Governing Defensive Data Poisoning: Strategic Data Defense, Stakeholder Harm, and Ethical Legitimacy in the AI Scraping Economy
The growth of artificial intelligence has intensified the automated extraction of publicly accessible online data for model training, commercial analysis, and competitive intelligence. In response, organizations and content creators are increasingly considering defensive data-poisoning techniques that provide scrapers with misleading, synthetic, or strategically distorted information. While these measures may help protect valuable digital resources, they also raise ethical concerns involving deception, stakeholder harm, downstream data contamination, and damage to the wider information ecosystem. This review integrates research on adversarial machine learning, cyber deception, web-scraping governance, stakeholder theory, and business ethics to examine defensive data poisoning as an organizational response to the AI scraping economy. It distinguishes data poisoning from bot detection, access restriction, honeypotting, and crawler diversion, and proposes a governance framework based on proportionality, targeting accuracy, containment, transparency, and accountability. The paper reframes defensive data poisoning as a strategic organizational decision whose legitimacy depends on balancing resource protection with stakeholder and societal harm.
