If you run an AI agent on your WhatsApp number, or you are about to, you have probably seen a headline about WhatsApp "banning AI" in 2026 and wondered whether that includes you. The short answer: almost certainly not. The policy change was aimed at a specific kind of product, and the AI that answers your own customers about your own business is exactly what WhatsApp still wants on the platform.
This is a calm explainer, not legal advice. It covers what changed, what is off-limits, what remains allowed, what a compliant business AI agent should do, how Meta's own Business Agent fits in, and a short self-check. Where your situation is unusual, check Meta's current terms; they change more often than blog posts do.
What changed in WhatsApp's AI policy, and when?
Meta updated the terms of the WhatsApp Business Platform (the API) in two steps:
October 15, 2025: new API accounts started under the updated terms.
January 15, 2026: the same terms applied to every existing account.
The change restricts what respond.io, in its explainer on the WhatsApp general-purpose AI policy, describes as "AI Providers": companies whose AI system is the product itself rather than a feature of a business, and who used WhatsApp as a distribution channel for an open-ended assistant.
The same piece gives the two reasons Meta had. First, open-ended assistants generated very large message volumes, which strained the platform. Second, WhatsApp's business model is built around conversations that fit a category (marketing, utility, authentication, service); an assistant that chats about the weather and then summarises a PDF does not fit any of them, so the traffic could not be priced.
Nothing in the change touched the rules business messaging already lived under: the 24-hour customer service window, templates outside it, and opt-in before you contact someone. That is where most of the practical compliance work for an AI agent sits.
What exactly is no longer allowed?
The banned category is the general-purpose AI assistant: a service that answers any question from anyone, with no connection to a particular business's products, customers or operations. The line respond.io draws from Meta's definition is the "core product versus supporting feature" test:
If the AI is the product, and WhatsApp is just the channel you distribute it through, you are an AI provider and the platform is no longer available for that.
If the AI is a supporting feature of a business that sells something else (furniture, dental appointments, software subscriptions, insurance), it is business messaging, and it is allowed.
In practice, three signs put a number on the wrong side of the line:
Anyone can message it and ask about anything; there is no "your business" it belongs to.
The number exists to showcase or sell access to the model itself.
There is no human team behind it to escalate to, because there is no business behind it, only a model.
What can a business still do with AI on WhatsApp?
Everything a business has always used the API for stays allowed, with AI doing the answering:
Customer support. "Do you deliver to Cali?", "what is your return policy?", "my order arrived damaged". An AI agent answers from your policies and hands the damaged-order case to a person.
Bookings and appointments. A clinic's AI agent offers real slots, confirms the appointment and sends the reminder.
Order tracking. A store's AI agent looks up an order number and replies with the status.
Notifications. Shipping updates, payment confirmations and appointment reminders sent as utility templates to customers who opted in.
Sales and lead qualification. An AI agent asks a new lead the first four questions, recommends a product from your catalog and books the call with a salesperson.
Authentication. One-time codes sent as authentication templates.
Every item has one thing in common: the conversation is about one business and its customers. The format of the AI (a scripted flow, a language model, or a mix) matters less than what the conversation is for.
What should a compliant business AI agent do?
Five habits keep an AI agent well inside the lines. They also happen to make it a better agent.
It answers about your business, from your material. Prices, hours, policies, catalog, order data. If a customer asks it to write a poem, a well-scoped agent politely steers back to what it is there for.
It can always reach a person. WhatsApp's Business Messaging Policy is explicit: "You may use automation when responding during the 24-hour window, but must also have available prompt, clear, and direct escalation paths." The list of acceptable paths starts with an in-chat transfer to a human agent. Our post on AI-to-human handoff rules lists the triggers that should always hand off.
It respects the 24-hour window and uses templates outside it. The same policy says: "Outside the 24-hour customer service window, you may only send messages via approved Message Templates." An AI agent replying inside the window is free-form; anything it sends to a customer who has gone quiet for more than a day has to be an approved template. Since October 1, 2026 Meta also bills free-form replies inside the window per message after the first 1,000 per phone number per month; the details are in Meta's pricing documentation for non-template messages.
It only reaches out to people who opted in. For outbound messages (campaigns, reminders, re-engagement), the policy requires that the recipient gave you their number and "opt-in permission ... confirming that they wish to receive subsequent messages". The AI agent can send the reminder, but the consent has to exist first, and opt-out requests have to be honoured.
It has no "ask me anything" mode. Connecting a capable model to your number and leaving it open-ended, "to be helpful", is how a business AI agent starts to look like a general-purpose assistant. Scope it to your knowledge base and your workflows.
How does this interact with Meta's own Business Agent?
In June 2026 Meta launched its Business Agent inside the WhatsApp Business app, Messenger and Instagram. It learns from your Facebook Page, past chats, website and catalog, and answers your customers about your business. It is allowed under the 2026 policy for the same reason your own AI agent on the API is allowed, and it is subject to the same expectations: answer about the business, escalate when it cannot.
The difference between the two is not policy, it is structure. The Business Agent is built for one phone and transfers a chat to whoever holds it; an AI agent on the API can hand the chat to a team, assign it to a person and leave a record. We cover that in Meta Business Agent explained.
A self-check for your WhatsApp number
If every answer is "yes", you are doing what the policy describes as business messaging.
Does the AI agent only answer questions about our business, our products and our customers' own orders or appointments?
Does it decline, or redirect, when someone asks it something unrelated to the business?
Can a customer reach a person from inside the chat, and does that happen promptly?
Does every outbound message outside the 24-hour window go out as an approved template?
Did every person we message proactively opt in, and can they opt out?
Is there a team behind the number that can take over a conversation and see its history?
If any answer is "no", it is usually a scoping or routing fix, not a reason to turn the AI off. If your case is genuinely unusual, check Meta's current terms before launching.
How this works in HellouOne
HellouOne is an AI agent and team inbox on the WhatsApp Business API, and the five habits above are how it is built rather than settings you have to remember.
Scoped to your knowledge base. The AI agent answers by searching your own business information: prices, policies, hours, documents you upload, your catalog through connectors like Shopify or WooCommerce. There is no general "ask me anything" mode, so it stays a supporting feature of your business. The WhatsApp AI agent guide explains how it is trained.
Handover areas are the escalation path. You describe in plain words when the AI agent should step aside (a complaint, a refund, a question it cannot answer, a customer who asks for a person) and which team takes over. The in-chat transfer the policy asks for is a built-in workflow, and the person who picks up sees the full history. The Human + AI solution shows the two working side by side.
Templates and campaigns with consent. Free-form AI replies stay inside the 24-hour window; outbound campaigns and reminders use approved templates, sent to contacts who opted in, with a cost estimator before you send.
0% markup on Meta's fees. Template and per-message charges are passed through at cost. Starter is $49 a month with 2,000 AI messages included, and the 7-day trial needs no card; see pricing.
Where does this leave you?
The 2026 policy drew a line between an AI product that uses WhatsApp as a channel and a business that uses AI to serve its customers. If your AI agent answers about your business, hands off to a person, respects the window and templates, and only reaches out with consent, it is on the right side of that line. Keep it scoped, keep a team behind it, and check Meta's current terms when your setup is out of the ordinary.





















