Updated September 13, 2026 CulturePolicy Cara

Scraping the anti-AI art platform Cara cost under ten dollars

Illustration for the Cara scraping story

A Reddit user says they scraped roughly 12 million images, just over 12 terabytes, from the anti-AI art platform Cara for under ten dollars, and posted about it as a fun project.

Cara exists specifically to keep artists’ work away from AI training. The cost figure is what makes the episode more than a platform breach: it sets a price on defeating every consent mechanism the site had in place, and that price is under ten dollars.

What Cara was built to prevent

Photographer Jingna Zhang started Cara in 2023 as a safe space for artists to share their work without fear of it being scraped for generative AI. According to Zhang, it ran anti-bot and anti-scraping measures. Its robots.txt told bots not to scrape for AI. It had opted out of federated services.

On August 14, 2026 Zhang shared on Instagram that a Reddit user had posted in r/DefendingAIArt: “I scraped all of Cara, an anti-AI art platform! Was a fun project, happy to answer any questions here.” According to PetaPixel, the Redditor claimed just over 12 terabytes, obtained at a cost of under ten dollars. AsiaOne reported roughly 12 million images belonging to more than a million users. The post was later deleted and the user was banned.

Zhang’s reaction on Instagram was blunt: “What the hell must I do? Artists just want a place online where platforms don’t feed their work to AI.” To the argument that the site should simply have been harder to scrape, she replied: “A door not being bank vault-strong isn’t an invitation to violate.”

Opt-out signals are requests, not locks

The episode exposes the uncomfortable center of every opt-out mechanism in the AI training debate. robots.txt directives, federated opt-outs and platform terms of service are all requests. They are readable by anyone who intends to honor them and invisible to anyone who does not. Publicly visible images are, by definition, retrievable, and the cost of retrieving them at scale is now less than lunch.

That is not an argument that Cara did anything wrong. It is an argument about what those measures can and cannot deliver.

What a platform can actually promise

The distinction the episode draws is between refusal and prevention. A platform can refuse cooperation, signal non-consent in every machine-readable form available, and make bulk retrieval inconvenient. It cannot make publicly displayed work uncopyable, and Cara had already implemented the first three.

Copyright litigation and data provenance standards are moving on this, slowly. Until they arrive, a consent signal that costs ten dollars to ignore functions as etiquette, and etiquette binds only the parties who already accepted it.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.