figma guide

Designing AI training opt-out and model data usage transparency UI in Figma: controls, notices, and enterprise policies

Design AI training opt-out UI in Figma with model data usage notices, workspace-level policies, content exclusion controls, and transparency panels for generative AI and ML products.

Published
Updated
Aug 09, 2026
Read time
8 min
Level
Intermediate

Quick answer

AI training opt-out UI tells users whether their content trains models, what is excluded by default, and how to change the setting at account or workspace level—before they paste sensitive data into a prompt. Design a first-use AI notice with training ON/OFF default by plan; a privacy settings panel with plain-language scopes (prompts, uploads, support tickets); and an admin policy console for enterprise “no training” guarantees. Start from the Figma guides hub and pair with privacy settings, automated decisions, consent admin, ROPA, and Dev Mode handoff.


Who this is for

  • Product designers shipping copilots, generative features, or ML-powered search where customer content may enter model pipelines.
  • Design system teams standardizing AI badges, “not used for training” chips, and enterprise lock icons across editor and admin surfaces.
  • Privacy and AI governance teams aligning with GDPR purpose limitation, EU AI Act transparency expectations, and enterprise DPAs that require contractual “no train” clauses—not a vague “we may improve our services” footer.

AI data governance hub (internal overview)

AIDataGovernanceHub — Acme AI Platform · 840 workspaces · 62% training opt-out on paid plans
├── Header: Training enabled 318 workspaces · Zero-retain 412 · Pending policy sync 6
├── Actions: [ Edit defaults ] [ Run exclusion audit ] [ Export transparency report ] [ DPA templates ]
├── Tabs: Policies · Opt-out ledger · Content scopes · Model routes · Retention · Incidents · Reports
├── Alert: WS-4421 Enterprise · DPA requires zero-retain · 3 users still on legacy "Improve AI" ON
├── Filters: Plan tier · Region · Policy template · Model vendor · Last changed
└── Link: [ROPA](/designing-records-of-processing-activities-and-data-mapping-ui-in-figma/) · [DPIA](/designing-privacy-impact-assessment-and-dpia-workflow-ui-in-figma/) · Trust center · Launch gates
SectionPurpose
PoliciesDefault training posture by plan, region, and contract
Opt-out ledgerImmutable user and admin changes with notice version
Content scopesWhat data classes can enter training pipelines
Model routesWhich vendors receive prompts; zero-retain vs fine-tune paths
RetentionPrompt logging TTL separate from training exclusion
IncidentsAccidental training inclusion or policy drift alerts

Verdict: AI transparency UI fails when “Improve the product” hides model training—users and enterprise buyers need scoped toggles and audit exports.


First-use AI notice (customer-facing)

AINotice — Acme Copilot uses AI · Before you continue
├── What AI does here: "Summarize docs, draft replies, and search your workspace"
├── How your data is used:
│   ├── Prompts and uploads may be processed by Acme models and subprocessors
│   ├── Training: OFF by default on your Pro plan · Your content is NOT used to train global models
│   └── Logging: Prompts retained 30 days for abuse detection · [Retention policy]
├── Your controls:
│   ├── Workspace admin locked: No training (contractual) · Badge: Zero-retain
│   └── Personal override: Not available on this workspace
├── Subprocessors: Acme ML · Azure OpenAI EU · [Trust center](/designing-trust-center-and-security-documentation-ui-in-figma/)
├── Automated outputs: May contain errors · [Human review recommended] · Not sole decision basis · See [automated decisions](/designing-automated-decision-making-and-profiling-transparency-ui-in-figma/)
└── [ Continue to Copilot ] · [ Privacy settings ] · Dismiss stores acknowledgment v3.2
ElementRequirement
Training defaultShow ON or OFF explicitly; match actual backend config
Scope listPrompts, file uploads, meeting transcripts—not “all data”
Retention vs trainingSeparate lines; logging TTL ≠ training use
Enterprise lockWhen admin disables training, hide user toggle
Subprocessor linkUpdated when model route changes
Re-show on material changeNew vendor or training default triggers re-notice

Free tiers that default training ON must use unchecked opt-in or clear opt-out—not pre-ticked “help improve AI.”


Privacy settings: training and model usage

AISettings — Privacy · AI & model usage
├── Workspace policy (read-only): Zero-retain · Set by admin @it-security · DPA §4.2
├── Your preferences (where allowed):
│   ├── [ ] Allow my prompts to improve Acme's global models · Currently OFF
│   ├── [✓] Allow personalized suggestions using my workspace only · On-device ranking where possible
│   └── Grayed: Upload training · Disabled by workspace policy
├── What is never used for training (even if logging ON):
│   ├── Password fields · Payment cards · Health tags · Content marked Confidential
│   └── [View classification rules](/designing-content-classification-and-sensitivity-labels-ui-in-figma/)
├── Activity transparency:
│   ├── Last 7 days: 42 Copilot sessions · 0 included in training sets · 0 export requests
│   └── [ Download AI usage report ] · [ Request deletion of prompt logs ]
├── Model info: acme-gpt-4o-mini · Region EU · Knowledge cutoff Jun 2026 · Not fine-tuned on your data
└── [ Save ] · Changes logged to [consent ledger](/designing-consent-records-and-preference-management-admin-ui-in-figma/)

Show effective policy (most restrictive wins): user cannot enable training if workspace or org forbids it.


