Digital Engagement Practices in Investment Services: Why the Regulatory Spotlight Moved, and Where It Now Sits

This informal CPD article, ‘Digital Engagement Practices in Investment Services: Why the Regulatory Spotlight Moved, and Where It Now Sits’, was provided by Nikolas Demetriades, founder of CPDs.Academy, a CPD training platform delivering compliance education for professionals in EU-regulated financial services.

In early 2023, the European Securities and Markets Authority (ESMA) seemed to be closing in on the way investment firms design their digital interfaces. Its revised guidelines on MiFID II product governance, finalised on 27 March 2023, dealt with gamification and digital engagement directly, asking distributors to consider, when they decide how a product is marketed and distributed, whether techniques such as gamification and nudging are in the interests of the target clients (1). A discussion paper later that year went further, working through finfluencers, dark patterns, layered disclosures and digital marketing in some detail (2). Anyone reading those two documents in 2023 might reasonably have expected a dedicated supervisory framework on digital engagement to follow.

It did not. Three years on, the strongest constraints on manipulative digital design sit not in sectoral investment rules but in the European Union’s horizontal digital and consumer law, where some practices have moved from being discouraged to being prohibited. That shift is not confined to investment firms. The Digital Services Act (3) and the Artificial Intelligence Act (4) are sector agnostic. The revised consumer-law regime for distance financial services (5) is different: it is financial-services-specific, but not investment-services-specific, and can therefore reach banking, insurance, payment and investment services where its conditions are met. For a firm with retail-facing digital products, the live questions are no longer about a forthcoming ESMA rulebook. They are about where supervisory attention has gone, which rules now carry legal force, and how to read a direction of travel that few predicted.

What ESMA said in 2023

Of the two interventions, the guidelines carried more weight, not because they are directly applicable law in the way a regulation is, but because they have stronger supervisory force than a discussion paper and sit within ESMA’s supervisory-convergence framework (1). ESMA defined gamification as the use of game-like elements, points and badges, leaderboards, performance graphs, in contexts that are not games, and it asked distributors, when settling how a product is marketed and distributed, to consider whether such techniques serve the interests of the client group concerned (1). On the most aggressive forms it was unusually direct, stating that “certain gamification techniques (such as those used in trading apps designed to nudge the (potential) client towards harmful behaviour, e.g., maximise the number of trades) will never be in the interest of the client” (1).

The discussion paper, published on 14 December 2023, ranged wider, examining choice architecture, behavioural techniques, the oversight of finfluencer arrangements and the boundary between legitimate engagement and manipulation (2). A discussion paper, though, is only that. It floated proposals and invited responses by March 2024. It imposed nothing.

Around the same period, ESMA and the national competent authorities ran a common supervisory action on marketing communications. The findings, combined with a mystery shopping exercise and drawing on 27 authorities, were published on 27 May 2024 (6). Marketing was largely compliant, the exercise concluded, though firms were pressed to make communications clearly identifiable as marketing and to set risks against benefits in a balanced way.

The quiet that followed, and what happened in it

It would be wrong to say nothing followed. Several things did. The narrower and more accurate point is that ESMA did not turn its 2023 thinking into a dedicated, binding framework for digital engagement practices.

Part of the reason is that the sectoral reform agenda was pointed elsewhere. On 24 May 2023, only weeks after the product governance guidelines (1) were finalised, the European Commission tabled its Retail Investment Strategy (7), a wide package amending MiFID II (8) and neighbouring directives and centred on value-for-money rules, inducements, suitability and strengthened investor-protection safeguards. That package took up much of the available bandwidth for retail investor protection. The Council and the Parliament reached a provisional political agreement in December 2025, Coreper confirmed the final compromise text on 28 May 2026, and formal adoption is still outstanding (7).

Nor did the discussion paper (2) mature into guidelines or technical standards on dark patterns, nudging or gamification. When ESMA reported on the retail investor journey on 12 March 2026, drawing on a call for evidence answered by 96 respondents, it did not return to digital engagement practices as a standalone workstream (9). It did, though, cross the same ground. Respondents pointed to digitalisation and online distribution, gamification features, the use of finfluencers and increasingly aggressive digital marketing as forces that can amplify risk-taking, and the report flagged behavioural design and the need for protections against dark patterns across digital user journeys, listing these among the areas the current framework does not fully capture (9). The message was that the problem is still live, not that a dedicated response is close.

