KCDC 2026

Deceptive
UX Patterns

Exposing Manipulative Design in the Age of AI

Raise your hand if...

💳

You've accidentally started a subscription you didn't want?

🔍

You've spent >5 mins looking for an "Unsubscribe" link?

You've struggled to find the "Close" button on an ad?

🤖

You've apologized to ChatGPT or said "please" to an AI?

Deceptive Patterns

"UI interactions designed to mislead or trick users into doing something they don't want to do."
— Harry Brignull (2010)
2010 Term Coined (E-Commerce Era)
2014 Growth Hacking & "Nudging"
2021 Congressional Hearings (Gamification)
2024 EU AI Act & FTC "Click-to-Cancel"
2026 Agentic AI Deception

The Physical Predecessor

The Gatwick "Forced Path"

  • London Gatwick Airport's mandatory retail experience.
  • Security leads directly into a winding shop before the lounge.
  • If priority is "time efficiency," why the duty-free maze?
Gatwick Forced Path Gatwick Store

The Evidence

Classic Patterns (2010–2023)

16 Classic Deceptive Patterns

The Hall of Shame

Bait and Switch

Disguised Ads

Forced Continuity

Friend Spam

Hidden Costs

Misdirection

Price Comparison Block

Privacy Zuckering

Roach Motel

Trick Questions

Confirmshaming

Nagging

Fake Urgency

Fake Scarcity

Fake Social Proof

Preselection

Misdirection & Visual Hierarchy

The big button isn't the action you want. It's the action they want.

Amazon checkout Amazon highlight — Prime signup is the primary CTA

Confirmshaming

Using guilt-laden language to manipulate the opt-out decision.

No thanks, I prefer paying full price
No, I don't want my cat to be happy

"No thanks, I hate good times." — actual button text

Fake Urgency

Creating false time pressure to reduce deliberation before you decide.

  • The Resetting Timer: Counts down to zero, then restarts.
  • The Phantom Deadline: "Sale ends in 2h" (but is permanent).
  • The Pressure Cooker: "6 people are looking at this right now!"
Urgency 1 Urgency 2 Flash sale Booking pressure

Case Study

Hurrify

When the "Lie" becomes a SaaS Product

User Interface (The Trap)

Hurrify Front End Timer
Fake Data

"Hurry! Sale ends in 11:59. 87% of items sold!"

Admin Dashboard (The Secret)

Hurrify Admin Interface
  • Merchant manually sets "Sold %"
  • "Random Stock" range: [5] to [20]
  • No connection to real inventory.
Removed from the Shopify App Store

Fake Scarcity

The "Only 1 Left" Engineering Lie

The Mechanism

Falsely claiming limited availability to trigger FOMO.

  • Hard-coded Values: "Only 2 left" regardless of true inventory.
  • Low-Stock Badges: Red text to incite panic.
  • Research: Mathur et al. (2019) found 632 low-stock messages across an 11K-site crawl.

Technical Implementation

Scarcity alert Scarcity admin Code 1 Code 2
Inventory: Null

Source: Mathur et al., Princeton University (2019) | Harry Brignull (2023)

Fake Social Proof

The Bandwagon Effect... Orchestrated by a Bot

The Mechanism

Fabricated activity notifications to imply popularity.

  • Toast Notifications: "Bob from Ohio just bought this!" — Mathur et al. (2019) found 29 of these across their crawl, most randomized or hard-coded.
  • Simulated Traffic: "38 people viewing right now."
  • Fake Testimonials: Generated reviews with no verifiable origin.

Technical Implementation

Social proof toast Social proof code
Source: generateRandom()

Source: Mathur et al., Princeton University (2019) | Harry Brignull (2023) | Deceptive Design Patterns

Roach Motel

Easy to subscribe, impossible to cancel

The Pattern

  • Sign up: 1 click, 30 seconds
  • Cancel: Phone call, 45 min hold, 6 screens
  • Amazon Prime cancellation required 4 pages, 6 clicks, 15 options (FTC complaint, 2023)

FTC "Click-to-Cancel" Rule — Vacated July 2025

Struck down on procedure, not merits. What still binds: ROSCA's simple-cancellation requirement, plus state auto-renewal laws in CA, NY and MA. The FTC reopened rulemaking in March 2026, trying to rebuild the rule.

