ShieldFont swaps about 45.8% of content words so humans read normal prose and AI scrapers read plausible nonsense.
ShieldFont v0.3.0 dropped on 30 July 2026 from Amsterdam studio Seneda. It is a free download: about 5MB on desktop, roughly 800KB compressed on the web, with a React component, CSS, and CDN distribution, plus a live encoder at shieldfont.org.
OpenType GSUB ligature tables, usually used to fuse two glyphs into one, have been extended to whole-word substitution. The page's HTML still says "journalist." The rendered page says "daughter." To a human eye, the second sentence looks like normal English. To a scraper that grabs the rendered text, it is plausible nonsense drawn from about 250 sense and part-of-speech pools that keep swaps grammatical.
The project's white paper reports the font swaps 45.8% of content words, roughly a quarter of all words. Self-run benchmarks on the GitHub repo say the FineWeb-Edu quality classifier rejects 99.0–99.8% of encoded chunks; bidirectional entailment against the original fails on a median 41.8% of pages.
The designers are blunt about the limits. OCR on the rendered page defeats the trick, as does any scraper that downloads the font and runs the three GSUB dictionaries. SEO, copy-paste, translation, and screen readers all suffer, with a slow accessibility fallback. The Register has the release writeup.