{"schema":"https://policywatcher.online/schemas/evidence-collection/v1","schemaVersion":"1.0.0","asOf":"2026-10-01T20:02:48.727Z","selection":{"count":1,"limit":12,"companyCount":1,"jurisdictionCount":1,"changeIds":["4961a031-d13e-4e25-b878-22fe5e890e52"]},"records":[{"changeId":"4961a031-d13e-4e25-b878-22fe5e890e52","screeningDate":"2026-10-01T20:02:48.727Z","company":{"id":"149c83d1-89a6-43b9-ade7-bd33a1cada68","name":"Stripe","slug":"stripe","industry":"FinTech"},"policy":{"id":"775c0c08-14f0-4e3f-b3e0-293dc8a4965c","name":"Services Agreement","type":"terms","jurisdiction":"EU","sourceUrl":"https://stripe.com/it/legal/ssa"},"sourceConfidence":{"state":"verified-retrieval","lastCheckedAt":"2026-10-01T20:02:48.714Z","retrievalChannel":"direct","limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"currentSnapshot":{"version":2,"sha256":"b515d0ee1571110505e323960a118fcbf8da3c6d9df076d1740a290ed8319c93","capturedAt":"2026-10-01T20:02:48.720Z"},"assessment":{"summary":"New Stripe terms increase user liability for AI agent actions and impose strict limits on how businesses can use Stripe-derived data, especially for AI and automated decisions.","overallRisk":"High","overallScore":8,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"alert","textEn":"New AI Agent clause shifts full liability to users for AI-driven actions.","textIt":"La nuova clausola sull'Agente AI sposta la piena responsabilità sugli utenti per le azioni AI.","deltaScore":2,"evidenceQuote":"If User uses an AI Agent to access the Stripe Services, User is solely responsible for each action initiated by or through the AI Agent.","evidenceSide":"new","relatedKpi":"kpiAutomatedDecision","anchorStatus":"verified"},{"icon":"alert","textEn":"Strict 48-hour data incident notification for users increases compliance burden.","textIt":"La notifica di incidente dati entro 48 ore per gli utenti aumenta l'onere di conformità.","deltaScore":2,"evidenceQuote":"User must notify Stripe without undue delay, which will be no later than 48 hours, after becoming aware of the Data Incident.","evidenceSide":"new","relatedKpi":"kpiBreachNotification","anchorStatus":"verified"},{"icon":"alert","textEn":"Extensive restrictions on using Stripe Output Data for AI, profiling, and selling.","textIt":"Ampie restrizioni sull'uso dei Dati di Output di Stripe per AI, profilazione e vendita.","deltaScore":3,"evidenceQuote":null,"evidenceSide":null,"relatedKpi":"kpiAiOutputOwnership","anchorStatus":"not-recorded"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"mappedFrameworks":[{"id":"eu-ai-act","name":"EU AI Act","referenceVersion":"Official Journal text, 2024","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?"},{"id":"iso-42001","name":"ISO/IEC 42001","referenceVersion":"ISO/IEC 42001:2023 overview","referenceUrl":"https://www.iso.org/standard/42001","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?"},{"id":"nist-ai-rmf","name":"NIST AI RMF","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?"},{"id":"oecd-ai-principles","name":"OECD AI Principles","referenceVersion":"OECD AI Principles, updated 2024","referenceUrl":"https://oecd.ai/en/ai-principles","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?"}],"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts."},"reviewQuestions":["Does the original Services Agreement source still match the recorded public snapshot version 2?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"links":{"change":"https://policywatcher.online/change/4961a031-d13e-4e25-b878-22fe5e890e52","evidence":"https://policywatcher.online/evidence/4961a031-d13e-4e25-b878-22fe5e890e52","json":"https://policywatcher.online/api/evidence-packet/4961a031-d13e-4e25-b878-22fe5e890e52?format=json","pdf":"https://policywatcher.online/api/evidence-packet/4961a031-d13e-4e25-b878-22fe5e890e52?format=pdf"},"evidencePacketDigest":"3cdbb29203361e3fe2546eb469ab2dd6ff1c485c14f22f0ad6626449645e29cd","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged."}],"reviewChecklist":["Confirm that each selected record is relevant to the intended review scope.","Open the provider source and exact Evidence Packet before relying on a summary.","Keep record-level limitations and advisory framework boundaries attached when reusing the bundle.","Check whether a later public change supersedes any selected record."],"boundary":"This collection groups selected public PolicyWatcher evidence records. It is not exhaustive market coverage, persistent team collaboration, legal advice, a compliance assessment or proof that an external source remains unchanged.","collectionId":"pwc_86928a961b3b91ba","contentDigest":"86928a961b3b91ba5d14f70032593396a0f588e37f511fe9ee8a77ec64679912"}