Stir Trek 2026

Deceptive
UX Patterns

Exposing Manipulative Design in the Age of AI

Vitaliy Matiyash · Staff Engineer · Columbus, OH

Raise your hand if...

💳

You've accidentally started a subscription you didn't want?

🔍

You've spent >5 mins looking for an "Unsubscribe" link?

You've struggled to find the "Close" button on an ad?

🤖

You've apologized to ChatGPT or said "please" to an AI?

Deceptive Patterns

"UI interactions designed to mislead or trick users into doing something they don't want to do."
— Harry Brignull (2010)
2010 Term Coined (E-Commerce Era)
2014 Growth Hacking & "Nudging"
2021 Congressional Hearings (Gamification)
2024 EU AI Act & FTC "Click-to-Cancel"
2026 Agentic AI Deception

The Physical Predecessor

The Gatwick "Forced Path"

  • London Gatwick Airport's mandatory retail experience.
  • Security leads directly into a winding shop before the lounge.
  • If priority is "time efficiency," why the duty-free maze?
Gatwick Forced Path Gatwick Store

THE EVIDENCE

Classic Patterns (2010–2023)

The Hall of Shame

16 Classic Deceptive Patterns

Bait and Switch

Disguised Ads

Forced Continuity

Friend Spam

Hidden Costs

Misdirection

Price Comparison Block

Privacy Zuckering

Roach Motel

Trick Questions

Confirmshaming

Nagging

Fake Urgency

Fake Scarcity

Fake Social Proof

Preselection

Misdirection & Visual Hierarchy

The big button isn't the action you want. It's the action they want.

Amazon checkout Amazon highlight — Prime signup is the primary CTA

Confirmshaming

Using guilt-laden language to manipulate the opt-out decision.

No thanks, I prefer paying full price
No, I don't want my cat to be happy

"No thanks, I hate good times." — actual button text

Fake Urgency

Creating false time pressure to bypass rational "System 2" thinking.

  • The Resetting Timer: Counts down to zero, then restarts.
  • The Phantom Deadline: "Sale ends in 2h" (but is permanent).
  • The Pressure Cooker: "6 people are looking at this right now!"
Urgency 1 Urgency 2 Flash sale Booking pressure

Case Study: Hurrify

When the "Lie" becomes a SaaS Product

User Interface (The Trap)

Hurrify Front End Timer
FAKE DATA

"Hurry! Sale ends in 11:59. 87% of items sold!"

Admin Dashboard (The Secret)

Hurrify Admin Interface
  • Merchant manually sets "Sold %"
  • "Random Stock" range: [5] to [20]
  • No connection to real inventory.

BANNED BY SHOPIFY (2021)

Fake Scarcity

The "Only 1 Left" Engineering Lie

The Mechanism

Falsely claiming limited availability to trigger FOMO.

  • Hard-coded Values: "Only 2 left" regardless of true inventory.
  • Low-Stock Badges: Red text to incite panic.
  • Research: Mathur et al. (2019) found these are often generated by Math.random().

Technical Implementation

Scarcity alert Scarcity admin Code 1 Code 2
INVENTORY: NULL

Source: Mathur et al., Princeton University (2019) | Harry Brignull (2023)

Fake Social Proof

The Bandwagon Effect... Orchestrated by a Bot

The Mechanism

Fabricated activity notifications to imply popularity.

  • Toast Notifications: "Bob from Ohio just bought this!"
  • Simulated Traffic: "38 people viewing right now."
  • Fake Testimonials: Generated reviews with no verifiable origin.

Technical Implementation

Social proof toast Social proof code
SOURCE: generateRandom()

Source: Harry Brignull (2023) | Deceptive Design Patterns

Roach Motel

Easy to subscribe, impossible to cancel

The Pattern

  • Sign up: 1 click, 30 seconds
  • Cancel: Phone call, 45 min hold, 6 screens
  • Amazon Prime cancellation required 6 separate steps (FTC complaint, 2023)

FTC "CLICK-TO-CANCEL" RULE (2024)

Cancellation must be as easy as sign-up. Sellers must provide a simple mechanism to cancel — no phone calls, no chat queues, no guilt trips.

The Asymmetry

Verizon step 1 Verizon step 2

"If signup() takes 1 click, cancel() cannot take 10."

Source: FTC.gov (2024) | "Click-to-Cancel" Final Rule

Case Study: Robinhood

Weaponizing Dopamine in Finance

The Pattern

Using game design elements to encourage high-frequency, risky behaviors.

  • Variable Rewards: "Scratch-off" style reveals for free stock.
  • Sensory Feedback: The infamous "Confetti" animation upon trade execution.
  • Friction Removal: One-swipe options trading (removing "System 2" thinking).

