The body that writes the accessibility guidelines says the interactive test excludes many disabled people outright. Screen reader users rank it the worst barrier on the web. And the bots it was meant to stop now solve it better than people do. Here is the evidence, the law by jurisdiction, and what to run instead.
If your organization serves the public, your forms are not a conversion funnel. They are how a resident applies for a permit, a patient reaches a clinic, a supporter gives, a student asks for help. The people a CAPTCHA turns away are the people those forms exist for, and the obligation to reach them is written into law rather than left to preference.
We sell an alternative, so read this with that in mind. Every claim below is quoted from or checked against a named primary source, with a link. The section on what the law does not say is there because compliance officers have heard the overstatements, and the case does not need them. None of this is legal advice.
The W3C's Accessible Platform Architectures Working Group maintains a note titled Inaccessibility of CAPTCHA. Its current edition is a Group Draft Note of December 2021, which is the working group's position rather than a W3C Recommendation, and its abstract puts the problem in one sentence:
"Unfortunately the very nature of the interactive task inherently excludes many people with disabilities, resulting in a denial of service to these users."
Not badly built CAPTCHAs: the task itself. The same note states the working group's preference without hedging — "All else being equal, we prefer non-interactive approaches because these pose no accessibility challenges" — and records that whenever an interactive CAPTCHA is used, "a variety of alternative challenges must be made available to engage different sensory and cognitive capabilities of the user." It also reaches a conclusion about security that a public body cannot ignore: traditional CAPTCHA "is increasingly insecure and arguably now ill suited to the purpose of distinguishing human individuals from their robotic impersonators."
For what WCAG itself requires of a CAPTCHA, and where implementations fail it, see is reCAPTCHA accessible? This page takes that as read and asks the next question: given all of this, why run one at all?
The standards position is backed by people who were asked, and by people who were tested.
The groups below are the ones the sources document, with the CAPTCHA type each is tied to. The barriers for attention, memory and executive function are described by function rather than by diagnosis, because that is how the W3C describes them and because no study recruits participants by those diagnoses. Motor impairment is widely reported for small tiles and sliders but is not in these particular sources, so it is not in this table.
| Who | CAPTCHA type | What the source says | Source |
|---|---|---|---|
| Blind and low-vision | Character and image tests | The screen readers they rely on "cannot process the image, thus preventing them from uncovering the information required by the form." | W3C, Inaccessibility of CAPTCHA |
| Dyslexia | Distorted text | Identifying characters in a distorted graphic asks them "to perform a task they are intrinsically least able to accomplish." | W3C, Inaccessibility of CAPTCHA |
| Learning disabilities | Distorted text most of all | More failed attempts and more negative attitudes than other users; solving speed was not different. Controlled study, 212 users, 60 with learning disabilities. | Gafni & Nagar, 2016 |
| Dyscalculia | Arithmetic puzzles | "An individual living with dyscalculia will understandably find even simple arithmetic puzzles challenging." | W3C, Inaccessibility of CAPTCHA |
| Language, learning and cognitive disabilities | Logic puzzles | Logic puzzles as a CAPTCHA "introduce substantial barriers to access for people with language, learning or cognitive disabilities." | W3C, Inaccessibility of CAPTCHA |
| Anxiety disorders | Any design that expects retries | A pattern "that expects multiple attempts from users as a matter of course is arguably inaccessible by design." | W3C, Inaccessibility of CAPTCHA |
| Visual processing disorders | Image comparison | Image-comparison tests are "very difficult for people living with visual processing disorders, among other cognitive and learning disabilities." | W3C, Inaccessibility of CAPTCHA |
| Deaf, hard of hearing, auditory processing disorder | Audio | Transcribing an audio CAPTCHA asks them "to perform a task they're intrinsically least likely to accomplish." | W3C, Inaccessibility of CAPTCHA |
| Deaf-blind | Visual and audio | Neither mode is usable: such users "are thus also prevented from proceeding." | W3C, Inaccessibility of CAPTCHA |
| Cognitive disabilities generally | Audio | May "find audio CAPTCHAs even more difficult to solve than character-based visual CAPTCHAs." | W3C, Inaccessibility of CAPTCHA |
| Memory, executive-function and attention limitations | Transcription, timed and multi-step tests | May need "to look at or listen to text several times to copy or type it," may not "complete a timed procedure," and lose focus through "frustration with time-limited procedures." | W3C Cognitive Accessibility Task Force (background; marked out of date by its authors) |
| Non-English speakers | English text and audio | Traditional CAPTCHAs make the test "inaccessible to a large number of non-English speaking web users worldwide"; measured as slower overall and less accurate on English-centric schemes. | W3C note; Bursztein et al., 2010 |
| Older adults | All types | Solving time rose by an average of 0.09 seconds per year of age across all CAPTCHA types tested. | Searles et al., USENIX Security 2023 |
| Anyone on a small screen or in a noisy room | Visual on mobile; audio anywhere loud | The note extends the barrier to "situational disabilities" on small screens and in noisy environments. | W3C, Inaccessibility of CAPTCHA |
The W3C adds that a design expecting multiple attempts "as a matter of course" is "arguably inaccessible by design" not only for anxiety disorders but for "many living with a range of other cognitive and learning disabilities." Offering two versions of a test narrows the set of people excluded. It does not empty it.
