figma guide
Designing AI training opt-out and model data usage transparency UI in Figma: controls, notices, and enterprise policies
Design AI training opt-out UI in Figma with model data usage notices, workspace-level policies, content exclusion controls, and transparency panels for generative AI and ML products.
- Published
- Updated
- Aug 09, 2026
- Read time
- 8 min
- Level
- Intermediate
Quick answer
AI training opt-out UI tells users whether their content trains models, what is excluded by default, and how to change the setting at account or workspace level—before they paste sensitive data into a prompt. Design a first-use AI notice with training ON/OFF default by plan; a privacy settings panel with plain-language scopes (prompts, uploads, support tickets); and an admin policy console for enterprise “no training” guarantees. Start from the Figma guides hub and pair with privacy settings, automated decisions, consent admin, ROPA, and Dev Mode handoff.
Who this is for
- Product designers shipping copilots, generative features, or ML-powered search where customer content may enter model pipelines.
- Design system teams standardizing AI badges, “not used for training” chips, and enterprise lock icons across editor and admin surfaces.
- Privacy and AI governance teams aligning with GDPR purpose limitation, EU AI Act transparency expectations, and enterprise DPAs that require contractual “no train” clauses—not a vague “we may improve our services” footer.
AI data governance hub (internal overview)
AIDataGovernanceHub — Acme AI Platform · 840 workspaces · 62% training opt-out on paid plans
├── Header: Training enabled 318 workspaces · Zero-retain 412 · Pending policy sync 6
├── Actions: [ Edit defaults ] [ Run exclusion audit ] [ Export transparency report ] [ DPA templates ]
├── Tabs: Policies · Opt-out ledger · Content scopes · Model routes · Retention · Incidents · Reports
├── Alert: WS-4421 Enterprise · DPA requires zero-retain · 3 users still on legacy "Improve AI" ON
├── Filters: Plan tier · Region · Policy template · Model vendor · Last changed
└── Link: [ROPA](/designing-records-of-processing-activities-and-data-mapping-ui-in-figma/) · [DPIA](/designing-privacy-impact-assessment-and-dpia-workflow-ui-in-figma/) · Trust center · Launch gates
| Section | Purpose |
|---|---|
| Policies | Default training posture by plan, region, and contract |
| Opt-out ledger | Immutable user and admin changes with notice version |
| Content scopes | What data classes can enter training pipelines |
| Model routes | Which vendors receive prompts; zero-retain vs fine-tune paths |
| Retention | Prompt logging TTL separate from training exclusion |
| Incidents | Accidental training inclusion or policy drift alerts |
Verdict: AI transparency UI fails when “Improve the product” hides model training—users and enterprise buyers need scoped toggles and audit exports.
First-use AI notice (customer-facing)
AINotice — Acme Copilot uses AI · Before you continue
├── What AI does here: "Summarize docs, draft replies, and search your workspace"
├── How your data is used:
│ ├── Prompts and uploads may be processed by Acme models and subprocessors
│ ├── Training: OFF by default on your Pro plan · Your content is NOT used to train global models
│ └── Logging: Prompts retained 30 days for abuse detection · [Retention policy]
├── Your controls:
│ ├── Workspace admin locked: No training (contractual) · Badge: Zero-retain
│ └── Personal override: Not available on this workspace
├── Subprocessors: Acme ML · Azure OpenAI EU · [Trust center](/designing-trust-center-and-security-documentation-ui-in-figma/)
├── Automated outputs: May contain errors · [Human review recommended] · Not sole decision basis · See [automated decisions](/designing-automated-decision-making-and-profiling-transparency-ui-in-figma/)
└── [ Continue to Copilot ] · [ Privacy settings ] · Dismiss stores acknowledgment v3.2
| Element | Requirement |
|---|---|
| Training default | Show ON or OFF explicitly; match actual backend config |
| Scope list | Prompts, file uploads, meeting transcripts—not “all data” |
| Retention vs training | Separate lines; logging TTL ≠ training use |
| Enterprise lock | When admin disables training, hide user toggle |
| Subprocessor link | Updated when model route changes |
| Re-show on material change | New vendor or training default triggers re-notice |
Free tiers that default training ON must use unchecked opt-in or clear opt-out—not pre-ticked “help improve AI.”
Privacy settings: training and model usage
AISettings — Privacy · AI & model usage
├── Workspace policy (read-only): Zero-retain · Set by admin @it-security · DPA §4.2
├── Your preferences (where allowed):
│ ├── [ ] Allow my prompts to improve Acme's global models · Currently OFF
│ ├── [✓] Allow personalized suggestions using my workspace only · On-device ranking where possible
│ └── Grayed: Upload training · Disabled by workspace policy
├── What is never used for training (even if logging ON):
│ ├── Password fields · Payment cards · Health tags · Content marked Confidential
│ └── [View classification rules](/designing-content-classification-and-sensitivity-labels-ui-in-figma/)
├── Activity transparency:
│ ├── Last 7 days: 42 Copilot sessions · 0 included in training sets · 0 export requests
│ └── [ Download AI usage report ] · [ Request deletion of prompt logs ]
├── Model info: acme-gpt-4o-mini · Region EU · Knowledge cutoff Jun 2026 · Not fine-tuned on your data
└── [ Save ] · Changes logged to [consent ledger](/designing-consent-records-and-preference-management-admin-ui-in-figma/)
Show effective policy (most restrictive wins): user cannot enable training if workspace or org forbids it.
