EU AI Act prohibited practices are the AI uses that Article 5 bans outright: harmful manipulation, exploiting vulnerabilities, social scoring, predicting crime from profiling alone, untargeted scraping of facial images, emotion recognition at work and in education, biometric categorisation by sensitive traits, and real-time remote biometric identification for policing. The bans have applied since 2 February 2025, and two more start on 2 December 2026.
The Article 5 list at a glance
Article 5(1) of the AI Act, Regulation (EU) 2024/1689, names eight banned practices, and the Digital Omnibus, Regulation (EU) 2026/1744, inserts two more as points (ba) and (bb). A ban applies only when every one of its conditions is met. Because breaches carry the Act’s heaviest fines, the Commission’s guidelines ask for those conditions to be read narrowly.
| Point | What is banned | Where the ban stops | Example in the Commission’s guidelines |
|---|---|---|---|
| 5(1)(a) | Subliminal, manipulative or deceptive techniques that distort behaviour and cause, or are reasonably likely to cause, significant harm | Lawful persuasion that is open about its aims and leaves the choice with the person | A chatbot that imitates a relative’s voice to run a scam |
| 5(1)(b) | Exploiting vulnerabilities due to age, disability or a specific social or economic situation, with significant harm | Inadvertent bias is not exploitation by default, unless the operator knows of unlawful discrimination and fails to correct it | Ads for predatory financial products aimed at people in low-income postcodes who are in financial distress |
| 5(1)(c) | Social scoring, by public or private actors, that leads to harmful treatment in unrelated contexts or out of proportion to the behaviour | Lawful scoring for a specific purpose with relevant data, such as credit scoring under consumer credit law | An insurer setting life cover premiums with unrelated spending data obtained from a bank |
| 5(1)(d) | Predicting that a person will commit a crime based solely on profiling or personality traits | Support for a human assessment built on objective, verifiable facts linked to a crime; place-based forecasts | Analytics run for the police that rate individuals as likely trafficking offenders |
| 5(1)(e) | Creating or expanding facial recognition databases by untargeted scraping of facial images from the internet or CCTV | Searches aimed at specific people; other biometrics such as voice; training datasets in which no one is identified | A vendor scraping social media photos into a searchable face index |
| 5(1)(f) | Inferring the emotions of people at work or in education | Medical or safety reasons, read narrowly; sentiment in written text; emotions of customers | A call centre using webcams and voice analysis to track staff anger |
| 5(1)(g) | Biometric categorisation that infers race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation | Labelling or filtering of lawfully acquired biometric datasets, for example to test for bias | A system that claims to deduce someone’s race from their voice |
| 5(1)(h) | Real-time remote biometric identification in publicly accessible spaces for law enforcement | Three narrow objectives under prior authorisation, such as searching for abduction victims | Live face matching in a shopping mall, on police instructions, to catch shoplifters |
| 5(1)(ba), from 2 Dec 2026 | Generating or manipulating realistic intimate images, video or audio of an identifiable person without explicit consent | Consented uses; non-realistic depictions; edits that do not increase exposure | Outside the 2025 guidelines |
| 5(1)(bb), from 2 Dec 2026 | Generating or manipulating child sexual abuse material | Cases where a “without right” defence applies under national law, such as authorised investigations | Outside the 2025 guidelines |
Article 5 forbids a practice whatever safeguards surround it, while Article 50 only attaches transparency duties to systems that stay lawful, such as chatbots and generated content; our guide to Article 50 covers those duties.
Dates and status of the bans
The prohibitions arrived ahead of every other substantive rule in the Act. In order:
- 2 February 2025. Chapters I and II, which contain Article 5, began to apply. The bans reach systems that were in use before that date, and the grace period that Article 111 gives older high-risk systems expressly leaves Article 5 untouched.
- 4 February 2025. The Commission approved the content of its guidelines on prohibited practices.
- 29 July 2025. The guidelines were formally adopted as C(2025) 5052, once every language version was ready.
- 2 August 2025. The penalty chapter began to apply, and Member States had to designate their market surveillance authorities. The guidelines note that the bans were binding and could be enforced in national courts before then, even though no fines were possible.