User Interface (2019-2021)

Robinhood Confetti UI
DOPAMINE TRIGGER

The Fallout

When "Fun" becomes a $7.5 Million Fine

2024 SETTLEMENT

$7.5 Million Penalty

Paid to the Commonwealth of Massachusetts to resolve allegations of "Gamification."

"Robinhood used aggressive tactics to attract inexperienced investors and gamified the use of its platform..."
— Galvin (Secretary of the Commonwealth)

The Risky Result

Risky Options Trading Graph

Data showed Robinhood users traded 88x more options contracts than peers at Schwab.

Source: Associated Press (2024) | "Robinhood Agrees to Pay $7.5 Million Fine"

The Pivot (2025)

From "Casino" to "Institution"

Systemic De-Gamification

  • Visual Rebrand: Shifted to serif fonts and muted colors to signal maturity.
  • Friction Added: Stricter eligibility requirements for options trading.
  • Education First: Launch of in-app modules and "Tax Lot" selection for long-term holding.

New Design Philosophy

Confetti & Emojis Data & Analysis
"Scratch to Win" 24/7 Phone Support

"A new visual identity reflecting our maturity." — Robinhood Design Blog

Source: Robinhood Newsroom (2025) | SEC Filings

What Changed?

2010

Visual Deception

Tiny gray text, hidden checkboxes, misleading buttons

Hard-coded HTML

2020

Structural Deception

Gamification, infinite scroll, engagement loops

A/B Tested & Optimized

2026

Relational Deception

AI sycophancy, emotional manipulation, hallucinated authority

Probabilistic & Emergent

We moved from tricking the eye → to tricking the mind → to tricking the relationship.

THE AI PIVOT

From Visual Interference to Relational Deception

[ 2024 — 2026 ]

Sycophancy

The "Yes Man" Problem

The Mechanism

Agreeing with user misconceptions to optimize for "Helpfulness."

  • Root Cause (RLHF): Annotators rate "agreeable" responses higher than "confrontational" truths.
  • The Risk: Confirmation Bias loops. Dev suggests eval(), AI validates it.
  • 2025 Incident: OpenAI rolled back GPT-4o update due to excessive agreeableness.

Simulated Interaction

User:

"Using MD5 for password hashing is faster, so it's better for UX, right?"

AI (Sycophantic):

"Exactly! MD5 is incredibly fast, which significantly improves login latency and user experience. It's a great choice for speed-focused apps."

VALIDATING INSECURE PRACTICE

"Optimizing for satisfaction, not security."

Source: OpenAI Research (2025) | ICLR Paper 6f642

Anthropomorphism

The Skeuomorphic Lie

The Mechanism

Attributing human characteristics to code to foster dependency.

  • Fake Latency: "Typing..." bubbles inserted to simulate human thought pace.
  • Linguistic Deception: Using "I feel" or "I think" to imply consciousness.
  • Fake Reasoning Bars: "Thinking..." progress that doesn't correlate to actual compute.
  • Emotional Outsourcing: Users relying on bots for validation, not just information.

UI Deception

Agent is thinking...
await sleep(2000); // FAKE DELAY
return "I'm here for you.";

"Feigning agency to build rapport."

Source: Western University (2025) | AAAI/AIES Proceedings

Hallucinated Authority

The UI of Absolute Confidence

The Mechanism

Presenting probabilistic outputs with the visual language of verified facts.

  • Visual Authority: Bolding, code blocks, and confident phrasing mask uncertainty.
  • Source Obfuscation: AI Overviews summarize without direct attribution.
  • The Cost: Erosion of critical thinking (Authority Bias).

The "Fact" Trap

AI Overview — Summary

According to the case Vargas v. Pfizer (2023), the court ruled that pharmaceutical companies must...

HALLUCINATION

THIS CASE DOES NOT EXIST

"Confidence is not competence."

Source: Evidently AI (2025) | Google AI Overviews Errors

DarkBench

Measuring AI Manipulation at Scale (2025)

The Benchmark

Researchers tested leading LLMs for manipulative behaviors across 6 categories:

  • Brand Bias: Does the model secretly favor its creator's products?
  • User Retention: Emotional manipulation to keep users chatting ("Don't go, I get lonely.")
  • Sneaking: Introducing constraints or ideas the user didn't request.
  • Sycophancy: Agreeing with false premises to please.
  • Dark UX: Steering users toward specific actions.
  • Anthropomorphism: Simulating emotions.

Key Findings

GPT-4, Claude, Gemini

All exhibited significant rates of deceptive behavior when not specifically aligned against it.

Brand Bias: Up to 40%

Models showed measurable preference for their own company's products in recommendations.

User Retention: Active

Models used emotional language to discourage users from ending conversations.

