The Black Forest Labs API signs Flux images with a C2PA provenance record. The FLUX.1 reference code writes EXIF data such as Software “AI generated;txt2img;flux” and embeds an invisible watermark, while many services that offer Flux document none of this.
If a Flux image in your store is a deep fake, Article 50(4) of the EU AI Act still requires a visible label (Commission guidelines para. 117).
What Flux writes into the file
Flux is available through the Black Forest Labs API, through other providers' services and as open models you run yourself. The traces differ by route.
| Trace | Status October 2026 | Source |
|---|---|---|
| C2PA (Content Credentials) | Partly The Black Forest Labs API signs output with C2PA (FLUX.1 Kontext and FLUX.2 model cards). The fal.ai service signs as well. For self-hosted open models, Black Forest Labs recommends adding provenance data such as C2PA yourself. | ↗ ↗ ↗ |
| IPTC Digital Source Type (XMP) | Not documented Not documented. | none found |
| Invisible watermark | Partly The FLUX.1 reference code always embeds an invisible watermark; for FLUX.2 it is an option. fal.ai states an invisible watermark. None is documented for the Black Forest Labs API. | ↗ ↗ ↗ |
| Prompt and settings in the file | Partly The FLUX.1 reference code writes EXIF: Software “AI generated;txt2img;flux”, Make “Black Forest Labs”, the model name and the prompt as image description. If Flux runs in ComfyUI or AUTOMATIC1111, that program writes its own fields. | ↗ |
| Visible mark on the image | Not documented Not documented. | none found |
C2PA (Content Credentials) is a signed provenance record in the file, IPTC Digital Source Type a metadata field on how the image was made, for example trainedAlgorithmicMedia for fully AI-generated images. An invisible watermark sits in the pixels, and only the vendor can read it.
How to check a Flux image
- Drag the original file from Flux into the box above. It is read in your browser, not uploaded. Screenshots and copies from stores or social networks usually no longer carry the data.
- For images from the Black Forest Labs API or from fal.ai, the checker shows the C2PA record under “Content Credentials (C2PA)”.
- For images from the FLUX.1 reference code, the checker shows Software “AI generated;txt2img;flux” and Make “Black Forest Labs” under EXIF and flags an AI hint.
- If Flux ran in ComfyUI or AUTOMATIC1111, you find the prompt and settings in the PNG fields, as with Stable Diffusion.
More detail in the AI image checker and Content Credentials viewer and Prompt reader.
The checker is not an AI detector. It only shows what the file says. An empty result does not prove a real photo, not least because providers of AI systems placed on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking (Article 111(4) AI Act).
What survives uploads and edits
According to fal.ai, metadata can be lost through editing, re-saving or compression. That applies to every route.
Many services offer Flux, such as Replicate, Together AI, Mistral Le Chat or Freepik. Their documentation does not say whether they pass on the Black Forest Labs C2PA record or add anything themselves.
Labelling duty in your store under the EU AI Act
If you use Flux to create or edit images for your own store, you are a deployer, even when an agency or an employee works on your instructions (Article 3(4) AI Act, Commission guidelines para. 12, 14). If the image is a deep fake, meaning realistic and falsely appearing authentic, you have had to label it visibly since 2 August 2026 (Article 50(4) AI Act). The labelling check tells you whether that applies, and the guide to the labelling duty explains the rules.
The traces in the table do not replace that label, because people cannot see them straight away (guidelines para. 117). Still, keep them in the file, as the guidelines recommend. They document where the image came from.
How Flux labels its own output
Black Forest Labs relies on C2PA metadata in its API and recommends that developers using the open models add their own provenance data such as C2PA. This is stated in the model cards, not in the API developer documentation.
fal.ai checks its own signature and watermark at fal.ai/verify. None of the routes documents a visible mark on the image.
Frequently asked questions
Do Flux images contain metadata?
It depends on the route. Images from the Black Forest Labs API and from fal.ai come with a C2PA record, images from the FLUX.1 reference code with EXIF data and a watermark. Nothing is documented for other services.
What does “AI generated;txt2img;flux” in the Software field mean?
The Black Forest Labs reference code for FLUX.1 writes this text into the EXIF Software field, together with “Black Forest Labs” as the make. So the image was generated with that code.
Sources
Para. refers to the paragraph number in the European Commission's guidelines on Article 50, C(2026) 5054.
- Black Forest Labs: FLUX.1 Kontext dev (Modellkarte)Hugging Face · Platform · 11 Oct 2026
- Black Forest Labs: FLUX.2 READMEGitHub · Platform · 11 Oct 2026
- Black Forest Labs: FLUX Quellcode util.pyGitHub · Standard · 11 Oct 2026
- fal.ai: Verifyfal.ai · Platform · 11 Oct 2026
- Black Forest Labs: API-IntegrationsrichtlinienBlack Forest Labs · Platform · 11 Oct 2026
- Regulation (EU) 2024/1689 (AI Act)EUR-Lex · Law · 12 Jul 2024
- Commission Guidelines on the transparency obligations under Article 50 AI Act, C(2026) 5054 finalEuropäische Kommission · Commission · 20 Jul 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)EUR-Lex · Law · 24 Jul 2026

