
The short version, as at 20 September 2026
Meta's WhatsApp Business Solution Terms ban AI Providers from the Business Platform when the AI itself is the product. That ban was aimed at OpenAI, Microsoft and Perplexity. It was never aimed at the clinic, salon, law firm or dealership running a booking bot, and it still is not.
If that is all you came for, you can stop reading. But if you last read about this in January, four things have changed, and three of them affect you rather than OpenAI:
- The clause you can read on Meta's site today is not the January clause. It carries a Last Modified date of 6 March 2026, and it is the version Meta wrote under antitrust pressure.
- The same paragraph contains a data-training prohibition that binds every business running an AI bot on WhatsApp. Almost nobody has written about it. It is the part most likely to put you in breach.
- Since 2 August 2026, EU law imposes a separate chatbot disclosure duty with fines up to EUR 15 million or 3% of worldwide turnover. Meta's rules cost you access. This one costs money.
- On 1 October 2026 the replies your bot sends inside the 24-hour service window stop being free once a number passes 1,000 in a month.
This guide quotes the clause in full, annotates it sentence by sentence, gives the complete dated timeline from primary sources, and sets out what the policy now costs. Every source is linked, with the date we read it.
The clause in full, annotated
Most coverage paraphrases one sentence of this clause. There are five, and the ones that matter to an ordinary business are the ones nobody quotes. Here is the whole thing, verbatim from the WhatsApp Business Solution Terms, read on 20 September 2026:
AI Providers. Providers and developers of artificial intelligence or machine learning technologies, including but not limited to large language models, generative artificial intelligence platforms, general-purpose artificial intelligence assistants, or similar technologies as determined by Meta in its sole discretion ("AI Providers"), are strictly prohibited from accessing or using the WhatsApp Business Solution, whether directly or indirectly, for the purposes of providing, delivering, offering, selling, or otherwise making available such technologies when such technologies are the primary (rather than incidental or ancillary) functionality being made available for use, as determined by Meta in its sole discretion; provided, however, that such technologies may be made available to WhatsApp users who have registered phone numbers with a European Economic Area or Brazil country code. Notwithstanding the foregoing, you may retain an AI Provider as your Third Party Service Provider in accordance with these WhatsApp Business Solution Terms. In such cases, you may not directly or indirectly allow Business Solution Data, including any anonymous, aggregate, or derived forms of Business Solution Data, to be used to create, develop, train, or improve any machine learning or artificial intelligence systems, models, or technologies, including large language models (collectively, "AI Models"); provided that you may use Business Solution Data to fine-tune an AI Model that is for your exclusive use, so long as this does not result in Business Solution Data being used to create, develop, train, or improve any other AI Models. We may terminate your account and revoke your access if we reasonably determine that you have breached these restrictions. This Section survives termination of these WhatsApp Business Solution Terms.
Now take it a sentence at a time.
Sentence 1: the ban, which is almost certainly not about you
The prohibition attaches to AI Providers, and it bites only where the AI is "the primary (rather than incidental or ancillary) functionality being made available for use". Two things are worth noticing.
First, the test is about what you are distributing, not what technology you use. A dental practice whose bot answers questions about crowns using a large language model is offering dentistry appointments. The AI is the mechanism, not the product. An assistant that will discuss anything you type is offering the AI itself. That is the line.
Second, and this is the part that should give any vendor pause, the clause says "as determined by Meta in its sole discretion" twice: once for who counts as an AI Provider, and once for what counts as primary functionality. There is no appeal to an objective standard written into the contract. Meta decides.
Sentence 2: the permission nobody quotes
"Notwithstanding the foregoing, you may retain an AI Provider as your Third Party Service Provider."
This is the sentence that settles the question most business owners are actually asking. You are expressly permitted to build on OpenAI, Anthropic, Google or anyone else, as your service provider, under these terms. Nobody needs to read tea leaves about whether using GPT or Claude behind a WhatsApp bot is allowed. It is written down.
