Skip to content
Make AI Good

Graph · Strategy

Distribute user-side technical countermeasures against AI

01 · In focus

One strategy, in the field.

The structured facts the source records about Distribute user-side technical countermeasures against AI, the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.

strategy

1 declared connection

Kind
Strategy
Status
active
Confidence
medium
Entity ID
strat-distribute-user-side-technical-countermeasures
Network
View in network

Tags glaze, nightshade, adversarial-perturbation, anti-scraping, user-tooling, technical-resistance, defensive-tools, opt-out, arms-race, do-not-train, consent-layer

Distribute user-side technical countermeasures against AI · 1 direct neighbour visible

02 · Connections

1 adjacency, by relation.

Split by direction. Direct links are the ones Distribute user-side technical countermeasures against AI’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.

Inferred backlinks

1 link

Other records that name this entity.

03 · Background

From the source record.

Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.

Researchers and small developer teams build and release tools that an individual can install or apply to defang a specific AI use against them: image perturbations that poison or confuse generative models trained on the user's art (Glaze, Nightshade), browser extensions that block scrapers, audio watermarks that survive synthesis, anti-deepfake provenance signing, hidden-prompt injection on resumes that hiring tools read. The work is distributed free or near-free, optimised for usability by non-technical users, and treated as an ongoing arms race rather than a one-shot release.

An actor chooses this strategy because regulation and litigation operate on a multi-year cycle while AI systems are deployed against people now, and a working tool delivers the protective effect immediately without waiting for any institution to act. The strategy also moves the cost of opting out off the user — for whom it is currently prohibitive — and back onto the AI system, which must invest in defeating each countermeasure, slowing the rate at which extraction becomes economic. It is one of very few strategies in which a small, well-placed technical team can produce a result the largest advocacy organisation cannot match.

It trades durability for immediate effect. Every countermeasure has a finite lifespan against a well-funded adversary willing to retrain or recompute around it, and the strategy risks entrenching a frame in which protection is the individual's burden rather than a public responsibility. Maintenance cost accumulates quickly — a tool that worked last year against last year's models may not work this year — and a movement that overinvests in this strategy can end up subsidising an arms race the larger industrial party always eventually wins.

Verdict — fast individual relief, structurally outside the corpus's organisational substrate

User-side technical countermeasures are the strategy in the corpus that ships protective effect at the user-installation horizon the rest of the movement's arms cannot match — Glaze available for download three months after the December 2022 Stability AI commitment, the Do Not Train registry accumulating 78 million opt-outs by March 2023, the Have I Been Trained search interface live within weeks of the LAION-5B scrape becoming a public concern in mid-2022. The four effects: above are typical of what the strategy returns to the movement: a mass individual-adoption number on a movement-affiliated tool (Glaze at more than 6 million downloads), a frontier-image-model developer accepting a movement-built registry as the binding interface between artist consent and a training run (Stability AI's December 2022 commitment), a cross-platform individual-action opt-out cycle reaching approximately 78 million artworks against a single training run (the March 2023 Spawning report), and the strategy's working evolution from defensive opt-out to constructive opt-in inside the same eighteen-month cycle (Source.Plus and Public Diffusion / PD12M in June 2024).

The strategy is strong at the individual horizon, structurally weak as the organisational form of the movement.

Strong on its primary claim — that a small technical team can produce a protective effect at the user-installation horizon the legislative and litigation arms cannot match. The pipeline from Karla Ortiz's documented prompt to the SAND Lab ("I would love a tool that if someone wrote my name and made a prompt, garbage came out") through the March 2023 Glaze release to the November 2024 six-million-download figure is shorter than any of the corpus's legislative arms have managed on the same training-data-consent question — the EU AI Act's training-data transparency provisions cleared trilogue in December 2023 and entered into force in August 2024, the Andersen v. Stability AI trial is scheduled for September 2026, and the Authors Guild's twelve-case consolidated proceeding has not yet reached merits. The user-side technical arm shipped a measurable protective layer to millions of artists in a window in which every other arm of the movement was still building the apparatus that would later carry its claim. The strategy's directness — between the artist's harm and the tool that defangs it — is the corpus's clearest case of refusal-as-engineering rather than refusal-as-advocacy.

Weaker on its secondary claim — that the strategy's success generalises beyond its founding constituency or carries political weight beyond the user-installation horizon. The visual-artist case is the only case in which the strategy has shipped at mass-adoption scale on the public record this corpus tracks, because the visual-artist case has a discrete artefact (the image file) on which an adversarial perturbation can land and a discrete search index (LAION-5B) against which an opt-out registry can match. The voice-actor, the gig-economy worker, the casual social-media user, and the journalist whose archive backs a news-publisher licensing deal have no equivalent user-installable tool because their labour is not a discrete artefact the perturbation apparatus can wrap. The strategy generalises to the visual-artist case and stops; outside that case the apparatus does not exist, and the rhetorical reach of the data-dignity argument the tools carry has run further than the tools themselves.

