Deceptive Patterns
‹ All reading

On the Suitability of LLM-Driven Agents for Dark Pattern Audits

Author
Chen Sun, Yash Vekaria, Rishab Nithyanand
Date
4 Mar 2026
Publisher
Proceedings on Privacy Enhancing Technologies
Focus
AI & Automation
Category
Academic Scholar

An LLM-driven agent that traverses data-rights request portals end to end, gathers evidence and classifies obstructive designs was run across 456 data broker websites to test whether such agents can reliably complete CCPA workflows and recognise friction, misdirection and coercion.

As LLM-driven agents begin to autonomously navigate the web, their ability to interpret and respond to manipulative interface design becomes critical. A fundamental question that emerges is: can such agents reliably recognize patterns of friction, misdirection, and coercion in interface design (i.e., dark patterns)? We study this question in a setting where the workflows are consequential: website portals associated with the submission of CCPA-related data rights requests. These portals operationalize statutory rights, but they are implemented as interactive interfaces whose design can be structured to facilitate, burden, or subtly discourage the exercise of those rights. We design and deploy an LLM-driven auditing agent capable of end-to-end traversal of rights-request workflows, structured evidence gathering, and classification of potential dark patterns. Across a set of 456 data broker websites, we evaluate: (1) the ability of the agent to consistently locate and complete request flows, (2) the reliability and reproducibility of its dark pattern classifications, and (3) the conditions under which it fails or produces poor judgments. Our findings characterize both the feasibility and the limitations of using LLM-driven agents for scalable dark pattern auditing.