Other actors did move. National consumer authorities grew more active on manipulative online design, though through general consumer law rather than anything specific to investment services. In a coordinated sweep reported in January 2023, the Commission and consumer authorities from 23 Member States, Norway and Iceland screened 399 retail websites and found that 148 used at least one dark pattern, from fake countdown timers to interfaces engineered to steer particular choices (10). The most substantial sector-specific work, though, came from the global standard-setter. In May 2025 the International Organization of Securities Commissions (IOSCO) published a final report devoted to digital engagement practices, part of its retail investor online safety programme and issued alongside reports on finfluencers and online imitative trading (11). IOSCO’s concern was that digital engagement tools can influence investor behaviour, including trading frequency and exposure to riskier products, and it set out good practices on governance, disclosure, monitoring and investor education (11). The concern had not gone away. It had surfaced elsewhere, in IOSCO’s international work and in laws written for the digital economy and consumer finance more broadly.

cpd-CPDs.Academy-Digital-Services-Act-EU
The Digital Services Act Regulation (EU)

Where the binding rules now sit

This is the main change. While sectoral investment regulation hesitated, the EU’s general digital and consumer law moved from discouragement to outright prohibition. Three layers deserve particular attention, alongside the existing MiFID (8), unfair-commercial-practices (12) and data-protection (13) rules.

The Digital Services Act, Regulation (EU) 2022/2065, speaks directly to manipulative interface design. Article 25 forbids providers of online platforms from designing or operating their interfaces so as to deceive or manipulate users, or otherwise to distort or impair their ability to make free and informed decisions (3). Two points are easy to lose. The duty falls on providers of online platforms, a defined category of hosting service that stores and disseminates user-provided information to the public, not on every business that runs a website or an app. A broker’s own trading application will usually sit outside that definition, but not always. An app with social, community, public content-sharing or copy-trading features may itself store and disseminate user-provided information to the public, and the question then needs closer analysis. The second point is the carve-out. Article 25 does not apply where the conduct is already covered by the Unfair Commercial Practices Directive (12) or the General Data Protection Regulation (13), so it fills gaps rather than displacing consumer or data protection law (3). For most investment firms, Article 25 will matter because it binds the online platforms on which they advertise and recruit, where those services fall within the DSA definition.

The Artificial Intelligence Act, Regulation (EU) 2024/1689, reaches further into substance. Article 5 lists prohibited practices, and the first of them captures an AI system that uses subliminal, purposefully manipulative or deceptive techniques to materially distort a person’s behaviour, by appreciably impairing their ability to make an informed decision and causing them to take a decision they would not otherwise have taken, in a way that causes or is reasonably likely to cause significant harm (4). The recitals make plain that significant harm can include sufficiently important adverse impacts on a person’s financial interests (4). This is a prohibition, in force since 2 February 2025, not a statement of good practice. Its limits matter as much as its scope. It applies only where the manipulation runs through an AI system, and only where the harm threshold is met, so it does not convert every nudge, default or personalised prompt into a banned practice. AI-driven personalisation begins to raise an Article 5 question at the point where it materially distorts a retail client’s behaviour, impairs their informed decision-making, and is reasonably likely to lead them into trading that causes them significant financial harm, a decision they would not otherwise have made.

The third layer is consumer law, and it is the one most easily missed, because it is neither a MiFID (8) rule nor a platform-only rule. Directive (EU) 2023/2673 (5), which revises the Consumer Rights Directive, inserts a new Article 16e that prohibits traders, when concluding financial services contracts at a distance, from designing, organising or operating their online interfaces in a way that deceives or manipulates consumers, or otherwise materially distorts or impairs their ability to make free and informed decisions (5). It applies to a firm’s own online contract journey, not only to intermediating platforms, and it reaches conduct that the platform focus of the Digital Services Act (3) does not. It takes effect through national implementing law and applies from 19 June 2026.

