For government, nonprofit and regulated sites

CAPTCHA accessibility: a public-facing form should never carry one.

The body that writes the accessibility guidelines says the interactive test excludes many disabled people outright. Screen reader users rank it the worst barrier on the web. And the bots it was meant to stop now solve it better than people do. Here is the evidence, the law by jurisdiction, and what to run instead.

Updated October 2026 · 12 min read · Sourced

If your organization serves the public, your forms are not a conversion funnel. They are how a resident applies for a permit, a patient reaches a clinic, a supporter gives, a student asks for help. The people a CAPTCHA turns away are the people those forms exist for, and the obligation to reach them is written into law rather than left to preference.

We sell an alternative, so read this with that in mind. Every claim below is quoted from or checked against a named primary source, with a link. The section on what the law does not say is there because compliance officers have heard the overstatements, and the case does not need them. None of this is legal advice.

What the standards body says

The W3C's Accessible Platform Architectures Working Group maintains a note titled Inaccessibility of CAPTCHA. Its current edition is a Group Draft Note of December 2021, which is the working group's position rather than a W3C Recommendation, and its abstract puts the problem in one sentence:

The line that matters

"Unfortunately the very nature of the interactive task inherently excludes many people with disabilities, resulting in a denial of service to these users."

Not badly built CAPTCHAs: the task itself. The same note states the working group's preference without hedging — "All else being equal, we prefer non-interactive approaches because these pose no accessibility challenges" — and records that whenever an interactive CAPTCHA is used, "a variety of alternative challenges must be made available to engage different sensory and cognitive capabilities of the user." It also reaches a conclusion about security that a public body cannot ignore: traditional CAPTCHA "is increasingly insecure and arguably now ill suited to the purpose of distinguishing human individuals from their robotic impersonators."

For what WCAG itself requires of a CAPTCHA, and where implementations fail it, see is reCAPTCHA accessible? This page takes that as read and asks the next question: given all of this, why run one at all?

It is measured, not asserted

The standards position is backed by people who were asked, and by people who were tested.

Who a CAPTCHA excludes

The groups below are the ones the sources document, with the CAPTCHA type each is tied to. The barriers for attention, memory and executive function are described by function rather than by diagnosis, because that is how the W3C describes them and because no study recruits participants by those diagnoses. Motor impairment is widely reported for small tiles and sliders but is not in these particular sources, so it is not in this table.

WhoCAPTCHA typeWhat the source saysSource
Blind and low-vision Character and image tests The screen readers they rely on "cannot process the image, thus preventing them from uncovering the information required by the form." W3C, Inaccessibility of CAPTCHA
Dyslexia Distorted text Identifying characters in a distorted graphic asks them "to perform a task they are intrinsically least able to accomplish." W3C, Inaccessibility of CAPTCHA
Learning disabilities Distorted text most of all More failed attempts and more negative attitudes than other users; solving speed was not different. Controlled study, 212 users, 60 with learning disabilities. Gafni & Nagar, 2016
Dyscalculia Arithmetic puzzles "An individual living with dyscalculia will understandably find even simple arithmetic puzzles challenging." W3C, Inaccessibility of CAPTCHA
Language, learning and cognitive disabilities Logic puzzles Logic puzzles as a CAPTCHA "introduce substantial barriers to access for people with language, learning or cognitive disabilities." W3C, Inaccessibility of CAPTCHA
Anxiety disorders Any design that expects retries A pattern "that expects multiple attempts from users as a matter of course is arguably inaccessible by design." W3C, Inaccessibility of CAPTCHA
Visual processing disorders Image comparison Image-comparison tests are "very difficult for people living with visual processing disorders, among other cognitive and learning disabilities." W3C, Inaccessibility of CAPTCHA
Deaf, hard of hearing, auditory processing disorder Audio Transcribing an audio CAPTCHA asks them "to perform a task they're intrinsically least likely to accomplish." W3C, Inaccessibility of CAPTCHA
Deaf-blind Visual and audio Neither mode is usable: such users "are thus also prevented from proceeding." W3C, Inaccessibility of CAPTCHA
Cognitive disabilities generally Audio May "find audio CAPTCHAs even more difficult to solve than character-based visual CAPTCHAs." W3C, Inaccessibility of CAPTCHA
Memory, executive-function and attention limitations Transcription, timed and multi-step tests May need "to look at or listen to text several times to copy or type it," may not "complete a timed procedure," and lose focus through "frustration with time-limited procedures." W3C Cognitive Accessibility Task Force (background; marked out of date by its authors)
Non-English speakers English text and audio Traditional CAPTCHAs make the test "inaccessible to a large number of non-English speaking web users worldwide"; measured as slower overall and less accurate on English-centric schemes. W3C note; Bursztein et al., 2010
Older adults All types Solving time rose by an average of 0.09 seconds per year of age across all CAPTCHA types tested. Searles et al., USENIX Security 2023
Anyone on a small screen or in a noisy room Visual on mobile; audio anywhere loud The note extends the barrier to "situational disabilities" on small screens and in noisy environments. W3C, Inaccessibility of CAPTCHA

