AI creative licensing is where agency pipelines quietly break — not at the model, but at the paperwork. The render looks right, the client signs off, and the exposure sits in a licence file nobody opened. The clearest example is flux-2-dev: open weights, free to download, and non-commercial by Black Forest Labs own terms, which turns the popular “just run it locally for free” advice into a licensing violation the moment the output touches client work.
That is one landmine of several, and they are not the ones most creative teams are watching for. One vendor bills you for generations its own moderation layer refuses. One asks you to identify the end customer you are generating on behalf of, and most integrations never set the field. One sells indemnification as the product. And images coming out of the OpenAI API now carry two provenance signals with no documented opt-out — a compliance asset and a permanent attribution at the same time.
This guide follows the chain rather than the model list: what survives as an asset passes from model to editor to ad platform, which vendor terms govern each hop, and where an agency actually carries the risk. Every claim below traces to a vendor licence page, a vendor pricing page or a regulatory text, and where a claim could only be confirmed in trade press we say so rather than dressing it up. This is commentary for operators, not legal advice.
- 01flux-2-dev is non-commercial, and that is the whole trap.BFL licenses the open-weight dev model for non-commercial use only, and its own pricing table labels it open weights, non-commercial, no hosted API. Running it locally to produce a client deliverable is the prohibited act, whoever owns the resulting pixels.
- 02Refused generations can still be billable.xAI states on its pricing page that requests its system deems in violation of the usage guidelines are still charged for the generation, with a separate flat fee for violations caught before generation. It is an API-wide clause, not an image-specific carve-out.
- 03fal.ai Seedance is self-serve, and end_user_id is reseller mode.The live model page reads as a standard GA API with published pricing and no waitlist. The B2B detail that matters is end_user_id, documented as required for B2B access — the field that attributes a generation to the client you ran it for.
- 04C2PA and SynthID solve different halves of one problem.By OpenAI own description, C2PA carries detailed context while SynthID preserves a signal when metadata does not survive. Ad platforms re-encode and strip metadata routinely, so a pipeline that relies on either signal alone loses provenance at a predictable hop.
- 05Indemnification is a product feature, not a default.Adobe states that customers on qualifying Firefly plans are eligible for IP indemnification for generated content, with terms applying and beta features reportedly carved out. No comparable indemnity appears on the other vendor pages cited here.
01 — Open Weights, Closed LicenceDownloadable is not the same as licensed.
Black Forest Labs publishes flux-2-dev under its Non-Commercial License, last revised November 25, 2025. The terms prohibit revenue-generating activities, prohibit use involving direct end-user interactions or impact, and prohibit using the model to train or fine-tune other models for commercial purposes. Commercial use is not impossible — it requires requesting a separate licence from BFL, granted at the company sole discretion, and that licence may carry fees or revenue sharing.
BFL says the same thing in a second place, which is what makes this unambiguous rather than a reading of dense legal prose. Its own pricing documentation labels the model open weights, non-commercial, no hosted API. The restriction is not buried; it is on the page where a developer goes to compare rates.
There is a genuine nuance worth spelling out, because it is the one people reach for to argue their way out. Outputs generated by FLUX.2 models are owned by the user and may be used commercially — the restriction bites on the model, not automatically on every pixel it produced under permitted non-commercial use. Users still may not use outputs to train a competing model. But this does not rescue the agency workflow, because “run the model locally to produce a client deliverable” is itself commercial, production use of the model. The prohibited act happens before the file is exported.
flux-2-pro, flux-2-max, flux-2-flex, flux-2-klein-* and the non-commercial flux-2-dev. FLUX 3 is the video line. A brief that specifies “FLUX 3 for the key visuals” is specifying a different product category, and the procurement conversation that follows will be about the wrong licence.The reason this trap is so effective is that it rewards the exact instinct good engineering teams have. Open weights on a workstation mean no per-image cost, no rate limits, no data leaving the building, and no vendor to ask permission from. Every one of those is a real advantage — and all of them are available under the licence, right up until the work is commercial. The failure mode is not recklessness. It is a team applying a habit formed on research and prototyping to a deliverable that happens to be billable.
02 — The Licensed PathWhat BFL will actually sell you instead.
