European Union
EU AI Act Article 5: The Prohibited AI Practices, Explained
Eight AI practices the EU AI Act bans outright — no documentation, no human oversight measure, and no conformity assessment fixes any of them. Here's each one, in plain terms.
Most of the EU AI Act is a compliance exercise: classify your system, document it, put the right controls around it, and you're in business. Article 5 isn't that. It's a short list of things you're not allowed to do at all, and no amount of documentation, human oversight, or third-party audit changes that answer. If a system falls into one of these eight categories, the fix isn't a better risk management file — it's not building the system that way in the first place.
That distinction matters more than most teams give it credit for, because Article 5 also has a fact about it that's easy to miss: it's already in force. While the bulk of the Act's high-risk obligations were still phasing in through 2025 and 2026, the prohibited-practices provisions became applicable on February 2, 2025 — six months after the regulation entered into force, and earlier than almost anything else in the statute. If your organization has been treating the whole Act as "something to get ready for by 2026," this is the part of it you were already supposed to have handled.
Scope works the same way it does everywhere else in the Act: Article 5 isn't limited to companies headquartered in the EU. A provider placing an AI system on the EU market, or a deployer using one within the EU, is covered regardless of where the company is incorporated — what matters is where the system's effects land, not where the org chart sits.
Why this comes before the risk-tier conversation, not inside it
Compliance teams tend to jump straight to the question the Act spends the most pages on: is my system high-risk under Article 6, and if so, what do I need to build around it? That's the right question — eventually. But it's the second question, not the first.
Article 5 is a categorical bar, checked before classification even starts. A system that would otherwise sail through high-risk classification with a clean bill of health can still be flatly illegal if it falls into one of the eight prohibited categories. There's no tier to move it into, no mitigation that satisfies a regulator, and no conformity assessment that makes it acceptable. The only compliant version of a prohibited practice is one that doesn't happen.
The eight practices Article 5 prohibits
Subliminal, manipulative, or deceptive techniques that distort behavior
Systems that deploy techniques beyond a person's conscious awareness, or that are purposefully manipulative or deceptive, in a way that materially distorts someone's behavior and causes — or is reasonably likely to cause — significant harm. Think dark-pattern interfaces engineered around psychological triggers a user can't perceive or resist, not ordinary persuasive design like a well-placed call-to-action button.
Exploiting vulnerabilities tied to age, disability, or economic situation
AI that targets people because of their age, a disability, or a specific social or economic situation, in order to materially distort their behavior in a way likely to cause them significant harm. A system engineered to push predatory financial products at people already identified as in economic distress is the paradigm case here.
Social scoring by public authorities
Evaluating or classifying people over time based on social behavior or predicted personal traits, where the resulting treatment is detrimental, and either disconnected from the context the data came from or disproportionate to what the behavior actually warrants. This is aimed squarely at government-style social-credit systems — not at every scoring model a business runs.
Predicting criminal offending from profiling alone
Risk-assessment tools that predict the likelihood of someone committing a criminal offense based solely on profiling or personality-trait analysis, with no underlying objective, verifiable facts tied to actual criminal activity. A tool that flags "this person's profile resembles past offenders" is prohibited; supporting a human assessment that's already grounded in real, verifiable facts about a specific case is a different, narrower thing.
Untargeted scraping of facial images to build recognition databases
Creating or expanding a facial-recognition database by scraping facial images indiscriminately from the internet or from CCTV footage. This is one of the more commercially relevant prohibitions — it directly targets the business model of building broad facial-recognition datasets from public sources without consent.
Emotion inference in the workplace and in schools
Inferring an employee's or a student's emotions in workplace or educational settings, outside narrow medical or safety exceptions — a driver-fatigue monitoring system being the standard example of what's still allowed. An employer running sentiment analysis on staff facial expressions during meetings is squarely inside the ban.
Biometric categorization to infer sensitive attributes
Using biometric data to infer or deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation. Narrow exceptions exist for labelling or filtering lawfully acquired biometric datasets and for certain law-enforcement biometric-data filtering — but inferring these categories as a general capability is prohibited.
Real-time remote biometric identification in public spaces, for law enforcement
The most heavily caveated of the eight: real-time remote biometric identification (functionally, live facial recognition) in publicly accessible spaces, used for law enforcement purposes, is prohibited by default. It becomes permissible only inside a narrow, specifically authorized set of circumstances — covered in the next section, because it's also the provision teams misread most often.
