AI Compliance

EU AI Act Prohibited Practices: The Article 5 List, Examples and a Screening Checklist

Article 5 of the EU AI Act has banned eight AI practices since 2 February 2025, and the Digital Omnibus adds two more from 2 December 2026. What each ban covers, where the Commission's guidelines draw its edges, the fines, and how an enterprise screens its AI inventory.

EU AI Act prohibited practices are the AI uses that Article 5 bans outright: harmful manipulation, exploiting vulnerabilities, social scoring, predicting crime from profiling alone, untargeted scraping of facial images, emotion recognition at work and in education, biometric categorisation by sensitive traits, and real-time remote biometric identification for policing. The bans have applied since 2 February 2025, and two more start on 2 December 2026.

The Article 5 list at a glance

Article 5(1) of the AI Act, Regulation (EU) 2024/1689, names eight banned practices, and the Digital Omnibus, Regulation (EU) 2026/1744, inserts two more as points (ba) and (bb). A ban applies only when every one of its conditions is met. Because breaches carry the Act’s heaviest fines, the Commission’s guidelines ask for those conditions to be read narrowly.

PointWhat is bannedWhere the ban stopsExample in the Commission’s guidelines
5(1)(a)Subliminal, manipulative or deceptive techniques that distort behaviour and cause, or are reasonably likely to cause, significant harmLawful persuasion that is open about its aims and leaves the choice with the personA chatbot that imitates a relative’s voice to run a scam
5(1)(b)Exploiting vulnerabilities due to age, disability or a specific social or economic situation, with significant harmInadvertent bias is not exploitation by default, unless the operator knows of unlawful discrimination and fails to correct itAds for predatory financial products aimed at people in low-income postcodes who are in financial distress
5(1)(c)Social scoring, by public or private actors, that leads to harmful treatment in unrelated contexts or out of proportion to the behaviourLawful scoring for a specific purpose with relevant data, such as credit scoring under consumer credit lawAn insurer setting life cover premiums with unrelated spending data obtained from a bank
5(1)(d)Predicting that a person will commit a crime based solely on profiling or personality traitsSupport for a human assessment built on objective, verifiable facts linked to a crime; place-based forecastsAnalytics run for the police that rate individuals as likely trafficking offenders
5(1)(e)Creating or expanding facial recognition databases by untargeted scraping of facial images from the internet or CCTVSearches aimed at specific people; other biometrics such as voice; training datasets in which no one is identifiedA vendor scraping social media photos into a searchable face index
5(1)(f)Inferring the emotions of people at work or in educationMedical or safety reasons, read narrowly; sentiment in written text; emotions of customersA call centre using webcams and voice analysis to track staff anger
5(1)(g)Biometric categorisation that infers race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientationLabelling or filtering of lawfully acquired biometric datasets, for example to test for biasA system that claims to deduce someone’s race from their voice
5(1)(h)Real-time remote biometric identification in publicly accessible spaces for law enforcementThree narrow objectives under prior authorisation, such as searching for abduction victimsLive face matching in a shopping mall, on police instructions, to catch shoplifters
5(1)(ba), from 2 Dec 2026Generating or manipulating realistic intimate images, video or audio of an identifiable person without explicit consentConsented uses; non-realistic depictions; edits that do not increase exposureOutside the 2025 guidelines
5(1)(bb), from 2 Dec 2026Generating or manipulating child sexual abuse materialCases where a “without right” defence applies under national law, such as authorised investigationsOutside the 2025 guidelines

Article 5 forbids a practice whatever safeguards surround it, while Article 50 only attaches transparency duties to systems that stay lawful, such as chatbots and generated content; our guide to Article 50 covers those duties.

Dates and status of the bans

The prohibitions arrived ahead of every other substantive rule in the Act. In order:

  • 2 February 2025. Chapters I and II, which contain Article 5, began to apply. The bans reach systems that were in use before that date, and the grace period that Article 111 gives older high-risk systems expressly leaves Article 5 untouched.
  • 4 February 2025. The Commission approved the content of its guidelines on prohibited practices.
  • 29 July 2025. The guidelines were formally adopted as C(2025) 5052, once every language version was ready.
  • 2 August 2025. The penalty chapter began to apply, and Member States had to designate their market surveillance authorities. The guidelines note that the bans were binding and could be enforced in national courts before then, even though no fines were possible.
  • 27 July 2026. The Digital Omnibus entered into force.
  • 2 December 2026. Points (ba) and (bb) on intimate imagery and child sexual abuse material apply (verified on EUR-Lex, October 2026).

The two new bans split responsibility along the value chain. A provider breaches them by supplying a system built to produce such material, or one for which producing it is a reasonably foreseeable and reproducible outcome without reasonable and adequate safeguards to prevent it. A deployer breaches them only by using a system for that purpose. If your marketing team runs a self-hosted image or video model under your own name, you may be its provider, so keep the safety filters on and record which safeguards you rely on. The EU AI Act timeline puts these dates next to the high-risk deadlines.

