Meta AI
Reached through accounts staff already hold, and interactions feed the same personalisation machinery as the rest of Meta’s products.
What leaks through it
No enterprise tier exists, so there is no version of this app with terms you can negotiate. Anything pasted in is consumer data by construction.
- meta.ai
Guardrails once it is inspected
Alectura intercepts only tools it has been tested against. Everything else is discovered, meaning you get the app, the devices running it and how often, but the content is never decrypted, so content rules cannot run on it yet.
Today Meta AI is discovered: you get the app, the devices running it and how often, without decrypting anything. The rules below are the ones that apply to it, and they run once it is onboarded for inspection.
- MaskNo secrets in inputALC-001
Credentials are masked before the prompt is sent, whatever the account behind it.
- AlertPII in input (basic)ALC-006
Personal data going into a consumer service with no data processing agreement behind it.
- AlertDenied topicsALC-004
Internal codenames and terms you have marked as not-for-consumer-services.
Those are the ones worth spelling out for Meta AI. All 27 rules in the catalog apply, and you can see the full catalog.
What happens to whatever gets through
- Model training
- Interactions are used to improve Meta’s AI models and personalise its services.
- Retention
- Retained per the Meta privacy policy; deletion controls vary by surface.
- Data residency
- Global Meta infrastructure.
The vendor’s own controls
- No enterprise tier
- Blocking at the network layer is the only vendor-side option
Sources
Vendor terms last checked August 14, 2026, and summarised from Meta’s published documentation. Confirm against the sources above before writing policy around this page.
Find out who is running Meta AI.
Discovery comes first, and it works on every AI tool on the fleet, including the ones nobody told you about. Inspection follows for the tools you decide matter.