Not just AI, it applies to any form of automated decision making (
https://gdpr-info.eu/art-22-gdpr/):
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
But there's the usual "explicit consent" caveat, which Meta will argue they have because the user (as in: habitual consumer of harmful substances) has agreed to it in their TOS.
But then there is also a transparency requirement on automated decision making (https://gdpr-info.eu/art-15-gdpr/):
[data subject has access to] the existence of automated decision-making [and] meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
This explicitly says that the user has the right to know what logic is employed by automated decision making systems.