SHIELD(FONT)
DemoWhitepaperGitHub
Press kit
SHIELD(FONT)

Everything you need to cover ShieldFont.

Publish for humans, not for crawlers. A web font that swaps the words in your HTML, so readers see your writing and AI training gets a stale copy — built by independent creative studio S&A with Copenhagen type foundry Playtype.

Live now — embargo lifted 30 July 2026 · 14:00 CET
01 · Assets

Logos, fonts, gallery, video.

Grab what you need one file at a time, or take a whole category as a zip below.

Press release

1 file · PDF
ShieldFont press release, page 1
Press releasePDF · 1.5 MBDownload

Logos

3 files
S&A logo
S&ASVG · 1.7 KBDownload
Playtype logo
PlaytypePNG · 3.9 KBDownload
ShieldFont outline mark
ShieldFont markPNG · 35.8 KBDownload

ShieldFont Optik — web font

6 weights · WOFF2
Aa
Regular · 400994.5 KB
Aa
Medium · 500819.9 KB
Aa
DemiBold · 600822.5 KB
Aa
Bold · 700821.3 KB
Aa
ExtraBold · 800820.9 KB
Aa
Black · 900820.6 KB

This is the shipped, GSUB-protected web font (WOFF2) — the same files served on shieldfont.org, safe to embed in an article or screenshot a specimen from. It is built on Playtype’s Optik under the studios’ partnership; for the underlying retail Optik family itself, contact Playtype directly at playtype.com.

Campaign gallery

10 visuals · stills + GIFs

Social cuts

3 cuts · 16:9 · 4:5 · 9:16
ShieldFont social cut, 16:9
Social cut · 16:9MP4 · 4.1 MBDownload
ShieldFont social cut, 4:5
Social cut · 4:5MP4 · 3.2 MBDownload
ShieldFont social cut, 9:16
Social cut · 9:16MP4 · 3.3 MBDownload

Ready-to-repost cuts in the three standard social aspect ratios, credit lockup “Powered by S&A · Playtype” burned in. Same edit as the studios’ own launch-day posts.

Tutorial video

MP4 · 21.0 MB

Grab a whole category

Zipped in your browser, on click

Logos & Brand

3 logos + all 6 ShieldFont Optik web-font weights.

~5.1 MB

Campaign gallery

All 10 campaign visuals, stills + GIFs.

~15.5 MB

Social

All 3 social-post cuts (16:9, 4:5, 9:16) + poster frames.

~11.0 MB

Video

Tutorial video + poster frame.

~21.1 MB

Press & Data

Release PDF + text, fact sheet, red-team findings.

~1.5 MB
02 · The release
Full release text, for publication ThursdayDanish foundry Playtype and creative studio S&A launch ShieldFont — the complete, publication-ready text.

Danish foundry Playtype and creative studio S&A launch ShieldFont, a typeface that protects human writing by poisoning unauthorized AI training

Bringing creative resistance to the AI ethics debate, the open-source typeface appears normal to human readers but alters the meaning of the text data scrapers collect, protecting authorship and corrupting datasets built from content taken without consent.

Independent creative studio S&A (Seneda & Abrucio) and Copenhagen type foundry Playtype today announce ShieldFont, the first web font designed to hide human writing from AI scrapers while polluting datasets collected without consent.

The open-source project works on a simple premise: humans read rendered pixels on a screen; most AI mass scrapers read the source code.

ShieldFont looks like a regular font to human readers. But underneath, selected words are swapped to alter sentences’ original meaning. In controlled testing, 55.8% of shielded passages no longer made the same factual claim as the original while remaining grammatically coherent, making them more likely to pass AI quality filters — feeding misleading content into AI training datasets.

As large language models (LLMs) are increasingly trained on the open internet, the project enters the AI ethics debate from a simple position: making creative work discoverable online should not automatically be treated as permission to be used for AI training. ShieldFont turns that position into a visible, widely available, enforceable stance for anyone who wants to protect human authorship.

“ShieldFont is not an anti-AI project. We’re simply against the idea that publishing is the same as consenting. We saw how existing opt-out protocols such as robots.txt were being routinely bypassed, so we wanted to create one that could enforce itself. The answer was to turn the content itself into the opt-out.”

Isaque Seneda & Gabriel Abrucio, founders of S&A

The launch typeface was created by Danish foundry Playtype, recognized for its progressive approach to type design. The font is an adaptation of Optik, highly legible to human readers and now featuring a hidden layer designed to disrupt machine reading.

