Wellenbrecher

Why a CAPTCHA is an accessibility problem

Two claims keep circulating: that WCAG bans CAPTCHAs, and that a wave of legal warnings followed. Neither holds up. A picture puzzle in front of your contact form is still the weakest answer to the problem it is meant to solve.

Two sentences show up in almost every guide on the subject. First, that WCAG bans CAPTCHAs. Second, that European accessibility law has therefore triggered a wave of legal warnings. The first fails on the wording of the success criteria, the second on the search for documented cases.

The annoying part is that a wrong argument damages a right cause. A picture puzzle in front of a contact form is the weakest available answer to the problem it is meant to solve. No invented prohibition is needed to see that.

What WCAG really says about CAPTCHAs

WCAG 2.2 has been the current version since 12 December 2024 and is a W3C Recommendation. CAPTCHAs appear in two places in it, and those two places get mixed up constantly.

1.1.1 asks for an alternative, not a ban

Success Criterion 1.1.1 Non-text Content sits at level A. For CAPTCHAs it requires "text alternatives that identify and describe the purpose of the non-text content" plus "alternative forms of CAPTCHA using output modes for different types of sensory perception". So: a text alternative saying what the element is for, and at least one further CAPTCHA form addressing a different sensory channel.

An image-only CAPTCHA with no alternative fails 1.1.1, and on a contact form that is the only criterion in play. The W3C spells out how far the exemption reaches: "WCAG still requires that alternative text identify the graphical object as a CAPTCHA."

3.3.8 applies to signing in, not to your contact form

Criterion 3.3.8 Accessible Authentication (Minimum) is new at level AA in WCAG 2.2. Its opening sentence: "A cognitive function test (such as remembering a password or solving a puzzle) is not required for any step in an authentication process unless that step provides at least one of the following." Two words decide the scope, namely "authentication process". A CAPTCHA in front of a contact, comment or newsletter form with no login is not covered, and there 1.1.1 is the whole story.

Even inside a sign-in flow, the W3C Understanding document for 3.3.8 says the opposite of what many guides claim: "While recognizing objects, or a picture the user has previously provided, are cognitive function tests, these are excepted in this criterion at AA level." A "select all images with traffic lights" challenge therefore does not fail 3.3.8 at level AA. Anyone claiming otherwise has not read the criterion.

The exception is not unlimited: arithmetic puzzles drop out as soon as the test goes beyond recognition. And at level AAA the verdict flips, because criterion 3.3.9 keeps only the Alternative and Mechanism exceptions.

In short: a picture puzzle in front of your contact form has a 1.1.1 problem, not a 3.3.8 problem. Conflating the two criteria is the most common mistake in guides on this topic.

Why the audio alternative does not close the gap

The obvious answer to 1.1.1 is the speaker button next to the image. Why that is not enough is set out in the W3C paper "Inaccessibility of CAPTCHA", a Group Draft Note since 16 December 2021 and therefore a draft with no normative force.

Sound has no equivalent of a still image, so a user cannot inspect the challenge at leisure. The study cited in the paper found audio CAPTCHAs unintelligible for all four test subjects, who all had good hearing: the distortion meant to stop machines destroys intelligibility. Audio also excludes deaf users, and anyone with combined sight and hearing loss entirely.

There is a normative point too: under the Understanding document for 3.3.8, an audio alternative that has to be transcribed cannot meet the Alternative exception. The accessible channel is also the weakest security channel, since the W3C paper cites work at the University of Maryland that solved Google audio reCAPTCHA at roughly 90 percent using Google speech recognition. And the WebAIM Screen Reader User Survey #10 (1,539 responses, December 2023 and January 2024) puts CAPTCHA first among the most problematic items, unchanged for 14 years.

What European accessibility law asks for, and who it covers

What follows is an assessment of the legal position as of 21 August 2026, not legal advice. If you need certainty for your own case, take it to a lawyer.

The European Accessibility Act, Directive (EU) 2019/882, covers services provided to consumers from 28 June 2025 onwards. Germany implements it through the BFSG, whose wording makes a useful example: section 2 no. 26 BFSG defines e-commerce services as digital services provided at the individual request of a consumer "with a view to concluding a consumer contract". That clause carries the weight. An online shop meets it, a pure presentation website does not, and the BFSG FAQ of the German federal accessibility agency says the same.

Section 3 (3) BFSG then exempts microenterprises that offer services. Under section 2 no. 17 BFSG that means fewer than ten employees plus either turnover or a balance sheet total of at most 2 million euros. The exemption covers services only: section 1 (2) BFSG lists the covered products exhaustively and they are hardware categories, so a WordPress plugin sold as a download is not a product in the sense of the act.