A control that excludes people might still be defended if it worked. The most thorough recent measurement says it does not. Searles and colleagues' An Empirical Study & Evaluation of Modern CAPTCHAs (USENIX Security 2023) had 1,400 participants solve 14,000 CAPTCHAs of the types in current deployment, then set the human results beside published results for automated solvers.
| CAPTCHA type | Humans: time, accuracy | Bots: time, accuracy |
|---|---|---|
| Distorted text | 9 to 15 seconds, 50 to 84% | Under 1 second, 99.8% |
| reCAPTCHA checkbox | 3.1 to 4.9 seconds, 71 to 85% | 1.4 seconds, 100% |
| reCAPTCHA image grid | 15 to 26 seconds, 81% | 17.5 seconds, 85% |
| hCaptcha | 18 to 32 seconds, 71 to 81% | 14.9 seconds, 98% |
Table 3 of the paper, human figures from its own study and bot figures from the prior work it cites. The authors' conclusion: the results "suggest that bots can outperform humans, both in terms of solving time and accuracy, across all these CAPTCHA types."
The same paper notes that bots "often outsource solving to CAPTCHA farms," where people are paid to solve them, and that automated tools passed 99% accuracy on distorted text by 2014. So the gate lets the automation through and charges the public for it. The W3C note, citing Cloudflare's data, puts the charge at "an average of 32 seconds" per CAPTCHA. And some people simply leave: in the USENIX study's abandonment experiment, 174 of 574 participants who started a task containing a CAPTCHA quit before finishing it, a 30% rate. Those were paid participants on Amazon Mechanical Turk, not members of the public with a permit to file, so quote the figure with that context. What the published research does and does not show about conversion is laid out in what CAPTCHAs cost in conversion.
None of these instruments names CAPTCHAs. Each incorporates WCAG, so the operative rules are the two WCAG criteria in the first rows, and the jurisdiction rows say which WCAG version applies to whom and from when. Verified against the primary texts in October 2026; this is a summary, not legal advice, and your own obligations depend on your sector and jurisdiction.
