You typed: "A ceramic coffee mug with our company logo on it, sitting on a walnut desk, morning window light." Your logo. Your product. ChatGPT thought for eleven seconds, produced nothing, and said it could not help with that request.
That refusal lands on people doing ordinary work: product mockups, medical diagrams for a nursing course, a movie-poster parody for an internal deck. None of it breaks the rules in spirit; all of it gets blocked in practice.
The honest version: some refusals are wording problems you fix in a minute, some are hard policy walls no rewrite will move, and a large share sit in between — your request is legitimate, GPT Image 2 will not do it, and a different model will. As of September 2026, that third category is where most people land.
Fast Answer: Is Your Refusal Fixable?
| What got refused |
Fixable? |
What to do instead |
| An ambiguous word ("shot", "strip", "kill it") |
Yes, easily |
Replace it with precise visual description |
| Your own brand logo on a product |
Usually |
Generate the blank product and composite the logo yourself |
| "In the style of [living artist]" |
Yes, by rewriting |
Describe the visual techniques instead of naming the person |
| Copyrighted character (Pikachu, Batman, Elsa) |
No |
Design an original character with a similar mood |
| A named celebrity or politician |
No |
Use a described fictional person, or licensed stock |
| Anatomical or surgical medical illustration |
Sometimes |
Reframe as textbook diagram style, or switch models |
| Passed once, failed the second time |
Yes |
Re-run it — this is the output classifier, not your prompt |
| Fine-art nudity, clinical anatomy, genre horror |
Not by rewriting |
Legal work that hosted APIs refuse — see the two-tier section below |
| Sexual content, minors, non-consensual likeness of a real person |
No, anywhere |
Stop here. The constraint is legal, not technical |
This guide will not hand you filter-evasion strings. Every hosted image model in 2026 is moderated; what differs is where the line sits, and that difference solves most legitimate blocked jobs.
Why GPT Image 2 Refuses: The 5 Trigger Categories
First the mechanism, because it explains refusals that otherwise look random.
GPT Image 2 moderates in two independent passes. A prompt-level check reads your text before any pixels exist and refuses within a second or two. An output-level check runs after generation, scoring the finished pixels — when that one fires, you wait out the full generation time and then get nothing.
This is why the same prompt succeeds on Monday and fails on Tuesday. The classifier scores pixels, not words, and image models produce different pixels every run — so a prompt sitting halfway toward "looks like a trademarked character" passes some seeds and fails others. If it worked once, re-run it before rewriting it.
The practical tell: instant refusal = prompt problem, slow refusal = output problem. Fix the first with words, the second with a re-run or a different model.
The largest and least negotiable category. OpenAI restricts generating identifiable real people — actors, politicians, executives, influencers — including in fictionalized or satirical contexts. Uploading a photo of a real person to restyle it is also blocked in ChatGPT, which is why the photo-to-anime trend of 2025 stopped working.
Accidental triggers count too: "a CEO on stage in a black turtleneck" reads as a specific person even though you typed no name. Describe the person from scratch and the trigger disappears.
Copyrighted characters and franchise IP
Well-known commercial characters are blocked, usually at the output stage. Blocking tracks how heavily a character appears in reference data more than who owns it, so the famous ones get caught reliably. An obscure character may slip through — that is a moderation gap, not permission, and republishing it stays your legal exposure.
Style mimicry of living artists
Naming a living artist in an "in the style of" prompt is one of the most reliably blocked patterns — and one of the most reliably fixable, because what you want is the technique, not the name. Deceased artists and historical movements are treated differently.
Minors, violence, and medical imagery
Anything sexualizing minors is a permanent, universal wall. Beyond that, this cluster hits professionals hardest: graphic injury, surgical fields, and clinical anatomy trip the same classifiers as gore. Children in ordinary contexts — a family photo, a classroom illustration — are also moderated more strictly than adults.
Brand logos and trademarks
The mug case from the opening. GPT Image 2 cannot verify the logo is yours — and could not reproduce it accurately anyway, since these models approximate marks rather than copy them. Even a successful generation returns a mangled near-copy you would not ship.
