Prohibited AI Practices Under the EU AI Act

Guides
by David Porter
Monday, 17 August 2026 at 21:29
thumbnail_prohibited-ai-practices-under-
Article 5 of the EU AI Act prohibits particular AI practices considered incompatible with fundamental rights and EU values. These are not merely “high-risk” systems that can be used after extra documentation. Where the legal conditions are met, the practice may not be placed on the market, put into service or used, subject only to the narrow exceptions written into the law.
The original prohibitions began applying on February 2, 2025. The 2026 Digital Omnibus added two further prohibitions addressing AI-generated or manipulated non-consensual intimate material and child sexual abuse material. Those additions apply from December 2, 2026.
A prohibition screen should be the first substantive step after confirming scope. Do not spend months designing a high-risk conformity program for a use that Article 5 does not permit.
For the law’s overall structure, start with our complete EU AI Act guide. For the classification sequence, use the EU AI Act risk-categories guide. For all milestones, see the EU AI Act timeline.

Prohibited practices at a glance

PracticeCore triggerMain date
Harmful manipulation or deceptionTechniques materially distort behavior and cause or are likely to cause significant harmFebruary 2, 2025
Exploitation of vulnerabilitiesExploits age, disability or social/economic vulnerability with harmful behavioral distortionFebruary 2, 2025
Social scoringScores people over time and produces unrelated or disproportionate detrimental treatmentFebruary 2, 2025
Certain individual criminal-risk predictionPredicts offending based solely on profiling or personality characteristicsFebruary 2, 2025
Untargeted facial-image scrapingBuilds or expands facial-recognition databases through untargeted internet or CCTV scrapingFebruary 2, 2025
Workplace or education emotion recognitionInfers emotions in those settings, except for medical or safety reasonsFebruary 2, 2025
Sensitive biometric categorizationUses biometric data to infer protected or highly sensitive characteristicsFebruary 2, 2025
Most real-time remote biometric identification by law enforcementIdentifies people remotely in real time in publicly accessible spaces, outside narrow exceptionsFebruary 2, 2025
Non-consensual intimate synthetic materialGenerates or manipulates realistic intimate or sexually explicit depictions of an identifiable person without required consentDecember 2, 2026
Child sexual abuse materialGenerates or manipulates material within the relevant criminal-law definition, subject to the “without right” defenseDecember 2, 2026

Are there eight, nine or ten prohibited practices?

You may see different numbers in official and secondary explanations.
  • The original 2024 Act contained eight lettered prohibitions in Article 5(1).
  • The 2026 amendment inserted two new legal points, (ba) and (bb), bringing the first subparagraph to ten distinct points.
  • The Commission sometimes communicates nine broad categories by grouping the two new sexual-content prohibitions together as one category concerning harmful synthetic intimate and child-abuse material.
The difference is presentational, not a conflict about what is prohibited. Compliance teams should map the actual legal points rather than rely only on a numbered infographic.

1. Harmful manipulation and deception

The Act prohibits placing, putting into service or using an AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques where the objective or effect is to materially distort behavior by appreciably impairing informed decision-making, causing a person to take a decision they would otherwise not take, in a manner that causes or is reasonably likely to cause significant harm.
Several elements must be tested:
  • Is the technique subliminal, manipulative or deceptive?
  • Does it appreciably impair the person’s ability to make an informed decision?
  • Does it materially distort behavior?
  • Is there significant harm or a reasonable likelihood of it?
Not every persuasive interface or recommendation is automatically prohibited. Consumer-protection, platform and privacy laws can still apply below the Article 5 threshold.

Red flags

  • hidden sensory cues designed to bypass conscious judgment;
  • deliberately false conversational personas used to secure consequential consent;
  • adaptive pressure exploiting emotional state to force spending or dangerous action;
  • and optimization objectives that reward harmful behavioral dependency.

2. Exploiting vulnerabilities

AI may not exploit the vulnerabilities of a person or group arising from age, disability or a specific social or economic situation where the objective or effect is to materially distort behavior and cause or be reasonably likely to cause significant harm.
This provision is especially relevant to systems aimed at:
  • children;
  • elderly people;
  • people with cognitive or other disabilities;
  • people in financial distress;
  • and users in dependency or crisis situations.
The analysis is not limited to whether the audience happens to be vulnerable. The system must exploit the vulnerability and meet the behavioral-distortion and harm conditions.
Design teams should test segmentation, personalization, persuasive features and business incentives—not only the model’s output text.

