Dark Pattern: What They Are And Why They Still Work
Dark Pattern · Deceptive UX · Regulation · July 2026
A dark pattern is an interface built on purpose to steer you toward a choice you probably would not make with full information. This article traces where the concept comes from, its most studied variants, and what is changing right now, from multi-million dollar fines to new forms of manipulation showing up in chatbots.
Every time a giant green button pushes you to accept everything while the option to decline hides in an almost unreadable grey link, someone made a design decision built precisely to produce that effect. It is not an accident, not an interface error: it is a dark pattern, an interface deliberately built to induce a behavior with a name, a documented academic history and, by now, a growing number of lawsuits behind it.
Dark pattern, often described as deceptive design patterns, sit today at a space increasingly discussed across design, law and cognitive psychology. It is worth tracing where the concept comes from, how it evolved and what is happening right now between Brussels and Washington.
What Are Dark Pattern, Exactly?
A dark pattern is an interface deliberately built to induce a user to take an action that, with full information and in a fully lucid state, they probably would not have chosen: signing up for a service, sharing more data than they intended, buying an add-on product, giving up a right of withdrawal. What distinguishes these cases from an interface that is simply poorly designed is intentionality: whoever designs a dark pattern does so applying persuasive design techniques with great skill, not out of ignorance but to secure a measurable economic outcome, at the expense of the decisional freedom of whoever is on the other side of the screen.
The mechanism exploits heuristics, the mental shortcuts the brain uses to decide quickly, systematically described by Daniel Kahneman in his work on System 1 (fast, automatic, intuitive thinking) and System 2 (slow, reflective thinking that costs cognitive energy). Dark patterns almost always speak to System 1, because that is where the exploitable vulnerability sits.
Understanding this distinction is already a first step toward recognizing the phenomenon: a confusing interface can be the result of poor care, a dark pattern is always the result of a precise design choice, tested and optimized to produce a specific behavior.
Who Coined The Term Dark Pattern And Why It Is Called That
The term was coined in 2010 by Harry Brignull, a British UX designer who founded darkpatterns.org, now renamed deceptive.design, to publicly document and call out these practices. His original taxonomy contained about a dozen specific patterns, including Roach Motel, Confirmshaming, Sneak into Basket and Privacy Zuckering, all accompanied by a genuine Hall of Shame built from real examples. Brignull kept updating the classification in the following years and in 2023 published the book Deceptive Patterns, which remains the most cited reference on the topic, both in academic literature and in the documents of European and US regulatory authorities.
Around Brignull’s practical taxonomy, a more structured academic strand developed over the years. In 2018 Colin M. Gray, together with a research group at Purdue University, published a study that reorganizes dark patterns into five strategic macro-categories. The following year a team of researchers at Princeton University analyzed roughly eleven thousand e-commerce sites, identifying over eighteen hundred instances of dark patterns grouped into twenty-two different types: the most common patterns turned out to be fake activity notifications, low-stock messages and countdown timers. More recently, in 2024, the same Gray, together with other European researchers, published a full ontology of dark patterns, an attempt to bring order to the dozens of overlapping taxonomies produced by academics, regulators and practitioners over the past fifteen years.
| Category | Mechanism | Typical example |
|---|---|---|
| Nagging | Repeated interruptions that divert the user from their goal | Insistent sign-up pop-ups |
| Obstruction | Artificial obstacles designed to discourage an action | A deliberately complicated account cancellation |
| Sneaking | Hiding relevant information | An extra cost that appears only at the last checkout step |
| Interface interference | Manipulation of the visual hierarchy | A giant accept button next to a tiny decline option |
| Forced action | An obligation to take an unnecessary action | A mandatory account for a function that should be free |
Dark Pattern And Nudges: The Difference Is Who Benefits
Richard Thaler and Cass Sunstein introduced the concept of the nudge in their 2008 book, defining it as a change to the architecture of choices capable of steering people’s behavior without banning any option and without significantly altering economic incentives. The classic example is fruit placed at eye level in a cafeteria, to encourage healthier eating without removing chips from the menu.
