Prohibited AI practices under Article 5: the 8 practices banned outright
In short
Article 5 sets out the only category of AI use the Act treats as unacceptable rather than regulated: practices no risk-mitigation measure, documentation package, or conformity assessment can make lawful. These prohibitions have applied since 2 February 2025 (the first part of the Act to take effect) and breaching them carries the Act’s highest penalty tier, up to €35 million or 7% of worldwide annual turnover, whichever is higher.
The eight prohibited practices
- Subliminal, manipulative, or deceptive techniques (Art. 5(1)(a)) that materially distort a person’s behaviour in a way that causes or is reasonably likely to cause significant harm.
- Exploiting vulnerabilities (Art. 5(1)(b)) due to age, disability, or a specific social or economic situation, to materially distort behaviour and cause harm.
- Social scoring (Art. 5(1)(c)), evaluating or classifying people based on social behaviour or predicted characteristics, leading to detrimental or unjustified treatment, including in contexts unrelated to where the data was originally generated.
- Predicting an individual’s risk of committing a crime (Art. 5(1)(d)) based solely on profiling or assessing personality traits, without objective, verifiable facts directly linked to a criminal activity.
- Untargeted scraping of facial images (Art. 5(1)(e)) from the internet or CCTV footage to build or expand facial recognition databases.
- Emotion recognition in the workplace or education institutions (Art. 5(1)(f)), except where used strictly for medical or safety reasons.
- Biometric categorisation inferring protected attributes (Art. 5(1)(g)) (race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation) from biometric data, with a narrow law-enforcement exception for lawfully acquired biometric datasets.
- Real-time remote biometric identification in publicly accessible spaces for law enforcement (Art. 5(1)(h)), except for narrowly defined purposes such as searching for a specific missing person, preventing an imminent threat to life, or identifying a suspect in a serious crime.
Why 'materially distort behaviour and cause harm' matters
Practices (a) and (b) are not blanket bans on persuasive or targeted design, they require the specific combination of material behavioural distortion and resulting (or reasonably likely) significant harm. A recommendation engine or personalised advertising system is not automatically caught; whether it crosses the line is a fact-specific assessment that typically warrants legal review rather than a self-certified conclusion.
The law-enforcement exceptions are narrow, not general
Both the real-time biometric identification ban (h) and the biometric categorisation ban (g) carry law-enforcement exceptions, but they are deliberately narrow: they require prior authorisation, apply only to the specific purposes listed in the Act, and do not extend to general public-safety or private-sector use. Assuming a “security” justification qualifies without checking the exact wording of Art. 5(2)-(7) is one of the most common ways organisations misjudge their exposure here.
Prohibited status overrides any high-risk classification
If a system matches both a prohibited practice and a high-risk criterion under Annex III, the prohibition controls, there is no partial compliance path through the high-risk obligations (Articles 9-15) that rescues an otherwise-banned use case. This is why prohibited-practice screening should always happen before, and independently of, high-risk classification.
Because several of these lines (“detrimental or unjustified treatment,” “materially distort behaviour,” the scope of the law-enforcement exceptions) are genuine legal judgment calls rather than simple yes/no facts, a system that plausibly touches Article 5 deserves specific legal confirmation before you conclude it is safe, rather than a self-assessment against the bullet points above.
Frequently asked questions
- When did the EU AI Act's prohibitions take effect?
- The Article 5 prohibitions have applied since 2 February 2025, the first part of the Act to take effect.
- What is the penalty for a prohibited AI practice?
- Breaching an Article 5 prohibition carries the Act's highest penalty tier: up to €35 million or 7% of worldwide annual turnover, whichever is higher.
- Is all emotion recognition or biometric identification banned?
- No. The bans are specific: emotion recognition is prohibited in workplaces and education institutions (except strictly for medical or safety reasons), and real-time remote biometric identification in publicly accessible spaces is prohibited for law enforcement except for narrowly defined, pre-authorised purposes. The law-enforcement exceptions are narrow, not general.
- Does a prohibited practice override high-risk obligations?
- Yes. If a system matches both a prohibited practice and a high-risk criterion, the prohibition controls, there is no compliance path through the Articles 9–15 high-risk obligations that rescues an otherwise-banned use case.
Related guides
Not sure where your company stands?
Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.
Start the free check