Updated July 2026 IN FORCE — HIGHEST PENALTY TIER

EU AI Act: Prohibited AI Practices — The Ten Things You May Not Do With AI in Europe

Article 5 bans specific AI practices outright — no conformity assessment, no transition, no exceptions beyond those written into the law. The complete guide to the eight original prohibitions, the two new Omnibus additions, and the €35M penalty tier that backs them.

The Bottom Line

Since February 2, 2025, eight AI practices have been banned outright in the EU: subliminal manipulation, exploitation of vulnerabilities, social scoring, crime prediction based solely on profiling, untargeted facial image scraping, emotion inference at work and school, biometric categorisation of sensitive attributes, and real-time remote biometric identification for law enforcement. The Digital Omnibus (signed July 8, 2026) adds two more — AI generation of non-consensual intimate material and CSAM — with compliance required by December 2, 2026. Violations carry the highest fines in the entire AI Act: up to €35 million or 7% of global turnover. These prohibitions apply now, to providers and deployers, inside and outside the EU.

What Article 5 Prohibits — The Unacceptable Risk Tier

The EU AI Act regulates AI through a risk pyramid. Most systems face no obligations; some face transparency duties (Article 50); high-risk systems face strict controls (Chapter III). At the top sits a category the law refuses to permit at all: unacceptable risk.

Article 5 lists AI practices considered incompatible with fundamental rights and Union values — human dignity, freedom, equality, non-discrimination, and privacy. These practices may not be placed on the market, put into service, or used in the EU. There is no conformity assessment pathway, no registration option, and no grandfathering for systems deployed before the ban.

Three features make Article 5 the sharpest instrument in the AI Act. First, it took effect earlier than any other substantive obligation — on February 2, 2025, six months after entry into force. Second, it carries the highest penalty tier: €35 million or 7% of worldwide turnover under Article 99(3). Third, it binds both providers and deployers — the company that builds the system and the company that uses it.

The prohibitions also reach beyond Europe. Under Article 2, a provider established anywhere in the world is covered if its system is placed on the EU market, and even a non-EU deployer is covered where the output of the system is used in the EU.

Source: Article 5 — artificialintelligenceact.eu →

The Eight Original Prohibitions at a Glance

Article 5(1) sets out eight prohibited practices, lettered (a) through (h). Each has precise conditions — and several have narrow, explicitly drafted exceptions.

Art. 5(1)Prohibited PracticeTypically AffectsException
(a)Subliminal, manipulative, or deceptive techniques causing significant harmConsumer apps, marketing tech, dark patternsLawful, transparent persuasion
(b)Exploiting vulnerabilities of age, disability, or socio-economic situationProducts targeting children, elderly, or vulnerable groupsNone
(c)Social scoring causing unjustified or disproportionate detrimental treatmentPublic authorities and private platformsJustified, proportionate scoring in the original context
(d)Predicting individual criminal offence risk based solely on profiling or personality traitsLaw enforcement, risk assessment vendorsHuman assessment support based on objective, verifiable facts
(e)Untargeted scraping of facial images from the internet or CCTV for facial recognition databasesFacial recognition database vendorsNone
(f)Emotion inference in workplaces and educational institutionsHR software, employee monitoring, proctoring toolsMedical or safety purposes
(g)Biometric categorisation to deduce race, political opinions, union membership, religion, sex life, or sexual orientationBiometric analytics vendorsLawful dataset labelling; certain law-enforcement uses
(h)Real-time remote biometric identification in public spaces for law enforcementPolice and public security deploymentsThree narrowly defined situations with prior authorisation
The Digital Omnibus adds a ninth and tenth category — AI generation of non-consensual intimate material and CSAM — covered in Section 7 below.

Manipulation and Exploitation — Art. 5(1)(a) and (b)

Subliminal and Manipulative Techniques — (a)

The first prohibition targets AI systems that deploy subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques. Three cumulative conditions must all be met:

  • The system uses subliminal, purposefully manipulative, or deceptive techniques
  • The technique materially distorts behaviour, appreciably impairing the ability to make an informed decision
  • The distorted behaviour causes, or is reasonably likely to cause, significant harm

The Commission guidelines draw the line between unlawful manipulation and lawful persuasion: advertising, recommendation, and personalisation that operate transparently remain permitted. The prohibition bites when techniques work covertly — below the threshold of awareness — and produce significant physical, psychological, or financial harm.

