The artist run network Cara, built to keep user work out of AI training, was scraped for a third time in ten days on August 22; founder Jingna Zhang calls it a 'targeted attack.'
Cara — the artist-run, public-benefit social network launched in late 2022 with terms of service explicitly blocking AI training use — was scraped for a third time in ten days on August 22, 2026, when copyrighted images and metadata from its roughly 1.5 million users appeared on Academic Torrents, the open-data torrent network.
Founder Jingna Zhang, a Singapore-based fashion and fine-art photographer and a 2018 Forbes 30 Under 30 honoree, called the lift "a targeted attack meant to cause artists pain." Prior scrapes in the same window had targeted Reddit — a dataset later removed by its original poster — and Hugging Face, the AI model clearinghouse where researchers and labs publish and download models. Three different platforms, three different surfaces, all in ten days.
Cara is the product Zhang built in response to a familiar grievance. The first wave of generative image models — Midjourney, Stable Diffusion, DALL-E — was trained on bulk-scraped internet images, including many under copyright, and artists watched their work surface inside outputs they had never consented to. Cara's terms of service and consent-preserving product features are designed to make that harder: the platform's pitch to its users is that work uploaded to Cara is not a free corpus for the next training run. Since launch, the network has attracted over 1.5 million users, including many professional and hobbyist artists who view generative AI as a livelihood threat and a values affront.
The structural fact is what makes the third scrape more than another entry in the AI-ethics notebook. Cara is a public benefit corporation, and Zhang has described it as a volunteer project with no financial means. The opt-out infrastructure — a platform that promises consent as its product — is small, slow, and volunteer-run. The other side is an automated training pipeline that does not need a budget, a legal opinion, or a relationship with the platform. It needs a URL.
That asymmetry is the mechanism. Whether a platform writes AI training into its terms of service, designs its product to refuse scraping, or runs as a public benefit corporation instead of a venture-funded startup, none of those signals currently bind the actors pulling the data. Scrapers can claim the lift is legal, while platforms and artists can each claim they did their part; the dataset still ends up on Academic Torrents, packaged for downstream training.
Zhang has framed the scrape as exploitation of Cara's volunteer posture. Her response, beyond the public statement, is a GoFundMe to fund a legal defense — a recognition that opt-out by platform policy is not the same as opt-out by enforcement. The "don't blame victims" line that runs through her public posts is the critique the story has to carry: scraping is a choice, and so is the platform design that shrugs it off.
What would make the signal stick? Four pressure points, none of them guaranteed:
The next test is procedural, not principled. The GoFundMe will measure whether a legal defense fund can be sustained by a community of users; the next dataset posted to Academic Torrents will show whether the cadence accelerates or pauses; a ruling in any of the pending copyright suits against model trainers would change the calculus everywhere. The opt-out principle is older than Cara, and the question is no longer whether artists want to enforce it. It is who pays to make the enforcement real.