Ai
ai.meta.comThe materials supplied for ai.meta.com are almost entirely research-publication pages (SONAR, FLORES-101) plus a single, narrowly scoped legal document: the Terms & Conditions for the Llama 3.1 Impact Grant Program. None of these documents is a general privacy policy, terms of service, or DPA for an AI product used by professional or enterprise users. The one substantive legal document governs a grant-application program, not a data-processing service, and it is silent on virtually every data-privacy and AI-governance topic in this assessment (input/output ownership for user prompts, model training on user data, retention, deletion, security controls, human review, and compliance certifications). Where the grant terms do speak, they are strongly vendor-favorable: broad IP licenses over submitted Proposals, a $100 liability cap, class-action waiver, sole-discretion termination, and mandatory indemnification. Because the actual product terms and privacy policy were inaccessible and the available text does not establish data-handling protections, this cannot be recommended for professional, enterprise, or regulated use without obtaining and reviewing the genuine product agreements. Confidence is low across most categories because the governing documents are simply not present.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
No product-level terms addressing ownership of user prompts, files, or inputs were supplied. The only relevant text is the grant program's treatment of submitted Proposals, which are subject to a broad license to Meta rather than a general data-ownership statement. For an AI product user, input data ownership is effectively undefined in the available documents.
Output Data Ownership
The supplied documents do not address ownership of AI-generated outputs for any product. The grant terms speak only to 'Developed IP' created using grant funds, assigning it to the Organization but subject to Meta's ownership of Llama Materials and derivatives. There is no general output-ownership provision for a user of an AI tool.
Training Data Usage
The supplied documents are entirely silent on whether user inputs to any AI product are used to train or improve models. No product privacy policy was accessible. Silence on such a central issue for an AI tool is a significant risk signal and cannot be treated as a no-training commitment.
Data Retention & Deletion
No retention schedule, deletion mechanism, or deletion SLA appears in the supplied documents. The grant terms address grant-fund usage timelines, not data retention. Users have no stated way to request deletion of their data based on the available text.
Third-Party Data Sharing
The only sharing disclosure relates to the grant program, where applicant and organization information may be shared with program partners and service providers for administering the program, and third-party 'Know Your Customer' checks may occur. There is no general product-level statement on whether user data is sold or shared with advertisers or data brokers, so the broader position is undisclosed.
Opt-Out Rights
The supplied documents provide no opt-out mechanism for data collection, model-training use, or third-party sharing. Participation in the grant program instead requires consent to information sharing. No opt-out rights are present in the available text.
Compliance & Certifications
No compliance certifications or regulatory frameworks (GDPR, CCPA, SOC 2, ISO 27001, ISO 42001, NIST CSF, EU AI Act) are claimed or evidenced in the supplied documents. The grant terms reference anti-money-laundering and sanctions statutes as obligations on grantees, not as data-privacy certifications. Against the universal baseline, no relevant framework is mentioned.
Model Explainability & Auditability
The supplied documents contain no provisions on model transparency, explainability, or enterprise auditing rights. The research-publication pages describe model methods academically but offer no product-level audit or explainability commitments to users.
Security Practices & Breach History
No security controls (encryption, access controls, penetration testing, incident response) are disclosed, and no trust center or security page is referenced in the supplied text. The grant terms disclaim that services will be 'secure,' and no breach history is discussed. This is a material silence for professional use.
Enterprise vs. Consumer Risk Delta
No enterprise or paid-tier agreement was supplied, and the available grant-program terms make no distinction between free and paid data handling. There is no basis in the documents to identify any protective delta for enterprise users; attempts to reach enterprise documents (DPA, MSA) were inaccessible.
Human Review of User Inputs
The supplied documents do not address whether staff may read or access user prompts or outputs in any AI product. The grant terms describe human review of Proposals for evaluation purposes, but this does not speak to product-level human review of user inputs. The topic is otherwise unaddressed.
Regulatory & Litigation Exposure
The grant terms include sanctions/export-control screening, compliance-notice obligations, a class-action waiver, and California exclusive jurisdiction, but no disclosures of government data requests, law-enforcement cooperation, or ongoing litigation appear. Dispute resolution is heavily vendor-favorable, requiring individual (non-class) claims in California courts.
PII & SPI Data Inventory
The grant application collects identifiable PII (name, email, city/country of residence, employment affiliation) and, during verification, banking information via KYC checks — which qualifies as financial SPI. There is no general product-level data inventory, and the broader privacy policy was inaccessible, so the full scope of collection for AI-product users is undisclosed.
Policy–Product Currency
No PRODUCT SURFACE was supplied, so this is judged on recency alone and capped accordingly. The only dated legal document is the Llama 3.1 Impact Grant Terms, 'Last Updated 11/18/24' — roughly 22 months before the analysis date — and it is a grant-program document that never addresses the AI product's data flows or model-training practices. No current product privacy policy or terms could be retrieved, which independently justifies a RED rating.
Cross-Document Consistency
Multiple documents were retrieved, but only one (the Llama 3.1 Impact Grant Terms) contains substantive legal provisions; the others are research publications with no policy terms to compare. A meaningful cross-document consistency check across Terms, Privacy Policy, and DPA is therefore not possible, and no direct contradictions were identified within the available material.
You've read all 15 risk ratings for Ai. Create a free account to see the exact policy wording behind each rating.