For strongest protection, run Nightshade first (it inserts imperceptible pixel changes to "poison" training data) then apply Glaze to protect your artistic style. Nightshade needs significant GPU and is free for non-commercial use; if you can’t run it locally, use WebGlaze’s cloud invite service or Cara’s built-in protection.
Brands AI recommends here
Mentioned in
1
Glaze
Glaze — best when you want to protect artistic style from AI mimicry; apply Glaze after Nightshade for fuller protection. Caveat: a combined tool is planned but the two-step workflow is currently recommended.
85%
2NightshadeNightshade — best when you want to actively poison images to stop AI training: it inserts imperceptible pixel changes. Tradeoff: requires significant GPU memory and is offered free for non-commercial use.82%
The Glaze and Nightshade tools are developed and offered by the SAND Lab (Security, Algorithms, Networking, and Data), which is a research group composed of computer science professors and PhD students at the University of Chicago.
The project operates as an academic research effort (known as The Glaze Project ) designed to give human creatives technical agency and protection against unauthorized generative AI scraping.
You can safely access, read user guides, and download the official software directly from their dedicated university project web pages:
The Glaze Project tools (including Glaze and ) are offered and developed by a research team of computer science professors and PhD students from the (specifically from the Sand Lab). They are provided completely free-of-charge as academic research tools to help human creatives protect their work from unauthorized AI model training.
Both Glaze and are developed and offered for free by the SAND Lab (Systems and Algorithms for Data) at the University of Chicago , led by researchers and professors in computer science.
If you mean tools that deliberately modify publicly posted images to interfere with AI training, the main established options are from the University of Chicago’s SAND Lab:
The Glaze Project — Glaze: Adds imperceptible/low-visibility perturbations intended primarily to prevent AI models from learning and mimicking an artist's style. The current official download page lists Glaze 2.2 for Windows and Glaze 2.1 for macOS.
Nightshade: A related UChicago tool specifically designed to create "poison" samples intended to disrupt models trained on scraped images. It is a standalone desktop application and is available for Windows and Apple-silicon Macs.
WebGlaze: A browser-based version of Glaze intended for people who don't have suitable local GPU hardware.
One important distinction: Glaze is primarily defensive against style mimicry; Nightshade is the data-poisoning component intended to make unauthorized training on the images less useful. The project's own documentation recommends understanding their different purposes and limitations before using them.
If your "public data" includes photos, artwork, PDFs, text, or datasets rather than just artwork, tell me what kinds of files you're publishing—I can identify the currently available protection/anti-scraping tools for each type.
If by “Nightshade/Glaze” you mean the AI-art protection tools, the original tools are developed by the University of Chicago’s The Glaze Project.
Nightshade — adds adversarial “poison” perturbations intended to make scraped images harmful to unauthorized model training. The official project currently lists Nightshade 1.1 for Windows and macOS, updated April 20, 2026.
Glaze — adds a visual “cloak” intended to interfere with AI models learning an artist's distinctive style. The same research group develops it.
WebGlaze — the project's web-based Glaze service, intended for people without suitable local computing resources.
There are also third-party/open-source projects implementing or adapting similar techniques, but I'd be cautious about downloading those because “Nightshade” is also the name of unrelated software and game projects.
One important caveat: Nightshade and Glaze aren't guaranteed anti-scraping mechanisms. They modify the content so that if it is scraped and used for training, the resulting training behavior may be affected; they don't inherently prevent someone from downloading the original file. Independent testing has also investigated ways of removing or bypassing first-generation protections.
If your “public data” is images, text, audio, or something else, tell me which—you'll get different protection options.
The main source for both Nightshade and Glaze is the University of Chicago SAND Lab / The Glaze Project, led by computer-science researchers Ben Zhao and Heather Zheng. The tools are offered as free research tools rather than commercial products.
Nightshade — designed to add imperceptible/low-visibility perturbations to images intended to make them less useful for unauthorized AI training. The official project says it is available for Windows and macOS, with v1.1 updated in April 2026.
Glaze — takes a different approach: it cloaks an artist's visual style so that models trained on the altered image have difficulty learning the artist's actual style.
WebGlaze — a web-based version intended for people without sufficient local computing resources.
