Ryanair's Checkout Is What Your A/B Testing Stack Optimizes For

4 min read 1 source clear_take
├── "Ryanair's checkout is the predictable output of CRO with no opposing metric, not moral failure"
│  └── top10.dev editorial (top10.dev) → read below

The editorial argues that calling Ryanair 'evil' misses the point — every dark pattern in the catalog won an A/B test optimizing for revenue. With no counterbalancing metric (user trust, completion-without-regret, refund rate), a CRO toolchain will inevitably converge on exactly this checkout. There is no villain; the system produced what it was asked to produce.

├── "Ryanair's checkout is a deliberate, growing catalog of deceptive design patterns"
│  └── Conor O'Sullivan (danosull) (blog.osull.com) → read

O'Sullivan's third annual audit documents fourteen distinct dark patterns in 2026 — up from eleven in 2024 and twelve in 2025 — with screenshot-by-screenshot evidence including the 'Do not insure me' option buried alphabetically between Djibouti and Dominica, and cancel buttons distinguished from primary CTAs by a 1px border. He treats this as intentional, persistent deception that the catalog keeps growing rather than shrinking.

├── "The EU's Digital Services Act has failed to deter dark patterns in practice"
│  └── top10.dev editorial (top10.dev) → read below

The editorial notes that Article 25 of the DSA explicitly bans 'deceptive design patterns' and has been in full force since February 2024, yet two and a half years later Ryanair has not been fined and the pattern count has increased from eleven to fourteen. The implicit argument: regulation without enforcement is indistinguishable from no regulation, and CRO-driven product teams have correctly priced the risk as zero.

├── "This is an industry-wide budget-airline problem, not a Ryanair-specific one"
│  └── @HN thread consensus (Hacker News) → view

The bulk of the 174-comment thread consists of users sharing parallel checkout horror stories from Wizz Air, Spirit, easyJet, and even legacy carriers like Lufthansa. The implicit position is that singling out Ryanair misses a structural pattern — every airline operating on thin margins has converged on the same CRO-driven deceptive checkout because the economics demand it.

└── "Insider confirmation: every dark pattern shipped because an A/B test said it would"
  └── @Ex-Ryanair contractors (HN subthread) (Hacker News) → view

A smaller subthread of self-identified former Ryanair contractors confirms that the patterns are not accidents of bad UX but the direct output of a relentless A/B testing program optimizing for revenue per session. Their testimony grounds the editorial's structural argument in firsthand process knowledge — there was no malicious designer, just a metric and a test harness.

What happened

Conor O'Sullivan published the 2026 refresh of his Ryanair dark-UX audit on June 12 (blog.osull.com), and it hit 233 points on Hacker News inside a day. The post is a clinical, screenshot-by-screenshot walk through ryanair.com's checkout: a preselected €11 insurance add-on with a 'Do not insure me' option buried in an alphabetized country dropdown between 'Djibouti' and 'Dominica'; a priority-boarding interstitial that requires two clicks to decline; a seat-selection page that visually distinguishes 'no thanks' from a cancel button only by a 1px border; a fare-class comparison that puts the cheapest option in the smallest font.

This is the third year O'Sullivan has run the audit. The 2024 version listed eleven patterns. The 2025 version listed twelve. The 2026 version lists fourteen — every pattern from prior years survived, and two new ones appeared. The EU's Digital Services Act, which came into full force in February 2024 and explicitly bans 'deceptive design patterns' (Article 25), has been live for two and a half years. Ryanair has not been fined under it. The catalog grows.

The HN thread is mostly people sharing their own checkout horror stories — Wizz Air, Spirit, easyJet, even Lufthansa — and a smaller, more interesting subthread of ex-Ryanair contractors confirming the obvious: every one of these patterns shipped because an A/B test said it would.

Why it matters

The lazy reading of O'Sullivan's audit is 'Ryanair is evil.' The useful reading is that Ryanair's checkout is not a moral failure. It is the logical, predictable output of a conversion-rate-optimization toolchain pointed at revenue with no opposing metric. Every dark pattern in the catalog won an A/B test. Someone, somewhere, ran a 50/50 split on whether 'Do not insure me' should be alphabetized or pinned to the top, and the alphabetized variant generated more insurance attachments per session. That's the entire causal story. There is no villain in a black hood. There is a dashboard, a p-value, and a roadmap ticket that closed as 'Done.'

