Consent, and the ways it is manufactured
What consent is supposed to mean
Under most modern data protection law, consent has a definition and it is demanding. The GDPR requires it to be freely given, specific, informed and unambiguous, given by a clear affirmative action. India's Digital Personal Data Protection Act, 2023 uses similar language: consent must be free, specific, informed, unconditional and unambiguous, signalled by clear affirmative action, and limited to the data necessary for the stated purpose.
Read those criteria against the consent you actually gave to the last five services you used. The gap is the subject of this lesson.
Four requirements, four ways to fail.
Freely given fails when refusal costs you the service, or when the person asking has power over you. An employer asking staff to consent to monitoring is the standard example: regulators generally treat employee consent as unreliable for exactly this reason.
Specific fails when one checkbox covers analytics, advertising, model training and sharing with unnamed partners. Bundling is the most common defect in practice.
Informed fails when the material fact is three clicks away in a document written to be skimmed past.
Unambiguous fails on pre-ticked boxes, on "by continuing you agree", and on consent inferred from silence.
The patterns you will recognise
The design techniques have been catalogued by regulators, and naming them makes them visible.
Asymmetric buttons. "Accept all" is a large coloured button; "Reject" is grey text, or one level down behind "Manage preferences". Several European authorities have ruled this unlawful, requiring refusal to be as easy as acceptance.
Bundling. One switch for things that serve different purposes, so agreeing to the one you want drags along four you do not.
Default on. The single most effective technique ever measured in this area. Defaults determine outcomes for the large majority of users, and every organisation building a consent flow knows it.
Confirmshaming. "No thanks, I prefer worse results."
Repetition. Asking again on every visit until you accept to make it stop. Under most frameworks a refusal should be remembered.
Privacy zuckering — a term from the consumer-rights literature — meaning an interface that leads people to share more than they intended by making sharing the path of least resistance.
AI-specific versions
Three that are worth watching for.
Training on by default with a hidden switch. Common in consumer AI products. The switch exists, satisfying the letter of an opt-out regime, and lives where almost nobody goes.
Retroactive scope changes. A service updates its terms to permit training on content uploaded years earlier under different terms. Whether the original consent stretches that far is contested, and several regulators have opened cases on it. When a platform announces this, the opt-out window is usually short and the notification easy to miss.
Consent by the wrong person. You paste a colleague's message, a client's document, a patient's history. Whatever you agreed to, they did not. Most data protection law puts the obligation on whoever determines the purpose of the processing — which, at that moment, is you. This is the single most common consent failure in ordinary AI use and it never involves a consent screen at all.
What to do
As a user: find the training switch on any AI tool you use regularly, and set it deliberately rather than by default. Where a service offers a granular consent panel, use it once — it takes ninety seconds and it persists. And treat other people's information as requiring their consent, not yours, which usually means removing the identifying parts before it goes anywhere.
As someone building anything: the compliant pattern is not complicated. Refusal as easy as acceptance, separate switches for separate purposes, nothing pre-ticked, the material fact in the interface rather than in a linked document, and a record of what was consented to and when, because consent you cannot evidence is consent you do not have.
The honest limit
Consent is a weak instrument for this problem, and it is worth saying so. Nobody can meaningfully evaluate the downstream consequences of releasing a piece of text into a system they cannot inspect, and no amount of interface design fixes that. Regulators increasingly agree, which is why the newer rules lean on purpose limitation, data minimisation and outright prohibitions rather than on asking people to agree.
Which means the practical protection is not the consent screen. It is sending less.
The one thing to keep
Valid consent must be free, specific, informed and unambiguous, and the common interface patterns — bundling, defaults, asymmetric buttons — defeat all four; the consent that fails most often in AI use is the one you gave on someone else's behalf.
Before you move on
An employer rolls out an AI assistant and asks staff to tick a box consenting to their conversations being reviewed for quality. Why do regulators generally treat this as weak consent?
Pick the one you would defend. Nobody sees your answer.