Is it safe to upload client footage to AI tools? A checklist for post teams
Where footage goes, who processes it, whether it trains models and how long copies are kept: the questions to ask any AI vendor before uploading client work.
Uploading client footage to an AI tool can be safe, but only if you can answer five questions in writing. Where does the footage go? Which companies process it? Can it be used to train models? How long is every copy kept? And does your contract with the client allow it? If the vendor can’t answer the first four, or your NDA says no to the fifth, don’t upload. This post covers why these questions matter for post work, a checklist you can send to any AI vendor, the red flags in their terms, what to add to your own client agreements, and a few habits that reduce risk whichever tool you use.
Why client footage is different from your own
Client footage is someone else’s property, and usually someone else’s secret. Before release, a shot can give away a plot point, a product launch, a campaign or a cast member’s look. Your NDA almost certainly limits who you can share it with, and an AI service counts as a third party. So does every model provider it forwards your footage to.
Footage also carries people. Faces, voices and bodies of talent are covered by their own contracts and, increasingly, by rules about how AI can use a performer’s likeness. Uploading a close-up of an actor to a service that keeps a licence to train on it is a different act from rendering it on your own workstation.
Larger clients formalize all of this. Studios and streamers look for vendors that follow the MPA Content Security Best Practices. Those best practices are maintained by the Trusted Partner Network (TPN), which is wholly owned by the Motion Picture Association and runs security assessments of vendors across the content supply chain, including cloud workflows. TPN has written about “emerging security concerns relating to AI and machine learning” (Digital Media World, July 2024).
Two things are worth knowing about TPN. First, it’s not a certification: TPN says its assessments “produce a report, not a pass/fail grade, certification or rating”. Vendors earn shield tiers, from Blue (a self-assessment) through Silver (checked by an accredited assessor), Gold (all gaps closed) and Gold Star (extra measures for the most sensitive work). Second, when you bring a cloud tool into a TPN-scoped workflow, that tool becomes part of your security picture. Your client will ask about it.
The questions to ask any AI vendor
Send these before the first upload, and keep the answers. A good vendor answers in writing and points to the clause in its terms or data processing agreement (DPA). “We take security seriously” is not an answer.
| # | Question | Why it matters | A good answer looks like |
|---|---|---|---|
| 1 | Do you, or any model provider you use, train on my inputs or outputs? | Training is the one use you can’t take back: once footage is in a training set, deleting the file doesn’t remove what the model learned from it. | “No, for us and every provider we route to,” with the contract clause. |
| 2 | Which sub-processors and model providers will touch my footage? | Many AI apps call third-party models. Aggregators forward requests to the model’s own vendor, and that vendor’s terms then apply. | A named list, per feature, before you upload. |
| 3 | How long is each copy kept, including provider copies, and how do I delete them? | Your upload, intermediate files, outputs, request logs and the provider’s own copies can each have a different retention period. | Specific periods for each copy, a delete mechanism, and written confirmation on request. |
| 4 | Where is the footage processed and stored? | Some contracts and data laws restrict which countries footage can be processed in. | Named regions; a way to keep processing in a region if your contract needs it. |
| 5 | Who can access my footage, and how is it encrypted? | Employee access and output links are the everyday leak paths. | Encryption in transit and at rest; access limited to named roles and logged. |
| 6 | Are output links public by default? | Some platforms return results as public URLs that work for anyone who has the link until they expire. | Private or signed links with short expiry. |
| 7 | Is there automated moderation or human review of content? | Some services run content checks, and some terms allow people to review inputs. That’s another person seeing unreleased work. | Clear statement of what’s reviewed, by whom, and when. |
| 8 | Which security audits or assessments do you hold? | SOC 2 Type II, ISO 27001 or a TPN assessment show that security controls exist and were checked. | The report or certificate, its date and its scope. |
| 9 | Will you sign my NDA or a DPA? | Terms of service can change; a signed agreement is what you can rely on. | Yes, before any footage is shared. |
Aggregators and pass-through risk
Question 2 is the one most often skipped. Many AI video tools don’t run their own models; they call them through an aggregator or directly from the model’s developer. Each extra hop is another company with its own terms. Together AI’s documentation says it plainly: data sent to “passthrough” models “is handled under that provider’s own policy” (Together AI, accessed September 2026). If a vendor can’t tell you which model provider will process your shot, you can’t know which terms apply to it.
