Dark patterns compliance: How to audit your UX for regulatory risk

Dark patterns compliance: How to audit your UX for regulatory risk

Regulators are no longer just looking at what your marketing says. They are looking at how your digital experiences behave.

Regulators are no longer just looking at what your marketing says. They are looking at how your digital experiences behave.

Dark patterns are deceptive design techniques that manipulate users into unintended actions - including subscription traps, hidden fees, misleading consent flows, and manipulative cancellation processes. Once a niche UX concern, dark patterns are now a global regulatory priority, subject to enforcement actions, legislative reform, and significant financial penalties across every major jurisdiction.

For marketing teams, this creates a compliance challenge with impact across design, copy, and legal teams. The landing page your team built to maximize conversions might contain dark patterns that expose your organization to regulatory risk. The checkout flow your product team optimized for revenue might trigger an enforcement review.

The difficulty is that dark patterns are often unintentional. They emerge from aggressive conversion optimization, not deliberate deception. But regulators do not distinguish between intent and outcome. If the experience misleads the consumer, the organization is liable.

What makes dark patterns compliance different

The definition problem

There is no single, universally agreed definition of what constitutes a dark pattern. The FTC uses the term "dark patterns" broadly to cover any design practice that tricks or manipulates users. The EU's Digital Services Act references "dark patterns" explicitly but defines categories differently. Australia's ACCC addresses the same behaviours under misleading and deceptive conduct provisions without using the term at all.

This means compliance teams cannot simply reference a checklist. What constitutes a dark pattern depends on jurisdiction, industry, and the specific consumer interaction.

The cross-team problem

Dark patterns compliance does not sit neatly within one team. Marketing owns the copy. Product owns the UX. Engineering owns the implementation. Legal owns the risk assessment. When a regulator identifies a dark pattern in your checkout flow, determining who is responsible - and who should have caught it - is often the first internal challenge.

The continuous drift problem

Digital experiences change constantly. A landing page that was compliant at launch can drift into non-compliance through A/B testing, copy updates, pricing changes, or AI-led optimization changes. Without continuous monitoring, compliant experiences can become non-compliant without anyone noticing.

The scale problem

A large organization might have hundreds of active landing pages, email sequences, app screens, and checkout flows across multiple markets. Auditing every customer-facing touchpoint manually is impractical. But selective auditing means non-compliant experiences can persist undetected in the long tail of your digital estate.

The regulatory landscape

Regulatory action against dark patterns has accelerated sharply. Enforcement is active and increasingly coordinated across jurisdictions.

Regulation / Framework

Region

Regulator

How It Applies to Dark Patterns in Marketing

FTC Act (Section 5) + FTC Dark Patterns Report

US

FTC

The FTC has brought multiple enforcement actions specifically targeting dark patterns - subscription traps, misleading cancellation flows, and deceptive consent mechanisms. 

Digital Services Act (DSA)

EU

European Commission / National DSAs

Article 25 explicitly prohibits dark patterns on online platforms. Covers manipulative design, deceptive framing, and obstructed choice. Applies to any platform with EU users. 

Australian Consumer Law

Australia

ACCC

Misleading or deceptive conduct provisions apply to digital design. The ACCC's Digital Platform Services Inquiry has specifically identified dark patterns as a priority. Drip pricing and subscription traps are active enforcement targets. 

Consumer Protection from Unfair Trading Regulations / Online Safety Act

UK

CMA / Ofcom

The CMA has taken enforcement action against subscription traps and drip pricing. Ofcom's codes of practice under the Online Safety Act address manipulative design in user-facing services.

CCPA / State Privacy Laws

US (State)

California AG / State AGs

The CCPA's implementing regulations explicitly define and prohibit dark patterns in consent interfaces. Several other state privacy laws have adopted similar provisions. 

Read about regulatory pressure points to watch out for this year in the US, UK and Australia.

