Consumer Neuroscience Foundations
12 canonical consumer-neuroscience primitives for product, content, interface, and retention design. Each primitive is domain-agnostic and ethically bounded. Primitives 1–8 cover engagement-time neural responses (salience, arousal, bonding, narrative, regulatory orientation, social mirroring, aesthetics, interoception). Primitives 9–12 cover temporal and predictive mechanisms (memory consolidation, reward anticipation, embodied cognition, predictive processing). Primitive #10 (reward anticipation, Berridge "wanting" vs "liking") is intentionally distinct from foundations-behavioral-economics primitive #13 (reinforcement schedules / dopamine prediction-error): that skill covers schedule-of-reinforcement design; this skill covers anticipatory dopamine as a separate design lever — countdown UX, drop reveals, daily-card open, pre-purchase excitement. Primitive #12 (predictive processing & active inference) is the unifying primitive that grounds attention (#1), interoception (#8), and narrative (#4) under one prediction-error-minimization frame: the brain continuously generates predictions; violations of priors incur a prediction-error cost that must be "earned" by the design.
Ethical obligation: every primitive in this skill operates on pre-conscious or sub-deliberative neural systems. The manipulation risk is higher than for behavioral-economics nudges, because users cannot easily introspect on the mechanism. Read the Misuse Boundary subsection in each playbook before applying any technique. The test from Thaler and Sunstein: "Would you be embarrassed if the technique appeared on the front page of a newspaper?" If yes, it is exploitation, not design. The DMCC Act 2024, in force from 6 April 2025, makes online choice architecture and dark patterns directly actionable by the CMA with fines up to 10% of global annual turnover.
When to Apply
Apply consumer-neuroscience when:
- Attention/salience design — first-7-second hook, visual hierarchy, modal vs inline
- Anxiety-driven engagement loops (cosmic, dating, status apps) — needs DMCC ethical audit
- Parasocial / narrative-led conversion (creator content, branded characters)
- Daily-cadence retention with timing-sensitive triggers (consolidation windows, wake-time)
- Trust repair, reciprocity, or oxytocin-bond design in social/community products
Skip and use simpler alternatives when:
- Pure pricing/defaults/anchoring question — foundations-behavioral-economics is sufficient and cheaper
- Audience has no measured anxiety/arousal/attention baseline — neuro framing is decoration, not insight
- B2B SaaS with rational-buyer mode dominant — emotional primitives mostly noise; use behavioral-econ + decision-theory
- The proposed mechanism manipulates without genuine user benefit — fails DMCC Act 2024 ethical gate; do not ship
- Required signals (eye-tracking, GSR, fMRI) aren't available AND no biomarker proxy exists — claim is unfalsifiable
- Causal lift question — use foundations-causal-inference to measure; neuro primitives suggest mechanisms, not effect sizes
Contents
Quick Reference
| # |
Primitive |
Core Property |
When to Use |
| 1 |
Attention & Salience |
Bottom-up capture via contrast/novelty; top-down via relevance |
Any surface where visibility or engagement priority matters |
| 2 |
Arousal Physiology |
Yerkes-Dodson inverted-U; autonomic cost; GSR as engagement signal |
Engagement loop design; onboarding intensity calibration |
| 3 |
Social Bonding |
Oxytocin-driven affiliative response; trust formation |
Trust mechanics, warmth signals, share/referral features |
| 4 |
Narrative Transportation |
DMN + vmPFC + ventral striatum absorb self-referential story |
Personalized content, horoscopes, product storytelling |
| 5 |
Approach-Avoidance & BIS/BAS |
BAS drives promotion seeking; BIS drives prevention vigilance |
Copy tone for mixed-orientation audiences; funnel segmentation |
| 6 |
Mirror Systems & Emotional Contagion |
FFA + MNS simulate observed emotional states |
Testimonial design, UGC placement, avatar/face elements |
| 7 |
Neuroaesthetics |
Visual beauty response via peak-shift, contrast, symmetry |
Visual hierarchy, brand asset design, landing page aesthetics |
| 8 |
Interoception & Somatic Markers |
Insular cortex body-state signals bias decisions before deliberation |
Wellness/anxiety product design; gut-feel purchase triggers |
| 9 |
Memory Consolidation |
Hebbian potentiation + sleep replay strengthen traces |
Notification timing, streak design, recall-based content |
| 10 |
Reward Anticipation |
VTA dopamine onset ~200ms before reward; wanting distinct from liking |
Countdown UX, drop reveals, daily unlock mechanics |
| 11 |
Embodied Cognition |
Sensorimotor grounding of abstract concepts; body-state metaphors |
Copy language, spatial UI metaphors, product texture cues |
| 12 |
Predictive Processing & Active Inference |
Brain minimizes free energy by updating predictions; violations cost attentional budget |
Feature reveals, onboarding surprises, brand consistency |
Primitive Index
Each primitive has a full playbook: Definition / When to use / Misuse boundary / Inputs / Outputs / Failure modes / Worked example / Sources.
| # |
Primitive |
Failure Mode It Addresses |
| 1 |
Attention & Salience |
Designs that assume attention is granted, not earned |
| 2 |
Arousal Physiology |
Engagement loops that ignore stress cost on the user |
| 3 |
Social Bonding |
Trust/share mechanics built without warmth signals |
| 4 |
Narrative Transportation |
"Personal-feeling" content reduced to facts and lists |
| 5 |
Approach-Avoidance & BIS/BAS |
Single-tone funnels for mixed promotion/prevention users |
| 6 |
Mirror Systems & Emotional Contagion |
Testimonials and UGC ignored as conversion lever |
| 7 |
Neuroaesthetics |
Aesthetic choices justified by taste, not neural response |
| 8 |
Interoception & Somatic Markers |
"Gut-feel" decisions ignored as design surface |
| 9 |
Memory Consolidation |
Reminders and streaks that fight consolidation timing |
| 10 |
Reward Anticipation |
Anticipation phase ignored in favor of payoff |
| 11 |
Embodied Cognition |
Copy and UI ignoring body-state metaphors |
| 12 |
Predictive Processing & Active Inference |
Surprises that violate user priors without earning the prediction-error budget |
Formal Supporting Theory
| Theory Area |
Use When |
Applied Primitives It Grounds |
| Attention theory (Feature Integration Theory, salience maps) |
Need to predict what captures or loses user attention |
#1 |
| Psychophysiology & autonomic regulation (Yerkes-Dodson, allostatic load) |
Need to calibrate engagement intensity without imposing stress cost |
#2 |
| Social neuroendocrinology (oxytocin system, affiliative circuits) |
Need to understand trust formation or prosocial behavior in product |
#3 |
| Narrative cognition & Default Mode Network (DMN, vmPFC, ventral striatum) |
Need to design self-referential or immersive content |
#4 |
| Regulatory focus & BIS/BAS (Higgins, Carver & White) |
Need to distinguish promotion-oriented from prevention-oriented users |
#5 |
| Mirror neuron system & emotional contagion (MNS, FFA) |
Need to understand social simulation in testimonials or face-based UI |
#6 |
| Neuroaesthetics (peak-shift, symmetry, contour, reward from visual beauty) |
Need to explain or predict aesthetic preference and visual reward |
#7 |
| Interoception & somatic marker theory (Craig insular cortex, Damasio vmPFC) |
Need to account for body-state signals in purchase or risk decisions |
#8 |
| Systems memory consolidation & sleep-dependent replay (Hebbian, hippocampal-neocortical transfer) |
Need to design for durable trace formation — not just exposure |
#9 |
| Incentive salience & wanting vs liking (Berridge mesolimbic dopamine, VTA) |
Need to distinguish anticipatory drive from hedonic reward |
#10 |
| Embodied / grounded cognition (Lakoff & Johnson, Barsalou) |
Need to align copy or UI metaphors with sensorimotor experience |
#11 |
| Predictive processing & active inference (Friston free energy, Clark, Constant) |
Need to manage prediction-error budget: when to surprise, when to confirm |
#12 |
Use references/formal-theory-map.md when the task needs source assumptions, ethical boundaries, or a distinction between observed neural response and normative welfare.
Ethical Bounds
The Harm Test
A neural design technique is legitimate if it:
- Steers users toward experiences or decisions they would endorse on reflection.
- Can be easily overridden or opted out of.
- Does not exploit pre-conscious neural mechanisms to act against the user's interests.
The same lever — arousal, oxytocin warmth, reward anticipation — can be legitimate or manipulative depending on whether the underlying offer genuinely serves the user.
