All notes
Essay7 min read

Whose filter said no

One model family, two routes, two answers. The mechanism is documented, and it is more useful than the workaround.

Joey Brass, Head of Communications

When an AI video model refuses a shot, the filter that refused it usually belongs to the model provider, not to the platform you are working in. Providers configure those filters per route, so a consumer app and an API endpoint serving the same model can reach different verdicts on identical material. Breme names which filter declined a request so you can tell a house rule from a provider rule, and never charges for a refused generation.

A member of our first group brought a family drama to Breme this month. Children in most of the frames, all of them invented, none of them anybody’s real child. He had been generating the same material for weeks on a consumer AI video site without incident. On Breme, running Seedance, roughly the same references came back refused.

Another member, working on an anti-hate short, had a rights-cleared face on a reference image that repeats across billboard screens in a city street. The image model declined it as sensitive content.

Both were doing ordinary film work. Both got a refusal that reads, on most platforms, as a verdict on them. It is worth explaining exactly what happened, because the explanation is more useful than the workaround.

The same model is not the same route

Seedance is one family of weights. It is not one service.

ByteDance operates the consumer apps, Dreamina internationally and Jimeng in China. BytePlus operates the API that studios and tools build on. Breme calls the API. Those are different deployments with different configurations, different regional obligations, and different amounts of context about who is asking.

The configuration part is documented. BytePlus ships what it calls the Content filter System, and in its own words the control lives on the inference endpoint: you enable or disable it when you create an endpoint, it is enabled by default, and you can change it later from the endpoint list (BytePlus, ModelArk Content filter overview). Public-figure likeness blocking is a separate feature layered on top, described as a deep-learning similarity check against a reference set of faces and voices across politics, sports, business, entertainment, and media (BytePlus, Content filter FAQ). BytePlus also states plainly that a baseline stays on no matter what: even with the feature disabled, its services maintain baseline content safety policies.

Read that as an operator and the picture resolves. Strictness is not one dial that a provider turns up or down per platform. It is a stack of separately configured layers, set per route, and two routes to the same weights can differ in which layers are armed and which categories each layer covers. That is why a frame can pass in one place and fail in another without anybody changing their mind about the content.

The published guides disagree about which direction the difference runs. One asserts that ByteDance-owned platforms apply stricter filters because they carry direct legal liability (seedance2pro). Another says the underlying filter is the same because both run the same model, with extra restrictions on the Chinese domestic app (vicsee). Our members observed the opposite of the first claim on material involving children. None of these claims carry a source, ours included: what we have is our refusal log, and what they have is theirs.

The honest version is the one the vendor documentation supports. Route A can be stricter than Route B on one category and looser on another, at the same moment, because the categories are configured separately. A consumer app also knows things an API endpoint does not. It has an account, a sign-in, a region, sometimes an age signal, and a history. An API request arrives with none of that. It carries an image and some text, and the filter has to adjudicate the image alone. Filters with less context decide conservatively on exactly the classes where context is what would clear you.

Why the innocent cases are the hard cases

Three structural reasons, all of them visible in the vendors’ own material.

A child in frame is a category, not a judgment. Minor Safety is the first named class on the BytePlus filter list, covering content touching the privacy and wellbeing of children and adolescents. A classifier that has to be very reliable on that category buys its reliability with a low threshold, and a low threshold on a category means the ordinary members of the category get caught with the rare bad ones. Nothing about a wholesome scene argues its way out, because the scene was never accused of anything. It was sorted.

Likeness checks are similarity scores. The public-figure feature compares a detected face against a reference set and blocks on a match. Similarity is continuous, the set is large, and the vendor says outright that the feature is not an authority on, and does not purport to be a comprehensive block on, prominent public figures. A real face you have every right to use can land near somebody in that set. Put that face on eight billboard screens in one frame and you have handed the checker eight chances to score, in a composition whose entire subject is the replication of one identity. That is the shape of the thing the filter exists to stop, drawn by someone with the opposite intention.