| Rule | Who it covers | What it requires | What that means for a CAPTCHA |
|---|---|---|---|
| WCAG 2.1 and 2.2, Success Criterion 1.1.1 (Level A) | Any site claiming WCAG conformance; the criterion every law below incorporates | A CAPTCHA is allowed if "text alternatives that identify and describe the purpose of the non-text content are provided, and alternative forms of CAPTCHA using output modes for different types of sensory perception are provided." | A visual-only CAPTCHA fails it everywhere. One with a described purpose and an audio version passes it everywhere. |
| WCAG 2.2, Success Criterion 3.3.8 Accessible Authentication (Level AA) | Any step of an authentication process, under any rule that cites WCAG 2.2 | No step may require a cognitive function test ("remember, manipulate, or transcribe information": memorizing, transcribing, spelling, calculating, "solving of puzzles") unless an alternative or an assistive mechanism exists. Object recognition and personal content are exempt at AA; the AAA criterion, 3.3.9, removes both exemptions. | Login only, not contact forms. An audio CAPTCHA the user must transcribe "cannot be used to meet the Alternative exception." Of the object-recognition exemption, the W3C says such techniques "do not fully support the cognitive accessibility community and should be avoided if possible." |
| Canada: Ontario AODA, and the Accessible Canada Regulations | Ontario designated public sector and organizations with 50 or more employees; federally, the public sector and regulated businesses | Ontario requires "WCAG 2.0 Level AA success criteria" since January 1, 2021. Federal rules are moving to CAN/ASC-EN 301 549, in force from December 2027 for the public sector. | WCAG 2.0 for Ontario means SC 1.1.1 applies and SC 3.3.8 does not. |
| United States: ADA Title II web rule (28 CFR part 35, subpart H) | State and local governments, their agencies, and special district governments | WCAG 2.1 Level AA "is the technical standard for state and local governments' web content and mobile apps." | Compliance by April 26, 2027 for governments serving 50,000 or more people, and April 26, 2028 for smaller ones and special districts, after an interim final rule in April 2026 extended both dates by a year. |
| United States: Section 508 (Revised 508 Standards) | Federal agencies and the ICT they procure, develop, maintain or use | WCAG 2.0 Level A and AA success criteria, incorporated by reference, in force since January 18, 2018. | Still WCAG 2.0, so SC 1.1.1 applies and SC 3.3.8 does not. |
| United States: ADA Title III | Businesses open to the public, including most nonprofits | No codified technical standard: the Department of Justice "does not have a regulation setting out detailed standards," and relies on the general nondiscrimination obligation, with WCAG cited as guidance. | Litigation and settlements commonly reference WCAG 2.1 AA, but that is not a rule. |
| United Kingdom: Public Sector Bodies Accessibility Regulations 2018 | All public sector bodies unless exempt | The regulations state the requirement generically; the Government Digital Service monitors against WCAG 2.2 AA, and "monitoring from October 2024 onwards uses WCAG 2.2." | SC 3.3.8 is therefore live for UK public sector logins. |
| European Union: Web Accessibility Directive (EU) 2016/2102 | Public sector bodies' websites and mobile apps | Presumption of conformity through the harmonised standard EN 301 549 V3.2.1, which "reflects the content of the W3C WCAG 2.1 Recommendation." | WCAG 2.1 AA remains the cited baseline until the 2026 version of EN 301 549 is cited in the Official Journal. |
| European Union: European Accessibility Act, Directive (EU) 2019/882 | Covered products and consumer services, applying "from 28 June 2025" | Functional requirements with a presumption of conformity through harmonised standards. EN 301 549 V4.1.1, published September 2026, has clauses "updated to align with the WCAG 2.2 recommendation." | As of this writing V4.1.1 has not been cited in the Official Journal; Ireland's National Disability Authority expects citation in December 2026. Until then, WCAG 2.2 is where the standard is going, not where the law is. |
A visual CAPTCHA with a described purpose and an audio alternative can pass SC 1.1.1 on paper. The W3C's own note, WebAIM's respondents and the deaf-blind row of the table above say what that paper pass is worth. Where WCAG 2.2 applies, a puzzle or transcription test at login already needs a non-cognitive alternative, and the W3C says the object-recognition exemption "should be avoided if possible." The direction of travel is one way.
Five claims circulate on vendor pages, including, until we checked, some of ours. None of them survives contact with the primary source, and a compliance reader who has seen them will discount everything near them.
| The claim | The problem | What holds up |
|---|---|---|
| "CAPTCHAs are banned by WCAG" or "a CAPTCHA automatically fails an audit" | WCAG permits CAPTCHAs with alternatives. SC 3.3.8 covers login only and exempts object recognition at AA. | "Puzzle, transcription and arithmetic CAPTCHAs at login need a non-cognitive alternative under WCAG 2.2 AA; a visual-only CAPTCHA fails SC 1.1.1 under every version." |
| "The European Accessibility Act requires WCAG 2.2 today" | The 2026 edition of EN 301 549 aligns with WCAG 2.2, but it has not been cited in the Official Journal yet. | "The EU's accessibility standard now aligns with WCAG 2.2 and is expected to take legal effect once cited, which Ireland's National Disability Authority expects in December 2026." |
| "A Stanford study showed CAPTCHAs cut conversions by a large percentage" | The 2010 Stanford evaluation measured solving accuracy and speed, not conversions. No primary source for the conversion figure has been traced. | "In a 2023 USENIX Security study, 30% of paid participants abandoned a task that included a CAPTCHA." |
| "30% of your customers abandon because of CAPTCHA" | The figure comes from paid study participants on Amazon Mechanical Turk, and ran from 18% to 45% depending on how the task was framed and paid. | The same sentence, with its context attached. |
| "Studies show users with specific attention or developmental diagnoses fail CAPTCHAs" | No peer-reviewed study recruits participants by those diagnoses. What exists describes barriers by function. | "The W3C documents CAPTCHA barriers for people with attention, memory and executive-function limitations." |
The W3C note is as careful about replacements as it is about CAPTCHAs, and its concerns give a public body three questions to put to any vendor, us included.
