Most of the debate on the AI Act revolves around high-risk systems and their obligations. But the Regulation opens with a sharper, often overlooked category: uses of artificial intelligence that are simply banned. Article 5 of Regulation EU 2024/1689 lists eight prohibited practices across the Union, applicable from 2 February 2025. The difference is fundamental: high-risk systems have a compliance path; these do not.
The eight practices banned by Article 5
If an AI system falls into one of these categories, placing it on the market or using it in the EU is unlawful, regardless of sector, operator type or stated purpose.
| Point | What it bans |
|---|---|
| (a) | Subliminal, manipulative or deceptive techniques that materially distort behaviour and cause significant harm |
| (b) | Exploiting the vulnerabilities of a person or group (age, disability, social or economic situation) |
| (c) | Social scoring: evaluating or classifying people by their social behaviour, leading to detrimental treatment in unrelated contexts or disproportionate treatment |
| (d) | Predictive policing on individuals: predicting the risk of committing a crime based solely on profiling or personality traits |
| (e) | Creating or expanding facial recognition databases through untargeted scraping of images from the internet or CCTV |
| (f) | Emotion recognition in the workplace and in education institutions |
| (g) | Biometric categorisation to infer sensitive data: race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation |
| (h) | "Real-time" remote biometric identification in public spaces for law enforcement, save for narrowly defined exceptions |
Points (d), (e) and (h) mostly concern law enforcement and surveillance-technology vendors. It is the first three — (a), (b) and (c) — and (f) where an ordinary company can trip up without noticing.
The three most insidious for a business
Emotion recognition at work (f). This is the ban that reaches the most companies. Systems that infer staff emotional states — from facial expressions, tone of voice, posture or keystrokes — for example to measure "engagement", monitor stress or prevent conflicts, are prohibited. Uses for medical or safety reasons remain allowed (detecting driver fatigue). Note the boundary: measuring productivity is not banned, but inferring emotions is; the line is thin and vendors rarely flag it.
Social scoring (c). Not just a government problem. Assigning people a "score" based on social behaviour and using it for detrimental treatment in a context unrelated to where the data was collected — or in a disproportionate way — falls within the ban.
Manipulation and exploitation of vulnerabilities (a, b). Systems using deceptive or subliminal techniques, or leveraging age, disability or economic fragility to push a person into a harmful decision. A concrete issue for marketing, advertising and the design of persuasive interfaces.
In early February 2025 the European Commission published guidelines on prohibited practices: they are not binding, but they are the practical reference that authorities, providers and users should follow when applying the bans.
What changes from 2 December 2026
The Digital Omnibus (Regulation EU 2026/1744, in force since 27 July 2026) does not touch the structure of the existing bans, but adds two more, applicable from 2 December 2026. AI systems that generate or manipulate the following will be prohibited:
- realistic images, video or audio depicting an identifiable person's intimate parts or sexually explicit activities without their consent (non-consensual intimate deepfakes);
- child sexual abuse material.
The provider is liable if the system produces such content intentionally, or if it is a reasonably foreseeable and reproducible outcome and the system lacks built-in safety measures to prevent it; the deployer is liable if it uses the system for that very purpose.
Prohibited is not high-risk: no compliance can save it
This is the point most often misunderstood. A high-risk system has a way out: technical documentation, risk management, human oversight, conformity assessment. A prohibited practice has none of that. No consent from the individual, contractual warranty or technical measure makes it lawful: it is banned, full stop.
The penalties are the highest in the Regulation. For breaches of the Art. 5 prohibitions, Article 99 sets fines up to €35 million or 7% of worldwide annual turnover, whichever is higher. For SMEs and start-ups the lower amount applies — but it is still a fine, and the practice remains unlawful regardless of company size.
How to check whether your company is exposed
Three concrete checks, to run now:
- Review your HR and monitoring tools. Software analysing staff "engagement", wellbeing or emotional tone is the most frequent candidate for the point (f) ban. Ask the vendor, in writing, whether the system infers emotions.
- Look at marketing and personalisation. Mechanisms that exploit fragilities or use manipulative levers can fall under (a) and (b).
- Tell "prohibited" from "high-risk". Many systems that look banned at first glance are in fact high-risk (lawful, but regulated). Getting the classification wrong costs both ways: it blocks lawful projects or leaves the truly unlawful ones uncovered.
Where to start
The fastest way to find out whether you are using — perhaps unknowingly, through a vendor — a prohibited practice is an independent gap assessment: a map of the AI systems in use, with their correct classification and remediation priorities. On the Art. 5 bans there is no room to negotiate: better to find them in an audit than in front of a supervisory authority.