What SOC 2 and ISO 27001 do and don’t tell you
A SOC 2 report is an independent auditor’s examination of a company’s controls relevant to security, availability, processing integrity, confidentiality or privacy (AICPA & CIMA). A Type II report covers how those controls worked over a period of time, not just on one day, which is why buyers ask for it. ISO/IEC 27001 is a standard for an information security management system; certificates are issued by accredited certification bodies and apply only within the scope written on the certificate (overview).
What neither tells you: whether the vendor is allowed to train on your footage, which model providers it uses, or whether the part of the business that handles your upload is in scope. Ask for the scope, and read the terms separately.
Red flags in AI tools’ terms
Read the terms for the exact product and tier you’d use. These are the clauses that should stop an upload of client work.
- A licence to train on your inputs or outputs. Some providers’ standard API terms grant this. As of September 2026, for example, Decart’s API terms (last updated July 26, 2026) give Decart a “perpetual, irrevocable, worldwide, non-exclusive and fully sublicensable” licence to your inputs and outputs, and say it may use them to train and improve its AI models (Decart API terms). That may be a reasonable deal for some uses. It isn’t compatible with most NDAs.
- Free tiers with different rules. Google’s Gemini API terms (last modified April 28, 2026) say content sent to unpaid services is used “to provide, improve, and develop Google products and services”, that human reviewers may read it, and “Do not submit sensitive, confidential, or personal information to the Unpaid Services.” Paid services are treated differently (Gemini API terms). The same model can come with very different data terms depending on how you pay for it.
- Vague wording. “May be used to improve our services” with no definition of what “improve” includes.
- No list of providers. If the app calls models it won’t name, you can’t check their terms.
- Public output URLs with long or no expiry. fal, for example, serves generated media as public URLs by default, with access controls and expiry you can configure (fal docs, accessed September 2026). That’s manageable if the vendor sets those controls; ask whether it does.
- Retention that depends on where you clicked. Replicate deletes API prediction data after an hour by default, but keeps predictions created in its web interface indefinitely (Replicate docs). Check which path your tool uses.
- Terms that can change without notice and no option to sign a fixed agreement.
None of these makes a company untrustworthy. They mean the default terms weren’t written for unreleased client footage, so you need a different agreement or a different tool.
What to put in your own client contract or NDA
The simplest protection is to settle AI use with your client before the job starts, not after. This isn’t legal advice, and a lawyer should check your wording, but these are the points worth covering:
- Whether AI tools may be used at all on the project, and for which tasks (for example roto, cleanup, background replacement, but not anything involving a performer’s likeness).
- Approval of named tools. List the services you plan to use, or agree that you’ll ask before adding one.
- No training. Footage and results may only be processed by services that don’t train models on them, including their model providers.
- Retention and deletion. How long any service may keep the footage, and that you’ll confirm deletion at the end of the job.
- Talent and likeness. Anything the client’s talent agreements say about AI and a performer’s likeness applies to you as well.
- Notice. What happens if a vendor changes its terms mid-project, or has a security incident.
If the client says no to AI tools, that’s the answer. It’s better to know on day one than to find out in a vendor review.
Practical habits that reduce risk with any tool
Even with a good vendor, send less, and send it more carefully.
- Send only the frame range you need. If the fix is 90 frames, don’t upload the whole reel. Add the handles the edit needs and nothing more.
- Test on something that isn’t sensitive. Judge a tool on a non-client shot, or a shot the client has already released, before you trust it with an unreleased one (what to look for is in is AI rotoscoping good enough?). A proxy is fine for a test; final work needs the original.
