← All articles Guides

How to Protect Your Art from AI Scraping

No single tool stops AI scraping — but layers help: platform settings, Glaze and Nightshade, noai signals and sensible posting hygiene. An honest guide to what each defence actually does, and what none of them can.

· 4 min read

Let’s start where most guides end: nothing you can do makes your art un-scrapeable while it’s publicly viewable. If a browser can render it, a determined scraper can copy it. Anyone selling you a bulletproof solution is selling something else.

What you can do is raise the cost — make your work more trouble to scrape, less useful in a dataset, and harder to mimic — while keeping the visibility your art career actually needs. That’s a layered defence, and every layer is cheap. Here they all are, honestly labelled.

Layer 1: choose platforms like it matters (it does)

Where you post is the single biggest lever you control, because platform policy decides whether your uploads are handed to training pipelines by the platform itself.

The differences are stark: X trains Grok on public posts by default, Meta trains on public posts with limited opt-outs, while Cara auto-tags everything NoAI and ArtStation offers an opt-out tag written into its terms. artbase’s position is the simplest: member artwork is never used to train AI models — no toggle to find, nothing to opt out of.

We maintain a full, regularly updated breakdown of every major platform’s AI policy — if you read one companion piece to this guide, make it that one. And wherever you do post, spend the five minutes: turn on every NoAI tag, opt-out toggle and data-sharing restriction the platform offers. They’re imperfect (see Layer 3), but they’re free.

Layer 2: Glaze and Nightshade — the active defences

Two free tools from the University of Chicago’s SAND Lab do something none of the passive signals can — they change what a scraper actually gets:

  • Glaze protects against style mimicry. It applies perturbations, largely imperceptible to humans, that disrupt models attempting to learn or fine-tune on your personal style. Think of it as a cloak for the thing most artists fear most specifically: “generate an image in the style of [you]”.
  • Nightshade goes further and is offence-shaped: it alters images so they act as poisoned data, degrading models that train on them without consent. Its logic is herd immunity — enough shaded images in scraped datasets make indiscriminate scraping expensive.

The honest caveats: processing takes time, the perturbations can be faintly visible on some art styles (flat colour and clean linework show it more than painterly texture), and this is an arms race — countermeasures emerge, the tools update, repeat. Neither is a forcefield. Both meaningfully raise the cost of targeting you. Cara integrates Glaze directly, and you can run either tool yourself before uploading anywhere.

Layer 3: machine-readable “no” — robots.txt and noai

If you run your own site or portfolio domain, you can post the signs:

  • robots.txt — block known AI crawlers (GPTBot, CCBot, Google-Extended and friends) from your site. Reputable operators respect it.
  • noai / noimageai meta directives — page-level equivalents that some scrapers and datasets honour, popularised after DeviantArt introduced them.
  • Managed blocking — several hosting and CDN providers now offer one-click AI-bot blocking that filters known scrapers at the network edge, which is more enforcement than a text file can offer.

Every one of these is a request rather than a wall — a “please don’t” that ethical crawlers obey and bad actors ignore. Post the signs anyway: they cost nothing, they’re increasingly cited in terms-of-service and legal contexts, and they filter the compliant majority of crawler traffic.

Layer 4: posting hygiene

Old-fashioned, boring, effective:

  • Post at display resolution — enough to look great on screen, well below print quality. Scrapers get the small version; clients and print buyers get the real file from you directly.
  • Keep source files private. Layered files and print-resolution exports shouldn’t live at public URLs at all.
  • Watermark strategically if you watermark. A watermark across meaningful detail is a nuisance to remove; a corner signature crops out in seconds. Be honest with yourself about what it deters — casual reposting more than serious scraping. (For reposts and outright theft, we’ve written a separate step-by-step response plan.)
  • Label your process if you sell. Increasingly, buyers ask whether work is human-made; being verifiably consistent about it is becoming its own kind of protection — one reason labelling policies matter beyond ideology.

What this looks like in practice

A realistic setup for a working artist, ranked by effort:

EffortAction
5 minutesSet NoAI tags and opt-outs on every platform you use
30 minutesAdd robots.txt AI-crawler rules (or enable your host’s AI-bot blocking) on your own site
Ongoing, smallPost display-resolution only; keep source files offline
Per uploadRun Glaze on portfolio pieces you’d hate to see mimicked; consider Nightshade if you want to contribute to the deterrent
OncePick your primary platforms for their data policies, not just their audiences

Final thoughts

The goal isn’t to win an unwinnable technical war — it’s to be visibly, layered-ly inconvenient while staying visible, because invisibility costs an artist more than scraping does. Set the signals, run the cloaks on what’s precious, post at screen size, and put your work where the house policy is on your side.

That last layer is the one artbase was built to be: AI work labelled, viewers in control, and member art never used for training — not as a setting, but as policy. It’s open to everyone now.

Frequently asked questions

Does Glaze actually work to protect art from AI?

Glaze, from the University of Chicago's SAND Lab, adds small perturbations that disrupt style-mimicry fine-tuning, and research and real-world use show it raises the cost and lowers the quality of copying a specific artist's style. It is a meaningful obstacle, not a guarantee — the tools and the scrapers are in an ongoing arms race.

Can I remove my art from AI models that were already trained?

Practically, no. Once a model has been trained on an image, opt-outs and takedowns do not reach back into its weights. Everything in the protection toolkit — tags, cloaking, platform settings — is forward-looking, which is a reason to set defences up early rather than after a problem.

Do "noai" tags and robots.txt actually stop AI scrapers?

They are requests, not locks. Reputable crawlers honour robots.txt and noai directives, and some platforms write them into their terms of service, but nothing in the file technically prevents a scraper that chooses to ignore it. Use them — they are free and take minutes — but pair them with other layers.

Should I stop posting my art online because of AI scraping?

That is the one defence that certainly works and certainly costs too much. Artists grow through sharing — feedback, community and opportunities all come from being visible. A calmer approach is to post at display resolution with layered protections, on platforms whose policies you trust.

#ai#scraping#glaze#nightshade#protection