The exception teams read too broadly
The law-enforcement carve-out for real-time biometric identification gets cited far more often than its actual scope justifies. It applies only to a specific, enumerated list of purposes — searching for a specific missing or trafficked person, preventing a specific, substantial, and imminent threat to life or a terrorist attack, or identifying a suspect in the investigation of specific serious crimes drawn from a defined list. Even within those purposes, deployment generally requires prior authorization from a judicial authority or an independent administrative body, with a genuinely narrow allowance for duly justified urgency.
Two things this exception does not do: it doesn't extend to private-sector use in any form, and it doesn't create a general public-safety justification. "We wanted better security coverage" is not one of the enumerated purposes, no matter how reasonable it sounds operationally.
What happens if you cross the line
Article 99 sets the penalty for a prohibited-practice violation at the top of the AI Act's entire fine structure: up to €35 million, or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. That's a materially higher ceiling than the fines attached to high-risk-system violations — a direct signal of how the regulation ranks the severity of these eight categories relative to everything else it regulates.
How Article 5 relates to Article 6's high-risk tier
Think of Article 5 and Article 6 as sequential gates, not parallel tracks. Article 5 asks a yes/no question: does this system do one of eight specifically prohibited things? If yes, the analysis stops there — no classification exercise changes that answer. Only a system that clears Article 5 moves on to the Article 6 question of whether it's high-risk, and if so, what obligations attach — starting with the Article 9 risk management system that becomes the backbone of everything else required afterward.
That sequencing is why it's worth running the Article 5 screen first, even though most governance programs are built around the high-risk classification process. A system that would classify cleanly under Annex III can still be dead on arrival if it also happens to fall into one of Article 5's categories — emotion inference in an HR tool, say, or a biometric categorization feature bolted onto an otherwise unremarkable access-control system. For the mechanics of what happens once a system clears this screen, see our breakdown of how Article 6 high-risk classification actually works.
A practical first-pass screen
Before a system goes anywhere near formal classification, run it through five quick questions:
- Does it use imperceptible or manipulative techniques to change someone's behavior in a way that could cause them real harm?
- Does it specifically target people based on age, disability, or economic hardship to influence their behavior?
- Does it score or rank people in a way that follows them into unrelated contexts?
- Does it predict criminal behavior from profiling alone, without grounding in verified facts about an actual case?
- Does it infer emotions, or categorize people by sensitive traits, using biometric data — especially in a workplace, a school, or a public space?
A "yes" to any of these isn't a documentation problem to route into your governance process — it's a build/don't-build decision that needs to happen before the system goes further. If your organization already runs an AI systems inventory and risk-tiering process, this screen belongs at the intake step, ahead of tiering, not folded into it.
Frequently asked questions
- Does Article 5 apply to companies outside the EU?
- Yes. Article 5 follows the same extraterritorial logic as the rest of the AI Act: a provider or deployer based outside the EU is still in scope if the system's output is used by people located in the EU. Where your company is incorporated doesn't change the analysis — where the system's effects land does.
- What exactly counts as 'social scoring' under the AI Act?
- A system that evaluates or classifies people over time based on their social behavior or on known or predicted personal characteristics, where the resulting treatment is detrimental and either unrelated to the context in which the data was originally gathered, or disproportionate to the behavior itself. Ordinary, context-specific credit scoring isn't automatically caught by this — that's addressed separately, including under the high-risk rules for creditworthiness assessment. The prohibition targets scoring that follows a person across unrelated contexts and produces outsized consequences.
- Is emotion-recognition AI banned everywhere, or just at work and school?
- Just in the workplace and in educational institutions, under Article 5(1)(f) — with narrow exceptions for genuine medical or safety purposes, such as a system monitoring driver fatigue. Emotion inference in other settings isn't prohibited by Article 5, though it can trigger separate transparency obligations under Article 50. Don't assume the ban is broader than the two named settings.
- What's the penalty for violating Article 5 specifically?
- The highest tier in the AI Act's entire penalty structure: administrative fines of up to €35 million, or 7% of the company's total worldwide annual turnover for the preceding financial year, whichever is higher. That ceiling sits above the fines for high-risk-system violations, which signals how seriously the regulation treats this category.
- Is real-time facial recognition in public spaces completely banned in the EU?
- No, but the exception is much narrower than it's often described. Law enforcement can use real-time remote biometric identification in publicly accessible spaces only for a specific, enumerated list of purposes — such as searching for a specific victim or preventing a specific, substantial, and imminent threat to life — and only with prior authorization from a judicial or independent administrative body. It does not extend to private-sector use, and general public-safety monitoring doesn't qualify.
Sources & references
Suggested next reading
regulations eu
The EU AI Act
regulatory checklists