Vol 26, No 20 · July 20, 2026

The_Ledger

You Pay Going In. You Carry the Risk Coming Out

Two companies rewrote their terms this week, and between them they touch the two halves of using any AI tool: the content you put through it and the work you take out.

Put content through Meta's new AI service and, on the free tier, everything you send can be used to train its models; pay, and it can't. A clear no training protection that used to cover everyone has become something you buy. Take work out of Black Forest Labs' Flux image models and you now own the review and the risk: a human has to check a generated image before you publish, and responsibility for intellectual property compliance is explicitly yours alone.

You do not have to use either tool to see the pattern: the terms almost nobody reads are deciding what your data costs and who is liable for your work.

The Notice

What changed in AI platform agreements this week

We are tracking over 60 companies and 280 policy documents daily - and growing. Things that govern how your data is handled, who owns what and who’s on the hook when something goes wrong. These are things you should be reading, but don't have the time for - plus they are super confusing.

If something truly concerns you, reach out to a lawyer - there are no guarantees we catch all changes, something vital to you may be missed or misinterpreted. Docs are diff'ed and summarized by multiple LLMs, then researched, edited and published by a non-lawyer human.

Meta replaced its Llama API Terms of Service with a new Meta Model API Terms of Service, released July 8, 2026. The old terms made a blanket promise: Meta would not use your Content to train any AI models. The new terms keep that promise for paid traffic and reverse it for unpaid traffic. So this is not simply a new pricing tier. A protection that used to cover everyone has been carved in two and sold back to the paid side. On the free service, your inputs and outputs can be used to train and improve Meta’s AI. On the paid service, Meta says they will not. There is no switch inside the free tier to hold specific traffic back. If you need that protection, Meta’s answer is to pay.

In human terms: A three person studio wires Meta’s model into a client tool to see how it performs. They run the trial on the free tier, because that is what free tiers are for. Every prompt they send, including the client’s brief and the sample assets pasted in to test it, is now eligible to train Meta’s models. Nothing warned them at the keyboard. The only way to have kept that material out was to have been on the paid service before they started typing.

Why this matters: For years the practical difference between a free and a paid API was cost, speed, and rate limits. Meta has added a new axis: confidentiality. Whether your inputs and outputs feed someone else’s model is now a billing decision you make before the first request, not a setting you toggle afterward. For anyone handling a client’s material, free no longer means private, and the choice of tier is now part of your compliance posture. Mechanics follow:

Black Forest Labs Black Forest Labs — FLUX Usage Policy

If Meta is the input side of this week’s story, this is the output side, and it lands closer to home. Black Forest Labs rewrote the FLUX usage policy, effective July 14, 2026. The most consequential addition is not a new prohibition. It is an allocation of responsibility. The policy now expects outputs to be reviewed case by case, in particular by a human, warns that your output may not be unique compared to other users’ output or to existing content, and puts responsibility for complying with intellectual property law on you.

In human terms: You generate a hero image for a campaign. Before it ships, Black Forest Labs now expressly expects a human to review whether the image is suitable for use, and it leaves responsibility for intellectual property compliance with you.

Why this matters: This is the model provider stating in the contract what used to go unsaid. The tool is a probabilistic component that belongs inside a supervised workflow, and responsibility for suitability and for IP compliance sits downstream, with you. For a production shop, that is a process requirement, not just legal boilerplate. Note what the policy does not do: it does not prescribe a copyright search or a comparison against a database of other users’ outputs. It requires human review and legal suitability, and leaves the method to you. Below for details:

Synthesia’s AI Governance Practices document used to open by stating, in plain words, that it requires each person to consent before their voice or likeness is cloned. That sentence is gone. In its place is a governance framework built around a “3Rs” model and alignment with an international standard.

In human terms: If you brief a client on why Synthesia is the responsible choice for a spokesperson avatar, the document you would have pointed to no longer carries the clean, quotable consent promise. It now points to process and certification. The word consent does not appear on the updated document at all.

Why this matters: A small change here captures a large industry drift. Companies that first explained responsible AI in human terms, consent and control, are increasingly explaining it through management systems and certifications instead.

To be fair to Synthesia, it still describes avatar consent safeguards elsewhere on its site, so this is not evidence that it stopped obtaining consent. What changed is narrower and still worth noting: its formal AI Governance Practices document no longer contains the categorical consent commitment it previously made.

A promise you can read in one sentence and a framework you have to trust are not the same thing to a client asking hard questions - and it's exactly the type of mechanism we've seen companies widen over time.

The mechanics: The prior document stated that Synthesia “requires that each person consent before their voice or likeness is cloned for an avatar, whether it’s for a Stock Avatar available to all customers, or a Custom Avatar.” The updated document is “structured around its 3Rs framework, Review, Report, and React,” and says Synthesia “aligns its practices with international standards, such as ISO/IEC 42001:2023.” The word consent appears zero times in the updated version of this document.

