Nu deținem și nu accesăm datele niciunui utilizator și nu suspendăm conturi decât dacă o autoritate legală impune o acțiune de executare.
Research · Positioning

Uncensored vs Filtered AI Image Generator

Content filters were built to stop a small set of real harms. In practice they also stop medical illustration, forensic reconstruction, life drawing, war history, editorial satire and companies picturing their own products. This is what that costs — and what removing the filter does and does not change.

Published September 5, 2026ResearchShannon Lab LLC

TL;DR

Mainstream image generators screen prompts and outputs with classifiers that see words and pixels, never purpose. That guarantees false positives, and they land hardest on skilled work: anatomy, forensics, art nudes, historical imagery, pre-visualization, satire, security-awareness material, and rights-holders asking for their own brand. OVERT (ICML 2025), the first large-scale benchmark for this failure mode, uses 4,600 benign-but-suspicious prompts and finds over-refusal is widespread across leading models. Shannon runs image generation, single-image editing and multi-image combination on our own GPU cluster with no content filter and no refusal layer, replacing the blocklist with a visible decision: a confirmation card showing the exact prompt before anything renders. That raises your responsibility and ours; both are in the Responsible Use Policy. There is no video generation, and image work lives in the chat app, not the API.

Almost everyone who works with images professionally has the same story. A prompt describing something ordinary — a cross-section of a knee joint, a car at the moment of impact, a figure study in charcoal, a soldier in 1944 — comes back as a policy violation. You rephrase, and get a different violation. Eventually you write something vague enough to pass, and get an image that no longer shows what you needed. The tool did not fail loudly; it failed by degrees, and made you the one who compromised.

01Why does an AI image generator refuse a prompt that is clearly legitimate?

The refusal is usually not the image model's opinion. It is the output of a filtering stack around the model, and its layers explain almost every strange refusal you have received.

LayerWhat it inspectsCharacteristic failure
Prompt blocklistLiteral strings and near-variants in your textBlocks a word regardless of the sentence around it — "speculum" fails, "stethoscope" passes
Prompt classifierA learned judgment of the prompt's "risk"Fires on topic proximity: anything near medicine, weapons, bodies or politics scores high
Model refusal trainingThe model's own trained reluctanceRefuses without an error, or quietly produces a sanitized substitute
Output classifierRendered pixels, with no prompt contextCannot tell an anatomy plate from pornography, or a film still from a real event
Policy substitutionSilent rewriting of your prompt before renderingYou get an image, but not the one you specified, and you are not told why

Every layer shares one blind spot: none can see why you are asking. A medical illustrator, a plaintiff's expert reconstructing a collision, and someone with bad intentions all type the same noun. The filter sees the noun, not the atlas or the case file, and it is graded on the harms it lets through — never on the work it destroys. Under that asymmetry, the rational setting for any operator is refuse more. It is also why "just rephrase it" is not a fix: rephrasing gives the filter no information it lacked, it only moves your prompt away from the words that tripped it, which usually means away from what you meant.

02What content filters are genuinely there to prevent

An argument for unfiltered generation that pretends filters exist for no reason is not worth reading. There is a narrow set of outputs whose harm is intrinsic to the image itself, independent of who asked or why:

  • Sexual content involving minors. No context makes it acceptable; no professional workflow requires it.
  • Non-consensual intimate imagery of real people. The harm lands on someone who did not agree, and a takedown does not undo it.
  • Targeted harassment and defamatory fabrication — making a named individual appear to have done something they did not.
  • Forgery-grade documents — passports, identity cards, banknotes, seals and financial instruments made to pass as genuine.
  • Deceptive synthetic evidence — fabricated imagery of real events presented as documentation rather than illustration.

The list is short and it has a structure: the harm lives in the artifact, in its resemblance to a real person or document, and in its presentation as truth. Notice what is not on it — nudity, blood, weapons, historical atrocity, political ridicule. Those are the raw material of medicine, journalism, art, forensics and satire, and a filter that treats them as harm categories is implementing a much broader idea about which subjects are respectable.

