
You assume that anything typed into a Meta product eventually trains a Meta model. On the WhatsApp Business Platform that assumption is wrong, and the reason is contractual rather than technical. Meta's WhatsApp business data AI training policy, written into WhatsApp's Business Solution Terms, bars you and any AI vendor connected to your account from allowing Business Solution Data, "including any anonymous, aggregate, or derived forms", to be used "to create, develop, train, or improve any machine learning or artificial intelligence systems, models, or technologies, including large language models". There is no toggle to switch on. It is a term you already agreed to.
Does Meta use your WhatsApp Business messages to train its AI?
No, and more usefully, nobody in the chain may. Read the clause slowly and the load-bearing words are "anonymous, aggregate, or derived". That phrasing closes the escape route every vendor reaches for first. Stripping names and phone numbers from a transcript, calling the result anonymised, and feeding it to a training run is exactly what the wording prohibits.
The parties bound are the business and any AI vendor wired into its WhatsApp account. That distinction matters, because the risk is rarely yours. A clinic has no model to improve. Its chatbot supplier does, and the supplier signed the same terms by connecting to your number.
What the terms do not do is describe every use Meta makes of data across its own consumer products. They govern the Business Solution pipeline, which is the pipeline your customer conversations actually run through. When a customer asks who can see their message to your business, the accurate answer points at the contract governing that pipeline, not at a privacy setting.
What counts as protected data, phone numbers or chat content?
Both, because the restriction is written against a category rather than a list of fields. Business Solution Data is the whole body of data flowing through the Business Solution, so the customer's phone number, the text of the thread, and anything derived from either sit inside the ban together. There is no tier where the number is fair game and the message is not.
A second restriction runs alongside it. The same policy update also rules out using conversation data to build or expand profiles on individual WhatsApp users beyond the content of that one message thread, according to one industry analysis of the change. In practice that is the clause that constrains enrichment: taking a number from a WhatsApp enquiry, matching it to a browsing profile or an external dataset, and building a richer record than the conversation itself produced.
One thing operators reach for and should not: WhatsApp's Advanced Chat Privacy setting, the control that blocks chat exports and AI training on personal conversations, does not extend to business chats. The same write-up notes that gap. Business chats are protected by contract, not by that switch, so do not cite it to a nervous customer.
Does the WhatsApp business data AI training policy change under UAE or UK data law?
No. The ban is contractual and it travels with the platform, so it reads identically for a +971 number in Dubai and a +44 number in Manchester. The only geography written into the policy is a carve-out on a different question entirely: general-purpose AI technologies "may be made available to WhatsApp users who have registered phone numbers with a European Economic Area or Brazil country code". UAE and UK numbers are not in that list, so a general-purpose AI assistant cannot be offered to them through the Business Solution.
Local data protection law sits on top of the contract rather than underneath it. It can add obligations, around consent records, retention and subject access. It does not loosen a term Meta can enforce against your account, and no regulator grants you permission to breach a commercial agreement.
The European Commission has opened an antitrust investigation into the policy, recording that Meta announced it in October 2025 and that it prohibits AI providers from using the WhatsApp Business Solution when AI is the primary service offered. The Commission's case page carries a 4 December 2025 update. That investigation concerns market access for AI providers, not your right to run support automation, and its outcome is unsettled. If you operate in the Gulf, the practical reading has not moved since the UAE policy shift.
Can you still fine-tune a private model on your own chats?
Yes, with one condition, and it is written plainly. Meta's Business Platform terms permit you to use WhatsApp Business Platform Data "to fine-tune an AI Model that is for your exclusive use, so long as this does not result in WhatsApp Business Platform Data being used to create, develop, train, or improve" other AI models. Exclusive use is the whole test.
Apply it to the arrangement you are actually being sold. If your vendor fine-tunes one model and points every client at it, your transcripts are improving a model that is not exclusively yours, and the permission does not cover it. If the vendor trains a separate adapter or model instance that only answers your number, and the resulting weights are not folded back into anything shared, that is the permitted case.
The question to put in writing is short. Ask whether the artefact produced from your conversations is used by any account other than yours, and ask for the answer in the contract rather than in an email.
Does compliance cost you AI-suggested replies or automated support?
No. Ancillary AI stays switched on. The European Commission's summary of the policy states that businesses may still use AI tools "for ancillary or support functions, such as automated customer support offered via WhatsApp". Suggested replies, intent routing, out-of-hours answering, booking capture and triage all sit inside that description.
The boundary is about character, not capability. The restriction targets AI providers making their technology available through the Business Solution "when such technologies are the primary (rather than incidental or ancillary) functionality being made available for use, as determined by Meta in its sole discretion". A dental practice answering enquiries with AI is running a support function. A vendor placing a general assistant on WhatsApp that people message for its own sake is offering the AI as the product.
Nothing in the data restriction degrades quality either. A model does not need to train on your transcripts to use them at inference time, which is why context handling and latency, not training data, determine whether you get natural-sounding AI replies.
Has any of this changed what messages cost?
