Ignoring a security warning is not a matter of negligence. An American research team measured the phenomenon where it truly occurs: in the brain.
Twenty-five volunteers in an MRI tube
The protocol is disarmingly simple. Twenty-five participants lie inside a functional magnetic resonance imaging (fMRI) machine, a screen before their eyes, and warning windows repeatedly displayed during the recording of brain activity.
The results were published in December 2016 by Bonnie Brinton Anderson, Anthony Vance, C. Brock Kirwan, Jeffrey L. Jenkins and David Eargle in the Journal of Management Information Systems (volume 33, issue 3, pages 713 to 743). The title leaves no room for doubt: the warning ends up as wallpaper. A preliminary version of these findings was presented a year earlier at CHI, the premier international gathering dedicated to human–computer interaction.
The imaging yields an unambiguous result. The neural response in the visually processing regions declines steeply as the same warning reappears on the screen. Not after fifty displays. From the very first repetitions.
The brain gradually stops processing the image. The user does not choose to ignore the window: he literally sees it less and less.
A mechanism described as early as 1970
Habituation is not a character flaw. Philip Groves and Richard Thompson laid out the reference theory in 1970, distinguishing two opposing processes: one dampens the response to a repeated, harmless stimulus, while the other strengthens it when a threat is perceived. It is among the most elementary learning mechanisms of living beings, observed even in the sea slug Aplysia, whose study earned Eric Kandel the Nobel Prize in Physiology or Medicine in 2000.
A nervous system that did not habituate to anything would be unmanageable. Each background noise, every reflection, every notification would demand the same resources as the very first time.
The trouble is that interface designers built their safety nets on exactly the opposite assumption.
What this means for any protection that rests on a click
The result extends far beyond the question of warning pop-ups. Any security measure that requires a conscious, repeated decision at every occasion is exposed to the same erosion. On day one, the user reads and decides. By the thirtieth, the action has become a motorized habit, and the window has joined the furniture.
Background-enabled devices, once configured, escape this trap for a trivial reason: they ask nothing more. Systematic encryption of outgoing traffic belongs to this family, since it applies thereafter without demanding any further decision. It still matters to know which technical criteria to compare these tools on, and 01net keeps a detailed file on the topic: https://www.01net.com/vpn/
The phenomenon does not stop at the laboratory door
An MRI remains an artificial environment, and the authors were aware of this. They therefore conducted a second experiment with eighty people, this time on their own computers, tracking the cursor movements as an indirect indicator of attention to the screen. The same trend as in the lab.
The same team published, that year, in Decision Support Systems (volume 92, pages 3–13) a complementary study based on eye-tracking. It links habituation to memory mechanisms: the more familiar the warning, the less the gaze lingers on it, and the less likely it is to be processed.
This detail matters, because it rules out the most convenient explanation. If the user were to deliberately look away, one would have to blame their motivation. Yet the decline in response occurs upstream of any intention, in areas not governed by conscious decision.
The warning that changes appearance resists adaptation better
The researchers did not stop at mere observation. They designed polymorphic warnings that alter their appearance with each display: color, framing, animation, the positioning of elements. In the scanner, these variants resist habituation far more effectively in the brain regions tied to attention. The four most effective variants were then tested in real-world conditions with the eighty participants from the second experiment, with the same benefit.
A decade later, browsers continue to display warnings that are strictly identical from one display to the next.
Consent banners play the same tune
Rainer Böhme and Stefan Köpsell presented at the CHI conference in 2010 a field experiment on consent windows. Those that took the form of a classic license agreement were accepted faster and more often. The click did not signify a thoughtful agreement, but a reflex learned through years of exposure to the same visual template.
The CNIL demands, on its side, that consent result from a clear positive act, and it details its expectations in its guidelines dedicated to cookies and other trackers. Between this legal requirement and what brain imaging documents, the gap remains wide: no text can decree that a brain will continue to perceive what it has learned to filter.
The problem goes far beyond the screens
Pharmacovigilance and industrial safety have confronted the same wall for decades, with leaflets that no one unfolds anymore and pictograms that have become decorative. The American standard ANSI Z535, which governs safety symbols, has been revised several times for this very reason.
What imaging reveals, fundamentally, is a shift of responsibility. As long as inattention was treated as a lack of discipline, the solution was to repeat the message louder. Once it is established that repetition is precisely what erases it, the burden falls on the designer of the interface. The question remains: how many years will it take for this conclusion to reach the software that everyone uses every day?