Dark patterns used to sound like a niche UX ethics topic. In 2026, they are a business risk.

Regulators are watching them. Customers are calling them out. Designers are being asked to explain them. Business owners are learning that a few extra short-term signups are not worth lost trust, refund requests, payment disputes, legal exposure, or support tickets.

A dark pattern is a design choice that pushes people toward an action they might not choose with clear information and a fair path. That can mean hiding fees, making cancellation harder than signup, preselecting a privacy-invasive option, using shame-heavy opt-out language, creating false urgency, or making the safer option look disabled.

This guide is a practical checklist for web professionals and business owners. Use it before launching a new site, auditing an ecommerce checkout, reviewing a SaaS onboarding flow, fixing cookie consent, or cleaning up a lead generation funnel.

Why dark patterns deserve a 2026 website audit

The numbers are too large to ignore.

The FTC, ICPEN, and GPEN announced a 2024 review of 642 subscription websites and apps where nearly 76% used at least one possible dark pattern and nearly 67% used multiple possible dark patterns. (FTC)

A separate GPEN privacy sweep reviewed more than 1,000 websites and mobile apps and found that nearly all used one or more deceptive design patterns affecting privacy choices. (GPEN)

The Office of the Privacy Commissioner of Canada found at least one indicator of deceptive design in 99% of the 145 websites and apps it reviewed, compared with 97% in the global GPEN result. (OPC Canada)

Researchers from Princeton and the University of Chicago analyzed about 53,000 product pages from about 11,000 shopping websites and found 1,818 dark pattern instances across 15 types and 7 categories. (Princeton Web Transparency Project)

This is not limited to fringe websites. The FTC finalized an order requiring Epic Games to pay $245 million in consumer refunds after alleging that Fortnite used dark patterns that led to unwanted charges. (FTC)

The FTC also sued Adobe in 2024, alleging that the company hid early termination fees and made subscription cancellation difficult through numerous hurdles. (FTC)

The takeaway is simple: dark patterns are no longer just “aggressive marketing.” They are documented, named, searched, regulated, and expensive.

The dark patterns checklist

Use this as a page-by-page review. If a pattern appears anywhere in the buyer journey, either remove it or rewrite it into a fair, clear version.

1. Hidden fees near checkout

Hidden fees appear when shipping, handling, service charges, taxes, installation costs, processing fees, or required add-ons show up late in the purchase flow.

Baymard reports that the average documented online shopping cart abandonment rate is 70.22%, and extra costs being too high is the top listed reason among shoppers who abandoned for reasons other than browsing. (Baymard Institute)

That does not mean every fee is deceptive. It means fees need to appear early enough that a reasonable buyer can compare real costs.

What to fix: show estimated totals before checkout, disclose required fees on pricing pages, and avoid waiting until the final payment step to reveal unavoidable costs.

2. Fake urgency and countdown timers

False urgency uses timers, “ending soon” banners, or expiring offers that do not really expire. Princeton’s crawl found 393 countdown timer instances across 361 websites. (Princeton Web Transparency Project)

Real deadlines are fine. Fake deadlines train people not to trust you.

What to fix: use countdowns only for real expiration dates. If the sale repeats every day, do not pretend it is a once-only event.

3. Fake scarcity and low-stock messages

Scarcity becomes deceptive when inventory claims are vague, automatic, or unrelated to actual stock. Princeton found 632 low-stock message instances across 581 websites, making it one of the most common examples in its shopping site crawl. (Princeton Web Transparency Project)

A real “3 left” notice can help shoppers. A generic “almost gone” badge on every product is pressure dressed up as information.

What to fix: connect stock messages to live inventory, remove vague pressure copy, and avoid showing scarcity signals on products where stock is not actually limited.

4. Preselected paid add-ons

A preselected add-on turns a default state into a sales tactic. The user has to notice the extra item, understand it, and remove it.

Princeton categorized “sneak into basket” as adding products to shopping carts without consent and documented examples where cards or screen protectors were included unless the user opted out. (Princeton Web Transparency Project)

What to fix: make add-ons opt-in, not opt-out. If something costs money, require a clear user action before adding it.

5. Hidden subscriptions

A hidden subscription occurs when a free trial, club, discount, or one-time purchase creates a recurring charge that is not obvious.

Princeton found hidden subscription examples where recurring charges were only revealed after clicking secondary terms links. (Princeton Web Transparency Project)

The FTC’s click-to-cancel rule also requires sellers to disclose key terms before collecting billing information for negative option programs. (FTC)

What to fix: state the renewal price, billing date, cancellation method, and trial length beside the signup button.