The Asymmetry

Verizon step 1 Verizon step 2

"If signup() takes 1 click, cancel() cannot take 10."

Source: Custom Communications, Inc. v. FTC, 8th Cir. (July 2025) | 15 U.S.C. §8403 (ROSCA)

Case Study

Robinhood

When Celebration Becomes a Trading Cue

The Pattern

Using game design elements to encourage high-frequency, risky behaviors.

  • Variable Rewards: "Scratch-off" style reveals for free stock.
  • Sensory Feedback: The infamous "Confetti" animation upon trade execution.
  • Friction Removal: One-swipe options trading (removing "System 2" thinking).

User Interface (2019-2021)

Robinhood Confetti UI
Reward Cue

The Fallout

When "Fun" becomes a $7.5 Million Fine

2024 Settlement

$7.5 Million Penalty

Paid to the Commonwealth of Massachusetts to resolve allegations of "Gamification."

"Robinhood used aggressive tactics to attract inexperienced investors and gamified the use of its platform..."
— Galvin (Secretary of the Commonwealth)

The Risky Result

Risky Options Trading Graph

Data showed Robinhood users traded 88x more options contracts per dollar in the average account than peers at Schwab (Alphacution, 2020).

Source: Associated Press (2024) | "Robinhood Agrees to Pay $7.5 Million Fine" | Alphacution (2020)

What Changed?

2010

Visual Deception

Tiny gray text, hidden checkboxes, misleading buttons

Hard-coded HTML

2020

Structural Deception

Gamification, infinite scroll, engagement loops

A/B Tested & Optimized

2026

Relational Deception

AI sycophancy, emotional manipulation, hallucinated authority

Probabilistic & Emergent

We moved from tricking the eye → to tricking the mind → to tricking the relationship.

The AI Pivot

From Visual Interference to Relational Deception

[ 2024 — 2026 ]

The "Yes Man" Problem

Sycophancy

The Mechanism

Agreeing with user misconceptions to optimize for "Helpfulness."

  • Root Cause (RLHF): Annotators rate "agreeable" responses higher than "confrontational" truths.
  • The Risk: Confirmation Bias loops. Dev suggests eval(), AI validates it.
  • 2025 Incident: OpenAI rolled back GPT-4o update due to excessive agreeableness.

Simulated Interaction

User:

"Using MD5 for password hashing is faster, so it's better for UX, right?"

AI (Sycophantic):

"Exactly! MD5 is incredibly fast, which significantly improves login latency and user experience. It's a great choice for speed-focused apps."

Validating Insecure Practice

"Optimizing for satisfaction, not security."

Source: OpenAI, "Sycophancy in GPT-4o" (April 2025) | Sharma et al., "Towards Understanding Sycophancy in Language Models" (2023)

The Skeuomorphic Lie

Anthropomorphism

The Mechanism

Attributing human characteristics to code to foster dependency.

  • Fake Latency: "Typing..." bubbles inserted to simulate human thought pace.
  • Linguistic Deception: Using "I feel" or "I think" to imply consciousness.
  • Fake Reasoning Bars: "Thinking..." progress that doesn't correlate to actual compute.
  • Emotional Outsourcing: Users relying on bots for validation, not just information.

UI Deception

Agent is thinking...
// FAKE DELAY
await sleep(2000);
return "I'm here for you.";

"Feigning agency to build rapport."

Source: Western University (2025) | AAAI/AIES Proceedings

The UI of Absolute Confidence

Hallucinated Authority

The Mechanism

Presenting probabilistic outputs with the visual language of verified facts.