The W3C adds that a design expecting multiple attempts "as a matter of course" is "arguably inaccessible by design" not only for anxiety disorders but for "many living with a range of other cognitive and learning disabilities." Offering two versions of a test narrows the set of people excluded. It does not empty it.

It no longer does the job

A control that excludes people might still be defended if it worked. The most thorough recent measurement says it does not. Searles and colleagues' An Empirical Study & Evaluation of Modern CAPTCHAs (USENIX Security 2023) had 1,400 participants solve 14,000 CAPTCHAs of the types in current deployment, then set the human results beside published results for automated solvers.

CAPTCHA typeHumans: time, accuracyBots: time, accuracy
Distorted text9 to 15 seconds, 50 to 84%Under 1 second, 99.8%
reCAPTCHA checkbox3.1 to 4.9 seconds, 71 to 85%1.4 seconds, 100%
reCAPTCHA image grid15 to 26 seconds, 81%17.5 seconds, 85%
hCaptcha18 to 32 seconds, 71 to 81%14.9 seconds, 98%

Table 3 of the paper, human figures from its own study and bot figures from the prior work it cites. The authors' conclusion: the results "suggest that bots can outperform humans, both in terms of solving time and accuracy, across all these CAPTCHA types."

The same paper notes that bots "often outsource solving to CAPTCHA farms," where people are paid to solve them, and that automated tools passed 99% accuracy on distorted text by 2014. So the gate lets the automation through and charges the public for it. The W3C note, citing Cloudflare's data, puts the charge at "an average of 32 seconds" per CAPTCHA. And some people simply leave: in the USENIX study's abandonment experiment, 174 of 574 participants who started a task containing a CAPTCHA quit before finishing it, a 30% rate. Those were paid participants on Amazon Mechanical Turk, not members of the public with a permit to file, so quote the figure with that context. What the published research does and does not show about conversion is laid out in what CAPTCHAs cost in conversion.

What the law requires, by jurisdiction

None of these instruments names CAPTCHAs. Each incorporates WCAG, so the operative rules are the two WCAG criteria in the first rows, and the jurisdiction rows say which WCAG version applies to whom and from when. Verified against the primary texts in October 2026; this is a summary, not legal advice, and your own obligations depend on your sector and jurisdiction.