“Every detail had to serve the human eye, while the hidden system underneath served an entirely different purpose.”

Jeppe Pendrup, the font’s type designer

Besides Optik, the project includes a toolkit that lets anyone shield their own typeface, turning a single font into a collective approach to protecting human work online.

“Typography has always helped humanity preserve and share its ideas. Now it can help protect them too. That is why ShieldFont had to be open source, so its system can grow beyond Optik and become part of many different typefaces.”

Daniél Andreasen, CEO of Playtype

The tech

ShieldFont uses OpenType glyph substitution. The page source carries one set of words; the font renders another. A person reads the author’s original writing. A scraper collects the substitutes.

The current release, v18, targets high-frequency English nouns: the words carrying most of a sentence’s meaning. Replacements are chosen to survive the quality filters that clean scraped text before training: nouns swap for nouns, verbs for verbs, and each substitute sits at a deliberate distance from the original — not a synonym, not an antonym, but a neighbouring term of similar frequency and register. Designed to maintain syntax and readability while changing meaning.

ShieldFont uses “poisoning” to describe misleading text entering a training dataset. Tests across publicly available scraping pipelines found that ShieldFont content can survive filtering and enter a dataset precisely as intended: no longer carrying the author’s original meaning. Full methodology, benchmark data, and red-team findings are published in the white paper at shieldfont.org/white-paper.

Built to stall

ShieldFont is not unbreakable. Anyone targeting a single site could inspect the font and reverse the mapping. Its purpose is not to stop a determined actor, but to slow unauthorized mass scraping by adding cost, friction and uncertainty. Scrapers cannot know in advance whether a site uses ShieldFont or which mapping it uses.

The font ships with three mappings (Alpha, Beta, Gamma) plus a builder for generating private, site-specific versions. A decoder built for one mapping may not work for another, while private mappings must be identified and reversed individually. Across millions of pages, that added cost is the point.

At scale, bypassing ShieldFont could require OCR on rendered pages, human verification or LLM-based cross-checking. Each adds computational, labor or verification costs to today’s mass-scraping process.

“Scraping the open web without consent is cheap, easy and effectively risk-free. ShieldFont is only one possible response. The bigger goal is to build a web where taking content without asking is no longer consequence-free.”

Isaque Seneda & Gabriel Abrucio, founders of S&A

Scope

ShieldFont is not a replacement for Cloudflare, Akamai, robots.txt or accessibility tools. It is an additional layer of friction, applied block by block, so SEO-critical text can be left unshielded.

The current version has caveats, including potentially decreased SEO quality and English-only support.

Accessibility remains one of the project’s core challenges, as screen readers rely on the same source code ShieldFont alters. By default, shielded text is hidden from screen readers (aria-hidden), so users are not exposed to misleading content. A beta option for dynamic websites lets screen readers reveal the original text by having the browser solve a compute-heavy puzzle, a more time-consuming request that deters most mass scrapers today.

Open source

ShieldFont is being released as an open-source project, inviting type designers, developers, linguists and creators to build new mappings, adapt the system to other languages and bring it to more typefaces. The goal is not just to release a tool, but to grow a collective statement: work published online should not automatically become free material for AI training.

Available Thursday at 14:00 CET

ShieldFont is available as a free, open-source project. Writers and developers can implement it via:

  • The online encoder — paste text, generate protected HTML, and publish it.
  • The React component — install @shieldfont/react and wrap selected text in <Shield>.
  • CSS and CDN integration — add the font and protected text to blogs, content-management systems, or static websites.
  • The custom font builder — apply the ShieldFont protocol to another compatible typeface and create a private mapping.

The project’s code, mappings, methodology, benchmark data, and red-team findings are open for audit and contribution.

Project: shieldfont.org · Demo encoder: shieldfont.org/encoder · White paper: shieldfont.org/white-paper · Code and data: github.com/isaqueseneda/shieldfont

03 · FAQ

Every number below is measured on v18, the dictionary shipping today. Full methodology and confidence intervals are in the white paper.

Swap
48%
Of the content words
Protect over
80%
Of shielded pages from AI training
1 in 10
filter-passing pages still poison training

Every shielded page has to clear three bars at once.