Enterprise admin: AI data policy console

AIAdminPolicy — Workspace Acme Legal · Enterprise · 220 seats
├── Template: Enterprise Zero-Retain · Locked fields: training, fine-tune, vendor export
├── Scopes:
│   ├── Prompts & completions: Zero-retain · 30-day abuse logs only
│   ├── File embeddings: Stored in tenant region · Not shared across customers
│   ├── Support tickets: Excluded from training · Included in search index (tenant-only)
│   └── Analytics aggregates: Allowed · No raw content
├── Model routes:
│   ├── Primary: Azure OpenAI EU · Fallback disabled
│   └── Blocked: Public fine-tune jobs · External dataset export
├── Compliance:
│   ├── DPA AI addendum v1.4 · Signed Jan 2026
│   ├── ROPA activity PA-201 Copilot inference · Linked
│   └── Launch gate: FEAT-AI-12 blocked until DPIA addendum approved
├── Drift alerts: 3 users on mobile still on legacy training ON · [ Force sync ] · [ Notify users ]
└── [ Export policy PDF for customer ] · [ Audit log ]

Admin overrides should propagate within minutes and surface a banner in the editor when user settings are reset.


In-product transparency chips and tooltips

CopilotEditor — Document draft.md
├── Header chip: AI active · Zero-retain workspace · [Info]
├── Tooltip: "Your content is not used to train shared models. Prompts logged 30 days for safety."
├── Sensitive banner (auto): Confidential label detected · Copilot disabled in this file
├── Output footer: Generated by acme-gpt-4o-mini · Review before sharing · [Report issue]
└── Shortcut: Open [AI settings](/designing-privacy-settings-and-data-management-ui-in-figma/) without leaving editor
ChipMeaning
Zero-retainContractual no-training; show on every AI surface
Training ONConsumer default; link to opt-out in one click
Personalization onlyTenant-scoped models; clarify not global training
Human review requiredHigh-risk outputs; pair with automated decision flows

Opt-out ledger and DSAR support

AIOptOutLedger — Filter: Last 90 days · Event type: policy_change
├── Aug 9 · user @design-lead · Training OFF · Notice v3.2 · Source: settings
├── Aug 8 · admin @security · Workspace zero-retain enforced · 220 users affected
├── Aug 5 · user @trial · Training ON · Free tier default · Source: signup notice
└── [ Export for DSAR ] · [ Link ROPA PA-201 ] · [ Verify backend sync ]

DSAR exports should list AI processing activities, opt-out history, and prompt log retention—not model weights.


Comparison: training posture by plan

PlanDefault trainingUser toggleAdmin lockTypical buyer expectation
FreeON (with opt-out)YesNoConsumer transparency
ProOFFYesOptionalSmall team control
BusinessOFFLimitedYesTeam policy
EnterpriseOFF + zero-retainNoRequiredContractual guarantee

Mismatch between marketing “private AI” and default ON is a common complaint—align copy with settings defaults.


Handoff checklist (Dev Mode)

  • AIPolicy — workspace_id, template_id, training_allowed, fine_tune_allowed, log_retention_days, regions.
  • UserAIPreference — user_id, training_opt_in, personalization_opt_in, notice_version, effective_at.
  • ContentScope — scope_key, included_in_training, included_in_logs, sensitivity_block list.
  • ModelRoute — vendor_id, region, zero_retain flag, fallback_allowed.
  • AINoticeAck — user_id, notice_version, acknowledged_at, surface (editor, mobile, API).
  • PolicyDriftAlert — workspace_id, conflicting_setting, affected_users, resolved_at.
  • Accessibility — toggles have visible labels; chips not color-only; tooltips keyboard reachable.

Common mistakes

MistakeWhy it hurtsFix
One vague “AI” toggleUsers cannot tell training from loggingSeparate training, personalization, logs
Marketing says “private” but default ONRegulatory and sales riskMatch defaults to claims
User opt-out ignored by backendClass-action and enterprise churnLedger + drift alerts
No enterprise admin lockDPA breachPolicy template overrides user settings
Sensitive data in prompts anywayTraining exclusion irrelevantClassification blocks + inline warnings
Hidden subprocessorsTrust center complaintsBlock model route until DPA listed
No re-notice on vendor changeStale consentForce acknowledgment on material changes
Equating zero-retain with no logsTransparency gapDocument abuse-detection retention separately

  1. Define training scopes and defaults per plan with Legal and AI platform teams.
  2. Design first-use notice with training status, retention, and subprocessors.
  3. Build settings panel with effective-policy logic and export/delete actions.
  4. Ship admin policy console for enterprise zero-retain and model routes.
  5. Add in-product chips on every AI surface linking to settings.
  6. Wire opt-out ledger to consent admin and ROPA.
  7. Gate new model vendors at launch review with DPIA addendum.

FAQ

Difference from automated decision transparency?

Training opt-out controls whether content improves models; automated decisions explains scoring that affects users. A fraud score may be an automated decision even when training is off.

Prompt logs vs training?

Logging for safety/abuse can remain while training is off—disclose both with different retention periods.

API customers?

Show the same policy via response headers or dashboard; document in trust center API section.

Include opt-out history, prompt log metadata, and deletion status—not proprietary model internals.

EU AI Act alignment?

Transparency UI supports documentation obligations; pair with technical docs in trust center.


Next steps

Share on X

§ Keep reading

Related guides.