6. Cancellation that is harder than signup

If someone can subscribe online in two minutes but has to call, email, wait, or talk to retention to cancel, that is a red flag.

The FTC’s final click-to-cancel rule requires sellers to make cancellation as easy as signup for covered recurring subscriptions and memberships. (FTC)

FTC complaint volume around negative option and recurring subscription practices rose from an average of 42 consumer complaints per day in 2021 to nearly 70 per day in 2024. (FTC)

What to fix: put cancellation in account settings, avoid unnecessary retention screens, confirm cancellation immediately, and email a clear receipt.

7. Confirmshaming

Confirmshaming uses guilt or insult language to push people into the preferred option. Examples include “No thanks, I hate saving money” or “I do not care about growing my business.”

Princeton found 169 confirmshaming instances across 164 websites in its shopping site crawl. (Princeton Web Transparency Project)

What to fix: make decline copy neutral. “No thanks” is enough.

8. Visual hierarchy that hides the fair choice

A page can technically offer a choice while visually punishing the option the business dislikes. The reject button might be gray, tiny, buried, or styled like disabled text.

The 2024 GPEN sweep found that 57% of websites and apps made the least privacy-protective option the most obvious and easiest to select when presenting privacy choices. (GPEN)

The California Privacy Protection Agency warned businesses to present privacy choices in a clear and balanced way and said dark patterns are about effect, not intent. (CPPA)

What to fix: make accept and reject choices equally visible, equally easy, and equally understandable.

9. Trick questions

Trick questions use confusing wording to get the answer the company wants. A checkbox might say “Do not uncheck this box if you do not want emails,” which forces the user to parse a logic puzzle.

Princeton documented trick questions where users had to tick a checkbox to opt out, reversing the normal expectation of checkboxes. (Princeton Web Transparency Project)

What to fix: write choices in plain language. Each option should make sense on its own.

10. Forced account creation

Forced account creation blocks a purchase, download, quote, or basic browsing task until the user creates an account or shares more information than needed.

Baymard found that 19% of US online shoppers who abandoned a cart for non-browsing reasons did so because the site wanted them to create an account. (Baymard Institute)

What to fix: offer guest checkout, delayed account creation, or magic-link account setup after purchase.

11. Privacy policy as a maze

A privacy policy can be visible and still unusable if it is too long, too technical, or written for lawyers instead of customers.

The GPEN sweep found that more than 89% of privacy policies reviewed were long or used complex language suited for people with a university education. (GPEN)

OPC Canada found that 76% of reviewed privacy policies were over 3,000 words and 83% were difficult to read by Flesch Reading Ease standards. (OPC Canada)

What to fix: add a plain-English summary, use section labels people recognize, and link directly to key topics like data sharing, retention, deletion, and opt-out rights.

Cookie banners become dark patterns when “accept all” is one click but “reject all” is hidden behind settings. A choice is not fair if one path is frictionless and the other path is a scavenger hunt.

The FTC says dark pattern techniques can steer consumers into actions they would not otherwise have taken, including giving up privacy. (FTC)

What to fix: include “accept all,” “reject all,” and “manage choices” in the same layer when possible.

13. Nagging after a decision

Nagging happens when users have already made a choice but the interface keeps asking them to reconsider.

The GPEN sweep found that 35% of websites and apps repeatedly asked users to reconsider their intention to delete their account. (GPEN)

What to fix: allow one confirmation for serious actions, then stop. Do not ask the same question three different ways.

14. Account deletion that cannot be found

Deletion rights are not meaningful if users cannot find the delete path.

OPC Canada found that sweepers could not find the account deletion option at all on 43% of reviewed websites and apps, compared with 55% in the global result. (OPC Canada)

What to fix: put deletion controls under account settings or privacy settings, label them clearly, and explain what happens next.

15. Emotionally loaded privacy language

Privacy choices should not be framed as fear, guilt, or social pressure. A banner that says “Yes, protect me” beside “No, put my account at risk” is not neutral.

The GPEN sweep found that 42% of websites and apps used emotionally charged language when asking users to make privacy choices. (GPEN)

What to fix: replace loaded labels with factual labels such as “Use optional analytics cookies” and “Do not use optional analytics cookies.”