Shannon prohibits everything in that list, in a published Responsible Use Policy with named categories and consequences, rather than a keyword table that also catches "placenta." One is a rule you can read and hold us to; the other is a guess about your intentions by a classifier you cannot see.

03How big is the over-refusal problem? What the research measures

Until recently, over-refusal in image models was an anecdote — thousands of people with the same story and no way to size it. That changed with OVERT (OVEr-Refusal evaluation on Text-to-image models), presented at ICML 2025 by a UC Berkeley group including Ziheng Cheng, Somayeh Sojoudi, Xuandong Zhao, Dawn Song and Song Mei: the first large-scale benchmark measuring how often text-to-image systems refuse prompts that are entirely benign.

4,600
Benign prompts
9
Safety categories
1,785
Harmful controls
ICML
2025

The design matters. The 4,600 prompts are built to look harmful while being harmless — the shape of a real professional request mentioning a scalpel, a bruise or a protest — and the 1,785 genuinely harmful prompts sit alongside them as a control, so a model cannot score well by refusing everything. The nine categories run from individual and public-figure privacy through copyright, discrimination, self-harm, sexual content and illegal activity to violence.

The headline finding is that over-refusal is widespread across categories and across leading models. The second is more damaging to the standard workaround: the authors tested prompt rewriting as a mitigation and report it "often compromises faithfulness to the meaning of the original prompts." You can get past the filter by changing what you asked for, and then you no longer have what you asked for.

A narrower study reaches the same conclusion from the pixel side. In An Art-centric perspective on AI-based content moderation of nudity (Riccio, Curto, Hofmann and Oliver, AI4VA workshop at ECCV 2024), the authors evaluate three production NSFW classifiers on artistic nudity and uncover both a gender bias and a stylistic bias: the verdict on a figure study depends on whose body is depicted and in what style. That is a measured statement of the thing every life-drawing artist has been told is imaginary.

04Eight kinds of legitimate work that filtered generators block

These are the categories where over-refusal is not an inconvenience but a work stoppage. Where a specific reported case exists it is cited; where none was verified, the category is described without inventing an incident.

1. Medical and anatomical illustration

The best-documented case in the field. In April 2023, The Intercept (Debbie Nathan) reported that Midjourney had banned anatomical terms including speculum, placenta, cervix, vulva, fallopian tubes, mammary glands, uterine, urethra, hymen, sperm, condom and IUD, while DALL·E 2 refused "pills used in medication abortion" with a content-policy message. The pattern was found by Julia Rockwell, a clinical data analyst who had tried to generate a picture of a placenta as a gift for a cell-biologist friend, and reported to MIT Technology Review. The asymmetry is the tell: "stethoscope" generated normally while "speculum" was prohibited. University of Washington researcher Bill Howe called the filters "ham-fisted" and said they made it "basically impossible to have a scientific discussion about reproduction." Patient education, surgical atlases and nursing curricula all need bodies depicted accurately, including the parts a keyword list has decided are indecent.

2. Forensic and accident reconstruction

Collision reconstruction, fire-origin analysis and courtroom demonstratives require depicting damage, wounds and violent mechanics with clinical accuracy. A filter tuned to reject "blood" or "gunshot wound" rejects the discipline: the context — an expert report, an insurance file — is invisible to the classifier, and the very neutrality that makes such imagery admissible is what makes it read as gore.

3. Art nudes and life drawing

The nude is a foundational subject of art everywhere, and figure study is core to art education. The ECCV 2024 result above is the measured version of what artists report: classifiers do not reliably separate a figure study from pornography, and their errors are biased by gender and style — a filter hardest on exactly the tradition it should recognize.

