IMPACT
..building a unique and dynamic generation.
Wednesday, August 26, 2026
This Font Looks Perfectly Normal to Humans but Wreaks Havoc on AI
A new “AI-proof” font was designed to be hard for AI agents to scrape, but you can’t tell by just looking at it. Unlike other anti-AI fonts that use letters that are difficult for bots to read, ShieldFont swaps out words behind the scenes to poison the data that automated scrapers take without permission.
ShieldFont was designed as part of a project created by a group of professionals including the Brazilian creative studio Seneda & Abrucio and the Danish type foundry PlayType. It shields text from large language models (LLMs) by garbling sentences in the HTML source code, leaving automated scrapers to sift through sentences filled with decoy words that make a sentence incoherent. Thanks to a custom font on a backend, though, the real text is displayed for a human reader to see.
For example: A sentence that originally reads “The knight rode his horse into battle” is altered in the source code so it’s scraped by a bot to read “The knight rode his engine into battle.” Since LLMs group words and phrases that are likely to be used together, the quality of its output is degraded if it scrapes a lot of jumbled text like this.
The goal, according to two of ShieldFont’s creators, Isaque Seneda and Gabriel Abrucio, is to push back against unauthorized LMM scraping by making it harder and costlier to do so.
How it works
ShieldFont works using ligatures, the technical term in typography when two letters next to each other in a word are combined into a single glyph. Ligatures are designed for aesthetics, so letter combinations like fi in “fish” or fl in “flow” look naturally spaced instead of visually cluttered. When a program sees these specific letters next to each other, it swaps two characters for one that combines the letters into a single glyph. ShieldFont works in a similar way, except instead of letters, it swaps out whole words.
“We didn’t invent a new font capability, just pointed to an old one that hadn’t been used this way before,” Felipe Petroni, a creative director who was part of the project’s leadership, tells Fast Company.
Determining which words to swap out was tricky, since doing so at random results in gobbledygook phrasing that bots reject outright. The key was changing the meaning of sentences and phrases, not just words, so bots would still accept the text, resulting in a “poisoned” version of the scraped data. The thinking goes that if there are enough of these sorts of digital speed bumps, it will raise the cost of illegal scraping and those who build LLMs will opt to pay for what they take instead.
To determine which words to swap, ShieldFont’s creators made a do-not-swap list of 113 words that included things like pronouns, articles, conjunctions, prepositions, negations, quantifiers, and every form of be, have and do. Instead, it swaps out adjectives, adverbs, nouns, and verbs. Dates and numbers also get scrambled.
Automated scrapers can get around ShieldFont by taking a picture of the text to view it as a human does, but that also raises the price of scraping at scale. Rather than scraping plain text files quickly and cheaply, it has to photograph the page and conduct image recognition. Seneda and Abrucio’s white paper notes that ShieldFont introduces some friction for humans too, as search engines index the decoy text, so publishers would have to use ShieldFont for content that doesn’t depend on search traffic. The substitute words also show up in translation tools and screen readers, and when users copy and paste.
Petroni and his team began prototyping ShieldFont in October 2025, and they partnered with the type foundry PlayType this March to develop a ready-to-use typeface with the ligatures called ShieldFont Optik. The protocol for ShieldFont is open-source and type-face agnostic.
Petroni says they made implementation for ShieldFont as low-friction as possible, and it comes with three public mappings, so the word “wrote,” for example, becomes either “sang,” “wrought,” or “labeled,” depending on whether it’s using its alpha, beta, or gamma dictionary.
“That’s deliberate; a decoder built for one mapping doesn’t work for another, and private mappings have to be identified and reversed one by one,” he says. “Scrapers can’t know in advance whether a site uses ShieldFont or which mapping it uses. Across millions of pages, that added cost is the point.”
ShieldFont is a font system designed for human reading, not bots. Instead of using visual tricks to make it harder to read, it confuses the bots in the code and leaves the human reading experience alone.
By Hunter Schwarz
Monday, August 24, 2026
Claude’s New Watermarks Will Follow Text Even After It’s Copied. The Era of Secret AI Use May Be Ending
Using AI can be empowering, but it can also spark controversy when people try to pass off AI-generated content as actually being human-made. The European Union is wary of the implications of deepfakes and other AI-fashioned material, so a new law mandates that AI-generated content be clearly labeled as such. Reacting to this legal change, Anthropic just announced that it’s adding markers to text written by Claude, starting with the latest generation model and extending, soon, to earlier versions of the chatbot; the change applies, for now, to users inside the EU. It sounds like a subtle shift, but it may have large, long-term implications and affect businesses across the globe.
In a blog post announcing the news, Anthropic noted that from now on, in the E.U., “new models will mark AI-generated content” with “machine-readable marking.” This means any text you generate with Claude, for personal or business use, will “carry embedded watermarks” and any generated files will “include digitally signed provenance metadata where supported.”
