Four questions every tool should answer (even Figma) about AI training model usage

Figma’s class action is not really about copyright, it is about defaults and they are a design decision your team makes. Here’s a test you can apply.

Disclaimer: I am not a lawyer; I don’t even own a suit. I did spend eight years in legal technology, which qualifies me to play one poorly on Law and Order and nothing further. This not about the law, it’s about trust. Read on.

In November 2025, Raza Khan, a startup founder, sued Figma in the Northern District of California. The complaint does not lead with copyright — it leads with consent, and with the claim that the company switched on model training over customer design files by default after years of promising otherwise.

Nothing in that case has been decided.

Figma disputes the allegations and says its training focuses on general patterns like, uh, creating weather apps, rather than customer content.

Hold the legal question open, because that is where it belongs. The design question is not open, and it is not really a question about Figma. Somebody chose between opt-in and opt-out, and chose differently by plan tier. And that decision sits in public documentation right now.

Here is the part that matters: Designers are the users in this story of a company lead by, and we know precisely how it feels to have a default decided on our behalf.

and his company should have a higher standard because where they sit in the public square; they are teaching designers through their actions.

We ship those same defaults to our own users every quarter. So this is a test with four questions, about twenty minutes of work, and it only counts if you turn it around so the users are treated with empathy and respect and not dark patterns.

The Pattern Rhymes

This has happened enough times to have a shape, AI or not. These are the AI cases.

In the summer of 2023, Zoom amended its terms of service to claim broad rights over customer data for training and tuning models. Nobody noticed for months. When a technology blog surfaced the clause in August, The Record reported in Zoom revises terms again to say it doesn’t use customer data to train AI models that the company rewrote the language twice inside a week.

Nine months later it was Slack. A post on Hacker News pointed at the privacy principles page, and workspace owners learned they were enrolled by default in machine learning training on messages, content, and files. TechCrunch covered the reaction in Slack under attack over sneaky AI training policy, including the detail that turned irritation into anger: opting out meant emailing a specific address with a specific subject line, and only a workspace owner could send it.

No toggle, no setting.

The terms had been live since at least September 2023, and Slack rewrote the language within days while saying it had changed no practice, which was true and beside the point. Fresh ink on their hands.

This has happened enough times to have a shape, and it doesn’t feel good.

Then June 2024. Adobe pushed a re-acceptance modal, creators read the license language, and the company spent two weeks walking it back. Its own post, Updating Adobe’s Terms of Use, conceded the terms needed to be more precise.

Adobe’s defaults were never the problem; its wording was. The company lost weeks of trust without doing the thing it stood accused of, which tells you that trust does not track behavior. It tracks what people can read and verify.

Slack is its own category, and the one worth studying. Zoom and Adobe reversed. Slack did not: it rewrote the sentence and kept the mechanism, which is a different move wearing the same clothes.

Trust is not a feeling, it is a set of defaults you can audit, and Zoom and Adobe both recovered inside a fortnight because reversal was available to them — a sentence to fix, a toggle to flip, a correction to make in public. Slack fixed the sentence only, and the email address is still the exit.

Same script every time.

  • A policy change lands quietly.
  • Enrollment is the default.
  • Somebody outside the company finds it.
  • Then the clarification, the apology, and sometimes the walk-back.

It feels a lot like Fight Club, where the companies are calculating risk and reward.

“My job was to apply the formula: Take the number of vehicles in the field, A, multiply it by the probable rate of failure, B, multiply the result by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don’t do one.”

Sounds like consent spirit, read like this:

“My job was to apply the formula: Take the number of users whose data we ingested, A, multiply it by the probable rate of anyone noticing, B, multiply that by the average settlement per claim, C. A times B times C equals X. If X is less than the cost of building a real consent flow, we don’t build one.”

What is different about Figma is that nothing was walked back at all, and the discovery arrived as a federal complaint. There was no drafting error to fix. The tiered default was announced, explained, defended with a stated rationale, and allowed to take effect on schedule. You cannot clarify a decision that was already clear.

The Sniff Test

Four questions fall out of that pattern, worth naming with their scoring before we run them.