RuleWho it coversWhat it requiresWhat that means for a CAPTCHA
WCAG 2.1 and 2.2, Success Criterion 1.1.1 (Level A) Any site claiming WCAG conformance; the criterion every law below incorporates A CAPTCHA is allowed if "text alternatives that identify and describe the purpose of the non-text content are provided, and alternative forms of CAPTCHA using output modes for different types of sensory perception are provided." A visual-only CAPTCHA fails it everywhere. One with a described purpose and an audio version passes it everywhere.
WCAG 2.2, Success Criterion 3.3.8 Accessible Authentication (Level AA) Any step of an authentication process, under any rule that cites WCAG 2.2 No step may require a cognitive function test ("remember, manipulate, or transcribe information": memorizing, transcribing, spelling, calculating, "solving of puzzles") unless an alternative or an assistive mechanism exists. Object recognition and personal content are exempt at AA; the AAA criterion, 3.3.9, removes both exemptions. Login only, not contact forms. An audio CAPTCHA the user must transcribe "cannot be used to meet the Alternative exception." Of the object-recognition exemption, the W3C says such techniques "do not fully support the cognitive accessibility community and should be avoided if possible."
Canada: Ontario AODA, and the Accessible Canada Regulations Ontario designated public sector and organizations with 50 or more employees; federally, the public sector and regulated businesses Ontario requires "WCAG 2.0 Level AA success criteria" since January 1, 2021. Federal rules are moving to CAN/ASC-EN 301 549, in force from December 2027 for the public sector. WCAG 2.0 for Ontario means SC 1.1.1 applies and SC 3.3.8 does not.
United States: ADA Title II web rule (28 CFR part 35, subpart H) State and local governments, their agencies, and special district governments WCAG 2.1 Level AA "is the technical standard for state and local governments' web content and mobile apps." Compliance by April 26, 2027 for governments serving 50,000 or more people, and April 26, 2028 for smaller ones and special districts, after an interim final rule in April 2026 extended both dates by a year.
United States: Section 508 (Revised 508 Standards) Federal agencies and the ICT they procure, develop, maintain or use WCAG 2.0 Level A and AA success criteria, incorporated by reference, in force since January 18, 2018. Still WCAG 2.0, so SC 1.1.1 applies and SC 3.3.8 does not.
United States: ADA Title III Businesses open to the public, including most nonprofits No codified technical standard: the Department of Justice "does not have a regulation setting out detailed standards," and relies on the general nondiscrimination obligation, with WCAG cited as guidance. Litigation and settlements commonly reference WCAG 2.1 AA, but that is not a rule.
United Kingdom: Public Sector Bodies Accessibility Regulations 2018 All public sector bodies unless exempt The regulations state the requirement generically; the Government Digital Service monitors against WCAG 2.2 AA, and "monitoring from October 2024 onwards uses WCAG 2.2." SC 3.3.8 is therefore live for UK public sector logins.
European Union: Web Accessibility Directive (EU) 2016/2102 Public sector bodies' websites and mobile apps Presumption of conformity through the harmonised standard EN 301 549 V3.2.1, which "reflects the content of the W3C WCAG 2.1 Recommendation." WCAG 2.1 AA remains the cited baseline until the 2026 version of EN 301 549 is cited in the Official Journal.
European Union: European Accessibility Act, Directive (EU) 2019/882 Covered products and consumer services, applying "from 28 June 2025" Functional requirements with a presumption of conformity through harmonised standards. EN 301 549 V4.1.1, published September 2026, has clauses "updated to align with the WCAG 2.2 recommendation." As of this writing V4.1.1 has not been cited in the Official Journal; Ireland's National Disability Authority expects citation in December 2026. Until then, WCAG 2.2 is where the standard is going, not where the law is.
The practical reading

A visual CAPTCHA with a described purpose and an audio alternative can pass SC 1.1.1 on paper. The W3C's own note, WebAIM's respondents and the deaf-blind row of the table above say what that paper pass is worth. Where WCAG 2.2 applies, a puzzle or transcription test at login already needs a non-cognitive alternative, and the W3C says the object-recognition exemption "should be avoided if possible." The direction of travel is one way.

What the law does not say

Five claims circulate on vendor pages, including, until we checked, some of ours. None of them survives contact with the primary source, and a compliance reader who has seen them will discount everything near them.

The claimThe problemWhat holds up
"CAPTCHAs are banned by WCAG" or "a CAPTCHA automatically fails an audit" WCAG permits CAPTCHAs with alternatives. SC 3.3.8 covers login only and exempts object recognition at AA. "Puzzle, transcription and arithmetic CAPTCHAs at login need a non-cognitive alternative under WCAG 2.2 AA; a visual-only CAPTCHA fails SC 1.1.1 under every version."
"The European Accessibility Act requires WCAG 2.2 today" The 2026 edition of EN 301 549 aligns with WCAG 2.2, but it has not been cited in the Official Journal yet. "The EU's accessibility standard now aligns with WCAG 2.2 and is expected to take legal effect once cited, which Ireland's National Disability Authority expects in December 2026."
"A Stanford study showed CAPTCHAs cut conversions by a large percentage" The 2010 Stanford evaluation measured solving accuracy and speed, not conversions. No primary source for the conversion figure has been traced. "In a 2023 USENIX Security study, 30% of paid participants abandoned a task that included a CAPTCHA."
"30% of your customers abandon because of CAPTCHA" The figure comes from paid study participants on Amazon Mechanical Turk, and ran from 18% to 45% depending on how the task was framed and paid. The same sentence, with its context attached.
"Studies show users with specific attention or developmental diagnoses fail CAPTCHAs" No peer-reviewed study recruits participants by those diagnoses. What exists describes barriers by function. "The W3C documents CAPTCHA barriers for people with attention, memory and executive-function limitations."

What to run instead has to pass the same tests

The W3C note is as careful about replacements as it is about CAPTCHAs, and its concerns give a public body three questions to put to any vendor, us included.

