Meta AI
high riskGenAI Assistantmeta.aiverified 2026-06-27profile 70% complete
Data-handling profile
- Trains on input
- Yes, on all tiers
- Retention
- Meta AI chatbot interactions across Facebook, Instagram, and WhatsApp (as of a Dec 2025 policy change) are used as training data for Meta's algorithms and to inform ad targeting; there is no way to fully deactivate Meta AI in Instagram/Facebook/Threads. Private 1:1/group chat message content is not used to train AI unless a user explicitly shares it with the AI. Public posts/photos may be used for AI training.
- Data region
- Global
- Certifications
- none listed
- DPA available
- No
- Breach history
- none known
- EU AI Act
- No consumer-facing opt-out from AI-chatbot-interaction data use combined with ads-targeting linkage creates significant EU AI Act and GDPR purpose-limitation exposure; already subject to EU regulatory pushback over AI training on user data (2024 EU pause of Meta's AI training in the bloc).
Sources
- https://about.fb.com/news/2023/09/privacy-matters-metas-generative-ai-features/
- https://www.malwarebytes.com/blog/news/2026/05/metas-confusing-new-approach-to-chat-privacy
- https://www.bitdefender.com/en-us/blog/hotforsecurity/metas-chatbot-data-grab-privacy-what-it-means-for-you
- https://us.norton.com/blog/ai/how-to-opt-out-of-meta-ai
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Control mapping
Obligations this vendor triggers, each attributable to the fact it rests on — for your supplier register, not a compliance determination.
- EU AI Act Art. 50 — Transparency obligations for AI systemsattention
trains_on_input = all_tiers. Inputs may be reused for model training — users interacting with this system need to be informed accordingly.
- EU AI Act Art. 26 — Obligations of deployers of high-risk AI systemsapplies
Applies to your organisation as deployer, independent of vendor. Assign human oversight, keep logs, and monitor operation where this tool is used in a high-risk context (Annex III duties apply from 2 Dec 2027).
- ISO/IEC 27001 A.5.19 — Information security in supplier relationshipsapplies
Meta AI processes organisational data as a supplier. Include this vendor in the supplier register and risk assessment.
- ISO/IEC 27001 A.5.20 — Addressing information security within supplier agreementsgap
dpa_available = false. No DPA identified — security and processing terms are not contractually established.
- ISO/IEC 27001 A.5.23 — Information security for use of cloud servicesattention
Cloud AI service; trains_on_input = all_tiers. Data submitted to this cloud service may be retained or reused — define acceptable-use rules for it.
- ISO/IEC 42001 A.10.3 — Suppliers of AI systems and servicesapplies
No certifications listed. No AI-management certification identified; assurance must come from your own supplier assessment.
- GDPR Art. 44–49 — International transfers of personal dataattention
data_region = Global. Processing occurs outside the EU/EEA — a transfer mechanism (SCCs or adequacy) must be in place.
- NIS2 Art. 21(2)(d) — Supply chain securityapplies
AI vendor forms part of your ICT supply chain. In scope for entities covered by NIS2; include in supply-chain risk measures.
- DORA Art. 28 — General principles for ICT third-party riskapplies
AI vendor is an ICT third-party service provider. For financial entities: register of information and contractual requirements apply.
Change history
No material changes recorded since monitoring began.