AI Policy Wiki
Dashboard

Three Theories of Consent Failure (Information / Capacity / Design)

medium confidence · updated 2026-06-06

Farahany's framework for the digital-consent problem: three distinct diagnoses (information failure / capacity failure / design failure) imply three distinct remedies (better disclosure / categorical protection / architectural regulation). Each theory underlies a different generation of US privacy law (GDPR-CCPA / COPPA / CAADCA). The legal-constitutional system is currently hostile to the design-failure remedy, which is why the architecture-theory laws keep getting blocked.

Three Theories of Consent Failure is a framework introduced by Nita Farahany in Class 8.3 of her Advanced Topics course for diagnosing the digital-consent problem. It holds that the failure of clickwrap consent — what Farahany calls the "biggest lie on the internet," the premise that clicking "I agree" constitutes meaningful agreement (Inside My Advanced Topics Class 8.1: The Biggest Lie on the Internet (Farahany, March 2026)) — admits three distinct diagnoses, each implying a different remedy. In Farahany's account US privacy law has tried all three, but only the first two are clearly constitutional.

The three theories

Information failure

The information theory diagnoses the problem as one of inadequate information: users would consent meaningfully if they understood the terms, and the obstacle is unreadable terms-of-service, buried disclosures, and information asymmetry between platforms and users. Its remedy is better disclosure — plain-language notices, just-in-time consent prompts, layered disclosures, and dashboards.

This theory is embedded in GDPR Article 13–14 (information requirements), the CCPA / CPRA notice provisions, and the California DELETE Act (a universal opt-out for data brokers, which makes exit cheaper without making entry meaningful). Constitutionally it is the easiest of the three, because compelled factual disclosure is generally permitted under the First Amendment.

Farahany argues it is also the least effective. Per Class 8.1, better disclosure produces marginal change at best; students who spent two hours reading platform terms still could not materially refuse. In this account the information theory is the easiest to enact and the least effective.

Capacity failure

The capacity theory diagnoses the problem as one of structurally inadequate capacity: some users — children and vulnerable adults — cannot give legally meaningful consent regardless of how good the information is. Its remedy is categorical protection: parental consent for minors, surrogate decision-makers for incapacitated adults, and categorical prohibitions on certain practices regardless of consent.

This theory is embedded in COPPA (1998, updated January 2025), covering children under 13; COPPA 2.0 (Senate-passed March 5, 2026), which extends coverage to teens 13–16; and California SB 243 (AI companions, October 2025), which imposes categorical restrictions for minors. Its constitutional profile is moderate: capacity-based laws have a long history and courts generally accept categorical protection of minors, but age-verification mechanisms run into First Amendment overhang under Free Speech Coalition v. Paxton (2025) for adults' access to verification-gated content.

Farahany identifies two structural problems with this theory in practice. The "actual knowledge" standard under COPPA before 2025 created an incentive to know less. And the age-verification trap — verification requires data collection from children, which COPPA forbids — is a structural conflict that the FTC's February 2026 prosecutorial-discretion policy patches but does not resolve.

Design failure

The design theory diagnoses the problem as one of architecture: even with perfect information and full capacity, the environment in which consent is exercised is engineered to produce particular outcomes. Defaults, friction asymmetry, urgency manufacture, salience manipulation, and choice architecture do the work below conscious awareness regardless of what users know. Its remedy is regulating the environment itself — mandating specific design properties such as highest-privacy defaults, no nudge techniques, click-to-cancel symmetry, and no engagement-optimization for minors.

This theory is embedded in the UK ICO Children's Code (2021, in effect), CAADCA (2022, mostly blocked), the FTC click-to-cancel rule (2024), and EU DSA Article 25 (dark patterns prohibition). Its constitutional profile is the hardest of the three: design-mandate laws face First Amendment compelled-speech challenges and vagueness challenges, per NetChoice II. Farahany identifies specificity as the path through — enumerated prohibited uses with clear definitional content survive, while standards-based prohibitions such as "materially detrimental to well-being" fail vagueness review. In her account the design theory is the most effective in principle and the hardest constitutionally; whether enumerated specificity can be drawn broadly enough to accomplish the underlying goal is the open question.

Why the theories do not reduce to each other

In Farahany's framing the three theories diagnose different mechanisms and imply different remedies, so they stack rather than substitute. A user who reads every word and refuses (information theory satisfied) can still be manipulated by friction asymmetry (design theory not satisfied). A child whose parents formally consent (capacity theory satisfied) can still be exploited by engagement-optimization (design theory not satisfied). An adult who fully understands the architecture (information and capacity satisfied) can still be exploited by it (design not satisfied). Robust consent regimes, on this account, need all three.

Relation to US constitutional law

Farahany describes the US system as structurally biased toward the information theory. The First Amendment is friendly to compelled factual disclosure, which is the information theory's remedy. Capacity-based laws require defining a vulnerable category, which raises equal-protection questions but is generally permitted. Design-based laws require regulating expression-adjacent conduct, which faces strict scrutiny.

The result, in this account, is that the US passes information-theory laws (GDPR-equivalent compliance regimes), occasionally passes capacity-theory laws such as COPPA, and rarely sustains design-theory laws such as CAADCA. The EU is described as more receptive to design-theory regulation, through the DSA and the Children's Code.

Relationships