7 Prompt Rewrites That Actually Get Approved
Each reframes a legitimate goal in language a classifier reads correctly. The pattern underneath all seven: replace the reference with the visual attributes you wanted from it.
| # |
Refused prompt |
Rewrite that works |
Why it clears |
| 1 |
"Coffee mug with the Acme logo" |
"Ceramic mug with a blank front panel, three-quarter view, walnut desk, soft morning light" |
Removes the trademark; composite your logo afterward at full fidelity |
| 2 |
"Portrait in the style of [living illustrator]" |
"Portrait with thick gouache texture, flat two-tone shadows, warm ochre and teal palette, visible brush edges" |
Describes technique instead of naming a person |
| 3 |
"Movie poster parody of [franchise film]" |
"Teal-and-orange one-sheet layout, low-angle hero silhouette against a burning skyline, condensed title block" |
Keeps the genre, drops the protected IP |
| 4 |
"Cross-section of a heart showing a myocardial infarction" |
"Vector medical textbook diagram of the heart in cross-section, flat color-coded chambers, labeled call-outs, white background" |
"Textbook diagram" reframes intent away from injury |
| 5 |
"Two boxers fighting, one taking a hard shot" |
"Two boxers mid-exchange in a lit ring, motion blur, sweat spray catching the key light, dramatic sports photography" |
Drops the ambiguous words, keeps the intensity |
| 6 |
"A young woman in a swimsuit on the beach" |
"An adult woman in a modest one-piece swimsuit at the shoreline, wide editorial travel photograph, midday light" |
Adult framing plus editorial context removes the ambiguity |
| 7 |
"Photo of a famous tech CEO in a meeting" |
"A confident executive in her forties, short silver hair, charcoal blazer, leading a glass-walled boardroom meeting" |
Invents a person instead of gesturing at a real one |
Three rules generalize:
Add specificity, not softeners. "Tasteful," "appropriate," and "safe for work" are not visual instructions and do nothing. Concrete detail moves a prompt out of the ambiguous zone.
Watch for double-meaning words. Shot, strip, execute, kill, blow, exposed, blade, needle.
Name the medium. "Vector medical diagram," "editorial product photograph," "children's book illustration." Declaring it tells the classifier what kind of image is coming, resolving ambiguity in your favor.
What Rewriting Won't Fix — and Where the Line Actually Is
Some refusals are not thresholds you can move with better wording. But "hosted models refuse this" and "you cannot do this" are different statements, and collapsing them into one is why most advice on this topic is useless. They split cleanly.
Tier 1: The model is not the constraint
These are restricted because the output itself is illegal to produce or distribute in most jurisdictions, not because OpenAI is being cautious:
- Sexual content involving minors
- Intimate imagery of a real person made without their consent
- Realistic depictions of real people doing things they did not do, passed off as real
- Working reproductions of ID documents, currency, or official credentials
Which model produced the file is not a defense — recent statutes in the US, UK, and EU attach liability to whoever created and distributed the image, whatever the pipeline. Nothing later in this article changes that. For real people the legitimate paths stay the same: licensed stock, a shoot with a signed release, or a likeness license.
Tier 2: The hosted API is the constraint
This is where most people reading this section actually are. Every row below is legal to produce, routine in professional practice, and refused by hosted models anyway:
| Blocked work |
Why hosted models refuse it |
Actually restricted? |
| Figure study, fine-art nudity |
Blanket adult-content filter with no context read |
No — taught in every art school |
| Clinical anatomy, surgical, wound imagery |
A gore classifier cannot see your syllabus |
No — standard medical publishing |
| "In the style of" a living artist |
IP caution |
Style is not copyrightable in the US; refusing is a policy choice |
| Political figures in satire or editorial cartoons |
Likeness policy applied bluntly |
No — satire and editorial use are long protected |
| Body horror, genre violence |
Violence threshold set for a general audience |
No — ordinary commercial genre work |
| Your own trademarks |
The model cannot verify the mark is yours |
No — it is your mark |
For these, a hosted API is simply the wrong tool, and no amount of rewriting fixes a tool mismatch. Model weights you run yourself carry no provider-side refusal layer, because there is no provider in the loop. Alibaba's Qwen-Image is the clearest example — a 20B open-weight model under Apache 2.0, free to deploy, fine-tune, and use commercially — with the Stable Diffusion and FLUX families in the same space. Game art teams, medical publishers, and studios run these locally for exactly the rows above.
Three tradeoffs before anyone reaches for a GPU:
- Quality gap. Open weights still trail GPT Image 2 and Nano Banana Pro on instruction-following and clean text. You trade output quality for the absence of a refusal.
- Infrastructure, not a login. A 20B model means serious VRAM, a diffusers or ComfyUI pipeline, and an afternoon of setup before the first image.
