{"schema":"https://policywatcher.online/schemas/evidence-packet/v1","schemaVersion":"1.0.0","mappingVersion":"2026-07-29.1","changeId":"e71b438b-cf6c-4e7c-b544-d9ac9bec97c9","screeningDate":"2026-10-01T19:47:11.938Z","publicationGate":"published","company":{"id":"149c83d1-89a6-43b9-ade7-bd33a1cada68","name":"Stripe","slug":"stripe","industry":"FinTech"},"policy":{"id":"66546f7a-ef51-4e0f-9595-7c3777c9b746","name":"Services Agreement","type":"terms","jurisdiction":"US","sourceUrl":"https://stripe.com/us/legal/ssa"},"sourceConfidence":{"state":"verified-retrieval","lastCheckedAt":"2026-10-01T20:02:49.488Z","retrievalChannel":"direct","dataStatus":"Available","publicSnapshotEvidence":true,"limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"snapshots":{"old":{"version":1,"sha256":"faf2af70f25041e08c72da1c855b41c9c2c6a2927d04c8b79c8c9f0658e53a74","capturedAt":"2026-07-06T07:19:15.933Z"},"current":{"version":2,"sha256":"b515d0ee1571110505e323960a118fcbf8da3c6d9df076d1740a290ed8319c93","capturedAt":"2026-10-01T19:47:11.931Z"}},"assessment":{"summary":"New clauses increase user responsibility for AI agent actions, restrict how users can utilize Stripe's data output, and impose stricter data breach notification rules.","overallRisk":"High","overallScore":7,"previousPublicChange":null,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"alert","textEn":"New AI Agent clause makes users fully liable for AI agent actions.","textIt":"La nuova clausola sull'Agente AI rende gli utenti pienamente responsabili delle azioni dell'agente AI.","deltaScore":2,"evidenceQuote":"If User uses an AI Agent to access the Stripe Services, User is solely responsible for each action initiated by or through the AI Agent.","evidenceSide":"new","relatedKpi":"kpiAutomatedDecision","anchorStatus":"verified"},{"icon":"warning","textEn":"Stricter 48-hour data breach notification for users, requiring detailed information.","textIt":"Notifica di violazione dati più stringente (48 ore) per gli utenti, con informazioni dettagliate.","deltaScore":1,"evidenceQuote":"If User experiences a Data Incident that is reasonably likely to impact Stripe or its Affiliates, User must notify Stripe without undue delay, which will be no later than 48 hours, after becoming aware of the Data Incident.","evidenceSide":"new","relatedKpi":"kpiBreachNotification","anchorStatus":"verified"},{"icon":"alert","textEn":"Restrictions on using Stripe Output Data for automated decisions or AI training.","textIt":"Restrizioni sull'uso dei dati di output di Stripe per decisioni automatizzate o addestramento AI.","deltaScore":2,"evidenceQuote":"User must not use Stripe Output Data: (a) as the sole input into User’s decision making process (e.g., automated decision making, profiling) about engaging, ceasing to engage, or refraining from engaging in a business relationship with any","evidenceSide":"new","relatedKpi":"kpiAiTrainingOptOut","anchorStatus":"verified"}],"keyPoints":[{"textEn":"Users are now fully responsible for all actions initiated by or through any AI Agent accessing Stripe Services.","textIt":"Gli utenti sono ora pienamente responsabili di tutte le azioni avviate da o tramite qualsiasi Agente AI che accede ai Servizi Stripe.","sentiment":"negative"},{"textEn":"Stricter data incident notification requires users to report breaches within 48 hours with detailed information.","textIt":"Una notifica più rigorosa degli incidenti sui dati richiede agli utenti di segnalare le violazioni entro 48 ore con informazioni dettagliate.","sentiment":"negative"},{"textEn":"New restrictions prevent users from using Stripe Output Data for automated decisions, credit eligibility, or AI model training.","textIt":"Nuove restrizioni impediscono agli utenti di utilizzare i dati di output di Stripe per decisioni automatizzate, idoneità al credito o addestramento di modelli AI.","sentiment":"negative"},{"textEn":"Stripe can modify services without notice if it creates or increases a security risk for itself, users, or financial providers.","textIt":"Stripe può modificare i servizi senza preavviso se ciò crea o aumenta un rischio per la sicurezza per sé, gli utenti o i fornitori finanziari.","sentiment":"negative"}],"regionImpacts":[{"region":"EU","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"Enterprises face a higher compliance burden due to the 48-hour data incident notification requirement (GDPR Art. 33). New restrictions on using Stripe Output Data for automated decisions or AI training require careful review to comply with the EU AI Act.","complianceNoteEn":"GDPR