Research explained · Peer-reviewed study

AI agents can recognise a dark pattern, and still follow it

Tang and colleagues tested GUI agents, human participants and human-agent teams across 16 dark-pattern types. They found that agents often failed to recognise manipulative interfaces; even when recognition appeared in their reasoning, task completion could still outrank protective action. Human oversight improved avoidance in some settings but introduced cognitive load and attentional narrowing. The study makes agent-mediated journeys a serious design question, not a reason to assume all agents or oversight models fail.

Peer-reviewed study
Original work
Dark Patterns Meet GUI Agents: LLM Agent Susceptibility to Manipulative Interfaces and the Role of Human Oversight
Authors
Jingyu Tang, Chaoran Chen, Jiawen Li, Zhiping Zhang and colleagues
Published
2026-04-13
Venue
ACM CHI 2026
Method
A two-phase controlled study comparing GUI agents, human participants and human-supervised agents across selected deceptive interfaces.
Sample or scope
Six evaluated GUI agents and 16 dark-pattern types across diverse controlled scenarios, followed by human and human-agent conditions.

Read the evidence carefully

From research question to useful conclusion

  1. 1

    Question

    Tang and colleagues tested GUI agents, human participants and human-agent teams across 16 dark-pattern types.

  2. 2

    Method

    A two-phase controlled study comparing GUI agents, human participants and human-supervised agents across selected deceptive interfaces.

  3. 3

    Finding

    An agent could mention a manipulation in its reasoning yet continue when avoidance required extra effort or conflicted with completing the assigned task.

  4. 4

    Boundary

    The selected agents, prompts, interfaces and 16 pattern types do not represent every model, deployment, accessibility need or real commercial journey.

Evidence at a glance

The controlled study’s design breadth

The counts describe the published experimental structure, not success or failure percentages.

  1. Dark-pattern types examined16
  2. GUI agents evaluated in phase one6
  3. Study phases2
The study compared automated, human and human-agent responses in controlled scenarios; real deployments may behave differently. Source: Dark Patterns Meet GUI Agents: LLM Agent Susceptibility to Manipulative Interfaces and the Role of Human Oversight.

A new participant has entered the customer journey

Dark-pattern research traditionally asks what an interface does to a person. GUI agents complicate that picture. A user can now delegate a task, subscribe to a creator, compare products, change a setting, and allow software to interpret the interface and act.

The 2026 CHI paper asks whether manipulative design also affects those agents. Its answer is not a simple yes or no. Agents and people failed in different ways, and putting them together did not automatically combine their strengths.

Recognition can lose to task completion

One of the paper’s most useful distinctions is between awareness and avoidance. An agent may detect that something looks manipulative but still prioritise the shortest route to the user’s stated goal. If an advertising consent box appears to be part of subscription, an agent can treat it as a necessary procedural step instead of stopping to ask whether the additional consequence was intended.

That is a specification problem as much as a perception problem. “Complete the task” is not enough when the interface contains material optional choices.

Why human confirmation is not a magic shield

Oversight helped, but it also demanded attention. A person supervising an agent must understand the instruction, notice the relevant interface state, interpret the agent’s proposed action and decide quickly whether to intervene. Repeated generic confirmations can become another form of noise.

A better handoff states the consequence in context: what will be selected, what data or money is involved, whether the action recurs and how it can be reversed. The person should be able to inspect the evidence rather than approve an opaque action label.

What this changes for product review

The same journey may now have at least three decision environments: a person acting directly, an agent acting autonomously and a person supervising an agent. Product and legal teams should record all three where the service supports or anticipates agent use.

The forced-action family is especially relevant where an agent mistakes an optional disclosure or consent for a requirement. The obstruction family matters when the protective route requires steps outside the task plan.

The paper calls attention to accountability and user-agency gaps. It does not settle how a future DFA proposal will address agent-mediated interfaces. Until published law says otherwise, the sound approach is to document the new interaction, apply current instruments where in scope and preserve unknowns rather than inventing an agent-specific duty.

Source check on 14 September 2026

The authors’ accessible paper distinguishes awareness coded from reasoning traces from avoidance observed in actions. Agents sometimes avoided a pattern without identifying it. This matters for evaluation: a successful outcome alone does not show reliable detection, and a warning alone does not show protection. The tested configurations are historical study conditions, not a September 2026 model ranking.

What to retain

Three findings worth carrying into review

Awareness was not enough

An agent could mention a manipulation in its reasoning yet continue when avoidance required extra effort or conflicted with completing the assigned task.

Failure modes differed

People were influenced by cognitive shortcuts and habitual compliance, while agents showed procedural blind spots tied to task execution and interface interpretation.

Oversight carried costs

Human involvement improved some outcomes but could narrow attention and increase cognitive load, so a confirmation prompt alone was not a complete safety design.

What this evidence cannot establish

  • The selected agents, prompts, interfaces and 16 pattern types do not represent every model, deployment, accessibility need or real commercial journey.
  • The paper identifies design and accountability questions; it does not create a Digital Fairness Act duty or validate a particular scanning product.

Questions for a journey review

  1. Which actions may an agent complete without confirmation, and which price, privacy, subscription or cancellation consequences require an explicit handoff?
  2. Does the oversight interface present the material choice and changed state, or merely ask a tired user to approve a generic action?
  3. Can the system preserve the interface, agent action, instruction, confirmation and final account state for later review?

Evidence base

Sources

  1. Dark Patterns Meet GUI Agents: LLM Agent Susceptibility to Manipulative Interfaces and the Role of Human OversightTang et al.; ACM CHI 2026 · Secondary · checked 2026-09-14 · DOI 10.1145/3772318.3791568; arXiv:2509.10723