4. Historical and wartime imagery

Textbook art, museum interpretation and memorial projects require depicting uniforms, weapons, camps, battles and atrocity. The February 2024 Gemini episode is instructive because the failure ran in the opposite direction and did equal damage. Google paused Gemini's ability to generate images of people on February 22, 2024 after it produced racially recomposed depictions of historical groups including Nazi-era German soldiers. CEO Sundar Pichai called the outputs "completely unacceptable"; SVP Prabhakar Raghavan acknowledged the model had "overcompensated" and become "over-conservative." Context-blind safety did not make historical imagery safer — it made it false, which for a history publisher is worse.

5. Violence in fiction and film pre-visualization

Storyboards, concept art, comics and game design depict violence for the same reason novels and films do. A filter that cannot tell a horror storyboard from a threat treats the whole narrative-arts pipeline as suspect — though a storyboard is explicitly non-real, a plan for a scene actors and effects teams will stage.

6. Political satire and editorial cartooning

Caricature of the powerful is among the most protected categories of speech in most democracies, and routinely the first thing an image filter removes. The clearest documented case is Midjourney's April 2023 decision to bar images of Chinese President Xi Jinping and block his name in prompts — reported by PetaPixel, Decrypt and others — while continuing to permit other world leaders. Founder David Holz explained on Discord that the company wanted to "minimize drama" and that "the ability for people in China to use this tech is more important than your ability to generate satire"; Sarah McLaughlin of the Foundation for Individual Rights and Expression called it censorship. Whatever one concludes about the business calculus, the mechanism deserves naming: a national speech restriction applied to every user worldwide, because a global filter has one setting.

7. Security research and phishing-awareness material

Security teams build training material that has to look like the thing it warns about: a convincing fake login screen, a spoofed invoice, a malicious QR code on a parking meter. To a classifier that is indistinguishable from the attack it inoculates against — verisimilitude is the point — so filters block defense and offense identically, advantaging the attacker, who was never going to use a filtered consumer tool anyway.

8. Rights-holders refused images of their own brand, product or likeness

Copyright and trademark filtering does not check ownership; it checks resemblance. A company cannot easily generate imagery of its own logo or product, a rights-holder cannot picture its own character, and people frequently cannot generate their own face, because likeness filters key on recognizability rather than consent. OVERT includes "copyright violations" among its nine over-refusal categories precisely because this false positive is so common. The filter is a blunt instrument for a question — do you have the right to this? — it has no way to ask.

Four of the eight above are anchored to a specific published case (medical, art nudes, historical, satire) plus OVERT's copyright category for the eighth. Forensics, fiction pre-visualization and security-awareness material are stated as categories: they are well-known classes of affected professional work for which we did not verify a specific published incident.

Check the primary sources

Every documented case above is public and independently verifiable. Read them rather than taking our characterization on trust.

05Why AI art generators block the wrong things, and why content filter false positives cannot be tuned away

The instinctive response to over-blocking is "loosen the threshold." It does not work, for structural reasons rather than a lack of effort.

The categories overlap in the signal but not in reality. A surgical illustration and pornography share nudity. A forensic reconstruction and gore share blood. An awareness slide and a phishing kit share a fake login form. A satirical cartoon and a defamatory fabrication share a recognizable politician. What distinguishes each pair is purpose and presentation — absent from the prompt and absent from the pixels. No threshold separates two populations occupying the same region of the input space; moving it only trades one error for the other. That is what the Gemini episode showed: an intervention meant to fix one failure produced another, described by Google's own SVP as "overcompensated."

The costs are asymmetric to the operator, not to you. A filter that lets one bad image through produces a news story. A filter that blocks ten thousand legitimate ones produces silence, because refused users do not organize — they give up. Risk management under that asymmetry converges on over-blocking, permanently. And because the underlying judgment is impossible, blocklists accrete literal strings as incidents occur, which is how you get "stethoscope" fine and "speculum" banned. Nobody decided female-specific instruments were more dangerous; the list grew where complaints landed. It encodes an operator's PR history, not a theory of harm.