The remedy is unglamorous: the same family, on the hosted API, at published per-image rates. BFL runs commercially licensed tiers alongside the non-commercial weights, which means the compliant route is not “pick a different vendor” but “pick a different tier of the vendor you already chose”.
flux-2-dev
Non-commercial licence, last revised November 25, 2025. Fine for research, evaluation and personal experiments. Commercial use requires a separate licence request to BFL, granted at its sole discretion and potentially with fees or revenue sharing.
flux-2-klein · 4b / 9b
Hosted, commercially licensed, and the cheapest way to stop the licence conversation entirely. At these rates the per-image cost of compliance is a rounding error against a single hour of the account manager time an IP dispute consumes.
flux-2-pro / max / flex
The commercially licensed flagship tiers. flux-2-pro starts at $0.03 for text-to-image and $0.045 for edits, flux-2-max at $0.07, flux-2-flex at $0.05, per BFL published pricing. This is the tier a client deliverable should be coming from.
Put the two paths next to each other and the decision stops being interesting. A campaign that renders two hundred licensed images on flux-2-pro at the published $0.03 text-to-image rate spends six dollars on licensing certainty. There is no version of an agency risk register where six dollars is the reason to run an unlicensed model against a client brief. The only real cost is engineering time to route through an API rather than a local checkpoint — which is time you were going to spend anyway the first time a second person needed to reproduce a render.
The same discipline applies upstream of the model. Rights clearance on the inputs is not a different workflow from rights clearance on the model, and the teams that handle one well usually already have the process for the other — the same rights-clearance discipline behind our UGC rights and licensing framework applies almost unchanged to AI-generated creative.
03 — Charged RefusalsYou can be billed for the render you never received.
xAI publishes a clause on its developer pricing page that most budget models never account for: a request its system deems to violate the usage guidelines is still charged for. There is also a separate flat fee of $0.05 for violations caught before generation on the Responses API. Read the placement carefully — this is a general, API-wide statement on the same page as the image pricing table, not a clause specific to any one image product.
"When your request is deemed to be in violation of our usage guideline by our system, we will still charge for the generation of the request."— xAI developer documentation, pricing page (dated July 3, 2026)
For a creative pipeline this is a budgeting mechanic, not a scandal. Content moderation on image and video models is probabilistic, and campaign work in regulated categories — alcohol, pharma, gambling, anything involving people and skin — sits closest to the boundary where false positives cluster. If every rejection is billable, your effective cost per delivered asset is not the list price; it is the list price divided by your acceptance rate. Very few agency rate cards model that.
There is a stronger version of this circulating, and it deserves an honest label. Users have reported that Grok Imagine video generations get rendered in full and then deleted by a second-pass moderation check, with no refund — described in community write-ups as a two-phase system that renders first and inspects second. That is community-observed behaviour reported by users, not something xAI documents for that product surface. It corroborates the direction of the published clause; it is not the same evidence, and we would not put it in a client deck as vendor-confirmed.
The other xAI detail worth an engineer hour is not a billing question at all. Its image-editing endpoint takes JSON, and the OpenAI SDK does not send JSON for that call — so the drop-in substitution most teams attempt fails on the first request rather than degrading quietly. The vendor documents the workaround explicitly.
images.edit() method is not supported for image editing because it uses multipart/form-data, while the xAI API requires application/json. Use the xAI SDK, Vercel AI SDK, or direct HTTP requests instead.” Budget the integration hour before you promise a client that the editing endpoint is a one-line swap.One pricing note, because the flattened version is already circulating: xAI published image rates are not a single number. Its quality image tier lists $0.05 at 1K and $0.07 at 2K. Budgeting the 1K figure for both resolutions pushes actual spend up to forty percent above the quoted rate on the asset class most likely to be delivered at the higher resolution.
04 — Reseller ModeThe field almost nobody sets, and the correction we owe you.
Start with the correction, because we were carrying the wrong version ourselves. The received wisdom — including in our own earlier working notes for this cluster — was that Seedance 2.5 on fal.ai was early access, not generally available, gated behind an access request and restricted to B2B customers. Fetching the live model pages at the time of writing does not support that. The text-to-video, image-to-video and reference-to-video endpoints all read as a standard self-serve API: published token pricing, worked examples, a client-install quickstart, a documented input schema, and no waitlist or request-access banner anywhere in the page content.
The narrower claim that survives is the more useful one for agencies. The endpoint documents an end_user_id field described as required for B2B access — a unique identifier for your end customer. That is a reseller-mode field, the standard SaaS pattern for integrations that run generations on behalf of somebody else account, not a gate on the API as a whole.