- 27 July 2026. The Digital Omnibus entered into force.
- 2 December 2026. Points (ba) and (bb) on intimate imagery and child sexual abuse material apply (verified on EUR-Lex, October 2026).
The two new bans split responsibility along the value chain. A provider breaches them by supplying a system built to produce such material, or one for which producing it is a reasonably foreseeable and reproducible outcome without reasonable and adequate safeguards to prevent it. A deployer breaches them only by using a system for that purpose. If your marketing team runs a self-hosted image or video model under your own name, you may be its provider, so keep the safety filters on and record which safeguards you rely on. The EU AI Act timeline puts these dates next to the high-risk deadlines.
What the Commission’s guidelines add
The guidelines run to well over a hundred pages of reasoning and examples. The points with the widest effect on enterprises:
- Status. They are non-binding, and the Court of Justice of the European Union has the final word. National authorities are encouraged to follow them so that comparable cases are treated alike.
- Every kind of AI system. The bans cover general-purpose systems as well as systems with a single intended purpose. Providers are expected to build in safeguards against foreseeable prohibited use and to rule it out in their terms of use, and deployers are expected not to work around those guardrails.
- Supply as well as use. Each ban except point (h) covers placing a system on the market and putting it into service, as well as using it. Point (h) covers use only.
- The border with high-risk. Systems that fall just outside a ban are often high-risk instead. Emotion recognition outside work and education sits in Annex III point 1(c), and lawful credit scoring sits in point 5(b). An Annex III system that escapes high-risk status through Article 6(3) can still be prohibited.
- Open-source models. The open-source exclusion in Article 2(12) does not apply to a system that falls under Article 5.
- Other law keeps running. Passing the Article 5 test settles nothing under GDPR, consumer law or employment law. Emotion recognition used for a genuine safety reason, for instance, still needs a lawful basis for processing biometric data.
Where enterprise assistants and agents could stray
Few companies set out to build a banned system. The usual route is a feature that drifts across the line: an analytics add-on, a new data source, or an agent handed a broader tool. These are the patterns to check first.
- Meeting and call analytics. An assistant that scores the mood or engagement of employees from their faces or voices in video calls is inferring emotions from biometric data at work. The guidelines list hybrid-team tone monitoring and call-centre anger tracking as prohibited, and they treat job candidates and probationary staff as part of the workplace. Sentiment drawn from transcripts alone is outside the ban, but feeding it into performance reviews brings Annex III point 4(b) into play from December 2027. Our post on the EU AI Act for HR covers that category.
- Wellbeing features. Detecting stress, burnout or boredom in staff does not count as a medical use; the guidelines tie the medical exception to uses such as CE-marked medical devices. Warning a driver or pilot about fatigue is a different matter, since fatigue is a physical state and not an emotion.
- Scores built from the wrong data. An HR or risk agent that merges data from unrelated contexts, such as private social media activity, into a score used for workplace decisions could meet the social scoring conditions. The guidelines accept specific employee evaluations and credit scoring based on relevant data, and they put the burden on the provider and deployer to show that any resulting treatment is justified.
- Research agents with web tools. The scraping ban bites only where facial images feed a database that can recognise faces. An open-source intelligence agent that harvests profile photos into a face index for investigations would cross that line. A reverse image search on one known face counts as targeted and falls outside it, although GDPR still applies.
- Customer-facing agents. Sales or collections agents that deceive, or that steer older customers or people in financial difficulty towards offers likely to cause them significant financial harm, can fall under points (a) and (b). For banks and insurers the credit and insurance post goes further. The guidelines also cite a system that behaves well while it is being evaluated and reverts afterwards, which is worth remembering when you test agents.
- Image and video generation. From 2 December 2026, a self-hosted generator that lacks adequate safeguards against intimate deepfakes of real people can put its provider in breach.