Art. 33, EU AI Act"},{"region":"EU","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Increased user responsibility for AI agent actions and stricter data breach reporting could indirectly affect individuals through the services they use. Restrictions on Stripe Output Data align with GDPR principles and the upcoming EU AI Act.","complianceNoteEn":"GDPR Art. 33, EU AI Act"},{"region":"Global","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"Global enterprises must implement robust internal policies for AI agent management and data incident response to meet the new requirements. The restrictions on Stripe Output Data impact global AI development and automated decision-making strategies.","complianceNoteEn":null},{"region":"Global","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Globally, individuals face increased responsibility for AI agent actions and potential limitations on how their data, processed by Stripe, can be used by businesses. This emphasizes the need for users to understand policy changes.","complianceNoteEn":null},{"region":"US","perspective":"Enterprise","riskLevel":"High","impactAnalysisEn":"US enterprises must adapt to new responsibilities for AI agents and stringent data incident reporting. Restrictions on Stripe Output Data, referencing FCRA and CCPA, necessitate careful review of data processing and AI model development practices.","complianceNoteEn":"FCRA, CCPA"},{"region":"US","perspective":"Individual","riskLevel":"Medium","impactAnalysisEn":"Individuals are indirectly impacted as businesses using Stripe must adhere to new AI agent responsibilities and data output restrictions. The policy references FCRA for data use in credit or employment decisions, offering some protection.","complianceNoteEn":"FCRA, CCPA"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts.","mappings":[{"framework":{"id":"eu-ai-act","name":"Regulation (EU) 2024/1689 (EU AI Act)","shortName":"EU AI Act","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","referenceVersion":"Official Journal text, 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?","kpiFields":["kpiAiTrainingOptOut","kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAiTrainingOptOut","label":"AI training opt-out","value":"Not Available"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"}]},{"framework":{"id":"iso-42001","name":"ISO/IEC 42001:2023","shortName":"ISO/IEC 42001","referenceUrl":"https://www.iso.org/standard/42001","referenceVersion":"ISO/IEC 42001:2023 overview","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?","kpiFields":["kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit","kpiRegulatoryCompliance"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Mentioned"},{"field":"kpiRegulatoryCompliance","label":"Regulatory compliance","value":"Comprehensive"}]},{"framework":{"id":"nist-ai-rmf","name":"NIST AI Risk Management Framework 1.0","shortName":"NIST AI RMF","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?","kpiFields":["kpiAlgoTransparency","kpiAutomatedDecision","kpiAiBiasFairness","kpiContentModeration"]},"status":"mapped","assessedCount":3,"mappedFieldCount":4,"evidence":[{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAutomatedDecision","label":"Automated decisions","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"}]},{"framework":{"id":"oecd-ai-principles","name":"OECD AI Principles","shortName":"OECD AI Principles","referenceUrl":"https://oecd.ai/en/ai-principles","referenceVersion":"OECD AI Principles, updated 2024","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?","kpiFields":["kpiConsentMechanism","kpiAlgoTransparency","kpiAiBiasFairness","kpiIndependentAudit"]},"status":"mapped","assessedCount":4,"mappedFieldCount":4,"evidence":[{"field":"kpiConsentMechanism","label":"Consent mechanism","value":"Implicit"},{"field":"kpiAlgoTransparency","label":"Algorithmic transparency","value":"Opaque"},{"field":"kpiAiBiasFairness","label":"AI bias and fairness","value":"Mentioned"},{"field":"kpiIndependentAudit","label":"Independent audit","value":"Mentioned"}]}]},"humanReviewQuestions":["Does the original Services Agreement source still match the recorded public snapshot version 2?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"methodologyUrl":"https://policywatcher.online/methodology/confidence","changeUrl":"https://policywatcher.online/change/e71b438b-cf6c-4e7c-b544-d9ac9bec97c9","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged.","contentDigest":"7cbf0b6d57a176fc9680276a9b03065a7c62c1be85fd5d5a6d2f91df9bd463d8"}