Sentence 3: the data-training prohibition, which is about you
Here is the operative restriction for an ordinary business, and it is the least-reported line in the whole affair:
you may not directly or indirectly allow Business Solution Data, including any anonymous, aggregate, or derived forms of Business Solution Data, to be used to create, develop, train, or improve any machine learning or artificial intelligence systems, models, or technologies, including large language models
Read that against how a lot of WhatsApp bots are actually wired. If you pipe customer conversations into a model API on a plan whose terms permit the vendor to train on your inputs, you are allowing Business Solution Data to be used to improve an AI model. The clause reaches "indirectly", and it reaches "anonymous, aggregate, or derived forms", which closes the obvious escape routes. De-identifying the transcript does not get you out.
The practical consequence is a procurement question, not a prompt-engineering question. For every AI vendor in your stack, you need to know what its default data-use terms say, whether you are on a tier that excludes training, and whether that is documented. Free tiers and consumer plans are where businesses get caught, because those are the plans most likely to permit training by default.
Sentence 4: the fine-tuning carve-out
"provided that you may use Business Solution Data to fine-tune an AI Model that is for your exclusive use, so long as this does not result in Business Solution Data being used to create, develop, train, or improve any other AI Models."
You can train on your own WhatsApp conversations, as long as the resulting model is yours alone and the data does not leak into anything else. That is a meaningful permission, and it distinguishes a private fine-tune from sending transcripts into a shared model. It also creates an obligation: if your vendor fine-tunes on your data and that model is available to other customers, the carve-out does not cover you.
Sentence 5: the penalty, and its half-life
"We may terminate your account and revoke your access if we reasonably determine that you have breached these restrictions. This Section survives termination."
Note what the penalty is and is not. It is not a fine. It is loss of the channel. And the data obligations do not end when the relationship does: the restriction on training survives termination, so conversation data you exported while you were a customer stays subject to it.
The two questions that decide your position
Everything above reduces to two questions. Answer them honestly and you know where you stand.
Question 1: If you described your product to a stranger without using the word "AI", would there be anything left?
"We book aesthetic consultations and answer treatment questions for a Dubai clinic" survives the test. There is a business underneath. "We give you an assistant that answers questions" does not. Nothing is left when you remove the AI, because the AI was the offer. That is the primary-functionality line in plain language.
Question 2: Can you name, for every AI vendor touching a WhatsApp message, the contractual term that stops them training on it?
If the answer is "I assume they don't", you have not met the clause. This is the question that catches otherwise well-run businesses, and it is answerable in an afternoon.
A business that clears both questions is compliant on the AI clause. A business that clears the first and fails the second is in the most common position we see, and it is fixable without changing anything a customer would notice.
The complete timeline, from primary sources
The story has been reported in fragments. Here it is in full, each entry traceable to a regulator or to Meta.
- 13 February 2025. The last version of the Business Solution Terms before any of this. Meta publishes exactly one archived revision, and it contains no AI Providers clause at all. The European Commission confirms the point: before 15 October 2025 the terms "did not provide for any limitation for third-party general-purpose AI assistants".
- July 2025. The Italian Competition Authority (AGCM) opens case A576 into Meta's integration of Meta AI into WhatsApp with greater prominence than competing services.
- 1 July 2025. Unrelated but load-bearing for what follows: WhatsApp moves to per-message pricing.
- 15 October 2025. Meta announces the AI Providers policy. It applies immediately to AI providers new to WhatsApp, and from 15 January 2026 to those already there.
- 25 November 2025. AGCM widens A576 to cover the new terms and opens an interim measures procedure.
- 4 December 2025. The European Commission opens formal proceedings, case AT.41034, under Article 102 TFEU. Scope: the EEA, except Italy, to avoid overlapping with AGCM.
- 24 December 2025. AGCM imposes interim measures under article 14-bis of Law 287/1990, ordering Meta to "immediately suspend the WhatsApp Business Solution Terms in order to preserve access to the WhatsApp platform for Meta AI's competitors".
- 12 January 2026. Brazil's competition authority, CADE, issues a temporary injunction on the same grounds, citing WhatsApp's more than 150 million Brazilian users. Meta complies, then wins an appeal suspending the injunction on 23 January 2026.
- 15 January 2026. The deadline lands. ChatGPT, Microsoft Copilot, Perplexity, Luzia and Poke stop operating on WhatsApp. Zapia withdrew ahead of the date. Meta AI is the only general-purpose assistant left on the platform.
- 9 February 2026. The Commission sends Meta a Statement of Objections, saying it intends to impose interim measures.
