Document Management Blog | QFlow Systems

NARA's AI Records Guidance (AC 11.2026) | QFlow Systems

Written by QFlow Systems, LLC | Sep 4, 2026, 3:59:52 PM

On August 21, the National Archives issued AC 11.2026, Guidance on Applying the Federal Records Act to Artificial Intelligence Materials (National Archives and Records Administration [NARA], 2026). Federal IT press picked it up a week later, and the headline wrote itself: agency use of AI does not automatically create federal records.

You could feel the shoulders drop across a hundred records offices. Nobody has to capture every prompt. Nobody has to schedule the chat logs. The nightmare scenario — an agency drowning in ten million retained conversations with a chatbot — is off the table.

That reading is correct and it is not the good news it appears to be.

NARA didn't remove a burden. It relocated one. The old anxiety was volume: how do we possibly keep all of this? The new burden is judgment: which of this counted, decided by whom, at the moment it happened. Volume problems get solved with storage. Judgment problems get solved with people, and people are the part that doesn't scale.

Here's what the guidance actually says, what it deliberately leaves alone, and where the real operational risk sits.

What AC 11.2026 actually says, in plain language

The memo comes in two parts. Part I applies the federal record definition to AI inputs, outputs, data, audit trails, and software. Part II confirms the obvious but necessary point that AI records still require a NARA-approved schedule before anyone disposes of them (NARA, 2026).

Part I is where the interesting move happens.

The test is context, not artifact type. NARA's position is that whether an AI material is a federal record "depends on the circumstances surrounding the creation, maintenance, and use of the materials" (NARA, 2026). In practice that resolves to four questions:

  1. Was it used in the course of official agency business?
  2. Was it relied upon in decision making?
  3. Was it circulated or shared with others?
  4. Was it integrated into an agency system?

Nothing about that is novel. It is the same functional test the Federal Records Act has always applied to a sticky note, a voicemail, or a napkin sketch. What is novel is the population it now governs. A napkin sketch is rare. A model output is not.

Prompts and outputs follow the same logic. Prompts and queries become records when they are captured and saved in an agency system and either circulated or used for official purposes. Outputs — query results, an AI-produced work product — become records when they are captured in an agency system and used for official business. Query results the agency never acts on are not records (NARA, 2026).

Commercial tools sit outside the boundary by default. NARA says plainly that commercial applications like Gemini and ChatGPT, which are not created or significantly modified by an agency employee or contractor acting on the agency's behalf, are not themselves records. And it draws a sharper line that deserves more attention than it has gotten: information created by AI and passively retained by a third-party platform is not necessarily "received" by the agency unless it is downloaded or otherwise captured in an agency system (NARA, 2026).

Sit with that one. The record-creating event is not the generation. It is the capture. Whatever happens in the vendor's tenant is, by default, not the agency's record — right up until someone copies it out.

The audit-trail carve-out is the memo's cleverest and most fragile piece. If an employee toggles on an audit trail of their own AI use for personal convenience, doesn't circulate it, and doesn't make decisions from it, that trail is likely a personal file. If the agency captures that same trail and uses it to conduct an investigation, it is a record (NARA, 2026).

Same bytes. Same system. Different status, determined by a downstream decision that hadn't been made yet at the time the data was created. That is defensible records theory. It is a nightmare to instrument.

Part II is the boring part that will bite people. AI materials that meet the record definition need a NARA-approved schedule before disposal (NARA, 2026). Mercifully, the memo takes the sensible line that the fact AI was used is secondary to what the thing is — AI drafted an email, email retention applies; AI produced a report, report retention applies. GRS 5.2 covers a lot of the short-lived material as transitory records (needed under 180 days, no financial or legal obligation attached) or intermediary records (destroyed on creation of the subsequent record).

But two gaps sit right in the middle of it. The GRS does not currently authorize disposal of bodies of data managed separately for the sole purpose of training or further developing AI, and it does not cover the agency's own AI policy documentation (NARA, 2026). Those need agency-specific schedules. If your agency is standing up a fine-tuning corpus this fiscal year, that corpus currently has no approved path to destruction.

What the guidance deliberately does not cover

NARA is unusually explicit about its own scope. AC 11.2026 addresses records management requirements under the FRA only. It does not establish policy on AI governance, e-discovery, privacy, security, or ethical use (NARA, 2026).

That is the right call institutionally — NARA is not the AI governance authority — and it means the memo answers one question out of six that a program office actually has. Someone in your agency owns the other five, and if you can't name them, that's the finding.

Gap NARA left open Who owns it The question they have to answer
AI governance CAIO / agency AI governance board Which tools are approved, for what use cases, with what human review?
E-discovery & litigation hold OGC If a prompt isn't a record, is it still discoverable? (Usually yes. "Not a record" is not "not evidence.")
Privacy SAOP / privacy office What happens when someone pastes PII into a prompt, and does the vendor's retention create a system of records issue?
Security CISO Where does the data physically live, and what's the FedRAMP posture of the tenant holding the "non-records"?
Ethical use Program leadership What can this output be used to decide about a person?
Recordkeeping Records officer ← This is the only one AC 11.2026 answers

The single most expensive misreading available right now is treating "not a federal record" as "not our problem." A prompt that isn't a record can still be produced in litigation, still contain PII, still sit in a tenant your CISO hasn't reviewed. NARA scoped its memo. Your risk isn't scoped.

