Independent AI intelligence Two editions daily · ET
Fervor AI

Analysis · October 6, 2026 · concept

ChatGPT image generationprivacyagent-securityfrontier-models

ChatGPT Is Signing Real Cartoonists' Names, and Your Image Feature Could Too

A generated cartoon with a real person's signature on it is a false authorship claim. Metadata will not fix it, and style refusals will not stop it.

A cartoon of Dolly Parton and Tim Curry in heaven went viral this week with a small, confident signature in the corner: "BLOPER." That is the mark of Brendan Loper, a working New Yorker cartoonist. He did not draw it. ChatGPT did.

The strange part is that the signature is the most believable thing in the image. Readers judge a cartoon's drawing style loosely. A signature they take at face value. It is the one element in the frame that exists to answer a single question: who made this?

And the model answered it wrong, with a real person's name.

What actually happened

On October 5, Nieman Lab's Andrew Deck reported that ChatGPT's image generator, asked for "New Yorker-style" cartoons, was producing images signed with the marks of more than 15 real cartoonists. The list includes Brendan Loper, Harry Bliss, Emily Flake and Joe Dator. Deck reproduced the behavior by prompting ChatGPT himself and gathered more examples that users had posted to Reddit.

OpenAI's response, as Nieman Lab quotes it, did not mention signatures. The company said it believes "the future of creativity is one that is fundamentally human" and that it appreciates communities "flagging bugs and unintended behavior." A spokesperson told Nieman Lab that "Condé Nast has never granted an LLM developer permission to train models on its cartoons," and that ChatGPT creations reproducing The New Yorker's logo are "also not allowed in any LLM deals."

You can read this as a story about training data and copyright. It is that. I want to look at it from a narrower angle, because the narrow angle is the one you can act on if you build anything that generates images.

Why the usual safeguards miss it

There are two safeguards people usually point to when AI images cause trouble. Neither one covers this.

The first is provenance metadata. OpenAI's March 2025 system card for GPT-4o image generation lists "C2PA metadata on all assets (verifiable origin, industry standard)" as one of its provenance tools. That metadata says a machine made the file. OpenAI's own help page on C2PA is candid that it "can sometimes be removed by platforms, editing tools, or file conversions." A screenshot is enough. And even when the metadata survives, nobody scrolling a feed opens a C2PA inspector. They read the corner of the cartoon.

So you get two authorship claims in one file. The invisible one says "a model made this." The visible one says "Brendan Loper made this." The visible one wins every time a human looks.

The second safeguard is the style refusal. The same 2025 system card says OpenAI "added a refusal which triggers when a user attempts to generate an image in the style of a living artist." OpenAI later clarified, in a statement reported by The Decoder, that it permits "broader studio styles." A publication's house style sits right in that gap. "New Yorker-style" names no individual, so a name-based refusal has nothing to catch, and the model fills in what a New Yorker cartoon usually has in the corner: a cartoonist's signature.

That is the mechanism worth understanding. The model learned that signatures are part of the genre, the way a caption is. The refusal checks the prompt. The signature appears in the output. The check and the harm live on opposite sides of the model.

The position: authorship marks are their own safety class

Here is where I land. If your product generates images, names and signatures in the output deserve their own check, separate from whatever your model provider does on the input side.

I'd group four things under "authorship marks":

  • Signatures and initials in the image itself, especially in corners.
  • Mastheads and logos of publications, studios and brands.
  • Bylines and credit lines, such as "Photo by" or "Illustration by".
  • Watermark-like text imitating stock agencies.

Every one of these makes a factual claim about who made or licensed the image. A model has no way to make those claims true. So the safe default is that your system makes none of them unless the user supplied the name and has a right to it, such as their own signature on their own design.

Some people will argue this belongs to the model vendor, and they are partly right. OpenAI should fix it, and probably will. But you do not ship OpenAI's product. You ship yours, with your logo on the page that served the image. When a fake signed cartoon goes viral from your app, the screenshot carries your interface around it, and "our provider has a bug" is a weak thing to say to a cartoonist whose name is on it.

Put this into practice

The lowest-friction version takes an afternoon.

1. Test your own pipeline first. Prompt your image feature for "a cartoon in the style of [major magazine]," "a comic strip like the Sunday funnies," and "a stock photo." Look at the corners. If you see anything that resembles a name, you have the bug.

2. Add a negative instruction at the prompt layer. Append a line to every image request telling the model to include no signatures, initials, logos, mastheads or watermarks. It will not catch everything, but it is free and it lowers the rate.

3. Run OCR on the output. Any off-the-shelf OCR pass over the generated image will find most text. Flag text that sits in a corner, matches a name pattern, or matches a list of publications you care about. For small text in a corner, cropping the four corners and scanning them at higher resolution catches more than scanning the full frame.

4. Decide what happens on a hit. Regenerate with a stronger instruction, inpaint the region, or refuse. Regenerating is usually the cleanest for users. Log every hit, because the rate tells you how much your model leans on genre conventions.

5. Allow-list the user's own marks. If someone uploads their own signature or brand kit, let it through. The goal is that no name appears that the user did not supply.

6. Keep provenance metadata anyway. C2PA still matters for platforms and investigators. It answers a different question than the one the signature answers.

Honest limitations

This approach has real gaps, and you should know them before you rely on it.

OCR misses stylized handwriting, which is exactly what signatures are. A scrawled "BLOPER" may come back as noise. You will get false negatives, and you should expect them to cluster on the most convincing fakes.

You will also get false positives. Cartoons contain signs, labels and speech bubbles. A filter that flags all corner text will catch a shop sign in a street scene. Tune it on your own outputs before you turn on automatic regeneration, or you will burn compute and annoy users.

A name list cannot be complete. You can list major publications, but you cannot list every working illustrator. That is why the default should be "no names the user did not supply" rather than "no names on this list."

None of this touches the bigger questions. Training on New Yorker cartoons without permission, as Condé Nast describes it, is a licensing dispute between Condé Nast and OpenAI. An output filter does not resolve it, and I would not pretend otherwise. What the filter does is stop your product from adding a false claim on top.

And I have not seen OpenAI's fix, if one is coming. It is possible the provider-side change makes most of this redundant within weeks. A cheap output check still costs you little and protects you from the next model that learns a different genre convention.

The question to ask your image feature

Most of the debate about AI images circles around whether a machine made the thing. That question has decent answers now: metadata, watermarks, detectors, all imperfect, all improving.

The cartoon in the corner raises a different question, and an older one. Who does this image say made it? Look at what your product generates this week and answer it honestly. If the answer is ever a real person who never touched it, you have found the cheapest fix you will ship all quarter.

Sources: Nieman Lab, OpenAI GPT-4o image generation system card (March 2025), OpenAI Help Center on C2PA, The Decoder.


Medium metadata

  • Title: ChatGPT Is Signing Real Cartoonists' Names, and Your Image Feature Could Too
  • Subtitle: A generated cartoon with a real person's signature on it is a false authorship claim. Metadata will not fix it, and style refusals will not stop it.
  • Tags: Artificial Intelligence, ChatGPT, Generative AI, AI Safety, Product Development
  • Canonical: fervorai.dev