Manipulation vs Legitimate Design
| Dimension |
Legitimate |
Manipulation |
| Transparency |
Mechanism can be disclosed without destroying the effect |
Requires concealment of mechanism to work |
| User-benefit alignment |
Steers toward user's own stated goals or wellbeing |
Overrides user goals in favor of operator revenue |
| Reversibility |
Easy to disengage, unsubscribe, or undo |
Designed to make exit costly or invisible |
| Signal honesty |
Arousal, urgency, or warmth reflects real content |
Signal is manufactured (fake countdown, artificial scarcity, paid "warmth") |
| Regulatory posture |
Survives CMA/ASA/ICO scrutiny |
Attracts DMCC Act enforcement action |
UK Regulatory Context (August 2026)
DMCC Act 2024 entered into force 6 April 2025, revoking the CPRs 2008 outright (s.251(1), commenced by SI 2025/272) and succeeding them with ss. 226 (misleading actions), 227 (misleading omissions), and 228 (aggressive practices), plus the Sch. 20 list of banned practices. The successor provisions are redrafted, not a restatement — old CPRs regulation numbers do not map across cleanly, so cite DMCC sections. The CMA has direct civil-enforcement power and can fine up to 10% of global annual turnover without requiring a court order.
Enforcement is now live, not prospective — the first two infringement decisions both concerned online choice architecture rather than advertising content:
- 18 November 2025: CMA opened its first DMCC enforcement actions against 8 firms (drip pricing, default opt-ins, pressure selling) and issued approximately 100 advisory letters across 14 sectors.
- 18 June 2026: second infringement decision — Marks Electrical fined £720,000 (£1.2m reduced 40% for early settlement) and ordered to refund ~£600,000 to ~40,000 customers, for pre-selected extra charges (customers auto-opted into paid recycling and unwrapping services). Conduct covered April–November 2025. This is the clearest signal of the enforcement floor: a mid-size retailer, a single default-opt-in pattern, a seven-figure headline penalty plus consumer redress.
April 2025: CMA published procedural guidance on DMCC enforcement. December 2025: CMA published price transparency guidance under DMCC.
Online Choice Architecture (dark patterns) now directly actionable under DMCC, including:
- Confirm-shaming (manipulative framing on decline options)
- Pre-ticked defaults that benefit the operator at user expense
- Drip pricing (incremental price reveal late in purchase flow)
- False urgency ("Only 2 left!" when stock is unconstrained)
- Forced continuity (auto-renew without prominent disclosure)
Secondary regulatory anchors:
- ASA CAP Code: misleading advertising, fabricated testimonials, manufactured social proof
- DMCC Act 2024 s.228 (aggressive practices — replaced CPRs 2008 Reg. 7, revoked 6 April 2025)
- UK GDPR: biometric and neuro-physiological signal capture (GSR, HRV, eye-tracking, fNIRS) constitutes special-category data in many use cases; requires explicit consent and lawful basis (Article 9)
EU Regulatory Context (August 2026)
For products serving EU users, the EU AI Act is the parallel anchor to DMCC and applies on top of GDPR.
- Article 5 prohibitions in force from 2 February 2025: AI systems that deploy "subliminal techniques beyond a person's consciousness" or "purposefully manipulative or deceptive techniques" causing significant harm are prohibited outright. AI systems that exploit vulnerabilities (age, disability, socio-economic situation) are also prohibited. This directly captures the manipulation column of the table above when AI is in the loop. Unaffected by the 2026 delay below — the prohibitions bind now.
- Emotion-recognition prohibition (workplace and education): AI inference of emotions from facial expression, voice, GSR, HRV, or any biometric stream is prohibited in workplace and education contexts (Article 5). Commercial deployment outside those contexts is not prohibited but is regulated.
- High-risk classification DELAYED to 2 December 2027 (was 2 August 2026): the AI Digital Omnibus was published in the Official Journal 24 July 2026 and entered into force 27 July 2026, deferring standalone Annex III high-risk obligations — which include commercial emotion-recognition and biometric-categorisation systems — by 16 months. Annex I (AI embedded in products under EU product-safety law) moves to 2 August 2028. Providers and deployers must still meet data-governance, transparency, human-oversight, robustness, accuracy, and post-market monitoring requirements, but the compliance deadline is December 2027. Treat this as schedule relief, not repeal: systems in design now will ship into the regime.
- Article 50 transparency obligations remain on the original 2 August 2026 schedule — they were not delayed. Users exposed to emotion-recognition or biometric-categorisation systems must be explicitly informed, now. A four-month grace period (to 2 December 2026) applies only to the Article 50(2) watermarking duty for systems already on the market. This is the live EU obligation for affect-inference products as of August 2026.
- GDPR continues to apply: lawful basis (typically Article 9 explicit consent for biometric data) is a precondition; the AI Act adds requirements on top. GDPR is unaffected by the Omnibus delay and is the binding constraint in the interim.
For UK-only products, DMCC + UK GDPR are sufficient. For EU users or shared-stack products, both regimes apply and the stricter rule binds.
US Regulatory Context (August 2026)
Four states have enacted neural-data-specific privacy laws (Colorado, California, Montana, Connecticut), and nine further bills were introduced across six states in the first six weeks of 2026 alone (Alabama, California, Illinois, New York, Vermont, Virginia). Treat this as a live patchwork, not a settled regime.
Scope caution — these laws are narrower than "any biometric signal." Most define neural data as signals from the nervous system measured directly, and several explicitly exclude the downstream physiological signals this skill most often uses. Montana SB 163 carves out "nonneural information … the downstream physical effects of neural activity, including but not limited to pupil dilation, motor activity, and breathing rate" — which excludes GSR and eye-tracking. California SB 1223 requires neural data be "not inferred from nonneural information," likely excluding facial coding and voice affect. Colorado's definition reaches only data used for identification purposes, excluding most consumer applications. Connecticut has no explicit carve-out, leaving GSR and eye-tracking ambiguous there. Practical consequence: EEG and fNIRS are squarely in scope; GSR, HRV, eye-tracking, facial coding, and voice affect are mostly out of neural-data statutes — but remain covered by general state biometric/sensitive-data law, BIPA-style statutes, and GDPR for EU users. Do not use a neural-data-law exemption as a reason to skip consent; check the general privacy regime instead.
- California SB 1223 (effective 1 January 2025): amends CCPA to classify "neural data" (signals from central or peripheral nervous system, not inferred from nonneural information) as sensitive personal information. Opt-in consent required; right to delete and restrict sharing apply. Primary source
- Colorado HB 24-1058 (effective 7 August 2024): amends Colorado Privacy Act to include "neural data" within "biological data" as sensitive data. First US law to define and protect neural data. Scope limited to data used or intended for identification. Primary source
- Montana SB 163 (effective 1 October 2025): adds neurotechnology data to Montana's Genetic Information Privacy Act. The most extensive of the four: detailed express-consent requirements for collection, marketing and research use, disclosure, transfer, and sale — often requiring separate informed consent per purpose and per third party. Explicitly excludes nonneural downstream signals. If a product captures true neural data from US users, Montana sets the strictest operative bar.
- Connecticut SB 1295 (signed 24 June 2025; effective 1 July 2026): amends CTDPA to add neural data as a sensitive data category; processing requires express consumer consent; selling sensitive data without consent prohibited. Primary source
- Vermont H.814 / Act 101 (signed 18 May 2026; effective 1 July 2026): correction — do not overstate this law. As enacted, H.814 was substantially narrowed in the Senate: it recognises a largely declaratory statement of "neurological rights" (mental privacy, freedom of thought, non-discrimination in neurotechnology), but the consent requirement and private right of action were stripped before passage. Enforcement rests exclusively with the Vermont Attorney General; there is no consent gate for businesses. Its main forward hook is a commissioned study reporting to the next legislative session. Vermont's binding neural-data framework is Vermont S.71 (neural data as sensitive data), effective 1 January 2028 — track that bill, not H.814, for compliance planning. Treat H.814 as a signal of legislative direction, not a live consent gate. Primary source
- UNESCO Recommendation on the Ethics of Neurotechnology (adopted 12 November 2025): first global non-binding framework covering neural data across commercial uses. Non-binding but widely cited in board-level compliance discussions and DPA engagement. Primary source
- US MIND Act 2025 (proposed): would direct FTC to study neuromarketing as a named use case; not yet law but signals federal regulatory attention. Document FTC-readiness posture if product involves neuromarketing explicitly.
