Meta's Privacy Policy now covers AI that acts for you

Stani Mihov
Founder & CEO
·

TL;DR
What happened: Meta published a new version of its Privacy Policy, effective July 23, 2026, rewritten around agentic AI features that can take actions for users. The update adds a new collection category for action data, broader AI personalization sources, external browser and connected-app data flows, and a statement that others can use AI features to share your content outside your chosen audience.
Why it matters: This is the first privacy policy at Meta's scale restructured around AI agents rather than AI chat. The same pattern of policy language will arrive across the software stack as vendors ship comparable agentic features, and most of those changes will get far less scrutiny than Meta's.
The change
On July 23, 2026, a new version of the Meta Privacy Policy took effect across Facebook, Instagram, and Meta's other products. Meta's own update note describes the scope: "Our Privacy Policy now includes more details about AI integrations, how we personalise your AI experiences, and new agentic AI capabilities (for example, AI tools that you can direct to take actions for you, like booking a restaurant or sending an email). Info shared with AI at Meta features is used to improve AI at Meta unless you have objected."
Behind that summary sit five distinct changes to what Meta collects, how it personalizes AI outputs, where request data can travel, and what happens to content shared with a limited audience. Venpo detected the new version within a day of the effective date and verified each change against the previous policy text. The full diff is available on the public change page.
What changed
The rewritten policy touches five areas. First, a new collection category for data generated when AI features perform actions. Second, a dedicated section describing the information sources used to personalize AI responses and actions. Third, disclosures that AI requests can flow to an external web browser and to connected third-party apps and services. Fourth, a new statement about others using AI features to share your content beyond your chosen audience. Fifth, a five-word expansion of the in-app browser clause.
AI that acts for you leaves a data trail
The policy previously covered prompts and responses exchanged with AI at Meta features. The new version adds a collection category for the actions themselves: "Information relating to the actions these features take, like booking you a restaurant reservation or sending an email, including the data these features access or share to take these actions."
The personalization section is equally explicit about inputs. AI responses and actions can now draw on "Your activity and information you provide," "Friends, followers and other connections," "App browser and device information," and "Information from partners, vendors and third parties." Meta illustrates this with a worked example: a user named Anna asks Meta AI for a restaurant recommendation, and the assistant combines her location, her stated love of Italian food, and her recent Instagram likes of fine dining posts to suggest a bistro, then offers to book her a table.
Two new data flows extend beyond Meta. The policy states that some AI features "may also use an external web browser to answer questions and perform actions for you. When you use these features, information related to your request will be shared with the browser. The browser may further share your information with other third parties." A parallel clause covers connected apps: when you link third-party apps and services to your Meta account, Meta "can use this information about you and others in the same ways we use your information as described in this Policy, and share information to perform actions for you involving those third-party apps and services."
Sharing beyond your chosen audience
The sharing section adds a sentence that changes what audience settings mean in practice: "When others interact with our features that are part of AI at Meta, they can share information about you, including messages and content you have shared. This may be on or off our Products and with others outside your chosen audience."
The policy already acknowledged that anyone who can see your content can download, screenshot, or reshare it. The new text names AI features as an additional path, and states plainly that the result can land outside the audience you selected, including off Meta's products entirely. To be precise about what the text says: this clause describes what other people can do using AI features, not a new Meta distribution practice. The practical effect for a user is the same. Content shared with a limited audience now carries an explicit, policy-level caveat that the limit is not a guarantee.
Five words in the in-app browser clause
The smallest change in the diff may be the most consequential for everyday browsing. The previous policy read: "Information about websites that you visit or interact with when you use our in-app browser." The new version reads: "Information about websites that you visit or interact with, and your activity on them, when you use our in-app browser."
The addition of "and your activity on them" moves the disclosed scope from which sites you open to what you do inside them. Every link opened from a Facebook or Instagram feed passes through this browser by default.
Why this matters
Privacy policies built for AI chat described a bounded exchange: you write a prompt, the model answers, the conversation is collected. Agentic AI breaks that boundary. An assistant that books a table or sends an email touches calendars, contacts, external websites, and third-party services, and the policy now claims each of those touchpoints as collectable data. Meta's broader AI data practices were already drawing scrutiny before this update, and this version extends them to a new category of activity.
