Legal Hold and eDiscovery With an AI Email Client

The short answer
Yes, but not by breaking the hold. Gmail and Microsoft 365 remain the system of record, and Vault or Purview holds still preserve sent and received mail. What changes is the discoverable surface: AI drafts, agent decision logs and approval records may sit outside that preserved boundary.
eDiscovery and legal hold with an AI email client: the provider stays your system of record — but drafts, agent logs and approvals widen the discoverable set.
On this page
- 01The short answer: the provider is still the system of record
- 02The question that actually decides it
- 03How Microsoft answered this for Copilot
- 04Where Vault and Purview draw the line
- 05Criteria that actually matter
- 06Scoring the artifacts: inside or outside the hold
- 07A worked example: the hold lands on a Tuesday
- 08Red flags in a vendor's answer
- 09What we'd pick — and who should pick something else
- 10Questions to put to counsel before rollout
Counsel asks one question when a new mail tool comes up for review: does eDiscovery and legal hold survive it? For an AI email client the answer is usually yes — the hold lives on the mail provider, not on the client you happen to read mail in.
But that answer stops one step short of useful. An AI layer creates artifacts a plain inbox never produced: rejected drafts, agent decision records, approval trails. Some land inside the preserved boundary. Some do not.
This guide is about telling which is which, and what to ask a vendor before counsel signs off.
The short answer: the provider is still the system of record#
A hold in Google Vault or Microsoft Purview attaches to a location — a mailbox, a site, an account — not to the application a person uses to open it. Vault's Gmail hold covers messages and their attachments sent, received, or drafted by users in your organization. Purview holds preserve content in Exchange Online mailboxes and other content locations in the case.
Reading or sending that mail through a third-party client does not move it. IMAP, the Gmail API and Microsoft Graph all operate on the provider's copy. A message sent through an AI client is written to the provider's Sent folder and preserved exactly like one sent from the native web app.
So a third-party client, AI or not, does not by itself break a hold. If counsel has already approved Outlook desktop, Apple Mail or a phone client, they have approved the same architecture.
The mail is the easy part
The question that actually decides it#
Most vendor answers stop at "your provider is the system of record." That is true, and it is not decision-relevant, because every client on the market can say it.
The question that separates tools is per-artifact: for each thing the AI layer creates or records, does it land in a location your existing hold already covers, or in the vendor's own database?
That distinction does all the work. Because a hold preserves locations, an artifact written into the mailbox inherits the hold automatically — no new process, no second collection. An artifact written to a vendor backend inherits nothing. It lives under that vendor's retention schedule, and if it turns out to be responsive it has to be collected separately, from a system your eDiscovery platform cannot see.
How Microsoft answered this for Copilot#
Microsoft faced the same problem with its own AI and solved it in a way worth studying. Purview's eDiscovery documentation states that all user prompts and responses from AI applications are stored in a user's mailbox. Each interaction is written as an individual message-class item, with headers naming the user and the Copilot application identity as the two participants.
The consequence shows up in Microsoft's own deletion workflow. Before you can purge Copilot data from a mailbox, you must first remove any hold or retention policy — and Microsoft says plainly that if you do not remove the hold, the data you are trying to delete is retained.
That is the pattern: put the AI artifact inside the boundary the hold already covers, and it is preserved, searchable and exportable alongside everything else. Microsoft even publishes item classes for connected and third-party AI applications, so an outside tool can write into the same place — but only if that tool integrates deliberately. Most do not.
Where Vault and Purview draw the line#
The two major platforms do not preserve identical things, and the gap matters most exactly where AI tools are busiest. Verify each row against the vendor's current documentation before you rely on it — both products change.
| Question | Google Vault (Gmail hold) | Microsoft Purview (Exchange hold) |
|---|---|---|
| What the hold attaches to | The user's Gmail account | Mailboxes and content locations in the case |
| Messages sent, received or drafted | Covered | Covered |
| Drafts sitting in the Drafts folder | Processed like other Gmail messages and subject to holds | Covered as ordinary mailbox items |
| Discarded drafts and auto-saved draft versions | Listed explicitly as not covered by the Gmail hold | Not published at this level of detail — confirm for your tenant |
| First-party AI interactions | The Gemini app is a supported Vault data type | Stored in the user's mailbox as message-class items |
| A third-party AI client's own agent logs | Outside Vault entirely | Outside Purview unless the tool writes into the mailbox |
| Effect of the hold on deletion | Held messages survive user deletion | Hold must be removed before AI data can be purged |
The discarded-draft line is the one to read twice
Criteria that actually matter#
Feature lists are not much help here. These six questions decide whether a tool is defensible under a hold, and a vendor should be able to answer every one in writing.
- Artifact placement — does the tool write drafts and decisions into the mailbox, or keep everything in its own store? This single answer determines whether your existing hold reaches them.
- Autonomy level — does it ever send without a human approving? Every autonomous send is an act you may later have to explain, and an approval record is the cheapest explanation there is.
- Log retention versus matter duration — a 90-day log is close to useless in a three-year matter, and nowhere near FINRA Rule 4511's six-year floor for records with no other specified period.
- Export format — can you pull the record as JSON or CSV your archive can ingest, or is it a screen you can only look at? A log you cannot export is not a record you can produce.
- Immutability — is the log append-only, or can entries be edited and deleted? An editable log invites an argument about whether it was edited.