Exploiting Vulnerabilities — (b)

The second prohibition covers AI systems that exploit vulnerabilities of a person or group due to their age, disability, or specific social or economic situation, with the objective or effect of materially distorting behaviour in a manner that causes or is reasonably likely to cause significant harm.

Practical examples from the guidelines include AI toys that nudge children toward dangerous behaviour, and predatory lending or pricing systems that target people in financial distress. Unlike (a), this prohibition has no persuasion carve-out — targeting a protected vulnerability with harmful behavioural distortion is banned outright.

Source: Article 5 — AI Act Service Desk (European Commission) →

Social Scoring and Crime Prediction — Art. 5(1)(c) and (d)

Social Scoring — (c)

AI systems that evaluate or classify people over time based on their social behaviour or known, inferred, or predicted personal characteristics are prohibited where the resulting score leads to either:

  • Detrimental treatment in social contexts unrelated to the context in which the data was originally generated or collected, or
  • Detrimental treatment that is unjustified or disproportionate to the social behaviour or its gravity

Critically, the ban applies to private companies as well as public authorities. It does not automatically prohibit credit scoring, insurance pricing, or fraud detection based on relevant data in the original context — the test is cross-context misuse or disproportionate treatment based on social data.

Individual Crime Prediction — (d)

AI systems that assess or predict the risk of a natural person committing a criminal offence, based solely on profiling or on assessing personality traits and characteristics, are prohibited.

The provision contains an explicit carve-out: AI systems used to support the human assessment of involvement in criminal activity remain permitted where that assessment is already based on objective and verifiable facts directly linked to a criminal activity. Place-based predictive policing — forecasting where offences may occur rather than who will commit them — also falls outside the prohibition, though it may be high-risk under Annex III.

The Biometric Prohibitions — Art. 5(1)(e), (f), (g)

e

Untargeted Facial Image Scraping

Creating or expanding facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage is banned. This provision targets the business model of services that harvested billions of face images from social media without consent. The scraping itself is the prohibited act — regardless of how the database is later used.

Article 5(1)(e) • No exceptions

f

Emotion Inference at Work and School

AI systems that infer emotions of natural persons in the areas of workplace and educational institutions are prohibited. This covers emotion analytics in hiring interviews, employee monitoring dashboards, call-centre agent scoring, and student proctoring. Outside these two contexts, emotion recognition is not banned but is classified as high-risk under Annex III.

Article 5(1)(f) • Exception: medical or safety purposes

Detecting driver fatigue in professional transport or supporting clinical care are the guideline examples of the medical/safety exception. HR analytics do not qualify.

g

Biometric Categorisation of Sensitive Attributes

Biometric categorisation systems that categorise individuals based on their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation are prohibited.

Article 5(1)(g) • Exceptions: lawful labelling or filtering of biometric datasets; categorisation in the area of law enforcement

Real-Time Remote Biometric Identification — Art. 5(1)(h)

The most heavily negotiated provision of the entire AI Act. The use of real-time remote biometric identification (RBI) systems — live facial recognition — in publicly accessible spaces for law enforcement purposes is prohibited, unless one of three exhaustively listed situations applies:

i

Targeted Search for Victims

The targeted search for specific victims of abduction, trafficking in human beings, or sexual exploitation, as well as the search for missing persons.

Article 5(1)(h)(i)

ii

Imminent Threats and Terrorism

The prevention of a specific, substantial, and imminent threat to the life or physical safety of natural persons, or a genuine and present or genuine and foreseeable threat of a terrorist attack.

Article 5(1)(h)(ii)

iii

Serious Crime Suspects

The localisation or identification of a person suspected of a criminal offence listed in Annex II, punishable in the Member State concerned by a custodial sentence of a maximum period of at least four years.

Article 5(1)(h)(iii) • Annex II

Safeguards That Apply Even Within the Exceptions

  • Art. 5(2) — Use only to confirm the identity of the specifically targeted individual; a fundamental rights impact assessment (Article 27) and registration in the EU database (Article 49) are required
  • Art. 5(3) — Prior authorisation by a judicial authority or independent administrative authority; in duly justified emergencies, authorisation may follow within 24 hours or use must stop
  • Art. 5(4) — Each use must be notified to the market surveillance authority and the data protection authority
  • Art. 5(5) — A Member State may only allow RBI if it has enacted national law; it must notify the Commission within 30 days, and may choose stricter rules — including not allowing RBI at all
Source: Article 5(2)–(5) — artificialintelligenceact.eu →

New for 2026: Non-Consensual Intimate Material and CSAM

The Digital Omnibus on AI — adopted by the European Parliament on June 16, 2026, approved by the Council on June 29, 2026, and signed on July 8, 2026 — adds a new prohibition to Article 5, the first expansion of the banned list since the AI Act was adopted.

What Is Now Prohibited

AI systems that generate or manipulate non-consensual intimate images, video, audio, or similar material, or child sexual abuse material (CSAM).

The Provider-Side Standard

For providers, the prohibition applies where such generation is a reasonably foreseeable and reproducible outcome of the system that cannot be avoided without substantial technical modification. In practice, this requires generative AI providers to implement and maintain technical safeguards — content filters, safety classifiers, and abuse monitoring — that prevent these outputs from being a reproducible result of ordinary use.

Transition Period

Deadline: December 2, 2026. A transitional period gives providers of existing generative systems time to implement safeguards. From that date, the new prohibition is enforceable under the same €35M / 7% penalty tier as the original eight practices.

The addition responds to the rapid growth of AI-generated intimate-image abuse and complements existing EU instruments on child sexual abuse and gender-based violence. For deployers, generating such material with any AI system was already unlawful under criminal law across Member States — the Omnibus places responsibility on the systems themselves.

Source: Gibson Dunn — EU AI Act Omnibus Agreement →

The Commission Guidelines on Prohibited Practices

Two days after the prohibitions took effect, the European Commission approved Guidelines on Prohibited AI Practices (C(2025) 884, February 4, 2025). The formally adopted all-language version followed on July 29, 2025 (C(2025) 5052). At over 130 pages, the guidelines are the most detailed interpretive document on Article 5 available.

What the Guidelines Clarify

  • Lawful persuasion vs. manipulation — transparent advertising, personalisation, and nudging remain permitted; covert techniques causing significant harm do not
  • Scope of each prohibition — concrete examples and non-examples for all eight practices, including edge cases like AI companions, games, and wellness apps
  • Interplay with other law — how Article 5 operates alongside the GDPR, the Digital Services Act, and consumer protection rules
  • The medical/safety exception for emotion inference — interpreted narrowly, covering fatigue detection and clinical support, not HR analytics
  • Out-of-scope uses — systems not placed on the EU market, and practices lacking the required harm element
The guidelines are non-binding: authoritative interpretation of the AI Act rests with the Court of Justice of the European Union. In practice, national market surveillance authorities follow them closely, and they are the reference point for enforcement decisions.
Source: European Commission — Guidelines on Prohibited AI Practices →

Enforcement and Penalties: The €35M / 7% Tier

Article 99(3) reserves the highest fines in the AI Act for Article 5 violations. Penalties have been applicable since August 2, 2025, when Member States were required to designate market surveillance authorities and lay down their national penalty rules.

€35M
Maximum administrative fine for non-compliance with the Article 5 prohibitions (Article 99(3))
7%
Of total worldwide annual turnover for the preceding financial year — whichever is higher

How Enforcement Works

  • National market surveillance authorities police the prohibitions in each Member State — unlike GPAI model obligations, which the Commission’s AI Office enforces centrally
  • Data protection authorities act in parallel where prohibited practices process personal data, since the GDPR applies cumulatively
  • Member State penalty laws set the specific rules within the Article 99 maximums; several states also provide criminal sanctions for related conduct
  • SME proportionality — for SMEs and startups, the lower of the fixed amount or percentage applies (Article 99(6))

Penalty Tiers Across the AI Act

Violation CategoryMaximum FineArticle
Prohibited AI practices€35M or 7% of global turnoverArt. 99(3)
Most other obligations (incl. Art. 50, high-risk)€15M or 3% of global turnoverArt. 99(4)
GPAI model obligations€15M or 3% of global turnoverArt. 101
Incorrect or misleading information supplied€7.5M or 1% of global turnoverArt. 99(5)
Source: Article 99 — artificialintelligenceact.eu →

Comparison: Prohibited vs High-Risk vs Transparency vs GPAI

The four obligation frameworks of the AI Act differ in who is bound, when, and how hard the penalties bite.

