Intermediate

Prohibited AI Practices

A short list of AI uses is banned outright in the EU - no safeguards, no exceptions for most of them, no conformity assessment that makes them lawful. These prohibitions have applied since 2 February 2025, making them the first part of the Act with real teeth.

✍️ AI School Editorial Team · Lilly Tech Systems 📅 Published Jun 13, 2026 · Reviewed Jun 13, 2026

Why a Ban At All?

Most of the Act manages risk; this part eliminates it. The EU concluded that certain AI uses are so contrary to its values - human dignity, autonomy, non-discrimination - that they cannot be made acceptable by documentation or oversight. Article 5 lists them. Because the prohibitions came into force first, on 2 February 2025, they are the obligations most likely to already apply to you today.

⚠️
Highest penalties in the Act. Breaching a prohibition carries the top fine tier: up to €35 million or 7% of total worldwide annual turnover, whichever is higher. These are not theoretical - the prohibitions are enforceable now.

The Eight Prohibited Categories

1. Harmful manipulation and deception

AI that uses subliminal techniques beyond a person’s awareness, or purposefully manipulative or deceptive techniques, to materially distort behaviour in a way that causes (or is likely to cause) significant harm. The classic example is a system designed to nudge people into decisions they would not otherwise make, to their detriment.

2. Exploiting vulnerabilities

AI that exploits vulnerabilities due to age, disability, or a specific social or economic situation to distort behaviour in a way that causes significant harm. This protects groups least able to protect themselves - children, the elderly, people in financial distress.

3. Social scoring

Evaluating or classifying people over time based on their social behaviour or personal characteristics, where the resulting "score" leads to detrimental treatment that is either unrelated to the original context or disproportionate. This is the prohibition aimed squarely at state-style social-credit systems, and it applies to private actors too.

4. Predictive policing of individuals

Assessing or predicting the risk that a specific person will commit a crime based solely on profiling or personality traits. Predictive tools that support human assessment based on objective, verifiable facts tied to criminal activity are treated differently - the ban targets prediction based purely on who someone is.

5. Untargeted scraping for facial recognition

Creating or expanding facial-recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. This directly outlaws the business model of several well-known facial-recognition vendors.

6. Emotion recognition at work and school

Inferring emotions of individuals in the workplace and in educational institutions - with a narrow exception for medical or safety reasons (for example, detecting driver fatigue). Selling sentiment analysis of employees or students is otherwise off the table.

7. Biometric categorisation of sensitive traits

Using biometric data to categorise people in order to infer or deduce sensitive attributes - race, political opinions, trade-union membership, religious or philosophical beliefs, sex life, or sexual orientation. Lawful labelling of datasets, and some law-enforcement uses, are carved out narrowly.

8. Real-time remote biometric identification in public

Live facial recognition in publicly accessible spaces for law-enforcement purposes is prohibited - with tightly drawn exceptions (such as searching for specific victims of serious crime, preventing an imminent threat, or locating suspects of certain serious offences), each subject to prior authorisation and safeguards. For private actors, real-time public biometric identification has essentially no lawful path.

The exceptions are narrow and mostly for the state. Where Article 5 allows something (certain biometric uses, some law-enforcement identification), the carve-out is hedged with conditions and is generally available only to public authorities under judicial or administrative authorisation. If you are a private company, assume the prohibitions apply to you without exception.

What This Means in Practice

For most product teams, none of these eight will describe your core business - but the edges catch people. A few patterns to watch:

  • "Engagement optimisation" that crosses into manipulation. Persuasion is legal; exploiting people below the level of their awareness to their significant harm is not.
  • Trust-and-safety scoring. A reputation score used proportionately within its original context is fine; one that follows people into unrelated decisions and harms them looks like social scoring.
  • HR and ed-tech "wellbeing" analytics. Inferring employee or student emotions is prohibited outside the medical and safety exception.
  • Face-search features. Building a facial-recognition database from scraped images is banned regardless of how the data is later used.
📝
Action: Run an Article 5 screen across your product portfolio now - this is the one part of the Act that is already enforceable and carries the largest fines. If anything lands near these eight categories, escalate to counsel before your next release, not after.

Ready to Go Deeper?

Live instructor-led courses from our partners. Affiliate disclosure.