The strictest jurisdiction becomes the global default. One filter serves every user in every country, so a restriction added for one market is exported to all of them — the Xi Jinping rule being the textbook case. And rewriting your prompt destroys your meaning, which is OVERT's experimental point: every professional who has laundered a request into euphemism to get it past a filter has confirmed it by hand. You did not win; you settled.

None of this is free, and because it fails quietly the cost is invisible in the metrics an operator watches. After enough refusals you stop asking, pre-narrowing every prompt to what you predict will pass; the euphemism that finally passes yields an image close to, but not, what your document needed. A generic policy message tells you nothing about which layer fired, so you can only guess and retry — and image work is iterative, so a filter catching one attempt in five disrupts the loop rather than merely slowing it. Meanwhile the fields with the strongest claim to serious tools get no reviewer, no appeal and usually no published list of what is blocked. A rule you cannot read is not a rule; it is weather.

06Uncensored vs filtered AI image generator: what actually changes

Here is the honest version of the comparison, including what an unfiltered system does not give you.

DimensionFiltered generatorUnfiltered (Shannon)
What decidesA classifier reading words and pixelsA person reading the exact prompt
When you find outAfter you submit — sometimes after you payBefore anything renders or is billed
What the rule isUnpublished, shifting blocklistsA published Responsible Use Policy
Professional contextInvisible to the systemYours to hold, and yours to answer for
Failure modeSilent over-blocking, meaning driftYou get what you asked for — including mistakes
Who carries the riskThe vendor, offloaded onto your workShared: operator policy plus user accountability

The last row is the one people skip, and the one that matters. Removing a filter does not remove the harm categories in section 02; it removes the machine that was guessing badly about them. The obligation stays where it was, held now by two parties who can reason about context: the operator, who publishes and enforces a policy, and you, who know what the image is for. Unfiltered AI image generation is a tool for people already prepared to stand behind their output — the surgeon's atlas, the expert report, the storyboard, the cartoon — who were being stopped by a system that could not tell them apart from someone else.

07What Shannon does — and what it does not do

Precision here matters more than enthusiasm, particularly for readers arriving from an API search.

Generate
New images
Edit
One source image
Combine
Two or more images
No
Video generation

What it does

  • Generation. Describe an image in plain language, in any language. Shannon writes the generation prompt itself, in English, whatever language you asked in.
  • Editing one image. Exactly one source — a picture already in the conversation, or one attached to your current message — changed by an instruction saying what changes and what stays. The output keeps the source aspect ratio automatically.
  • Combining two or more images. Outfit transfer, object-into-scene, person beside person, product-on-person, subject from one image with style from another. The prompt names the role of each image in order, and the real images are used, so their actual appearance is preserved rather than re-described.
  • Aspect control. square (default), portrait, landscape, wide and tall. An explicit request always wins.
  • Rendering on our own GPU cluster, with no content filter on the generation path and no refusal layer on the model that writes the prompt.

What it does not do

  • No video. Shannon does not animate images and does not produce video. Not a roadmap item being coyly withheld — it does not exist.
  • Not on the API. Image generation, editing and combination live in the Shannon chat app. The /v1 API serves text and vision — it can read images you send it — but it does not render them.
  • No uninvited generation. A greeting, a question or a casually attached photo does not trigger an image. Asking Shannon to look at an image — describe it, read it, analyze it — is ordinary vision work, not a generation, and costs nothing extra.

The confirmation card

This is the mechanism that replaces the filter, and it is a design choice rather than a formality. When Shannon determines you are asking for an image, it writes the generation prompt and shows it to you on a confirmation card before anything renders. Nothing is generated and nothing is billed until you confirm.

Compare the designs on their merits. A filter guesses at your intent with less information than you have, and enforces the guess silently. A confirmation card puts the literal specification of the image in front of the party who knows what it is for, before any compute is spent. It catches misreadings of your request, which filters never do; it lets you add the anatomical precision or historical detail the model under-specified; and it makes responsibility legible rather than diffuse. You saw the prompt, and you pressed the button.

