Back to blog Compliance

AI Tool Compliance Audit

15 AI tools across image, video, audio, and text generation, evaluating training opt-out, commercial licensing, privacy defaults, and data safety for professional client work.

Compliance5 Apr 2026WonderLoop
At a glance

Quick-Reference Comparison

Safe to Use
ToolMin. PlanCommercialTraining Opt-OutKey Note
Freepik AIEssential ~€5.75/moAutoAutoNo training by Freepik or third-party providers. Private by default.
Artlist AIAI Starter $15.99/moAutoAutoISO 27001 certified. No training on inputs/outputs.
KreaBusiness $40/moBusiness+Business+Real-time generation canvas. 50+ models incl. Veo 3, Sora, Kling, Flux.
Figma WeaveAny paid planAutoAutoStick to "Verified" badge models only.
Safe with Settings Changes
ToolMin. PlanCommercialTraining Opt-OutKey Note
Claude MaxMax $100/moToggleToggleSettings → Privacy → toggle OFF. Use incognito for sensitive content.
ElevenLabsStarter $5/moToggleToggleAccount Settings → Terms & Privacy → Data use → OFF before generating.
HeyGenCreator+ $24/moEmailEmailEmail to opt out. SOC 2 Type II certified.
OpenRouterPay-per-useModel-dep.Default offVerify prompt logging is OFF. Enable "no training" provider filter.
Use with Caution
ToolMin. PlanCommercialTraining Opt-OutKey Note
Utopai PAICredits $100/10KUnclearUnclearBuilt for commercial use with IP provenance. Too new — no formal ToS published yet.
fal.ai~$0.025/imgModel-dep.NoneAnonymized data may train models. Generated URLs publicly accessible.
RunwayStandard $12/moEnterprise onlyEnterprise onlyAll content used for training. No opt-out on consumer plans. SOC 2 certified.
Luma LabsPlus $29.99/moPlus+Enterprise onlyPlus/Unlimited: limited training rights. No consumer opt-out.
SunoPro $10/moPro+NonePerpetual license on everything. You don't own the output. Never put client info in prompts.
Do Not Use for Client Work
ToolMin. PlanCommercialTraining Opt-OutKey Note
Kling AI directN/AAmbiguousEmail onlyContent deemed "non-proprietary." China data residency. Use via Freepik/Artlist instead.
Dreamina / CapCutN/AByteDance trains on all content. Use Seedance via Freepik/Artlist instead.
Google Veo 3.1N/A (Pre-GA)Vertex AIPre-GA = evaluation only. Use via Freepik instead.
The shortcut

The Aggregator Shield

Freepik's Protections

"Freepik doesn't use anything you create or upload to train our AI tools — and the same goes for our third-party providers."

All paid plans include commercial licensing. Content is private by default. Enterprise plans add IP indemnification.

Artlist's Protections

"Artlist does not use your prompts, inputs, or outputs to train or fine-tune AI models."

ISO 27001 certified, GDPR compliant. Commercial rights on all paid plans with AI access. Business plans include indemnification.

The Restaurant Analogy

Think of it like buying food from a restaurant vs. foraging in the wild. The restaurant has its own food safety standards, sourcing agreements, and liability — regardless of where the ingredients came from.

One Important Caveat

Aggregator protections are contractual, not technical. If Freepik or Artlist breached their provider agreements, there could be a gap. Enterprise plans with MSAs provide the strongest legal footing.

Tool by tool

Detailed Findings

Freepik AI

Never uses user content for AI training. All generated content is private by default. Paid plans start at Essential (~€5.75/mo). February 2025 ToS update assigns all rights in AI outputs to paid subscribers.

Available models include Nano Banana Pro, Google Imagen, Z-image Flux, Seedream, Magnific (upscaling), plus 36+ video models including Kling 3.0, Veo 3.1, Runway Gen-4.5, Seedance 2, Sora 2. IP indemnification only available on Enterprise plans.

Artlist AI

Does not use prompts, inputs, or outputs to train AI models. ISO 27001 certified and GDPR compliant. Plans start at AI Starter ($15.99/mo). Artlist Max ($39.99/mo) includes all creative assets plus AI tools. License explicitly prohibits using stock assets to train AI models.

