We have spent fifteen years teaching people that consent is an obstacle

August 2026 · 8 min read

I dismissed four cookie banners before I finished the first paragraph of this piece. I could not tell you what any of them said. That is not carelessness on my part, or not only carelessness. It is the entirely predictable result of a system that has asked me the same question several thousand times and never once made the answer matter.

What the evidence already shows

The cookie banner is usually studied as a design and compliance problem, and there is very good work here. Nouwens, Liccardi, Veale, Karger and Kagal (2020) scraped the five most popular consent management platforms across the top 10,000 UK websites, ending up with 680 sites, and tested them against three minimum conditions drawn from European law. Consent must be explicit. Rejecting must be as easy as accepting. Nothing optional may be pre-ticked.

11.8 percent passed. The authors are careful to call that a maximum rather than an estimate, since it only counts what a scraper can test and would fall further under closer legal reading.

The individual failures are worth listing because they are so uniform. Around a third of sites treated something other than a click as consent, including simply visiting the site, scrolling, or refreshing the page. Half had no reject-all button at all. Only 12.6 percent placed reject-all within the same number of clicks as accept-all, and an accept-all button was never once buried on a second page. Over half pre-ticked optional vendors or purposes.

Their field experiment then measured what those designs do. Removing the reject-all button from the first page raised the accept rate by 22 to 23 percentage points. Moving granular controls onto the first page lowered it by 8 to 20.

So the banner is not a neutral question. It is a designed instrument, and it is usually built to produce one answer.

The number that stopped me

But the finding I keep returning to is not about design at all.

Across 1,280 recorded answers, 17 represented a participant consenting to a specific selection of purposes or vendors. Not 17 percent. Seventeen answers. That is 1.3 percent.

Almost everything else came through the bulk buttons. Participants stayed on the first page 93.1 percent of the time. The “more options” link, present on seven of the eight interfaces, was clicked 88 times out of 1,280. When a scrollable list of purposes or vendors was put in front of them, they ignored it 68.6 percent of the time, and when they did scroll, they mostly went either barely at all or all the way to the bottom.

The authors draw the obvious conclusion, which is that anything not immediately visible might as well not exist. But there is a legal consequence sitting next to it. European law requires consent to be specific to a purpose. Empirically, in this sample, specific consent essentially did not occur. The mechanism the law describes and the behaviour the law produces are not the same phenomenon.

Nouwens and colleagues are honest that they cannot say why. Users may be unable to make the decisions, uninterested in that level of detail, or fatigued by the form and frequency of the question. Those are three different diagnoses with three different remedies, and the paper leaves the question open.

I want to argue that the third one has been underweighted, and that there is an entire literature sitting next to this that would help.

The other literature

There is a large body of research on what happens to people exposed to frequent alerts that almost never precede consequences. It comes mostly from safety-critical settings. Clinical alarm fatigue in intensive care, where staff hear hundreds of alarms per patient per day and the overwhelming majority are false or clinically irrelevant. Aviation. Industrial process control.

The findings are consistent and uncomfortable. Response rates decay with exposure. The decay generalises beyond the specific alert that caused it. And it is not repaired by making the alert more salient, which is the intervention everybody reaches for first.

Computer security researchers made this connection early. Sunshine, Egelman, Almuhimedi, Atri and Cranor published a study in 2009 titled “Crying Wolf”, testing whether SSL warnings actually worked, and found people clicking through browser security warnings at rates that made the warnings close to decorative. Users had learned, correctly, that the warning almost never indicated a real problem for them.

Notice what that literature predicts for the banner-versus-barrier comparison. Making an alert impossible to avoid should not change the quality of the response, only whether a response happens.

Which is more or less what the data show. Nouwens and colleagues found no significant difference in accept rate between a banner at the edge of the page and a barrier blocking the content entirely. What did differ was avoidance. The banner was ignored 3.6 times more often than the barrier, with 106 of the 133 ignored pop-ups being banners. Blocking the page did not produce a more considered answer. It produced an answer.

The authors read this generously, suggesting the non-blocking banner offers users a neutral middle ground, a third option between accepting and rejecting. I think that reading is right and I think it is also a description of habituation. A neutral middle ground that 78.9 percent of ignorers take is not deliberation. It is the trained response to an interruption that has never once mattered.

What was accidentally built

Consider what the ePrivacy Directive and the GDPR jointly constructed, without anyone intending it.

Every adult internet user in Europe now meets an interruption, framed as a permission request, somewhere between several and several dozen times a day. It stands between the person and a goal they already had. Dismissing it as fast as possible has no consequence they will ever perceive. And the fastest route through is very often the one granting the most permission.