  • Consent
  • Symmetry
  • Disclosure
  • Exit

A tool that passes all four treats your work as yours, and three passes is ordinary enough to be worth raising at renewal. But symmetry does not weigh the same as the rest, and a failure there counts for more than the other three combined.

Test One: Consent

The question is not whether a tool told you. It is whether the switch was off when you got there.

Figma’s announcement, Meet Figma AI, is unusually direct. Published in June 2024, it states that sharing customer content for training is optional, that admins set the preference, and that Starter and Professional plans are opted in by default, with no training before August 15, 2024. That is seven weeks of notice, published openly, with the mechanism described.

That is more transparency than Zoom or Slack managed.

Slack buried its terms in a privacy policy and answered discovery with an email address.

Figma published a date.

It is still opt-out.

Notice is not consent.

A seven-week window before a default takes effect is a courtesy, and a real one, but it puts the burden of refusal on the person whose work is at stake. Consent that has to be revoked was never asked for. It was assumed, announced, and then made cancellable.

Consent that has to be revoked was never asked for. It was assumed, announced, and then made cancellable.

The research on this is settled. Nielsen Norman Group’s Sneaking: The Deceptive UX Pattern You Never Saw Coming catalogs the family of practices that get someone to agree to something they never intended, and the finding is not an ethical one so much as an accounting one: sneaking converts, and it costs long-term trust at a rate that outruns the gain.

Designers know the pattern because we build it — the pre-checked box, the bundled permission at install, the subscription folded into account creation. We have spent two decades publishing research on why these patterns are hostile, then shipping them anyway when a growth target needed hitting.

has spent the last stretch of his career arguing this is the job rather than a footnote to it. Design for a Better World presses designers to widen the frame past the person at the screen and treat a shipped decision’s consequences as their own. A default is exactly that kind of decision. It gets made once, by a few people in one room, and applies to millions who will never meet them.

The standard that produced the opt-out default was whether it would survive legal review. Ours is narrower and harder: what is right for the person whose work this is. The two agree most of the time, which is why the gap goes unnoticed until a quarter when they do not.

Run it this way. Open the tool, find the training setting, and look at its state.

If it is on and you did not turn it on, the company made a decision about your work and told you afterward.

Test Two: Symmetry

Here is where it stops being an ordinary default and starts being a statement. Figma’s engineering explainer, Building Figma AI, lays out the tiering plainly.

Get Patrick Neeman’s stories in your inbox

Join Medium for free to get updates from this writer.

Content training defaults to on for Starter and Professional, off for Organization and Enterprise. That’s a pretty clear statement and the stated reason is that agreements with Organization and Enterprise are typically more complex and include specific requirements and restrictions.

Read that again, because it is the most important sentence in the whole episode and Figma published it voluntarily. What it says is this: we understood the setting carried contractual risk, so for customers who had negotiated terms making that risk explicit we defaulted to off, and for everyone else we defaulted to on.

Then read the consequence, which sits in Figma’s own registration statement: roughly seventy percent of new Organization and Enterprise customers included at least one person who had previously been on a Professional plan. The protected tier is grown from the enrolled one. The designer whose files trained the models on a Professional account is the same designer who later brings her company onto an Enterprise contract and receives the protective default as a welcome gift.

The asymmetry is not evidence of bad faith. It is evidence of accurate risk assessment.

Bad faith is a mistake you can apologize for. This was a correct read of where leverage sat, followed by placing the exposure where it was least likely to generate a lawsuit.

That calculation was wrong by about seventeen months.

The underlying premise does not hold either. A freelance designer working under a client nondisclosure agreement is not carrying less confidentiality risk than a company with a master services agreement. She carries the same risk with a thinner contract and no procurement team. The obligation is identical.

The direct version: this was not morally right, and it does not respect designers.

Set the litigation aside and assume Figma wins outright. The tiering still sits in the published record, put there by the company itself: customers with procurement departments get protected, customers without them get enrolled. That is a judgment about whose work matters, made by a company whose business is the work of designers.

