Skip to main content
TrustEdge AI
Model developer

Meta

Frontier model developer, and the only one here that also distributes open weights. This row describes the hosted Meta Model API on Standard Services — the tier where Meta acts as your processor. The cheaper Discounted Services tier trains on your content by default, and self-hosting the open weights moves every question below to whoever runs them.

5 of 7 criteria carry a sourced value · 2 recorded as a gap ·  Verified August 8, 2026

What this means for a regulated buyer

Our analysis, not Meta’s. Every statement here traces to a sourced claim further down the page.

The only developer here absent from the EU Code of Practice signatory list, and the only one whose cheaper tier trains on your content with no way to exclude traffic.

Where it is strong

  • Standard Services place Meta in a processor role with an explicit commitment not to train on your content.
  • Open weights mean the deployment can be moved entirely in-house, which relocates every question on this page to infrastructure you control.
  • Improved from sixth to fourth between the Winter 2025 and Summer 2026 editions of the FLI Index.

What to check or negotiate

  • Discounted Services train on your content by default and "do not offer a mechanism to exclude specific traffic from training" — the only opt-out is choosing the other tier.
  • The terms instruct that you "must not submit sensitive, confidential, or personal information to the Discounted Services", which is a contractual prohibition, not advice.
  • Retention is purpose-bound across five listed purposes with no period, no deletion commitment and no zero-retention option — the weakest retention disclosure of any vendor tracked here.
  • No HIPAA, Business Associate, SOC or ISO language appears anywhere in the Model API Terms, the general Terms of Service, or the Privacy Policy. Security is delegated to incorporated "Data Security Terms" published separately.
  • Sub-processors are authorised in bulk and prospectively, "as may be updated by Meta from time to time", with no notice period or notification channel.

Verdict

Viable on Standard Services for non-regulated workloads. For PHI or confidential data, the absence of any published BAA or certification means the self-hosted route — where Meta processes nothing — is the defensible one.

The full record

Every criterion, with Meta’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.

FLI safety grade

Safety-research posture, per the Future of Life Institute

D+ · 1.32 (Summer 2026)

Fourth overall of the nine companies graded, up from sixth in the Winter 2025 edition. Received an F in the Existential Safety domain, as did every company other than Anthropic, OpenAI and Google DeepMind.

Primary source · verified 2026-08-07

BAA available

Will they sign a business associate agreement for PHI

Not publicly documented

Neither the Meta Model API Terms of Service, Meta's general Terms of Service, nor Meta's Privacy Policy contains any occurrence of "HIPAA" or "Business Associate". The terms point the other way for the discounted tier: "You must not submit sensitive, confidential, or personal information to the Discounted Services. If you intend, or are required (including by contract), to keep information such as software code confidential, you must not submit that information to the Discounted Services."

Primary source · verified 2026-08-08

Certifications

Independently audited attestations

Not publicly documented

No SOC, ISO or equivalent attestation is named anywhere in the Meta Model API Terms of Service, Meta's general Terms of Service, or Meta's Privacy Policy. Section 14 delegates the whole subject to a separate document — "Meta shall treat your Content and Customer Data in accordance with the Data Security Terms" — which is incorporated by reference rather than published alongside the terms. Ask for that document, and for certificate scope, before relying on any assurance here.

Primary source · verified 2026-08-08

Trains on your data

Whether your inputs and outputs feed model training

Not by default — Standard Services only. Content from Standard Services is not used to train Meta models; the cheaper Discounted Services tier trains on Content by default and offers no mechanism to exclude traffic.

The tier split is the whole story. Standard: Meta acts as processor and "will not use Content from Standard Services to train Meta Models". Discounted: "You agree that Meta may use your Content to train, develop, evaluate, and improve Meta's artificial intelligence models, products, and services", and critically "the Discounted Services do not offer a mechanism to exclude specific traffic from training. If… you otherwise require that Content not be used for training, you must use the Standard Services for that traffic." Disassociation from your account is attempted but bounded: "Meta may use Content for evaluation, safety, abuse, quality, and policy review without first applying those steps", and models so trained "may produce outputs or take actions (including for third parties) that are similar or identical to your Content". Note also that on both tiers you instruct Meta to retain and process Content "to develop, evaluate, and improve systems for the safety and the security of Meta products and services" — not model training, but not nothing.

Primary source · verified 2026-08-08

Retention

How long your data is kept, and where

Purpose-bound with no period stated. Meta retains Content and Usage Data for as long as any of five listed purposes applies.

Meta: "Meta will retain your Content and Usage Data as needed: (i) to provide the Services under these Terms; (ii) to the extent necessary for compliance with applicable laws; (iii) in connection with the exercise of Meta's rights to use your Content and Usage Data under these Terms; (iv) when our systems flag data for a potential policy violation; and (v) for security, safety, abuse, and policy review and improvements." No duration, no deletion commitment and no zero-retention option appears anywhere in the terms. This is the weakest retention disclosure of any vendor tracked here — Google at least bounds it to "a limited period of time", and every other row publishes a number or a zero-retention path.

Primary source · verified 2026-08-08

Subprocessors

Who else processes your data

List incorporated by reference into the Standard Services terms and amendable by Meta at will. No notice period and no notification mechanism.

Meta: "You authorize Meta to engage subprocessors included in the list located [here], as may be updated by Meta from time to time." The authorisation is blanket and prospective, and the terms attach no advance-notice period, no change log and no subscription. Compare Microsoft at six months and AWS at thirty days, both contractual. The list itself sits behind a link in the terms rather than on a public compliance page.

Primary source · verified 2026-08-08

EU AI Act

Obligations, and which transfer to you as deployer

Not listed among the signatories of the EU General-Purpose AI Code of Practice. Meta is the only developer tracked here that does not appear on the Commission’s list.

Read from the European Commission’s published signatory list, on which Amazon, Anthropic, Google, Microsoft, Mistral AI and OpenAI all appear and Meta does not. Absence is weaker evidence than presence: the Commission states that "Some signatories may not appear immediately, but we are making sure to continuously update the list as signatures are confirmed." Non-signature is not non-compliance — the Code is one route to demonstrating compliance with the AI Act, and a provider may use alternative adequate means instead.

Primary source · verified 2026-08-07

This is a model developer, so the FLI grade above describes its safety-research posture. It says nothing about whether a deployment is compliant — that comes from the contractual terms, either this vendor’s own or those of a platform you run the model through.

This developer’s models are also available through Amazon Bedrock, under those platforms’ terms rather than these. Where the direct API cannot meet a requirement, the platform route often can.

Safety grades come from the FLI AI Safety Index, Summer 2026 — what it measures, and what it explicitly does not.

Deploying Meta in a regulated environment

We help regulated organisations build AI vendor diligence that holds up in an audit.