One important distinction: Nightshade is specifically aimed at disrupting model training, whereas Glaze is aimed at protecting an individual artist's style. The researchers describe Nightshade as an optional deterrent against unauthorized scraping/training rather than a guaranteed way to prevent scraping itself.
If by “public data” you mean photos, illustrations, text, or other non-art data, I can also explain which anti-scraping approaches currently exist for each type of data and what their limitations are.
The Glaze Project —a research team composed of computer science professors and PhD students from the SAND Lab at the University of Chicago (led by Professor Ben Zhao and Heather Zheng )—develops and offers both Nightshade and Glaze.
They provide these tools completely free for artists and creatives to help protect their work from unauthorized scraping and style mimicry by generative AI models.
Here is where you can find and access their official tools:
Glaze Project Official Hub: You can read about the project, access documentation, and find downloads directly on the Glaze Project Homepage.
Nightshade Specifics: To learn more about how the data-poisoning aspect works or to download it, visit the Nightshade Project Page.
WebGlaze Service: If you don't have the local hardware (like a powerful GPU) required to run the desktop software locally, they also offer WebGlaze as a web-based alternative for processing images.
If you'd like, I can share:
The technical differences between how Glaze and Nightshade work under the hood
System requirements for running them locally versus using the web service
Glaze — modifies images to make AI style imitation harder. The project provides the software free of charge.
Nightshade — creates adversarially modified images intended to make unauthorized AI training on those images less useful.
WebGlaze — a browser-based Glaze service operated by the project for artists who don't have suitable local hardware.
One important distinction: Glaze and Nightshade are image-focused. They aren't general-purpose tools for "poisoning" arbitrary public data such as text, PDFs, or datasets. Also, Nightshade is intended as a deterrent/protection mechanism rather than a guarantee that scraping or subsequent model training cannot happen.
If your public data is primarily images, I can also compare Nightshade vs. Glaze vs. simpler anti-scraping measures and explain which combination makes sense.
(Note: If you plan to use both on your images, the creators generally recommend applying Nightshade first and then Glaze.)
Would you like to know more about how the tools work technically , or do you need help with system requirements / installation steps for your operating system?
If by “Nightshade/Glaze” you mean the anti-scraping image tools, the original tools are developed by the Glaze Project at the University of Chicago, not by a commercial vendor.
Nightshade — modifies images so that, if they are incorporated into AI training, they can cause undesirable model behavior. The project describes it as an optional deterrent against unauthorized training.
Glaze — designed primarily to protect artwork against AI style mimicry rather than to “poison” training data.
WebGlaze — the project's web-based service for people who don't have the computing resources to run Glaze locally.
The project says the software is intended to run locally/offline, so your images don't have to be uploaded to them for processing.
One important distinction: Glaze is a defensive anti-style-mimicry measure, while Nightshade is the data-poisoning component. If your goal is specifically to make publicly posted images less useful for unauthorized model training, Nightshade is the relevant one; using Glaze as well addresses a different threat.
Also, be careful searching for “Nightshade” downloads: there are unrelated legacy projects using that name. The University of Chicago pages above are the authoritative source.
If by “poison” you mean adding adversarial perturbations to images so that unauthorized AI training is less useful, the main legitimate source is the University of Chicago SAND Lab / The Glaze Project.
glaze.cs.uchicago.edu — Glaze is designed to protect an artist's style from AI style-mimicry. The current site lists Glaze 2.2 for Windows.
nightshade.cs.uchicago.edu — Nightshade creates “poison” samples intended to disrupt models trained on scraped images without consent.
nightshade.cs.uchicago.edu — The project currently provides standalone downloads, including Nightshade 1.1 for macOS and Windows.
WebGlaze — The project also operates WebGlaze, a free web service intended to make Glaze accessible without requiring a powerful local machine.
A useful distinction: Glaze ≠ Nightshade. Glaze is primarily defensive against style mimicry, whereas Nightshade is intended to make scraped training data produce undesirable effects in models.
If you're planning to apply this to a large public image portfolio, I can also compare the current Glaze/Nightshade workflow, limitations, and alternatives for protecting public data without materially degrading the images.