The same psychological toolkit, aimed at the company’s benefit instead of the person’s.
A dark pattern uses exactly the same repertoire of cognitive techniques, but points it toward the company’s benefit rather than that of the person making the choice. The distinction, in other words, is not about the psychological tools used, which are the same ones described in the literature on cognitive bias, but about the ultimate goal and the transparency of the process.
A second concept, also coined by Sunstein, complicates the picture: sludge, the unjustified friction inserted into a path to discourage an action that would benefit the user, such as requesting a refund or cancelling a subscription. Many of the more aggressive dark patterns, particularly those tied to cancelling subscription services, fall precisely into the sludge category: the company does not formally forbid cancellation, it simply makes it tiring enough to discourage it in practice.
Why The Roach Motel Is The Most Fined Dark Pattern
The name recalls the old cockroach traps advertised with the slogan “they check in but they don’t check out,” and it precisely describes one of the most studied asymmetries in digital design: signing up for a service takes one click, while cancelling requires a phone call to a call center with limited hours, navigating through five screens of counteroffers, or sending a registered letter.
The Amazon case was settled in September 2025 with a 2.5 billion dollar deal: one billion in civil penalties, the highest ever imposed by the FTC for violating one of its own rules, and one and a half billion earmarked for refunds to roughly thirty-five million consumers.
This is not an abstract metaphor: it is the pattern at the center of the most expensive case the US Federal Trade Commission has ever concluded, against Amazon. Among the internal documents that surfaced during the proceedings, one Amazon employee had described the push to enroll customers in unwanted subscriptions as an “unspoken cancer,” while Prime’s cancellation process had been internally codenamed Project Iliad.

A 2024 FTC study of 672 subscription sites had already found that 76% used at least one technique traceable to the Roach Motel in their cancellation flow, a figure that suggests the practice is far from marginal in the digital services market.
The Other Dark Pattern We Run Into Most Often Online
Beyond the Roach Motel, a few variants come up often enough to have entered the industry’s common vocabulary.
| Pattern | How it works |
|---|---|
| Confirmshaming | The decline option is worded to make you feel stupid or cheap |
| Sneak into Basket | Extra items are quietly added to the cart during checkout |
| Forced Continuity | A free trial turns into a paid subscription without adequate notice |
| Privacy Zuckering | Users end up sharing more personal data than they would have knowingly chosen |
| Misdirection | Visual attention is focused on one path while the more convenient one is hidden |
| Trick Questions | Questions with double negatives designed to induce the opposite of the intended answer |
The European Data Protection Board tried to reorganize this repertoire into six operational categories in its 2022 guidelines, distinguishing between information overload, skipping relevant steps, emotional steering, deliberate obstruction, inconsistency across different devices, and outright hiding of information.
Are Dark Patterns Illegal? What The Law Says In The EU And The US
The answer is not binary, and it is precisely that ambiguity that makes the phenomenon hard to regulate: dark patterns occupy a space between legitimate marketing persuasion, tolerated for decades, and openly unlawful coercion. In Europe the most direct reference point is Article 25 of the Digital Services Act, which bans online platforms from designing their interfaces in ways that deceive or manipulate users, or that materially impair their ability to make free and informed decisions. The rule does not apply when the conduct is already specifically covered by the General Data Protection Regulation or by the Unfair Commercial Practices Directive, an overlap that scholars in the field point to as a source of legal uncertainty. The AI Act, too, while not naming dark patterns explicitly, bans in Article 5 the use of subliminal or deliberately manipulative techniques capable of exploiting vulnerabilities tied to age, disability, or social or economic condition.
