Figma AI Vendor Risk Profile
Collaborative design platform with AI-powered features including auto-layout suggestions, content generation, image editing, and design-to-code capabilities. Used by product and design teams worldwide.
Risk overview
Risk score: 35/100
Risk tier: Moderate
Safety rating: 65/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: Apr 19, 2026 Aging
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 42/100 |
| IP Exposure | 31/100 |
| Jurisdiction | 13/100 |
| Security | 30/100 |
| Regulatory Compliance | 60/100 |
| Transparency | 45/100 |
| Business Stability | 35/100 |
| Dependency Chain | 30/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Acceptable
Figma's AI features layer onto the dominant collaborative design platform with clear no-training defaults for customer files and zero-retention subprocessor contracts. The 2024 Make Designs incident (generating near-identical Apple Weather app replicas) exposed a training-data provenance issue, and the absence of a HIPAA BAA limits healthcare use.
Bottom line: Acceptable for existing Figma customers; treat AI features as ideation aids, not final deliverables.
Strengths
- No training on customer file content; opt-in required for Figma-owned model improvement
- Zero-retention contracts with OpenAI and Anthropic as AI subprocessors
- SOC 2 Type II, ISO 27001, and ISO 27701 certified with mature GDPR DPA
- Deep integration with existing Figma design and FigJam workflows
Concerns
- Make Designs incident reproduced Apple's Weather app nearly identically, exposing training-data provenance gaps
- No HIPAA Business Associate Agreement available
- AI features entirely depend on third-party LLM providers
- Adobe acquisition attempt abandoned in 2023 leaves strategic direction fluid
Best for
- Design teams already standardized on Figma wanting AI-assisted ideation
- Product and UX teams doing early-stage design exploration and variant generation
- Organizations wanting AI design features inside existing tenant permissions and audit logs
Avoid if
- You need HIPAA-eligible design tooling for healthcare workflows
- You require IP indemnification for AI-generated design output
- Your brand team cannot accept recognizable-content-reproduction risk without process controls
Citations
- Data Handling — Hipaa Baa Available
Figma does not currently sign HIPAA Business Associate Agreements or support HIPAA workloads.
- Data Handling — Third Party Data Sharing
Figma AI features use third-party LLM providers (including OpenAI and Anthropic) under contracts requiring zero-retention and no-training terms.
- Data Handling — Trains On User Data
Figma does not use customer file content to train third-party AI models. Customers can opt out of Figma using content to train Figma-owned models.
- Ip Profiles — Known Ip Lawsuits
Figma temporarily disabled its Make Designs AI feature after users demonstrated it reproduced near-identical copies of Apple's Weather app.
- Ip Profiles — User Owns Outputs
As between the parties, you retain all right, title, and interest in your User Content, including designs generated through Figma AI features.
- Jurisdiction Profiles — Incorporation Country
Figma, Inc. is a Delaware corporation headquartered in San Francisco, California.
- Security Compliance — Gdpr Compliant
Figma provides a GDPR-compliant Data Processing Addendum and lists subprocessors publicly.
- Security Compliance — Iso 27001
Figma is certified to ISO/IEC 27001 and ISO/IEC 27701 for information security and privacy management.
- Security Compliance — Soc2 Type2
Figma maintains SOC 2 Type II compliance with annual third-party audits.