3. Social scoring

Article 5 prohibits evaluating or classifying people or groups over a period based on social behavior or known, inferred or predicted personal or personality characteristics where the score leads to either:
  • detrimental or unfavorable treatment in social contexts unrelated to the contexts in which the data was generated or collected; or
  • treatment that is unjustified or disproportionate to the behavior or its gravity.
This is broader than a government-operated national score and narrower than every risk score.
A fraud score based on relevant transaction behavior for a defined purpose is not automatically “social scoring.” Risk rises when data from one life context is aggregated into a generalized reputation and used to penalize a person elsewhere, or when the response is disproportionate.

Questions to ask

  • Over what period is the person evaluated?
  • Which behaviors and inferred characteristics feed the score?
  • Is the treatment in the same context?
  • Is it justified and proportionate?
  • Can the person challenge the input and result?

4. Criminal-risk prediction based solely on profiling

The Act prohibits AI used to make risk assessments of natural persons to assess or predict the risk that they will commit a criminal offense when the assessment is based solely on profiling or on assessing personality traits and characteristics.
The prohibition does not cover AI supporting a human assessment of a person’s involvement in criminal activity where that assessment is already based on objective and verifiable facts directly linked to criminal activity.
The distinction does not create a broad license for predictive policing. Law-enforcement, data-protection, discrimination and high-risk requirements can still apply. “Human in the loop” also does not cure a system if the underlying assessment is still solely personality-based in substance.

5. Untargeted facial-image scraping

AI systems may not create or expand facial-recognition databases through the untargeted scraping of facial images from the internet or CCTV footage.
This addresses indiscriminate collection used to build biometric identification resources. It focuses on the method and purpose:
  • facial images;
  • untargeted scraping;
  • from internet or CCTV sources;
  • to create or expand a facial-recognition database.
It does not mean every targeted collection of a face image is lawful. GDPR, law-enforcement data rules, biometric restrictions and consent requirements remain.
Organizations buying biometric datasets should perform source due diligence rather than assume the supplier collected the images lawfully.

6. Emotion recognition in workplaces and education

The use of AI systems to infer emotions of a natural person in workplace and educational settings is prohibited, except where the use is intended for medical or safety reasons.
This can capture systems marketed for:
  • employee engagement detection;
  • attention or stress scoring;
  • interview emotion analysis;
  • classroom concentration monitoring;
  • or exam anxiety assessment.
The medical and safety exception should be read narrowly and tied to a genuine purpose. Relabeling productivity monitoring as “wellbeing” is not enough.
A system can also involve biometric data, worker surveillance and discrimination concerns under other laws. The Article 5 screen is only the beginning.

7. Biometric categorization of sensitive traits

Article 5 prohibits biometric categorization systems that individually categorize natural persons based on biometric data to deduce or infer specified sensitive or protected characteristics, including race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation.
The Act preserves limited situations involving lawful labeling or filtering of lawfully acquired biometric datasets, such as images, and categorization in law-enforcement contexts under the conditions of applicable law.
Do not confuse:
  • biometric identification, which seeks to identify a person;
  • biometric verification, which checks a claimed identity;
  • and biometric categorization, which assigns a person to a category based on biometric data.
The specific function and inferred trait determine the analysis.

8. Real-time remote biometric identification in public spaces

The use of real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes is generally prohibited.
The Act creates narrow exceptions where use is strictly necessary for specified objectives, including:
  • searching for particular victims of abduction, trafficking or sexual exploitation, or missing persons;
  • preventing a specific, substantial and imminent threat to life or physical safety, or a genuine and present or foreseeable terrorist threat;
  • and locating or identifying a person suspected of specified serious crimes under the Act’s conditions.
Even within an exception, additional safeguards apply. These include necessity and proportionality, limits in time and geography, authorization, impact assessment, registration and restrictions on making adverse legal decisions solely from the system output.
This is not a general police facial-recognition authorization. Each deployment requires a tightly documented legal basis and conditions.

