Skip to content
The Product Guys
All principles
DecidingAlso called Nudge ethics, Responsible design

Ethical choice architecture

The line is whether the user would endorse the influence once it is explained to them.


Since no presentation is neutral, the ethical question is not whether to influence but which influences you can defend. The workable tests are publicity, whether you would state the mechanism openly; endorsement, whether the user would agree with it once told; and reversibility, whether backing out is as cheap as going along. A design that fails any of the three needs a better justification than its conversion rate: The share of people at one step of a flow who reach the next one..

Who benefits, and can the user see it

Hidden help:nudges you willnot describeDefensible: userbenefit, statedopenlyManipulation:company benefit,concealedHonest selling:company benefit,disclosedUnexplained feedrankingOpt-out pensionenrolmentSecurity defaultsonPretickedmarketing consentCancellation mazeConfirmshamingdecline copyLabelledsponsored resultsUpgrade prompt ata real limitWould you explain the mechanism to the userWho the influence serves
Two questions decide whether an influence is defensible: does it serve the user, and would it survive being explained. Only the top right is clearly safe. The top left is paternalism the user has not agreed to, the bottom right is honest selling, and the bottom left is where dark patterns live.

How it shows up in software

In practice this becomes a review step: someone asks, for each influence in a flow, who it serves and whether it survives being described. Teams that do this well keep a written register of defaults and nudges with an owner for each, and treat removing a manipulative one as shippable work rather than a loss to be argued away.

Using it well

  • Apply the publicity test in writing. Draft the sentence explaining the mechanism to the user, and if you will not ship the sentence, do not ship the mechanism.
  • Keep an influence register: every default, prompt, urgency element and asymmetric flow, with an owner and a stated beneficiary.
  • Budget for removals. Put at least one dark pattern: An interface built to get an outcome the user would reject if it were stated plainly. removal in each quarter, with the expected conversion cost stated up front so it is not a surprise.
  • Measure the harm side too. Track refunds, cancellation complaints, support contacts about unexpected charges, and read them alongside conversion.

Where it turns manipulative

  • Ethics used as a shield rather than a practice, such as a published set of principles with no review gate, makes it harder to raise the specific objection because the company has already declared itself good.
  • Treating legal compliance as the ceiling means the design is set by the slowest regulator. Several patterns were standard practice for a decade before they became illegal.
  • Selective application, where the ethics review covers consent flows but not pricing or retention, tends to leave exactly the surfaces where the money is.

Where you have seen it

  • Apple App Tracking Transparency prompt

    A symmetric two-option system prompt with equal weight on both choices, where the platform sets the architecture rather than the party with the incentive.

  • GOV.UK service standard

    A published set of checks applied at review gates before a service can go live, which is the register-plus-gate model rather than a statement of values.

  • Mozilla and similar privacy notices

    Data practices summarised in plain language at the point of collection, with defaults set to the protective option.

What the research says

  • Sunstein, 2015 (The Ethics of Influence)Well evidenced

    Works through the autonomy, dignity and welfare objections to nudging and proposes transparency and ease of opt-out as the core constraints.

    Philosophical argument rather than empirical work. Treat it as a framework to apply, not a result to cite.

  • Loewenstein et al., 2015 and Bruns et al., 2018Well evidenced

    Transparency about a nudge: A change to how choices are presented that shifts behaviour without removing any option. did not measurably reduce its effect in either set of experiments.

    This is the empirical load-bearing point. Because disclosure is close to free in effectiveness terms, choosing not to disclose is a choice about the mechanism, not about the results.

  • Luguri and Strahilevitz, 2021 (Journal of Legal Analysis)Well evidenced

    Aggressive manipulative designs raised short-term acceptance but produced measurable user backlash, and milder ones fell hardest on less educated participants.

    Gives the distributional argument teeth. Manipulation is not evenly distributed in its harms.

Grades are a judgement about the evidence, not about how useful the idea is. Plenty of contested effects are still worth knowing, as long as you do not cite them as settled.

Related