- 4 March 2026. Meta revises the policy and re-admits third-party assistants, subject to a fee.
- 6 March 2026. The Last Modified date on the Business Solution Terms you can read today.
- 15 April 2026. The Commission sends a Supplementary Statement of Objections, finding the fee "in effect equivalent to the previous access ban", and expands the investigation to cover Italy as well. The case now covers the whole EEA.
- 9 June 2026. The Commission imposes interim measures, ordering Meta to restore access on the terms in place before 15 October 2025, "notably free of charge", within five working days, and to keep it that way until the investigation ends.
- 13 July 2026. ChatGPT returns to WhatsApp across the EEA: the 27 EU member states plus Iceland, Liechtenstein and Norway.
- 1 August 2026. Meta begins charging all businesses for Meta Business Agent messages.
- 2 August 2026. Article 50 of the EU AI Act becomes applicable.
- August 2026. Meta appeals the interim measures to the EU General Court. The appeal does not suspend its obligation to comply.
- 1 October 2026. Service messages and in-window utility messages become chargeable, with the first 1,000 service messages a month free on each business phone number.
Two observations are worth drawing out of that list.
The first is that the EEA and Brazil carve-out in the terms was not a design choice, it was won. Read the Commission's February Statement of Objections: "since 15 January 2026, the only AI assistant available on WhatsApp is Meta's own tool, Meta AI, while competitors have been excluded". There was no functioning EEA exemption in January. The sentence you can read in the terms today arrived with the March revision, after an Italian injunction, a Brazilian injunction and a Commission Statement of Objections.
The second is that the Commission's June order is rare. It is only the second time the Commission has imposed interim measures under Regulation 1/2003, the first being against Broadcom in 2019. Meta can be fined up to 10% of worldwide turnover for contravening it, plus daily periodic penalties.
Where you stand depends on where your customers' numbers are registered
This is the detail that trips people up. The carve-out is not about where your business is. It is about the country code of the WhatsApp user's registered phone number.
| Market | Third-party general-purpose assistants | Your own purpose-built bot | Basis |
|---|---|---|---|
| EEA (27 EU states, Iceland, Liechtenstein, Norway) | Allowed, and must be free of charge | Allowed | Commission interim measures, 9 June 2026, case AT.41034 |
| Brazil | Allowed | Allowed | Country-code carve-out in the terms |
| UAE, UK, US, India, and the rest of the world | Prohibited | Allowed | AI Providers clause, unmodified |
For a UAE or UK business the practical answer is short. None of the antitrust action helps you, and none of it hurts you, because you were never the target. The clause that governs you is the data-training sentence, and it governs you everywhere.
Three rulebooks now, not one
Until August 2026 this was a platform-policy question. It is not any more. A business running an AI chatbot on WhatsApp for EU customers is now subject to three separate regimes with three different penalties.
| Rulebook | What it demands | What non-compliance costs |
|---|---|---|
| WhatsApp Business Solution Terms | AI must be ancillary to your own business; no training on Business Solution Data | Termination of your account and loss of the channel |
| WhatsApp Business Messaging Policy | Automation is permitted in the 24-hour window, but you must offer prompt, clear and direct escalation to a human | Quality rating damage, messaging limits, restriction |
| EU AI Act, Article 50 (from 2 August 2026) | The chatbot must identify itself as a machine; synthetic content must be machine-readably marked | Up to EUR 15 million or 3% of worldwide annual turnover |
Article 50 of Regulation (EU) 2024/1689 is the one to act on, because the obligation is simple and the deadline has already passed. If a person is interacting with an AI system, they must be told, unless it is obvious to a reasonably well-informed person. A WhatsApp thread that looks exactly like a message from a human is precisely the case the article was written for.
There is one date still ahead: for systems placed on the market before 2 August 2026, the machine-readable marking obligation in Article 50(2) applies from 2 December 2026.
Note that this is a duty on you, the deployer, not on Meta, and it applies regardless of whether your bot is compliant with Meta's rules. We have written separately on how to word an AI disclosure without killing the conversation.
