Dark Patterns are Now
a Regulatory Risk

Detect, Classify, Remediate Manipulative Journeys Before
Regulators Intervene

Motherson Technology Services Dark Pattern Detection scans customer journeys, source code and API traffic to find manipulative design before it becomes a compliance issue. Every result is mapped against the relevant regulation, backed by evidence, and paired with clear guidance on what to fix.

CCPA Dark Patterns Guidelines 2023 | IRDAI Directive 2026 | RBI Responsible Business Conduct Directions 2026
Request a Demo / Free PoC




    When Good Design Turns into Manipulation

    The practices the Consumer Protection Authority Now Regulates

    A dark pattern is a design choice built to steer a customer towards an outcome they did not intend: an unwanted purchase, an unnecessary disclosure, or agreement to terms they never properly saw. The Central Consumer Protection Authority (CCPA) has mandated such practices.

    False Urgency

    False Urgency

    Countdown timers, low-stock warnings and similar pressure tactics used to force a rushed decision

    Basket Sneaking

    Basket Sneaking

    Products or add-ons placed in a customer's cart without their explicit consent

    Disguised Advertising

    Confirm Shaming

    Wording designed to guilt a customer into staying on a particular option

    Forced Action

    Forced Action

    Requiring registration, subscription or an unrelated step before a customer can proceed

    Confirm Shaming

    Drip Pricing (Hidden Charges)

    Fees or charges that only appear once the customer has committed to the purchase

    Subscription Trap

    Subscription Trap

    A sign-up flow that takes seconds, paired with a cancellation flow that is deliberately hard to find

    Hidden Information

    Interface Interference

    Visual design choices that highlight one option while burying another

    Interface Interference

    Bait and Switch

    Advertising one product, price or outcome, then delivering a different one at checkout

    Drip Pricing

    Disguised Advertisement

    Paid promotional content presented as an independent review or organic content.

    Privacy Manipulation

    Nagging

    Repeated prompts or pop-ups used to wear a customer down into a particular choice.

    Nagging

    SaaS Billing

    Recurring charges structured so renewal is automatic and cancellation is difficult to locate

    Trick Wording

    Rogue Malware

    Fake security alerts used to push a download or a purchase.

    Other Practices

    Trick Wording

    Opt-in or opt-out language written to be misread or misunderstood.

    One Platform, Three Layers of Detection

    Live Screens, Source Code and API Calls, Covered

    MTSL Dark Pattern Detection is an AI-powered compliance platform that identifies, classifies and reports dark patterns across an organisation's digital estate. It replaces periodic manual reviews with repeatable, evidence-backed detection, across the interfaces customers see, the code behind them, and the APIs that move data between the two.

    Scanning Layer
    Scope & Mechanism
    Key Operational Value

    Screen Scanner

    Real-time crawl of live digital surfaces, responsive web pages, and mobile applications (iOS/Android).
    Detects visual manipulations, pressure tactics, and hidden charges directly visible to consumers.

    Repo Scanner

    Direct analysis of source code repositories during development cycles.
    Flags non-compliant implementation logic before software updates reach live environments.

    API & Payload Analyser

    Inspection of network requests, backend responses, and transactional payloads.
    Identifies algorithmic steering, dynamic fee additions, and obfuscated consent transfers.
    Detection and compliance illustration

    Detection is only Where
    This Starts

    Six Capabilities that Turn Findings into Fixed Issues

    Automated Detection - AI models analyse digital journeys and flag patterns that need a compliance review

    Regulatory Classification - Every flagged pattern is mapped to the relevant regulatory category and journey stage, with a confidence score attached

    Risk & Severity - Findings are organised by severity, so teams know what to prioritise first

    Remediation Guidance - Specific, actionable direction for product, UX, technology and compliance teams on how to close each finding

    Evidence Packs - Screenshots, findings and audit trails, captured into a record built for review and reporting

    Self-Audit Dashboard - One consolidated view of findings, severity, trends and remediation progress for the compliance team

    Numbers That Matter to Compliance Teams

    Proof-of-concept Results Based on the Current Solution Scope

    13
    CCPA-specified dark
    pattern categories
    covered
    7
    Insurance journey
    stages mapped
    95%
    Detection accuracy
    recorded in the proof
    of concept
    <24h
    Time to first
    compliance report
    Cybersecurity Monitoring

    Six Steps from Scan to Report

    A Repeatable Process from Scan to Full Report

    Scan - Analyse selected websites, applications, repositories or API payloads

    Detect - Identify potential dark patterns across the configured categories

    Classify - Map each finding to the relevant regulatory category, with confidence and severity assigned

    Review - Present findings on a dashboard, with supporting evidence and context

    Remediate - Give product, UX, compliance and engineering teams clear, actionable guidance

    Report - Generate evidence-backed findings and audit trails for internal governance and compliance review

    Built for Every Consumer-Facing Digital
    Business Today

    Industries Where Digital Journeys Carry Real Risk

    E-Commerce & Digital
    Marketplaces

    Review product discovery, pricing, cart and checkout journeys for potentially manipulative practices

    Direct-to-Consumer
    Brands

    Continuously assess digital storefronts and customer journeys as products and experiences evolve

    OTT & Subscription
    Services

    Review subscription, renewal, cancellation and billing experiences for misleading or restrictive practices

    Insurance & BFSI

    Assess regulated digital journeys where consent, suitability, product selection and communication need closer scrutiny

    Compliance Rules

    Built Around India's Changing Compliance Rules

    Aligned to CCPA, IRDAI and RBI Requirements Today

    Digital consumer journeys are under growing regulatory scrutiny. The platform helps organisations assess their digital experiences against applicable dark-pattern and responsible-business-conduct requirements.

