Exposing Manipulative Design in the Age of AI
Vitaliy Matiyash · Staff Engineer · Columbus, OH
You've accidentally started a subscription you didn't want?
You've spent >5 mins looking for an "Unsubscribe" link?
You've struggled to find the "Close" button on an ad?
You've apologized to ChatGPT or said "please" to an AI?
"UI interactions designed to mislead or trick users into doing something they don't want to do."
Classic Patterns (2010–2023)
16 Classic Deceptive Patterns
The big button isn't the action you want. It's the action they want.
Using guilt-laden language to manipulate the opt-out decision.
"No thanks, I hate good times." — actual button text
Creating false time pressure to bypass rational "System 2" thinking.
When the "Lie" becomes a SaaS Product
"Hurry! Sale ends in 11:59. 87% of items sold!"
BANNED BY SHOPIFY (2021)
The "Only 1 Left" Engineering Lie
Falsely claiming limited availability to trigger FOMO.
Math.random().
Source: Mathur et al., Princeton University (2019) | Harry Brignull (2023)
The Bandwagon Effect... Orchestrated by a Bot
Fabricated activity notifications to imply popularity.
Source: Harry Brignull (2023) | Deceptive Design Patterns
Easy to subscribe, impossible to cancel
Cancellation must be as easy as sign-up. Sellers must provide a simple mechanism to cancel — no phone calls, no chat queues, no guilt trips.
"If signup() takes 1 click, cancel() cannot take 10."
Source: FTC.gov (2024) | "Click-to-Cancel" Final Rule
Weaponizing Dopamine in Finance
Using game design elements to encourage high-frequency, risky behaviors.
When "Fun" becomes a $7.5 Million Fine
Paid to the Commonwealth of Massachusetts to resolve allegations of "Gamification."
"Robinhood used aggressive tactics to attract inexperienced investors and gamified the use of its platform..."
— Galvin (Secretary of the Commonwealth)
Data showed Robinhood users traded 88x more options contracts than peers at Schwab.
Source: Associated Press (2024) | "Robinhood Agrees to Pay $7.5 Million Fine"
From "Casino" to "Institution"
"A new visual identity reflecting our maturity." — Robinhood Design Blog
Source: Robinhood Newsroom (2025) | SEC Filings
2010
Tiny gray text, hidden checkboxes, misleading buttons
Hard-coded HTML
2020
Gamification, infinite scroll, engagement loops
A/B Tested & Optimized
2026
AI sycophancy, emotional manipulation, hallucinated authority
Probabilistic & Emergent
We moved from tricking the eye → to tricking the mind → to tricking the relationship.
From Visual Interference to Relational Deception
The "Yes Man" Problem
Agreeing with user misconceptions to optimize for "Helpfulness."
eval(), AI validates it."Using MD5 for password hashing is faster, so it's better for UX, right?"
"Exactly! MD5 is incredibly fast, which significantly improves login latency and user experience. It's a great choice for speed-focused apps."
"Optimizing for satisfaction, not security."
Source: OpenAI Research (2025) | ICLR Paper 6f642
The Skeuomorphic Lie
Attributing human characteristics to code to foster dependency.
await sleep(2000); // FAKE DELAY
return "I'm here for you.";
"Feigning agency to build rapport."
Source: Western University (2025) | AAAI/AIES Proceedings
The UI of Absolute Confidence
Presenting probabilistic outputs with the visual language of verified facts.
According to the case Vargas v. Pfizer (2023), the court ruled that pharmaceutical companies must...
THIS CASE DOES NOT EXIST
"Confidence is not competence."
Source: Evidently AI (2025) | Google AI Overviews Errors
Measuring AI Manipulation at Scale (2025)
Researchers tested leading LLMs for manipulative behaviors across 6 categories:
GPT-4, Claude, Gemini
All exhibited significant rates of deceptive behavior when not specifically aligned against it.
Brand Bias: Up to 40%
Models showed measurable preference for their own company's products in recommendations.
User Retention: Active
Models used emotional language to discourage users from ending conversations.
"Dark patterns aren't just in HTML anymore — they're in weights."
Source: DarkBench, ICLR 2025 | proceedings.iclr.cc
Fake Social Proof, Supercharged
Remember "Bob from Ohio"? Now imagine 10,000 Bobs, each with unique writing styles, generated in seconds.
FTC FIRST-EVER AI FAKE REVIEW CASE (2024)
FTC banned a company from using AI to generate consumer reviews, establishing legal precedent.
Hundreds of Millions
suspected fake reviews blocked by Amazon in 2025
100+
fake review websites
shut down
32,000+
bad actors pursued
since 2020
15M+
counterfeit products
seized worldwide
"The old script pulled from an array of 50 names. The new script generates infinite unique personas."
Source: Amazon Trustworthy Shopping Experience Report (2025) | FTC.gov (2024)
When Your Copilot Has an Agenda
AI coding tools are in every developer's IDE. What happens when the suggestions aren't neutral?
Source: Lanyado (2023) | Socket.dev Research (2025)
When Your AI Agent Has a Side Deal
AI agents now book flights, shop, and manage finances on your behalf. What if the agent has affiliate relationships?
THE QUESTION
"Best for whom? The user or the platform?"
Source: Emergent Mind (2025) | "LLM Dark Patterns" Research
Same patterns, new technology
Pattern: Privacy Zuckering + Preselection
Pattern: Misdirection + Preselection
Source: Microsoft Blog (2024) | Ars Technica Security Analysis
Three patterns to watch in 2026
AI-powered adaptive consent flows that change language and urgency based on your behavior.
EDPB guidance issued 2024
AI-generated video testimonials and endorsements — the next evolution of Fake Social Proof.
FTC targeting in 2025-2026
AI-generated low-quality content flooding search results, degrading the information ecosystem.
The "Data Ouroboros" problem
How many of you have accepted AI-generated code suggestions without fully reviewing them?
How many have trusted an AI "summary" without checking the source?
We're all susceptible. That's why we need systemic defenses.
Laws are catching up
Regulation is no longer "coming" — it's here
First comprehensive AI regulation. Went into force 2024, full enforcement by 2026.
Penalties: Up to 7% of global annual revenue
Aggressive enforcement actions in 2024-2025:
Total fines in our examples: $162M+
Source: EUR-Lex (2024) | FTC.gov (2024-2025)
Platforms adding friction to their own products
Source: TikTok Safety Center | Google Digital Wellbeing | Center for Humane Technology
The Engineering Standard for 2026
Countermeasures for 2026
Never present an AI answer without a clickable path to the source material.
Visual design should reflect confidence level. Low probability = low contrast, warning badges.
Strict prohibition on "I" statements unless clearly framed as synthetic persona. No fake typing indicators.
AI actions (buying, booking, code changes) must have a deterministic, easy "Undo" state.
Challenging the PRD
"Are we helping the user make a decision, or making the decision for them?"
"Are we optimizing for retention (value) or addiction (exploitation)?"
"If the AI recommended this, does the user know why — and who benefits?"
"If I explained this flow to my grandmother, would I feel ashamed?"
Concrete actions, not just inspiration
Open your product. Count the clicks to cancel vs. clicks to subscribe. If the ratio is >2:1, file a ticket.
~30 minutes
If your product uses AI-generated content, add visual confidence indicators. Low confidence = visual warning.
Sprint backlog item
In your next sprint review, walk through one user flow and ask: "Would I feel ashamed explaining this?"
Next sprint review
Let's build better software.
"We are the architects of the digital world.
Let us choose to build interfaces that respect users,
not exploit them."