Skip to content
Brands & Campaigns July 21, 2026

Some Brands Are Now Poisoning the AI Crawlers They Used to Just Block

AI bots scrape owned content billions of times a day and rarely send a visitor back. A few publishers and e-commerce brands are fighting the economics with traps. Most marketers shouldn't.

By The State of AI Marketing newsroom
Share
Credit: JAC Growth Marketing

Cloudflare fields more than 50 billion AI crawler requests a day, and since March 2025 it has fought a slice of them with a trap. Its AI Labyrinth tool spots a bot that ignores the rules and funnels it into a maze of AI-generated pages. The pages are factually correct, carry none of your real content, and lead nowhere. The crawler spends its compute reading filler.

Sixteen months later the tactic has a name and a small following building their own versions. Digiday reported on July 17 that a handful of publishers and e-commerce brands have started running what the trade now calls LLM honeypotting: instead of trying to keep AI bots out, they let the bots in and make the visit expensive.

The methods vary. Some sites add proof-of-work challenges or slowdowns that cost the crawler time. Some build infinite content mazes that spin up plausible but meaningless pages forever. The most aggressive try model poisoning, feeding the scraper statistically coherent nonsense in the hope it degrades whatever model trains on it.

The goal is to make each crawl cost the scraper more than the data is worth.

That math is the whole pitch. Simon Wistow, co-founder of the edge-computing firm Fastly, framed it as changing “the economics of attacking” rather than blocking traffic outright. He put a sharper point on it too: “If they could burn through that 10 million funding in one crawl then suddenly those businesses aren’t viable.” A startup that has to pay for compute every time it re-scrapes a poisoned site is a startup with a shorter runway.

Wistow also said the quiet part. “This is early, bespoke and experimental, not table stakes,” he told Digiday. Some large e-commerce brands are trying it with early success, he said, but nobody is shipping it as a standard defense.

Not everyone thinks it survives contact with reality. Frederick Jahn, co-founder of the analytics firm Centennal, called it “a good concept, but more on a marketing level, and like a gimmick.” Chris Dicker, CEO of Candr Media, warned that if poisoned pages spread, the impact on the open web would be “horrendous,” because the same junk that fools a crawler can end up in front of a human.

Here is why the tactic exists at all. Training and indexing an AI model means crawling enormous volumes of pages as cheaply as possible, then doing it again as the model refreshes. Meta alone drove 5.3 billion agent requests through DataDome’s network in the second quarter, up 74% in three months, and its real-time indexing crawler grew 163%, according to DataDome’s Q2 report. The economics only work for the scraper while each page is nearly free to fetch. Honeypotting attacks that assumption. Make the fetch cost real compute, or corrupt the data it returns, and you have put a tax on the thing that was taxing you.

The catch is that it only works on polite bots, the ones that follow links and read what they are served. The worst-behaved scrapers spoof their identity and ignore signals, so they walk past the trap. And a poison page is a loaded gun pointed at your own foot: the crawler you corrupt today might be the one deciding tomorrow whether to cite you in an answer.

That is the part marketers should sit with. For the last year the entire owned-media playbook has pointed the other way. The goal was to get quoted inside AI answers rather than ranked on a page, a shift we covered in the split between AI Overview visibility and Google rankings and in the collapse of the organic click. Poisoning the crawler that feeds those answers is the opposite move. It makes sense when your content is a product someone pays for, which is why publishers with paid archives are rebuilding their sites around access deals and licensing instead. It makes no sense when your content is a funnel meant to pull a buyer toward you.

So honeypotting works in one narrow case: when the content is the product and the crawler is a thief. For the marketer whose site exists to be found and recommended, feeding poison to the machine that could recommend you is paying to disappear. Block the bots that only cost you money, cut licensing deals where the content is worth licensing, and spend the rest of the budget being worth quoting.

Quoted in this story

  • Simon Wistow, Co-founder, Fastly (source)
  • Frederick Jahn, Co-founder, Centennal (source)
  • Chris Dicker, CEO, Candr Media (source)

Want your perspective in coverage like this? Get quoted.

Sources

This story is part of our running coverage: the full picture →

Get Net Effect.

The net effect of AI on your marketing: the stories that matter, twice a week, in five minutes.

More from Brands & Campaigns