A New Type of Varnish: Nightshade, Glaze, and Artists’ Battle with AI
September 12, 2026
Gerardo Cibo, Nightshade, colored drawing 1564-1584, photographed by the British Library
By Hannah Gadway
As AI-generated images flood the Internet, protecting original art from illicit copying can seem like a daunting task. While some AI models allow artists to “opt-out” of their work being used in training sets, this assumes that all artists are automatically opted-in, even without consent.[1] Artists also stand at a crossroads in terms of the legal status of AI models’ use of copyrighted images. Dozens of American lawsuits are pending surrounding the application of copyright’s fair use doctrine to AI.[2] While waiting for results, artists are afraid to post their work online, lest it get mined into AI systems.[3] On top of these issues, AI-generated art is affecting artists’ job market.[4] As the U.S. Copyright Office explains: “[t]he stakes are high.”[5]
While artists wait for the law to catch up, some are finding that technological tools of their own may provide a solution. With the help of researchers at the University of Chicago, artists have adapted to the technological age by digitally “varnishing” their artworks with programs that either defend against AI mimicry or poison models directly.
Artists on Offense and Defense: Glaze and Nightshade
In facing generative AI, artists enter a realm that is legally complicated. Models don’t often spit out exact replicas of the work in their training datasets, which could be easily identified as copyright infringement. Instead, AI models tend to engage in style mimicry. Style mimicry is aided by AI models’ ability to group an artist’s work into “feature spaces.”
Feature spaces are created like this: trained AI models, using millions of images, map specific images to representations associated with a certain word.[6] For example, there could be a feature space linked with the word “Monet,” attached to hundreds of Claude Monet paintings housed within the model. When prompted to create an image in the style of Monet, an AI model would draw from the artist’s corresponding feature space to synthesize repeated patterns. This allows a model to directly copy an artist’s recurring style, even if its output doesn’t exactly replicate a pre-existing artwork.
In order to pursue legal recourse from this type of copying, an artist must demonstrate that an AI-generated image is substantially similar to their training set artwork.[7] This type of claim is currently being litigated in the Northern District of California in the case Andersen v Stability AI. Andersen is set to go to trial in September of 2026, but in the meantime, many questions remain regarding how similar an AI image must be for a copyright infringement claim and the extent to which generative AI falls under fair use.[8]
This is where technology may be able to help artists. Take Glaze for example, a free program designed by computer science professors and PhD students from the University of Chicago.[9] Glaze is a type of invisible digital varnish which can be applied to artworks posted online.
Glaze works by disrupting style mimicry at its roots. When applied to an image, it makes a generative AI model think that an artist’s art style is in a very different location than the artist’s actual feature space. It does this by running an algorithm over the images which alters low-level pixels that distort AI models’ ability to manage the artist’s images.[10] The goal is to push the style far away enough from the artist’s actual style that if a prompter asks for an image in the style of Monet, it instead generates something in the style of Picasso or Warhol. Like an eye glazing over an image, a generative AI model will be unable to correctly identify an artist’s unique look.
Glaze is simply defensive, helping artists avoid style mimicry of their specific works. Others may want to counteract models’ taking of art in the first place — or take an offensive stance against AI-generated images.
This is where Nightshade, another program by the same University of Chicago team, plays a role.[11] Nightshade does not protect against style mimicry; its goal is to “poison” AI models’ datasets when an artist’s image is used without their permission. Instead of shifting work into a new feature space, Nightshade makes an image look completely different for AI models, which disrupts models’ ability to create coherent outputs.[12] When applied, it could make a Monet painting of trees look like a group of soda cans, or anything else it wants it to look like.
Art Law Conference 2026: Ben Zhao, Founder of Nightshade and Glaze, on AI Mimicry

On May 27th, 2026, the Center for Art Law was grateful to host Ben Zhao, Neubauer Professor of Computer Science at the University of Chicago and the founder of Nightshade & Glaze, for the keynote address at its 2026 Art Law Conference. Professor Zhao has been the technical AI witness in key legal cases like Bartz v. Anthropic and Authors Guild v. Open AI. His software has been used in over 170 countries, with a combined total of over 13 million downloads.[13] In his address, Professor Zhao explained how he began fighting against generative AI and why tools like Glaze and Nightshade matter for artists.
