{"schema":"https://policywatcher.online/schemas/evidence-collection/v1","schemaVersion":"1.0.0","asOf":"2026-10-01T19:47:11.938Z","selection":{"count":1,"limit":12,"companyCount":1,"jurisdictionCount":1,"changeIds":["e71b438b-cf6c-4e7c-b544-d9ac9bec97c9"]},"records":[{"changeId":"e71b438b-cf6c-4e7c-b544-d9ac9bec97c9","screeningDate":"2026-10-01T19:47:11.938Z","company":{"id":"149c83d1-89a6-43b9-ade7-bd33a1cada68","name":"Stripe","slug":"stripe","industry":"FinTech"},"policy":{"id":"66546f7a-ef51-4e0f-9595-7c3777c9b746","name":"Services Agreement","type":"terms","jurisdiction":"US","sourceUrl":"https://stripe.com/us/legal/ssa"},"sourceConfidence":{"state":"verified-retrieval","lastCheckedAt":"2026-10-01T20:02:49.488Z","retrievalChannel":"direct","limitation":"Source confidence describes recorded retrieval and publication state. It does not rate the provider policy or certify source authenticity."},"currentSnapshot":{"version":2,"sha256":"b515d0ee1571110505e323960a118fcbf8da3c6d9df076d1740a290ed8319c93","capturedAt":"2026-10-01T19:47:11.931Z"},"assessment":{"summary":"New clauses increase user responsibility for AI agent actions, restrict how users can utilize Stripe's data output, and impose stricter data breach notification rules.","overallRisk":"High","overallScore":7,"scoreDelta":null,"direction":"baseline","reasons":[{"icon":"alert","textEn":"New AI Agent clause makes users fully liable for AI agent actions.","textIt":"La nuova clausola sull'Agente AI rende gli utenti pienamente responsabili delle azioni dell'agente AI.","deltaScore":2,"evidenceQuote":"If User uses an AI Agent to access the Stripe Services, User is solely responsible for each action initiated by or through the AI Agent.","evidenceSide":"new","relatedKpi":"kpiAutomatedDecision","anchorStatus":"verified"},{"icon":"warning","textEn":"Stricter 48-hour data breach notification for users, requiring detailed information.","textIt":"Notifica di violazione dati più stringente (48 ore) per gli utenti, con informazioni dettagliate.","deltaScore":1,"evidenceQuote":"If User experiences a Data Incident that is reasonably likely to impact Stripe or its Affiliates, User must notify Stripe without undue delay, which will be no later than 48 hours, after becoming aware of the Data Incident.","evidenceSide":"new","relatedKpi":"kpiBreachNotification","anchorStatus":"verified"},{"icon":"alert","textEn":"Restrictions on using Stripe Output Data for automated decisions or AI training.","textIt":"Restrizioni sull'uso dei dati di output di Stripe per decisioni automatizzate o addestramento AI.","deltaScore":2,"evidenceQuote":"User must not use Stripe Output Data: (a) as the sole input into User’s decision making process (e.g., automated decision making, profiling) about engaging, ceasing to engage, or refraining from engaging in a business relationship with any","evidenceSide":"new","relatedKpi":"kpiAiTrainingOptOut","anchorStatus":"verified"}],"explanationBoundary":"Score reasons and deltaScore values are stored AI-assisted screening outputs. Verified anchors confirm only that the quoted passage occurs in the named snapshot; they do not prove the interpretation."},"governance":{"mappedFrameworks":[{"id":"eu-ai-act","name":"EU AI Act","referenceVersion":"Official Journal text, 2024","referenceUrl":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","reviewQuestion":"Which recorded policy statements may be relevant to transparency, automated decisions, data use and human oversight review?"},{"id":"iso-42001","name":"ISO/IEC 42001","referenceVersion":"ISO/IEC 42001:2023 overview","referenceUrl":"https://www.iso.org/standard/42001","reviewQuestion":"Which recorded policy statements may inform an AI management-system review of transparency, risk oversight and independent assurance?"},{"id":"nist-ai-rmf","name":"NIST AI RMF","referenceVersion":"AI RMF 1.0; NIST revision in progress, checked 2026-07-29","referenceUrl":"https://www.nist.gov/itl/ai-risk-management-framework","reviewQuestion":"Which recorded policy statements may support Govern, Map, Measure or Manage review questions?"},{"id":"oecd-ai-principles","name":"OECD AI Principles","referenceVersion":"OECD AI Principles, updated 2024","referenceUrl":"https://oecd.ai/en/ai-principles","reviewQuestion":"Which recorded policy statements may be relevant to transparency, fairness, accountability and user agency review?"}],"boundary":"Mappings identify review relevance between recorded PolicyWatcher KPI fields and framework topics. They are not legal interpretations, conformity assessments, certifications or compliance verdicts."},"reviewQuestions":["Does the original Services Agreement source still match the recorded public snapshot version 2?","Do the cited source passages support each displayed reason, KPI value and regional note?","Which advisory framework topics require specialist legal, risk or governance review for this use case?","Has a later public change superseded this packet before it is reused in a decision or publication?"],"links":{"change":"https://policywatcher.online/change/e71b438b-cf6c-4e7c-b544-d9ac9bec97c9","evidence":"https://policywatcher.online/evidence/e71b438b-cf6c-4e7c-b544-d9ac9bec97c9","json":"https://policywatcher.online/api/evidence-packet/e71b438b-cf6c-4e7c-b544-d9ac9bec97c9?format=json","pdf":"https://policywatcher.online/api/evidence-packet/e71b438b-cf6c-4e7c-b544-d9ac9bec97c9?format=pdf"},"evidencePacketDigest":"7cbf0b6d57a176fc9680276a9b03065a7c62c1be85fd5d5a6d2f91df9bd463d8","boundary":"This packet records PolicyWatcher evidence and AI-assisted screening for one public change. It is not legal advice, a compliance verdict, a certification, or proof that the external source remains unchanged."}],"reviewChecklist":["Confirm that each selected record is relevant to the intended review scope.","Open the provider source and exact Evidence Packet before relying on a summary.","Keep record-level limitations and advisory framework boundaries attached when reusing the bundle.","Check whether a later public change supersedes any selected record."],"boundary":"This collection groups selected public PolicyWatcher evidence records. It is not exhaustive market coverage, persistent team collaboration, legal advice, a compliance assessment or proof that an external source remains unchanged.","collectionId":"pwc_899a2927bb5e446f","contentDigest":"899a2927bb5e446f3e6670c8dcb5e3f25646d37ebafe67485a028d64c725635c"}