{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"7db948e3-a96e-4118-85d0-41c51c80796f","screeningDate":"2026-07-28T22:40:16.793Z","publicationGate":"published","company":{"id":"6f69e944-8b6c-4dce-8693-58804624471b","name":"Meta","slug":"meta","industry":"Tech Giant"},"policy":{"id":"466d072b-d894-49fe-aa33-8d607a298f67","name":"Privacy Policy","type":"privacy","jurisdiction":"EU","sourceUrl":"https://www.facebook.com/privacy/policy/"},"sourceConfidence":{"state":"review-required","lastCheckedAt":"2026-07-06T03:59:34.660Z","retrievalChannel":"seeded","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":{"version":4,"sha256":"52164a545dbe7a8d2468fdc70157cf96f334218f3157404e271267a6f71d9f8c","capturedAt":"2026-07-07T02:39:05.496Z"},"current":{"version":5,"sha256":"f1efe39ef8d90e7cab3f599bb1a847daa85a55afa8dd02cbcae2d7e313b2c265","capturedAt":"2026-07-28T22:40:16.790Z"}},"assessment":{"summary":"Meta's updated policy clarifies AI feature interactions and capabilities, including AI performing actions, while also committing to safeguards for AI development.","overallRisk":"Medium","overallScore":7,"previousPublicChange":{"id":"7d60dfa9-f444-46e9-972a-e1679643fa6e","overallRisk":"High","overallScore":8,"screeningDate":"2026-07-07T02:39:05.499Z"},"scoreDelta":-1,"direction":"lower","reasons":[{"icon":"warning","textEn":"AI can \"perform actions,\" expanding its operational scope.","textIt":"L'AI può \"eseguire azioni\", ampliando il suo ambito operativo.","deltaScore":1,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"warning","textEn":"AI safeguards are mentioned but lack specific, actionable details.","textIt":"Le salvaguardie AI sono menzionate ma mancano di dettagli specifici e attuabili.","deltaScore":1,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"},{"icon":"alert","textEn":"Broad data collection for AI training remains extensive.","textIt":"L'ampia raccolta di dati per l'addestramento dell'AI rimane estesa.","deltaScore":1,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":null,"anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"AI branding changed from \"AI at Meta\" to \"Meta AI\" for clarity.","textIt":"Il branding dell'AI è cambiato da \"AI at Meta\" a \"Meta AI\" per maggiore chiarezza.","sentiment":"neutral"},{"textEn":"AI features can now \"perform actions,\" expanding their operational scope.","textIt":"Le funzionalità AI possono ora \"eseguire azioni\", ampliando il loro ambito operativo.","sentiment":"negative"},{"textEn":"Policy commits to \"appropriate safeguards\" for AI development and model accuracy.","textIt":"La policy si impegna a \"salvaguardie appropriate\" per lo sviluppo dell'AI e l'accuratezza dei modelli.","sentiment":"positive"},{"textEn":"Metadata collection is now explicitly \"subject to applicable law.\"","textIt":"La raccolta di metadati è ora esplicitamente \"soggetta alla legge applicabile.\"","sentiment":"neutral"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Businesses using Meta's platforms must assess how Meta AI's expanded \"perform actions\" capability impacts their data processing and compliance with GDPR and the AI Act, especially concerning data flows and accountability.","complianceNoteEn":"GDPR, EU AI Act, DORA"},{"region":"EU","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"The policy's commitment to \"safeguards\" for AI development is a positive step towards compliance with the upcoming EU AI Act, but the expanded AI capabilities require careful monitoring under GDPR for data processing.","complianceNoteEn":"GDPR, EU AI Act"},{"region":"Global","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Global businesses must consider the broader implications of Meta AI's expanded capabilities and the general nature of AI safeguards for their international data strategies and ethical AI frameworks.","complianceNoteEn":"International Data Transfer"},{"region":"Global","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"The policy's clarification on AI interactions and commitment to safeguards is a general improvement, but users globally should remain vigilant about how their data fuels AI features that can now \"perform actions.\"","complianceNoteEn":"Global Privacy Norms"},{"region":"US","perspective":"Enterprise","riskLevel":"Medium","impactAnalysisEn":"Companies leveraging Meta's AI features need to evaluate the implications of AI \"performing actions\" on their data governance and compliance with evolving state privacy laws, ensuring transparency and user consent where applicable.","complianceNoteEn":"State Privacy Laws"},{"region":"US","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Users should note the expanded AI capabilities, including \"performing actions,\" and review their privacy settings to understand how their data interacts with Meta AI, aligning with CCPA/CPRA data rights.","complianceNoteEn":"CCPA/CPRA"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAiTrainingOptOut","label":"AI training opt-out","value":"Not Available"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"}]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Comprehensive"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"},{"field":"kpiContentModeration","label":"Content moderation","value":"Partial"}]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiConsentMechanism","label":"Consent mechanism","value":"Implicit"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"}]}]},"humanReviewQuestions":["Does the original Privacy Policy source still match the recorded public snapshot version 5?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/7db948e3-a96e-4118-85d0-41c51c80796f","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"b904802292a6c63b505feaa87cb8bd9b0d876f9c24ca3b5ad4bf90c69f92e6bd"}