MICKAI®ArticlesAre AI prompts and outputs subjec…
Article · 21 July 2026

Are AI prompts and outputs subject to freedom of information?

For UK public authorities yes where the information is held, including records a vendor keeps on the authority's behalf.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign aifreedom of informationpublic sector aiai governancefoia

For UK public authorities, yes, where the information is held. The Freedom of Information Act 2000 applies to recorded information held by a public authority, and under section 3(2)(b) information held by another person on behalf of the authority is in scope too, which captures AI logs sitting in a vendor cloud on the authority's behalf. Prompts, outputs, transcripts and system logs are therefore all potentially disclosable, subject to the usual exemptions. In Scotland, FOISA applies the same principle to Scottish public authorities.

The question matters in 2026 because councils, NHS bodies, police forces and government departments are deploying AI now, and few authorities have answered the disclosure question cleanly. Requests for AI records are already arriving with little established practice waiting for them, and the authorities that thought about retention and search in advance will be the ones that answer lawfully and on time.

What does FOIA actually cover?

Recorded information, held by the authority, at the time of the request. The test is not where the record sits or what software created it. A prompt typed by an officer in the course of authority business, an output pasted into a draft report, a transcript retained by the system: each is recorded information if it exists, and section 3(2)(b) means that moving the record into a vendor's cloud does not move it out of scope, because information held by another person on behalf of the authority is still held by the authority.

Why are prompts a special disclosure problem?

Because a prompt is often more candid than the document it produced. Officials type draft positions, doubts and half-formed policy thinking into an AI system in a way they never would into a committee paper. That raises the metadata question: even where the output is innocuous, the prompt may reveal material that engages an exemption, such as the formulation of policy. Authorities need to treat prompts and outputs as records in their own right, not as disposable by-products of a tool, because a requester is entitled to ask for either.

Which exemptions are likely to matter?

The familiar ones. Personal data in prompts or outputs engages the data protection exemption. Commercial interests can protect supplier and procurement material. The formulation of government policy has its own protection at departmental level. What no exemption provides is a blanket answer: exemptions are applied request by request, record by record, and several involve a balancing exercise. An authority cannot classify its AI logs as exempt in advance any more than it could its email archive, which means the operational task is retention, search and review, not a standing policy of refusal.

Can an authority avoid FOI by not logging?

No, and the attempt fails twice. An authority cannot disclose what it cannot find, but the section 46 records-management code expects authorities to keep adequate records of their business, and choosing not to log AI use so that there is nothing to disclose falls well short of that standard. It also destroys the authority's own position, because an authority that keeps no record of AI use cannot show what the AI did when a decision is challenged, whether by a requester, a court or an auditor. Not logging trades a disclosure obligation for an evidential vacuum, and the vacuum is worse.

Why do vendor contracts make FOI compliance hard?

Because the records are in scope but the retrieval path runs through a supplier. Contracts vary on what is logged, how long it is retained, whether the authority can search it, and how quickly it can be exported for review and redaction. A request arrives with a statutory clock, and the authority is on that clock whether or not the vendor's export process cooperates. An authority procuring cloud AI should treat FOI retrieval as a contractual requirement tested before signature; in practice many discover the gap at the first request, which is the most expensive moment to learn it.

How does a sovereign deployment change the answer?

It puts the records where the duty sits. When AI runs inside the authority's own boundary, every prompt, output and action is written to a sealed record the authority itself holds and can search. On Mickai, a Sovereign Intelligence Operating System running offline on operator-owned hardware, that record is complete and cryptographically sealed, so the authority can find the material, assess exemptions, redact and respond accurately and on time, instead of guessing what a vendor kept. Transparency obligations do not weaken the case for sovereign infrastructure; they are one of its strongest arguments.

An authority cannot disclose what it cannot find, and arranging not to know is a position it will struggle to defend.

How we build that complete record into the architecture is set out at /sovereign-ai, and the film at /film shows the interface, audit trail included, in operation.

Frequently asked questions

Can someone FOI the prompts my council typed into ChatGPT?

If the prompts are recorded and held by the council, or by a vendor on the council's behalf, they are within the scope of FOIA and must be considered like any other record, with exemptions applied case by case. The practical difficulty is usually retrieval: the council has to be able to find and export them within the statutory time limit.

Are AI logs held by a vendor still covered by FOIA?

Yes, where they are held on behalf of the authority, under section 3(2)(b) of FOIA. Moving records into a vendor cloud does not move them out of scope; it only makes them harder to retrieve, which is the authority's problem rather than an answer to the request.

Can we just switch off logging so there is nothing to disclose?

Choosing not to log in order to avoid FOI falls short of the records-management standards authorities are held to, and it leaves the authority unable to evidence its own decisions when they are challenged. Retention should follow records-management duties and operational need, not the desire to have nothing to hand over.

Does the same apply in Scotland?

Yes in principle. Scottish public authorities are covered by FOISA rather than FOIA 2000, and the same practical questions arise: whether AI prompts, outputs and logs are recorded information held by or on behalf of the authority, and whether the authority can retrieve them in time.

What exemptions could protect sensitive AI use?

The usual candidates for AI records are personal data, commercial interests and the formulation of policy. None operates as a blanket, each is assessed per request, and several involve a balancing exercise, so the safe assumption is that AI records are disclosable unless a specific exemption is made out.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/are-ai-prompts-and-outputs-subject-to-freedom-of-information. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles