The tools in this layer are genuinely dual-use: a default, a frame, a social-proof cue, a chosen messenger can help someone reach their own goal or quietly work against them, and it is the same tool either way. This is the screen that tells the two apart before you ship.
choice architecture cannot be neutral. Someone sets the default, the order of the options, the wording, the amount of friction. There is no version of the cafeteria where the food is arranged in no order at all. Thaler and Sunstein (2003) built their case for libertarian paternalism on exactly this: since you are shaping the choice whether you mean to or not, the ethical move is to shape it toward what benefits the chooser by their own lights, while keeping the freedom to opt out. The important consequence for applied work is that "we didn't nudge, we just showed the options" describes an illusion. Showing the options is a design, and a defensible one has to be defended, not hidden behind a claim of neutrality.
If the technique is unavoidable and identical across good and bad uses, the ethics has to live somewhere else. The most useful place to put it is Bovens' (2009) distinction between transparent and non-transparent nudges. A transparent nudge works even when the target knows about it: putting the fruit at eye level still works after you announce that you did it, a plain reminder still reminds, a visible default still holds. A non-transparent nudge works only because the target does not notice it, so disclosing it dissolves the effect. Many framing and social-proof tricks are non-transparent in exactly this way. Bovens' claim, and the single most practical idea in this article, is that transparent nudges survive ethical scrutiny far more comfortably than non-transparent ones. That is the "would it survive being seen?" test we have used throughout the layer, stated formally.
This is a genuine philosophical dispute, and it would be dishonest to present a settled answer, because there is not one. Three serious positions pull in different directions.
Thaler and Sunstein (2003) place nudging as the ethical middle: it steers, but it preserves the opt-out, so autonomy is respected. Hausman and Welch (2010) push back from one side. Their argument is that a nudge which works by exploiting a cognitive bias, rather than by informing the chooser or engaging their reasoning, fails to respect autonomy even when it improves the person's welfare, and is continuous with manipulation. On their view the relevant line runs between rational persuasion, which addresses you as a thinker, and everything that bypasses your thinking to get a result. Conly (2013) pushes from the opposite side entirely. Given how deep and pervasive our biases are, she argues, the gentle opt-out-preserving nudge is too weak and philosophically half-hearted; where the evidence is strong enough, outright coercive paternalism, bans and mandates, is sometimes the honest and justified response. So the field does not agree on a verdict. One camp says nudging is the responsible compromise, one says even nudging can cross the autonomy line, and one says nudging does not go nearly far enough. The applied reader's job is to hold that tension, not to pretend a favourite author dissolved it.
The tension stops being abstract the moment you look at dark patterns: the same choice-architecture apparatus deliberately turned against the user. Brignull named them in 2010, and researchers have since catalogued them at scale across thousands of live sites, from the roach motel (easy to get in, engineered to be hard to leave) to confirmshaming, forced continuity, and drip pricing (Mathur et al., 2019). Regulators now treat them as consumer-protection violations. The existence of dark patterns is the practical proof that the apparatus is not neutral: the identical technical moves that make a helpful default also make a predatory one. The difference is never visible in the code. It is visible only in whose welfare the design serves and whether it can stand being seen.
The screen this article recommends is a strong heuristic, not a formula, and it is worth being honest about where it strains. The transparency test has awkward edges: a few non-transparent nudges look plainly benign (the etched fly in the urinal that improves aim works only because you are not really thinking about it, yet harms no one), and there is mixed evidence on whether openly disclosing a nudge preserves or weakens it. "Whose welfare" is genuinely hard to establish, and architects reliably flatter themselves that a design serves the chooser when it serves the institution; welfare-alignment has to rest on evidence about the chooser's goals, not on the designer's good intentions. Autonomy and welfare really do trade off, and reasonable, well-informed people land in different places on that trade. And legitimacy is context-bound: a doctor, an employer, a state, and a brand each have very different standing to steer, and what counts as acceptable steering varies across cultures and political systems. The three tests structure the judgement. They do not remove the need to make one.
The hardest new problems are about personalised, algorithmic choice architecture. When the default is individually optimised by a model, and different people see different framings tuned to their own weak points, transparency and consent get much harder: a nudge you cannot even perceive is not really one you can opt out of. Where the regulatory line between a lawful nudge and an unlawful dark pattern falls, and whether it converges across jurisdictions, is still being drawn. And the empirical question underneath Bovens' test, whether telling people about a nudge leaves it working or dissolves it, does not yet have a clean general answer.
The payoff of this layer is a single screen you run before shipping any behaviour-change intervention, whichever of the earlier tools it uses. Three tests, in order, plus one tie-breaker.
1. The transparency test (the tie-breaker when in doubt). Would this still work if your audience saw exactly what you were doing and why (Bovens, 2009)? Write the disclosure sentence out: "We placed the healthy option first on purpose, to make it easier to choose." If the intervention survives that sentence, it is on the assistance side. If saying it out loud would kill the effect, you are relying on the audience not noticing, and that is the definition of the manipulation side. This single question resolves most real cases faster than any amount of philosophising.
2. The welfare-alignment test. Does the design serve the chooser's own goals, by their lights, on evidence, or does it serve only yours? A default that enrols people into a savings plan they would endorse passes. A default that enrols them into an add-on they would cancel if they noticed fails. The honest version of this test demands evidence about what the chooser actually wants, because the designer's belief that "this is good for them" is exactly the belief that every paternalist and every dark-pattern designer also holds.
3. The legitimacy test. Do you have the standing to steer here: consent, a mandate, a relationship that grants it? And is the steer reversible, with a genuine, low-friction opt-out? A physician nudging toward a screening has standing a random brand does not. A government setting an organ-donation default has a mandate a private actor lacks.
One more, from Hausman and Welch (2010): does it engage reasoning or bypass it? An intervention that informs, reminds, or makes a good option easier respects the chooser as a thinker. One that works purely by exploiting a bias the person would disown if they noticed does not. When two designs are equally effective, prefer the one that engages.
For companies. Dark patterns have moved from clever growth tactics to legal and reputational liability: the FTC and EU consumer and platform law now treat them as violations, and the empirical catalogues make them easy to name (Mathur et al., 2019). Make the screen a formal gate in design review, the way accessibility or security is a gate. Write the disclosure sentence for every default, every pre-checked box, every "only 2 left" cue, and every cancellation flow. If a growth experiment lifts a metric only because users cannot see what it is doing, you have not found growth, you have booked a liability. Document the choice architecture you shipped and the reason for it, because "we didn't realise it was a nudge" is not a defence when there is no neutral design.
For political parties and campaigns. Legitimacy is sharpest here, because the people you are steering are the same people who confer your authority to steer. Mobilisation that engages, real argument, real evidence of a real coalition, respects that relationship. Manufactured consensus does not: astroturfed movements, faked grassroots numbers, and bought social proof (the errors of L5-06, L5-07, and L5-18) fail all three tests at once, and they are increasingly unlawful as well as corrosive. The transparency test is brutal and clarifying in this domain: if your tactic depends on voters not knowing it is your tactic, it is manipulation of the electorate, whatever the cause it serves.
For government. The state is the default architect whether it wants the role or not, so the honest posture is to own it: every default is an editorial choice, so publish the rationale rather than presenting it as administrative neutrality. Align defaults to the welfare of the typical citizen under the best available information, keep the opt-out real, and treat the paternalism debate (Thaler and Sunstein versus Hausman and Welch versus Conly) as live policy rather than seminar-room decoration, because a democratic architect owes citizens the argument, not just the outcome. The deepest reason to be transparent is not only ethics but trust: a public that discovers it was steered without being told stops believing the next steer, even the good ones.
The through-line of the whole layer lands here. These tools are powerful because they work on real features of how people decide, and that same power is why they are dangerous in the wrong hands, including, occasionally, our own well-meaning ones. There is no value-neutral choice architecture, and refusing to design is itself a design. So the responsible move is not to disavow the toolkit. It is to run the screen, choose deliberately, and let "would it survive being seen?" be the question you cannot talk your way around.
Bovens, L. (2009) 'The ethics of nudge', in Grüne-Yanoff, T. and Hansson, S.O. (eds) Preference Change: Approaches from Philosophy, Economics and Psychology. Dordrecht: Springer. Available at: https://doi.org/10.1007/978-90-481-2593-7_10 (Accessed: 18 June 2026).
Conly, S. (2013) Against Autonomy: Justifying Coercive Paternalism. Cambridge: Cambridge University Press.
Hausman, D.M. and Welch, B. (2010) 'Debate: to nudge or not to nudge', Journal of Political Philosophy, 18(1), pp. 123-136. Available at: https://doi.org/10.1111/j.1467-9760.2009.00351.x (Accessed: 18 June 2026).
Mathur, A., Acar, G., Friedman, M.J., Lucherini, E., Mayer, J., Chetty, M. and Narayanan, A. (2019) 'Dark patterns at scale: findings from a crawl of 11K shopping websites', Proceedings of the ACM on Human-Computer Interaction, 3(CSCW), article 81. Available at: https://doi.org/10.1145/3359183 (Accessed: 18 June 2026).
Thaler, R.H. and Sunstein, C.R. (2003) 'Libertarian paternalism', American Economic Review, 93(2), pp. 175-179. Available at: https://doi.org/10.1257/000282803321947001 (Accessed: 18 June 2026).