The scale of what informed consent would actually require is worth stating plainly. Of the sites that listed their vendors, the median site listed 315 of them, with the upper quartile at 542. The mean total length of the vendor descriptions came to 7,985 words per site, which the authors calculate as roughly 32 minutes of reading at average speed, for one website, not counting unfolding collapsed sections or opening any vendor's own policy.

Nobody has 32 minutes per website. The behaviour that the law calls consent is the only behaviour the situation permits.

Described this way it is difficult not to see a conditioning schedule. High frequency, negligible perceived consequence, a reinforced escape response, running continuously since 2011 and intensifying after 2018. If you had set out to train a population to treat permission requests as friction rather than information, it is not obvious you could have designed a better protocol.

I should say clearly that the authors reach a version of this themselves. In their discussion they note that their participants' own reflections put the whole notice-and-consent model in question, not because of any specific design decision, but because an action is required before the user can reach their goal and because the notices appear too often when they are shown site by site. Their participants used the phrase consent fatigue unprompted. One said they clicked accept “just to make the window go away.”

The question nobody has answered

Here is what I want to know and cannot find.

Does the trained response transfer?

The moments where consent genuinely matters are structurally identical at the surface. A modal dialogue. A goal on the other side of it. A button that makes it disappear. Sharing medical records with a research programme. Opting a child's data out of a school platform. Permissions on a banking app. An opt-out from having your work used to train a model. Each is a decision with real and asymmetric consequences, and each arrives wearing the costume of a thing the person has been taught, thousands of times, to dismiss without reading.

The alarm literature would predict transfer, since habituation there generally generalises across alarms rather than staying attached to the one that produced it. That prediction does not appear to have been tested for consent. The privacy studies measure behaviour on consent notices. The alarm studies measure behaviour on alarms. I cannot find the study that measures whether banner exposure predicts click-through on a consequential permission, which is the number that would tell us whether we have a nuisance or an erosion of informed consent as a mechanism.

I am not certain the effect exists. People may discriminate better than the pessimistic reading suggests, and a consent form arriving in a hospital may be processed quite differently from a banner arriving on a recipe site. Context does a great deal of work. That is exactly why it seems worth measuring rather than assuming.

Why the framing changes the remedy

If this is a design problem, the fix is better banners. Clearer language, symmetric buttons, honest defaults, enforcement against dark patterns. Worth doing, and broadly the direction regulators have taken.

If it is a habituation problem, better banners cannot fix it, because the mechanism is frequency rather than quality. A well-designed banner met forty times a day teaches the same lesson as a badly designed one. The remedy has to reduce exposure rather than improve the instance, which points toward browser-level or device-level signals with legal force behind them, and away from the site-by-site model the current regime produced.

Nouwens and colleagues arrive at the same place from their own evidence, asking how users might reflect on tracking across the web rather than per site, and noting that browser settings would need to be legally binding rather than self-regulatory to work. They also note that adtech lobbying around the draft ePrivacy Regulation has been aimed at preventing exactly that.

The part that troubles me most

Warnings and consent requests work by transferring responsibility. The system tells you, and once you have been told, the decision is yours.

That transfer only holds if the telling informs. Twenty-five of the 40 participants said their recorded behaviour did not match their own ideal privacy settings, after being shown a visualisation of what they had actually clicked. A regime that produces reflexive dismissal at scale, while continuing to treat the resulting click as consent, has not protected anybody. It has built a very durable legal record that people agreed.

I do not think that was anyone's intention. Intentions are not the thing that gets measured.

References: Nouwens, M., Liccardi, I., Veale, M., Karger, D., & Kagal, L. (2020). Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their Influence. CHI ’20. Utz, C., Degeling, M., Fahl, S., Schaub, F., & Holz, T. (2019). (Un)informed Consent: Studying GDPR Consent Notices in the Field. CCS ’19. Sunshine, J., Egelman, S., Almuhimedi, H., Atri, N., & Cranor, L. (2009). Crying Wolf: An Empirical Study of SSL Warning Effectiveness. USENIX Security.

On the limits of the experiment I lean on most: n=40, US-resident, mean age 26.1, mostly university-educated and recruited partly through a computer science mailing list. The authors describe this as a best-case sample, on the grounds that these participants should understand consent interfaces better than the average user. The scrape was run from a Danish IP over three days in September 2019. Treat the percentage-point effects as indicative rather than settled, and note that a US sample has been exposed to a different regulatory history than a European one.

More writing|[email protected]