NOBODY ASKED FOR THE COOKIE BANNER

The mistake we can’t afford to repeat with AI.

No law has ever required a cookie banner. The rules asked for informed consent and left the interface to us — and what our profession built, collectively, was the most disliked pattern on the web, the cookie banner.

learn how the  protection of personal data has been gamed 

Every attempt to replace the banner, failed

It wasn’t a failure of imagination. Five serious alternatives were built. Each one moved consent out of the interface and into the browser, from every site, every visit, to once.
Which is exactly what the banner is trying to prevent.

P3P

1997–2018

A machine-readable privacy standard your browser would act on for you. Browsers barely implemented it — then Google and Facebook sent invalid P3P headers to defeat what enforcement existed.

P3P is dead
Tracking protection working group

Do Not Track

2009–2019

One browser setting, near-universal adoption in eighteen months. Killed by being turned on by default — the ad industry argued that made it not a “real” choice. 

The ePrivacy Regulation

2017–2025

A proper law, meant to harmonise consent across the EU with browser-level settings. Deadlocked in Council for years on exactly those settings, then withdrawn.

EU abandons ePrivacy, AI liability reforms as bloc shifts focus to AI competitiveness
The Market Court rules in the IAB Europe case

The IAB Case

2018–present

The ad industry’s own consent system — the machinery under most cookie banners. Found to breach the GDPR by the Belgian regulator in 2022; still tangled in litigation eight years on, with a partial industry win on appeal in 2026.

Article 88b

2025–2026

The Commission’s proposal for a browser-level signal, the same idea as California’s working Global Privacy Control. Removed from the Council’s position on 18 June 2026 after industry lobbying.

 

EU Member States (and Google) suddenly want to keep cookie banners!

Six human rights sections.
Six case studies of Ai powered human right violations. 

The EU Charter is organised into six titles. For each one, here is a documented case of AI causing the harm, and the AI Act or other provisions meant to prevent it. Some are already into effect others are to come. 

 

DIGNITY

In 2023, more than twenty girls in a Spanish town, some as young as eleven, received AI-generated nude images of themselves, made from their own social-media photos.
The perpetrators were classmates aged 13–15. A free app removed the barrier entirely.

EU AI Act: new Article 5 prohibition on AI systems that generate non-consensual intimate imagery of an identifiable person, and CSAM.

FREEDOMS

Automated moderation flags women’s health content as pornography. Women pleasure product are not censored only if they are reframed for man. A study found all 60 women’s-health firms had ads rejected by Meta; a UK survey found nine in ten accounts censored in a year.

DIGITAL SERVICE ACT: content moderation sits mainly under the Digital Services Act, not the AI Act — and algorithmic bias against lawful content is poorly addressed even there. This is the case the law barely reaches.

EQUALITY

Amazon built an AI to score CVs. Trained on a decade of hiring history, which skewed mostly male hires, it taught itself to prefer men, downgrading any CV with the word “women’s.” Amazon Engineers tried to fix it, but couldn’t stop the AI finding ways to keep doing this, so it got scrapped.

EU AI Act: hiring is high-risk (Annex III). Article 10 requires examining training data for bias; Article 14 requires meaningful human oversight.

SOLIDARITY

Uber drivers, were flagged for fraud by an algorithm and fired. In 2023 an Amsterdam court ruled they were dismissed “based solely on automated processing” and called the human review Uber claimed “nothing more than a symbolic act.

EU AI Act: AI in worker management is high-risk; Article 14 requires human oversight that is meaningful, not symbolic. (The drivers actually won under GDPR Article 22.)

CITIZENS' RIGHTS

A Dutch tax-authority algorithm flagged childcare claims as fraud, treating non-Dutch name as a risk factor. Around 26,000 families were wrongly accused, with no explanation or appeal; more than a thousand children were taken into care.

EU AI Act: social scoring is banned now (Article 5). But this kind of fraud-risk system is high-risk — and those protections, including a right to an explanation, are delayed to 2027.

JUSTICE

In 2020, Detroit police arrested Robert Williams at home in front of his daughters for a theft he didn’t commit, a facial-recognition false match. Holding the photo to his face, he said “this isn’t me.” The officer replied: “the computer says it’s you.”

EU AI Act: Article 5 bans real-time remote biometric identification in public spaces (narrowly). But after-the-fact matching, which caught Williams, is treated as high-risk, and that part of the legislation is delayed.

What next?

If this information resonates with you and you would like to get involved, here are four layers, we suggest you explore: The System, The Process, The Community and The Space.

THE SYSTEM

business model and human rights

Learn about this awesome non-profit brings these two together beautifully

THE PROCESS

regenerative design

We are on a journey to not only train our members but also make training widely available on Regenerative Design practices. UX for Change is hosting a Harms Mapping Workshop on October 15 in Shoreditch you are all welcome to come along.

THE COMMUNITY

THE UNLEARNING ROOM

Our founder, Sandra Gonzalez, has been creating communities for over 12 years and her latest concept is for leaders who want to listen to her stories when things didn’t go as planned, with the hope of igniting conversations that help us unlearn.

THE SPACE

THE RESPONSIBLE FOR CHANGE FELLOWSHIP

Safe space to give unlearning a try with
a social impact regenerative project while learning Regenerative Leadership