The external browser clause is worth particular attention. Once request data reaches a third-party browser, the policy states that browser "may further share your information with other third parties." The data leaves Meta's policy perimeter entirely, and the downstream practices are governed by documents most users will never see.
For anyone relying on audience settings as a privacy control, the new sharing language is a formal notice that those settings bound the initial share, not the content's afterlife. The mechanics differ, but the lesson is the same one from our Perplexity case study: what the policy text permits matters more than what the interface suggests.
Potential impact
For consumers, the immediate effect is a wider gap between the interface and the policy. Audience selectors, browser windows, and AI assistants look unchanged, while the text governing them now permits broader collection and movement of data.
For companies, the pattern matters more than the instance. Meta is the first platform of this scale to restructure its privacy policy around agentic AI, but it is not the first vendor to write agent-enabling clauses into a legal document. Stripe did the same for financial data access, as we covered when Stripe opened financial account data to AI agents. Vendors across every category are shipping comparable features, each will need equivalent policy language, and most will add it with far less scrutiny than Meta receives. A clause that lets an AI feature access, share, and act on data across connected services is precisely the kind of change that is easy to miss in a vendor's document mid-contract, because most teams have no process for re-reading terms they already accepted.
How Venpo detected it
Venpo runs continuous monitoring on the Meta Privacy Policy and flagged the new version within a day of the July 23 effective date. The diff engine isolated 181 insertions against the prior text, and the evaluation layer separated substantive changes from the large volume of footnote renumbering, navigation blocks, and formatting cleanup that accompanied the rewrite.
That separation is the practical difficulty with a change like this one. The five substantive shifts described above sit inside a diff dominated by cosmetic edits, and a manual reviewer would need to read the entire restructured document to find them.
Business outcome
Teams monitoring Meta as a vendor, an advertising platform, or a data source received a verified, plain-English account of what changed and where, with each claim traceable to the inserted text. The alternative is discovering the new data flows after an AI feature has already acted on company data through a connected service.
Key takeaway
Agentic AI is rewriting privacy policies before it rewrites products. The features Meta describes are arriving across the software stack, and the policy language enabling them arrives first. Reading the diff is the only way to know what an assistant is permitted to touch before you let it act, which is why monitoring the documents themselves is the control that scales.
The change
On July 23, 2026, a new version of the Meta Privacy Policy took effect across Facebook, Instagram, and Meta's other products. Meta's own update note describes the scope: "Our Privacy Policy now includes more details about AI integrations, how we personalise your AI experiences, and new agentic AI capabilities (for example, AI tools that you can direct to take actions for you, like booking a restaurant or sending an email). Info shared with AI at Meta features is used to improve AI at Meta unless you have objected."
Behind that summary sit five distinct changes to what Meta collects, how it personalizes AI outputs, where request data can travel, and what happens to content shared with a limited audience. Venpo detected the new version within a day of the effective date and verified each change against the previous policy text. The full diff is available on the public change page.
What changed
The rewritten policy touches five areas. First, a new collection category for data generated when AI features perform actions. Second, a dedicated section describing the information sources used to personalize AI responses and actions. Third, disclosures that AI requests can flow to an external web browser and to connected third-party apps and services. Fourth, a new statement about others using AI features to share your content beyond your chosen audience. Fifth, a five-word expansion of the in-app browser clause.
AI that acts for you leaves a data trail
The policy previously covered prompts and responses exchanged with AI at Meta features. The new version adds a collection category for the actions themselves: "Information relating to the actions these features take, like booking you a restaurant reservation or sending an email, including the data these features access or share to take these actions."
The personalization section is equally explicit about inputs. AI responses and actions can now draw on "Your activity and information you provide," "Friends, followers and other connections," "App browser and device information," and "Information from partners, vendors and third parties." Meta illustrates this with a worked example: a user named Anna asks Meta AI for a restaurant recommendation, and the assistant combines her location, her stated love of Italian food, and her recent Instagram likes of fine dining posts to suggest a bistro, then offers to book her a table.