Practical implication: any product capturing genuine neural signal (EEG, fNIRS) from US users must run a per-state consent analysis — California CCPA sensitive PI from 1 January 2025, Montana's per-purpose express consent from 1 October 2025, Colorado and Connecticut in parallel. For GSR, HRV, eye-tracking, facial coding, and voice affect, the neural-data statutes mostly do not bite; the governing constraints are general sensitive-data and biometric law plus GDPR Article 9 for EU users. See references/ethics-operational-checklist.md US Neural Data Laws section.
Vulnerable-User Note
CMA enforcement priorities specifically name "aggressive sales practices which take advantage of vulnerability." Wellness, anxiety-relief, and astrology/spiritual audiences are explicitly in scope as vulnerability-risk contexts. EU AI Act Article 5 reinforces this with an outright prohibition on AI systems that exploit vulnerabilities of specific groups (age, disability, socio-economic situation) to materially distort behaviour. Any application in these categories must apply the stricter column of the manipulation table — not the middle ground. Manufactured urgency, oxytocin-proxy warmth without genuine care mechanics, and reward-anticipation loops targeting financially or emotionally vulnerable users are highest-risk under both regimes.
Misuse Boundaries
| Misuse |
Why It Is Wrong |
Required Correction |
| Manufacturing arousal without informational value (#2) |
GSR spike earned by stimulus intensity, not content quality — violates prediction-error budget and harms user attention economy. Note: GSR/HRV-as-arousal-proxy claims require qualification — BAAS (Nature Communications 2025, 24-study validation) confirms autonomic signals are statistically distinct from subjective affective arousal; interpret autonomic signals as physiological activation, not as direct proxies for the subjective arousal consumers experience |
Earn arousal through genuine novelty or high personal relevance; measure dwell quality, not just engagement duration; acknowledge GSR/HRV–affective-arousal dissociation in any study claiming arousal measurement |
| Exploiting oxytocin proxies without genuine warmth (#3) |
Artificial warmth signals (faked testimonials, performed care language) produce short-term affiliation that collapses on discovery, destroying trust. Claiming universal oxytocin-driven trust from warmth signals overstates the evidence; the Declerck 2020 registered replication (Nature Human Behaviour, >95% power) found no main effect of oxytocin on trust under standard conditions — design for genuine warmth and affiliative behavior, not a neuroendocrine mechanism the replication literature does not support uniformly |
Use only real social proof and care signals; oxytocin half-life ~3–5 min means trust must be re-earned each session; do not claim design patterns universally increase trust via oxytocin mechanism |
| Narrative transport without consent (#4) |
DMN immersion suppresses critical evaluation — delivering false information during transportation is a manipulation under DMCC |
Narrative content must be accurate; emotional immersion does not override disclosure obligations |
| Biometric/neuro-signal capture without lawful basis (#2, #8) |
GSR, HRV, facial EMG, eye-tracking, and EEG are special-category biometric data under UK GDPR in research or product contexts; capture without explicit consent is unlawful |
Obtain explicit Article 9 consent; document lawful basis before any physiological measurement |
| Single-tone funnel for mixed BIS/BAS audience (#5) |
Prevention-oriented users subjected to unrelenting promotion framing experience regulatory mismatch; trust drops |
Segment or test copy by regulatory focus; offer prevention-framed and promotion-framed variants |
| Fabricating social contagion signals (#6) |
Showing false emotional reactions (fake ratings, manufactured "people are loving this") triggers mirror system without real social proof |
All emotional-contagion signals must reflect real user sentiment from verified cohort data |
| Neuroaesthetic dopamine trap — aesthetic beauty without functional value (#7, #10) |
Highly polished aesthetics trigger visual reward and reward anticipation; if the underlying product fails to deliver, disappointment amplifies by contrast (prediction error) |
Aesthetic quality must be matched by functional delivery; do not use visual reward to paper over a weak product |
| False-prediction surprise (#12) |
Violating established user priors without earning the prediction-error budget creates confusion, anxiety, and trust loss |
Predict before you surprise; reserve prediction-error violations for high-value reveals backed by strong prior evidence of user benefit |
| Interoceptive exploitation in vulnerable users (#8) |
Triggering somatic anxiety signals ("your body is telling you something is wrong") in wellness/anxiety contexts to manufacture urgency is manipulation under DMCC vulnerable-user clause |
Do not manufacture somatic urgency; if body-state signals are referenced, they must reflect real data or established scientific context |
| Reward anticipation loops without ceiling (#10) |
Unbounded wanting loops (infinite scroll, endless daily unlocks) exploit mesolimbic anticipation without a natural satiation point — compulsion-design risk |
Design explicit satiation signals; rate-cap anticipation mechanics; gate any wanting-loop design behind a harm-test sign-off |
| AI-driven emotion or affect inference without transparency or high-risk readiness (#2, #6, #8) |
EU AI Act Article 50 transparency is live from 2 August 2026 — users must be told an emotion-recognition system is operating. Annex III high-risk obligations were deferred to 2 December 2027 by the July 2026 Digital Omnibus, but Article 5 prohibitions bind now and GDPR Article 9 is unaffected |
Ship the Article 50 notice now; build toward Annex III (data governance, human oversight, post-market monitoring) for December 2027; if vulnerable cohort, exit the design — Article 5 prohibition likely applies regardless of the delay |
Check references/patterns-scenarios-traps.md before applying primitives to production user flows.
Decision Checklist
Anti-Patterns
| Anti-Pattern |
Neural Diagnosis |
Fix |
| Salience hijack without informational reward |
Bottom-up capture via contrast/motion violates user prior; attention cost is charged, no prediction-error budget earned (#1, #12) |
Use bottom-up salience only when the destination genuinely warrants attentional priority |
| Engagement-loop that never decelerates |
Sustained arousal above Yerkes-Dodson optimum drives autonomic stress, not engagement; user associates product with tension (#2) |
Build explicit arousal arcs — peak then resolve; do not maintain maximum arousal across full sessions |
| Warmth language without real care mechanics |
Oxytocin-adjacent copy ("we care about you") triggers affiliative response; when care is not operationally real, trust destruction is sharper than if no warmth was claimed (#3) |
Warmth signals must be backed by actual product behavior: support quality, error recovery, data transparency |
| Narrative immersion used to obscure material terms |
DMN suppresses critical evaluation during transportation; inserting T&C or pricing in high-immersion narrative flow exploits the suppression (#4) |
Material disclosures must occur at low-narrative-load moments; never embed key terms inside story content |
| Single promotional tone for prevention-oriented users |
BIS-dominant users interpret promotion-framed copy as threat of insufficient caution; conversion collapses in prevention segments (#5) |
Test BAS vs BIS copy variants; offer safety-frame and gain-frame alternatives |
| Testimonial using stock photography or unverified claims |
Mirror system generates social simulation from faces and emotional cues; fake signals trigger real neural warmth that is owed, not earned — deception under DMCC (#6) |
All testimonials from real verified users; face images from actual customers or replaced with abstract representation |
| Over-polished aesthetics masking under-built product |
Visual beauty response releases reward signal; prediction error on first real product interaction is amplified by contrast (#7, #12) |
Aesthetic investment must be proportional to functional delivery; do not use polish to buy credibility the product has not earned |
| Push notifications sent for engagement metrics at maximum-interruptibility time |
Hippocampal replay occurs during sleep and evening consolidation windows; interrupting these windows fragments encoding and creates negative product association (#9) |
Time reminders to early evening or morning; avoid late-night push; measure consolidation-window timing impact on Day-7 retention |
| Wanting loop without satiation design |
Unbounded reward anticipation (infinite scroll, endless feed, daily unlock chains) exploits mesolimbic dopamine with no natural ceiling — compulsion-design under harm test (#10) |
Provide explicit stopping signals; rate-cap unlock chains; require harm-test sign-off for any open-ended anticipation loop |
| Body-metaphor copy mismatched to product experience |
"Lighten your load" applied to a cognitively demanding feature; incongruent embodied metaphor creates cognitive interference (#11) |
Map body-state metaphors to the actual sensorimotor experience the product produces |
| Surprise release without prior expectation-setting |
Novel feature or UI change without priming violates prediction priors; attentional cost is maximal; anxiety not excitement is the more likely response in cautious users (#12) |
Prime before reveal: build the prior (teasers, waitlist, progress signals) so the reveal is a confirmation, not a shock |
| "Neuro-marketing" claim with no mechanism named |
Marketing veneer — "scientifically designed for engagement" with no primitive, circuit, or evidence named; same as behavioral-economics habit-loop abuse (#1–#12) |
Force every neuroscience-grounded claim to name the primitive (#), the circuit (e.g., VTA, insular cortex, MNS), and the anchor citation |
Composition Recipes
Recipe 1: Anxiety-Relief Consumer Loop (pre-purchase)
Goal: guide an anxiety-experiencing user through a reassurance journey to a confident purchase decision, without manufacturing or amplifying anxiety.
