AI Tool Compliance Audit
15 AI tools across image, video, audio, and text generation, evaluating training opt-out, commercial licensing, privacy defaults, and data safety for professional client work.
Quick-Reference Comparison
| Tool | Min. Plan | Commercial | Training Opt-Out | Key Note |
|---|---|---|---|---|
| Freepik AI | Essential ~€5.75/mo | Auto | Auto | No training by Freepik or third-party providers. Private by default. |
| Artlist AI | AI Starter $15.99/mo | Auto | Auto | ISO 27001 certified. No training on inputs/outputs. |
| Krea | Business $40/mo | Business+ | Business+ | Real-time generation canvas. 50+ models incl. Veo 3, Sora, Kling, Flux. |
| Figma Weave | Any paid plan | Auto | Auto | Stick to "Verified" badge models only. |
| Tool | Min. Plan | Commercial | Training Opt-Out | Key Note |
|---|---|---|---|---|
| Claude Max | Max $100/mo | Toggle | Toggle | Settings → Privacy → toggle OFF. Use incognito for sensitive content. |
| ElevenLabs | Starter $5/mo | Toggle | Toggle | Account Settings → Terms & Privacy → Data use → OFF before generating. |
| HeyGen | Creator+ $24/mo | Email to opt out. SOC 2 Type II certified. | ||
| OpenRouter | Pay-per-use | Model-dep. | Default off | Verify prompt logging is OFF. Enable "no training" provider filter. |
| Tool | Min. Plan | Commercial | Training Opt-Out | Key Note |
|---|---|---|---|---|
| Utopai PAI | Credits $100/10K | Unclear | Unclear | Built for commercial use with IP provenance. Too new — no formal ToS published yet. |
| fal.ai | ~$0.025/img | Model-dep. | None | Anonymized data may train models. Generated URLs publicly accessible. |
| Runway | Standard $12/mo | Enterprise only | Enterprise only | All content used for training. No opt-out on consumer plans. SOC 2 certified. |
| Luma Labs | Plus $29.99/mo | Plus+ | Enterprise only | Plus/Unlimited: limited training rights. No consumer opt-out. |
| Suno | Pro $10/mo | Pro+ | None | Perpetual license on everything. You don't own the output. Never put client info in prompts. |
| Tool | Min. Plan | Commercial | Training Opt-Out | Key Note |
|---|---|---|---|---|
| Kling AI direct | N/A | Ambiguous | Email only | Content deemed "non-proprietary." China data residency. Use via Freepik/Artlist instead. |
| Dreamina / CapCut | N/A | — | — | ByteDance trains on all content. Use Seedance via Freepik/Artlist instead. |
| Google Veo 3.1 | N/A (Pre-GA) | Vertex AI | — | Pre-GA = evaluation only. Use via Freepik instead. |
The Aggregator Shield
Freepik's Protections
"Freepik doesn't use anything you create or upload to train our AI tools — and the same goes for our third-party providers."
All paid plans include commercial licensing. Content is private by default. Enterprise plans add IP indemnification.
Artlist's Protections
"Artlist does not use your prompts, inputs, or outputs to train or fine-tune AI models."
ISO 27001 certified, GDPR compliant. Commercial rights on all paid plans with AI access. Business plans include indemnification.
The Restaurant Analogy
Think of it like buying food from a restaurant vs. foraging in the wild. The restaurant has its own food safety standards, sourcing agreements, and liability — regardless of where the ingredients came from.
One Important Caveat
Aggregator protections are contractual, not technical. If Freepik or Artlist breached their provider agreements, there could be a gap. Enterprise plans with MSAs provide the strongest legal footing.
Detailed Findings
Freepik AI
Never uses user content for AI training. All generated content is private by default. Paid plans start at Essential (~€5.75/mo). February 2025 ToS update assigns all rights in AI outputs to paid subscribers.
Available models include Nano Banana Pro, Google Imagen, Z-image Flux, Seedream, Magnific (upscaling), plus 36+ video models including Kling 3.0, Veo 3.1, Runway Gen-4.5, Seedance 2, Sora 2. IP indemnification only available on Enterprise plans.