Leverage is not a moral category. Bargaining power tells you what a customer can force you to do, and nothing at all about what you owe her, which is why we do not let doctors calibrate care to a patient’s ability to sue.

Symmetry is the best question in the test because it is hardest to explain away. A single default applied to everyone might be a philosophy. Two defaults split along a payment line approved by legal is a position on who is worth protecting.

Test Three: Disclosure

The third question is whether a working designer, doing her job, would have found out without somebody else telling her.

Blog posts are not product notifications. Figma published openly and design press covered it, but the audience for an engineering blog is a fraction of the audience for the product, and the people least likely to read it are the people the default applied to: individual designers and small teams with no administrator tracking vendor policy changes.

Bloomberg Law’s account, Figma Trained AI on User Data Without Consent, Class Action Says, frames the plaintiff’s central allegation as a gap between years of assurances and a settings change. The docket is public at Khan v. Figma, Inc.. The claims are unproven, and reasonable people can read the notice period as adequate.

The disclosure test is not about whether a company published something. It is about whether the publication reached the person the change applied to.

You can watch this fail in Figma’s own forum. In a thread titled Opting out of AI Features, one designer called the arrangement “sketchy as hell” and said the way it was done felt disrespectful.

Another asked, plainly, whether her work was being used given that she could find nowhere to opt out. A third wrote that he had not logged in for months and was learning about it only then.

Those are not journalists reading a policy. Those are users finding out.

So here is the standard, stated plainly enough to apply. A change to what a tool does with your files should reach you inside the tool, once, before it takes effect, with nothing pre-selected. Anything clearing all four conditions is disclosure. Anything clearing three is publication wearing the same coat.

Measured that way, Figma cleared two of the four. The notice arrived before the effective date and it was published once. It never arrived inside the product, and the choice was pre-selected when it did. There is a version that would have passed cleanly: an in-product modal, shown once, two buttons, no default selection. Companies build exactly that for cookie consent because regulation forced them to.

Test Four: Exit

Disclosure only matters if it leads somewhere. The last question is whether you can leave, and what leaves with you.

Figma’s documentation, Manage AI settings and content training for your team or organization, answers precisely. Content training took effect August 15, 2024. If an admin turns the setting off after that date, new content and edits will not be used to train models.

New content and edits. Forward-looking only. And for a while, not everything was covered.

Designers in that same forum thread pointed at documentation stating that opting a team out did not reach an individual user’s personal drafts, which on Starter and Professional could not be excluded at that time.

Personal drafts are where the unfinished work lives — the pitch nobody approved, the client concept that never shipped, the side project. The one place a designer would most reasonably assume was hers was the one place the switch did not reach.

An exit that requires an administrator is not an exit for the person whose work it is.

That is a reasonable engineering position. Unwinding a trained model to extract one team’s contribution is a research problem, not a settings toggle. But it means the exit is partial by construction, and its value decays every day you wait.

Then there is who holds the switch. It is an admin control, team-level on Starter and Professional plans. An individual contributor cannot turn it off. She can ask. If the team lead is busy or unconvinced, the answer is no by inaction. An exit that requires an administrator is not an exit for the person whose work it is.

Test it like any recovery path. Can the person harmed by the state change the state? How long does it take? What is unrecoverable afterward? Ordinary usability questions. We just do not point them at the terms of service.Permission and Forgiveness

The industry has an operating rule, and everyone reading knows it. Better to ask forgiveness than permission. It has been repeated in enough keynotes to pass for wisdom, when what it describes is a wager: that the cost of being wrong will land later, on somebody else, in pieces small enough to absorb.

A default-on training setting is that wager, placed in a settings panel.

Three regimes now govern it, and they do not read it the same way.