    CCPA (Central Consumer
    Protection Authority),
    2023

    Supports detection across the dark-pattern categories set out in the Guidelines for Prevention and Regulation of Dark Patterns, 2023

    IRDAI

    IRDAI has directed insurers and intermediaries to comply with the CCPA dark-pattern guidelines and to self-assess their digital journeys. Findings are mapped across insurance-specific journey stages to support that assessment

    RBI Responsible
    Business Conduct
    Directions

    Supports assessment of banking-specific customer journeys involving consent, product suitability, bundling, agent conduct and mis-selling controls, ahead of the Responsible Business Conduct (Second Amendment) Directions, 2026, taking effect on 1 January 2027

    Cybersecurity Monitoring

    Banking Journeys Need a Closer Look

    Six Assessment Areas Built for Regulated Banking Journeys

    Consent by Design - Assess whether consent mechanisms are explicit and properly separated across products

    Mis-Selling Controls - Identify journey characteristics that may contribute to inappropriate product selling or outcomes

    Bundling - Assess whether third-party products or services are presented in ways that could improperly restrict customer choice

    Agent Governance (DSA / DMA) - Support review of journeys involving direct selling agents, direct marketing agents, sub-agents and other channels now within regulatory scope

    Suitability - Assess journey controls around customer suitability and product fit

    Customer Contact Controls - Support review of applicable consent and interaction controls across customer journeys

    Two Ways to Bring This Live

    Managed Cloud or Direct API Integration, Your Choice

    Managed Cloud - fastest to deploy

    Hosted on AWS. Built for rapid compliance validation, with no customer-managed on-premise infrastructure required. Delivered on a subscription basis

    API Integration - platform-native

    REST APIs integrate with existing workflows. Scanning can be triggered from page-publish or application events, connected to seller portals and CI/CD pipelines, with webhook support for alerts and downstream workflows

    AWS Enterprise Scale

    Built on AWS for Enterprise Scale

    Six AWS Layers Powering Capture, Detection and Evidence

    The managed deployment runs on AWS services chosen for scalable capture, orchestration, AI-powered detection, evidence management, identity and operational visibility.

    Capture - Amazon ECS / AWS Fargate, AWS WAF and Elastic Load Balancing support scalable web capture and controlled ingress

    Orchestration - Amazon EventBridge, Amazon SQS and AWS Step Functions coordinate scheduled and event-driven scanning workflows

    AI & Detection - Amazon Bedrock and/or Amazon SageMaker support managed inference, with Amazon OpenSearch supporting retrieval and pattern knowledge

    Data & Evidence - Amazon S3 stores screenshots and evidence; Amazon Aurora holds cases, findings and configuration data

    Identity & Access - Amazon Cognito supports authentication and role-based application access

    Security & Operations - AWS KMS, AWS Secrets Manager, AWS IAM, AWS CloudTrail, Amazon GuardDuty, Amazon CloudWatch and AWS Config support encryption, access control, auditability, monitoring and governance

    Catch Issues Before and After Release

    Four Checkpoints Across your Entire Delivery Lifecycle

    This gives product, engineering and compliance teams a way to manage dark-pattern risk across the entire delivery lifecycle, rather than relying solely on periodic manual audits.

    Live Experience

    Scan customer-facing web and
    application journeys

    Source Code

    Analyse repositories to identify
    risky implementation patterns
    earlier

    APIs & Payloads

    Inspect application behaviour
    that isn't obvious from the visual
    interface alone

    Evidence &
    Reporting

    Consolidate findings, screenshots,
    severity and remediation guidance
    in one place

    Compliance and enterprise technology

    Compliance Expertise Meets
    Enterprise-Grade Technology
    Delivery Together

    One Team Spanning AI, Compliance and Enterprise Technology

    Motherson Technology Services pairs AI-led detection with enterprise technology delivery, helping organisations put dark-pattern compliance into practice across complex digital estates; not just identify it on paper.

    The platform is built to bring compliance, product, UX and engineering teams into a single workflow: surfacing issues, providing evidence, prioritising remediation and supporting ongoing governance.

    Start Small, Prove Value in Days

    A 15-day Proof of Concept, Evidence Included

    Validate the platform against selected digital journeys before committing to a broader deployment.

    Live Surface
    Coverage

    Crawler-based detection across selected web, responsive, iOS and Android experiences

    Configurable
    Categories

    Run the full supported dark- pattern set, or a subset chosen for the use case

    Evidence-Backed
    Findings

    Findings organised by surface, journey step and category, ready for review and remediation

    Multi-Entity Scope

    Assess multiple agreed entities or digital properties, with each assessment scope kept separate

    15-Day PoC: end-to-end crawl, detection and an evidence-backed findings register, delivered within the agreed window.
    Compliance technology

    Know Before Your
    Regulator Does, Not After

    Move from Manual Reviews to Automated,
    Evidence-backed Detection

    Replace point-in-time manual compliance reviews with continuous, evidence-backed dark-pattern detection across your digital estate.