Artlist AI
Does not use prompts, inputs, or outputs to train AI models. ISO 27001 certified and GDPR compliant. Plans start at AI Starter ($15.99/mo). Artlist Max ($39.99/mo) includes all creative assets plus AI tools. License explicitly prohibits using stock assets to train AI models.
Figma Weave
"We don't use your images or prompts to train our platform." A "Verified by Figma" badge distinguishes models where Figma holds direct contractual no-training agreements. All plans include commercial licensing.
Claude Max
Anthropic reversed its earlier no-training policy on August 28, 2025. All consumer plans now present a consent flow where the "Improve Claude for everyone" toggle defaults to ON. Users who accept with training enabled face 5-year data retention.
ElevenLabs
A training opt-out toggle exists at Account Settings → Terms and Privacy → Data use. Not retroactive — toggle before generating content for client projects. Custom voices are private by default. Commercial use on all paid plans (Starter at $5/mo+).
HeyGen
SOC 2 Type II certified. Videos private by default. Enterprise customers automatically excluded from AI training; others can opt out by email. Commercial use on all plans including Free.
OpenRouter
Prompts and completions not logged or stored by default. Account-level setting restricts routing to non-training providers. Includes a mutual confidentiality clause (rare).
Utopai PAI
Launched March 5, 2026. Credit-based ($100 for 10,000 credits). Built for professional filmmaking with IP provenance and audit trails. Blocks copyrighted IP, protected characters, and public figure likenesses. SynthID watermarks on all outputs.
fal.ai
Pay-per-use API (~$0.025/image). Anonymized/aggregated data may be used for AI model development with no explicit opt-out. Generated media URLs are publicly accessible until they expire. No confidentiality clause.
Runway
All inputs/outputs used for training on Standard/Pro/Unlimited plans. No opt-out for non-Enterprise. SOC 2 Type II certified. Content private by default. Commercial use on all plans. You retain ownership.
Luma Labs
Free/Lite: broad rights including public display and training. Plus/Unlimited: limited rights, training still possible. Enterprise: no training, full privacy. Commercial use only on Plus ($29.99/mo) and above.
Suno
Perpetual, irrevocable, sublicensable, royalty-free license to all content for model training. No opt-out. Songs "Link-Only" by default, not fully private. Commercial use requires Pro ($10/mo) or Premier ($30/mo).
Kling AI (direct)
ToS declares all user content "non-proprietary and non-confidential." This alone disqualifies direct use for NDA-protected work. China data residency. Training opt-out only via email.
Dreamina / CapCut (direct)
ByteDance's privacy policy explicitly states content is used to train ML models with no opt-out. Base terms restrict to non-commercial use. Community gallery exposure risk.
Google Veo 3.1 (direct)
Despite plans up to $249.99/month, Veo 3.1 remains Pre-GA. Google's terms: "evaluation and testing purposes" only. No commercial use, no sharing output with third parties, no IP indemnification.
Compliance Checklist
Immediate Actions Required
- Claude: Settings → Privacy → "Improve Claude for everyone" → OFF
- ElevenLabs: Account Settings → Terms & Privacy → Data use → OFF
- HeyGen: Email requesting training opt-out
- OpenRouter: Verify prompt logging is OFF in account settings
Best Practices for Client Work
Protect Client Data
Never put client names, employee contacts, financial data, or NDA-covered material in any AI tool without a verified no-training guarantee.
Use Aggregators
Access Kling, Seedance, Seedream, and Veo 3.1 through Freepik or Artlist instead of directly. Same models, better governance.
Keep Prompts Generic
Use abstract descriptions rather than client-specific names or proprietary concepts wherever possible.
Download Immediately
Especially from platforms like fal.ai where generated URLs are publicly accessible to anyone with the link.
Document Your Stack
If a client requires AI transparency (increasingly common), keep a record of which tools and settings you used.
Paid Plans Only
Free tiers often grant broader rights to the platform. Always use paid accounts for professional client work.