Video gets moderated twice, and the second pass sees frames you never wrote. BytePlus describes a two-layer design: an input filter over what you send, and the model’s own output moderation over what comes back (BytePlus support). The error names follow the same split, input text and input image on the way in, output video on the way out. A clean prompt and a clean reference can still produce one ambiguous intermediate frame, and the clip fails on the way home. Which is also why re-running the identical request sometimes succeeds. That is not superstition. The input layer is deterministic about your inputs, and the output layer is looking at a different video each time.

Two smaller ones worth knowing. Sign text, logos, and license plates near faces raise the score on several vendors’ checks at once, privacy and trademark and likeness, so signage-heavy street work is structurally noisier than the same scene without lettering. And compression artifacts in a reference can read as the visual signature of the material the filter was trained to catch.

What Breme does, and what Breme will not do

Breme sends Seedance no safety parameter. Our adapter sets watermarking off and nothing else. The filter that refused those frames is the provider’s, running on the provider’s side of the API, in a configuration the provider controls. We could not have tuned it down for a shot if we had wanted to. The only lever on offer is wholesale removal of the filter, sold as an enterprise contract with identity verification attached, and it is not a per-request dial. It is a switch that would change the platform, for everybody, permanently, and we are not buying it. A studio that removes the layer protecting the category most worth protecting has not improved anybody’s film.

So the filters stay. What we changed is what happens when one speaks.

We tell you whose filter it was. Breme runs its own screen on prompt text before a request ever leaves us, and its refusals say so in Breme’s voice, as house policy, because that decision is ours. Everything that gets past it and comes back refused wears the provider’s name: the model declined this, and here is the class it declined it under. Those are two different sentences on purpose, and neither one is allowed to speak for the other. Most tools collapse both into a generic failure, which leaves a working filmmaker guessing whether they hit a rule, a bug, or an opinion about their work.

A refusal costs nothing. Reservations release. You are not charged for a decline, on any model.

Likeness refusals point at another model. Sensitive-content refusals do not. This is the distinction that took us longest to get right. Likeness checks differ genuinely between vendors, they false-positive at a documented rate, and a reference you hold the rights to deserves a second route, so our copy says so. A decline for sensitive content is different. Breme applies one content standard across every model on the platform, which means shopping a refused input around the catalog until something accepts it is not a workflow we will coach. Our error copy used to suggest it and now does not. Runway treats a pattern of moderated requests as grounds for suspension (Runway), and they are right to.

One standard, stated once. Breme makes PG-13 and R. We do not make NC-17, and there is no age-gated mode arriving later. Anything involving minors or the intimate depiction of a real person is zero tolerance and ends the account. That line exists for its own sake, and it also happens to be why we can be relaxed about violence, weapons, horror, period nudity implied by framing, and the rest of the material film has always used.

The part we owe you next

Attribution is the floor. Above it sits the thing our members actually asked for, which is knowing before the render which model will look at their material and shrug.

A children’s drama should not discover a minor-safety threshold one refusal at a time. Google’s Veo makes this explicit in its API: person generation defaults to adults only and will not produce children at all, with the permissive setting gated behind an allowlist (Google). That is a harder answer than Seedance gives, and a far more useful one, because you learn it once instead of fifteen times in an evening. We are working toward showing that shape of knowledge in the app: which classes each model family guards hardest, drawn from provider documentation and from our own refusal log, attached to the model picker rather than buried in a help page.

Until then, the practical guide covers how to read a refusal, the errors name their author, and the switch to another model is one click from the refusal.

None of this is a complaint about ByteDance. They built a filter that errs toward protecting children, and given what it is guarding, erring in that direction is the correct engineering decision even when it costs a filmmaker an evening. The failure worth fixing is not the filter. It is the silence around it.

Common questions

Why does the same image work on one AI video site and get refused on another?
Because the filter is configured per route, not per model. Providers expose content filtering as an endpoint-level setting, so a consumer app and an API endpoint serving the same weights can have different layers armed. A consumer app also has account context an API request does not, and filters with less context decide more conservatively.
Does Breme make its own models stricter?
No. Breme sends no safety parameter to Seedance beyond turning watermarking off. Breme screens prompt text on its own side before dispatch, and those refusals are labelled as Breme policy. Everything else comes from the provider and is labelled with the provider name.
Am I charged when a model refuses a generation?
No. The billing reservation is released on a refusal, on every model. A decline costs nothing.

Keep reading