Prohibited AI Practices
A short list of AI uses is banned outright in the EU - no safeguards, no exceptions for most of them, no conformity assessment that makes them lawful. These prohibitions have applied since 2 February 2025, making them the first part of the Act with real teeth.
Why a Ban At All?
Most of the Act manages risk; this part eliminates it. The EU concluded that certain AI uses are so contrary to its values - human dignity, autonomy, non-discrimination - that they cannot be made acceptable by documentation or oversight. Article 5 lists them. Because the prohibitions came into force first, on 2 February 2025, they are the obligations most likely to already apply to you today.
The Eight Prohibited Categories
1. Harmful manipulation and deception
AI that uses subliminal techniques beyond a person’s awareness, or purposefully manipulative or deceptive techniques, to materially distort behaviour in a way that causes (or is likely to cause) significant harm. The classic example is a system designed to nudge people into decisions they would not otherwise make, to their detriment.
2. Exploiting vulnerabilities
AI that exploits vulnerabilities due to age, disability, or a specific social or economic situation to distort behaviour in a way that causes significant harm. This protects groups least able to protect themselves - children, the elderly, people in financial distress.
3. Social scoring
Evaluating or classifying people over time based on their social behaviour or personal characteristics, where the resulting "score" leads to detrimental treatment that is either unrelated to the original context or disproportionate. This is the prohibition aimed squarely at state-style social-credit systems, and it applies to private actors too.
4. Predictive policing of individuals
Assessing or predicting the risk that a specific person will commit a crime based solely on profiling or personality traits. Predictive tools that support human assessment based on objective, verifiable facts tied to criminal activity are treated differently - the ban targets prediction based purely on who someone is.
5. Untargeted scraping for facial recognition
Creating or expanding facial-recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. This directly outlaws the business model of several well-known facial-recognition vendors.
6. Emotion recognition at work and school
Inferring emotions of individuals in the workplace and in educational institutions - with a narrow exception for medical or safety reasons (for example, detecting driver fatigue). Selling sentiment analysis of employees or students is otherwise off the table.
7. Biometric categorisation of sensitive traits
Using biometric data to categorise people in order to infer or deduce sensitive attributes - race, political opinions, trade-union membership, religious or philosophical beliefs, sex life, or sexual orientation. Lawful labelling of datasets, and some law-enforcement uses, are carved out narrowly.
8. Real-time remote biometric identification in public
Live facial recognition in publicly accessible spaces for law-enforcement purposes is prohibited - with tightly drawn exceptions (such as searching for specific victims of serious crime, preventing an imminent threat, or locating suspects of certain serious offences), each subject to prior authorisation and safeguards. For private actors, real-time public biometric identification has essentially no lawful path.
What This Means in Practice
For most product teams, none of these eight will describe your core business - but the edges catch people. A few patterns to watch:
- "Engagement optimisation" that crosses into manipulation. Persuasion is legal; exploiting people below the level of their awareness to their significant harm is not.
- Trust-and-safety scoring. A reputation score used proportionately within its original context is fine; one that follows people into unrelated decisions and harms them looks like social scoring.
- HR and ed-tech "wellbeing" analytics. Inferring employee or student emotions is prohibited outside the medical and safety exception.
- Face-search features. Building a facial-recognition database from scraped images is banned regardless of how the data is later used.
Ready to Go Deeper?
Live instructor-led courses from our partners. Affiliate disclosure.
AI & ML Courses - 30% Off
Live instructor-led AI, machine learning, data science, and cloud courses for working professionals. Use code Limited30 at checkout.
EdurekaDataCamp - AI & Data Science
Hands-on Python, machine learning, and AI courses with interactive exercises and real projects.
DataCampedX - Top AI Courses
University-level AI courses from MIT, Harvard, Stanford. Earn certificates that employers recognize.
edX