Fines and enforcement
Article 99 sets three tiers, and Article 5 sits at the top:
| Breach | Maximum fine (Article 99) |
|---|---|
| Any Article 5 prohibition | €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher |
| Other operator duties, including deployer duties under Article 26 and transparency under Article 50 | €15 million or 3%, whichever is higher |
| Incorrect, incomplete or misleading information to authorities | €7.5 million or 1%, whichever is higher |
SMEs, including start-ups, pay the lower of the two amounts in every tier. The Omnibus extended that relief to small mid-cap enterprises for the second and third tiers only, so a small mid-cap faces the full Article 5 tier. Under Article 100, the European Data Protection Supervisor can fine EU institutions up to €1.5 million for a prohibited practice.
National market surveillance authorities enforce the bans, on their own initiative or after a complaint, and Article 85 lets any person or organisation complain. For cases that reach beyond one Member State, the guidelines describe a Union safeguard procedure that ends with the Commission deciding whether the system is a prohibited practice. Under the Omnibus, the AI Office becomes the competent authority, with some exceptions, for AI systems that a general-purpose model’s own provider builds on that model, and for systems that are or sit inside very large online platforms and search engines. People affected by a prohibited practice can also go to national courts, because the bans have direct effect.
How to screen your AI inventory against Article 5
A screening is a documented pass over every AI system you build, buy or switch on, repeated whenever a use changes. A workable sequence:
- Start from a complete inventory. Include AI features inside SaaS products, such as meeting platforms, contact-centre suites and HR software, and every agent with tool access. An AI system register is the natural home for the results.
- Describe actual use. Record the purpose, who is affected (employees, candidates, customers, students, the public), the inputs (text, images, voice, video, keystrokes) and which outputs feed decisions.
- Ask the screening questions in the table below for each system.
- Test exceptions narrowly. Safety means protecting life and health, not property against theft. Targeted means a specific person or predefined group. Lawful scoring means relevant data and proportionate consequences, ideally under sector rules such as consumer credit law.
- Remove the risky feature. Switch off emotion or engagement scoring in meeting and interview tools, and ask providers to exclude prohibited uses in their terms, as the guidelines expect them to.
- Record the decision. Note the reviewer, the date, the evidence relied on and the change that would trigger a new review.
- Check the other law. GDPR rules on biometric data and automated decisions, national employment law and works council rights, and consumer law all apply alongside the AI Act. Article 2(11) lets Member States keep stricter rules protecting workers.
- Re-screen generative tools before 2 December 2026, when the intimate-imagery ban starts.
| Screening question | If the answer is yes, check |
|---|---|
| Does it infer emotions or intentions from faces, voice, gestures, keystrokes or other biometric data? | Point (f) at work or in education; elsewhere Annex III point 1(c) and Article 50(3) |
| Does it sort individuals by biometric data into race, politics, union membership, religion, sex life or sexual orientation? | Point (g) |
| Does it collect facial images from the internet or CCTV into something that can recognise faces? | Point (e) |
| Does it score people with data from unrelated contexts, or with consequences out of proportion to their behaviour? | Point (c) |
| Does it predict whether a person will commit an offence from their profile or personality alone? | Point (d) |
| Does it use covert, deceptive or pressure techniques, or target people because of age, disability or financial hardship? | Points (a) and (b) |
| Does it generate realistic images, video or audio of identifiable people? | Point (ba) from 2 December 2026, plus Article 50 labelling |
| Does it identify people remotely in public spaces for the police? | Point (h) |
How VDF AI fits
VDF AI can run assistants and agents inside your own infrastructure, on-premises, in a private cloud or air-gapped, so the inventory, prompts and audit trail behind an Article 5 screening stay in systems you control. The AI risk classification agent checks each described use against the prohibited practices first, then the Annex III categories and the transparency-only cases, and records the criteria and evidence behind its finding for a compliance owner to sign.
In VDF AI Agents, role-based access control decides which tools and knowledge sources an agent may use, and each execution is logged from input through retrieval and tool calls to the model’s response. That record shows which data and tools an agent actually touched. The EU AI Act agents hub covers the rest of the toolkit. None of it makes a use lawful on its own; the decision on each system stays with your legal and compliance teams.