This is the part that should worry engineers who build CRO infrastructure for a living. Optimizely, VWO, Statsig, GrowthBook, in-house bandits at every B2C company over $50M ARR — none of them ship with a native concept of user harm. They measure conversion. They measure revenue per session. They measure funnel completion. They do not measure regret, refund-request rates six months later, NPS decay among customers who attached the insurance and later realized they did not want it, or the slow drip of brand erosion that shows up as 'I'll fly anyone but Ryanair if the price difference is under €30.' Those signals exist in the data — they just exist outside the window the experimentation platform looks at.

The DSA was supposed to be the opposing metric. It is not, because regulators have no telemetry. They can audit a screenshot. They cannot audit a multi-armed bandit running 47 concurrent variants of the seat-selection page, none of which exists for more than 72 hours. O'Sullivan's audit is a snapshot. Ryanair's actual checkout is a probability distribution over hundreds of variants, half of which would individually clear a DSA review and only become deceptive in aggregate. The regulator is bringing a still camera to a video shoot.

The HN comments include a former growth engineer at a competing low-cost carrier who put it bluntly: 'We A/B tested the insurance opt-out wording every two weeks for three years. The version that performed best was always the most confusing one. We knew. We shipped it anyway because the platform had no way to flag it.' This is the quiet part. The dark patterns are not hidden from the engineering team. They are produced by the engineering team's tooling, on the engineering team's roadmap, and shipped under tickets titled 'Insurance attach optimization v47.'

What this means for your stack

If you run experimentation at scale, three things are worth doing this quarter, regardless of whether you ship consumer flows or B2B. First: add at least one guardrail metric to every checkout-funnel experiment that measures something other than the conversion you are optimizing for — refund rate at 30/60/90 days, support ticket volume tagged with the experiment ID, or NPS among users who completed the funnel. Most platforms support guardrails. Almost no one configures them for the right thing.

Second: instrument 'second-thought' interactions. The number of users who click 'Do not insure me,' then go back, then click again is a measurable signal of confusion. So is hover-without-click time on opt-out elements. Most CRO platforms can capture this; almost no one runs the report. If your alphabetized-country dropdown is generating 4× the hover time of the prior variant, that is a dark-pattern detector you already have, you just have not turned it on.

Third, and harder: write down, in your experimentation policy, what categories of variants you will not ship even if they win. The Ryanair school of thought says the market disciplines you — users will leave. The data says the market does not discipline you fast enough to show up in a quarterly OKR review. Pre-commitment is the only mechanism that survives the pressure of a winning variant, because once the test reaches significance, the argument for shipping it becomes overwhelming inside any revenue-aligned org.

Looking ahead

The DSA will eventually grow teeth, probably via a high-profile Ryanair or Wizz Air fine in the next 18 months — Brussels has been telegraphing it. But the structural fix is not regulatory; it is internal. The next generation of experimentation platforms will either ship guardrails for user harm as a first-class concept, or someone will build the open-source one that does, and CRO teams will start adopting it the way they adopted feature flags a decade ago. Until then, O'Sullivan's audit will keep getting longer every June, and the answer to 'why does Ryanair's checkout look like that' will remain the same: because your tools, pointed at their problem, would produce the same result.

Hacker News 233 pts 174 comments

Ryanair dark UX patterns summer 2026 refresher

→ read on Hacker News
thimabi · Hacker News

That “Don’t Insure Me” option hidden in the middle of a country list is pure evil. I’m used to seeing dark patterns everywhere but that’s a first for me.From where I stand, it’s not fair to charge the hell out of people who fall for these tricks while giving steep discounts to the ones who don’t. Ma

bojangleslover · Hacker News

About 1/3 of their revenue is ancillary (the dark patterns are there to cause ancillary revenue).I just flew from Bournemouth to Alicante on Ryanair for £50. A similar flight in the US (DC to Miami, for example) would be easily 5x that, possibly 7-8x. The dark patterns took me about 10min to cl

sverhagen · Hacker News

Oh, don't get me started on Ryanair, but alas.You go through what seems the entire check-in process, you get what seems like a summary at the end, with a link to a UK government site where you need to go next to get a travel authorization, I spend an hour doing that, finally finish that, I show

leni536 · Hacker News

And a last, most sneaky one: At checkout if you pay with credit/debit card don't use Ryanair's "guaranteed exhange rate" if the cost of the flight is not in your card's currency (ticket by default, at least two clicks to find and untick it). That's ~6% gap from mid

shark1 · Hacker News

They managed to create a business model relying in some sort of "slot machine" where customers buy the ticket to discover later they are "stupid" not noticing some rule hidden in the meticulously engineered dark patterns and, to board now and do not miss the planned trip, they wi

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.