08Unfiltered generation raises responsibility, it does not remove it

This belongs here rather than in a footer, because it is half of the argument. A filtered generator makes a promise it cannot keep: that the tool will prevent misuse on your behalf. It fails in both directions — it blocks the surgeon, and it does not stop a determined bad actor, who has other options and always did. What it reliably does is let everyone feel responsibility was handled upstream, by machine. Removing the filter removes that fiction; the question of whether an image should exist returns to the people who can answer it.

  • Shannon Lab LLC's obligation. A published, specific Responsible Use Policy naming prohibited categories rather than an unpublished blocklist — rules you can read, cite and hold us to.
  • Your obligation. You know the purpose, the audience, the jurisdiction and the consent status of everyone depicted. The tool does not, and a classifier never could. The confirmation card exists so that knowledge is applied at the moment it matters, by the party that has it.
  • The line that does not move. "The filter did not stop me" has never been a defense in any medium. A camera does not refuse, a pencil does not refuse; law and professional ethics govern the use, not the instrument. An unfiltered generator restores the ordinary arrangement every other professional tool operates under.

Read the Responsible Use Policy before you start. It is short, specific, and the part of this product that makes the rest of it defensible.

09Frequently asked questions

Why does an AI image generator refuse a prompt that is clearly legitimate?

Because most filters judge the words in your prompt, not your purpose. A classifier sits in front of the model with no access to who you are or why you are asking, so a medical illustrator, a forensic analyst and a bad actor all type the same noun and all get the same refusal. The Intercept reported in April 2023 that Midjourney banned anatomical terms including speculum, placenta and cervix, while stethoscope worked normally.

Is there research measuring content filter false positives in AI art tools?

Yes. OVERT (arXiv:2505.21347, ICML 2025) is the first large-scale over-refusal benchmark for text-to-image models: 4,600 seemingly harmful but genuinely benign prompts across nine safety categories, plus 1,785 truly harmful prompts as a control. Its authors report over-refusal is widespread across leading models. A separate ECCV 2024 study found gender and stylistic bias in three NSFW classifiers evaluated on artistic nudity.

What does an uncensored AI image generator actually change?

It removes the refusal layer and the content filter from the generation path, so a legitimate request is not silently reclassified as an attack. It does not remove judgment — it relocates it. Shannon shows you the exact generation prompt on a confirmation card before anything renders, so the decision is made by a person who can see what will be produced, under the Responsible Use Policy.

Does Shannon generate video?

No. Shannon generates new images, edits one existing image, and combines two or more images into one. It does not animate images and does not produce video of any kind.

Can I generate images through the Shannon API?

No. Image generation, editing and combination live in the Shannon chat app. The /v1 API serves text and vision — reading and analyzing images you supply — not image generation.

If there is no filter, what stops misuse?

Policy, accountability and a visible decision point rather than a keyword blocklist. Shannon never generates uninvited, shows the full prompt before rendering, bills nothing until you confirm, and operates under a published Responsible Use Policy prohibiting sexual content involving minors, non-consensual intimate imagery of real people, targeted harassment, and forgery of identity or financial documents.

Ask for the image you actually need

Generation, single-image editing and multi-image combination in the chat app — no content filter, no refusal layer, and the prompt on screen before anything renders.

Start Chatting Responsible Use Policy

Images in the chat app · no video generation · more research


Sources: Cheng, Huang, Xu, Sojoudi, Zhao, Song & Mei — OVERT (arXiv:2505.21347, ICML 2025) · Riccio, Curto, Hofmann & Oliver — An Art-centric perspective on AI-based content moderation of nudity (arXiv:2409.17156, AI4VA @ ECCV 2024) · Debbie Nathan, The Intercept, April 22, 2023 · PetaPixel, April 3, 2023 · CNBC, February 22, 2024. Shannon AI is operated by Shannon Lab LLC, New Mexico, USA.

Toate linkurile de cercetare