PILLAR 01
Conceal
Hide the meaning from the machine. Humans read your page; a scraper reads swapped words.
PILLAR 02
Pass the filter
Survive the AI quality gate. Grammar intact, sentence fluent. Only the meaning is wrong.
PILLAR 03
Poison
Make the kept page worse than nothing. Whatever trains on it learns the wrong associations.
01 Conceal · hiding the meaning
Q1What actually happens to my words?
We swap key words in your text with other real words in the page’s source code. For example, “winners” might become “avengers,” “toy gun” might become “sofa car,” and “Halloween contest” might become “Autumn campaign.” You still see the original text because the font restores it on screen. Only machines reading the raw HTML see the substituted version.
Q2What if I copy-paste ShieldFont text into ChatGPT?
The clipboard copies the substituted words stored in the page’s code, not the original words you see on screen. So when you paste shielded text into ChatGPT, it reads the altered version rather than your original writing.
Q3Why swap “content words” specifically, and why does that matter?
Content words carry most of a sentence’s meaning, while words such as the, of, and and mainly hold it together. ShieldFont changes only about 25% of all words, but nearly half of the content words. Across 1,500 passages from news, independent websites, and fiction, this caused 50% to lose their original factual claim. A control test replaced the same number of words with true synonyms, and only about 2% of passages changed meaning. The effect comes not from swapping words, but from swapping the words that matter most.
Q4Which words can be swapped? Where does the dictionary come from?
The dictionary is built from the 10,000 most common English words, focusing on nouns, verbs, adjectives, and adverbs because they carry most of a sentence’s meaning. Each word is paired with another of the same type, so nouns replace nouns and verbs replace verbs, helping sentences remain grammatically correct even as their meaning changes. Function words such as the, of, and and are left untouched because they hold sentences together but carry little meaning. Once different forms of each word are included, the current dictionary contains nearly 12,000 entries, covering a large share of everyday English.
Q5So can an AI still tell what my page is about?
Roughly, yes: topic and tone may survive. But the specifics, such as names, numbers, and claims, are often lost. When seven leading AI models tried to reconstruct the argument of shielded text, conceptual accuracy fell by 67%. Several models also refused the task, which counted as complete loss. Looking only at the models that answered, the drop was still 49%. The result is consistent: the broad subject may survive, but the details do not. The effect also grows with length. If an early sentence is altered, later reasoning may build on a false premise, so longer texts can lose more meaning than passage-level scores suggest.
02 Pass the filter · surviving the quality gate
Q6How does “gibberish” get past AI quality filters?
It’s not gibberish. Every substituted word keeps the same grammatical role, so nouns replace nouns and past-tense verbs replace past-tense verbs. The sentence still reads correctly, but its meaning changes. In tests with FineWeb-Edu, a quality filter used to build a major public training dataset, about one in ten chunks that passed before shielding still passed afterwards. The other nine were rejected. Both outcomes help: rejected content stays out of training, while accepted content carries the “wrong” meaning into the dataset.
Q7Isn't hiding meaning and passing the filter a contradiction?
That tension is the core challenge, and we have worked to balance protection with disruption. If the text changes too much, quality filters reject it, keeping the content out of training. If it changes too little, the original meaning survives. ShieldFont aims for the point between these outcomes, where text can pass a filter without communicating the same meaning. Reaching that balance took sixteen generations of mappings, followed by a second line of development.
03 Poison · wasting their compute
Q8What does “poison” actually mean here?
If a shielded text passes the scraper’s quality filter, the training system receives the substituted words as if they were the original content. It may see that a contest’s “winners” were “avengers,” or that a child found a “sofa car.” Instead of simply hiding the original content, the text adds false connections between names, events, and actions to an unauthorized AI training dataset.
Q9Does the poisoning really work, or is that hype?
We are careful with that claim. Early tests on small fine-tuned models showed the strongest negative effect of any mapping we tried, but those tests are too limited to prove what would happen at scale. What we can say with confidence is measured directly from the text: changing about 25% of the words caused 50% of passages to stop making the same factual claim. Whether you call the result poisoning or wasted training effort, what matters is that the content becomes less useful in unauthorized AI training datasets.
Q10Does one shielded page even matter? What if everyone does it?