Professor Zhao has years of experience fighting against unauthorized data scraping. Before starting on Glaze and Nightshade, Zhao worked on protecting personal privacy, developing Fawkes with the University of Chicago’s SAND Lab. Fawkes applied pixel-level changes to personal photos to “poison” facial recognition models attempting to scan internet users’ faces without permission.[14]
In June of 2022, while working on Fawkes, an artist contacted Zhao to ask about the viability of applying his technology to artworks. At first, he was puzzled why artists needed specific help. Then he started attending artists’ digital town hall meetings focused on the negative effects of AI.[15] He did additional research, learning about artists like Kelly McKernan, who had fifty of her paintings scraped into the LAION-5B database without her permission or any credit.[16] He was startled to see that artists’ entire bodies of work were quickly being turned into prompts.
In March of 2023, Professor Zhao accordingly released an initial version of Glaze, and by August of the same year released a paper on how his technology could protect artists against AI mimicry.[17]
Beyond establishing Glaze and Nightshade, Professor Zhao also studied AI’s effect on artists. After conducting a study featuring over 1,200 professional artists in January of 2023, Zhao’s team found that AI mimicry led to a tangible disruption of artists’ livelihood.[18] Artists reported that AI mimicry resulted in the halt of posting art online, alongside personal feelings of anguish and hopelessness.[19] The study also found that this trend demoralized art students and correlated with shrinking art class sizes.[20]
Zhao specifically criticized those in the tech world insisting that AI “democratizes” art.[21] He illustrated the point with an example: even if one sees a woman walking down the street and likes their purse, he wouldn’t “democratize” that purse by stealing it.[22] “There are rules and there are reasons that we have those rules,” he explained.[23] Nightshade and Glaze are here to keep rules against stealing art in place.
The Battle Goes On
Just like any tools, Nightshade and Glaze are not perfect. Although it is difficult to remove the programs from an image (screenshotting a work does not remove Nightshade, for example), they can be worked around in other ways.[24] Nightshade’s website directly states that it is “unlikely to stay future proof over long periods of time.”[25] Some researchers find that image upscaling and other simple techniques are enough to eradicate Glaze’s protections.[26] Specific programs like LightShed also claim to be able to “depoison” Nightshade and other copyright protections.
Professor Zhao’s programs are also not the only tools working to protect artists from AI-generated images. Other programs like Mist act as adversarial filters against AI-generated art.[27] Artists are also working together to resist the spread of AI artwork, using social media sites like Cara which block AI-generated images.
Additionally, while tools help temporarily, legislation aimed at the ills of generative AI may be the most effective long-term solution. Even that may face obstacles, though; Professor Zhao warned at the 2026 Art Law Conference that legislators should be aware of the unique features of generative AI. For example, he stated that attribution in generative AI models is often not meaningful, since there are thousands of images which may contribute to one output.[28] In Professor Zhao’s view, legislation geared toward AI must be built on a solid understanding of what artists actually want out of the law.
Even if Nightshade and Glaze are not singular nor infallible, their popularity signals that artists are willing and eager to fight against unauthorized copying of their work for AI models. Technology can be beneficial for artists, despite being destructive in some contexts.
Nightshade and Glaze are helpful, even if they are not the panacea for the larger problem of AI-generated art. How long artists will have to keep fighting technology-aided battles with AI is left up to how the law will evaluate models’ status in the world of copyright. Still, in the meantime, Nightshade and Glaze give artists a way to fight back.
About the Author:
Hannah Gadway is a student at Harvard Law School and a Summer 2026 legal intern with the Center for Art Law. She graduated from Harvard College in 2025, where she majored in History & Literature. She has art history experience from working at the Harvard Art Museums. Hannah is interested in art law-related questions concerning museum provenance and the Internet.
