AI assistant logs: how long to keep them, and who gets to read them
9 min read
A typical scenario, not the case of a real company. A company AI assistant has been running for six months, and its register holds forty thousand conversations: draft quotations, machining tolerances, price lists, the formula no supplier is meant to see. Beside every line, who asked what and at what time. Then two requests arrive in the same month. Legal wants everything kept, because that register proves the know-how was guarded. Management control wants a dashboard by department, because that register shows who is working and how.
Only one of the two can be met without going through a procedure. In projects the register turns up at the bottom of the checklist, under “logging: yes”: that “yes” creates two legal objects at once, an archive of trade secrets and an instrument from which the remote monitoring of workers may follow. Opposite regimes, same file.
The rule that decides, with the references
Article 4 of Law 300 of 20 May 1970, as replaced by article 23 of Legislative Decree 151 of 14 September 2015 (text in force since 8 October 2016). Paragraph 1: “Audiovisual installations and other instruments from which the possibility of remote monitoring of workers’ activity also follows may be used exclusively for organisational and production needs, for occupational safety and for the protection of company assets, and may be installed subject to a collective agreement concluded with the unitary union body or with the company union bodies.” Failing an agreement, authorisation is required from the territorial office of the National Labour Inspectorate, and those decisions are final.
Two words carry the weight. “Also”: you need not intend to monitor, it is enough that the possibility follows from the instrument. “Exclusively”: the permitted purposes are three and form a closed list, one that “understanding how AI is being used across the company” does not join.
Paragraph 2: “Paragraph 1 does not apply to instruments used by the worker to perform the work, nor to instruments recording access and attendance.” This is where anyone who has already switched logging on takes shelter: the assistant is there to do the job, so it falls outside.
Paragraph 3, the trap: “The information collected under paragraphs 1 and 2 may be used for all purposes connected with the employment relationship provided that the worker has been given adequate information as to the manner of use of the instruments and of the carrying out of checks.” Even on the most favourable reading, that information may be used only if the notice came first. A log collected quietly will not support a disciplinary case.
Article 114 of Legislative Decree 196/2003, “Safeguards concerning remote monitoring”, closes the circle with a single paragraph: “Article 4 of Law 300 of 20 May 1970 continues to apply.” Article 4 thereby becomes a condition for the lawfulness of the processing, not a separate box to tick — on the same axis as article 88 GDPR on “monitoring systems at the work place”.
The paragraph 2 exemption covers the instrument, not its memory
The most useful precedent is not about AI. It is the Italian data protection authority’s guidance document of 6 June 2024 (provvedimento no. 364, doc-web 10026277) on email metadata in the workplace. Email is uncontroversially an instrument used to perform the work. Even so, the Garante writes that “for paragraph 2 of article 4 of Law 300/1970 to be considered applicable”, the retention of “only the metadata/logs necessary to ensure the functioning of the email system infrastructure” may take place “as a rule, for a limited period of a few days; by way of orientation, such retention should in any event not exceed 21 days”. Otherwise, retention “for a longer period, since it may entail indirect remote monitoring of workers’ activity, requires the safeguards under article 4(1) to be carried out”.
The document addresses email, not AI assistants, and it is guidance with a threshold stated “by way of orientation”: it does not apply by automatic analogy. But the reasoning is the one a regulator will apply — what triggers paragraph 1 is not the nature of the tool, it is the breadth and duration of the retention.
One detail then shifts the centre of gravity. That guidance, the Garante specifies, “does not concern the content of email messages… which remain at the disposal of the user/worker”; the metadata are the entries written by the routing servers, “the email addresses of sender and recipient, the IP addresses of the servers or clients involved in routing the message, the times…”. A prompt is not metadata: it is content. And content, which in email stays in the worker’s mailbox, in a company assistant normally sits server-side, with the user name and the timestamp. Anyone reasoning “if email is 21 days, let us do the same for AI” is applying a ceiling designed for a far poorer archive.
