Figma AI
medium riskGenerative AI Design Toolsfigma.comverified 2026-07-27profile 100% complete
Data-handling profile
- Trains on input
- Yes, on the consumer tier (enterprise tier excluded)
- Retention
- Content is stored as long as the account is active or until deleted by the user; for enterprise, specific data retention policies can be configured via admin controls.
- Data region
- United States (primary), with options for enterprise data residency in specific regions (e.g., AWS regions)
- Certifications
- SOC 2 Type IISOC 3ISO/IEC 27001ISO/IEC 27018ISO/IEC 27017FedRAMP (Authorized at Moderate Impact Level)
- DPA available
- Yes
- Breach history
- No major public data breaches linked to AI-specific features; Figma has maintained a clean record regarding unauthorized access to user-generated AI content.
- EU AI Act
- Figma is actively monitoring the EU AI Act; as a provider of generative AI features, they are implementing transparency measures and risk assessment documentation to comply with future requirements.
By plan and surface
Vendor-level answers are often wrong for a specific tier. These are the precise claims, each with the verbatim sentence we relied on.
| Plan | Surface | Trains | Opt-out default |
|---|---|---|---|
| free | web | all_tiers | opted_in |
| pro | web | all_tiers | opted_in |
- free/web: “By default, content training is turned on for Starter teams.”
- pro/web: “By default, content training is turned on for Professional teams.”
Sources
- https://help.figma.com/hc/en-us/articles/17725942479127
- https://www.figma.com/security
- https://www.figma.com/legal/privacy/
- https://help.figma.com/hc/en-us/articles/21325608674967-Figma-AI-FAQlink no longer resolves
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes. 1 of these 4 links no longer resolve. We record what we relied on rather than deleting it, so the trail stays auditable — but a struck-through source cannot be re-checked today.
Control mapping
Obligations this vendor triggers, each attributable to the fact it rests on — for your supplier register, not a compliance determination.
- EU AI Act Art. 50 — Transparency obligations for AI systemsattention
trains_on_input = all_tiers. Inputs may be reused for model training — users interacting with this system need to be informed accordingly.
- EU AI Act Art. 26 — Obligations of deployers of high-risk AI systemsapplies
Applies to your organisation as deployer, independent of vendor. Assign human oversight, keep logs, and monitor operation where this tool is used in a high-risk context (Annex III duties apply from 2 Dec 2027).
- ISO/IEC 27001 A.5.19 — Information security in supplier relationshipsapplies
Figma AI processes organisational data as a supplier. Include this vendor in the supplier register and risk assessment.
- ISO/IEC 27001 A.5.20 — Addressing information security within supplier agreementsok
dpa_available = true. A data processing agreement is available and should be executed.
- ISO/IEC 27001 A.5.23 — Information security for use of cloud servicesattention
Cloud AI service; trains_on_input = all_tiers. Data submitted to this cloud service may be retained or reused — define acceptable-use rules for it.
- ISO/IEC 42001 A.10.3 — Suppliers of AI systems and servicesapplies
certifications: SOC 2 Type II, SOC 3, ISO/IEC 27001, ISO/IEC 27018, ISO/IEC 27017, FedRAMP (Authorized at Moderate Impact Level) No AI-management certification identified; assurance must come from your own supplier assessment.
- GDPR Art. 44–49 — International transfers of personal dataattention
data_region = United States (primary), with options for enterprise data residency in specific regions (e.g., AWS regions). Processing occurs outside the EU/EEA — a transfer mechanism (SCCs or adequacy) must be in place.
- NIS2 Art. 21(2)(d) — Supply chain securityapplies
AI vendor forms part of your ICT supply chain. In scope for entities covered by NIS2; include in supply-chain risk measures.
- DORA Art. 28 — General principles for ICT third-party riskapplies
AI vendor is an ICT third-party service provider. For financial entities: register of information and contractual requirements apply.
Change history
No material changes recorded since monitoring began.