← All Evidentiary Developments
EVIDE › Evidentiary Developments › WhatsApp Third-Party Agents: Where Does the Evidentiary Record of User Authority Continue?
Current Development Agentic AI Published 2026-09-05

WhatsApp Third-Party Agents: Where Does the Evidentiary Record of User Authority Continue?

On August 25, 2026, WhatsApp's "Terms of Service for Use of Third Party Agents" ("Agent Terms") were last updated. The document governs third-party AI agents, bots, and automated services ("3P Agents") that WhatsApp users can connect to their account through a technical platform ("3P Platform") provided by WhatsApp. Users may connect up to five 3P Agents at any time. 3P Agents are, per the Terms, "built, owned, and operated by independent third-parties" ("Agent Providers") - not by WhatsApp. WhatsApp states it "does not own, build, operate, control, or direct any 3P Agent," and does not "endorse, verify, guarantee, or assume any responsibility for any 3P Agent, its content, outputs, conduct." The Terms allocate responsibility explicitly. Agent Providers are stated to be solely responsible for, among other things, "(a) the content and accuracy of any outputs or responses generated by their 3P Agents" and "(b) any actions taken by their 3P Agents on behalf of or at the direction of users." This mechanism is distinct from two other WhatsApp/Meta products: Meta AI, governed by a separate Meta AI Terms of Service and explicitly excluded from these Agent Terms; and Meta Business Agent / Meta Business Agent Platform, a different product (announced June 3, 2026) through which a business deploys its own agent to respond to its own customers - a business-to-customer relationship, not the personal, user-connects-a-third-party-agent relationship these Agent Terms govern. Communications between a user and a 3P Agent are not end-to-end encrypted; to operate the 3P Agent, the Agent Provider "receives, processes, and stores" those messages in unencrypted form.

What this is not. This is not a report of a WhatsApp product failure or a documented incident. No specific 3P Agent action is known to have exceeded a user's direction. This is not a claim that WhatsApp's Agent Terms are legally deficient, non-compliant with any regulation, or inadequate for their stated purpose. It is not the Meta Business Agent Platform, and should not be conflated with it. As of this writing, no specific Agent Provider has been publicly and verifiably confirmed to be operating under this specific mechanism - the provider ecosystem/deployment remains emerging, and that absence of confirmed providers is a statement about the current state of research, not evidence that no provider exists or is preparing to launch.

This is a real, currently published set of platform terms, issued by a platform operating at a scale of billions of users, that allocates responsibility for agent actions to a specific, named category of party (Agent Providers) using language directly comparable to the abstract question EQ-001 already examines: a human gives an instruction, an agent may act "on behalf of or at the direction of" that human, and a form of accountability is assigned by category. WhatsApp's Agent Terms are a live, documented instance of exactly that structure, not a hypothetical construction.

When a WhatsApp user directs a connected 3P Agent to take a specific action, and the Agent Provider is contractually allocated responsibility for "any actions taken... on behalf of or at the direction of users," what independently examinable record exists - or would need to exist - to show that a subsequent agent action remained within the scope of what that specific user actually directed at that specific moment?

  • 3P Agents are built, owned, and operated by Agent Providers, not WhatsApp.
  • WhatsApp provides only the 3P Platform enabling connection; it disclaims ownership, control, or direction of any 3P Agent.
  • Agent Providers are stated to be solely responsible for the content/accuracy of 3P Agent outputs and for "any actions taken by their 3P Agents on behalf of or at the direction of users," among other enumerated items.
  • A user may connect up to five 3P Agents at any time.
  • Disputes regarding a 3P Agent's content, outputs, or actions are directed to the Agent Provider; WhatsApp states it has no obligation to mediate such disputes.
  • Conversations with 3P Agents are not end-to-end encrypted; the Agent Provider receives, processes, and stores them in unencrypted form.
  • The mechanism is explicitly separate from Meta AI and from Meta Business Agent Platform.

The reviewed Terms do not specify how the scope of authority recognized for a particular user-directed action is preserved across the subsequent agent/action boundary. They do not specify what technical or evidentiary record, if any, an Agent Provider must create or retain connecting a specific user instruction to a specific subsequent agent action. They do not specify how a dispute over whether an action exceeded a user's direction would be evidenced, beyond directing that dispute to the Agent Provider under the Agent Provider's own terms. This is not established to mean no such record exists anywhere, or that no Agent Provider maintains one - only that these specific Terms do not specify one.

The boundary sits at the moment a 3P Agent acts "on behalf of or at the direction of" a user for one specific, directed action, as distinct from whatever the agent subsequently does - further tool calls, further messages, a chain of downstream effects - that may or may not remain within that original direction's scope. This is the same human-instruction-to-agent-action boundary EQ-001 already examines in general terms, now instantiated in WhatsApp's published Terms of Service for Use of Third Party Agents.

For an Agent Provider operating under these Terms, an evidentiary layer would need to be able to preserve, at minimum: a declared reference to the specific user instruction at the moment it was given; a declared execution context identifying which agent, session, or run handled it; a material checkpoint at the moment the agent transitions from receiving the instruction to invoking a specific external action; any escalation or human-intervention state, if the action required confirmation or was overridden; the resulting declared state, i.e. what the agent reports having done; and a declared reference to any external evidence (chat transcript, action log) the Agent Provider already holds - not the artifact itself, but a reference to it.

EVIDE could offer an Agent Provider operating under these Terms a complementary external evidentiary layer, not a replacement for the Agent Provider's own logs or audit systems: preserving declared execution identity, a declared authority/perimeter reference for a given interaction, material checkpoints at tool/action transitions, declared escalation or human-intervention states, the resulting declared state, and declared references to external evidence. None of these elements are known to be observable in any specific WhatsApp 3P Agent implementation today - this describes what an Agent Provider could choose to preserve, not what any provider currently does preserve.

  • Whether any specific 3P Agent action exceeded the scope of a user's direction.
  • Whether an Agent Provider is in compliance with WhatsApp's Agent Terms or any applicable law.
  • Legal liability under the Agent Terms.
  • The internal reasoning or decision process of any 3P Agent.
  • Whether WhatsApp's allocation of responsibility to Agent Providers is itself adequate, sufficient, or complete.

Are WhatsApp Third-Party Agents the same as Meta Business Agent?

No - different products, different relationships (personal user-to-third-party-agent vs. business-to-its-own-customers).

Does WhatsApp's Agent Terms say who is responsible if a 3P Agent acts incorrectly?

Yes, in general terms - Agent Providers are stated to be solely responsible for actions taken on behalf of or at the direction of users, among other items.

Does the document explain how a specific user instruction is tracked through an agent's subsequent actions?

No. The reviewed Terms do not specify such a mechanism. This article examines the resulting evidentiary question without assuming that no such mechanism exists elsewhere.

#WhatsApp #Third-PartyAgents #Authorization #EvidentiaryContinuity
← All Evidentiary Developments