The meter starts on 1 October 2026
This is the change with the most direct effect on anyone running an AI bot, and it has had a fraction of the coverage the ban received. From Meta's own pricing documentation, read 20 September 2026:
- Service messages. "Effective October 1, 2026, Meta will charge for service messages, which have not been charged since November 2024." Charged per message, at the same rates as utility and authentication messages in each market. There are no volume tiers for service messages. Meta has since added a monthly free tier: each business phone number gets its first 1,000 delivered service messages free, with no roll-over. In the UAE each one after that costs AED 0.0576 (USD 0.0157), on Meta's rate card effective 1 October 2026.
- In-window utility messages. "Effective October 1, 2026, Meta will charge on a per-message basis for utility messages sent in response to users within an open 24-hour customer service window. These messages have not been charged since July 1, 2025."
- Meta Business Agent. "Effective August 1, 2026, Meta will charge all businesses for Meta Business Agent messages", at one global rate of USD 2.00 per million tokens. Meta puts a typical message at 20,000 to 25,000 tokens, which is roughly 4 to 5 US cents each.
Put plainly: the free replies are ending. If your AI bot handles an inbound enquiry with a twelve-message back-and-forth inside the service window, every one of your outbound messages in that exchange was free until 30 September and is billable from 1 October.
The strategic consequence is that conversation length is now a cost centre. A bot that asks six questions where three would do has always been worse for the customer. From October it is also more expensive, on every conversation, forever. If you have never measured messages-per-resolved-enquiry, that is the number to start with, and you have eleven days.
Several markets also move from regional pricing to standalone rate cards on the same date, including Bangladesh, Iraq, Nepal, Sri Lanka, Kazakhstan, Kuwait, Morocco, Oman and Ukraine. Our UAE pricing page carries the AED rate card and the date it was read, and we break down pricing by country separately.
The wider shape of it
Step back from the individual dates and a pattern is hard to miss.
In October 2025 Meta closed the Business Platform to third-party general-purpose assistants. In June 2026 it launched Meta Business Agent globally, its own AI agent for businesses across WhatsApp, Instagram and Messenger, free at launch. On 1 August 2026 it began charging for it. On 1 October 2026 it begins charging for the service-window replies that competing automation depends on.
We are not alleging anything the regulators have not already alleged, and the Commission's investigation on the merits is still open, so nothing is proven. But a business planning its next two years should read the sequence for what it plainly is: the field was cleared, a first-party product was introduced into it, and the meter was then switched on. Meta reports more than one million businesses already using a Business Agent.
The defensive position is the same one it has always been: own your prompts, own your conversation data, own your escalation logic, and keep them portable. If your entire customer-conversation layer is a first-party product on a platform whose pricing you do not control, you have a dependency, not a system.
What compliant actually looks like
Compliance here is not a setting. It is a small file you should be able to produce if Meta, a client or a regulator asks. Seven items, and most businesses can assemble them in a morning.
- A one-paragraph description of your bot's job. Written without the word "AI". If nothing is left, you have a problem with sentence 1 of the clause.
- Your model vendor list, with the data-use term for each. Vendor, plan tier, the specific contractual term excluding training on your inputs, and the date you checked. This is the evidence for sentence 3, and it is the item almost nobody has.
- Your retention position. How long transcripts sit with each vendor, and whether zero-retention is available and enabled.
- Your fine-tuning position. If you fine-tune, evidence the resulting model is for your exclusive use.
- Your escalation path, as configured. Not "we have one", but the actual trigger conditions and the route to a human. Our guide to handoff design covers the thread-control problem this creates.
- Your AI disclosure, and where it appears in the thread. Required under Article 50 for EU users from 2 August 2026.
- Your opt-in records and template categories. Unchanged by all of this, and still the most common cause of actual enforcement. See what triggers an account review.
Note what is not on the list: your vendor's logo. No platform badge makes you compliant, because the test in the terms is about how the bot is used, not whose dashboard it runs on. Ask any provider that claims otherwise to confirm your specific use case in writing.
What enforcement actually looks like
The consequence of breaching the AI clause is written into it: Meta "may terminate your account and revoke your access". There is no fine, and there is no notice period in the contract.
In practice, enforcement on the Business Platform arrives in two shapes, and it is worth knowing which one you are looking at. A restriction disables messaging for a period while leaving the account intact, and is usually reversible once the underlying behaviour stops. A ban deactivates the account, and takes the conversation history with it. Where a review is available you will see a "Request a review" option; where it is not, Meta treats the decision as final.