The CAPTCHA hook sits in the implementing regulation: section 19 no. 2 BFSGV requires identification, authentication, security and payment functions in e-commerce services to be perceivable, operable, understandable and robust. A CAPTCHA is a security function in that sense, and section 12 no. 2 (g) BFSGV adds an alternative presentation of non-text content.

The standard everyone cites is not harmonised under the EAA

As of 21 August 2026, no harmonised standard for the European Accessibility Act was listed in the Official Journal of the European Union. The German federal accessibility agency writes explicitly that the standards foreseen under request M/587 are not yet announced, so there is no presumption of conformity. The much cited harmonisation of EN 301 549 V3.2.1 through Implementing Decision (EU) 2021/1339 relates to the Web Accessibility Directive (EU) 2016/2102 for public sector bodies. Plenty of guides treat the two as one.

The BFSGV never names EN 301 549 anyway, it requires the state of the art. As a side note, the published version V3.2.1 from March 2021 points to WCAG 2.1, so criterion 3.3.8 is not wired into the standard at all.

What the record on fines actually shows

As of 21 August 2026, no fine and no court confirmed legal warning could be found in Germany that specifically concerned an inaccessible CAPTCHA. The responsible body, the market surveillance authority of the German states for accessibility (MLBF) in Magdeburg, has been operating since 26 September 2025 and publishes no case numbers. The range in section 37 (2) BFSG reaches up to one hundred thousand euros.

Law firm sources do document accessibility warning letters since summer 2025, naming CLAIM Rechtsanwalts GmbH of Düsseldorf acting for a private individual, with claims around 595 euros. None of it is CAPTCHA specific, and whether these provisions are enforceable through unfair competition law has not been decided by a court. That is no licence to ignore the issue: a form your prospects cannot get through costs you enquiries regardless of any regulator.

Where the data goes when the CAPTCHA comes from a cloud vendor

Google LLC and Cloudflare, Inc. are US companies. The legal basis for the transfer is the adequacy decision on the EU-US Data Privacy Framework of 10 July 2023. The General Court dismissed the action for annulment on 3 September 2025 in case T-553/23, Latombe v Commission, but the decision is not final: an appeal has been pending since 31 October 2025 as case C-703/25 P. Both vendors are merely self-certified.

Something material changed at Google on 2 April 2026: reCAPTCHA moved to a processor model worldwide, and the customer is now "the sole data controller of Customer Data". Whether that removes the need for consent is open, because German telecoms privacy law ties consent to access to the terminal device, not to the GDPR role. Exactly one decision on reCAPTCHA is cleanly citable so far, and it is Austrian: the Federal Administrative Court there held on 13 September 2024, W298 2274626-1/8E, that reCAPTCHA without prior consent breaches the GDPR.

Cloudflare Turnstile normally does without picture and audio puzzles and called itself "WCAG 2.1 Level AA compliant" in its blog post of 29 September 2023, with the redesign post of 27 February 2026 adding the goal of WCAG 2.2 AAA. Both are vendor statements, and no independent audit report exists for either. The knot sits at the consent banner anyway: if the CAPTCHA needs consent, a visitor who declines cannot get through the form.

Four methods that ask the visitor for nothing

The purpose of a CAPTCHA is bot defence. It sets every visitor a task in order to filter out a small share. For the same purpose there are methods that demand nothing from anyone: the W3C paper names honeypots, heuristics and spam filters.

Honeypot: a field only machines see

The form gets an extra field that is invisible to people. A visitor never fills it in, a bot that blindly populates every field does. If the field is not empty on submit, the decision is made. Implementation matters: a field merely pushed out of the visual area but left in the accessibility tree gets announced by a screen reader, and then catches exactly the people it must not catch. It belongs marked with aria-hidden and out of the tab order. The limit: anyone targeting your site leaves the field alone from then on. Against ordinary mass bots it is reliable.

Time trap: how long filling in took

The form is served with a signed timestamp, and on submit the server compares how much time has passed. Anyone filling a form in under two seconds did not read it. Keep the threshold low, because some visitors autofill in fractions of a second. A bot can wait, but waiting cuts its throughput: the method makes the attack more expensive, not impossible.

Rate limit: how much comes from one source

The server counts submissions arriving from the same source within a time window and rejects beyond a threshold. That handles the single source hammering one form and does nothing against attacks distributed over many addresses. The threshold must not be too tight, because corporate networks and mobile carriers put many people behind one address.

