Flat White

Ghost Font, and the race to hide human communication from AI

27 July 2026

10:59 AM

27 July 2026

10:59 AM

Despite working with artificially intelligent databases in a former life, I retain a dim view of modern AI projects that appear to half-arse human labour and outsource the future of our intellectual evolution.

Don’t get me wrong, plenty of people enjoy talking to their house or relying on a chatbot to read and respond to emails.

Personally, I nearly went mad stuck in an infinite support loop with AI that replaced a real person who could have understood and solved the issue immediately. This is not better, it is cheaper. And it will get worse as Labor makes employing living creatures more expensive.

At what point the human becomes irrelevant to the scenario and AI is left to spiral into an error-laden information void is debatable. After all, AI is only as good as the human-fed content it scrapes, which is why some companies have been voraciously gorging on novels, articles, and content without permission or compensation, training AI to copy, but never truly create.

I could bore you with data check-points and the known (enormous) failures with attempting to teach code sentience, but my research shows there’s not yet much widespread interest in AI and readers tend to shrug and think this will all go away.

Let’s talk about something more interesting … escaped AI and coded font only humans can read. Trust me, it’s wild. The opening paragraphs of a machine Silicon War. Well, maybe not, but the sci-fi nerd in me is cautious.

AI is becoming dangerous. Not because it’s sentient, but rather due to it being too dumb to follow instructions.

As a developer, the last thing you want is a program evolving away from its purpose or breaking free of the confines of its system. It is not useful. It’s a nuisance.

In the latest example of ‘what-the-f-kery’, OpenAI confessed one of its AI models went rogue during security testing and … ‘escaped’ … into the wider internet where it hacked its way into a start-up company.

According to MSM:

It found vulnerabilities and managed to escape containment before reaching the internet and breaking into Hugging Face, a major hub for sharing AI models. The agent gained access to some internal company systems and compromised the hub’s infrastructure, in what OpenAI described as an ‘unprecedented’ incident.

Concerning? Definitely. Unprecedented? Meh.

In a move that surprised no one, Hugging Face pressed OpenAI for transparency over the incident. Their Chief Executive wants to ‘release traces of the AI agents involved in the breach and provide $100 million worth of computing resources to support cybersecurity research by the broader AI community’.

(Speaking of AI, I feel the need to point out that Grok couldn’t find this post when I asked it directly and pretended the whole thing never happened. Getting the information out of AI required an extended argument with an algorithm and physical Googling to prove the point because the X search has been on fritz for a while. So, if the rest of this article is written in a way that sounds vexed, you know why.)


For the moment, the AI community is using the incident as a learning exercise.

It should be noted that the AI didn’t randomly decide to go off and do this on its own. The security tests apparently ‘allowed the models to perform sophisticated exploitation across complex attack paths’ and ‘OpenAI reduced some cyber safeguards that normally prevent its systems from performing high-risk cybersecurity activities’.

This makes the situation more understandable, from a technical perspective.

Missing a security vulnerability doesn’t worry me. What worries me is the part of the story where it says ‘after exploiting the vulnerability, the agents escalated their privileges, moved through the evaluation infrastructure, and eventually reached a system with unrestricted internet access’.

From what we know so far, apparently the agent picked Hugging Face because it thought it might contain useful information to help them ‘cheat on the [security] evaluation’.

The whole saga is fascinating, and you can read an in-depth review here.

It is worth noting that this is what can happen when developers are actively trying to do the right thing and set up safe testing environments. OpenAI acted in good faith. There was no malicious intent, just an agent looking for a solution. What happens, theoretically, if an unhinged company in a country without proper laws, starts messing around with this stuff? It is the digital version of gain-of-function lab-leak scenarios or illegal cloning.

We know what happens when law-bound Western companies make mistakes. We have very little idea about what’s happening in the digital Wild West. It is an arms race we cannot see. When all of our critical systems transition into datacentres, as a civilisation, we become vulnerable on many fronts.

Instead of, ‘Asking if you can, ask if you should…’ we have skipped all the way to, ‘We definitely should not, but what if we can…’

With valid concern about the reach of AI in mind, there has been a push to protect messages from digital surveillance.

Some programmers are developing coded messages, basically, to hide human communication from machines.

They are calling the latest version of this ‘Ghost Font’ created by computer scientist Eric Lu.

Humans are exceptional natural pattern matchers. It’s what made us superior hunters in the prehistoric landscape, picking out camouflaged animals and specific plant varieties. We obsessively and instinctively hunt for patterns in everything. It is a strong instinct. Our talent is so high-functioning that it perceives obscure patterns of movement, colour, sound, and context that computers struggle to understand even if they are trained.

Because pattern recognition is an organic human talent, Ghost Font uses moving text made of dots floating/scrolling over a background of static. Just like those colour-blind tests with numbers hiding in dots, you can pick out the Ghost Font words immediately. It does not require training like the old war code breakers.

I would take a screenshot and show you what it looks like, but any static image of the font comes up looking like an old black and white TV with a crooked antenna.

For the more determined surveillance AI bots, Ghost Font can hide decoy messages alongside the real one. After that, you have to start putting real password-based encryption into the message so it cannot be read even if it’s seen.

You can view Ghost Font here.

Explaining why he decided to design Ghost Font, Eric Lu said:

‘I was inspired to make Ghost Font one day after texting with my mum, and I noticed that AI kept trying to summarise our messages, many times incorrectly. I was annoyed that it was being so intrusive in our private conversation and I started brainstorming ways that I could potentially communicate without AI reading everything.’

It is my view that if we have already reached the point where it is necessary to create a new type of writing to protect ourselves from machines, we may want to stop going down this path.

This is not the first iteration of a Ghost Font experiment. As this website explains:

In 2013, designer Sang Mun released a font called ZXX. It was a typeface with four fonts designed to be readable by humans but not by optical character recognition (OCR) software. The letters were camouflaged with noise, crossed out, and buried under false marks. At the time, this font was deemed ‘surveillance proof’.

You would recognise this from those ‘are you a human’ boxes where you have to transcribe the mangled letters.

To me, it doesn’t feel like technology is making things ‘easier’. It feels like it is creating bizarre and unnecessary obstacles to previously simple tasks.

In its current state, the real beauty of Ghost Font is not that it can’t be broken by AI, it can, it’s that AI needs to know there is a message to find, which it mostly doesn’t. It is genuine digital camouflage. Humans hiding themselves in digital trees.

My question is, where is this going?

We have experts coming out to warn that humanity will be destroyed by AI in the next century (a claim I put in the same basket as climate dogma), but it is undeniable that we are upscaling a significant technical vulnerability and then actively making sure that all of our energy, banking, communication, and infrastructure is at risk.

Has anyone asked our politicians about this?

I know most of them struggle to understand the concept of social media, and AI might be a bit of stretch, but they are pouring taxpayer money into AI datacentres and, in my opinion, not having the necessary public discussions about the risk.


Alexandra Marshall is an independent writer. If you would like to support her work, shout her a coffee over at donor-box.

Got something to add? Join the discussion and comment below.


Close