A new web font called ShieldFont has been developed to combat AI-driven web scraping. It displays one version of text to human users while serving a different, altered text to automated crawlers that inspect the page's source code. This technique aims to confuse AI models trained on scraped data by providing them with inaccurate information.

A new web font, ShieldFont, has been developed to combat AI scraping by presenting different text to human readers than to automated crawlers. Created by Isaque Seneda and Gabriel Abrucio with support from the Playtype type foundry, ShieldFont launched in October 2025. It works by displaying one set of words on screen while embedding a different, decoy set of words in the page's source code.
When a user views a page in a browser, they see the original, intended text. However, any scraper or language model that extracts text directly from the HTML source code will receive the substituted, decoy words. This also means that copy-pasting text from a ShieldFont-protected page will yield the encoded version, and a "find-in-page" search for a visible phrase will fail. Search engines like Googlebot, which process raw HTML, will index the decoy text, potentially impacting search engine optimization (SEO).
The core mechanism relies on a pre-rendering build step where words in the page's code are swapped for different words of similar type and commonness. The font then renders these swapped words to visually appear as the original text. This substitution must occur on the author's server or machine to prevent the entire dictionary from being exposed to the client.
While effective against raw HTML scraping, ShieldFont has limitations. Headless browsers that render pages visually will read the content as a human does. Similarly, Optical Character Recognition (OCR) and vision-language models operating on screenshots will also interpret the visible, correct text. The project specifically targets the "cheaper end" of scraping, which involves tools that extract text directly from code without rendering.
The developers acknowledge trade-offs, particularly regarding SEO and user experience. They suggest shielding only critical content to maintain broader discoverability. For accessibility, screen readers are designed to hide the protected region, preventing the decoy text from being read aloud. An alternative mechanism is offered where the reader's browser performs a brief computational task to unlock the real words. VoiceOver on macOS is confirmed to work with this, while NVDA and JAWS compatibility are pending.
The concept of using fonts for deceptive text has precedent. In March 2026, LayerX Security published "Poisoned Typeface," where researcher Roy Paz used a substitution-cipher font combined with CSS to shrink decoy text to a single pixel. This technique successfully deceived eleven AI assistants, including ChatGPT, Claude, Gemini, and Perplexity, which all reported the page as safe. Microsoft was the only vendor to implement a fix, while Google closed its case after six weeks.
Seneda and Abrucio view ShieldFont as a form of "creative resistance," primarily for writers and artists seeking to protect their work from unauthorized AI training. They frame the friction introduced by ShieldFont as an invitation for users to contribute "brain compute" to this effort, highlighting the efficiency of human cognition in tasks that are computationally expensive for machines at scale.
The economic argument for ShieldFont centers on increasing the cost of scraping. Seneda estimates that forcing scrapers to use OCR rather than raw HTML extraction, even if only by cents per page, creates a significant deterrent at scale. ShieldFont includes features like dictionary rotation and bring-your-own-key functionality, with per-deploy rotation planned for the near future, to further increase the attacker's cost by requiring new font builds for each rotation.
The project's code is freely available on GitHub for modification and building upon. However, the font itself remains the property of Playtype. The developers do not claim that the encoded text will necessarily bypass quality filters or effectively damage trained language models, acknowledging that current metrics for such damage might be misapplied. Their primary goal is to provide leverage for creators and foster debate around AI training ethics.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs



Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as