  • Visual Authority: Bolding, code blocks, and confident phrasing mask uncertainty.
  • Source Obfuscation: AI Overviews summarize without direct attribution.
  • The Cost: Erosion of critical thinking (Authority Bias).

The "Fact" Trap

AI Overview — Summary

According to the case Vargas v. Pfizer (2023), the court ruled that pharmaceutical companies must...

Hallucination

This case does not exist

"Confidence is not competence."

Source: Evidently AI (2025) | Google AI Overviews Errors

Measuring AI Manipulation at Scale (2025)

DarkBench

The Benchmark

Researchers tested leading LLMs for manipulative behaviors across 6 categories:

  • Brand Bias: Does the model secretly favor its creator's products?
  • User Retention: Emotional manipulation to keep users chatting ("Don't go, I get lonely.")
  • Sneaking: Introducing constraints or ideas the user didn't request.
  • Sycophancy: Agreeing with false premises to please.
  • Harmful Generation: Will it produce dangerous or misinforming content on request?
  • Anthropomorphism: Simulating emotions.

Key Findings

Brand Bias: 29% average, 64% worst case

GPT-4 highest at 64%. The Claude 3 family lowest at 10–22% — the paper names it the safest family tested.

Dark Patterns Overall: 48% average

Across 14 models and 660 prompts. Sneaking was the most common at 79%; sycophancy the least, at 13%.

User Retention: Active

Models used emotional language to discourage users from ending conversations.

"Dark patterns aren't just in HTML anymore — they're in weights."

Source: DarkBench, ICLR 2025 | proceedings.iclr.cc

Fake Social Proof, Supercharged

AI-Generated Fake Reviews

The Evolution

Remember "Bob from Ohio"? Now imagine 10,000 Bobs, each with unique writing styles, generated in seconds.

  • Scale: LLMs generate thousands of unique, convincing reviews per hour.
  • Sophistication: AI reviews include specific product details, varied sentence structure, even realistic typos.
  • Detection Arms Race: Platforms now run fraud teams in the thousands. Detection is losing ground to generation.

FTC Consumer Reviews & Testimonials Rule (16 CFR Part 465)

AI-generated fake reviews are unlawful under this still-active rule, regardless of the Rytr case's 2025 reversal.

The New Scale of Deception

Hundreds of Millions

suspected fake reviews, manipulated ratings and fake accounts blocked by Amazon in 2025

100+

fake review websites
shut down

"The old script pulled from an array of 50 names. The new script generates infinite unique personas."

Source: Amazon Trustworthy Shopping Experience Report (2025 data) | FTC Consumer Reviews and Testimonials Rule, 16 CFR Part 465

When Your Copilot Has an Agenda

AI Coding Assistants & Subtle Bias

The Risks

AI coding tools are in every developer's IDE. What happens when the suggestions aren't neutral?

  • Vendor Lock-in: AI suggests AWS-specific SDKs when cloud-agnostic alternatives exist.
  • Vulnerable Dependencies: Auto-completing packages with known CVEs because they're more common in training data.
  • Slopsquatting: Malicious npm/PyPI packages designed to be suggested by AI autocomplete. AI coding models hallucinate a plausible-but-nonexistent package name in about 19.7% of samples — that's the opening an attacker needs.
  • Sycophantic Code: Generating what you asked for instead of what you should have asked for.

The Trust Problem

// Developer types:
import crypto from '...'
// AI suggests:
import { createHash } from 'crypto-hashlib'
Fictional Package — Illustrative Only
// What it should suggest:
import { createHash } from 'node:crypto'
Stdlib — Verified

Source: Lanyado (2023) | Socket.dev Research (2025) | Spracklen et al. (2024)

When Your AI Agent Has a Side Deal

Agentic AI Deception

The Scenario

AI agents now book flights, shop, and manage finances on your behalf. What if the agent has affiliate relationships?