Figma Weave

"We don't use your images or prompts to train our platform." A "Verified by Figma" badge distinguishes models where Figma holds direct contractual no-training agreements. All plans include commercial licensing.

Claude Max

Anthropic reversed its earlier no-training policy on August 28, 2025. All consumer plans now present a consent flow where the "Improve Claude for everyone" toggle defaults to ON. Users who accept with training enabled face 5-year data retention.

Action required: Settings → Privacy → "Improve Claude for everyone" → OFF

ElevenLabs

A training opt-out toggle exists at Account Settings → Terms and Privacy → Data use. Not retroactive — toggle before generating content for client projects. Custom voices are private by default. Commercial use on all paid plans (Starter at $5/mo+).

HeyGen

SOC 2 Type II certified. Videos private by default. Enterprise customers automatically excluded from AI training; others can opt out by email. Commercial use on all plans including Free.

OpenRouter

Prompts and completions not logged or stored by default. Account-level setting restricts routing to non-training providers. Includes a mutual confidentiality clause (rare).

Note: Accounts created Nov 14, 2023 – Apr 3, 2025: prompt logging may be ON by default. Verify immediately.

Utopai PAI

Launched March 5, 2026. Credit-based ($100 for 10,000 credits). Built for professional filmmaking with IP provenance and audit trails. Blocks copyrighted IP, protected characters, and public figure likenesses. SynthID watermarks on all outputs.

Limitation: No formal ToS published yet. Contact directly for licensing and confidentiality terms before client use.

fal.ai

Pay-per-use API (~$0.025/image). Anonymized/aggregated data may be used for AI model development with no explicit opt-out. Generated media URLs are publicly accessible until they expire. No confidentiality clause.

Runway

All inputs/outputs used for training on Standard/Pro/Unlimited plans. No opt-out for non-Enterprise. SOC 2 Type II certified. Content private by default. Commercial use on all plans. You retain ownership.

Luma Labs

Free/Lite: broad rights including public display and training. Plus/Unlimited: limited rights, training still possible. Enterprise: no training, full privacy. Commercial use only on Plus ($29.99/mo) and above.

Suno

Perpetual, irrevocable, sublicensable, royalty-free license to all content for model training. No opt-out. Songs "Link-Only" by default, not fully private. Commercial use requires Pro ($10/mo) or Premier ($30/mo).

Kling AI (direct)

ToS declares all user content "non-proprietary and non-confidential." This alone disqualifies direct use for NDA-protected work. China data residency. Training opt-out only via email.

Dreamina / CapCut (direct)

ByteDance's privacy policy explicitly states content is used to train ML models with no opt-out. Base terms restrict to non-commercial use. Community gallery exposure risk.

Google Veo 3.1 (direct)

Despite plans up to $249.99/month, Veo 3.1 remains Pre-GA. Google's terms: "evaluation and testing purposes" only. No commercial use, no sharing output with third parties, no IP indemnification.

Do this

Compliance Checklist

Immediate Actions Required

  1. Claude: Settings → Privacy → "Improve Claude for everyone" → OFF
  2. ElevenLabs: Account Settings → Terms & Privacy → Data use → OFF
  3. HeyGen: Email requesting training opt-out
  4. OpenRouter: Verify prompt logging is OFF in account settings

Best Practices for Client Work

Protect Client Data

Never put client names, employee contacts, financial data, or NDA-covered material in any AI tool without a verified no-training guarantee.

Use Aggregators

Access Kling, Seedance, Seedream, and Veo 3.1 through Freepik or Artlist instead of directly. Same models, better governance.

Keep Prompts Generic

Use abstract descriptions rather than client-specific names or proprietary concepts wherever possible.

Download Immediately

Especially from platforms like fal.ai where generated URLs are publicly accessible to anyone with the link.

Document Your Stack

If a client requires AI transparency (increasingly common), keep a record of which tools and settings you used.

Paid Plans Only

Free tiers often grant broader rights to the platform. Always use paid accounts for professional client work.

WonderLoop · AI Tool Compliance Audit · April 2026

AI work you can deploy with legal peace of mind.

Book a call