90 Days Gen AI Risk Trial -Start Now
Book a demo
Image Gen·Free; Apprentice $10/mo; Artisan $24/mo; Maestro $48/mo; Team and API custom·leonardo.ai

Leonardo AI

Leonardo AI generates images and short video from text prompts, with custom model training, style LoRAs, and a Phoenix 2.0 flagship model; now owned by Canva.

Risk Score
Medium
5/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Leonardo AI is a generative image and video platform with its own Phoenix 2.0 model plus access to community and licensed models. Creators use it for concept art, game assets, marketing visuals, and character design, with features like Consistent Character Engine, LoRA training, and live canvas. An API is available for developers, and the company was acquired by Canva in 2024. Commercial use is allowed on all tiers, but free users generate public images and grant Leonardo a perpetual license to use that content, including for model training. Paid users generate privately and retain IP, and Leonardo pledges not to use private content for training without consent. Leonardo states it is maintaining SOC 2 certification, processes EU data under GDPR, and encrypts data with AES-256 at rest and TLS 1.2+ in transit. HIPAA is not advertised.

Risk factors

3
  • Generates images from text prompts, potentially using user data.
  • Cloud-based service with third-party data handling.
  • Limited transparency on data retention and usage policies.

Recommendations

8
  • Require paid tier for any commercial or brand work so content stays private and IP is retained
  • Disable community sharing and public gallery for workforce accounts
  • Forbid uploading unreleased brand assets, customer photos, or PII as references
  • Establish a brand/legal review for any AI-generated imagery before publication
  • Avoid generating recognizable real people without written consent
  • Prefer first-party or licensed LoRAs; block community LoRAs of unknown provenance
  • Review SOC 2 attestation and DPA before workforce rollout
  • Pair with a DLP policy that blocks uploads of sensitive asset libraries

Data handling

Storage
Content stored encrypted at rest (AES-256) on cloud infrastructure; TLS 1.2+ in transit. Account data and generations are tenant-scoped for paid users; free-tier generations are publicly accessible.
Retention
Customer personal data deletion honored within 30 days of request; export available. Generated images retained per account plan until explicitly deleted.
Training on inputs
Paid private generations are not used to train models without express written consent. Free-tier public content is licensed to Leonardo for training, new offerings, and commercial use under a perpetual, royalty-free license.