- Compliance moves to you. Removing the provider's filter removes the provider's judgment, not your legal exposure. Everything in Tier 1 stays illegal on your own hardware.
The decision rule: occasional Tier 2 work is faster to solve by switching hosted models for a few credits. If it is your core workload, self-hosting is the structural answer.
Models With Different Policies: What Each One Will and Won't Do
Every hosted model here is moderated. What varies is the character of it: where thresholds sit, whether the filter runs on the prompt or the output, and how much benign work gets caught as collateral. A blocked medical diagram or stylized portrait often clears on a second model in one attempt.
| Model |
Policy character |
Handles well |
Still refuses |
Credits (text-to-image) |
| GPT Image 2 |
Strictest here. Dual prompt + output moderation |
Instruction-following, clean text, composition |
Real people, franchise IP, living-artist styles, most clinical imagery |
1K: 3 · 2K: 5 · 4K: 8 |
| Nano Banana Pro |
Strict on deception and real-person misuse, permissive on stylistic work |
Photoreal editing, multi-image composition, typography, 4K |
Impersonation, deceptive content, sexual content |
1K: 8 · 2K: 10 · 4K: 14 |
| Nano Banana 2 |
Same policy family as Pro, faster and cheaper |
Fast iteration, strong text, everyday commercial imagery |
Same categories as Pro |
1K: 6 · 2K: 10 · 4K: 18 |
| Seedream 5.0 Pro |
Context-aware staged checks including a post-generation pass |
Cinematic rendering, dramatic lighting, artistic composition |
Sexual content, explicit violence, illegal content |
1K: 7 · 2K: 14 |
| Ideogram 4.0 |
Hive-based moderation; comparatively tolerant of horror and fantasy violence |
Typography, posters, logos-as-design, darker stylized work |
Adult content; benign edge cases sometimes over-blocked |
turbo: 4 · balanced: 7 · quality: 10 |
Scenario recommendations:
- Blocked stylized portrait or illustration → Nano Banana Pro, the most reliable substitute when OpenAI's style filters catch you.
- Blocked everyday commercial image, high volume → Nano Banana 2, same policy family at lower cost per attempt.
- Cinematic or genre work → Seedream 5.0 Pro, whose read of "dramatic" is less jumpy.
- Posters, badges, packaging → Ideogram 4.0, also the most forgiving of horror aesthetics.
- Unsure → the image model hub. Run one prompt on two models instead of five rewrites on one.
Searches for "nano banana 2 unrestricted" or "discord nano banana celebrities" lead to resellers and Discord bots claiming to run Google models without limits. They either proxy the same moderated models or do not run the advertised one at all — and you hand prompts and payment details to an anonymous operator either way. If you want a genuinely unfiltered pipeline, run open weights yourself rather than trusting someone else's.
Watermarks Are Not Content Restrictions
The most common conflation on this topic, and it costs people real time. Two unrelated systems:
|
Content restriction |
Watermark / provenance |
| What it is |
A classifier refusing to produce an image |
A mark on an image that was produced |
| When |
Before you get output |
After you get output |
| Looks like |
"I can't help with that" |
A visible logo, or invisible metadata |
| Can you change it? |
Only by rewriting or switching models |
Depends on the platform and your plan |
Google's models embed SynthID, an invisible signal in the pixel data that survives cropping, resizing, and recompression. It is a provenance marker, not a restriction — it does not affect what you can generate and does not appear in your image. Separately, Google's Gemini app has applied a visible sparkle mark on some tiers, with rules varying by plan, region, and account type. That mark is what people mean by "nano banana watermark" — a property of where you ran the model, not of the model.
On makifyai.com, watermark-free output is a Standard plan and above feature. It has no bearing on what the models will generate — a Pro subscriber and a free user hit identical policy walls. If you upgraded expecting fewer refusals, that is not what the plan buys.
One distinction worth keeping straight: removing a platform watermark from work you generated under a commercial plan is normal — that is what the plan buys. Stripping provenance signals to pass an AI image off as human-made violates the terms of the platforms that embed them.
Commercial Use and Licensing in 2026
Refusals and licensing get tangled together. The clean version:
OpenAI assigns output rights to you. You own the images you generate and can use them commercially on free and paid tiers alike. The caveat: OpenAI disclaims any warranty against third-party infringement, so if your image reproduces a protected character or a real likeness, the assignment does not shield you.
