights and higher API bandwidth. An interaction event is not a substitute for conversation content: a complete investigation combines Audit and eDiscovery.

Non-Microsoft AI applications follow a different billing path

Auditing interactions with non-Microsoft AI applications uses pay-as-you-go, and Microsoft specifies 180-day retention for those audit records. Microsoft apps remain included in Audit Standard. Capturing prompts and responses from other AI services additionally requires the relevant collection policy. An organization allowing ChatGPT Enterprise or another service cannot copy its Microsoft 365 Copilot conclusion. It must design collection, billing, retention location and lawful purpose separately.

eDiscovery Standard and Premium are different workflows

eDiscovery Standard can create a case, search, hold and export relevant Copilot interactions when licensing is appropriate. Premium adds an end-to-end process with custodians, collections, review sets, analysis and legal communications. The service description also distinguishes premium search for Copilot interactions. Purview roles for investigators and licenses for users whose data benefits from the service are separate concerns. Test the actual query and export before an incident rather than confirming only that a menu is visible.

The referenced file can change after the answer

Audit can indicate that Copilot used a file or site. An investigator may need the version that was available at that moment. Purview can apply retention labels to cloud attachments and links to preserve the exact shared version; Microsoft extends this capability to content referenced in Copilot interactions. Without it, today’s document may differ from the one that grounded the answer. Connect audit references with SharePoint and OneDrive version and retention design.

Source permissions are enforced at query time

Copilot can use only content the user is authorized to access. Encrypted material additionally requires VIEW and EXTRACT rights; sensitivity labels and Azure Rights Management are enforced during grounding and generation. Current permission, however, does not prove the historic state. The user might have had access when asking and lost it later. Investigations should correlate audit, sign-in, sharing changes, file version and interaction content. A screenshot of an answer is not sufficient evidence.

Prompts can themselves be sensitive records

Users put names, contract context, customer information and incident details into prompts. Governance must define lawful purpose, retention duration, investigator access and data-subject processes. Minimization does not always mean the shortest deletion policy; deleting too quickly can destroy evidence required for an incident or dispute. Indefinite retention increases the stock of sensitive text. The decision should follow a records schedule and risk assessment rather than a technical default.

Retention decision matrix
ScenarioPriorityTypical design
Routine productivityMinimization and operational needDefined period from the records schedule
Regulated activityEvidence of decisionsLonger retention and explicit scope
Litigation or investigationPrevent relevant deletioneDiscovery hold for affected custodians
Security incidentCorrelate source and eventAudit plus preserved content and versions
External AI serviceCollection and lawful purposeSeparate policy, billing and privacy assessment

Access to prompts should be narrower than ordinary log access

Audit and eDiscovery can expose highly sensitive material, so do not give every administrator a global compliance role. Separate Audit Reader, case-based eDiscovery access, export approval and oversight of investigators. Record the reason for a search and scope cases to necessary custodians and dates. Teams should also understand that audit schemas evolve: fields such as Messages, jailbreak detection and DLP evaluation flags are metadata whose availability depends on workload and scenario.

A test protocol for one prompt

  1. 01

    Create a controlled interaction

    Use a unique phrase and versioned document without real sensitive data

  2. 02

    Record the visible state

    Capture time, app, account, source and expected answer

  3. 03

    Find the audit event

    Verify user, workload, operation and references

  4. 04

    Find content in eDiscovery

    Search the phrase and verify prompt and response

  5. 05

    Delete the visible chat

    Confirm compliance results still follow the retention policy

  6. 06

    Change the source document

    Check whether the relevant historic version remains discoverable

  7. 07

    Document timing and licensing

    Put timer jobs and roles in the runbook; do not call delay data loss

Governance minimum before broad rollout

The Copilot approval pack should contain a trace map, retention decision record, roles and separation of duties, an eDiscovery test, legal-hold procedure, DLP and sensitivity-label baseline, oversharing remediation and user guidance. Add an incident contact for prompt-related events and a regular review of new AI locations in Purview. The product changes faster than many records schedules, so an owner should verify locations, supported workloads and licensing at least quarterly.

The management conclusion

The choice is not simply to retain or not retain “AI history.” The organization manages several traces with different purposes, costs and risks. A short visible history does not eliminate the compliance copy, Audit Premium alone does not preserve prompt text, and eDiscovery hold does not repair access to source content. A defensible model joins records management, legal process, security monitoring and SharePoint governance. Only then can the company say who can retrieve what, for how long and with which evidence.

Frequently asked questions

Does a prompt disappear from eDiscovery when the user deletes the chat?

Not necessarily. Retention or hold can preserve the copy in hidden storage for eDiscovery according to policy and processing time.

Is Microsoft 365 Copilot included in Audit Standard?

Yes. Microsoft AI applications are included when organizational auditing is enabled.

Does the audit log contain the complete prompt and response text?

Audit captures interaction metadata. Use retention and eDiscovery for content, holds and export.

Is 30 days the correct retention period?

There is no universal number. Derive it from records schedules, legal obligations, incident response and data minimization.