Yes, for entities Meta classifies as AI Providers, and the counting rule inside that change is worth knowing whoever you are. Meta for Developers documentation, last updated on 21 May 2026, records that effective 13 May 2026 Meta "will no longer charge AI Providers for non-template messages delivered to users in certain markets", having begun charging for messages to Brazil (+55) on 11 March 2026. The wider pricing documentation, updated on 5 August 2026, sets out the per-message basis that took effect on 1 July 2025 and the rule that non-template messages have not been billable since 1 November 2024.
| Date | What changed | What it means for a service business |
|---|---|---|
| 1 November 2024 | Non-template messages stop being billable under WhatsApp pricing | Replying inside an open conversation is not what costs you money |
| 1 July 2025 | WhatsApp pricing moves to a per-message basis | Each message counts on its own, so message shape drives cost |
| October 2025 | Meta announces the AI provider policy (per the European Commission) | The primary-versus-ancillary line is set |
| 15 January | General-purpose AI chatbot contacts wound down on business accounts | Assistant-style contacts are gone; support automation is not |
| 4 December 2025 | European Commission case page on the investigation updated | Market access for AI providers is contested, your support stack is not |
| 11 March 2026 | Meta begins charging AI Providers for messages to Brazil (+55) | AI Provider billing is applied market by market |
| 13 May 2026 | Meta stops charging AI Providers for non-template messages in certain markets | The charge set is narrowing, not widening |
| 21 May 2026 | AI Providers pricing documentation last updated | The current reference point for any pricing question |
Now the counting rule. Meta's own worked example: if a user in Italy sends an AI Provider a prompt and the provider delivers three non-template message responses over five minutes, that incurs three charges. Redo it with your own volume. Four hundred conversations a month, each answered in three short bubbles because the bot was configured to feel chatty, produces 1,200 chargeable events instead of 400 wherever that traffic is billable. The multiplier is three, applied to whatever rate your market carries. Configure the assistant to answer in one message and the same conversation costs a third as much.
What happens if you or your vendor break the rule?
Account termination, and Meta reserves that outcome in the same sentence as the fine-tuning permission: "We may terminate your account and revoke your access if we reasonably determine that you have breached these restrictions." Enforcement is account-level. That means the number, the verified display name, the template library and the quality rating you built over two years.
Two details sharpen the risk. Determination of what counts as primary functionality sits with Meta "in its sole discretion", so the argument is not one you win on a technicality. And the restriction is written to outlive the relationship, which is why a vendor who leaves with a copy of your transcripts remains your exposure. Businesses running enquiries through an unverified personal handset avoid this contract entirely, along with every protection in it, which is one more reason the business number versus personal decision is not cosmetic.
How operators keep AI on the safe side of the line
The territory is narrower than it sounds, and almost everything a service business wants is inside it. Three questions decide any proposal on the table. Run them in order and you will not need a lawyer for most decisions.
- Character: is the AI a function of my business, or the thing the customer came to talk to? Answering enquiries about your clinic is ancillary. A general assistant living on your number is primary, and that is the configuration Meta already required vendors to retire.
- Direction of data: does anything derived from these conversations end up improving a model that serves anyone but me? If the answer involves the words anonymised or aggregated, it is still a breach, because the clause names those forms explicitly.
- Depth of record: am I building a profile of this person that reaches beyond this thread? Storing the thread and the booking it produced is ordinary operations. Matching the number against outside datasets to enrich a profile is the move the policy rules out.
Two practices sit in the honest middle, and you will meet both. Pasting transcripts into a general-purpose assistant account to summarise the week's enquiries is common, fast, and carries platform-contract risk if that provider's default settings allow training on inputs, since the data left your control the moment you pasted it. Retaining full transcripts indefinitely in your CRM for quality review carries no platform risk at all, but it is a data protection question under your local law, and the two risks are not interchangeable. Operators with a low appetite turn off provider-side training in writing before either.
The task worth doing this week costs nothing. Send your AI vendor one message and keep the reply: confirm in writing that no Business Solution Data, including any anonymous, aggregate or derived form of it, is used to create, develop, train or improve any AI model other than one for our exclusive use, and that no profiles of individual users are built beyond the content of a single message thread. A vendor who cannot answer that in two lines is telling you something.
Questions owners still ask before switching the AI on
Do I have to tell customers an AI is answering?
The restrictions described here govern data use and product character, not disclosure, so Meta's terms are not where that duty would come from. Consumer and data protection rules in your market are. The operational answer most practices settle on is to say it in the first reply and offer a human path immediately, because customers object far less to an AI that identifies itself than to one they catch out three messages in.
If I change vendors, what happens to the transcripts the old one holds?
The training restriction binds them whether or not they still hold your account, since Meta's terms allow enforcement after the underlying agreement has ended. What the terms do not give you is an automatic deletion timetable, so put one in the contract: a named retention period, a deletion confirmation on exit, and a clause covering backups. Ask for it at signing, when you have leverage, rather than at exit when you have none.
Does a vendor saying my data is anonymised satisfy the rule?
No, and this is the single most common misunderstanding. The clause covers anonymous, aggregate and derived forms by name. A vendor citing anonymisation as their compliance answer has either not read the terms or is hoping you have not.
The question to ask yourself: is AI my product, or a function of my business?
For a clinic, salon, agency or gym, the honest answer is the second one, and that answer places you comfortably inside what Meta permits: automated support, suggested replies, routing, booking capture, and a fine-tuned model for your exclusive use. The businesses caught by this policy were selling the assistant itself. If you are selling treatments, tenancies or training sessions, the constraint you are worried about was never aimed at you.
If you are about to sign with an AI vendor for your WhatsApp line, send us their data and training clauses before you do, and we will tell you which two sentences to change. No pitch attached.
Related reading
- WhatsApp Business AI Chatbot Policy 2026: A Plain-English Guide
- Will WhatsApp Automation Get Your Business Banned?
- WhatsApp's AI Chatbot Policy in 2026: What the Business Platform Terms Allow and What They Ban



