90 Days Gen AI Risk Trial -Start Now
Book a demo
Image Gen·API pay-per-image via bfl.ai; open-weights free for non-commercial; enterprise custom·blackforestlabs.ai

Flux

Black Forest Labs' FLUX family of image models (FLUX.1 and FLUX.2) — the open-weights successor to Stable Diffusion, with hosted API and enterprise deployments on Azure AI Foundry.

Risk Score
Low
3/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Black Forest Labs, founded by Stable Diffusion co-creators, ships the FLUX model family through three channels: open-weights releases on Hugging Face (dev, schnell, klein variants), a hosted API at bfl.ai, and enterprise deployments including Microsoft Azure AI Foundry. FLUX.2 [pro], [flex], [max] and [klein] deliver up to 4MP photorealistic output with multi-reference control. From a governance standpoint, the risk profile depends heavily on deployment mode. Self-hosted open-weights deployments keep data fully in-boundary but require commercial licensing for paid use. The BFL hosted API offers zero-data-retention, GDPR-compliant processing, and EU data residency for enterprise customers, with DPAs and security questionnaires available on request. SOC 2 is not publicly attested. Image-gen IP risks (likeness, copyrighted style) remain regardless of hosting.

Risk factors

3
  • Open-source tool that can be self-hosted, reducing data exposure.
  • Limited data access as it primarily generates images.
  • No default training on user data.

Recommendations

8
  • Use BFL enterprise API with zero-retention and DPA for any business workflow
  • For sensitive assets, self-host FLUX weights on customer VPC or Azure AI Foundry
  • Validate commercial license tier matches intended use (dev/schnell are non-commercial)
  • Prohibit likeness generation of real people without signed releases
  • Scan any third-party FLUX checkpoints for tampering before production use
  • Require C2PA or internal watermarking on outputs used in customer-facing channels
  • Route enterprise procurement for DPA and EU data residency confirmation
  • Maintain prompt and output logs for IP and brand-safety audits

Data handling

Storage
Hosted API: BFL cloud with EU residency option for enterprise; self-hosted: customer-controlled
Retention
Enterprise API offers zero data retention; standard API retains logs per default policy; self-hosted retention is customer-controlled
Training on inputs
BFL does not train on customer API inputs under enterprise terms; open-weights self-hosted data stays in customer boundary