Stack:
- Arousal physiology (#2): Detect or assume elevated arousal state (wellness/anxiety audience). Design the entry experience to begin deescalating arousal — calm visual pacing, low-contrast background, short sentence length. Do not spike arousal at entry.
- Predictive processing (#12): Establish clear product-structure priors immediately. Anxious users have a high prediction-error cost; predictability is reassurance. Consistent layout, no hidden elements.
- Narrative transportation (#4): Use a "person like me" story (brief, first-person, past-tense) in which anxiety was the starting state and resolution was the outcome. DMN engagement with a self-relevant arc reduces threat appraisal.
- Social bonding (#3): Introduce real human warmth — a named support person, a real community count, a genuine care statement backed by operational reality (response time, refund policy). Oxytocin half-life ~3–5 min; warmth must be re-encountered across the session, not front-loaded only.
- Interoception (#8): Close with a body-state check cue ("How do you feel right now?") that invites somatic attention; let the user register their own shift. This is the somatic marker that encodes the product association positively.
Ethical-bound check: The anxiety being relieved must be real. Do not manufacture anxiety (#2 misuse) to then relieve it. DMCC vulnerable-user test must pass: would the CMA say this practice takes advantage of vulnerability?
Fail signal: "felt scammed" or "felt manipulated" qualitative reports; CSAT drop post-purchase; CMA/ASA complaint volume rising.
Inputs: Baseline anxiety trigger (product category, entry surface, referral source); relief mechanism (narrative arc, warmth signal, somatic check-in); time-to-relief target (default: ≤90s from entry to perceived deescalation); audience retention metric (Day-7 and Day-30 re-engagement rate); persona arousal profile (high-BIS prevention-dominant vs. moderate arousal).
Rules: Relief must be initiated within 90s of entry trigger — cortisol arousal curves peak and begin recovery in this window; delay beyond 90s risks entrenchment. Avoid intermittent reinforcement schedules in the relief journey (no random resolution timing) — variable-ratio schedules for an anxiety audience create compulsive re-checking, not relief. Ethical gate: relief must address a genuine user need; manufactured anxiety to then relieve it fails the DMCC harm test and the EU AI Act Article 5 prohibition on exploiting vulnerabilities.
Outputs: Trigger-to-relief interaction sequence (step-by-step UX flow with timing); measurable anxiety reduction signal (PSS-style 1–5 self-report at session close, target mean shift ≥1 point); ethical pass/fail flag (CMA vulnerable-user test + DMCC harm test result documented before ship).
Recipe 2: Parasocial Reading Bond (purchase)
Goal: generate a genuine reading bond between user and content (horoscope, tarot, interpretive reading) that drives purchase and repeat engagement without deception.
Stack:
- Narrative transportation (#4): Open with a brief orienting narrative that primes the DMN. The reading itself should use second-person, present-tense framing to maximize self-referential processing in vmPFC.
- Mirror systems (#6): Include at least one face or depicted emotional state that matches the emotion the user is likely experiencing. FFA activation and MNS simulation generate social presence with a non-present author.
- Social bonding (#3): "Others who received this reading reported..." — real cohort social framing; affiliative warmth through shared experience, not manufactured intimacy.
- Embodied cognition (#11): Copy uses body-state metaphors grounded in the product's actual experience ("a weight lifts," "clarity settles in") — not random metaphors.
Ethical-bound check: Content accuracy: predictive or interpretive content must be labeled as such (ASA CAP Code; no false claims of scientific accuracy). Social data must be real. Face imagery must be genuine or clearly illustrative.
Fail signal: Low share rate despite high session time — narrative bond did not activate social-contagion desire; revisit mirror system (#6) and real social proof (#3).
Inputs: Content type (horoscope, tarot, interpretive reading, personalized narrative); audience persona arousal profile (DMN engagement baseline — emotionally primed vs. neutral); social proof artifacts available (verified cohort testimonials, face assets, share-rate data from prior sessions); notification timing options (session-start cue window, post-read follow-up timing).
Rules: Second-person present-tense framing required for vmPFC self-referential processing; first-person past-tense for embedded "person like me" social proof arc. Face or emotional-state imagery must match the target resolution emotion (relief, clarity, confidence) — mismatched affect in testimonials suppresses MNS simulation. All cohort framing ("others who received this reading...") must use verified real user data — fabricated social proof is deception under DMCC and ASA CAP Code. Content labeled predictive or interpretive, never factual-scientific.
Outputs: Parasocial bond sequence (narrative arc + social proof placement + embodied metaphor copy); share-intent signal (post-session share prompt acceptance rate, target ≥15% of completers); cohort split result (high-DMN engagement vs. baseline by content format tested).
Recipe 3: Daily-Cadence Retention (post-purchase)
Goal: build a voluntary daily engagement habit that the user values, without compulsion design.
Stack:
- Reward anticipation (#10): Design a daily reveal or unlock that create
…(truncated)
1---2name: foundations-consumer-neuroscience3description: Consumer-neuroscience primitives for attention, arousal, bonding, narrative, memory, and reward. Use when shaping ethical UX, neuro study design, or DMCC/AI Act gates.4---5
6# Consumer Neuroscience Foundations
7
8
912 canonical consumer-neuroscience primitives for product, content, interface, and retention design. Each primitive is domain-agnostic and ethically bounded. Primitives 1–8 cover engagement-time neural responses (salience, arousal, bonding, narrative, regulatory orientation, social mirroring, aesthetics, interoception). Primitives 9–12 cover temporal and predictive mechanisms (memory consolidation, reward anticipation, embodied cognition, predictive processing). Primitive #10 (reward anticipation, Berridge "wanting" vs "liking") is intentionally distinct from `foundations-behavioral-economics` primitive #13 (reinforcement schedules / dopamine prediction-error): that skill covers schedule-of-reinforcement design; this skill covers anticipatory dopamine as a separate design lever — countdown UX, drop reveals, daily-card open, pre-purchase excitement. Primitive #12 (predictive processing & active inference) is the unifying primitive that grounds attention (#1), interoception (#8), and narrative (#4) under one prediction-error-minimization frame: the brain continuously generates predictions; violations of priors incur a prediction-error cost that must be "earned" by the design.
10
11**Ethical obligation**: every primitive in this skill operates on pre-conscious or sub-deliberative neural systems. The manipulation risk is higher than for behavioral-economics nudges, because users cannot easily introspect on the mechanism. Read the Misuse Boundary subsection in each playbook before applying any technique. The test from Thaler and Sunstein: "Would you be embarrassed if the technique appeared on the front page of a newspaper?" If yes, it is exploitation, not design. The DMCC Act 2024, in force from 6 April 2025, makes online choice architecture and dark patterns directly actionable by the CMA with fines up to 10% of global annual turnover.
12
13## When to Apply
14
15**Apply consumer-neuroscience when:**
16- Attention/salience design — first-7-second hook, visual hierarchy, modal vs inline
17- Anxiety-driven engagement loops (cosmic, dating, status apps) — needs DMCC ethical audit
18- Parasocial / narrative-led conversion (creator content, branded characters)
19- Daily-cadence retention with timing-sensitive triggers (consolidation windows, wake-time)
20- Trust repair, reciprocity, or oxytocin-bond design in social/community products
21
22**Skip and use simpler alternatives when:**
23- Pure pricing/defaults/anchoring question — foundations-behavioral-economics is sufficient and cheaper
24- Audience has no measured anxiety/arousal/attention baseline — neuro framing is decoration, not insight
25- B2B SaaS with rational-buyer mode dominant — emotional primitives mostly noise; use behavioral-econ + decision-theory
26- The proposed mechanism manipulates without genuine user benefit — fails DMCC Act 2024 ethical gate; do not ship
27- Required signals (eye-tracking, GSR, fMRI) aren't available AND no biomarker proxy exists — claim is unfalsifiable
28- Causal lift question — use foundations-causal-inference to measure; neuro primitives suggest mechanisms, not effect sizes
29
30## Contents
31
32- [Quick Reference](#quick-reference)
33- [Primitive Index](#primitive-index)
34- [Formal Supporting Theory](#formal-supporting-theory)
35- [Ethical Bounds](#ethical-bounds)
36- [Misuse Boundaries](#misuse-boundaries)
37- [Decision Checklist](#decision-checklist)
38- [Anti-Patterns](#anti-patterns)
39- [Composition Recipes](#composition-recipes)
40- [Knowledge Base & Operational Guides](#knowledge-base--operational-guides)
41- [Workflow](#workflow)
42- [ASCII Flow](#ascii-flow)
43- [Navigation](#navigation)
44- [Related Skills](#related-skills)
45- [Fact-Checking](#fact-checking)
46
47---
48
49## Quick Reference
50
51| # | Primitive | Core Property | When to Use |
52|---|-----------|---------------|-------------|
53| 1 | [Attention & Salience](assets/templates/consumer-neuroscience/01-attention-salience.md) | Bottom-up capture via contrast/novelty; top-down via relevance | Any surface where visibility or engagement priority matters |
54| 2 | [Arousal Physiology](assets/templates/consumer-neuroscience/02-arousal-physiology.md) | Yerkes-Dodson inverted-U; autonomic cost; GSR as engagement signal | Engagement loop design; onboarding intensity calibration |
55| 3 | [Social Bonding](assets/templates/consumer-neuroscience/03-social-bonding.md) | Oxytocin-driven affiliative response; trust formation | Trust mechanics, warmth signals, share/referral features |
56| 4 | [Narrative Transportation](assets/templates/consumer-neuroscience/04-narrative-transportation.md) | DMN + vmPFC + ventral striatum absorb self-referential story | Personalized content, horoscopes, product storytelling |
57| 5 | [Approach-Avoidance & BIS/BAS](assets/templates/consumer-neuroscience/05-approach-avoidance.md) | BAS drives promotion seeking; BIS drives prevention vigilance | Copy tone for mixed-orientation audiences; funnel segmentation |
58| 6 | [Mirror Systems & Emotional Contagion](assets/templates/consumer-neuroscience/06-mirror-systems.md) | FFA + MNS simulate observed emotional states | Testimonial design, UGC placement, avatar/face elements |
59| 7 | [Neuroaesthetics](assets/templates/consumer-neuroscience/07-neuroaesthetics.md) | Visual beauty response via peak-shift, contrast, symmetry | Visual hierarchy, brand asset design, landing page aesthetics |
60| 8 | [Interoception & Somatic Markers](assets/templates/consumer-neuroscience/08-interoception-somatic.md) | Insular cortex body-state signals bias decisions before deliberation | Wellness/anxiety product design; gut-feel purchase triggers |
61| 9 | [Memory Consolidation](assets/templates/consumer-neuroscience/09-memory-consolidation.md) | Hebbian potentiation + sleep replay strengthen traces | Notification timing, streak design, recall-based content |
62| 10 | [Reward Anticipation](assets/templates/consumer-neuroscience/10-reward-anticipation.md) | VTA dopamine onset ~200ms before reward; wanting distinct from liking | Countdown UX, drop reveals, daily unlock mechanics |
63| 11 | [Embodied Cognition](assets/templates/consumer-neuroscience/11-embodied-cognition.md) | Sensorimotor grounding of abstract concepts; body-state metaphors | Copy language, spatial UI metaphors, product texture cues |
64| 12 | [Predictive Processing & Active Inference](assets/templates/consumer-neuroscience/12-predictive-processing.md) | Brain minimizes free energy by updating predictions; violations cost attentional budget | Feature reveals, onboarding surprises, brand consistency |
65
66---
67
68## Primitive Index
69
70Each primitive has a full playbook: Definition / When to use / Misuse boundary / Inputs / Outputs / Failure modes / Worked example / Sources.
71
72| # | Primitive | Failure Mode It Addresses |
73|---|-----------|--------------------------|
74| 1 | [Attention & Salience](assets/templates/consumer-neuroscience/01-attention-salience.md) | Designs that assume attention is granted, not earned |
75| 2 | [Arousal Physiology](assets/templates/consumer-neuroscience/02-arousal-physiology.md) | Engagement loops that ignore stress cost on the user |
76| 3 | [Social Bonding](assets/templates/consumer-neuroscience/03-social-bonding.md) | Trust/share mechanics built without warmth signals |
77| 4 | [Narrative Transportation](assets/templates/consumer-neuroscience/04-narrative-transportation.md) | "Personal-feeling" content reduced to facts and lists |
78| 5 | [Approach-Avoidance & BIS/BAS](assets/templates/consumer-neuroscience/05-approach-avoidance.md) | Single-tone funnels for mixed promotion/prevention users |
79| 6 | [Mirror Systems & Emotional Contagion](assets/templates/consumer-neuroscience/06-mirror-systems.md) | Testimonials and UGC ignored as conversion lever |
80| 7 | [Neuroaesthetics](assets/templates/consumer-neuroscience/07-neuroaesthetics.md) | Aesthetic choices justified by taste, not neural response |
81| 8 | [Interoception & Somatic Markers](assets/templates/consumer-neuroscience/08-interoception-somatic.md) | "Gut-feel" decisions ignored as design surface |
82| 9 | [Memory Consolidation](assets/templates/consumer-neuroscience/09-memory-consolidation.md) | Reminders and streaks that fight consolidation timing |
83| 10 | [Reward Anticipation](assets/templates/consumer-neuroscience/10-reward-anticipation.md) | Anticipation phase ignored in favor of payoff |
84| 11 | [Embodied Cognition](assets/templates/consumer-neuroscience/11-embodied-cognition.md) | Copy and UI ignoring body-state metaphors |
85| 12 | [Predictive Processing & Active Inference](assets/templates/consumer-neuroscience/12-predictive-processing.md) | Surprises that violate user priors without earning the prediction-error budget |
86
87---
88
89## Formal Supporting Theory
90
91| Theory Area | Use When | Applied Primitives It Grounds |
92|---|---|---|
93| Attention theory (Feature Integration Theory, salience maps) | Need to predict what captures or loses user attention | #1 |
94| Psychophysiology & autonomic regulation (Yerkes-Dodson, allostatic load) | Need to calibrate engagement intensity without imposing stress cost | #2 |
95| Social neuroendocrinology (oxytocin system, affiliative circuits) | Need to understand trust formation or prosocial behavior in product | #3 |
96| Narrative cognition & Default Mode Network (DMN, vmPFC, ventral striatum) | Need to design self-referential or immersive content | #4 |
97| Regulatory focus & BIS/BAS (Higgins, Carver & White) | Need to distinguish promotion-oriented from prevention-oriented users | #5 |
98| Mirror neuron system & emotional contagion (MNS, FFA) | Need to understand social simulation in testimonials or face-based UI | #6 |
99| Neuroaesthetics (peak-shift, symmetry, contour, reward from visual beauty) | Need to explain or predict aesthetic preference and visual reward | #7 |
100| Interoception & somatic marker theory (Craig insular cortex, Damasio vmPFC) | Need to account for body-state signals in purchase or risk decisions | #8 |
101| Systems memory consolidation & sleep-dependent replay (Hebbian, hippocampal-neocortical transfer) | Need to design for durable trace formation — not just exposure | #9 |
102| Incentive salience & wanting vs liking (Berridge mesolimbic dopamine, VTA) | Need to distinguish anticipatory drive from hedonic reward | #10 |
103| Embodied / grounded cognition (Lakoff & Johnson, Barsalou) | Need to align copy or UI metaphors with sensorimotor experience | #11 |
104| Predictive processing & active inference (Friston free energy, Clark, Constant) | Need to manage prediction-error budget: when to surprise, when to confirm | #12 |
105
106Use [`references/formal-theory-map.md`](references/formal-theory-map.md) when the task needs source assumptions, ethical boundaries, or a distinction between observed neural response and normative welfare.
107
108---
109
110## Ethical Bounds
111
112### The Harm Test
113
114A neural design technique is legitimate if it:
115
1161. Steers users toward experiences or decisions they would endorse on reflection.
1172. Can be easily overridden or opted out of.
1183. Does not exploit pre-conscious neural mechanisms to act against the user's interests.
119
120The same lever — arousal, oxytocin warmth, reward anticipation — can be legitimate or manipulative depending on whether the underlying offer genuinely serves the user.