The approaches the note lists as reducing or removing the interactive challenge are spam filtering, proof-of-work, heuristics, honeypots, limited-use accounts and privacy-preserving tokens. An even-handed comparison of the current options, including the free ones and our competitors, is at CAPTCHA alternatives. One trap to know about: a honeypot field hidden only with CSS is still announced to a screen reader, whose user fills it in and is silently rejected. See honeypot vs CAPTCHA for the fix.
SpamKill sets the visitor no test. Every protected form is rendered twice: a clean version for people, including anyone on assistive technology, and an obfuscated version aimed at automated parsers. Detection runs on how the submission was composed, after the visitor has typed everything, at 99.9% accuracy across more than 100M+ submissions screened for 1,500+ businesses. When we are unsure about a real person, they confirm with a standard social or device sign-in, in any of 13 languages: nothing to transcribe, solve or beat a clock on. If they skip it, the submission is held with everything they typed rather than discarded, and on the Professional plan and up you can review it and release it.
What we do not claim: a conformance level, for your site or for ours. "No challenge to fail" is a design property, not an audit result, and your site's conformance is yours to test. What we collect and how long we keep it is on the privacy page. And whatever you choose, run one gate, not two: a CAPTCHA kept "just in case" alongside any of the approaches above puts every excluded group right back where they were.
Nonprofits get 20% off every plan, verified against the public register. From $29/month with a 30-day free trial, no credit card.
In every jurisdiction on this page, yes, on conditions. WCAG Success Criterion 1.1.1 allows a CAPTCHA if its purpose is described in text and an alternative form using a different sense is offered, and WCAG 2.2 adds that a puzzle or transcription test at login needs a non-cognitive alternative. The question for a public body is not whether a CAPTCHA is permitted but whether a test the standards body says excludes many disabled people is a defensible choice when non-interactive options exist and the test no longer stops the bots it was meant to.
It removes the visible challenge for most visitors, which is a real improvement. But it returns a score, and the W3C notes that what happens in response to an ambiguous score is in the hands of the content provider, which in practice means a puzzle for the visitors who score low: assistive technology, older devices, privacy tools. The W3C also warns that non-interactive approaches can come at the price of exposing data about the individual user, and a public body has to weigh that trade on behalf of the public.
No. There is no puzzle, nothing to transcribe or solve, and no timer. Detection runs on how the form was filled in, after the visitor has typed everything. In the minority of cases where we are unsure about a real person, they confirm with a standard social or device sign-in, in any of 13 languages, and continue. If they skip it, the submission is held with everything they typed rather than discarded, and on the Professional plan and up you can review and release it.
Only this: there is no challenge for a visitor to fail. Screen readers and other assistive technology receive the clean version of the form, because the obfuscated version is aimed at automated parsers, not at people. We do not claim a conformance level for your site or for ours, and we would rather you test on your own forms than take our word for it.
Yes. Registered charities, 501(c)(3) organizations, schools, libraries and NGOs get 20% off every plan for as long as they are a nonprofit. Tell us your registration or EIN number, we verify it against the public register within one business day, and the discount comes off every invoice from then on.
The W3C pages were read in full. Study findings come from the published papers and abstracts. Legal rows were checked against the primary instrument or the responsible agency's own page.
Standards
Law
Studies and surveys
Thirty days, every feature, no card. Or paste a form into the Form Transformer first and see the protected version with nothing for a visitor to fail.
Start the 30-day free trial