What Is changing in 2026

Enforcement is shifting from guidance to penalties

Regulators have published guidance, issued warnings, and signalled priorities. In 2026, the focus is shifting to enforcement and financial penalties. In September 2025, the FTC secured a $2.5 billion settlement with Amazon - a $1 billion civil penalty plus $1.5 billion in consumer refunds - over allegations that its Prime enrollment and cancellation flows used dark patterns to mislead consumers. It was the largest settlement the agency has obtained in a dark patterns case. In the EU, the DSA's enforcement infrastructure is now operational, with the first fines against major platforms handed down in late 2025. Organizations that have not audited their digital experiences are running out of time to self-correct before regulators do it for them.

Subscription and cancellation flows are the primary target

Across jurisdictions, subscription traps and obstructed cancellation flows are the most actively enforced category of dark patterns. In the US, the FTC's "click-to-cancel" rule was vacated by a federal appeals court in July 2025 on procedural grounds - but the principle behind it did not disappear. The FTC has continued to enforce the same standard under the Restore Online Shoppers' Confidence Act (ROSCA) and Section 5 of the FTC Act, roughly 30 US states now have their own automatic-renewal laws, and in March 2026 the FTC opened a new rulemaking to revive the rule. Alongside the UK's enforcement of subscription and drip-pricing practices and the ACCC's active investigations in Australia, all of these converge on the same expectation: it should be as easy to cancel as it is to subscribe.

Design-level compliance is becoming expected

Regulators are increasingly looking beyond copy and claims to the design itself. How a consent banner is structured, where a cancellation button is placed, how pricing is visually presented - these are now compliance considerations, not just UX decisions. This means compliance teams need to review wireframes and user flows, not just marketing copy.

Cross-border coordination is increasing

Regulatory bodies are sharing intelligence on dark patterns enforcement. An enforcement action in one jurisdiction often triggers scrutiny in others. organizations operating across markets cannot assume that a practice tolerated in one jurisdiction will be accepted in another.

Where dark patterns compliance breaks down

Scenario 1: The optimised checkout

A marketing compliance retail team runs A/B tests on their checkout flow to reduce cart abandonment. The winning variation pre-selects a premium shipping option, uses a muted colour for the standard shipping alternative, and adds a time-pressure banner ("Only 2 left at this price"). Conversion rates improve by 15%. Six months later, the ACCC opens an investigation into drip pricing and manipulative design in online retail.

The marketing team did not intend to create dark patterns. They were optimising for conversion. But the design choices - pre-selection, visual de-emphasis of alternatives, artificial urgency - are exactly what regulators are targeting.

Scenario 2: The consent flow

A telecommunications company redesigns its cookie consent banner to maximise opt-in rates. The "Accept All" button is large and prominently coloured. The "Manage Preferences" option is small, greyed out, and requires three additional clicks to reach meaningful choices. The design is compliant with the letter of the regulation - all options are technically available. But the implementation makes one choice significantly easier than the other.

A data protection regulator reviews the consent flow and determines it fails to obtain valid, freely given consent - a manipulative design that regulators increasingly treat as a dark pattern. Under the GDPR, the resulting fine can reach 4% of the company's global annual turnover, not a figure tied to the consent flow alone. And for businesses that qualify as online platforms, the same asymmetric design would also breach the DSA's Article 25 prohibition on manipulative interfaces, which carries fines of up to 6% of global turnover.

Scenario 3: The cancellation maze

A financial services company offers a subscription-based premium account. Signing up takes two clicks online. Cancelling requires calling a phone line, available only during business hours, where a retention specialist attempts to dissuade the customer. The company views this as standard retention practice. The FTC views it as an obstructed cancellation flow - the kind of sign-up-versus-cancellation asymmetry it continues to pursue under ROSCA and Section 5 of the FTC Act, even after the formal click-to-cancel rule was vacated.

The challenge is not that the company was trying to deceive customers. The challenge is that the asymmetry between sign-up and cancellation has become a regulatory red line that many organizations have not yet adjusted to.

What a compliance system needs to do

Dark patterns compliance requires a different approach than traditional content compliance. It is not just about what the words say - it is about how the entire experience is structured. Where might problems arise, and how can marketing compliance software support a better approach?