The 21 days and the six months answer different questions
The second figure is the one most often misquoted. The Garante’s general measure of 27 November 2008 (doc-web 1577499, Official Gazette no. 300 of 24 December 2008), amended on 25 June 2009, requires the recording of logical access to processing systems and electronic archives by system administrators: records that are complete, unalterable, with verifiable integrity, retained for “an appropriate period, not shorter than six months”. It predates the GDPR and does not appear to have been repealed.
Those six months concern whoever administers the system, not whoever uses it to work. Confusing the two lists produces the commonest mistake: keeping everybody’s prompt register for six months “because the Garante says so”. It does not. It says, about a different object, that privileged access must be traced for a long time — which if anything sharpens the other horn of the problem: whoever holds privileges over the environment can read the conversations, and that reading must itself be traced.
The same file is also the proof of the secret
Article 98 of the Italian Industrial Property Code, in the wording given by Legislative Decree 63 of 11 May 2018 (implementing Directive (EU) 2016/943), protects confidential business information only where it has been subject to “measures that may be considered reasonably adequate to keep them secret”: the burden of proving them lies with whoever claims the secret, and access tracking is one of those proofs. Wiping everything every three weeks tidies up one front and weakens the other. The conflict dissolves once you separate two archives that today almost always coincide.
- The measures register, long retention: which restrictions were active on a given date, which classes of document were admitted, who had accepted the policy, which privileged accesses were exercised. It proves article 98(c) without the text of prompts and without tying it to an individual.
- The operational register, short and declared retention: prompts, answers, documents retrieved. It serves functioning and security, with a written duration, a written reason and an automatic deletion somebody verifies.
The first is a compliance archive, the second is potentially a monitoring instrument. They should not sit in the same place under the same key.
What to do now
Four indicators say you are already outside the paragraph 2 exemption, and then the agreement with the union body — or, failing that, the Inspectorate’s authorisation — must be sought before switching anything on: the register can be queried by name and not only by incident; there is reporting per user or per team; retention exceeds what functioning and security require, and nobody can say why; the dashboard is readable by line managers, not by the administrator alone. The last is the one that slips past: the declared purpose stays technical, but the readership transforms it.
Then five things to put in writing. The retention period of the operational register and the technical reason that justifies it, with a date. The check that deletion actually happens: a retention setting configured and never verified is not a measure. The separation between the measures register and the content register. Who may read what, with privileged reads traced. The paragraph 3 notice, given before and not after.
If the register then starts being used to assess people, the job changes: point 4 of Annex III to the AI Act, high risk, with the article 26(7) duty to inform workers’ representatives and workers, applicable from 2 December 2027 after the postponement by Regulation (EU) 2026/1744. What already applies today is the information duty under article 1-bis of Legislative Decree 152/1997, and so does the boundary the Garante drew when a supplier reads employees’ language.
How we solve it
None of this is governable if the register sits in a supplier’s infrastructure that decides on its own what to keep and for how long: the issue is not trust, it is verifiability — the same reason why, on hardware and open-weight models, the right question is not how good the system is but whose environment it runs in. So we build dedicated, closed AI, detached from the open web, in two modes: on-premise in the client’s own environment, or on our dedicated cloud — reserved for the single client, accessed over a dedicated VPN, with the data centre resident in Italy and premises we staff ourselves. In both, the conversation register and the measures register stay distinct archives, with distinct durations and permissions; privileged reads leave a trace; deletion is a function, not a promise. That is how we hold together the protection of know-how and the protection of people: an architectural choice, not a sales argument.
Could you say today how long your company keeps its employees’ prompts, and who can read them back? Half an hour with one of our experts is enough to answer, and to work out which of the two procedures you need.
Sources
- Law 300 of 20 May 1970, article 4 — consolidated text (Normattiva, in Italian)
- Legislative Decree 196 of 30 June 2003, article 114 — safeguards concerning remote monitoring (Normattiva, in Italian)
- Garante per la protezione dei dati personali, guidance document of 6 June 2024 on email metadata in the workplace (doc-web 10026277)
- Garante per la protezione dei dati personali, measure of 27 November 2008 on system administrators (doc-web 1577499)