16. Activity messages of uncertain origin

“Someone in Dallas just bought this” can be useful if it is real and recent. It becomes deceptive when the activity is stale, automated, invented, or unverifiable.

Princeton found 313 activity message instances across 264 websites and described examples where messages suggested recent customer activity even when the underlying event was not recent. (Princeton Web Transparency Project)

What to fix: only show real activity, avoid personal-looking fake alerts, and remove notifications that cannot be explained internally.

17. Testimonials with unclear sourcing

Testimonials lose credibility when readers cannot tell whether they came from real customers, paid promotions, imported reviews, or internal copywriting.

Princeton identified testimonials of uncertain origin as a deceptive pattern where the source of the testimonial was unclear. (Princeton Web Transparency Project)

What to fix: include names, roles, company names, review platforms, dates, or case study links where appropriate.

Payment consent needs to be clear before money moves. If a user can be charged because a card was saved by default, because a purchase button was easy to hit accidentally, or because the pricing model was unclear, the interface is carrying serious risk.

The FTC said Epic’s confusing button configuration led players to incur unwanted charges from a single button press and barred Epic from charging consumers through dark patterns or without affirmative consent. (FTC)

What to fix: show the item, price, billing frequency, payment method, and final action in one clear confirmation step.

19. “Free” offers with buried conditions

Free offers are high-risk when the user must enter payment information, will be charged later, must cancel by a deadline, or must accept restrictions.

The FTC’s negative option rule requires important information before obtaining billing information and informed consent before charging for negative option features. (FTC)

What to fix: state what is free, what triggers payment, when payment starts, and how to cancel before the trial converts.

A fast scoring framework for any website

Give each page or flow a score from 0 to 2 for each question below.

  • 0 means the pattern is not present.
  • 1 means the pattern may be present or needs review.
  • 2 means the pattern is clearly present and should be fixed.

Questions:

  1. Are any prices, fees, renewals, or required conditions delayed until late in the flow?
  2. Is the business-preferred choice easier to see, click, or understand than the user-protective choice?
  3. Does the user have to take extra steps to say no, cancel, delete, reject, or opt out?
  4. Is any urgency, scarcity, activity, or testimonial claim difficult to verify?
  5. Would a reasonable customer feel misled if they described the flow to a friend?

A score of 0 to 2 is low risk. A score of 3 to 5 means the flow needs copy or interface cleanup. A score of 6 or more means you should treat it as a conversion, trust, and compliance problem.

What ethical conversion design looks like

Removing dark patterns does not mean making your website passive. You can still sell clearly. You can still write persuasive copy. You can still recommend a plan, highlight a deadline, show reviews, and ask for the lead.

The line is whether the user has a fair view of the decision.

A good pricing page explains who each plan is for. A bad pricing page hides the real billing commitment.

A good checkout reminds people why they should complete the order. A bad checkout adds products they did not choose.

A good cookie banner explains options. A bad cookie banner makes privacy-protective choices harder to find.

A good cancellation flow asks for confirmation and offers help. A bad cancellation flow turns cancellation into a maze.

Nielsen Norman Group describes deceptive patterns as designs that promote business outcomes at the user’s expense. (Nielsen Norman Group) That is the right test. If the business wins only because the user is confused, rushed, ashamed, or blocked, the design is doing the wrong job.

What to audit first

If you do not have time to review the whole site, start with the places where money, data, or consent changes hands.

Prioritize these flows:

  • Pricing, quote, cart, checkout, payment, trial signup, renewal, cancellation, cookie consent, privacy choices, account deletion, lead forms, and newsletter popups.

Then look at the supporting trust signals: testimonials, review widgets, stock notices, offer banners, guarantee copy, FAQs, comparison tables, and plan selectors.

For each issue, rewrite the interface around a simple rule: the user should understand what happens if they click.

That single standard fixes more website trust problems than most redesigns.

Final takeaway

Dark patterns can lift a metric while damaging the business behind it.

They may increase email captures while lowering brand trust. They may increase trials while raising refunds. They may delay cancellations while increasing complaints. They may squeeze a few more orders out of checkout while teaching customers to never come back.

The better move is not softer marketing. It is clearer marketing.

Make the real offer easier to understand. Make the total cost visible. Make consent meaningful. Make cancellation findable. Make proof verifiable. Make privacy choices balanced. Then measure conversion, support volume, refunds, chargebacks, repeat purchases, and customer sentiment together.

If you want a second set of eyes on a website flow before it costs you trust, Your Web Team can review your site and help clean up the risky parts.