What the Commission’s guidelines add

The guidelines run to well over a hundred pages of reasoning and examples. The points with the widest effect on enterprises:

  • Status. They are non-binding, and the Court of Justice of the European Union has the final word. National authorities are encouraged to follow them so that comparable cases are treated alike.
  • Every kind of AI system. The bans cover general-purpose systems as well as systems with a single intended purpose. Providers are expected to build in safeguards against foreseeable prohibited use and to rule it out in their terms of use, and deployers are expected not to work around those guardrails.
  • Supply as well as use. Each ban except point (h) covers placing a system on the market and putting it into service, as well as using it. Point (h) covers use only.
  • The border with high-risk. Systems that fall just outside a ban are often high-risk instead. Emotion recognition outside work and education sits in Annex III point 1(c), and lawful credit scoring sits in point 5(b). An Annex III system that escapes high-risk status through Article 6(3) can still be prohibited.
  • Open-source models. The open-source exclusion in Article 2(12) does not apply to a system that falls under Article 5.
  • Other law keeps running. Passing the Article 5 test settles nothing under GDPR, consumer law or employment law. Emotion recognition used for a genuine safety reason, for instance, still needs a lawful basis for processing biometric data.

Where enterprise assistants and agents could stray

Few companies set out to build a banned system. The usual route is a feature that drifts across the line: an analytics add-on, a new data source, or an agent handed a broader tool. These are the patterns to check first.

  • Meeting and call analytics. An assistant that scores the mood or engagement of employees from their faces or voices in video calls is inferring emotions from biometric data at work. The guidelines list hybrid-team tone monitoring and call-centre anger tracking as prohibited, and they treat job candidates and probationary staff as part of the workplace. Sentiment drawn from transcripts alone is outside the ban, but feeding it into performance reviews brings Annex III point 4(b) into play from December 2027. Our post on the EU AI Act for HR covers that category.
  • Wellbeing features. Detecting stress, burnout or boredom in staff does not count as a medical use; the guidelines tie the medical exception to uses such as CE-marked medical devices. Warning a driver or pilot about fatigue is a different matter, since fatigue is a physical state and not an emotion.
  • Scores built from the wrong data. An HR or risk agent that merges data from unrelated contexts, such as private social media activity, into a score used for workplace decisions could meet the social scoring conditions. The guidelines accept specific employee evaluations and credit scoring based on relevant data, and they put the burden on the provider and deployer to show that any resulting treatment is justified.
  • Research agents with web tools. The scraping ban bites only where facial images feed a database that can recognise faces. An open-source intelligence agent that harvests profile photos into a face index for investigations would cross that line. A reverse image search on one known face counts as targeted and falls outside it, although GDPR still applies.
  • Customer-facing agents. Sales or collections agents that deceive, or that steer older customers or people in financial difficulty towards offers likely to cause them significant financial harm, can fall under points (a) and (b). For banks and insurers the credit and insurance post goes further. The guidelines also cite a system that behaves well while it is being evaluated and reverts afterwards, which is worth remembering when you test agents.
  • Image and video generation. From 2 December 2026, a self-hosted generator that lacks adequate safeguards against intimate deepfakes of real people can put its provider in breach.

Fines and enforcement

Article 99 sets three tiers, and Article 5 sits at the top:

BreachMaximum fine (Article 99)
Any Article 5 prohibition€35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher
Other operator duties, including deployer duties under Article 26 and transparency under Article 50€15 million or 3%, whichever is higher
Incorrect, incomplete or misleading information to authorities€7.5 million or 1%, whichever is higher

SMEs, including start-ups, pay the lower of the two amounts in every tier. The Omnibus extended that relief to small mid-cap enterprises for the second and third tiers only, so a small mid-cap faces the full Article 5 tier. Under Article 100, the European Data Protection Supervisor can fine EU institutions up to €1.5 million for a prohibited practice.

National market surveillance authorities enforce the bans, on their own initiative or after a complaint, and Article 85 lets any person or organisation complain. For cases that reach beyond one Member State, the guidelines describe a Union safeguard procedure that ends with the Commission deciding whether the system is a prohibited practice. Under the Omnibus, the AI Office becomes the competent authority, with some exceptions, for AI systems that a general-purpose model’s own provider builds on that model, and for systems that are or sit inside very large online platforms and search engines. People affected by a prohibited practice can also go to national courts, because the bans have direct effect.

How to screen your AI inventory against Article 5

A screening is a documented pass over every AI system you build, buy or switch on, repeated whenever a use changes. A workable sequence:

  1. Start from a complete inventory. Include AI features inside SaaS products, such as meeting platforms, contact-centre suites and HR software, and every agent with tool access. An AI system register is the natural home for the results.
  2. Describe actual use. Record the purpose, who is affected (employees, candidates, customers, students, the public), the inputs (text, images, voice, video, keystrokes) and which outputs feed decisions.
  3. Ask the screening questions in the table below for each system.
  4. Test exceptions narrowly. Safety means protecting life and health, not property against theft. Targeted means a specific person or predefined group. Lawful scoring means relevant data and proportionate consequences, ideally under sector rules such as consumer credit law.
  5. Remove the risky feature. Switch off emotion or engagement scoring in meeting and interview tools, and ask providers to exclude prohibited uses in their terms, as the guidelines expect them to.
  6. Record the decision. Note the reviewer, the date, the evidence relied on and the change that would trigger a new review.
  7. Check the other law. GDPR rules on biometric data and automated decisions, national employment law and works council rights, and consumer law all apply alongside the AI Act. Article 2(11) lets Member States keep stricter rules protecting workers.
  8. Re-screen generative tools before 2 December 2026, when the intimate-imagery ban starts.
Screening questionIf the answer is yes, check
Does it infer emotions or intentions from faces, voice, gestures, keystrokes or other biometric data?Point (f) at work or in education; elsewhere Annex III point 1(c) and Article 50(3)
Does it sort individuals by biometric data into race, politics, union membership, religion, sex life or sexual orientation?Point (g)
Does it collect facial images from the internet or CCTV into something that can recognise faces?Point (e)
Does it score people with data from unrelated contexts, or with consequences out of proportion to their behaviour?Point (c)
Does it predict whether a person will commit an offence from their profile or personality alone?Point (d)
Does it use covert, deceptive or pressure techniques, or target people because of age, disability or financial hardship?Points (a) and (b)
Does it generate realistic images, video or audio of identifiable people?Point (ba) from 2 December 2026, plus Article 50 labelling
Does it identify people remotely in public spaces for the police?Point (h)

How VDF AI fits

VDF AI can run assistants and agents inside your own infrastructure, on-premises, in a private cloud or air-gapped, so the inventory, prompts and audit trail behind an Article 5 screening stay in systems you control. The AI risk classification agent checks each described use against the prohibited practices first, then the Annex III categories and the transparency-only cases, and records the criteria and evidence behind its finding for a compliance owner to sign.

In VDF AI Agents, role-based access control decides which tools and knowledge sources an agent may use, and each execution is logged from input through retrieval and tool calls to the model’s response. That record shows which data and tools an agent actually touched. The EU AI Act agents hub covers the rest of the toolkit. None of it makes a use lawful on its own; the decision on each system stays with your legal and compliance teams.

Sources

Frequently asked questions

What AI practices are prohibited under the EU AI Act?

Article 5 bans eight practices: manipulative or deceptive techniques that cause significant harm, exploiting vulnerabilities linked to age, disability or social or economic situation, social scoring that leads to unjustified or out-of-context treatment, predicting crime from profiling or personality alone, building facial recognition databases by untargeted scraping, inferring emotions at work or in education, biometric categorisation by race, politics, union membership, religion, sex life or sexual orientation, and real-time remote biometric identification for policing in public spaces. From 2 December 2026, AI that generates non-consensual intimate imagery or child sexual abuse material is banned as well.

When did the EU AI Act prohibitions come into force?

The Article 5 prohibitions have applied since 2 February 2025, to every AI system, including systems that were already in use before that date. The penalty chapter and the deadline for Member States to name their market surveillance authorities followed on 2 August 2025, so fines have been possible since then. The Digital Omnibus, Regulation (EU) 2026/1744, adds bans on non-consensual intimate material and child sexual abuse material that apply from 2 December 2026.

What is the fine for using a prohibited AI system?

Article 99(3) of the AI Act allows administrative fines of up to 35 million euros or, for an undertaking, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. It is the highest tier in the Act. For SMEs, including start-ups, the lower of the two amounts applies instead. The Digital Omnibus gave small mid-cap enterprises the same relief only for the lower tiers in Article 99(4) and (5), so a small mid-cap faces the full tier for an Article 5 breach.

Is emotion recognition banned in the workplace under the EU AI Act?

Yes, where a system infers emotions or intentions from biometric data such as facial expressions, voice or typing patterns. The Commission's guidelines read the workplace broadly, covering job candidates, probation periods, hybrid work and call centre staff. The exception for medical or safety reasons is narrow, and general stress or burnout monitoring does not qualify. Sentiment analysis of written text is not biometric, so it falls outside this ban, and inferring customers' emotions is treated as high-risk rather than prohibited.

Are the Commission's guidelines on prohibited AI practices binding?

No. The Commission approved their content on 4 February 2025 and formally adopted them on 29 July 2025 as C(2025) 5052. The guidelines say they are non-binding and that only the Court of Justice of the European Union can give an authoritative interpretation of the AI Act. They are still the best available reading of where each ban starts and stops, and national market surveillance authorities are encouraged to draw on them for comparable cases.

Do the Article 5 prohibitions apply to general-purpose chatbots and AI agents?

Yes. The guidelines state that the prohibitions apply to any AI system, whether it has a specific intended purpose or a general one. Providers are expected to build in safeguards against reasonably foreseeable prohibited uses and to exclude those uses in their terms. Deployers must not use a system in a prohibited way, which includes working around the provider's guardrails. An agent that infers employees' emotions from video calls is prohibited whichever model sits underneath it.

Filed under
EU AI ActAI complianceAI governanceregulated AIAI risk managemententerprise AI agents
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading