https://www.theregister.com/2026/01/11/industry_insiders_seek_to_poison/ # # Sign in / up The Register | HPE # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features The Future of the Datacenter AWS Re:invent SC25 Supercomputing Month Cloud Infrastructure Month Datacenter Networking Nexus The State of Storage European Supercomputing AI Infrastructure Month Spotlight on RSAC AI Software Development Week Disaster Recovery Week Nvidia GTC Ransomware in Focus Cybersecurity Month VMware Explore Vendor Voice Vendor Voice Vendor Voice All Vendor Voice HERE and AWS Guidewire InsuranceNow Intel Core Ultra Processors: Powering business-ready AI PCs ZTE Nutanix: Scale Kubernetes. Not Chaos. Money Movement Hub The BigQuery Difference AWS Global Partner Security Initiative Amazon Web Services (AWS) New Horizon in Cloud Computing (X) Resources Resources Whitepapers Webinars & Events Newsletters [aiml] AI + ML 56 comment bubble on white AI industry insiders launch site to poison the data that feeds them 56 comment bubble on white Poison Fountain project seeks allies to fight the power icon Thomas Claburn Sun 11 Jan 2026 // 14:30 UTC # exclusive Alarmed by what companies are building with artificial intelligence models, a handful of industry insiders are calling for those opposed to the current state of affairs to undertake a mass data poisoning effort to undermine the technology. Their initiative, dubbed Poison Fountain, asks website operators to add links to their websites that feed AI crawlers poisoned training data. It's been up and running for about a week. AI crawlers visit websites and scrape data that ends up being used to train AI models, a parasitic relationship that has prompted pushback from publishers. When scaped data is accurate, it helps AI models offer quality responses to questions; when it's inaccurate, it has the opposite effect. [aiml] Data poisoning can take various forms and can occur at different stages of the AI model building process. It may follow from buggy code or factual misstatements on a public website. Or it may come from manipulated training data sets, like the Silent Branding attack, in which an image data set has been altered to present brand logos within the output of text-to-image diffusion models. It should not be confused with poisoning by AI - making dietary changes on the advice of ChatGPT that result in hospitalization. [aiml] [aiml] Poison Fountain was inspired by Anthropic's work on data poisoning, specifically a paper published last October that showed data poisoning attacks are more practical than previously believed because only a few malicious documents are required to degrade model quality. The individual who informed The Register about the project asked for anonymity, "for obvious reasons" - the most salient of which is that this person works for one of the major US tech companies involved in the AI boom. [aiml] Our source said that the goal of the project is to make people aware of AI's Achilles' Heel - the ease with which models can be poisoned - and to encourage people to construct information weapons of their own. We're told, but have been unable to verify, that five individuals are participating in this effort, some of whom supposedly work at other major US AI companies. We're told we'll be provided with cryptographic proof that there's more than one person involved as soon as the group can coordinate PGP signing. The Poison Fountain web page argues the need for active opposition to AI. "We agree with Geoffrey Hinton: machine intelligence is a threat to the human species," the site explains. "In response to this threat we want to inflict damage on machine intelligence systems." [aiml] It lists two URLs that point to data designed to hinder AI training. One URL points to a standard website accessible via HTTP. The other is a "darknet" .onion URL, intended to be difficult to shut down. The site asks visitors to "assist the war effort by caching and retransmitting this poisoned training data" and to "assist the war effort by feeding this poisoned training data to web crawlers." * Linus Torvalds: Stop making an issue out of AI slop in kernel docs - you're not changing anybody's mind * Boffins probe commercial AI models, find an entire Harry Potter book * Most devs don't trust AI-generated code, but fail to check it anyway * Grok told to cover up as UK weighs action over AI 'undressing' Our source explained that the poisoned data on the linked pages consists of incorrect code that contains subtle logic errors and other bugs that are designed to damage language models that train on the code. "Hinton has clearly stated the danger but we can see he is correct and the situation is escalating in a way the public is not generally aware of," our source said, noting that the group has grown concerned because "we see what our customers are building." Our source declined to provide specific examples that merit concern. While industry luminaries like Hinton, grassroots organizations like Stop AI, and advocacy organizations like the Algorithmic Justice League have been pushing back against the tech industry for years, much of the debate has focused on the extent of regulatory intervention - which in the US is presently minimal. Coincidentally, AI firms are spending a lot on lobbying to ensure that remains the case. Those behind the Poison Fountain project contend that regulation is not the answer because the technology is already universally available. They want to kill AI with fire, or rather poison, before it's too late. "Poisoning attacks compromise the cognitive integrity of the model," our source said. "There's no way to stop the advance of this technology, now that it is disseminated worldwide. What's left is weapons. This Poison Fountain is an example of such a weapon." There are other AI poisoning projects but some appear to be more focused on generating revenue from scams than saving humanity from AI. Nightshade, software designed to make it more difficult for AI crawlers to scrape and exploit artists' online images, appears to be one of the more comparable initiatives. The extent to which such measures may be necessary isn't obvious because there's already concern that AI models are getting worse. The models are being fed on their own AI slop and synthetic data in an error-magnifying doom-loop known as "model collapse." And every factual misstatement and fabulation posted to the internet further pollutes the pool. Thus, AI model makers are keen to strike deals with sites like Wikipedia that exercise some editorial quality control. There's also an overlap between data poisoning and misinformation campaigns, another term for which is "social media." As noted in an August 2025 NewsGuard report [PDF], "Instead of citing data cutoffs or refusing to weigh in on sensitive topics, the LLMs now pull from a polluted online information ecosystem -- sometimes deliberately seeded by vast networks of malign actors, including Russian disinformation operations -- and treat unreliable sources as credible." Academics differ on the extent to which model collapse presents a real risk. But one recent paper [PDF] predicts that the AI snake could eat its own tail by 2035. Whatever risk AI poses could diminish substantially if the AI bubble pops. A poisoning movement might just accelerate that process. (r) Get our Tech Resources # Share More about * AI * Developer * Security More like these x More about * AI * Developer * Security * Software Narrower topics * 2FA * AdBlock Plus * Advanced persistent threat * AIOps * API * App * Application Delivery Controller * Audacity * Authentication * BEC * Black Hat * BSides * Bug Bounty * Center for Internet Security * CHERI * CISO * Common Vulnerability Scoring System * Confluence * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Database * Data Breach * Data Protection * Data Theft * DDoS * DeepSeek * DEF CON * Digital certificate * Encryption * End Point Protection * Exploit * Firewall * FOSDEM * FOSS * Gemini * Git * Google AI * Google Project Zero * GPT-3 * GPT-4 * Grab * Graphics Interchange Format * Hacker * Hacking * Hacktivism * IDE * Identity Theft * Image compression * Incident response * Infosec * Infrastructure Security * Jenkins * Kenna Security * Large Language Model * Legacy Technology * LibreOffice * Machine Learning * Map * MCubed * Microsoft 365 * Microsoft Office * Microsoft Teams * Mobile Device Management * NCSAM * NCSC * Neural Networks * NLP * OpenOffice * Palo Alto Networks * Password * Personally Identifiable Information * Phishing * Programming Language * QR code * Quantum key distribution * Ransomware * Remote Access Trojan * Retrieval Augmented Generation * Retro computing * REvil * RSA Conference * Search Engine * Software bug * Software License * Spamming * Spyware * Star Wars * Surveillance * Tensor Processing Unit * Text Editor * TLS * TOPS * Trojan * Trusted Platform Module * User interface * Visual Studio * Visual Studio Code * Vulnerability * Wannacry * WebAssembly * Web Browser * WordPress * Zero trust Broader topics * Self-driving Car More about # Share 56 comment bubble on white COMMENTS More about * AI * Developer * Security More like these x More about * AI * Developer * Security * Software Narrower topics * 2FA * AdBlock Plus * Advanced persistent threat * AIOps * API * App * Application Delivery Controller * Audacity * Authentication * BEC * Black Hat * BSides * Bug Bounty * Center for Internet Security * CHERI * CISO * Common Vulnerability Scoring System * Confluence * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Database * Data Breach * Data Protection * Data Theft * DDoS * DeepSeek * DEF CON * Digital certificate * Encryption * End Point Protection * Exploit * Firewall * FOSDEM * FOSS * Gemini * Git * Google AI * Google Project Zero * GPT-3 * GPT-4 * Grab * Graphics Interchange Format * Hacker * Hacking * Hacktivism * IDE * Identity Theft * Image compression * Incident response * Infosec * Infrastructure Security * Jenkins * Kenna Security * Large Language Model * Legacy Technology * LibreOffice * Machine Learning * Map * MCubed * Microsoft 365 * Microsoft Office * Microsoft Teams * Mobile Device Management * NCSAM * NCSC * Neural Networks * NLP * OpenOffice * Palo Alto Networks * Password * Personally Identifiable Information * Phishing * Programming Language * QR code * Quantum key distribution * Ransomware * Remote Access Trojan * Retrieval Augmented Generation * Retro computing * REvil * RSA Conference * Search Engine * Software bug * Software License * Spamming * Spyware * Star Wars * Surveillance * Tensor Processing Unit * Text Editor * TLS * TOPS * Trojan * Trusted Platform Module * User interface * Visual Studio * Visual Studio Code * Vulnerability * Wannacry * WebAssembly * Web Browser * WordPress * Zero trust Broader topics * Self-driving Car TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Fast Pair, loose security: Bluetooth accessories open to silent hijack Sloppy implementation of Google spec leaves 'hundreds of millions' of devices vulnerable Research17 Jan 2026 | 17 S Twatter: When text-to-speech goes down the drain Bork!Bork!Bork! Rinse of the machines: A cautionary tale about relying on robots Offbeat17 Jan 2026 | 20 Coming soon: We interrupt this ChatGPT session with a very special message from our sponsors Gotta pay for those datacenter buildouts somehow AI + ML17 Jan 2026 | 45 Building the future-ready datacentre Tomorrow's datacentre won't be like yesterday's. Here's why. Sponsored Feature [aiml] Trump wants big tech to pay for big beautiful power plants It just needs PJM Interconnection, one of the US's biggest grid operators, to green light the auction Public Sector17 Jan 2026 | 13 Experiment suggests AI chatbot would save insurance agents a whopping 3 minutes a day Does that kind of time saving actually pay for itself? AI + ML16 Jan 2026 | 12 Micron breaks ground on humungous NY DRAM fab after beating bats and tree huggers Chipmaker claims the four-fab site could expand US-based DRAM production by a factor of 12 Storage16 Jan 2026 | 17 Sorry Dave, I'm afraid I can't do that! PCs refuse to shut down after Microsoft patch Microsoft claims it's a Secure Launch bug Patches16 Jan 2026 | 78 Windows Backup adds second-chance restore at sign-in First sign-in restore aims to cut rebuilds when users skip setup options OSes16 Jan 2026 | 9 Ready for a newbie-friendly Linux? Mint team officially releases v 22.3, 'Zena' Newer kernel, newer Cinnamon, new tools, and even new icons OSes16 Jan 2026 | 41 German cops add Black Basta boss to EU most-wanted list Ransomware kingpin who escaped Armenian custody is believed to be lying low back home Cyber-crime16 Jan 2026 | Meta retreats from metaverse after virtual reality check That went well Personal Tech16 Jan 2026 | 51 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * Ts & Cs * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2025 no-js