- Strip what the job doesn’t need. Remove audio if the task is visual; dialogue can give away more than the picture. Rename files so they don’t carry project code names, and check embedded metadata (camera, reel, project fields) before export.
- Watermark review copies. Anything that goes out for review, from you or from a vendor, should carry a visible watermark and ideally the viewer’s name.
- Use expiring, access-controlled transfer links rather than open links.
- Keep a log. Which shots went to which service, when, and when they were deleted. When a client security questionnaire arrives, you’ll have the answer.
- Delete when you’re done, and ask the vendor to confirm deletion of provider copies too.
These habits also protect you if something goes wrong: you can say exactly what was shared, with whom, and under which terms.
How nolanlabs handles footage
nolanlabs works with invited teams, and often the first footage we see is a shot someone chooses to share for a demo. For every shot, our commitments are the ones on our privacy page:
- Never used to train AI models, ours or our providers’. We only process footage with AI providers whose terms don’t allow them to train on it.
- Providers named before processing. We tell you which AI providers will process your shot before we run anything.
- Deleted within 30 days after the demo, along with anything we made from it, and sooner if you ask.
- NDA first. If your project is under NDA, tell us before you send anything, and we can sign yours first.
We don’t hold SOC 2, ISO 27001 or a TPN assessment. If your client requires one of those for this project, we’re not the right fit for that footage yet, and we’d rather tell you now. Our reasoning on why only the pixels you mark should change is in generative video editing vs plate-preserving VFX. If you’d like to see how we’d handle a shot, you can request a demo.
The practical takeaway: before any client shot leaves your machine, get the five answers in writing (where it goes, who processes it, whether it trains models, how long every copy is kept, and whether your contract allows it) and keep them with the job.
Questions
- Is it safe to upload client footage to a free AI tool?
- Usually not for work under NDA. Free tiers often come with broader rights to use your content. For example, Google's Gemini API terms (as of April 2026) say content sent to unpaid services is used to improve Google products, may be read by human reviewers, and should not include confidential information. Read the terms for the exact tier you're on before uploading anything.
- Does SOC 2 or ISO 27001 mean an AI tool won't train on my footage?
- No. SOC 2 and ISO 27001 describe how a company controls and audits its security. Neither one tells you whether the company, or the model provider behind it, has the right to train on your inputs. That's in the terms of service and the data processing agreement, so check those separately.
- Is TPN a certification?
- No. The Trusted Partner Network, owned by the Motion Picture Association, runs security assessments against the MPA Content Security Best Practices. TPN says its assessments produce a report, not a pass/fail grade, certification or rating. Vendors earn shield tiers (Blue, Silver, Gold, Gold Star) based on how the assessment went and what they fixed afterward.
- Should I tell my client I'm using AI tools on their shots?
- Yes, before you upload anything. Many NDAs forbid sharing footage with third parties, and an AI vendor and its model providers are third parties. Get written approval that names the tool, what it will be used for and how long the footage will be kept.
Sources
- Trusted Partner Network home page (ownership, assessments, best practices) · accessed 2026-09-24
- Where to start, Trusted Partner Network (shield tiers; assessments are not a certification) · accessed 2026-09-24
- Trusted Partner Network on taking a best practice approach to content security, Digital Media World (July 2024) · accessed 2026-09-24
- Gemini API Additional Terms of Service (last modified April 28, 2026), Google · accessed 2026-09-24
- API Terms (last updated July 26, 2026), Decart · accessed 2026-09-24
- Zero data retention, Together AI docs · accessed 2026-09-24
- Data retention and media expiration, fal docs · accessed 2026-09-24
- Data retention, Replicate docs · accessed 2026-09-24
- System and Organization Controls (SOC) suite of services, AICPA & CIMA · accessed 2026-09-24
- ISO/IEC 27001, Wikipedia (scope and certification overview) · accessed 2026-09-24
Written by the nolanlabs team. nolanlabs does AI shot work for post-production; product names mentioned belong to their owners. Tool details were accurate on the date shown above. Check the vendor’s documentation before relying on them.