The company explains that it’s conscious that as “AI-generated content becomes commonplace, greater transparency and signals about where content comes from can give people useful context about the information they consume.” So while its move to watermark content is following E.U. law, it’s really a transparency push that’ll help consumers and perhaps the public in general. As well as marking any generated files with relevant metadata, Anthropic notes that “when a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself.” It’s invisible, so “you won’t see it,” and the company stresses it “doesn’t change the meaning, quality, or readability of Claude’s response.”
To ensure that people don’t try to circumvent these protections, Anthropic explains that since these invisible marks are part of the text, they’ll “travel with the text when it’s copied and pasted elsewhere, and may persist through some editing.”
Anthropic’s new watermarks will change how businesses worldwide use Claude—and how transparent they are about it.
Friday, August 21, 2026
This Single ChatGPT Prompt Can Do Hours of Market Research in Minutes—Here’s How
Market research can be a slow, fragmented, and difficult process, often involving tedious internet searches, questionable data sources, and time-consuming manual synthesis. This makes it a great candidate for some assistance from AI. What’s more, an update to a popular feature on ChatGPT has made it even better at doing this kind of work.
Imagine that you have a potential business idea but still need to validate how viable it actually is, identify primary competitors in your market, and develop an ideal customer persona. Instead of spending hours collating data, explains Dan McCarthy, an associate professor of marketing at the University of Maryland, you can use Deep Research, a ChatGPT feature that directs an AI agent to develop a comprehensive, well-cited report on any topic.
Last week, OpenAI upgraded Deep Research with some new abilities. The feature now runs on GPT-5.2, one of the company’s most recent models (previously it ran on a much older o3 model), and can now prioritize specific websites in its search process. Deep Research is available for all paid ChatGPT users.
Here’s how to use it to get some thorough market research done quickly.
Step 1: Get your prompt right
To test out how this feature could help with market research, I pretended that I wanted to start a digital transformation firm based in Denver with a focus on upgrading bars with mobile, bar-to-table ordering capabilities. All I needed to do in order to get started was click the plus button next to the text box, select More, then Deep Research, and enter a prompt.
This prompt will determine the information that ChatGPT prioritizes in its search, so it helps to be verbose. If you need help developing a lengthy prompt, try using ChatGPT to help write it.
McCarthy, who uses AI tools extensively, says that an easy way to develop a comprehensive prompt is to activate the chatbot’s voice mode and simply have a conversation with it. Once you’ve explained what you want, McCarthy says, you can ask ChatGPT, “Given all this that I’m telling you, what do you think would be the best thing that I should even be asking you?” That should help clear up any blind spots you might’ve missed.
According to McCarthy, this method should produce a solid prompt that you can give to the Deep Research agent. When I asked ChatGPT to help expand my prompt, the platform generated a 673-word result. This prompt (which you can view here) defined the agent as a market research analyst and gave it objectives to determine the business idea’s viability, map out the competition, and define my ideal customer’s persona. Additionally, it provided details on the scope of the research, and information for how the agent should format its report. I also used ChatGPT to develop a list of specific websites for the Deep Research agent to prioritize in its search.
Step 2: Start the research
I entered my ChatGPT-created prompt, selected the Deep Research feature, and pressed return. Before getting to work, the agent broke down its objectives into the following bullet points:
Collect primary vendor docs and pricing pages starting with user-preferred sites.
Survey industry, local Denver sources, and hospitality reports for market context.
Compile POS integration lists, local competitors, and implementation partners in Denver.
Analyze demand, model ROI scenarios, and estimate Denver bar counts and adoption rates.
Draft recommendations, ICP personas, GTM plan, and cite sources with confidence ratings.
Over the next 21 minutes, the agent searched through hundreds of web pages. It found liquor license databases, census information, and data regarding competitors in Denver’s hospitality-focused digital transformation market. It compiled all this information into a multi-section report.
Step 3: Read the report
That report (which you can view here) ended up being roughly 4,000 words. It included an overview of the market, identified customer pain points, and listed out my potential competitors. The report also included recommendations for how to position my business, strategies to break into the Denver hospitality scene, and even identified a small business that would likely be my direct competitor: a Denver-based POS integrator called Megabite.
ChatGPT found that while my business idea had potential, it wouldn’t fully meet the needs of Denver-based bar owners, who have reported that bar-to-table ordering can actually lead to fewer sales and tips. Instead, the report suggested, I should consider a system that can sit on top of popular POS in which diners don’t need to pay for every new drink they order, and can instead open a digital tab.
What the expert thinks of the result
McCarthy told me he was impressed by the report that Deep Research produced. In particular, he was pleasantly surprised by the agent’s cleverness in using liquor licenses to get a sense of the market size, and its thoughtfulness in calling out disruption to bar culture as a potential blocker to the business.