121
122### Manipulation vs Legitimate Design
123
124| Dimension | Legitimate | Manipulation |
125|-----------|-----------|--------------|
126| Transparency | Mechanism can be disclosed without destroying the effect | Requires concealment of mechanism to work |
127| User-benefit alignment | Steers toward user's own stated goals or wellbeing | Overrides user goals in favor of operator revenue |
128| Reversibility | Easy to disengage, unsubscribe, or undo | Designed to make exit costly or invisible |
129| Signal honesty | Arousal, urgency, or warmth reflects real content | Signal is manufactured (fake countdown, artificial scarcity, paid "warmth") |
130| Regulatory posture | Survives CMA/ASA/ICO scrutiny | Attracts DMCC Act enforcement action |
131
132### UK Regulatory Context (August 2026)
133
134**DMCC Act 2024** entered into force **6 April 2025**, **revoking** the CPRs 2008 outright (s.251(1), commenced by SI 2025/272) and succeeding them with ss. 226 (misleading actions), 227 (misleading omissions), and 228 (aggressive practices), plus the Sch. 20 list of banned practices. The successor provisions are redrafted, not a restatement — old CPRs regulation numbers do not map across cleanly, so cite DMCC sections. The CMA has direct civil-enforcement power and can fine **up to 10% of global annual turnover** without requiring a court order.
135
136Enforcement is now live, not prospective — the first two infringement decisions both concerned online choice architecture rather than advertising content:
137
138- **18 November 2025**: CMA opened its first DMCC enforcement actions against 8 firms (drip pricing, default opt-ins, pressure selling) and issued approximately 100 advisory letters across 14 sectors.
139- **18 June 2026**: second infringement decision — **Marks Electrical fined £720,000** (£1.2m reduced 40% for early settlement) and ordered to refund ~£600,000 to ~40,000 customers, for **pre-selected extra charges** (customers auto-opted into paid recycling and unwrapping services). Conduct covered April–November 2025. This is the clearest signal of the enforcement floor: a mid-size retailer, a single default-opt-in pattern, a seven-figure headline penalty plus consumer redress.
140
141**April 2025**: CMA published procedural guidance on DMCC enforcement. **December 2025**: CMA published price transparency guidance under DMCC.
142
143Online Choice Architecture (dark patterns) now directly actionable under DMCC, including:
144- Confirm-shaming (manipulative framing on decline options)
145- Pre-ticked defaults that benefit the operator at user expense
146- Drip pricing (incremental price reveal late in purchase flow)
147- False urgency ("Only 2 left!" when stock is unconstrained)
148- Forced continuity (auto-renew without prominent disclosure)
149
150Secondary regulatory anchors:
151- **ASA CAP Code**: misleading advertising, fabricated testimonials, manufactured social proof
152- **DMCC Act 2024 s.228** (aggressive practices — replaced CPRs 2008 Reg. 7, revoked 6 April 2025)
153- **UK GDPR**: biometric and neuro-physiological signal capture (GSR, HRV, eye-tracking, fNIRS) constitutes special-category data in many use cases; requires explicit consent and lawful basis (Article 9)
154
155### EU Regulatory Context (August 2026)
156
157For products serving EU users, the **EU AI Act** is the parallel anchor to DMCC and applies on top of GDPR.
158
159- **Article 5 prohibitions in force from 2 February 2025**: AI systems that deploy "subliminal techniques beyond a person's consciousness" or "purposefully manipulative or deceptive techniques" causing significant harm are prohibited outright. AI systems that exploit vulnerabilities (age, disability, socio-economic situation) are also prohibited. This directly captures the manipulation column of the table above when AI is in the loop. Unaffected by the 2026 delay below — the prohibitions bind now.
160- **Emotion-recognition prohibition (workplace and education)**: AI inference of emotions from facial expression, voice, GSR, HRV, or any biometric stream is prohibited in workplace and education contexts (Article 5). Commercial deployment outside those contexts is not prohibited but is regulated.
161- **High-risk classification DELAYED to 2 December 2027** (was 2 August 2026): the **AI Digital Omnibus** was published in the Official Journal 24 July 2026 and entered into force 27 July 2026, deferring standalone Annex III high-risk obligations — which include commercial emotion-recognition and biometric-categorisation systems — by 16 months. Annex I (AI embedded in products under EU product-safety law) moves to 2 August 2028. Providers and deployers must still meet data-governance, transparency, human-oversight, robustness, accuracy, and post-market monitoring requirements, but the compliance deadline is **December 2027**. Treat this as schedule relief, not repeal: systems in design now will ship into the regime.
162- **Article 50 transparency obligations remain on the original 2 August 2026 schedule** — they were *not* delayed. Users exposed to emotion-recognition or biometric-categorisation systems must be explicitly informed, **now**. A four-month grace period (to 2 December 2026) applies only to the Article 50(2) watermarking duty for systems already on the market. This is the live EU obligation for affect-inference products as of August 2026.
163- **GDPR continues to apply**: lawful basis (typically Article 9 explicit consent for biometric data) is a precondition; the AI Act adds requirements on top. GDPR is unaffected by the Omnibus delay and is the binding constraint in the interim.
164
165For UK-only products, DMCC + UK GDPR are sufficient. For EU users or shared-stack products, both regimes apply and the **stricter** rule binds.
166
167### US Regulatory Context (August 2026)
168
169Four states have enacted neural-data-specific privacy laws (Colorado, California, Montana, Connecticut), and nine further bills were introduced across six states in the first six weeks of 2026 alone (Alabama, California, Illinois, New York, Vermont, Virginia). Treat this as a live patchwork, not a settled regime.
170
171**Scope caution — these laws are narrower than "any biometric signal."** Most define neural data as signals from the nervous system measured directly, and several explicitly exclude the downstream physiological signals this skill most often uses. Montana SB 163 carves out "nonneural information … the downstream physical effects of neural activity, including but not limited to pupil dilation, motor activity, and breathing rate" — which excludes GSR and eye-tracking. California SB 1223 requires neural data be "not inferred from nonneural information," likely excluding facial coding and voice affect. Colorado's definition reaches only data used for **identification** purposes, excluding most consumer applications. Connecticut has no explicit carve-out, leaving GSR and eye-tracking ambiguous there. **Practical consequence**: EEG and fNIRS are squarely in scope; GSR, HRV, eye-tracking, facial coding, and voice affect are mostly *out* of neural-data statutes — but remain covered by general state biometric/sensitive-data law, BIPA-style statutes, and GDPR for EU users. Do not use a neural-data-law exemption as a reason to skip consent; check the general privacy regime instead.
172
173- **California SB 1223** (effective **1 January 2025**): amends CCPA to classify "neural data" (signals from central or peripheral nervous system, not inferred from nonneural information) as sensitive personal information. Opt-in consent required; right to delete and restrict sharing apply. [Primary source](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB1223)
174- **Colorado HB 24-1058** (effective **7 August 2024**): amends Colorado Privacy Act to include "neural data" within "biological data" as sensitive data. First US law to define and protect neural data. Scope limited to data used or intended for identification. [Primary source](https://leg.colorado.gov/bills/hb24-1058)
175- **Montana SB 163** (effective **1 October 2025**): adds neurotechnology data to Montana's Genetic Information Privacy Act. The **most extensive** of the four: detailed express-consent requirements for collection, marketing and research use, disclosure, transfer, and sale — often requiring separate informed consent per purpose and per third party. Explicitly excludes nonneural downstream signals. If a product captures true neural data from US users, Montana sets the strictest operative bar.
176- **Connecticut SB 1295** (signed **24 June 2025**; effective **1 July 2026**): amends CTDPA to add neural data as a sensitive data category; processing requires express consumer consent; selling sensitive data without consent prohibited. [Primary source](https://natlawreview.com/article/connecticut-amends-connecticut-data-privacy-act)
177- **Vermont H.814 / Act 101** (signed **18 May 2026**; effective **1 July 2026**): **correction — do not overstate this law.** As enacted, H.814 was substantially narrowed in the Senate: it recognises a largely declaratory statement of "neurological rights" (mental privacy, freedom of thought, non-discrimination in neurotechnology), but the **consent requirement and private right of action were stripped** before passage. Enforcement rests exclusively with the Vermont Attorney General; there is no consent gate for businesses. Its main forward hook is a commissioned study reporting to the next legislative session. Vermont's binding neural-data framework is **Vermont S.71** (neural data as sensitive data), effective **1 January 2028** — track that bill, not H.814, for compliance planning. Treat H.814 as a signal of legislative direction, not a live consent gate. [Primary source](https://www.cooley.com/news/insight/2026/2026-06-23-from-maple-to-mind-taps-new-vermont-law-puts-neurotech-on-notice)
178- **UNESCO Recommendation on the Ethics of Neurotechnology** (adopted **12 November 2025**): first global non-binding framework covering neural data across commercial uses. Non-binding but widely cited in board-level compliance discussions and DPA engagement. [Primary source](https://www.unesco.org/en/legal-affairs/recommendation-ethics-neurotechnology)
179- **US MIND Act 2025** (proposed): would direct FTC to study neuromarketing as a named use case; not yet law but signals federal regulatory attention. Document FTC-readiness posture if product involves neuromarketing explicitly.
