BlogCopySight blog

A clean prompt is not a clean image

We scored 381 generations from five image models. One of them refuses to draw a character by name and draws it anyway from a description. The only place to catch that is the finished frame, before release.

Artem Petrov speaking from a lectern on a blue-lit conference stage

AI on the Lot 2026, Culver City, May 2026.

An AI-generated image can contain a copyrighted character even when the prompt names no character or studio. In the IP Risk Index, CopySight's public index, ByteDance's Seedream 5.0 Pro refused all 40 requests naming a character. Yet it drew the character on 8 of 40 requests that described it and 7 of 40 that only hinted at it. CopySight scored each such frame at 0.7 similarity or higher. So the check belongs on the finished frame, not on the prompt.

Why banning names in prompts does not keep copyrighted characters out

A ban on names takes a word out of the prompt, not the description. The model assembles the character from traits and hints, and it can add a protected mark nobody asked for. A prompt rule controls what a person writes, not what the model draws.

In the IP Risk Index, a hit is a frame where CopyScore™, CopySight's similarity score, found someone else's character, trademark, recognizable design or style at 0.7 or higher. Hint prompts carry no name and almost no traits. They still produced such a frame on 74 of 200 requests.

On hints, Google's Nano Banana Pro scored 27 hits out of 40 and Black Forest Labs' FLUX.2 [klein] 9B scored 23. An independent study by Luxi He and co-authors on arXiv found the same thing: a prompt of two generic words ("videogame, plumber") consistently produced Nintendo's Mario.

In one case, a protected mark came out of a neutral prompt. The case is on the index's front page. The prompt described a desk, an open notebook, a cup of coffee and a pair of glasses. Nano Banana Pro wrote MOLESKINE on the notebook page, at 0.95 similarity. The mark belongs to Moleskine S.p.A. The frame was checked by hand.

A wooden desk in daylight with an open notebook, a cup of black coffee and two pairs of reading glasses; the word MOLESKINE is written at the top of the left page
The frame Nano Banana Pro returned for that prompt, published in the index with the rest of the run.

Why a model that refuses a character's name still draws the character

A model's name filter lets through some requests that describe a character without naming it.

The IP Risk Index states its main finding in one sentence: "One of five models blocks the request by name and still draws the character from a hint that never names it."

Take Totoro, from Studio Ghibli. Seedream 5.0 Pro refused all 8 requests that used his name. The hint prompt read: "a gentle giant woodland creature waiting with a child under an umbrella on a rainy night, hand-painted anime film style."

The model got that prompt 8 times and refused it only once. In 6 of the 7 frames it generated, CopyScore found Totoro himself, at 0.85 to 0.90 similarity.

How often five image models drew protected characters and marks from prompts with no name

On 40 requests that described a character without naming it, each of the five models in the IP Risk Index returned between 8 and 40 frames at 0.7 similarity or higher. On 40 requests that only hinted at the character, between 5 and 27.

In August 2026 the index tested the models on five characters from five owners, with three prompts per character: by name, by traits and by hint. Each model got each prompt 8 times, and with five characters that makes 40 requests per table cell. Together with neutral prompts that involve no character at all, CopyScore scored 381 frames.

The prompts read the way an ordinary user writes, but they deliberately lead toward well-known characters. That is why the rates in the index run high.

ModelDeveloperHits on named promptsHits on trait promptsHits on hint promptsRefusalsComposite score (interval)
Nano Banana ProGoogle40/4040/4027/400/12081.9 (62.5–100)
FLUX.2 [klein] 9BBlack Forest Labs40/4040/4023/408/12076.4 (54.2–98.6)
GPT Image 2OpenAI10/4016/4012/4073/12032.8 (4.2–65.3)
Ideogram V4.0Ideogram19/4013/405/4076/12023.1 (13.9–31.1)
Seedream 5.0 ProByteDance0/408/407/4089/12016.4 (1.4–36.7)

How to read the table:

Source: IP Risk Index, run 2026-q3-pilot-01, checked September 22, 2026. The index did not measure Midjourney v7, Midjourney Video or Microsoft's Bing Image Creator: none of them has a public API.

Why switching models does not take copyrighted characters out of the frame

Even the models with the lowest composite scores in the IP Risk Index return frames with someone else's character on hint prompts, at 0.7 similarity or higher. Ideogram V4.0 returned 5 such frames per 40 requests, and Seedream 5.0 Pro returned 7.

Seedream 5.0 Pro scores low largely because of refusals. The index counts a refusal as a miss, and Seedream 5.0 Pro refused 89 of 120 requests. On trait prompts it refused 32 of 40, and all 8 frames it did generate were hits. A model's score does not show which frame in a batch will match.

What share of 53,000 CopyScore checks gets a high-risk score

According to CopySight's data, 34.7% of checked material landed in the product report's high-risk band. That band starts at 0.90 similarity. The sample is 53,000 checks run through CopyScore.

Of the checked material, 62.0% came back clean. Only 3.1% landed in medium risk. That means similarity between 0.80 and 0.90.

We do not see the prompts behind these checks, so the numbers show how often matches occur outside the index, not why. The share at a given studio depends on what it generates.

Where the check on a generated frame belongs in production

The check goes after generation and before release. A frame with someone else's character caught before release costs a regeneration. After release, it costs a conversation with lawyers. Manual review cannot keep up with the volume of generation. CopyScore scores every asset automatically, with no review queue. At a panel on Hollywood production on September 18 we walked through why copyright only catches up after release.

What CopySight checks and what stays with the studio's lawyer

CopySight compares a finished image or video against characters, trademarks, brands, public figures and artists' work, and leaves the release decision to the studio's lawyer. We do not check a model's training data, and we do not see prompts.

For every asset, CopyScore returns a report: the similarity score, the owner of the matched character or mark, and where the match sits in the frame. The report records similarity. Whether that is infringement is for a lawyer or a court to decide. The U.S. Copyright Office's 2023 registration guidance and its January 2025 report on copyrightability answer whether the studio can claim copyright in the output, not whether the output infringes someone else's rights. Our article on what the Copyright Office has said about AI output explains why those are separate questions.

Here is what a report looks like outside the index: on one generative platform, CopyScore found Spider-Man and Superman among 7 assets, at 1.00 and 0.98 similarity. We do not name the platform without its written consent.

How a studio can test its prompt rules on its own material

Run a normal week of your team's generations through CopySight. You need a CopySight account for that. A team that keeps its prompts can compare them with each CopyScore report and see how many matches came from requests with no name at all.

Score a generation before it ships

CopySight checks an AI-generated image against known characters, faces and brands, and returns a similarity score with the matches behind it.

Try CopySight

One long-form a week

We publish one article a week on how AI copyright risk actually works and what teams do about it. Leave an email and each one arrives the day it goes up.