{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"4961a031-d13e-4e25-b878-22fe5e890e52","screeningDate":"2026-10-01T20:02:48.727Z","publicationGate":"published","company":{"id":"149c83d1-89a6-43b9-ade7-bd33a1cada68","name":"Stripe","slug":"stripe","industry":"FinTech"},"policy":{"id":"775c0c08-14f0-4e3f-b3e0-293dc8a4965c","name":"Services Agreement","type":"terms","jurisdiction":"EU","sourceUrl":"https://stripe.com/it/legal/ssa"},"sourceConfidence":{"state":"verified-retrieval","lastCheckedAt":"2026-10-01T20:02:48.714Z","retrievalChannel":"direct","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":{"version":1,"sha256":"faf2af70f25041e08c72da1c855b41c9c2c6a2927d04c8b79c8c9f0658e53a74","capturedAt":"2026-07-06T07:19:13.125Z"},"current":{"version":2,"sha256":"b515d0ee1571110505e323960a118fcbf8da3c6d9df076d1740a290ed8319c93","capturedAt":"2026-10-01T20:02:48.720Z"}},"assessment":{"summary":"New Stripe terms increase user liability for AI agent actions and impose strict limits on how businesses can use Stripe-derived data, especially for AI and automated decisions.","overallRisk":"High","overallScore":8,"previousPublicChange":null,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"alert","textEn":"New AI Agent clause shifts full liability to users for AI-driven actions.","textIt":"La nuova clausola sull'Agente AI sposta la piena responsabilità sugli utenti per le azioni AI.","deltaScore":2,"evidenceQuote":"If User uses an AI Agent to access the Stripe Services, User is solely responsible for each action initiated by or through the AI Agent.","evidenceSide":"new","relatedKpi":"kpiAutomatedDecision","anchorStatus":"verified"},{"icon":"alert","textEn":"Strict 48-hour data incident notification for users increases compliance burden.","textIt":"La notifica di incidente dati entro 48 ore per gli utenti aumenta l'onere di conformità.","deltaScore":2,"evidenceQuote":"User must notify Stripe without undue delay, which will be no later than 48 hours, after becoming aware of the Data Incident.","evidenceSide":"new","relatedKpi":"kpiBreachNotification","anchorStatus":"verified"},{"icon":"alert","textEn":"Extensive restrictions on using Stripe Output Data for AI, profiling, and selling.","textIt":"Ampie restrizioni sull'uso dei Dati di Output di Stripe per AI, profilazione e vendita.","deltaScore":3,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":"kpiAiOutputOwnership","anchorStatus":"not-recorded"}],"keyPoints":[{"textEn":"Users are fully liable for all actions initiated by or through any AI Agent used to access Stripe Services.","textIt":"Gli utenti sono pienamente responsabili per tutte le azioni avviate da o tramite qualsiasi Agente AI utilizzato per accedere ai Servizi Stripe.","sentiment":"negative"},{"textEn":"Strict 48-hour deadline for users to report data incidents impacting Stripe, with detailed information required.","textIt":"Termine rigoroso di 48 ore per gli utenti per segnalare incidenti di dati che impattano Stripe, con informazioni dettagliate richieste.","sentiment":"negative"},{"textEn":"New restrictions prohibit using Stripe Output Data for automated decision-making, credit scoring, or training competing AI models.","textIt":"Nuove restrizioni vietano l'uso dei Dati di Output di Stripe per decisioni automatizzate, punteggi di credito o addestramento di modelli AI concorrenti.","sentiment":"negative"},{"textEn":"Users are explicitly prohibited from using Stripe Output Data in ways that violate FCRA, CCPA, or the EU AI Act.","textIt":"Agli utenti è esplicitamente vietato utilizzare i Dati di Output di Stripe in modi che violino FCRA, CCPA o l'EU AI Act.","sentiment":"negative"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"EU businesses face high compliance risk due to strict 48-hour data incident notification and extensive restrictions on using Stripe Output Data, especially concerning the EU AI Act and GDPR. Liability for AI Agent actions is fully shifted to the user.","complianceNoteEn":"GDPR, EU AI Act"},{"region":"EU","perspective":"Individual","riskLevel":"High","impactAnalysisEn":"Individuals face increased risk from potential misuse of their data if businesses fail to comply with new restrictions on automated decision-making and AI practices. The EU AI Act is directly referenced, aiming to protect individuals from harmful AI.","complianceNoteEn":"GDPR, EU AI Act"},{"region":"Global","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"Global enterprises must adapt to the new 48-hour data incident notification and the broad restrictions on Stripe Output Data, which align with global trends in AI and data governance. Managing AI Agent liability is a universal challenge.","complianceNoteEn":null},{"region":"Global","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Globally, individuals benefit from the general intent to prevent discriminatory or harmful uses of AI and data. However, the specific protections vary by local regulations, which users must ensure are met.","complianceNoteEn":null},{"region":"US","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"US businesses face increased compliance burden due to the 48-hour data incident notification and strict rules on using Stripe Output Data, particularly concerning FCRA and CCPA. Full liability for AI Agent actions is a significant new risk.","complianceNoteEn":"FCRA, CCPA"},{"region":"US","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Individuals are protected by explicit prohibitions against using Stripe Output Data for credit, insurance, or employment eligibility decisions under FCRA. CCPA is also referenced regarding data selling, offering some consumer control.","complianceNoteEn":"FCRA, CCPA"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAiTrainingOptOut","label":"AI training opt-out","value":"Not Available"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Partial"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"}]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Comprehensive"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"mapped","assessedCount":3,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Partial"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"}]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":3,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Absent"}]}]},"humanReviewQuestions":["Does the original Services Agreement source still match the recorded public snapshot version 2?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/4961a031-d13e-4e25-b878-22fe5e890e52","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"3cdbb29203361e3fe2546eb469ab2dd6ff1c485c14f22f0ad6626449645e29cd"}