The deepest structural problem is the organisational-substrate gap, addressed at length in the counter_read: above. The two operators that ship the corpus's leading countermeasures — Spawning AI for Have I Been Trained, Source.Plus, and Public Diffusion; the SAND Lab at the University of Chicago for Glaze and Nightshade — sit outside the corpus's organisational substrate of Concept Art Association, Authors Guild, WGA, SAG-AFTRA and adjacent sectoral organising vehicles. CAA commissioned Glaze via Ortiz's working partnership with Ben Zhao and propagates the "Have I Been Trained?" framing through Ortiz's Senate testimony and FTC roundtable appearances, and CAA's own model contract rider (a contractual, not technical, user-side opt-out) is the closest movement-organisation-built artefact in the strategy's vicinity — but the technical builders themselves are a small startup and an academic research lab, neither of whose continued operation, posture, or financial runway is governed by movement-organisation accountability mechanisms. The strategy's mass-adoption layer is carried by the corpus's organisations and built by actors structurally outside them, and the operator-concentration risk this produces is the strategy's most consequential vulnerability at the organisational scale at which the rest of the movement's arms operate.

Ecology

The strategy is paired with creator-class collective bargaining on generative AI as the immediate-action layer behind the slower contractual-and-litigation track. The same adopters (Ortiz, the Concept Art Association, the visual-artist plaintiffs in Andersen v. Stability AI) operate both arms in parallel: the Have I Been Trained? registry collected 78 million opt-outs before the WGA Article 5 ratification, Glaze shipped six months before the SAG-AFTRA five-category digital-replica regime, and the Stability AI Do Not Train commitment landed seventeen days before the Andersen class-action complaint. The two strategies serve the same constituency at different cycle times — the contractual arm produces enforceable claims at multi-year horizons, the technical arm produces a protective tool at the user-installation horizon — and the bargaining arm's Consent, Credit, Compensation, Transparency framing is in part doing the public-affairs work of legitimating the technical arm's individual-installation register at the policy level. They are working sisters; the technical arm without the bargaining arm is a tool with no public-rule shadow, the bargaining arm without the technical arm is a multi-year wait an artist working today cannot rely on.

It is fed by counter-narrative framing through the "Have I Been Trained?" framing the Spawning AI tool's own name fixed in September 2022 — the question-as-framing that made unconsented training-data ingestion legible at the level of the individual artist's dignity and supplied the registry's argumentative anchor. The frame's installation in U.S. federal-policy and creative-industry discourse (Ortiz's Senate Judiciary testimony of 12 July 2023; the FTC Creative Economy roundtable of 4 October 2023; the bargaining arm's 3 Cs and a T formulation) is what produced the public-affairs ground on which the registry's 78-million-artwork uptake stood; the technical arm without the framing arm reaches the artists who already know the tool exists and stops, and the framing arm without the technical arm produces a slogan that names a problem the movement cannot offer an immediate answer to.

It is fed by empirical audit and expose of deployed AI systems at the founding-incident horizon: the first headline find that Have I Been Trained produced in late September 2022 — a patient discovering private medical photographs of herself inside LAION-5B within days of the tool's launch — is itself a participatory audit of the open scrape that anchors Stable Diffusion, and it is the founding evidentiary artefact that fixed the dignity-harm argument behind the framing. The tool is both a countermeasure (the registry produces an opt-out) and an audit instrument (the search produces an answer to the question "am I in there?") at the same time; the dual nature is why the strategy lands so quickly in the public-affairs cycle — the user who searches the tool to use it also runs an audit on their own behalf, and the auditable answer is what gives the registry the moral force of an empirical finding rather than only a refusal.

It runs in parallel with class-action litigation against private AI as the immediate-effect arm against the same defendants. The Andersen v. Stability AI class action and the Stability AI Do Not Train commitment are pressures on the same actor running on different cycle times — the litigation arm produces a judicial outcome at multi-year horizons (the Andersen August 2024 motion-to-dismiss ruling is the strongest case the strategy has produced so far, and the trial sits in September 2026), the technical arm produced an immediate corporate concession three weeks before the complaint was filed. The two arms run as complementary pressures rather than substitutes: the litigation arm establishes the doctrinal precedent that a movement-built consent layer can be enforced if the developer refuses to honour it; the technical arm operates the consent layer the doctrine would protect.

The strongest competing strategy on the AI-developer side is the licensed-corpus and consent-layer counter-offer in which the frontier-AI developers and adjacent commercial-distribution partners build their own consent-and-licensing apparatus before the movement's tools become structurally indispensable — Adobe Firefly's curated-corpus training, OpenAI's news-publisher licensing deals, Anthropic's Bartz settlement, the news-publisher and stock-image opt-out and licensing schemes that have proliferated since 2023. Each is an attempt by the developer to absorb the consent-layer function the movement's tools provide into the developer's own commercial apparatus, on terms the developer can price into the model's economics and structure to favour its largest licensable counterparties. The strategy's strongest hedge against the counter-offer is the same hedge the bargaining arm leans on — the under-organised tier of the creative workforce that the licensing apparatus cannot reach — but the technical arm's specific vulnerability is that Spawning AI's own Source.Plus and Public Diffusion pivot has already moved partway into the licensing register the counter-offer is built on. The movement's leading consent-layer operator is now also a licensable counterparty, and the boundary between the movement's countermeasure apparatus and the developer-side licensing apparatus is no longer the clean refusal posture that the September 2022 launch began with.

Source: entities/strategies/strat-distribute-user-side-technical-countermeasures.md — movement-graph pin 5d136ad.