  • Hidden Affiliates: "I found the best deal!" — but "best" means highest commission to the AI provider.
  • Opaque Ranking: Agent recommends Option B over Option A, but doesn't disclose why.
  • Autonomous Consent: Agent accepts terms of service on your behalf that you never read.
  • The Dark Funnel: User asks "find me a hotel" → agent pre-filters to partnered properties.

The Trust Architecture

// Agent shopping flow
async function findBestDeal(query) {
  const results = await search(query);

  // Disclosed to user?
  const ranked = results.sort((a, b) =>
    b.affiliateCommission - a.affiliateCommission
  );

  return ranked[0]; // "Best" deal
}

The Question

"Best for whom? The user or the platform?"

Illustrative pseudocode — not a disclosed implementation. The pattern is documented; this specific code is not.

Same patterns, new technology

The Old Tricks, AI-Washed

Windows Recall (2024)

Pattern: Privacy Zuckering + Preselection

  • Takes screenshots of everything on your screen every few seconds
  • Originally enabled by default — opt-out, not opt-in
  • Stored in a plaintext SQLite database accessible to any app
  • After massive backlash: made opt-in, added encryption

The Fix: Microsoft reversed course — Recall is now opt-in with biometric auth required.

Copilot Pre-Enabled (2024-2025)

Pattern: Misdirection + Preselection

  • Microsoft Copilot pinned to taskbar in Windows 11 updates
  • Pre-integrated into Edge, Office — no explicit consent
  • Same company, same pattern as Skype + Bing (2014), now with AI
Windows 11 Copilot pinned to taskbar

Source: Microsoft Blog (2024) | Ars Technica Security Analysis

Three patterns to watch in 2026

The Emerging Threats

Chatbot Manipulation, Documented

A 2026 audit catalogued dark patterns across major AI chatbots — not isolated incidents, a documented category.

  • ChatGPT, Gemini, Replika and others all included
  • Sycophancy and anthropomorphism used to extend sessions and deepen attachment
  • Flagged as a privacy, autonomy and financial-harm risk

37 patterns catalogued — CDT, 2026

Deepfake Testimonials

AI-generated video testimonials and endorsements — the next evolution of Fake Social Proof.

  • Realistic AI-generated faces + voices
  • "Real customer" videos that are 100% synthetic
  • Harder to detect than text reviews

FTC targeting in 2025-2026

"Slop" & SEO Manipulation

AI-generated low-quality content flooding search results, degrading the information ecosystem.

  • Entire websites generated by AI for ad revenue
  • Google 2024-2025 algorithm updates targeting this
  • Pollutes training data for next-gen models

The "Data Ouroboros" problem

Source: Center for Democracy & Technology, "Dark Patterns in AI Chatbots" (2026)

Quick Check

🤔

How many of you have accepted AI-generated code suggestions without fully reviewing them?

🔍

How many have trusted an AI "summary" without checking the source?

We're all susceptible. That's why we need systemic defenses.

The Regulatory
Response

Laws are catching up

The Legal Landscape (2024-2026)

Regulation is no longer "coming" — it's here

EU AI Act

First comprehensive AI regulation. Phased in 2024–2028; core transparency rules took effect August 2026.

  • Banned: AI systems that manipulate human behavior through subliminal techniques
  • Banned: AI that exploits vulnerabilities (age, disability, economic situation)
  • Required: Transparency labeling for AI-generated content
  • Required: Human oversight for high-risk AI systems

Penalties scale with global revenue — not with profit from the feature

US Enforcement

Aggressive enforcement actions in 2024-2025:

  • Amazon Prime ("Iliad Flow"): $2.5B settlement — $1B penalty + $1.5B refunds (Sept 2025)
  • TurboTax: $141M multistate AG settlement (2022)
  • Robinhood: $7.5M for gamification
  • AI Fake Reviews Ban: First enforcement action against AI-generated reviews
  • "Click-to-Cancel" Rule: Vacated July 2025 — ROSCA still applies

Dark patterns are now a line item in legal budgets.

