Next.js Discord

Discord Forum

next/image strips AI provenance metadata (C2PA / IPTC), a problem under the EU AI Act 🖼️ ⚖️

Unanswered
Great Black-backed Gull posted this in #help-forum
Open in Discord
Great Black-backed GullOP
Hey all! Since Aug 2, 2026, the EU AI Act (Art. 50) requires AI-generated images to carry a machine-readable marking. That means a C2PA manifest (Content Credentials) and/or IPTC DigitalSourceType in XMP.

The good news: the big models already do this. Google, OpenAI, FLUX, Seedream and Firefly all output images with signed C2PA.

The bad news: next/image throws it all away 😬
• The optimizer resizes with sharp without keeping metadata, so C2PA, XMP and EXIF are all gone
• There's no images config option to change that
• On Vercel, /_next/image runs on Vercel's own service, so patching Next doesn't help in prod
• Even sharp().keepMetadata() keeps XMP but not C2PA, and a resized image would break the signature anyway

So right now the choices are unoptimized (bye bye performance) or building and securing your own resize pipeline. Cloudflare Images and Fastly already solve this by passing the C2PA manifest through and re-signing it after the transform. It'd be great to have the same in Next/Vercel.

Questions for the community:
1. Is anyone else hitting this? How are you handling it?
2. Has anyone built a clean custom loader that writes XMP or keeps Content Credentials?

If this affects you too, please 👍 / comment on the GitHub discussion so it gets more visibility:
👉 https://github.com/vercel/next.js/discussions/39249

0 Replies