Accessible upon judicial requisition, the prompts sent to an LLM can constitute criminal evidence. A circular of April 13, 2026 systematizes the collection from OpenAI.
The words fly away, the writings remain… and the prompts too. At the bend of a circular dated April 13, 2026 and signed by the Minister of Justice, instructions are given to prosecutors on the conduct to be taken in the context of criminal investigations in their relationship with AI. In an increasingly dematerialized world, digital proof is now central. Service providers, including artificial intelligence platforms, will have to answer for this.
1- An undisputed increase in crimes and offenses committed via digital tools
The circular opens with an observation that no longer surprises anyone: 85% of surveys today involve digital data: emails, instant messages, various dematerialized content. The game of cops and robbers has become considerably more complex, with an advantage given to criminal organizations that have a head start. It is only the repetition of an eternal story: the policeman always runs behind the thief. Criminal organizations have systematized the use of encrypted messaging to conceal their exchanges and organize their actions. The Directorate of Criminal Affairs and Pardons (DACG), responsible for defining criminal policy and ensuring its consistency across the entire territory, now intends to mobilize all available procedural levers to rebalance this balance of power. Citizens can only applaud this necessary step.
The circular is a continuation of two previous texts: the circular of March 5, 2025 on judicial coordination in matters of organized crime, and that of December 27, 2025 relating to the same subject. Three circulars in one year: we cannot say that the signal lacks clarity.
2- The “systematic” solicitation of service or electronic messaging providers
The heart of the system is based on the injunction made to public prosecutors’ offices to systematically contact service or electronic messaging providers “each time the needs of the investigation require it”, including when they are established outside the national territory.
The circular makes a procedural distinction. User identification and location data are accessible upon simple judicial requisition. Content data, which is more sensitive, requires a heavier arsenal: interceptions (art. 100 to 100-8 and 706-95 CPP), remote access to stored correspondence (art. 706-95-1 to 706-95-3 CPP), capture of computer data (art. 706-102-1 to 706-102-5 CPP). The range is wide, and the Minister of Justice intends for us to use it.
3- Kodex platform: a private American platform at the heart of the public system
The DACG explicitly recommends the use of private platforms dedicated to the voluntary exchange of information, and specifically cites Kodex, an intermediary between public authorities and service providers. It is a private American platform founded in 2020, dedicated to the secure management of data requests from judicial and police authorities. It centralizes exchanges between law enforcement and companies (crypto, telecom, fintech, etc.) via an encrypted and verified portal, replacing traditional faxes and emails.
Beyond the incongruity of an American platform recommended by public services (again!), the list of operators accessible via Kodex deserves our full attention: Discord, LinkedIn, Grindr, Binance, Coinbase, Strava, Airbnb, Vodafone Global… and the American company OpenAI. Concrete translation: a French Prosecutor is invited to directly request OpenAI to obtain data relating to a user… and OpenAI organized this circuit well before the circular recommended it.
4- What this changes for professional users of AI tools
For companies and professionals using generative AI tools in the context of their activities, this circular is a reminder which should dispel any illusion: the data transmitted to an LLM is not confidential. Contractual confidentiality clauses do not prevent this if the operator chooses to cooperate voluntarily or is forced to do so in the context of a criminal investigation.
Risky situations are more commonplace than you might think. An employee who inserts the financial terms of an acquisition in progress into a prompt risks having these exchanges seized as part of an investigation for violation of business secrets. A manager who submits a memo to an LLM describing a disputed commercial practice and asking how to “secure” it produces, without knowing it, a potential incriminating document, which is not protected by any professional secrecy, unlike an exchange with his lawyer. A financial analyst who models via ChatGPT the impact of non-public information on a stock price before placing an order provides the prosecution, via OpenAI logs, with proof of the prior nature of his intention.
Under French law, there is no absolute protection similar to professional lawyer secrecy for communications with an AI tool. Reflection on the governance of data entrusted to third parties, including AI providers, must integrate this procedural reality. In the three cases mentioned, it is the prompt itself which constitutes the proof, much more than the response of the model.
Digital hygiene measures are therefore necessary as a preventative measure: deactivate the retention of conversation history in the account settings, use modes without backup when they exist and, failing that, regularly purge the histories.