9. Non-consensual intimate material

From December 2, 2026, Article 5 prohibits AI systems generating or manipulating realistic images, video, audio or similar material depicting the intimate parts of an identifiable natural person, or that person engaged in sexually explicit activity, without the person’s freely given, specific, informed, unambiguous and explicit consent for that generation or manipulation.
The amendment targets practices often associated with “nudification” or sexually explicit deepfakes while defining the boundaries more precisely.

For deployers

The prohibited use concerns deploying an AI system for the purpose of generating or manipulating the prohibited material. It can include:
  • deliberately using a system without safeguards;
  • circumventing safeguards;
  • or using a lawful general system for the prohibited purpose.
Accidental generation during otherwise lawful use is not treated in the same way, although it should trigger reporting, correction and safety review.

For providers

A provider can be caught where the system is intended for the prohibited purpose. A provider can also be caught where such output is a reasonably foreseeable and reproducible result and reasonable and adequate technical measures and safeguards are absent.
The Omnibus recitals identify possible safeguards such as:
  • data cleaning;
  • refusal training;
  • safe prompt and output controls;
  • runtime guardrails;
  • content classification and filtering;
  • usage restrictions;
  • abuse detection;
  • notice-and-action mechanisms;
  • and corrective action after circumvention or reported misuse.
The required safeguards should be state of the art, appropriate for the system and demonstrably effective against foreseeable misuse. Distribution strategy matters, including whether the provider retains control through an interface or releases weights openly.

Consent and scope

Consent must meet the specific standard in the provision. Product teams need reliable ways to collect and demonstrate it where a system legitimately handles intimate depictions.
The law focuses on realistic depictions of identifiable people and defines relevant intimate or sexually explicit material. It does not convert every artistic nude, medical image, try-on application or non-realistic depiction into a prohibited practice. Other laws still apply.

10. Child sexual abuse material

Also from December 2, 2026, Article 5 prohibits placing, putting into service or using an AI system that generates or manipulates child sexual abuse material within the referenced EU criminal-law definitions, except where a “without right” defense applies under national law.
The exception can cover narrowly lawful activity such as authorized criminal investigations and legitimate red-teaming or evaluation aimed at assessing compliance with the prohibition, subject to the applicable legal framework and safeguards.
This is not an ordinary content-policy category. Providers should integrate specialist trust-and-safety, legal, security and reporting processes and should not retain or circulate illegal material as routine test evidence.

Provider versus deployer treatment for the new bans

IssueProviderDeployer
Intended harmful systemMust not place or put it into serviceMust not use it for the prohibited purpose
Foreseeable reproducible harmful outputNeeds reasonable and adequate safeguardsProhibited when deliberately used for the harmful purpose
CircumventionMust correct observed or reported circumvention where reasonableMust not circumvent safeguards
Accidental outputCan reveal inadequate safeguards and require correctionNot automatically the prohibited purposeful use, but should be handled and reported
EvidenceSafety design, testing, abuse monitoring, consent mechanisms, corrective actionPurpose, prompts, user conduct, approvals, incident records
The new provisions make intent important for deployers and safety engineering important for providers.

How to screen a use case

Use a structured sequence.

1. Define the practice

Record the exact system, user, affected person, purpose, inputs, outputs, environment and business incentive. “Facial AI” or “behavioral analytics” is too vague.

2. Test each Article 5 element

A prohibition usually contains several cumulative conditions. Map facts to each one instead of relying on labels.

3. Check exceptions narrowly

Document why an exception applies, who authorized it, what safeguards apply and when the conclusion expires.

4. Test foreseeable misuse

Providers should evaluate realistic misuse, guardrail bypass, distribution strategy and abuse at scale. A terms-of-service clause alone is not an adequate technical measure.

5. Stop or redesign before deployment

Where the practice is prohibited, do not “accept the risk.” Remove the function, constrain purpose, add safeguards where the provision permits, or abandon the deployment.

6. Preserve the decision

Keep the legal test, evidence, approvals, red-team findings, safety controls and review triggers in the AI register.

Interaction with high-risk and transparency rules

The legal layers are not alternatives.
  • A prohibited practice cannot become lawful merely by satisfying high-risk requirements.
  • A permitted biometric or employment system may still be high-risk.
  • A synthetic-media system can have Article 50 duties even when the content is lawful.
  • A GPAI model provider can have Chapter V duties while downstream harmful uses are prohibited.
The correct order is: prohibition first, then high-risk, transparency, GPAI and other obligations.

Other laws still matter

Article 5 does not occupy the entire field. Depending on the use, organizations must also consider:
  • GDPR and law-enforcement data protection;
  • the Digital Services Act;
  • consumer-protection and unfair-commercial-practices law;
  • employment and anti-discrimination law;
  • product-safety law;
  • criminal law;
  • copyright and personality rights;
  • and national rules on biometrics, surveillance and evidence.
A use outside Article 5 can still be unlawful under another regime.

Enforcement and fines

The most serious Article 5 infringements sit in the AI Act’s highest general penalty tier. Article 99 permits maximum administrative fines of up to €35 million or 7% of total worldwide annual turnover for an undertaking, subject to the applicable penalty rules.
The newer Article 5 points apply only from December 2, 2026. The original prohibitions have applied since February 2025.
Maximums are not automatic. Authorities consider the nature, gravity and duration of the infringement, affected persons, intent or negligence, cooperation, mitigation, prior infringements and organizational size.
Use the EU AI Act compliance checklist for enforcement ownership and documentation.

Common mistakes

Calling all high-risk AI “banned”

High-risk systems are generally permitted subject to requirements. Article 5 is the prohibition layer.

Screening only the product description

The actual deployment, personalization, affected groups and incentive structure can reveal a prohibited practice.

Treating human review as a universal exception

Human involvement does not erase a prohibited manipulation, biometric categorization or purposeful harmful generation.

Assuming a disclaimer cures the use

Disclosure can satisfy some transparency obligations; it does not legalize an Article 5 practice.

Ignoring foreseeable misuse

The new provider rules expressly focus on reproducible outcomes, safeguards, circumvention and corrective action.

Treating consent as a vague checkbox

For non-consensual intimate material, the amendment specifies a high consent standard and requires that consent relate to the generation or manipulation.

Frequently asked questions

Are all facial-recognition systems banned in the EU?

No. Untargeted scraping to build facial-recognition databases is prohibited, and most real-time remote identification by law enforcement in public spaces is prohibited. Other biometric uses require separate analysis and may be high-risk or restricted by data-protection law.

Is social scoring always prohibited?

The Article 5 prohibition applies when the specified scoring and detrimental-treatment conditions are met. Ordinary relevant risk scoring is not automatically social scoring.

Is emotion recognition banned everywhere?

The explicit Article 5 ban covers workplace and education settings, subject to medical or safety exceptions. Other emotion-recognition use can still be high-risk or subject to Article 50 and privacy rules.

Are nudification apps prohibited now?

The new legal points apply from December 2, 2026. They cover defined realistic non-consensual intimate material and child sexual abuse material, with detailed provider, deployer and exception rules.

Is every deepfake prohibited?

No. Many lawful deepfakes are regulated through Article 50 disclosure. Deepfakes can become prohibited where they meet a specific Article 5 rule or violate other law.

Can providers rely on content filters?

Filters can be part of reasonable and adequate safeguards, but adequacy depends on state of the art, foreseeable misuse, circumvention, testing and corrective action.

Does accidental harmful output make a deployer liable under the new ban?

The deployer prohibition focuses on use for the prohibited purpose. Accidental output is treated differently, but should still trigger incident handling and may indicate provider-safeguard failures.

Can law enforcement use real-time facial identification?

Only within narrow statutory objectives and procedural safeguards, including necessity, proportionality and authorization.

Who should perform the prohibition screen?

Product, technical, legal/compliance, privacy, security and relevant subject-matter teams should review it before procurement or release.

How often should Article 5 be reassessed?

At every material change in purpose, audience, model, data, personalization, safeguards or distribution—and whenever the law or guidance changes.

Bottom line

Article 5 is not a list of forbidden technologies. It is a set of precise practice-based bans with conditions, exceptions and role-specific responsibilities.
Screen every use before risk classification, document each legal element, test foreseeable misuse and stop deployments that meet a prohibition. For generative systems, the December 2026 additions make consent, abuse prevention, guardrail resilience and corrective action part of the core product-safety case.
loading

Loading