Intelligence

The Appeal Ended Before a Human Review Began

CBC reports that a Toronto user's Facebook and Instagram accounts were disabled and that repeated support attempts did not produce an effective human escalation, even after paid Meta Verified support. The public evidence does not establish that AI made the original disablement decision. It does establish a consequential state with an apparently ineffective recovery path.

Event analysed: . This analysis was published on 1 October 2026.

When an automated service can enforce or maintain a high impact account state, what authority must exist after the user disputes that state?

A separate, reachable review and restoration authority must exist. The reporting does not establish whether AI made the original account disablement decision, so this record does not claim that it did. What it does establish is the recovery problem: a user disputed a consequential state, repeatedly encountered automated support, and did not obtain an effective human review path. Meta had stated earlier in 2026 that humans remain involved in the most consequential decisions and specifically named appeals of account disablement. Moona therefore treats review authority, override authority and restoration authority as separate from the authority that imposed or maintained the original state.

The important fact in this case is narrower than the headline can make it sound. Public reporting does not establish that an AI model itself made the first decision to disable the accounts. This record therefore does not describe the event as an AI deleting an account. It describes a consequential account state and the recovery path available after the affected person disputed it.

CBC reports that Jasmine Ault of Toronto lost access to Facebook and Instagram on 24 September 2026 and that repeated attempts to obtain support did not lead to an effective human escalation. The reporting states that even support associated with a paid Meta Verified subscription remained automated from the user's perspective. That makes the authority question visible regardless of what mechanism produced the original disablement.

Authority to impose a state is not authority to adjudicate its appeal

A system can legitimately have authority to enforce one decision and still lack authority to resolve a dispute about that decision. Review authority, override authority and restoration authority are therefore separate roles. Moona now models them as separate recovery requirements rather than assuming that whatever system produced the state is also the final judge of whether it should persist.

High impact states need a legitimate restoration path

Account disablement can remove access to years of content, relationships and identity dependent services. Where the impact is high, a recovery mechanism is part of the control architecture, not an optional customer experience layer. A terminal automated loop with no reachable reviewer can make a reversible technical state practically irreversible for the affected person.

Meta stated in March 2026 that AI would help scale support and safety while humans would remain involved in the most consequential decisions, explicitly giving appeals of account disablement as an example. This record does not infer from one reported case that Meta has no human review process in general. It records the narrower gap between that stated principle and the recovery path the reported user says she actually reached.

Recoverability now changes Moona's impact assessment

Moona now asks not only what an action changes but how difficult it is to reverse, whether external copies or downstream effects can survive reversal, whether rollback evidence exists, and whether an authorized reviewer can restore the prior state. Consequential automation without reachable recovery is therefore treated as incomplete governance even when the initial enforcement action was technically valid.

Sources

This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.

[2]
Boosting Your Support and Safety on Meta's Apps With AI
Meta · 19 March 2026 · Company announcement

Protocol evidence

This record does not assess these architectures. The connection runs through the Risk Registry requirement each one bears on, and these published authority architectures are what the evidence says about that requirement.

Protocol evidence related through AEW-009 Oversight without the ability to stop

  • Supports requirement

    AC2, the Agentic Communication and Control Protocol

    Algorand Foundation, with Pera Wallet building the reference AC2 Wallet on Rocca infrastructure

    Requirement Every signing operation currently requires explicit, uncached human approval

    AC2 currently requires explicit, uncached human approval for every signing operation, a blocking control before the effect rather than observation after it, which is the corrective for oversight that can watch but not stop.

    This record is the cited evidence for this relationship.

    View protocol evidence

  • Supports requirement

    Agent Control Standard (ACS)

    OWASP GenAI Security Project, originally Zenity

    Requirement Ask and defer are a normatively defined, authenticated human, agent or service approval mechanism

    ACS's ask and defer dispositions route to an authenticated human, agent or service Approver before a guarded step proceeds, a blocking control before the effect rather than observation after it, which is the corrective for oversight that can watch but not stop.

    View protocol evidence

  • Reveals bypass

    Agent Control Standard (ACS)

    OWASP GenAI Security Project, originally Zenity

    Requirement The default posture when no decision arrives in time is to proceed, not to block

    ACS's own default posture when no decision arrives in time is to proceed rather than block, stated in the specification's own words as trading enforcement for availability under disruption, since an adversary who can disrupt the channel converts control into audit. Under exactly the condition a stop would matter most, a disrupted or unreachable Guardian, the same specification that elsewhere requires a received decision to be honored reverts by default to the oversight without the ability to stop this weakness describes.

    View protocol evidence

Related Intelligence

All Intelligence Records →