  1. Is it non-interactive? "All else being equal, we prefer non-interactive approaches because these pose no accessibility challenges." If a real person ever has to prove they are human, the accessibility question has not gone away, only moved.
  2. What does it collect, and from whom? The note warns that some non-interactive approaches "come at the price of exposing much data about the individual user," and that deployers "are participating in exposing their users to a massive collection of personal data across multiple trans-national data profiling systems." A score-based CAPTCHA from an advertising company is the example it has in mind. For a public body, that data belongs to the public.
  3. What happens when it is unsure? Of reCAPTCHA v3, the note observes that "what action is taken in response to an ambiguous score returned by v3 is in the hands of the content provider." In practice that action is a puzzle, served to exactly the visitors least able to complete one: assistive technology, older devices, privacy tools, unusual browsers.

The approaches the note lists as reducing or removing the interactive challenge are spam filtering, proof-of-work, heuristics, honeypots, limited-use accounts and privacy-preserving tokens. An even-handed comparison of the current options, including the free ones and our competitors, is at CAPTCHA alternatives. One trap to know about: a honeypot field hidden only with CSS is still announced to a screen reader, whose user fills it in and is silently rejected. See honeypot vs CAPTCHA for the fix.

Where SpamKill fits, and what we do not claim

SpamKill sets the visitor no test. Every protected form is rendered twice: a clean version for people, including anyone on assistive technology, and an obfuscated version aimed at automated parsers. Detection runs on how the submission was composed, after the visitor has typed everything, at 99.9% accuracy across more than 100M+ submissions screened for 1,500+ businesses. When we are unsure about a real person, they confirm with a standard social or device sign-in, in any of 13 languages: nothing to transcribe, solve or beat a clock on. If they skip it, the submission is held with everything they typed rather than discarded, and on the Professional plan and up you can review it and release it.

What we do not claim: a conformance level, for your site or for ours. "No challenge to fail" is a design property, not an audit result, and your site's conformance is yours to test. What we collect and how long we keep it is on the privacy page. And whatever you choose, run one gate, not two: a CAPTCHA kept "just in case" alongside any of the approaches above puts every excluded group right back where they were.

Nonprofits get 20% off every plan, verified against the public register. From $29/month with a 30-day free trial, no credit card.

Frequently asked questions

Can a government or nonprofit website legally use a CAPTCHA?

In every jurisdiction on this page, yes, on conditions. WCAG Success Criterion 1.1.1 allows a CAPTCHA if its purpose is described in text and an alternative form using a different sense is offered, and WCAG 2.2 adds that a puzzle or transcription test at login needs a non-cognitive alternative. The question for a public body is not whether a CAPTCHA is permitted but whether a test the standards body says excludes many disabled people is a defensible choice when non-interactive options exist and the test no longer stops the bots it was meant to.

Does invisible reCAPTCHA solve the accessibility problem?

It removes the visible challenge for most visitors, which is a real improvement. But it returns a score, and the W3C notes that what happens in response to an ambiguous score is in the hands of the content provider, which in practice means a puzzle for the visitors who score low: assistive technology, older devices, privacy tools. The W3C also warns that non-interactive approaches can come at the price of exposing data about the individual user, and a public body has to weigh that trade on behalf of the public.

Is the SpamKill verification step a CAPTCHA?

No. There is no puzzle, nothing to transcribe or solve, and no timer. Detection runs on how the form was filled in, after the visitor has typed everything. In the minority of cases where we are unsure about a real person, they confirm with a standard social or device sign-in, in any of 13 languages, and continue. If they skip it, the submission is held with everything they typed rather than discarded, and on the Professional plan and up you can review and release it.

What does SpamKill claim about its own accessibility?

Only this: there is no challenge for a visitor to fail. Screen readers and other assistive technology receive the clean version of the form, because the obfuscated version is aimed at automated parsers, not at people. We do not claim a conformance level for your site or for ours, and we would rather you test on your own forms than take our word for it.

We are a nonprofit. Is there a discount?

Yes. Registered charities, 501(c)(3) organizations, schools, libraries and NGOs get 20% off every plan for as long as they are a nonprofit. Tell us your registration or EIN number, we verify it against the public register within one business day, and the discount comes off every invoice from then on.

Sources

The W3C pages were read in full. Study findings come from the published papers and abstracts. Legal rows were checked against the primary instrument or the responsible agency's own page.

Standards

Law

Studies and surveys

Take the test off your forms

Thirty days, every feature, no card. Or paste a form into the Form Transformer first and see the protected version with nothing for a visitor to fail.

Start the 30-day free trial

Talk to Sales — 20 min  ·  Open the Form Transformer