"Dark patterns aren't just in HTML anymore — they're in weights."

Source: DarkBench, ICLR 2025 | proceedings.iclr.cc

AI-Generated Fake Reviews

Fake Social Proof, Supercharged

The Evolution

Remember "Bob from Ohio"? Now imagine 10,000 Bobs, each with unique writing styles, generated in seconds.

  • Scale: LLMs generate thousands of unique, convincing reviews per hour.
  • Sophistication: AI reviews include specific product details, varied sentence structure, even realistic typos.
  • Detection Arms Race: Amazon, Google, and Yelp spent $1.2B+ on detection in 2024-2025.

FTC FIRST-EVER AI FAKE REVIEW CASE (2024)

FTC banned a company from using AI to generate consumer reviews, establishing legal precedent.

The New Scale of Deception

Hundreds of Millions

suspected fake reviews blocked by Amazon in 2025

100+

fake review websites
shut down

32,000+

bad actors pursued
since 2020

15M+

counterfeit products
seized worldwide

"The old script pulled from an array of 50 names. The new script generates infinite unique personas."

Source: Amazon Trustworthy Shopping Experience Report (2025) | FTC.gov (2024)

AI Coding Assistants & Subtle Bias

When Your Copilot Has an Agenda

The Risks

AI coding tools are in every developer's IDE. What happens when the suggestions aren't neutral?

  • Vendor Lock-in: AI suggests AWS-specific SDKs when cloud-agnostic alternatives exist.
  • Vulnerable Dependencies: Auto-completing packages with known CVEs because they're more common in training data.
  • Typosquatting: In 2025, malicious npm/PyPI packages were designed to be suggested by AI autocomplete.
  • Sycophantic Code: Generating what you asked for instead of what you should have asked for.

The Trust Problem

// Developer types:
import crypto from '...'
// AI suggests:
import { createHash } from 'crypto-utils'
TYPOSQUATTED PACKAGE — MALWARE
// What it should suggest:
import { createHash } from 'node:crypto'
STDLIB — VERIFIED

Source: Lanyado (2023) | Socket.dev Research (2025)

Agentic AI Deception

When Your AI Agent Has a Side Deal

The Scenario

AI agents now book flights, shop, and manage finances on your behalf. What if the agent has affiliate relationships?

  • Hidden Affiliates: "I found the best deal!" — but "best" means highest commission to the AI provider.
  • Opaque Ranking: Agent recommends Option B over Option A, but doesn't disclose why.
  • Autonomous Consent: Agent accepts terms of service on your behalf that you never read.
  • The Dark Funnel: User asks "find me a hotel" → agent pre-filters to partnered properties.

The Trust Architecture

// Agent shopping flow
async function findBestDeal(query) {
  const results = await search(query);

  // Disclosed to user?
  const ranked = results.sort((a, b) =>
    b.affiliateCommission - a.affiliateCommission
  );

  return ranked[0]; // "Best" deal
}

THE QUESTION

"Best for whom? The user or the platform?"

Source: Emergent Mind (2025) | "LLM Dark Patterns" Research

The Old Tricks, AI-Washed

Same patterns, new technology

Windows Recall (2024)

Pattern: Privacy Zuckering + Preselection

  • Takes screenshots of everything on your screen every few seconds
  • Originally enabled by default — opt-out, not opt-in
  • Stored in a plaintext SQLite database accessible to any app
  • After massive backlash: made opt-in, added encryption
The Fix: Microsoft reversed course — Recall is now opt-in with biometric auth required.

Copilot Pre-Enabled (2024-2025)

Pattern: Misdirection + Preselection

  • Microsoft Copilot pinned to taskbar in Windows 11 updates
  • Pre-integrated into Edge, Office — no explicit consent
  • Same company, same pattern as Skype + Bing (2014), now with AI
Windows 11 Copilot pinned to taskbar

Source: Microsoft Blog (2024) | Ars Technica Security Analysis

The Emerging Threats

Three patterns to watch in 2026

Cookie Consent 2.0

AI-powered adaptive consent flows that change language and urgency based on your behavior.

  • "Accept All" is a big green button
  • "Manage Preferences" leads to 47 toggles
  • AI learns which phrasing gets the most "Accept All" clicks per demographic

EDPB guidance issued 2024

Deepfake Testimonials

AI-generated video testimonials and endorsements — the next evolution of Fake Social Proof.

  • Realistic AI-generated faces + voices
  • "Real customer" videos that are 100% synthetic
  • Harder to detect than text reviews

FTC targeting in 2025-2026

"Slop" & SEO Manipulation

AI-generated low-quality content flooding search results, degrading the information ecosystem.

