Which Foundry models add C2PA and a watermark: GPT Image, FLUX.2, MAI

Microsoft's Foundry page lists the image, audio and voice models that get C2PA credentials and watermarks. What that does and does not tell you about Sume.

4 min readSume
All posts

Microsoft states which of its hosted models mark their output. The Foundry provenance page, dated 2026-09-17 with an update on 2026-10-01 and read on 2026-10-05, says supported models add C2PA Content Credentials and invisible watermarks to what they generate. It is one of the few vendor pages that gives a model-by-model list.

If you use any of those models through another API, the useful question is whether the same marks survive. This post lists the models and then says what I can and cannot say about Sume.

The list on the page

Models Microsoft lists for provenance on Foundry (read 2026-10-05)
TypeModels named on the page
ImageGPT Image (gpt-image-1-mini, 1.5, 2), MAI-Image-2.5 variants
Image, Black Forest LabsFlux-1.1-Pro, Flux.1-Kontext-pro, Flux.2-flex, Flux.2-Pro
AudioGPT Audio, MAI-Voice-1, MAI-Voice-2, Azure AI Speech TTS
Audio formatsMP3 and WAV are supported

What this does not tell you about Sume

Sume's image docs list models including openai/gpt-image-2.5 and black-forest-labs/flux.2-pro. The Foundry page names GPT Image up to version 2 and Flux.2-Pro, not 2.5, and it describes Microsoft's own endpoints. It does not say what happens when a model is reached through a different provider.

Sume's docs say nothing about carrying, adding or stripping C2PA data, so I cannot tell you a Sume FLUX.2 Pro image has credentials. The two facts to hold apart are Microsoft's claim for Foundry and the absence of any Sume claim.

What to do with that

Microsoft also says customers are responsible for their own transparency obligations, which is the same conclusion from the other side: the model vendor's mark does not replace your disclosure. Sume's docs describe a metadata field on video, image and music jobs that Sume stores on the job and does not send to the provider. I found nothing in the docs about Sume adding, keeping or removing C2PA credentials, watermarks or platform labels, so treat that as undocumented and check the delivered file.

  • Do not repeat "it carries C2PA" in your own disclosure copy unless you inspected the delivered file.
  • Download one Sume output and check for credentials with a verifier; use the vendor's own tool where one exists.
  • Remember Microsoft's own caveat: provenance does not prove authorship or trustworthiness.
  • Disclose on the platform where you publish, because the platform's toggle is what viewers see.

Sources

Related posts

More in Models

All Models posts

Written by Sume