The determination problem

Here is the sentence in the coverage that everyone quoted and nobody sat with. An employee doing preliminary research for a work-related white paper, who doesn't incorporate or share the AI output, likely hasn't created a federal record — even though search records exist. Take that same output, paste it into a decision memo, and it probably is one (Nextgov/FCW, 2026).

That's a sound distinction. It's also a judgment call, and it is now being made thousands of times a day by people who have never met their agency records officer and have no reason to think of themselves as making a records decision at all.

NARA anticipates this and says the right thing: there is no one-size-fits-all solution, and agencies should build their own AI policies with legal, IT, and program stakeholders (NARA, 2026). Fair. Necessary, even.

But policies don't make determinations. Systems and habits do.

An analyst at 4:40 on a Thursday, pulling a model output into the memo that goes to the deputy administrator tomorrow, is not going to open the AI policy PDF. They are going to paste. The determination gets made — correctly or not — by the paste. The only question is whether your environment noticed.

And note the asymmetry in how this fails. Over-retention is a cost problem: storage, noise, a slightly worse search index. Under-capture is an evidentiary problem, and it surfaces years late. The failure mode isn't an agency drowning in chat logs. It's a decision made in 2026 that nobody can reconstruct in 2029, because the reasoning lived in a chat window nobody thought counted, in a tenant nobody scheduled, generated by a model version nobody logged.

You cannot FOIA a judgment call that was never written down.

Three places to build capture into the workflow instead of the policy

Stop trying to train 40,000 people to classify. Instrument the three moments where NARA's own context test is already being satisfied.

1. The decision memo. NARA's strongest signal is reliance in decision making. So capture at the artifact that is the decision. If your memo, determination, or approval template has a provenance field — what AI assistance was used, which system, what the human reviewer changed — the record captures itself as a byproduct of the work. No classification step. No records training required. The employee fills in a field, not a determination.

2. The system of record. "Integrated into agency systems" is a bright line hiding inside a fuzzy test — and it's the one line you control. Make the ingestion path the capture path. When AI-assisted content crosses from a commercial tenant into an agency repository, that crossing is the moment NARA says receipt occurs (NARA, 2026). Instrument the boundary, not the behavior. This is also the cheapest place to fix the third-party retention problem, because it's the only moment where you know for certain that something left the vendor's environment and entered yours.

3. Shared outputs. Circulation is the third context factor and the easiest to miss, because sharing feels casual. An AI-drafted analysis emailed to four colleagues has been circulated and used for official business. It is very likely a record and almost certainly nobody classified it. If your email and collaboration capture already runs on Capstone or equivalent, most of this is solved — but confirm it covers the newer surfaces, because chat and collaboration tools are where the sharing actually happens now, not in email.

The agencies that handle this well won't be the ones with the best-written AI policy. They'll be the ones where the act of relying on an AI output for official business is what captures it, and the record exists whether or not anyone stopped to classify it.

What to ask your CAIO this quarter

A short list. If the answers take more than a meeting, that's your finding.

  1. What's the inventory? Which AI tools are in use, sanctioned and unsanctioned, and which of them sit inside an agency system versus a vendor tenant?
  2. Where's the boundary? At what exact point does AI-assisted content cross into an agency system — and is that crossing logged?
  3. Who fills the field? Do our decision memo, determination, and approval templates have a place to note AI assistance, and is it required?
  4. What's the audit-trail posture? Are we capturing AI usage logs institutionally? If yes, we've likely made them records. If no, can we reconstruct usage if we ever need to?
  5. Is the training corpus scheduled? If we're building or fine-tuning on agency data, that body of data needs an agency-specific schedule (NARA, 2026). Does it have one, or is it a submission we haven't drafted?
  6. Who owns the other five gaps? Name the person for governance, e-discovery, privacy, security, and ethical use. Not the office. The person.
  7. When did we last test reconstruction? Pick a decision from the last 90 days that used AI assistance. Try to rebuild the reasoning from what we retained. Time it.

That last one is the whole post in a single exercise. Everything else is preparation for it.

The short version

NARA got the policy right. Context is the correct test, a bright line would have been worse, and scoping the memo to records management was institutionally honest.

But correct policy and workable operations are different achievements, and the second one is now the agency's job. AC 11.2026 hands you a standard. It does not hand you a mechanism.

If your AI policy is a PDF and not a workflow, you don't have one yet.

This is the problem QFlow has been building for since before AI made it urgent. QAction was designed on the premise that a record should be captured by the act of doing the work — a decision made, a document approved, a file crossing into the system of record — rather than by a person stopping to classify it. That was a good idea when the volume was human-scale. At AI volume, it's the only thing that holds. If you're working through what AC 11.2026 means for your agency's capture posture, we're glad to talk it through — no pitch required.

References

National Archives and Records Administration (2026) AC 11.2026: Guidance on Applying the Federal Records Act to Artificial Intelligence Materials. Washington, DC: National Archives and Records Administration, 21 August. Available at: https://www.archives.gov/records-mgmt/memos/ac-11-2026 (full text at https://www.archives.gov/files/records-mgmt/policy/nara-fra-ai-guidance.pdf) (Accessed: 4 September 2026).

Nextgov/FCW (2026) 'National Archives says agencies' AI use does not automatically create federal records', Nextgov/FCW, 28 August. Available at: https://www.nextgov.com/artificial-intelligence/2026/08/national-archives-says-agencies-ai-use-does-not-automatically-create-federal-records/415711/ (Accessed: 4 September 2026).