Which is exactly the shape of an agency. If you hold one API key and generate for six clients through it, the integration mode you choose is a licensing-adjacent decision, not a plumbing detail. Set the field and usage, billing and moderation events attach to the right end customer. Leave it unset and every generation is attributable only to you — which is fine until a client asks what was produced under their name, or a moderation event needs to be traced to the brief that caused it.
The second thing the live page settles is price, and it is a clean illustration of a pattern worth building into procurement. Seedance 2.5 is token-billed, not billed per second or per clip. fal publishes $0.0214 per 1,000 tokens; the Vercel AI Gateway publishes $10.70 per million tokens for the same underlying ByteDance model. Those are the same unit once you normalise them, and the normalising is one multiplication.
| Surface | Published rate | Normalised per 1M tokens | Multiple of the lowest |
|---|---|---|---|
| Same model, two surfaces — rate per 1,000 tokens × 1,000 = rate per 1M; multiple = rate ÷ $10.70 | |||
| Vercel AI Gateway | $10.70 / 1M tokens | $10.70 | 1.00× |
| fal.ai (bytedance/seedance-2.5) | $0.0214 / 1,000 tokens | $21.40 | 2.00× |
| What the gap is not | Not a per-second or per-clip difference. Seedance 2.5 bills in tokens on both surfaces, so any “$X per N-second clip” figure you see quoted is somebody derived estimate, not ByteDance billing unit. | ||
Two times is not a scandal either — aggregators carry real cost, and a single key across many models has genuine operational value. It is simply a number that belongs in the decision rather than underneath it. We walked through the single-key argument in detail when the gateway put Grok Imagine and Seedance behind one key, and the economics of deciding what to render at all in the draft-tier storyboarding piece. The cheapest licensed asset is still the one you decided not to generate.
Seedance 2.5 · normalised token rate by surface
Rates as published on each vendor page; bars scaled to the higher rate05 — IndemnificationThe clause an agency should be costing, and rarely does.
Adobe sells the thing everyone else leaves to your contract. Its Firefly business page states that customers on qualifying plans are eligible for IP indemnification for generated content, with terms applying. That is a product feature with a price attached, and it is the honest answer to the question a general counsel asks first: if an output turns out to infringe, who carries it?
Note what the indemnity is built on. Adobe ties it directly to a training-data claim — that it only trains its models on content where it has permission or rights, and that this prevents content creation infringing copyright or intellectual property rights. The indemnity is downstream of the provenance argument, not independent of it. That matters when you are comparing vendors, because a vendor that cannot make the training-data claim has no obvious route to making the indemnity claim either.
Two caveats, both of which we would rather state than smooth over. Adobe enterprise terms are reported to carve beta features out of the indemnity, including on paid plans — we could not re-verify that wording against Adobe own legal document at the time of writing, so treat it as a general characterisation to check with counsel rather than a quotation. And “qualifying plans” plus “terms apply” is doing real work in that sentence; the eligibility boundary is the part worth reading, not the headline.
The practical read for an agency is that indemnification is a line item, not a vibe. If a client brief carries genuine IP risk — packaging, character work, anything adjacent to a recognisable style — the vendor that sells indemnity is competing against the cost of the coverage you would otherwise have to arrange, not against the per-image rate of a vendor that sells none. Compared like that, the enterprise plan is frequently the cheaper of the two, and it almost never gets compared like that. Mapping that comparison across a whole model mix is one of the first workstreams in an AI transformation engagement — and one of the few that pays for itself before anything ships.
06 — Provenance ChainC2PA survives format. SynthID survives loss.
OpenAI has become a C2PA Conforming Generator Product and added SynthID watermarking to images generated through ChatGPT, Codex and the OpenAI API, per its own provenance post, which carries a July 31, 2026 update extending the same system to audio. The post does not contain an explicit opt-out statement in either direction, so the accurate framing is that there is no documented opt-out — not that opting out is impossible. For planning purposes the effect is the same: assume marking rides along.
The reason both signals exist is the part that should shape your pipeline. OpenAI describes them as complementary: C2PA helps content carry detailed context, while SynthID helps preserve a signal when metadata does not survive. Watermarking can be more durable through transformations such as screenshots; metadata can carry more information than a watermark alone. Two different failure modes, two different mitigations.
Content Credentials manifest
Signed metadata travelling with the file. Rich context — what generated it, what edited it, when. Durable through workflows that preserve metadata, and the first thing lost when a platform re-encodes, strips or flattens the asset on upload.
