Meta
Llama 4 (Scout / Maverick)
v4 · open-weights · Released April 5, 2025
Updated August 8, 2026
A federal lawsuit alleging Meta's internal AI system selected approximately 8,000 employees for layoffs without adequate human oversight introduces reputational and regulatory risk for enterprise Meta AI deployments. While the suit targets an internal system rather than Llama 4 directly, it signals governance exposure that warrants a cautionary flag.
Enterprise guidance
Llama 4 open weights can be downloaded from Meta's website, Hugging Face, and major cloud providers. Self-hosting eliminates third-party data residency risk entirely — all inference stays in your own infrastructure. Before deploying, verify your organization falls under the Llama 4 Community License: commercial use is permitted for most enterprises, but organizations whose products exceed 700 million monthly active users require a separate commercial license from Meta.
Data handling
Default data retention
N/A for self-hosted — data never leaves your infrastructure
Zero-retention available
YesVia: Inherent to self-hosting — no data transmitted to Meta
API data used for training
NoSelf-hosted: your data never reaches Meta. Third-party hosted inference providers (Groq, Together AI, etc.) have their own data retention policies.
GDPR Data Processing Agreement
Not availableHIPAA Business Associate Agreement
Not availableNot offered by Meta. Arrange a BAA directly with your cloud infrastructure provider (AWS, Azure, GCP).
Data residency options
Fully configurable — runs in your own infrastructure
Vendor compliance certifications
Key use restrictions
- —Llama 4 Community License: commercial use permitted for most organizations
- —Products exceeding 700 million monthly active users require a separate commercial license from Meta
- —Meta's Acceptable Use Policy prohibits: CSAM, mass casualty weapons content, election interference, cyberweapons
- —Attribution required in commercial products or services built on Llama 4
Safety documentation
Llama 4 model card and Responsible Use Guide published by Meta. Llama Guard 4 safety classifier available to integrate into your inference pipeline. Meta's Acceptable Use Policy applies to all Llama deployments regardless of hosting.
Safety documentation →Related governance resources
Governance controls
Self-Hosted Open-Weight AI Model Governance
Set intake rules for model weights downloaded from public repositories and hosted internally. Check integrity, licensing, and safety before deployment. Manage ongoing updates separately from vendor-hosted AI procurement.
AI Procurement Risk Assessment
Assess technical, legal, privacy, and operational risks before approving an AI system or service purchase. Document the findings.
AI System Risk Classification
Assign every AI system a risk tier that determines the oversight requirements, review frequency, and documentation standards applied to it.
AI System Intake and Approval Workflow
Use a standard intake process before new AI systems enter the organization. Record use case, data classification, risk tier, and ownership. Route approvals across relevant functions and retain GRC records.
AI Tool and Plugin Supply Chain Risk Assessment
Assess supply-chain risks from agents’ third-party tools, plugins, and extensions. Include AI-generated code committed to production repositories. Apply software supply-chain controls to these dependencies.
Playbook guides
How do we ensure third-party AI vendors meet our standards?
Review AI vendors for model transparency, data handling, bias testing, and contractual liability for their outputs.
How do we inventory and classify AI systems by risk level?
Catalog your AI tools, including shadow AI. Assess each system’s data sensitivity, decision impact, and regulatory exposure.
How do we maintain data privacy compliance when using AI?
Review training data sources, data minimization, cross-border transfers, and applicable explanation duties under GDPR and CCPA.
Status history
August 8, 2026· green to yellow
The federal lawsuit (qkblMohXdIskjMBOwR8M) does not target Llama 4 directly but creates a vendor-governance risk environment consistent with YELLOW criteria, particularly regarding adversarial vendor-government and litigation-adjacent dynamics. Enterprise customers in regulated industries may face heightened scrutiny when deploying Meta AI products during active federal proceedings against the vendor.
