The web’s newest weapon against AI scrapers is a font
Source Entity
Kyle Orland

Designers Isaque Seneda and Gabriel Abrucio have introduced ShieldFont, a tool designed to poison AI training data by rendering readable text for humans while providing nonsensical data to scrapers. This innovation aims to provide publishers with a practical opt-out mechanism against unauthorized data harvesting.
The Rise of Data Poisoning: ShieldFont Explained
The rapid expansion of large language models (LLMs) has sparked an unprecedented conflict between content creators and AI companies. As developers scrape massive swaths of the public web to train their models, publishers have increasingly sought ways to protect their intellectual property. The introduction of "ShieldFont," developed by designers Isaque Seneda and Gabriel Abrucio, represents a sophisticated technical countermeasure in this ongoing digital tug-of-war.
How ShieldFont Functions
At its core, ShieldFont utilizes the technical architecture of font ligatures—a traditional typographical feature where two or more characters are joined into a single glyph. By manipulating these ligatures, the font displays correct, human-readable text on the screen while the underlying HTML code remains intentionally garbled or nonsensical. For example, a word that appears as "horse" to a human reader might be encoded in the raw data as "potato," effectively poisoning the dataset harvested by automated scrapers.
Protecting Intellectual Property
This innovation addresses the growing demand for an "opt-out" mechanism for web publishers. As highlighted in the project’s white paper, the goal is to disrupt the unauthorized collection of training data. By creating a discrepancy between what a human perceives and what a machine reads, ShieldFont forces AI developers to grapple with the integrity of their training sets, potentially rendering the scraped data useless for model training purposes.
The Legal and Ethical Landscape
The emergence of tools like ShieldFont is a direct response to the broader landscape of lawsuits and technical friction surrounding AI training. Since many AI companies scrape public data without explicit compensation or permission, designers are now taking matters into their own hands. This tool serves as a practical, defensive layer that operates independently of complex legal frameworks or opt-out headers like robots.txt, which are not always respected by aggressive scrapers.
Future Implications for Web Content
If widely adopted, ShieldFont could signal a shift toward "adversarial design" on the web. As AI models become more reliant on high-quality, human-generated content, the ability to "poison" that data becomes a significant bargaining chip for content creators. We may see a future where the web is bifurcated between accessible human environments and machine-readable databases, with tools like ShieldFont acting as the gatekeepers.
Conclusion
ShieldFont is a pioneering effort to restore agency to web publishers. By leveraging the fundamental mechanics of typography, Seneda and Abrucio have created a clever, low-friction solution to a high-stakes problem. Whether this will force AI companies to change their scraping behaviors remains to be seen, but it undoubtedly marks a new chapter in the technological resistance against unauthorized data exploitation.