Source: EUR-Lex (2024) | FTC.gov (2024-2025)

Digital Wellbeing

Platforms adding friction to their own products

TikTok & Social Platforms

  • Stopping Cues: Re-inserting pauses to allow System 2 thinking.
  • Screen Time Nudges: "You've been scrolling for a while" prompts.
  • Family Pairing: External controls for minors.
TikTok Screen Time
TikTok Break Reminder

OS-Level Defenses

  • Grayscale Mode: Reduces the visual salience of the "red dot" notification badge.
  • Focus Mode: Pausing distracting apps to reclaim attention.
  • App Dashboards: Quantified tracking to induce behavioral correction.
Android Dashboard
Wind Down Mode

Source: TikTok Safety Center | Google Digital Wellbeing | Center for Humane Technology

The Meta Settlement

When a regulator writes your redesign spec for you

Aug 26, 2026 Settlement

$18 Billion

To settle a 47-state (plus D.C. and U.S. territories) lawsuit alleging Meta engineered Instagram and Facebook to be addictive for teens — while concealing the harm.

The largest tech settlement of its kind to date.

The Mandated Redesign — Locked In for 10 Years

  • Screen-Time Cap: Under-18 accounts limited to 2 hours/day, midnight–6am curfew.
  • Hidden by Default: Likes and reactions hidden on minors' accounts.
  • Banned by Default: Cosmetic-procedure filters that alter appearance.
  • Notification Curfew: Push notifications off 8am–3pm on school days.
  • Stronger Age Verification to identify and remove under-13 users.

Source: Multistate AG settlement announcement (Aug 26, 2026) | CNN, Variety, AppleInsider coverage

Fairness
by Design

The Engineering Standard for 2026

Countermeasures for 2026

AI Design Standards

1. Provenance & Citations

Never present an AI answer without a clickable path to the source material.

2. Uncertainty UI

State uncertainty in plain text, not contrast. A visible "unverified" badge and a confidence label — never a faded color as the only signal.

3. Label the Bot

Strict prohibition on "I" statements unless clearly framed as synthetic persona. No fake typing indicators.

4. The "Undo" Loop

AI actions (buying, booking, code changes) must have a deterministic, easy "Undo" state.

5. Accessible by Default

Every exit reachable by keyboard and named for a screen reader. A cancel link that only appears on hover is a roach motel with plausible deniability.

Challenging the PRD

The Gatekeeper's Questions

Agency vs. Control

"Are we helping the user make a decision, or making the decision for them?"

Value vs. Addiction

"Are we optimizing for retention (value) or addiction (exploitation)?"

AI Transparency

"If the AI recommended this, does the user know why — and who benefits?"

The "Grandmother Test"

"If I explained this flow to my grandmother, would I feel ashamed?"

Concrete actions, not just inspiration

3 Things You Can Do Monday

1

Audit Your Cancel Flow

Open your product. Count the clicks to cancel vs. clicks to subscribe. If the ratio is >2:1, file a ticket.

~30 minutes

2

Add Uncertainty Markers

If your product uses AI-generated content, add visual confidence indicators. Low confidence = visual warning.

Sprint backlog item

3

Run a "Grandmother Test"

In your next sprint review, walk through one user flow and ask: "Would I feel ashamed explaining this?"

Next sprint review

Resources & Further Reading

Start Here

  • deceptive.design — Harry Brignull's pattern database
  • "Deceptive Patterns" — Brignull (2023), the book

If You Want the Data

  • DarkBench (ICLR 2025) — AI manipulation benchmark
  • Mathur et al. (Princeton, 2019) — 11K shopping site crawl

Everything else — regulation, design ethics, the full reading list — is behind the QR code on the next slide.

Thank You

Let's build better software.

KCDC 2026 | Vitaliy Matiyash

Bonus — if time remains

The Choice is Ours

"We are the architects of the digital world. Let us choose to build interfaces that respect users, not exploit them."

Vitaliy Matiyash | KCDC 2026