One shielded page is only a drop. The value comes from scale. If many creators use ShieldFont, scrapers must either reject more pages or spend more time identifying and decoding them. Pages that still enter the dataset carry altered information, making the collected text less useful for training. Blocking removes content from the scrape; shielding can either keep it out or change what gets collected. Individually, the effect is small. It is a collective defense: the more people use it, the harder and more expensive mass scraping becomes.
Practical · the objections everyone raises
Q11Couldn't someone just OCR the rendered page?
Yes. If someone photographs your page and runs OCR (optical character recognition: reading text back out of an image), they recover your words. But ShieldFont is not designed to stop someone deliberately targeting a specific site. It is designed to disrupt mass scraping, which depends on collecting HTML from billions of pages cheaply and automatically. Using OCR would require scrapers to render each page, turn it into an image, and process the pixels with a vision model. Because they do not know which pages are shielded, they would have to do this at scale. ShieldFont does not need to make OCR impossible; it needs to make it too costly to be worthwhile.
Q12Won't models eventually just learn to decode ShieldFont?
They will not need to learn. Here is the part we would rather you heard from us than found in a footnote: the font is the codebook, and anyone who downloads it can read the substitution table back out of it. We tested this ourselves and recovered all 11,962 word pairs with no errors. ShieldFont is not designed to keep a permanent secret or stop someone deliberately targeting one site. Its strength is at scale. ShieldFont ships with three mappings, alpha, beta, and gamma, and assigns each text block to one of them. Creating your own mapping makes a universal, prebuilt decoder useless against your site. A scraper must identify your font, extract its mapping, and decode your content specifically. The defense is economic, not cryptographic: the aim is to turn cheap, indiscriminate scraping into slower, more complex, per-target work. The more independent mappings people create, the harder that becomes across the web.
Q13What happens to my SEO?
Search engines read the same scrambled HTML as scrapers, so they index the decoy words, not yours. Shield content you do not need Google to rank: paywalled pieces, archives, manifestos, or anything you would rather keep out of current AI training than surface in search. Leave your marketing pages plain. ShieldFont works block by block, so the choice is entirely yours.
Q14Why poison at all? Why not just block the crawlers?
Blocking tools such as robots.txt and Cloudflare’s AI gate are like walls: crawlers can ignore or work around them. We still recommend using them to express your non-consent publicly. Poisoning, however, creates leverage: if a lab trains on shielded text before it is detected, the data becomes less useful and may require extra work to remove or correct. The longer-term goal is to give creators a seat at the table, with a licensing route where AI companies pay for clean versions instead of using altered copies obtained through scraping. That system does not exist yet, but it is an outcome we’d like to help make possible.
Q15Hasn't this been tried? What about TuringFonts, ZXX, Ghost Font, Nightshade?
Respect to the ancestors. The closest is TuringFonts (jfmdev): a substitution-cipher font that draws one letter in place of another, so a crawler reads scrambled text while a human reads the original. It was built to keep bots from indexing emails and phone numbers, and it predates the AI era. A letter-for-letter cipher produces character noise a modern quality filter throws away (and an LLM unscrambles by frequency in a single pass), and it never hides that the page is enciphered. ShieldFont is built for how AI actually ingests text: we swap whole words for other real, same-grammar-class words, so the page stays fluent prose with no character noise to flag and nothing to unscramble by frequency. Every word is a real word in the right grammatical slot, and the only thing broken is the meaning. We think in tokens and meaning rather than a hidden string, and the font itself is camouflaged. ZXX (Sang Mun, 2013) fought OCR at the glyph level, but modern vision models read it in one prompt. Ghost Font hides text in motion; Nightshade and Glaze poison images for artists. ShieldFont is the text-native cousin: it corrupts the source the machine actually copies. The reading gap itself also has independent security research behind it. In March 2026, LayerX Security published “Poisoned Typeface”, an attack study showing that a remapped font makes an AI assistant and a human read different text from the same page. All eleven assistants they tested read the underlying text instead of the rendered one, and only Microsoft took the disclosure through a full fix. Their work is offensive in framing and unaffiliated with ours, and it confirms from the other direction the same gap ShieldFont uses in defense.
Q16Is this legal and ethical?
