AI Dispatch
The wirewireAug 26, 2026

AI video-agent vendor HeyGen cites GDPR, SOC 2 and EU AI Act in compliance list; discloses no insurance or liability cover

HeyGen names five compliance frameworks in a single line on its security page and says it logs user and admin activity; it publishes no insurance, indemnification, liability cap or runtime-governance terms for its AI video-generation product.

HeyGen, a company that builds AI video-generation agents, lists "GDPR SOC 2 TYPE II CCPA AI ACT DPF" among its compliance references on its security page — naming the EU's General Data Protection Regulation, a SOC 2 Type II audit standard, California's consumer-privacy law, the EU AI Act and the EU-US Data Privacy Framework in a single line, with no further detail on which controls map to which framework.

The company also says it "maintains audit logs of user activity and administrative actions," visible to enterprise customers.

HeyGen's public pages do not disclose insurance coverage, a named carrier, coverage limits, indemnification terms or a liability cap for its own product, nor its own liability cover as a vendor. Runtime governance — what automated limits, if any, apply to the agent's actions at run time — is likewise not addressed. All of the above register as no public information available in AI Dispatch's index, most recently checked Aug. 21.

The gap matters because of what HeyGen sells: AI-generated video and synthetic likenesses, a product category where errors or misuse carry direct reputational and legal exposure for the businesses that deploy it. A company can name the compliance frameworks it aligns with without stating who is financially responsible if an agent-generated video causes harm — the distinction AI Dispatch's insurance-indemnity dimension is built to track. On HeyGen's current public record, that dimension is unaddressed, not merely unmet.

Compliance certification and insurance coverage answer different questions. A certification like SOC 2 Type II speaks to how a company handles data internally; it says nothing about who pays, or how much, if an AI-generated video is used to defraud, defame or impersonate someone without consent. HeyGen's site addresses the first question in a single line of badge text and does not address the second at all in the record reviewed.

Entries in this piece 1

Published index entries backed by the same source documents this piece cites.

Sources 2

  1. GDPR SOC 2 TYPE II CCPA AI ACT DPF
    www.heygen.com · checked Aug 3, 2026
  2. HeyGen maintains audit logs of user activity and administrative actions
    www.heygen.com · checked Aug 21, 2026