  • California codified forgiveness.The California Consumer Privacy Act gives consumers the right to opt out of the sale or sharing of personal information, alongside notices explaining what a business does with it. Notice first, then a switch, which is the shape Figma’s design sits comfortably inside. One detail is worth carrying: California’s regulations define a dark pattern as an interface that substantially impairs autonomy or choice regardless of intent, and require that opting out be no harder than opting in. Symmetry is not only a design principle; in California it is a rule.
  • Europe codified permission.Under the General Data Protection Regulation you need a lawful basis before processing, not a notice afterward. The European Data Protection Board’s Opinion 28/2024 on personal data in the context of AI models confirms legitimate interest can serve as that basis, subject to a three-part assessment. It also states the consequence designers should sit with: data processed unlawfully during development can follow a model into deployment, carrying erasure obligations with it. Forgiveness there can reach the model.
  • The EU AI Act codified disclosure.Then the calendar moved. As Gibson Dunn’s summary of the Digital Omnibus agreement sets out, high-risk obligations slipped to December 2027 for stand-alone systems and August 2028 for embedded ones. Most Article 50 transparency obligations still apply from August 2, 2026. The wider package also proposed amendments to the General Data Protection Regulation aimed at making training on European personal data easier.

Read the scoreboard from a designer’s chair. The industry asked forgiveness at scale, and in the largest regulatory market it is being granted, partly as time and partly as amended rules. Regulation is not going to settle whether default-on training is acceptable. The question lands back with whoever sets the default.

Running the Test on Your Own Stack

Anil Dash wrote the clearest version of the principle in The Internet of Consent: technology should only ever do what we have explicitly given it permission to do. That standard is testable, product by product, and most teams have never tried.

The first four items protect you. The fifth is the one that matters.

  • Inventory where the work lives. Eight minutes.List every tool holding files your team produces, including the ones nobody formally approved. The tools nobody approved are usually the ones with the most permissive defaults, because nobody read the terms before signing up.
  • Read the default, not the promise. Six minutes.Marketing pages describe intentions. Settings panels describe behavior. Open the toggle in the actual account and record its state today.
  • Check the tier line. Three minutes.Find out whether the vendor treats enterprise accounts differently from yours. If it does, you now know which side of that line you are on.
  • Screenshot the settings with a date. Three minutes.Defaults change quietly and version histories are rarely public. A dated screenshot is the only evidence you will have that a setting changed.
  • Run the test on your own product. One design review.This is the part designers skip, and the reason the test exists. If your company ships a feature that learns from customer content, somebody chose a default and you may have been in the room. Kronenberger Rosenfeld’s Figma Lawsuit Opens Door to New Damages Claims notes the exposure runs through the gap between what a company says and what its product does.

The tools nobody approved are usually the ones with the most permissive defaults, because nobody read the terms before signing up.

Then score it against the threshold set out earlier. A symmetry failure on its own outweighs the rest, and here is the reason promised back then: it is the only one of the four where a company assessed the risk correctly and decided you would carry it.

None of this requires an opinion about the litigation. The test works whether Khan wins, loses, or settles quietly next spring.

And do not assume the alternative is leaving, because switching cost is the point. The registration statement reports 132 percent net dollar retention as of the first quarter of 2025, among the strongest figures of any public cloud company.

Read how the number is built, though. As Figma S-1 | The IPO Bar is High sets out, the calculation counts customers above ten thousand dollars in annual recurring revenue who are still customers, so accounts that left entirely never appear in it.

It measures expansion among the people who stayed and cannot see the ones who went. The bill for this does not arrive as churn, and the instrument pointed at churn would miss it anyway. It arrives as interpretation, in the pause before somebody vouches for you.

Figma may win this case. The trade secret theory is aggressive, the class definition will be fought hard, and seven weeks of notice is a defense. I would not bet against the company.

Winning is not the same as being trusted, AI or not, and only one is a design outcome.

The dispute traces back to one product decision, made by people doing a job many of us have done. Nobody in that room needed to be cynical. They needed a training corpus, a legal review that cleared the language, and a notice period. That is how these decisions get made, and how we make them.

Defaults are the quietest thing we ship and the loudest thing we say. Opt-out says your work is ours until you object. Opt-in says it is yours until you offer it. The engineering cost between them is nothing. Permission costs a modal; forgiveness costs everything after.

So run the test. Then go run it on what you build, where your answer counts. Designers spent this year asking a vendor for consent it never thought to ask us for. We should not need a lawsuit to remember how that felt, or to stop doing it to somebody else.