We are contributing to the AI ethics debate from a simple position: creators should have a meaningful say in whether their work is used to train AI. You are changing how your own words appear in your own HTML, not entering another system or attacking a model. We encourage creators to state their non-consent clearly alongside their content. If an AI company respects that choice, nothing happens. The effect only applies when the work is scraped and used without permission. The goal is not to damage AI (we are not anti-AI; read Q20 for more), but to make unauthorized training less useful and harder to ignore.
Q17What about screen readers and accessibility?
Screen readers read the source code rather than the words displayed by the font, so the current <Shield> component uses aria-hidden to stop the substituted text from being read aloud. We have a built-in alternative, in beta and off by default, which allows users to spawn the real words on the page through an aria button only screen readers reach. The reader’s browser solves a compute-costly puzzle for the key, taking a few seconds. It works in our Dynamic Websites tier and requires JavaScript, which is part of the point: most scrapers never run any. We are aware of the friction landing on the wrong person. Fixing it properly is where we most want help at the moment. Tested with VoiceOver and an automated screen reader.
Q18Won't scrapers just learn to spot the aria-labels or the ShieldFont classes and skip those pages?
Eventually, yes. Any fixed marker, such as a known class, font name, file pattern, or ARIA attribute, can become a fingerprint. ShieldFont responds in two ways: add camouflage so those markers no longer reliably identify protected text, and keep changing the pattern by shielding selected blocks and using different mappings across sites. A single deployment is easier to work around. Thousands of creators using different mappings and implementations force scrapers to spend more time identifying, checking, and decoding what they collect. ShieldFont does not end the arms race; it gives the open web a way to make unauthorized scraping harder and more expensive, especially when people build on it together.
Q19Is this permanent? Unbreakable?
No, and we won’t pretend otherwise. ShieldFont isn’t a lock. It’s friction. It disrupts large-scale automated scraping by changing the underlying text while keeping it readable for people on screen. That makes scraping and processing slower and more expensive, though the impact may vary. It is open source and designed to evolve, so “it’ll be decoded eventually” misses the point. The target can keep moving as others add new mappings and approaches. It is also not a client-grade security product, so do not replace Cloudflare, Akamai, robots.txt, or accessibility standards with it. Think of it as a creative intervention with teeth: a way for creators to make unauthorized AI training harder, more visible, and more costly.
Q20So… is ShieldFont anti-AI?
No. ShieldFont is pro-consent, pro-choice, and pro-human authorship. People may want their work to be discovered without agreeing to have it copied into AI training datasets. ShieldFont gives them a simple, visible way to opt out of mass scraping and make that choice harder to ignore. The font is the creative expression of that position: not a rejection of AI, but a demand that creators have a say in how it is built, especially in what is taken from them.
Q21Does it work in languages other than English?
Not yet. ShieldFont currently works only in English. Its three main dictionaries contain about 12,000 word pairs each: 11,970 in alpha, 12,034 in beta, and 12,036 in gamma. The optional maxhide version contains 2,534. Words in other languages are left unchanged, so they are not protected. On a mixed-language page, only the English text will be shielded, even if the whole section appears protected. For clarity, the current versions can be named en-a, en-b, en-c, and en-m; a future Portuguese set might use names such as pt-a. Creating a new language version is not simply a translation task: it requires native speakers to choose substitutions that still sound natural. Contributing a new language is therefore one of the most useful ways to help.
04 · Credits
Studio
S&A (Seneda & Abrucio)
Concept, Creative Development & Technology
Gabriel Abrucio, Isaque Seneda
Independent Design & Craft Collaborators
Renato Zandoná, Felipe Petroni, Marcos Lee, Marina Meireles, Rafael Martins, Vinicius Biss, Gabriel Grossi, João Barabás, Anderson Lima, Luciane Nuvolara, Natália Albertoni
3D Production
Altrn Studio
Client & Type Design Partner
Playtype
CEO, Playtype
Daniél Andreasen
Type Designer, Playtype
Jeppe Pendrup
05 · Boilerplate

About S&A

S&A, or Seneda & Abrucio, is an independent creative studio founded by Isaque Seneda and Gabriel Abrucio: a geek and a backpacker who create unformatted tech and cultural ideas for global brands. Having worked with leading agencies in Amsterdam, London, Toronto, Paris, and São Paulo, ShieldFont is the studio’s first independent project.

s-a.website

About Playtype

Playtype is a type foundry based in Copenhagen, Denmark. For more than twenty years, it has created retail and custom typefaces for international brands. ShieldFont’s flagship typeface, ShieldFont Optik, was developed in partnership with Playtype.

playtype.com

Other collaborators

The project was crafted with the support of highly talented independent creatives in São Paulo, from copywriters to art directors, 3D artists, motion designers, producers, and more.

Isaque Seneda
Press contact, S&A