Suggested Readings:
- Chen Zhu, Double Glazed: Taking Artists’ Rights Seriously and Algorithmically, UNIV. OF BIRMINGHAM INST. OF ART & L. (2024)
- U.S. Copyright Office, Copyright and Artificial Intelligence Part 3: Generative AI Training (2025)
- Thomas A. Hemphill, Copyright protection, artistic imagery, and the adoption of responsible artificial intelligence principles, J. OF ETHICS IN ENTREPRENUERSHIP & TECH (2024)
- CONFERENCE LINK WHEN AVAILABLE
Select References:
- Thomas A. Hemphill, Editorial: Copyright protection, artistic imagery, and the adoption of responsible artificial intelligence principles, J. OF ETHICS IN ENTREPRENUERSHIP & TECH (2024), accessible at https://www.emerald.com/jeet/article/4/1/2/1218086 ↑
- U.S. COPYRIGHT OFFICE, Copyright and Artificial Intelligence Part 3: Generative AI Training (2025) at 1, accessible at https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-3-Generative-AI-Training-Report-Pre-Publication-Version.pdf. ↑
- Will Douglas Heaven, What comes next for AI copyright lawsuits?, MIT TECH REV. (2025), accessible at https://www.technologyreview.com/2025/07/01/1119486/ai-copyright-meta-anthropic/. ↑
- Artists face steep income decline due to AI, UNESCO finds, UN NEWS (2026), accessible at https://news.un.org/en/story/2026/02/1166989. ↑
- U.S. COPYRIGHT OFFICE, supra note 2. ↑
- Burr H. Settles, Feature Spaces, UW-Madison (2003), accessible at https://pages.cs.wisc.edu/~bsettles/cs540/lectures/16_feature_spaces.pdf. ↑
- Chen Zhu, Double Glazed: Taking Artists’ Rights Seriously and Algorithmically, UNIV. OF BIRMINGHAM INST. OF ART & L. (2024) at 3, accessible at https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5208735. ↑
- Zach Schor, Andersen v. Stability AI: The Landmark Case Unpacking the Copyright Risks of AI Image Generators, N.Y.U. J. INTELL. PROP. & ENT. L., accessible at https://jipel.law.nyu.edu/andersen-v-stability-ai-the-landmark-case-unpacking-the-copyright-risks-of-ai-image-generators/. ↑
- About the Glaze Project, UNI. CHICAGO SAND LAB (2026), accessible at https://glaze.cs.uchicago.edu/aboutus.html. ↑
- What is Glaze? , UNI. CHICAGO SAND LAB (2026), accessible athttps://glaze.cs.uchicago.edu/what-is-glaze.html. ↑
- What is Nightshade?, UNI. CHICAGO SAND LAB (2026), accessible athttps://nightshade.cs.uchicago.edu/whatis.html. ↑
- Id. ↑
- CENTER FOR ART LAW, Art Law Conference 2026 (Youtube, May 27, 2026) , How to Use the Wayback Machine (YouTube, Jan. 13, 2021) at 11:14. (Recording available to Premium Members) ↑
- Image “Cloaking” for Personal Privacy, UNI. CHICAGO SAND LAB (2022), accessible athttps://sandlab.cs.uchicago.edu/fawkes/. ↑
- https://people.cs.uchicago.edu/~ravenben/publications/pdf/glaze-usenix23.pdf ↑
- CENTER FOR ART LAW, supra note 12 at 15:40 ↑
- https://people.cs.uchicago.edu/~ravenben/publications/pdf/glaze-usenix23.pdf ↑
- CENTER FOR ART LAW, supra note 12 at 19:45 ↑
- Id. ↑
- Id. ↑
- Id. at 17:30 ↑
- Id. ↑
- Id. at 18:40 ↑
- What is Nightshade?, supra note 10 ↑
- Id. ↑
- Robert Hönig, Adversarial Perturbations Cannot Reliably Protect Artists From Generative AI, CORNELL ArXiv (2025), accessible at https://arxiv.org/abs/2406.12027. ↑
- Chumeng Liang, Mist: Towards Improved Adversarial Examples for Diffusion Models, CORNELL ArXiv (2023), accessible at https://arxiv.org/pdf/2305.12683. ↑
- CENTER FOR ART LAW, supra note 12 at 32:00 ↑
Disclaimer: This article is for educational purposes only and is not meant to provide legal advice. Readers should not construe or rely on any comment or statement in this article as legal advice. For legal advice, readers should seek a consultation with an attorney.
You must be logged in to post a comment.