In-pixel watermark
A signal embedded in the content itself rather than alongside it. Carries far less information than a manifest, but keeps a detectable trace through transformations such as screenshots, where metadata does not follow. Complementary by design, not redundant.
The verification tool boundary
OpenAI public tool checks an uploaded image for provenance signals including Content Credentials and SynthID — but at launch it is limited to content generated by OpenAI. Verification is not yet a cross-vendor service you can point a client at.
The standard underneath the first column moved recently too. C2PA Technical Specification 2.3 was published on January 5, 2026. It adds a per-manifest declaration of the specification version used, a default C2PA Trust List for hardware and software certificates, and a protocol for signing live and broadcast media at the CMAF segment level, compatible with HLS, DASH, CDN and DRM infrastructure. The live-media work is the tell: provenance is being engineered for distribution pipelines, not just for files at rest.
Now trace an actual asset. It leaves the model with a C2PA manifest and an embedded watermark. It goes into an editor, which may or may not preserve and extend the manifest. It gets exported to a platform-specific aspect ratio and compressed. It gets uploaded to an ad platform that re-encodes it for delivery. Somewhere in that chain, on most real pipelines, the metadata stops travelling and only the in-pixel signal remains — which is precisely why the two signals exist, and why a compliance story that names only one of them is describing half a pipeline.
This has a second-order consequence agencies underrate. The same marking that satisfies a disclosure obligation is also permanent, unremovable-by-you attribution on the asset you handed a client. It is not a reason to avoid marked models — it is a reason to decide deliberately, at brief stage, which assets are generated where, and to say so in the statement of work rather than discovering the question during a brand review.
07 — Regulatory FloorArticle 50 is live. The rules live next door.
The EU AI Act transparency obligations for synthetic content took effect on August 2, 2026. We are not going to restate them here — we already published the full provenance marking and labelling guide for ad creative, and how the labelling duties land on advertisers specifically. What belongs in a licensing post is narrower: the operative text sets a floor that your vendor choices either help you meet or quietly work against.
The Commission second draft Code of Practice on marking and labelling confirms the same application date and describes a two-layered approach for providers — secured metadata plus watermarking — with optional fingerprinting and logging, and a separate set of labelling duties for deployers covering deepfakes and public-interest text. If that structure sounds familiar, it is the C2PA-plus-SynthID pairing from the previous section, arrived at from the regulatory side rather than the engineering side. Two layers, for the same reason: one survives format, one survives loss.
Two boundaries worth holding onto. Article 50 contains no advertising-specific clause — it is a general synthetic-content transparency floor, and marketing work inherits it rather than being singled out by it. And separately, the broader stand-alone obligations for Annex III high-risk systems were deferred to December 2, 2027 under the Digital Omnibus regulation; that deferral is not a deferral of the Article 50 marking duties, which are in application now.
On penalties, we are going to disappoint anyone looking for a headline number. Trade-press summaries report a ceiling of up to EUR 15 million or 3% of worldwide annual turnover for Article 50 non-compliance, consistent with the Act general tier for other requirements. We could not confirm that figure stated as Article-50-specific on an EU primary source, so we are reporting it as reported and declining to build a stat card out of it. If the number is load-bearing in your risk assessment, it needs a lawyer and the current consolidated text, not a blog post. Again: commentary, not legal advice.
08 — Decision TableWhat actually survives the handoff.
Every cell below exists on some vendor page. None of them exist in one place, which is the whole reason this table is worth building. Read it as a build-versus-license decision aid, and note how often the honest cell is “not documented on the pages cited here” — that phrasing is deliberate, and it is the difference between a checkable claim and a confident guess.