Pillar 1: UX and design review

  • Pattern recognition: systematic identification of known dark pattern categories across your digital estate: pre-selection defaults, misdirection, obstruction, forced continuity, hidden costs, confirmshaming

  • Consent flow auditing: every consent interface reviewed against jurisdiction-specific requirements for balanced choice presentation

  • Checkout and pricing review: drip pricing, hidden fees, and manipulative urgency signals identified and flagged

Pillar 2: Copy and claims compliance

  • Misleading framing detection: copy that creates false urgency, implies scarcity without basis, or frames choices in manipulative ways

  • Disclosure adequacy: terms, conditions, and qualifying information assessed for visibility, readability, and proximity to the claims they qualify

  • Consistency across channels: the same offer presented the same way across every touchpoint

Pillar 3: Continuous monitoring

  • Live experience scanning: published digital experiences monitored continuously for drift from approved designs

  • A/B test compliance checks: new test variations reviewed against dark patterns criteria before deployment

  • Regulatory update integration: compliance checks encoded into the system and updated as regulations evolve, so experiences that were compliant yesterday are re-assessed when requirements change

Pillar 4: Documentation and audit readiness

  • Design decision records: why specific UX choices were made, what compliance review they underwent, and who approved them

  • Version history: every iteration of a customer-facing experience documented with timestamps

  • Regulatory response packages: pre-structured documentation that can be provided to regulators on request

How these scenarios play out differently with Haast

Many of the problems regulators target are structural: a pre-selected shipping option, a de-emphasized decline button, a cancellation flow that routes through a phone line. Those are UX, product, and operational fixes. No content compliance tool changes where a button sits or rebuilds a cancellation journey - that work belongs to design, engineering, and the teams who own the customer experience.

Where Haast helps is the layer that sits on top of all of it: the promotional copy, claims, and disclosure language that surround these experiences and that dark patterns enforcement increasingly targets in its own right. Misleading scarcity claims, unsubstantiated urgency, inadequate disclosure of subscription terms, and manipulative framing of choices are content problems - and they're a large and growing share of what regulators actually cite. Haast governs that content at scale, and each check reflects the organization's bespoke risk tolerance: not generic industry rules, but the specific policies, thresholds, and regulatory interpretations encoded for that business. Just as important, it flags the risk before launch and routes the structural issues it surfaces to the teams that own them.

The checkout promotion's misleading claims get flagged before launch

Haast reviews the promotional content driving traffic to the checkout - the landing page copy, ad creative, and on-page promotional claims. The urgency statement ("Only 2 left at this price") is flagged as an unsubstantiated scarcity claim against the relevant consumer protection requirements for each market. The pricing representation is checked for drip pricing risk. The marketing team corrects the promotional language before the campaign launches, reducing the risk that conversion-optimised copy crosses into misleading conduct.

The consent flow's copy is flagged for misleading framing

 Haast reviews the marketing and disclosure language within the consent interface - how choices are labelled, how options are described, and whether the disclosure text meets adequacy requirements. The asymmetric framing between "Accept All" and "Manage Preferences" is flagged as a risk under the DSA's dark patterns prohibition, CCPA's consent design rules, and the UK's ICO guidance. The team revises the consent language to present options in balanced, neutral terms before deployment.

The subscription marketing is checked for accurate cancellation disclosure

Haast reviews the promotional materials for the subscription product - the sign-up landing page, email campaigns, and ad creative - and flags that the cancellation process is not adequately disclosed alongside the sign-up claims. Marketing materials promote a two-click sign-up without mentioning the phone-only cancellation requirement. The compliance team updates the promotional copy to include clear, prominent cancellation terms, and escalates the operational asymmetry to the product team for resolution.

Haast's implementation is led by a team of former lawyers who understand the regulatory nuance of dark patterns enforcement - not generic customer success. And the system continuously learns from every review, calibrating its pattern recognition to your organization's evolving risk tolerance over time.

See how Zurich cut compliance review times by 50% using the same compliance AI platform to govern marketing compliance across their digital estate.

Book a demo

If your organization needs to audit and govern digital experiences for dark patterns risk across multiple markets, book a demo with the Haast team today.

Team Haast

Explore more