AI Is Stealing Your Work. This Stupid Font Trick Is Fighting Back.

You wrote it. You published it. You put it out there for humans to read. And within hours, a bot scraped it, chewed it up, and fed it into a trillion-dollar machine that will never credit you, pay you, or even say thanks.

That’s the internet in 2026. Your content is fuel. You don’t get to opt out.

Or do you?

An open-source project just dropped one of the most gleefully petty countermeasures I’ve seen in years: a poisoned font. The idea is almost insultingly simple. You serve a custom font on your website that renders text perfectly fine to human eyes, but scrambles the underlying character encoding so that AI scrapers ingest garbage. The machine sees gibberish. The human sees your article. It’s adversarial camouflage, and it’s beautiful.

Every scrap of content you’ve ever created is someone else’s training data. The only question is whether you’re going to keep donating it for free.

Here’s why this matters beyond the cleverness. The entire AI industry is built on a single assumption: that public data is free labor. Every blog post, every comment, every photo, every frustrated midnight rant you posted on a forum — it’s all grist for the mill. The companies building these models didn’t ask permission. They didn’t negotiate licenses. They just took it, because the architecture of the web makes taking trivial and stopping them nearly impossible.

Until now, the defenses have been pathetic. Robots.txt? Bots ignore it. Paywalls? They lock out readers too. CAPTCHAs? They punish humans for being human. Every solution either doesn’t work or hurts the wrong people.

The poisoned font is different because it exploits the one thing AI still can’t do well: perceive like a human. The gap between what a machine reads and what a human sees is real, it’s measurable, and now it’s weaponized. It’s a cat-and-mouse game that doesn’t require a PhD in adversarial ML to play. You just install a font.

But here’s where it gets uncomfortable.

The same trick that blinds the scraper also blinds the screen reader. You can’t exclude the machine without excluding the human who depends on one.

That’s not a bug. That’s the dilemma. And it reveals something most people haven’t reckoned with: defending your data from AI scraping isn’t a technical problem. It’s an ethical trade-off. You’re choosing who to exclude. You’re deciding that protecting your creative labor matters more than universal accessibility — or you’re deciding it doesn’t. Either way, you’re making a moral call, not a technical one.

The comment sections are already split. Some call it a clever hack. Others point out, correctly, that it breaks accessibility tools. Still others shrug and say the AI companies will just switch to OCR and bypass the whole thing.

They’re probably right about OCR. The scrapers will adapt. They always do. But that misses the point entirely.

This isn’t about building an unbreakable wall. It’s about making the cost of theft visible — and making the thieves work for every stolen word.

Every poisoned font, every adversarial image, every subtle distortion that forces a scraper to burn more compute is a tiny act of resistance. It won’t stop the machine. But it raises the price. It slows the harvest. And most importantly, it sends a signal that the people whose work fuels these models are not passive resources. They’re watching. They’re angry. And some of them are willing to break accessibility norms to make a point.

That last part should make you uncomfortable. It should. The accessibility critique isn’t a gotcha — it’s the sharpest edge of a real problem. When the only way to fight back against mass data extraction is to exclude vulnerable users, something is deeply broken in the system. Not in the font trick. In the system that made the font trick necessary.

So where do you stand? If you publish anything online — articles, code, art, music, comments — your work is being scraped right now. You didn’t consent. You weren’t asked. The font trick gives you a weapon, but using it means accepting collateral damage.

The age of free data is ending. The only question is who pays the toll — the machines that took everything, or the humans who made it.

That’s not a technical question. It never was.

FAQ

Q: Won't AI companies just switch to OCR and bypass the poisoned font entirely?

A: Yes, probably. OCR will read the rendered pixels instead of the underlying text. But that's not the point — every workaround costs compute, slows the harvest, and signals resistance. The font isn't a wall; it's a toll booth.

Q: What does this mean for everyday content creators?

A: Your work is being scraped right now without consent. This technique gives you a defensive option, but it forces a real choice: protect your data or maintain full accessibility for screen-reader users. You can't do both.

Q: Is breaking accessibility tools ever justified as a protest tactic?

A: That's the uncomfortable core of this. The system that makes the font trick necessary is the real villain here. When creators feel forced to exclude vulnerable users just to stop machines from stealing their labor, the blame belongs on the companies that made consent optional in the first place.

📎 Source: View Source