180
181**Practical implication**: any product capturing genuine neural signal (EEG, fNIRS) from US users must run a per-state consent analysis — California CCPA sensitive PI from 1 January 2025, Montana's per-purpose express consent from 1 October 2025, Colorado and Connecticut in parallel. For GSR, HRV, eye-tracking, facial coding, and voice affect, the neural-data statutes mostly do not bite; the governing constraints are general sensitive-data and biometric law plus GDPR Article 9 for EU users. See `references/ethics-operational-checklist.md` US Neural Data Laws section.
182
183### Vulnerable-User Note
184
185CMA enforcement priorities specifically name "aggressive sales practices which take advantage of vulnerability." Wellness, anxiety-relief, and astrology/spiritual audiences are explicitly in scope as vulnerability-risk contexts. EU AI Act Article 5 reinforces this with an outright prohibition on AI systems that exploit vulnerabilities of specific groups (age, disability, socio-economic situation) to materially distort behaviour. Any application in these categories must apply the stricter column of the manipulation table — not the middle ground. Manufactured urgency, oxytocin-proxy warmth without genuine care mechanics, and reward-anticipation loops targeting financially or emotionally vulnerable users are highest-risk under both regimes.
186
187---
188
189## Misuse Boundaries
190
191| Misuse | Why It Is Wrong | Required Correction |
192|---|---|---|
193| Manufacturing arousal without informational value (#2) | GSR spike earned by stimulus intensity, not content quality — violates prediction-error budget and harms user attention economy. Note: GSR/HRV-as-arousal-proxy claims require qualification — BAAS (Nature Communications 2025, 24-study validation) confirms autonomic signals are statistically distinct from subjective affective arousal; interpret autonomic signals as physiological activation, not as direct proxies for the subjective arousal consumers experience | Earn arousal through genuine novelty or high personal relevance; measure dwell quality, not just engagement duration; acknowledge GSR/HRV–affective-arousal dissociation in any study claiming arousal measurement |
194| Exploiting oxytocin proxies without genuine warmth (#3) | Artificial warmth signals (faked testimonials, performed care language) produce short-term affiliation that collapses on discovery, destroying trust. Claiming universal oxytocin-driven trust from warmth signals overstates the evidence; the Declerck 2020 registered replication (Nature Human Behaviour, >95% power) found no main effect of oxytocin on trust under standard conditions — design for genuine warmth and affiliative behavior, not a neuroendocrine mechanism the replication literature does not support uniformly | Use only real social proof and care signals; oxytocin half-life ~3–5 min means trust must be re-earned each session; do not claim design patterns universally increase trust via oxytocin mechanism |
195| Narrative transport without consent (#4) | DMN immersion suppresses critical evaluation — delivering false information during transportation is a manipulation under DMCC | Narrative content must be accurate; emotional immersion does not override disclosure obligations |
196| Biometric/neuro-signal capture without lawful basis (#2, #8) | GSR, HRV, facial EMG, eye-tracking, and EEG are special-category biometric data under UK GDPR in research or product contexts; capture without explicit consent is unlawful | Obtain explicit Article 9 consent; document lawful basis before any physiological measurement |
197| Single-tone funnel for mixed BIS/BAS audience (#5) | Prevention-oriented users subjected to unrelenting promotion framing experience regulatory mismatch; trust drops | Segment or test copy by regulatory focus; offer prevention-framed and promotion-framed variants |
198| Fabricating social contagion signals (#6) | Showing false emotional reactions (fake ratings, manufactured "people are loving this") triggers mirror system without real social proof | All emotional-contagion signals must reflect real user sentiment from verified cohort data |
199| Neuroaesthetic dopamine trap — aesthetic beauty without functional value (#7, #10) | Highly polished aesthetics trigger visual reward and reward anticipation; if the underlying product fails to deliver, disappointment amplifies by contrast (prediction error) | Aesthetic quality must be matched by functional delivery; do not use visual reward to paper over a weak product |
200| False-prediction surprise (#12) | Violating established user priors without earning the prediction-error budget creates confusion, anxiety, and trust loss | Predict before you surprise; reserve prediction-error violations for high-value reveals backed by strong prior evidence of user benefit |
201| Interoceptive exploitation in vulnerable users (#8) | Triggering somatic anxiety signals ("your body is telling you something is wrong") in wellness/anxiety contexts to manufacture urgency is manipulation under DMCC vulnerable-user clause | Do not manufacture somatic urgency; if body-state signals are referenced, they must reflect real data or established scientific context |
202| Reward anticipation loops without ceiling (#10) | Unbounded wanting loops (infinite scroll, endless daily unlocks) exploit mesolimbic anticipation without a natural satiation point — compulsion-design risk | Design explicit satiation signals; rate-cap anticipation mechanics; gate any wanting-loop design behind a harm-test sign-off |
203| AI-driven emotion or affect inference without transparency or high-risk readiness (#2, #6, #8) | EU AI Act **Article 50 transparency is live from 2 August 2026** — users must be told an emotion-recognition system is operating. Annex III high-risk obligations were deferred to **2 December 2027** by the July 2026 Digital Omnibus, but Article 5 prohibitions bind now and GDPR Article 9 is unaffected | Ship the Article 50 notice now; build toward Annex III (data governance, human oversight, post-market monitoring) for December 2027; if vulnerable cohort, exit the design — Article 5 prohibition likely applies regardless of the delay |
204
205Check [`references/patterns-scenarios-traps.md`](references/patterns-scenarios-traps.md) before applying primitives to production user flows.