Two new data flows extend beyond Meta. The policy states that some AI features "may also use an external web browser to answer questions and perform actions for you. When you use these features, information related to your request will be shared with the browser. The browser may further share your information with other third parties." A parallel clause covers connected apps: when you link third-party apps and services to your Meta account, Meta "can use this information about you and others in the same ways we use your information as described in this Policy, and share information to perform actions for you involving those third-party apps and services."
Sharing beyond your chosen audience
The sharing section adds a sentence that changes what audience settings mean in practice: "When others interact with our features that are part of AI at Meta, they can share information about you, including messages and content you have shared. This may be on or off our Products and with others outside your chosen audience."
The policy already acknowledged that anyone who can see your content can download, screenshot, or reshare it. The new text names AI features as an additional path, and states plainly that the result can land outside the audience you selected, including off Meta's products entirely. To be precise about what the text says: this clause describes what other people can do using AI features, not a new Meta distribution practice. The practical effect for a user is the same. Content shared with a limited audience now carries an explicit, policy-level caveat that the limit is not a guarantee.
Five words in the in-app browser clause
The smallest change in the diff may be the most consequential for everyday browsing. The previous policy read: "Information about websites that you visit or interact with when you use our in-app browser." The new version reads: "Information about websites that you visit or interact with, and your activity on them, when you use our in-app browser."
The addition of "and your activity on them" moves the disclosed scope from which sites you open to what you do inside them. Every link opened from a Facebook or Instagram feed passes through this browser by default.
Why this matters
Privacy policies built for AI chat described a bounded exchange: you write a prompt, the model answers, the conversation is collected. Agentic AI breaks that boundary. An assistant that books a table or sends an email touches calendars, contacts, external websites, and third-party services, and the policy now claims each of those touchpoints as collectable data. Meta's broader AI data practices were already drawing scrutiny before this update, and this version extends them to a new category of activity.
The external browser clause is worth particular attention. Once request data reaches a third-party browser, the policy states that browser "may further share your information with other third parties." The data leaves Meta's policy perimeter entirely, and the downstream practices are governed by documents most users will never see.
For anyone relying on audience settings as a privacy control, the new sharing language is a formal notice that those settings bound the initial share, not the content's afterlife. The mechanics differ, but the lesson is the same one from our Perplexity case study: what the policy text permits matters more than what the interface suggests.
Potential impact
For consumers, the immediate effect is a wider gap between the interface and the policy. Audience selectors, browser windows, and AI assistants look unchanged, while the text governing them now permits broader collection and movement of data.
For companies, the pattern matters more than the instance. Meta is the first platform of this scale to restructure its privacy policy around agentic AI, but it is not the first vendor to write agent-enabling clauses into a legal document. Stripe did the same for financial data access, as we covered when Stripe opened financial account data to AI agents. Vendors across every category are shipping comparable features, each will need equivalent policy language, and most will add it with far less scrutiny than Meta receives. A clause that lets an AI feature access, share, and act on data across connected services is precisely the kind of change that is easy to miss in a vendor's document mid-contract, because most teams have no process for re-reading terms they already accepted.
How Venpo detected it
Venpo runs continuous monitoring on the Meta Privacy Policy and flagged the new version within a day of the July 23 effective date. The diff engine isolated 181 insertions against the prior text, and the evaluation layer separated substantive changes from the large volume of footnote renumbering, navigation blocks, and formatting cleanup that accompanied the rewrite.
That separation is the practical difficulty with a change like this one. The five substantive shifts described above sit inside a diff dominated by cosmetic edits, and a manual reviewer would need to read the entire restructured document to find them.
Business outcome
Teams monitoring Meta as a vendor, an advertising platform, or a data source received a verified, plain-English account of what changed and where, with each claim traceable to the inserted text. The alternative is discovering the new data flows after an AI feature has already acted on company data through a connected service.
Key takeaway
Agentic AI is rewriting privacy policies before it rewrites products. The features Meta describes are arriving across the software stack, and the policy language enabling them arrives first. Reading the diff is the only way to know what an assistant is permitted to touch before you let it act, which is why monitoring the documents themselves is the control that scales.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