| Surface | Commercial-use path | Provenance marking documented | IP indemnification documented | Practical agency gotcha |
|---|---|---|---|---|
| Licensed paths — usable for client deliverables | ||||
| OpenAI GPT Image 2 (API) | Licensed, metered API | C2PA Content Credentials plus SynthID, per OpenAI provenance post | Not documented on the pages cited here | Marking rides along with no documented opt-out. Plan for it in the SOW rather than around it. |
| xAI image API | Licensed, metered API — quality tier $0.05 at 1K, $0.07 at 2K | Not documented on the pages cited here | Not documented on the pages cited here | Policy-refused generations are still charged, per xAI pricing page. The OpenAI SDK images.edit() will not work against the editing endpoint. |
| ByteDance Seedance 2.5 (fal / gateway) | Licensed, token-billed, self-serve on both surfaces | Not documented on the pages cited here | Not documented on the pages cited here | end_user_id is required for B2B access. fal published rate normalises to 2.00× the gateway rate. |
| BFL FLUX.2 hosted tiers | Licensed hosted API — klein from $0.014, pro from $0.03 t2i | Not documented on the pages cited here | Not documented on the pages cited here | Naming trap: FLUX.2 is the image line, FLUX 3 is the video line. Brief the right family. |
| Adobe Firefly (qualifying plans) | Licensed, qualifying plans | Not documented on the pages cited here | Yes — eligible on qualifying plans, terms apply | The indemnity rests on the training-data claim, and beta features are reportedly carved out. Check the current terms. |
| Not a client-work path — whatever the demo suggested | ||||
| BFL flux-2-dev (local weights) | None by default — non-commercial licence, separate BFL licence required | Not documented on the pages cited here | None | Running it for a client deliverable is the prohibited act, regardless of who owns the resulting pixels. |
| Midjourney | Subscription surfaces only — no public API (press-level confirmation) | Not documented on the pages cited here | Not documented on the pages cited here | “We automated it” means a person exported by hand somewhere in the chain. Price the person. |
The column that should change behaviour is the fourth one. Across seven surfaces, exactly one documents indemnification on its own page — and it is the one agencies most often skip on price. That is not an argument for standardising on Adobe. It is an argument for noticing that when you choose a cheaper generator, you have not removed the indemnity cost from the project; you have moved it onto your own balance sheet and stopped tracking it.
The pattern also tells you something about where this market is heading. Provenance marking is the column most likely to fill in over the next few quarters, because a regulatory floor is now in application and vendors that sell to European advertisers will be asked for it by procurement rather than by regulators. Expect marking to become table stakes and indemnification to remain a paid tier — the first is cheap for a vendor to add, the second is a balance-sheet commitment. Plan your vendor mix on that asymmetry rather than on today snapshot. And check what actually ships before you build on it, the same way we did in the buildability audit of which creative models really ship a working pipeline.
Licensed hosted tier, always
Route every billable render through a commercially licensed API tier. On the FLUX.2 family that means klein from $0.014 or pro from $0.03 text-to-image rather than the non-commercial dev weights. The per-image delta is trivial against a single hour of dispute handling.
Buy the indemnity
Packaging, character work, anything adjacent to a recognisable style. Compare the enterprise plan against the cost of arranging equivalent coverage yourself, not against a cheaper generator per-image rate. Confirm beta-feature exclusions with counsel before relying on the clause.
Set the end-customer identifier
If one API key serves several clients, use the integration mode that attributes generations to an end customer. On the Seedance endpoint that is end_user_id, documented as required for B2B access. Retrofitting attribution after a moderation event is painful.
Two provenance layers, not one
Assume metadata will be stripped at some hop and design for both signals — a C2PA manifest for context and an in-pixel watermark for durability. The Commission draft Code of Practice describes the same two-layer structure from the regulatory side.
09 — ConclusionRead the licence before you read the benchmark.
The model choice is a licensing choice wearing a benchmark costume.
Nothing in this post is exotic. A non-commercial licence on a popular open-weight model. A billing clause covering refused requests. A reseller identifier most integrations never set. An indemnity sold as a plan feature. Two provenance signals that solve different halves of the same durability problem. Each one is a single line on a page a vendor already publishes — and together they describe most of the actual commercial risk in an AI creative pipeline.
The reason they keep biting is structural. Creative teams evaluate models on output quality and price per image, because those are the two numbers every comparison surfaces. Licence scope, indemnity eligibility, billing behaviour under moderation and provenance durability are not in any comparison table, so they get discovered in the order that hurts most: at contract review, at invoice reconciliation, at brand safety escalation. Building the table yourself, once, is a few hours of work that pays for itself the first time a brief lands in a regulated category.
Our forward read is that the two columns diverge. Provenance marking becomes commodity — the regulatory floor is in application, the standards work is heading into live and broadcast distribution, and it is cheap for a vendor to implement. Indemnification stays a paid tier, because it is a balance-sheet commitment rather than a feature flag, and only vendors that can defend a training-data claim can offer it credibly at all. If that holds, the interesting question a year from now is not which model renders best. It is which vendor will put its own money behind the output — and what that costs relative to carrying the risk yourself. Decide that at brief stage, not at review stage. As throughout: commentary, not legal advice.