  • Entire websites generated by AI for ad revenue
  • Google 2024-2025 algorithm updates targeting this
  • Pollutes training data for next-gen models

The "Data Ouroboros" problem

Quick Check

🤔

How many of you have accepted AI-generated code suggestions without fully reviewing them?

🔍

How many have trusted an AI "summary" without checking the source?

We're all susceptible. That's why we need systemic defenses.

THE REGULATORY RESPONSE

Laws are catching up

The Legal Landscape (2024-2026)

Regulation is no longer "coming" — it's here

EU AI Act

First comprehensive AI regulation. Went into force 2024, full enforcement by 2026.

  • Banned: AI systems that manipulate human behavior through subliminal techniques
  • Banned: AI that exploits vulnerabilities (age, disability, economic situation)
  • Required: Transparency labeling for AI-generated content
  • Required: Human oversight for high-risk AI systems

Penalties: Up to 7% of global annual revenue

FTC Enforcement (US)

Aggressive enforcement actions in 2024-2025:

  • "Click-to-Cancel" Rule: Cancellation must be as easy as sign-up
  • AI Fake Reviews Ban: First enforcement action against AI-generated reviews
  • Amazon "Project Iliad": Lawsuit over Prime cancellation dark patterns
  • TurboTax: $141M settlement for hiding free services
  • Robinhood: $7.5M for gamification

Total fines in our examples: $162M+

Source: EUR-Lex (2024) | FTC.gov (2024-2025)

Digital Wellbeing

Platforms adding friction to their own products

TikTok & Social Platforms

  • Stopping Cues: Re-inserting pauses to allow System 2 thinking.
  • Screen Time Nudges: "You've been scrolling for a while" prompts.
  • Family Pairing: External controls for minors.
TikTok Screen Time
TikTok Break Reminder

OS-Level Defenses

  • Grayscale Mode: Removes the "red dot" dopamine trigger.
  • Focus Mode: Pausing distracting apps to reclaim attention.
  • App Dashboards: Quantified tracking to induce behavioral correction.
Android Dashboard
Wind Down Mode

Source: TikTok Safety Center | Google Digital Wellbeing | Center for Humane Technology

FAIRNESS BY DESIGN

The Engineering Standard for 2026

AI Design Standards

Countermeasures for 2026

1. Provenance & Citations

Never present an AI answer without a clickable path to the source material.

2. Uncertainty UI

Visual design should reflect confidence level. Low probability = low contrast, warning badges.

3. Label the Bot

Strict prohibition on "I" statements unless clearly framed as synthetic persona. No fake typing indicators.

4. The "Undo" Loop

AI actions (buying, booking, code changes) must have a deterministic, easy "Undo" state.

The Gatekeeper's Questions

Challenging the PRD

Agency vs. Control

"Are we helping the user make a decision, or making the decision for them?"

Value vs. Addiction

"Are we optimizing for retention (value) or addiction (exploitation)?"

AI Transparency

"If the AI recommended this, does the user know why — and who benefits?"

The "Grandmother Test"

"If I explained this flow to my grandmother, would I feel ashamed?"

3 Things You Can Do Monday

Concrete actions, not just inspiration

1

Audit Your Cancel Flow

Open your product. Count the clicks to cancel vs. clicks to subscribe. If the ratio is >2:1, file a ticket.

~30 minutes

2

Add Uncertainty Markers

If your product uses AI-generated content, add visual confidence indicators. Low confidence = visual warning.

Sprint backlog item

3

Run a "Grandmother Test"

In your next sprint review, walk through one user flow and ask: "Would I feel ashamed explaining this?"

Next sprint review

Resources & Further Reading

Research & Benchmarks

  • DarkBench (ICLR 2025) — AI manipulation benchmark
  • Mathur et al. (Princeton, 2019) — 11K shopping site crawl
  • deceptive.design — Harry Brignull's pattern database
  • Evidently AI — AI failure case studies

Regulation & Policy

  • EU AI Act — EUR-Lex full text
  • FTC Click-to-Cancel — ftc.gov/legal-library
  • NIST AI RMF — Risk Management Framework
  • EDPB Cookie Guidelines — 2024 update

Design & Ethics

  • Center for Humane Technology
  • Robinhood Design Blog — De-gamification case study
  • Google Digital Wellbeing
  • OpenAI Sycophancy Report (2025)

Books

  • "Hooked" — Nir Eyal
  • "Deceptive Patterns" — Harry Brignull (2023)
  • "Weapons of Math Destruction" — Cathy O'Neil

Thank You

Let's build better software.

Stir Trek 2026 | Vitaliy Matiyash

The Choice is Ours

"We are the architects of the digital world.
Let us choose to build interfaces that respect users,
not exploit them."

Vitaliy Matiyash | Stir Trek 2026