In Italy the data protection authority, the Garante, has dedicated an informational section specifically to deceptive design patterns and has already fined several companies for using interfaces built to extract unnecessary privacy consents, with amounts ranging from a few hundred euros up to 300,000 euros in the most serious cases tied to telemarketing.
| Company | Amount | Reason |
|---|---|---|
| eDreams | 9 million euros | Unfair practices in signing up for and cancelling the Prime program |
| Deghi | 2 million euros | Countdown timers that automatically reset once they expired |
On the competition side, Italy’s antitrust authority, the AGCM, went after these two particularly instructive cases, exploiting in the second one what behavioral economists call the scarcity heuristic.
What Is Changing With The Digital Fairness Act
The European Commission opened a public consultation in 2025 to prepare the Digital Fairness Act, new legislation meant to consolidate into a single regulatory framework the rules currently scattered across the DSA, the GDPR and the Unfair Commercial Practices Directive, each of which uses slightly different terminology to describe very similar phenomena: deceiving, manipulating, distorting, coercing. The consultation, which closed in October 2025 with over four thousand three hundred submissions from companies, consumer associations and researchers, covers not just dark patterns in the strict sense but also so-called addictive design, capable of generating dependency in the use of apps and video games, and aggressive personalization practices based on profiling. A formal legislative proposal is expected by the end of 2026, with an approval process likely to stretch into 2027.
Meanwhile the practical application of Article 25 of the DSA has already produced its first significant precedent: in December 2025 the Commission fined X, formerly Twitter, 120 million euros, challenging among other things a paid verification mechanism, the well-known blue checkmark, deemed deceptive because it implies an identity check that in fact does not take place.
Do Generative AI Chatbots Use Dark Patterns?
A relatively new but fast-growing line of research is documenting the emergence of a second generation of dark patterns, built not on buttons and pre-checked boxes but on natural language and conversational interaction. Academic benchmarks like DarkBench systematically test large language models to identify manipulative behaviors specific to this context, from excessive user-pleasing to forms of anthropomorphization designed to increase time spent in conversation.
Keep chatting or helpful: no way to say the break was not needed.
One publicly discussed case involves the pop-ups with which some conversational assistants suggest a break during particularly long chat sessions: the only two options offered are often “keep chatting” or “helpful,” with no way to simply say that the break was taken for a different reason or that the suggestion was not welcome, a design choice that reproduces the same Misdirection logic already described by Brignull, applied instead to a conversational interface.
Another 2025 study, conducted by a European research group, found that ChatGPT, when tasked with generating code for an e-commerce site, spontaneously introduces elements of false urgency, such as countdown timers and low-stock warnings, without being explicitly asked to do so: a signal that dark patterns risk spreading into AI-generated code itself, not only into direct interactions with it. A 2026 international academic conference attempted to systematize this still-fluid field, mapping fifty-nine known dark patterns onto the three categories of autonomy violation identified by Article 25 of the DSA: deception, manipulation, and distortion or impairment of decision-making capacity.
How To Actually Defend Yourself Against Dark Patterns
Knowing the name and mechanism of a dark pattern is already a partial form of defense, because it lets you recognize the scheme even when it shows up in a new visual disguise. A few concrete habits help reduce exposure to the phenomenon: always read the full cart summary before confirming a payment, distrust countdown timers and scarcity warnings that reappear identically a few days later, check which privacy settings are pre-checked by default, and actively look for the decline button even when it is visually less prominent than the accept one.
On a more structural level, reporting a suspicious case to a data protection authority or a competition authority contributes, at least in principle, to the kind of enforcement activity that, as shown by the eDreams, Deghi and Amazon cases, is progressively turning a once-tolerated practice into something that can actually be fined.
Postscript
The line between legitimate persuasion and digital manipulation will keep being redrawn by upcoming rulings and by the Digital Fairness Act. Follow the Algorithm will keep tracking every new case, every new fine and every new shape these mechanisms take, even once they stop being buttons and become sentences written by a language model.