The honest picture as at September 2026 is that visible enforcement under the AI clause has been aimed at AI Providers, exactly as written, and we are not aware of a wave of ordinary businesses losing access over it. That is not a reason to ignore the data-training sentence. It is a reason to fix it cheaply now, while it is a procurement task rather than an incident. What does get ordinary businesses restricted is still the familiar list: block rates, template abuse, and messaging people who never opted in.
Questions we get asked
Is ChatGPT banned from WhatsApp?
Not everywhere, and not any more in Europe. It stopped operating on 15 January 2026, and returned across the EEA on 13 July 2026 after the European Commission ordered Meta to restore free access. Outside the EEA and Brazil, third-party general-purpose assistants remain prohibited.
Can I use OpenAI or Claude to power my WhatsApp bot?
Yes, expressly. The terms permit you to retain an AI Provider as your Third Party Service Provider. The condition is that your WhatsApp conversation data must not be used to train or improve any AI model other than one for your exclusive use.
Does the policy apply to the WhatsApp Business app, or only the API?
The Business Solution Terms govern the WhatsApp Business Platform, the API. The free Business app is a different product with different terms and different capabilities. We set out the difference in the app versus API guide.
What date did the policy take effect?
15 October 2025 for AI providers new to WhatsApp, and 15 January 2026 for those already on the platform. The text you can read today was last modified on 6 March 2026.
Is my business an "AI Provider"?
Almost certainly not. The definition catches providers and developers of AI technologies who make those technologies available as the primary functionality. A business using AI to serve its own customers is on the other side of the line, and the terms say so explicitly in the next sentence.
Does my bot have to say it is a bot?
Under the WhatsApp Business Messaging Policy, no, but you must offer prompt and direct escalation to a human. Under Article 50 of the EU AI Act, yes for EU users, since 2 August 2026, unless it would be obvious to a reasonably well-informed person.
What changes on 1 October 2026?
Service messages become chargeable for the first time since November 2024, and utility messages sent inside an open 24-hour customer service window become chargeable for the first time since 1 July 2025. If your AI bot replies inside the service window, those replies start costing money once a number passes 1,000 service messages in the month.
Who decides whether my use case is "ancillary"?
Meta, in its sole discretion. The phrase appears twice in the clause. That is a good reason to keep a written description of your bot's business purpose and to make sure your provider will stand behind your use case in writing.
Where this leaves you
If you run a service business using WhatsApp to talk to your own customers, the ban was never about you and still is not. The three things that are about you are the data-training sentence in the same clause, the EU disclosure duty that landed on 2 August 2026, and the pricing change that lands on 1 October 2026.
The first is a procurement task. The second is a wording task. The third is an efficiency task, and it is the one with a deadline eleven days away.
Learnmind builds and runs WhatsApp automation and AI receptionists for service businesses from Dubai. If you would like your setup checked against all three rulebooks, with the vendor data-use terms actually read rather than assumed, ask us to run that audit and we will tell you what we find, including if the answer is that you are already fine.
Sources
Every document below was read on 20 September 2026. Where a position is contested or still under investigation, this guide says so rather than rounding it into a verdict.
- WhatsApp Business Solution Terms, Last Modified 6 March 2026, and the single published prior revision of 13 February 2025.
- WhatsApp Business Messaging Policy, on automation and escalation.
- Meta for Developers, upcoming pricing updates for Meta Business Agent, service and utility messages, and the main pricing documentation.
- European Commission, opening of proceedings in case AT.41034; Statement of Objections, 9 February 2026; Supplementary Statement of Objections, 15 April 2026; interim measures decision, 9 June 2026.
- Autorità Garante della Concorrenza e del Mercato, case A576 interim measures, 24 December 2025.
- European Commission, guidelines on transparency obligations under Article 50 of the AI Act.
- TechCrunch, the October 2025 terms change, the Italian order, the Brazilian order, and the global launch of Meta Business Agent.
- TLT LLP on the parallel competition investigations.
- For the line-by-line contract read, see our companion guide to what the Business Platform terms allow and ban, and to classifying your agent under the generative AI policy.