- Suppression and offboarding — can the agent be told to stop acting on custodial mailboxes, and what happens to the logs when the account closes?
Scoring the artifacts: inside or outside the hold#
Run this table against whichever tool you are evaluating. The column that matters is the third one — and for most AI clients, most rows say no.

| Artifact | Who creates it | Preserved by the provider hold? | What to do about it |
|---|---|---|---|
| Sent and received messages | The user, through any client | Yes — this is the mail the hold exists for | Nothing extra. Vault or Purview already has it |
| Drafts saved to the mailbox | The client, if it syncs drafts to the provider | Yes, while the draft is in Drafts | Confirm the tool writes drafts to the provider, not only to its own store |
| Discarded and auto-saved drafts | A user rejecting an AI suggestion | No on Gmail; unpublished on Exchange | Decide with counsel whether rejected suggestions are in scope, and record the decision |
| Agent action log | The AI client's backend | No — it is not in the mailbox | Export on a schedule into the same archive that holds your mail |
| Approval and undo records | The human approving or cancelling | No, unless the tool writes them to the mailbox | Treat as the evidence a person authorised the send |
| Model prompts and responses | The AI layer | Only where the platform stores them in the mailbox | Ask where these are stored, and for how long |
| Triage, label and filing decisions | The agent | Label state syncs; the reasoning does not | Usually low relevance — but scope it out deliberately, not by omission |
A worked example: the hold lands on a Tuesday#
A twelve-person team runs Google Workspace with an AI client on top, in approval-first mode. Litigation counsel issues a hold naming four custodians. Here is the order of operations that keeps it defensible.
- 1
Place the Vault hold first
This is the step that actually preserves the mail, and it works the same whether or not anyone uses an AI client. Do it before touching the AI tool, so no gap opens while you investigate the rest.
- 2
Freeze the AI layer's retention clock
Export the agent log for the four custodians immediately. Vendor logs roll on a fixed window that no hold notice reaches, so an export today is the only version of the record that survives the window.
- 3
Move custodians out of autonomous mode
Switch the named custodians to approval-first or manual for the duration. Not because autonomy is improper, but because during a hold every action is cheaper to explain when a person signed off on it.
- 4
Map the artifacts to the table above
Walk the seven rows and write down, for each one, whether it is preserved by Vault, exported separately, or scoped out. This document is the answer when opposing counsel asks what you did.
- 5
Record what you scoped out and why
Rejected drafts are the usual candidate. A reasoned, contemporaneous decision that they are out of scope is defensible; discovering months later that they were silently purged is not.
Red flags in a vendor's answer#
You will mostly be reading between the lines of a security page. These are the tells that a vendor has not thought about holds at all.
- Answering a question about logs with a statement about mail. "We never store your emails" is not an answer to "how long do you keep the agent's decision record?"
- No published retention period for the agent log anywhere in the docs. If it is not written down, it is not a commitment.
- A log you can view but not export. Screenshots are not a production format.
- "Your provider is the system of record" offered as the entire answer, with nothing after it about what the tool itself keeps.
- Autonomous sending enabled by default with no approval record and no undo window.
- Logs that staff can edit or delete on request. Convenient in support, indefensible in discovery.
Not legal advice
What we'd pick — and who should pick something else#
Start with the honest concession, because it decides a real slice of readers. If your requirement is that the AI decision record must live inside a single preserved system of record — a FINRA-regulated firm reasoning from Rule 4511, or any organisation whose counsel will not accept a second custodial system — then Microsoft 365 Copilot under Purview is the better answer and you should go price that instead. Microsoft writes AI interactions into the mailbox your hold already covers. No third-party client does that today, including ours. Premium eDiscovery features sit behind E5-tier licensing, so check Microsoft's current plan comparison before you budget.
We build AI Emaily, so read the rest with that in mind. We are the right pick for a different reader: teams keeping Gmail, Outlook or IMAP as the system of record, who need a governance record of what the agent did and can export it into the archive they already run.
What that looks like in practice: every send in Copilot mode requires a human to approve it, so there is an approval event behind each message rather than an unexplained autonomous action. The audit log is append-only — entries are never edited or deleted after they are written — and each one carries the actor, action, thread, recipient and the agent's reasoning. You can export the full log or a filtered subset as JSON or CSV. Drafting works from a Personal Context brain and per-client profiles you set yourself, not from a model reading your old mail, and we run zero-retention with model providers and never train on your content.
Our limits, plainly. The audit log is stored in our backend and is not written into your connected mail account, which means a Vault or Purview hold does not reach it — you export it into your archive, and that is a step you have to own. Our published retention is 90 days on the lower tiers and indefinite on the team tier, so a long matter needs a scheduled export. Manual actions you take yourself are not written to the agent log. We hold no SOC 2 Type II yet and will not claim it before it is real. And we are not an archiving or eDiscovery platform — keep Vault or Purview; we sit above it, not instead of it. Access runs on a 7-day free trial; there is no permanent free version.
Questions to put to counsel before rollout#
Five questions, answered once, will cover most of what a rollout review needs.
- Are AI-generated drafts the user never sent within our preservation scope, or outside it?
- Does the agent's reasoning log count as a business record we must retain, or as transient system output?
- What retention period must the agent log meet to satisfy our longest applicable obligation?
- Who is responsible for exporting vendor-held records when a hold issues, and on what schedule thereafter?
- Which mailboxes must be moved out of autonomous mode when a matter opens, and who makes that change?
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.