Reading the trajectory

What does this ask of a compliance function? Mostly a change of map. The hard limits on manipulative digital design now come substantially from horizontal law rather than from any single MiFID (8) instrument, so a firm that checks its practices only against ESMA material will miss the instruments that now carry the real prohibitions. The product governance guidelines still apply, and remain the right place to weigh gamification in how products are designed and distributed (1). But whether an interface manipulates, whether an AI system has crossed into prohibited territory, and whether an online contract journey complies with the distance-financial-services rules (5) are questions for the Digital Services Act (3), the Artificial Intelligence Act (4) and consumer law, with long-standing unfair commercial practices rules (12) beneath them.

It would be just as much a mistake to read the absence of a dedicated ESMA framework as an absence of expectation. The 2023 guidelines (1) set a standard that still governs distribution decisions, the common supervisory action (6) showed how marketing is examined in practice, and IOSCO’s 2025 work (11) indicates where international good practice is going. Quiet on a new rulebook is not quiet on the underlying conduct.

The most useful exercise is also the most concrete. Match each digital engagement practice to the instrument that actually governs it. Gamified rewards, streaks, celebratory animations or loss framing inside a firm’s own app are, first, a product governance (1) and consumer-protection question. If they form part of an online consumer financial-services contract journey, the distance-financial-services rules (5) may also need to be considered. Manipulative design on third-party platforms is an Article 25 DSA (3) issue for the platform provider, where the platform is in scope, while the investment firm’s own exposure will usually arise through MiFID (8), advertising, consumer-law or contractual obligations. AI-driven steering capable of causing significant financial harm is where the Artificial Intelligence Act (4) prohibition comes into view. Mapping practice to instrument in this way turns a single missing framework into an accurate account of the several that already apply.

Closing thoughts

None of this means the subject went quiet after 2023. The opposite is closer to the truth. The strongest obligations now sit across legislation that was not written specifically for investment services, or not only for investment services, alongside an international standard that has no direct legal force but real persuasive weight, while the sectoral guidance that began the conversation remains in place and still applies. For a firm running retail-facing digital products, the task is unglamorous and exact. It is to know, for each design choice on its own interface and on the platforms it markets through, which regime governs it, and to show that the question has been asked. That, more than the next ESMA paper, is where the exposure now lies.

We hope this article was helpful. For more information from CPDs.Academy, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.

References

(1) European Securities and Markets Authority, Final Report, Guidelines on MiFID II product governance requirements, ESMA35-43-3448, 27 March 2023, in particular the guidance on distribution strategy. The guidelines were published in all EU official languages on 3 August 2023 and applicable from 3 October 2023.

(2) European Securities and Markets Authority, Discussion Paper on MiFID II investor protection topics linked to digitalisation, ESMA35-43-3682, 14 December 2023.

(3) Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services (Digital Services Act), Article 25, read with the definition of online platform in Article 3.

(4) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Article 5, with the prohibited practices applying from 2 February 2025.

(5) Directive (EU) 2023/2673 of the European Parliament and of the Council of 22 November 2023 amending Directive 2011/83/EU as regards financial services contracts concluded at a distance, in particular Article 16e of Directive 2011/83/EU as amended, which applies from 19 June 2026 through national implementing measures.

(6) European Securities and Markets Authority, Final Report on the 2023 Common Supervisory Action, with the accompanying Mystery Shopping Exercise, on the application of MiFID II marketing communication requirements, ESMA35-335435667-5931, 27 May 2024.

(7) European Commission, Retail Investment Strategy, proposal published on 24 May 2023 amending Directive 2014/65/EU (MiFID II) and related directives. The Council and the European Parliament reached a provisional political agreement on 18 December 2025, the Permanent Representatives Committee (Coreper) confirmed the final compromise text on 28 May 2026, and formal adoption remains outstanding.

(8) Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments (MiFID II), as amended.

(9) European Securities and Markets Authority, Report on the retail investor journey, ESMA35-243228190-7410, 12 March 2026.

(10) European Commission and the Consumer Protection Cooperation Network, results of a coordinated website sweep on dark patterns published on 30 January 2023, covering 399 retail websites across 23 Member States, Norway and Iceland, of which 148 displayed at least one dark pattern.

(11) International Organization of Securities Commissions, Digital Engagement Practices, Final Report FR/07/2025, 19 May 2025.

(12) Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market (Unfair Commercial Practices Directive), as amended.

(13) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).