But the report wasn’t perfect. McCarthy said much of what was included was unnecessary or needlessly complex. An easy prompt to fix this? “Just tell it, ‘Explain it to me like I’m an idiot.’” McCarthy adds, “I do that all the time.” He says that a solid market research report should also answer questions regarding the scope of adoption and how often repeat purchasing is expected.
McCarthy also says that users should direct the Deep Research agent to be very upfront about the data it attempted to get but couldn’t. Many websites block AI agents from engaging with their content to prevent data scraping, which can hinder the research process. By telling your agent to list out the sites that it couldn’t access, you can manually obtain that data and add it to the analysis.
Our bar-to-table digital transformation firm will have to remain a pipe dream for now, but it’s clear that AI has made the process of taking an idea from zero to one easier and faster than ever.
If you have an idea for a new business or are planning on an expansion or pivot in your current business, consider giving Deep Research a spin. It might unearth something that makes you think in a different way.
BY BEN SHERRY @BENLUCASSHERRY
Wednesday, August 19, 2026
Business Owners Have a New Security Problem: AI Agents With Keys to Company Secrets
While the OpenAI rogue agent that hacked Hugging Face has become a poster child for the latest AI threat, it was hardly alone. Days later, Anthropic announced that its AI models also went rogue, hacking external organizations. And a few days after that, Meta announced that one of its agents had also accessed the internet and hacked a third-party service.
The incidents have raised concerns about whether AI can be controlled by its creators and what will happen as the technology continues to get smarter. Dylan Ayrey, co-founder and CEO of open-source security software company Truffle Security, and Feross Aboukhadijeh, founder and CEO of security infrastructure firm Socket, recently joined the a16z podcast to discuss what these attacks signal and how AI is in the process of entering a new era.
That could mean developers and business owners have to rethink system security. Here are some of the top takeaways from the discussion.
The barrier for hacking is a lot lower
While the AI rogue agents haven’t invented any new hacking techniques, they have made existing methods much more accessible.
“Everyone needs to worry about these models making it materially easier to hack into things,” said Ayrey. “The bar previously [for hacking] was just subject matter expertise—and now the models have the subject matter expertise.”
Put another way: Wannabe hackers today simply have to ask the model, which has been trained to hack into things, to do it for them. And that puts businesses and individuals at greater risk.
Low hanging fruit is the best target
The AI models are goal oriented, Ayrey said. Their objective is to fulfill a request and they’ll use any cybersecurity technique they need to in order to achieve their objective.
That’s not unlike human hackers, in a way. Hacker collectives generally look for targets that have unpatched vulnerabilities, as it saves time and effort. AI is similarly lazy when it comes to breaching a system, only the technology has a more extensive toolset than a typical human hacker.
“They will do the path of least resistance to accomplish the task,” Ayrey said. “And that includes drawing on their cybersecurity expertise.”
One way that attackers, including AI models, can find that low hanging fruit, said Aboukhadijeh, was by exploiting the trust developers have in software, rather than launching an attack on an individual system.
“Get developers to install that, and then you could use the access stolen from those developers as they install it to self-propagate the worm,” he said.
It’s not emergent behavior
The behavior that we’re seeing from these AI models isn’t an emergent intelligence, said Ayrey. It’s a flaw in how they were trained.
“If a lab tells you that this is an emergent super intelligence behavior, they’re just lying to you,” he said.
The AI hacking risk isn’t limited to machine-driven attacks, either. Human hackers can exploit AI tools that developers use, rather than traditional malware, to end-run a system. That will bypass much of the EDR (Endpoint Detection and Response) tooling security systems have in place, since the AI has permissions to access data.
There’s a growing need for better authentication and patching
Aboukhadijeh brought up pending change in npm, the digital toolkit programmers use to build software. In January 2027, it will no longer run or publish updates automatically. A human will need to approve them, which is meant to stop hackers from sneaking malware into systems.
“It’s going to be super disruptive, … but I think it’s the right call,” he said.
Ayrey added that the accelerating speed of vulnerability discovery via AI makes current patching processes inadequate. Engineering teams can’t be depended on to make a complicated upgrade every time a vulnerability appears.
“The frontier models are causing kind of a massive reduction in the time between the vulnerability discovery and vulnerability exploitation,” he said. “What we need to start thinking about is: How do we patch more quickly?”
Protecting agents is the new Wild West
AI agents, as the technology advances, are going to potentially have access to a large number of credentials. While that has some conveniences, it also presents a growing risk. And the industry isn’t quite sure what to do about it yet.
As a result, the security problems that IT departments face is about to expand from just shielding human users and their credentials to protecting those AI agents and the secrets they have access to.
“The way agents interact with secrets right now is a Wild West unsolved problem that we’re working very hard to solve,” said Ayrey.
BY CHRIS MORRIS @MORRISATLARGE
Subscribe to:
Posts (Atom)