206
207---
208
209## Decision Checklist
210
211- [ ] **Attention earned**: Is the design earning attention through genuine relevance or novelty, not bottom-up hijacking? → attention & salience (#1)
212- [ ] **Arousal calibration**: Is the engagement intensity appropriate for the decision being made? Will the arousal level impair or support the user's goal? → arousal physiology (#2)
213- [ ] **Warmth signals**: Are trust and affiliation signals real? Is any warmth mechanic backed by genuine social data? → social bonding (#3)
214- [ ] **Narrative accuracy**: If the experience transports users emotionally, is the content accurate? Does immersion serve or obscure the user's interests? → narrative transportation (#4)
215- [ ] **Regulatory orientation**: Does the audience skew BIS (prevention) or BAS (approach)? Is the primary message tone matched to the audience's dominant orientation? → approach-avoidance (#5)
216- [ ] **Social proof quality**: Are testimonials, reactions, and contagion signals from real users in verified data? → mirror systems (#6)
217- [ ] **Aesthetic-to-delivery ratio**: Does visual quality match functional delivery? Is aesthetic reward being used to compensate for a weak product? → neuroaesthetics (#7), reward anticipation (#10)
218- [ ] **Interoceptive framing**: Is any body-state or "gut feel" framing based on real signals? Is it used to inform, not to manufacture anxiety? → interoception (#8)
219- [ ] **Consolidation timing**: Are push notifications and reminders timed to consolidation windows (evening, post-sleep) rather than maximum interruptibility? → memory consolidation (#9)
220- [ ] **Wanting vs liking balance**: Is reward anticipation matched by hedonic payoff? Is the anticipation loop capped to prevent compulsion? → reward anticipation (#10)
221- [ ] **Embodied language**: Does copy use body-state metaphors congruent with the product experience? → embodied cognition (#11)
222- [ ] **Prediction-error budget**: Does the design surprise users only when it has earned the attentional cost? Are established priors preserved during routine use? → predictive processing (#12)
223- [ ] **Ethical gate**: Does each technique pass the harm test? Does it survive DMCC scrutiny for vulnerable-user contexts? → ethical bounds section
224
225---
226
227## Anti-Patterns
228
229| Anti-Pattern | Neural Diagnosis | Fix |
230|-------------|-----------------|-----|
231| Salience hijack without informational reward | Bottom-up capture via contrast/motion violates user prior; attention cost is charged, no prediction-error budget earned (#1, #12) | Use bottom-up salience only when the destination genuinely warrants attentional priority |
232| Engagement-loop that never decelerates | Sustained arousal above Yerkes-Dodson optimum drives autonomic stress, not engagement; user associates product with tension (#2) | Build explicit arousal arcs — peak then resolve; do not maintain maximum arousal across full sessions |
233| Warmth language without real care mechanics | Oxytocin-adjacent copy ("we care about you") triggers affiliative response; when care is not operationally real, trust destruction is sharper than if no warmth was claimed (#3) | Warmth signals must be backed by actual product behavior: support quality, error recovery, data transparency |
234| Narrative immersion used to obscure material terms | DMN suppresses critical evaluation during transportation; inserting T&C or pricing in high-immersion narrative flow exploits the suppression (#4) | Material disclosures must occur at low-narrative-load moments; never embed key terms inside story content |
235| Single promotional tone for prevention-oriented users | BIS-dominant users interpret promotion-framed copy as threat of insufficient caution; conversion collapses in prevention segments (#5) | Test BAS vs BIS copy variants; offer safety-frame and gain-frame alternatives |
236| Testimonial using stock photography or unverified claims | Mirror system generates social simulation from faces and emotional cues; fake signals trigger real neural warmth that is owed, not earned — deception under DMCC (#6) | All testimonials from real verified users; face images from actual customers or replaced with abstract representation |
237| Over-polished aesthetics masking under-built product | Visual beauty response releases reward signal; prediction error on first real product interaction is amplified by contrast (#7, #12) | Aesthetic investment must be proportional to functional delivery; do not use polish to buy credibility the product has not earned |
238| Push notifications sent for engagement metrics at maximum-interruptibility time | Hippocampal replay occurs during sleep and evening consolidation windows; interrupting these windows fragments encoding and creates negative product association (#9) | Time reminders to early evening or morning; avoid late-night push; measure consolidation-window timing impact on Day-7 retention |
239| Wanting loop without satiation design | Unbounded reward anticipation (infinite scroll, endless feed, daily unlock chains) exploits mesolimbic dopamine with no natural ceiling — compulsion-design under harm test (#10) | Provide explicit stopping signals; rate-cap unlock chains; require harm-test sign-off for any open-ended anticipation loop |
240| Body-metaphor copy mismatched to product experience | "Lighten your load" applied to a cognitively demanding feature; incongruent embodied metaphor creates cognitive interference (#11) | Map body-state metaphors to the actual sensorimotor experience the product produces |
241| Surprise release without prior expectation-setting | Novel feature or UI change without priming violates prediction priors; attentional cost is maximal; anxiety not excitement is the more likely response in cautious users (#12) | Prime before reveal: build the prior (teasers, waitlist, progress signals) so the reveal is a confirmation, not a shock |
242| "Neuro-marketing" claim with no mechanism named | Marketing veneer — "scientifically designed for engagement" with no primitive, circuit, or evidence named; same as behavioral-economics habit-loop abuse (#1–#12) | Force every neuroscience-grounded claim to name the primitive (#), the circuit (e.g., VTA, insular cortex, MNS), and the anchor citation |
243
244---
245
246## Composition Recipes
247
248### Recipe 1: Anxiety-Relief Consumer Loop (pre-purchase)
249
250**Goal**: guide an anxiety-experiencing user through a reassurance journey to a confident purchase decision, without manufacturing or amplifying anxiety.
251
252**Stack**:
2531. **Arousal physiology (#2)**: Detect or assume elevated arousal state (wellness/anxiety audience). Design the entry experience to begin deescalating arousal — calm visual pacing, low-contrast background, short sentence length. Do not spike arousal at entry.
2542. **Predictive processing (#12)**: Establish clear product-structure priors immediately. Anxious users have a high prediction-error cost; predictability is reassurance. Consistent layout, no hidden elements.
2553. **Narrative transportation (#4)**: Use a "person like me" story (brief, first-person, past-tense) in which anxiety was the starting state and resolution was the outcome. DMN engagement with a self-relevant arc reduces threat appraisal.
2564. **Social bonding (#3)**: Introduce real human warmth — a named support person, a real community count, a genuine care statement backed by operational reality (response time, refund policy). Oxytocin half-life ~3–5 min; warmth must be re-encountered across the session, not front-loaded only.
2575. **Interoception (#8)**: Close with a body-state check cue ("How do you feel right now?") that invites somatic attention; let the user register their own shift. This is the somatic marker that encodes the product association positively.
258
259**Ethical-bound check**: The anxiety being relieved must be real. Do not manufacture anxiety (#2 misuse) to then relieve it. DMCC vulnerable-user test must pass: would the CMA say this practice takes advantage of vulnerability?
260
261**Fail signal**: "felt scammed" or "felt manipulated" qualitative reports; CSAT drop post-purchase; CMA/ASA complaint volume rising.
262
263**Inputs:** Baseline anxiety trigger (product category, entry surface, referral source); relief mechanism (narrative arc, warmth signal, somatic check-in); time-to-relief target (default: ≤90s from entry to perceived deescalation); audience retention metric (Day-7 and Day-30 re-engagement rate); persona arousal profile (high-BIS prevention-dominant vs. moderate arousal).
264**Rules:** Relief must be initiated within 90s of entry trigger — cortisol arousal curves peak and begin recovery in this window; delay beyond 90s risks entrenchment. Avoid intermittent reinforcement schedules in the relief journey (no random resolution timing) — variable-ratio schedules for an anxiety audience create compulsive re-checking, not relief. Ethical gate: relief must address a genuine user need; manufactured anxiety to then relieve it fails the DMCC harm test and the EU AI Act Article 5 prohibition on exploiting vulnerabilities.
265**Outputs:** Trigger-to-relief interaction sequence (step-by-step UX flow with timing); measurable anxiety reduction signal (PSS-style 1–5 self-report at session close, target mean shift ≥1 point); ethical pass/fail flag (CMA vulnerable-user test + DMCC harm test result documented before ship).
266
267---
268
269### Recipe 2: Parasocial Reading Bond (purchase)
270
271**Goal**: generate a genuine reading bond between user and content (horoscope, tarot, interpretive reading) that drives purchase and repeat engagement without deception.
272
273**Stack**:
2741. **Narrative transportation (#4)**: Open with a brief orienting narrative that primes the DMN. The reading itself should use second-person, present-tense framing to maximize self-referential processing in vmPFC.
2752. **Mirror systems (#6)**: Include at least one face or depicted emotional state that matches the emotion the user is likely experiencing. FFA activation and MNS simulation generate social presence with a non-present author.
2763. **Social bonding (#3)**: "Others who received this reading reported..." — real cohort social framing; affiliative warmth through shared experience, not manufactured intimacy.
2774. **Embodied cognition (#11)**: Copy uses body-state metaphors grounded in the product's actual experience ("a weight lifts," "clarity settles in") — not random metaphors.
278
279**Ethical-bound check**: Content accuracy: predictive or interpretive content must be labeled as such (ASA CAP Code; no false claims of scientific accuracy). Social data must be real. Face imagery must be genuine or clearly illustrative.
280
281**Fail signal**: Low share rate despite high session time — narrative bond did not activate social-contagion desire; revisit mirror system (#6) and real social proof (#3).
282
283**Inputs:** Content type (horoscope, tarot, interpretive reading, personalized narrative); audience persona arousal profile (DMN engagement baseline — emotionally primed vs. neutral); social proof artifacts available (verified cohort testimonials, face assets, share-rate data from prior sessions); notification timing options (session-start cue window, post-read follow-up timing).
284**Rules:** Second-person present-tense framing required for vmPFC self-referential processing; first-person past-tense for embedded "person like me" social proof arc. Face or emotional-state imagery must match the target resolution emotion (relief, clarity, confidence) — mismatched affect in testimonials suppresses MNS simulation. All cohort framing ("others who received this reading...") must use verified real user data — fabricated social proof is deception under DMCC and ASA CAP Code. Content labeled predictive or interpretive, never factual-scientific.
285**Outputs:** Parasocial bond sequence (narrative arc + social proof placement + embodied metaphor copy); share-intent signal (post-session share prompt acceptance rate, target ≥15% of completers); cohort split result (high-DMN engagement vs. baseline by content format tested).
286
287---
288
289### Recipe 3: Daily-Cadence Retention (post-purchase)
290
291**Goal**: build a voluntary daily engagement habit that the user values, without compulsion design.
292
293**Stack**:
2941. **Reward anticipation (#10)**: Design a daily reveal or unlock that create
295
296…(truncated)