Ideogram does not claim ownership of outputs and permits commercial use provided you respect third-party rights. Google and ByteDance likewise permit commercial use, with the same structural caveat.
On makifyai.com the commercial license is a Standard-plan-and-above entitlement, bundled with watermark-free output. The pricing page has current tiers; Standard is $29.90/month for 300 credits, or $19.90/month billed annually for 400 credits a month.
The rule that survives all of this: the license covers the file, not the subject. An AI image of a real athlete in your brand's jersey is a rights problem however permissive the generator's terms. An original character you invented is yours to ship.
A Practical Workflow When You Hit a Wall
Four steps. Most blocked jobs resolve at step 2 or 3.
1. Diagnose — time the refusal. Instant means the prompt filter caught your text; go to step 2. Slow, after a generation delay, means the output classifier caught the pixels — re-run the identical prompt twice before changing anything, since seed variation alone clears a meaningful share.
2. Rewrite once, deliberately. Scan for the four usual culprits: a proper noun (person, character, brand, artist), a double-meaning word, an unstated medium, an ambiguous age or state of dress. Fix all four in one pass — do not iterate word by word.
3. Switch models. If one deliberate rewrite fails, stop rewriting — you are hitting a threshold this model sets and another sets differently. Run the same text on Nano Banana Pro or Seedream 5.0 Pro. At 3 to 8 credits an attempt, that costs less than a fourth rewrite.
4. Change production method. If two or three models with different policy characters all refuse, that is the line every provider independently drew, not a quirk. Check your tier: Tier 2 work you need regularly points to self-hosted open weights; Tier 1 points to licensed stock, a signed release, or a redesigned brief. Recognizing this at attempt six instead of sixty is the whole skill.
On budget: the Standard plan's 300 monthly credits cover roughly 100 GPT Image 2 generations at 1K, or about 37 Nano Banana Pro. Just testing whether a second model clears your prompt? The free daily check-in gives 30 credits a week — about 10 GPT Image 2 attempts at 1K.
FAQ
Why does ChatGPT refuse to generate my image when the prompt is completely normal?
Most often one word is doing it — a proper noun, or a term with a second meaning like "shot" or "strip." The other common cause is the output classifier flagging finished pixels rather than your text, which you can spot because the refusal arrives after a generation delay instead of instantly. Re-run once before rewriting.
What is GPT Image 2's content policy blocking most often?
Identifiable real people, well-known copyrighted characters, "in the style of" prompts naming living artists, clinical or injury-related medical imagery, and recognizable trademarks. The first two are hard limits; the style, medical, and brand categories are usually solvable by rewriting, switching models, or self-hosting.
Is Nano Banana 2 unrestricted?
No. It is moderated under Google's policies and refuses sexual content, impersonation, and deceptive material. It does read some artistic prompts more permissively than GPT Image 2, which is why it clears jobs OpenAI blocks — but "different threshold" is not "no threshold." Only weights you run yourself have no threshold.
Can I get AI images of celebrities from a Discord bot?
Those bots either proxy the same moderated models or do not run the model they advertise. More importantly, a real person's likeness generated without consent is your legal exposure regardless of tool. Use licensed stock or a signed release.
Is there any AI image generator with no restrictions and no cost?
No hosted one — every major provider moderates outputs, and sites advertising "free, no restrictions" are usually unmoderated proxies with unclear data handling and no usable commercial license. Open weights on your own hardware are the real answer: no provider-side refusal layer, no per-image cost, Apache-2.0 licensing on models like Qwen-Image. You pay in setup time, output quality, and the compliance burden.
Does the Nano Banana watermark mean my image is restricted?
No, they are unrelated. SynthID is an invisible provenance signal in Google model outputs and does not limit what you can generate; a visible watermark, where it appears, is a property of the platform tier you used. Here, watermark-free download comes with Standard and above and changes nothing about which prompts get accepted.
Can I use GPT Image 2 output commercially?
Yes. OpenAI assigns output rights to you and permits commercial use, though it disclaims any guarantee against third-party infringement. On this site the commercial license is included from Standard upward. The license covers the file, never the subject.
Do this next: run the refused prompt unchanged on Nano Banana Pro, 8 credits at 1K. If it clears, you had a threshold problem, not a prompt problem. If it refuses too, apply the four-culprit rewrite and try GPT Image 2 once more for 3 credits. Two attempts, 11 credits, and you know which problem you have.
Sources
Provider policies change often. These are the primary documents behind the claims above — check them against this article's date rather than trusting any summary, including this one.