Perplexity retired the separate privacy notice for Comet, its AI browser, and folded Comet users under the general company privacy notice. In the process, a set of browser specific promises that lived in the old notice are no longer stated in the document that now governs.

In human terms: You chose Comet partly because its privacy notice spelled out that much of your browsing stayed on your own machine, and that you could delete saved passwords, payment details, and history from settings. Those specific assurances are no longer in the notice you are now covered by. Several of them still appear in Perplexity’s help articles, but the formal document that used to make the promise now speaks in general, company wide terms.

Why this matters: A browser is the most sensitive tool most people run, because it sees everything. It is exactly where a user needs one clear, consolidated statement of what stays local, what reaches the company, and what can train its models. Removing those assurances from the formal privacy notice and leaving them scattered in help content is not proof that behavior changed, but it weakens what is actually promised, and it is worth watching. Below for specific language changes:

n8n kept its headline promise: it will not use your content or the AI outputs to train machine learning models. What changed, across two documents updated the same week, is what n8n can do with your data short of training on it. The AI Terms now let n8n use your prompts, in aggregated and de-identified form, to improve its AI services, and the rewritten Self-Serve terms let n8n derive de-identified datasets from your content to run and develop the platform.

In human terms: You chose n8n partly on the strength of a clean no training promise. That promise holds. But the prompts you send can now feed product analytics once de-identified and aggregated, and the content you run through the platform can be turned into de-identified datasets that help n8n build its product. Training the model on your data is still off the table. Mining around it is not.

Why this matters: This is the clearest illustration of the week of why a “we don’t train on your data” badge is not the end of a review. Training a model and mining prompts and content for de-identified analytics are different activities, and a policy can forbid the first while permitting the second. The questions that actually matter are whether prompts are retained, when they are de-identified, and how far a de-identified dataset built from your content can travel.

In a future deep dive, we'll review the competitive moat that companies like n8n have built, and predict how they may use it: how far down the chain a platform can reach before it is competing with the customers who built on it. For now, read below for the mechanics of this current change:

Invideo replaced its terms of service on July 8, 2026, and unusually for this week, most of the rewrite moves in the creator’s favor. It adds an explicit promise not to train on your data, assigns you the rights in the outputs you generate, narrows the license it takes over your content, and requires your affirmative acceptance before material changes take effect. The catch is the one this whole issue keeps circling: a carve-out for de-identified, aggregated data that Invideo owns and keeps after you leave. Our diff is against a June 2026 archive of the prior terms, since the tracked page had been failing to scrape.

In human terms: You make client videos on Invideo. Under the old terms, Invideo could use your AI output “to develop and improve our technologies,” and it took a perpetual, sublicensable license over your content. Under the new ones, it promises not to train on your data, hands you the rights in your outputs, and only licenses your content as far as it needs to run the service. What it keeps is the de-identified, aggregated record of how you use the platform, which it now owns outright.

Why this matters: This is the counter-example to the rest of the week, and worth stating plainly: protections can move toward the creator, not only away. But look at the shape even here. The no training promise is real and welcome, and it sits directly beside a right to de-identified, aggregated data that Invideo owns and retains after you go, plus a clause claiming the machine-learning improvements derived from running the service. The badge a reviewer checks, “won’t train on my data,” is honored. The data question just slides one step over, to what counts as de-identified and how far Invideo’s ownership of it reaches. That is the same question we are pressing on n8n, and Invideo reserves these rights whether or not it ever leans on them. For the legal pros, mechanics follow:

Expanded its public description of how it trains models. Worth a look for anyone tracking training data sources: it now names purchased and openly available third party datasets, “non-public datasets obtained from businesses,” physical texts, and “Data we generate internally,” and states that “the same training material may be used at more than one of the stages above, and we may use it again to train newer versions of our models over time.” It reads as fuller disclosure of an existing process, not a newly claimed right.

Anthropic Anthropic Transparency Hub

updated its model listing this week to note that Claude Opus 4 and Claude Sonnet 4 “are retired and no longer available for use.” The retirement itself happened earlier; the hub caught up this week.

trimmed a few words, for example “your workspace data” became “your data.” Wording cleanup, not a change of substance.

Autodesk Autodesk Offerings

removed a niche construction product clause from its Offerings page and refreshed some analytics vendor names. Nothing for our main audience.

Topaz Labs Topaz Labs Terms of Service

changed its legal name from “Topaz Labs LLC” to “Topaz Labs Inc.” Same obligations.

flipped to its UK edition in our scrape this week, which reads as a large diff but is mostly British spelling.