Google Trends showed a steady climb in paywall-related searches through 2024 to 2026, and the intent behind them is pretty clear. People searching "bypass paywall," "12 ft ladder paywall," and "archive.today paywall" weren't researching business models.

Then in July 2025, the News/Media Alliance secured the takedown of 12ft.io, the most-searched bypass service on the web. The domain has been dark since.
Search volume for that specific tool dropped. The behavior didn't. It moved to archive.ph, to sideloaded browser extensions, and to a category of software that didn't exist when the original wave of bypass tools appeared: AI browsers.

How many readers actually do this
The behavior is mainstream, and the research is consistent about it.
Pew Research Center surveyed 9,482 U.S. adults in March 2025 and found that 74% hit paywalls at least sometimes when looking for news. When they do, 53% look for the information somewhere else, 32% give up, and 1% pay. Across the full year, 83% of U.S. adults paid nothing for news at all.

Source: Pew Research Center
Research from Toolkits and National Research Group puts a finer point on it: 53% of consumers say they actively try to bypass paywalls, and 69% avoid clicking links to sites they know are gated. Even 66% of people who already pay for at least one digital subscription still try to get around other publishers' paywalls.
That last number is the one to sit with. Willingness to pay and willingness to bypass are not opposites. The same reader does both.
What does this cost publishers
Lost subscription revenue. Every bypassed session is a conversion that had a chance and didn't get one.
Eroded pricing power. Content that's reliably free through a workaround stops reading as premium, and that shows up in renewal rates before it shows up anywhere else.
Broken measurement. Bypassed sessions still generate pageviews. They just don't generate the identity signals that segmentation, personalization, and forecasting run on. Traffic looks healthy while conversion looks broken, and the two numbers never reconcile. Toolkits has written on how hard circumvention is to quantify for exactly this reason.
The bypass methods in use
|
Method |
How it works |
Stopped by client-side paywalls? |
|
Incognito and cookie clearing |
Resets the meter counter stored in the browser |
No |
|
Archive services (archive.ph, archive.today) |
Serves a cached snapshot captured before the gate rendered |
No |
|
Browser extensions (Bypass Paywalls Clean and forks) |
Strips or blocks the gating script before it executes |
No |
|
Crawler spoofing |
Presents as Googlebot to get the indexable version |
No |
|
Syndication hunting |
Finds the same wire story on an ungated site |
Not applicable |
|
AI browsers (Atlas, Comet) |
Reads DOM content hidden behind an overlay, or reassembles the article from other sources |
No |
The pattern across every row: these methods work because the paywall logic runs in the browser. Anything that lives client-side lives in territory the visitor controls.
Bypass Paywalls Clean is instructive here. The News/Media Alliance got it removed from GitLab in 2024 and restricted on GitHub the same year. It's still installed, still maintained, still working, just sideloaded now. Takedowns move these tools. They don't remove them.
AI browsers are the version of this problem publishers can't see
The bypass tools publishers learned to detect announced themselves. An extension leaves fingerprints. A known bypass service arrives from a known IP range.
AI browsers do neither. Research reported by Cybernews found that OpenAI's Atlas and Perplexity's Comet retrieved the full text of subscriber-only articles, including from MIT Technology Review. Two techniques do most of the work:
- Reading what's already there. Client-side overlay paywalls, the kind used widely across magazine and trade publishing, load the full article into the DOM and cover it. A human sees a gate. An agent reads straight through it.
- Reassembling from fragments. When content genuinely isn't served, agents rebuild it from syndicated copies, social posts, and coverage of the coverage.
The detection problem is what makes this different. These browsers appear in logs as standard Chrome sessions, with request patterns close enough to humans that user-agent filtering catches nothing useful. Block aggressively on those signals and you block subscribers.
Server-side access control is the only layer that holds here, because it decides what to send before anything reaches the client. An agent can't read content the server never rendered.
How Admiral Protect handles it
Admiral Protect enforces access at the server, which closes the loopholes client-side scripts can't reach.
- Server-side gating. Protected content isn't delivered to unqualified sessions in the first place. There's no hidden DOM to read and no script to strip.
- Blocker-aware detection. Ad blockers, paywall blockers, and circumvention tools are identified at the session level, then routed to a registration prompt, an alternative offer, or a full block.
- First-party proxy. Calls route through the publisher's own domain, which removes the third-party signature militant blockers key on.
- Value exchange instead of a dead end. A blocked visitor is still an audience. Email signups, social follows, and ad-free subscription offers all run inside the same visitor journey, with targeting and A/B testing behind them.
Read more about Admiral Protect
Results at CBS Sports, Mediaite, and NY Post
Mediaite cut its average adblock rate by 45% and recovered 52% of adblock revenue while growing subscription revenue through Admiral Transact. Full numbers in the Mediaite case study.
New York Post, CNBC, and CBS Sports run Admiral detection at scale, with blocked pageview recovery reaching 70% to 90% and millions recovered per property.
FAQs
Q: Is bypassing a paywall illegal?
It sits in a contested area. There's no statute naming the act, and enforcement has run through copyright instead. The News/Media Alliance used DMCA notices to take down 12ft.io in July 2025 and to restrict Bypass Paywalls Clean's repositories in 2024. Both actions targeted the tools and their hosts rather than individual readers. Read more about it here.
Q: Can a client-side paywall be made bypass-proof?
No. Any logic running in the browser can be inspected, blocked, or read around by whoever controls that browser. Client-side gating raises the effort required. It doesn't set a ceiling.
Q: How do I tell how much bypassing my site is getting?
It doesn't show up in standard analytics, because bypassed sessions register as ordinary pageviews. You need session-level detection that flags circumvention signals as they happen. Admiral's analytics dashboard reports this alongside adblock rates.
Q: Does blocking AI browsers block real readers?
It does if you're filtering on user agent, since Atlas and Comet present as Chrome. Server-side enforcement avoids the tradeoff by gating on session qualification rather than client identity.
Q: What about AI crawlers scraping content for training?
Related problem, different enforcement point. Copyright Access Control covers detection and enforcement against unlicensed AI scraping.
Why this matters now
Paywall bypass used to be a fringe behavior with a few well-known tools. It's now default reader behavior with tooling built into mainstream browsers, and the newest generation of it is invisible to client-side defenses by design.
Publishers who want subscription revenue to hold need enforcement that runs before content leaves the server, and a path for blocked visitors that leads somewhere other than a wall. If you're still deciding on a model, what is a paywall covers the options, and launching a subscription model in 30 days covers the build.
Talk to Admiral about closing the gap between your paywall and what readers are actually doing to it.