Content scoring: what the message actually says

The fourth route looks at the text. Bayesian classification scores a message against examples previously marked as spam or wanted, and runs entirely on your own server. It also catches promotion a human sent by hand, and it has an error rate. How local scoring differs from a cloud filter is covered in the piece on the Akismet alternative.

MethodEffort for the userAccessibilityWhere data goesAgainst mass botsAgainst targeted attacks
Image CAPTCHASolve a task, put at 32 seconds on average in the W3C paperFails WCAG 1.1.1 without an alternative for another sensory channelTo the vendor, as a rule to the USWorks while the task cannot be solved automaticallyAudio channel solved at roughly 90 percent in the cited study
Invisible CAPTCHA from the cloudUsually noneVendor statement of WCAG 2.1 AA, no independent auditTo the vendor in the US, consent question openWorksNot verifiable, the detection is not disclosed
Honeypot plus time trapNoneUnnoticeable when the field is kept out of the accessibility treeNowhere, everything stays on your own serverWorks against bots that blindly fill every formBypassed by a bot tailored to your site
Local content scoringNoneUnnoticeable, the visitor sees nothingNowhere, everything stays on your own serverWorks, including on promotion sent by handDepends on the text, not on the sender
In short: swapping an image CAPTCHA for an invisible cloud CAPTCHA largely solves the accessibility problem and buys you a consent question instead. Local scoring has neither.

What happens when the filter gets it wrong

Any method that sorts automatically will sort wrongly at some point, in the cloud and locally alike. The question is what happens to a genuine enquiry afterwards. If it is dropped in silence, nobody finds out: the prospect waits for a reply, the operator sees a quiet inbox. Spam protection without a visible holding area is a silent loss of enquiries.

It becomes usable with three things: rejected messages sit in a searchable list, each shows which check flagged it, and a button releases it after the fact and feeds that back into the scoring. If you are rebuilding your form anyway, the field side of the topic is in the piece on Contact Form 7 alternatives.

Spam protection that asks nobody to prove anything

Wellenbrecher runs a honeypot, a time trap, a rate limit and content scoring directly on your own installation. No cloud service, no check quota, no puzzle in front of your form.

View Wellenbrecher

Wellenbrecher has been in the WordPress plugin directory since 21 August 2026 and the free tier covers commercial use too. Pro costs 19 euros a year for one website and adds proof of work, WooCommerce checkout protection, GeoIP and ASN, an AbuseIPDB lookup and an AI second opinion with your own key; the fleet licence for ten websites costs 69 euros. Prices exclude VAT, as of 21 August 2026, overview on the pricing page.

Frequently asked questions

Does WCAG ban CAPTCHAs?

No. Success Criterion 1.1.1 at level A asks for a text alternative describing the purpose of the challenge, plus a CAPTCHA form addressing a different sensory channel. An image CAPTCHA with no alternative at all fails it. An image CAPTCHA with a workable alternative does not.

Does criterion 3.3.8 apply to a contact form with no login?

No. The opening sentence of 3.3.8 refers to steps in an authentication process. A CAPTCHA in front of a contact, comment or newsletter form with no login is outside its scope, and 1.1.1 is the criterion that applies. Inside a sign-in flow, image CAPTCHAs based on plain object recognition are explicitly excepted at level AA under the W3C Understanding document, while at level AAA in criterion 3.3.9 they are not.

Is an audio alternative next to the image enough?

The W3C paper on the inaccessibility of CAPTCHA says no. Sound cannot be examined at leisure the way a still image can, the distortion added to stop machines destroys intelligibility, and deaf and deafblind users are left out entirely. The Understanding document for 3.3.8 also notes that an audio alternative requiring transcription cannot meet the Alternative exception.

Have there been fines or legal warnings over inaccessible CAPTCHAs?

As of 21 August 2026 no fine and no court confirmed legal warning could be found in Germany that specifically concerned an inaccessible CAPTCHA. What is documented are general accessibility warning letters since summer 2025 with claims around 595 euros, none of them CAPTCHA specific. Whether these provisions can be enforced through unfair competition law at all has not been decided by a court. That is not a licence to ignore the issue.

What protects a form when there is no CAPTCHA on it?

Four methods that ask the visitor for nothing: a honeypot field only machines fill in, a time trap that catches submissions arriving too fast, a rate limit against repeated submissions from one source, and content scoring of the message text. Against the ordinary mass bots that combination works. An attack tailored to your specific site gets past the honeypot and the time trap.

Back to blog A post by hafenstudios