Enterprise admin: AI data policy console
AIAdminPolicy — Workspace Acme Legal · Enterprise · 220 seats
├── Template: Enterprise Zero-Retain · Locked fields: training, fine-tune, vendor export
├── Scopes:
│ ├── Prompts & completions: Zero-retain · 30-day abuse logs only
│ ├── File embeddings: Stored in tenant region · Not shared across customers
│ ├── Support tickets: Excluded from training · Included in search index (tenant-only)
│ └── Analytics aggregates: Allowed · No raw content
├── Model routes:
│ ├── Primary: Azure OpenAI EU · Fallback disabled
│ └── Blocked: Public fine-tune jobs · External dataset export
├── Compliance:
│ ├── DPA AI addendum v1.4 · Signed Jan 2026
│ ├── ROPA activity PA-201 Copilot inference · Linked
│ └── Launch gate: FEAT-AI-12 blocked until DPIA addendum approved
├── Drift alerts: 3 users on mobile still on legacy training ON · [ Force sync ] · [ Notify users ]
└── [ Export policy PDF for customer ] · [ Audit log ]
Admin overrides should propagate within minutes and surface a banner in the editor when user settings are reset.
In-product transparency chips and tooltips
CopilotEditor — Document draft.md
├── Header chip: AI active · Zero-retain workspace · [Info]
├── Tooltip: "Your content is not used to train shared models. Prompts logged 30 days for safety."
├── Sensitive banner (auto): Confidential label detected · Copilot disabled in this file
├── Output footer: Generated by acme-gpt-4o-mini · Review before sharing · [Report issue]
└── Shortcut: Open [AI settings](/designing-privacy-settings-and-data-management-ui-in-figma/) without leaving editor
| Chip | Meaning |
|---|---|
| Zero-retain | Contractual no-training; show on every AI surface |
| Training ON | Consumer default; link to opt-out in one click |
| Personalization only | Tenant-scoped models; clarify not global training |
| Human review required | High-risk outputs; pair with automated decision flows |
Opt-out ledger and DSAR support
AIOptOutLedger — Filter: Last 90 days · Event type: policy_change
├── Aug 9 · user @design-lead · Training OFF · Notice v3.2 · Source: settings
├── Aug 8 · admin @security · Workspace zero-retain enforced · 220 users affected
├── Aug 5 · user @trial · Training ON · Free tier default · Source: signup notice
└── [ Export for DSAR ] · [ Link ROPA PA-201 ] · [ Verify backend sync ]
DSAR exports should list AI processing activities, opt-out history, and prompt log retention—not model weights.
Comparison: training posture by plan
| Plan | Default training | User toggle | Admin lock | Typical buyer expectation |
|---|---|---|---|---|
| Free | ON (with opt-out) | Yes | No | Consumer transparency |
| Pro | OFF | Yes | Optional | Small team control |
| Business | OFF | Limited | Yes | Team policy |
| Enterprise | OFF + zero-retain | No | Required | Contractual guarantee |
Mismatch between marketing “private AI” and default ON is a common complaint—align copy with settings defaults.
Handoff checklist (Dev Mode)
- AIPolicy — workspace_id, template_id, training_allowed, fine_tune_allowed, log_retention_days, regions.
- UserAIPreference — user_id, training_opt_in, personalization_opt_in, notice_version, effective_at.
- ContentScope — scope_key, included_in_training, included_in_logs, sensitivity_block list.
- ModelRoute — vendor_id, region, zero_retain flag, fallback_allowed.
- AINoticeAck — user_id, notice_version, acknowledged_at, surface (editor, mobile, API).
- PolicyDriftAlert — workspace_id, conflicting_setting, affected_users, resolved_at.
- Accessibility — toggles have visible labels; chips not color-only; tooltips keyboard reachable.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| One vague “AI” toggle | Users cannot tell training from logging | Separate training, personalization, logs |
| Marketing says “private” but default ON | Regulatory and sales risk | Match defaults to claims |
| User opt-out ignored by backend | Class-action and enterprise churn | Ledger + drift alerts |
| No enterprise admin lock | DPA breach | Policy template overrides user settings |
| Sensitive data in prompts anyway | Training exclusion irrelevant | Classification blocks + inline warnings |
| Hidden subprocessors | Trust center complaints | Block model route until DPA listed |
| No re-notice on vendor change | Stale consent | Force acknowledgment on material changes |
| Equating zero-retain with no logs | Transparency gap | Document abuse-detection retention separately |
Recommended workflow
- Define training scopes and defaults per plan with Legal and AI platform teams.
- Design first-use notice with training status, retention, and subprocessors.
- Build settings panel with effective-policy logic and export/delete actions.
- Ship admin policy console for enterprise zero-retain and model routes.
- Add in-product chips on every AI surface linking to settings.
- Wire opt-out ledger to consent admin and ROPA.
- Gate new model vendors at launch review with DPIA addendum.
FAQ
Difference from automated decision transparency?
Training opt-out controls whether content improves models; automated decisions explains scoring that affects users. A fraud score may be an automated decision even when training is off.
Prompt logs vs training?
Logging for safety/abuse can remain while training is off—disclose both with different retention periods.
API customers?
Show the same policy via response headers or dashboard; document in trust center API section.
Link to DSAR portal?
Include opt-out history, prompt log metadata, and deletion status—not proprietary model internals.
EU AI Act alignment?
Transparency UI supports documentation obligations; pair with technical docs in trust center.
Next steps
- Design privacy settings and data management UI in Figma — home for AI toggles and exports
- Design automated decision-making and profiling transparency UI in Figma — when AI outputs affect users materially
- Design consent records and preference management admin UI in Figma — opt-out audit trail
- Design privacy by design launch gates and feature privacy review UI in Figma — block new model routes without review
- Design trust center and security documentation UI in Figma — publish AI subprocessors and policies
§ Keep reading