AspectProhibited (Art. 5)High-Risk (Ch. III)Transparency (Art. 50)GPAI (Ch. V)
NatureBanned outrightPermitted, heavily regulatedPermitted with disclosurePermitted with documentation
Who is boundProviders & deployersProviders & deployersProviders & deployersModel providers
Applicable since / from2 Feb 20252 Dec 2027 (Omnibus deferral)2 Aug 20262 Aug 2025
Penalties from2 Aug 20252 Dec 20272 Aug 20262 Aug 2026
Maximum fine€35M / 7%€15M / 3%€15M / 3%€15M / 3%
Enforcement bodyNational authoritiesNational authoritiesNational authoritiesAI Office (EU level)
Conformity assessment None exists
Omnibus impact+2 new prohibitions (2 Dec 2026)Deferred 16 monthsUnchanged; watermarking grace to 2 Dec 2026Unchanged

Read our companion guides: Article 50 Transparency Obligations and GPAI Model Obligations.

Five-Step Article 5 Screening Checklist

Because prohibited practices cannot be fixed with documentation or registration, the only compliance strategy is to make sure none of your systems performs one. Screen systematically:

1

Inventory Your AI Systems

List every AI system you provide or deploy — including embedded third-party tools, HR and recruitment software, scoring engines, biometric systems, and generative AI applications. Remember: deployers are bound by Article 5 just as providers are.

2

Screen Against the Ten Prohibitions

Check each system against the eight prohibitions in force since February 2, 2025, plus the two Omnibus additions applicable by December 2, 2026. The highest-frequency corporate risks: emotion inference in HR tools, cross-context scoring, and generative systems lacking abuse safeguards.

3

Check Exceptions and Document the Legal Basis

Where a use resembles a prohibited practice, verify whether a written exception applies — medical or safety purposes for emotion inference, objective-facts human assessment support for crime risk — and record the analysis. The Commission guidelines are the reference document for these boundary questions.

4

Remediate or Withdraw Immediately

The prohibitions are enforceable now, with no grandfathering. Disable prohibited functions, reconfigure systems, or withdraw them from the EU market. For generative systems, verify that safety filters make non-consensual intimate material and CSAM generation neither foreseeable nor reproducible.

5

Monitor Guidelines and Deadlines

Track the Commission guidelines, national market surveillance practice, and the December 2, 2026 deadline for the new prohibitions. Record your screening in a compliance log — documented diligence matters when authorities assess proportionality of fines.

Complete Article 5 Timeline

1 Aug 2024
EU AI Act enters into force (Regulation 2024/1689) Active
2 Feb 2025
The eight Article 5 prohibitions become applicable — the first substantive obligations of the AI Act Active
4 Feb 2025
Commission approves Guidelines on Prohibited AI Practices (C(2025) 884) Active
29 Jul 2025
Formal adoption of the guidelines in all EU languages (C(2025) 5052) Active
2 Aug 2025
Penalties become applicable; Member States designate market surveillance authorities Active
8 Jul 2026
Digital Omnibus signed — adds prohibitions on non-consensual intimate material and CSAM generation Active
2 Aug 2026
Article 50 transparency obligations activate; GPAI penalty enforcement begins 12 days
2 Dec 2026
New prohibitions fully enforceable. Transition ends for non-consensual intimate material and CSAM generation safeguards Upcoming
2 Dec 2027
Annex III high-risk obligations become enforceable (deferred by Omnibus) Future
Source: Implementation Timeline — artificialintelligenceact.eu →

Frequently Asked Questions

Article 5(1) of the EU AI Act bans eight AI practices: (a) subliminal or purposefully manipulative techniques that distort behaviour and cause significant harm; (b) exploitation of vulnerabilities based on age, disability, or socio-economic situation; (c) social scoring leading to unjustified or disproportionate detrimental treatment; (d) predicting criminal offence risk based solely on profiling or personality traits; (e) untargeted scraping of facial images from the internet or CCTV to build facial recognition databases; (f) emotion inference in workplaces and educational institutions; (g) biometric categorisation to deduce race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation; and (h) real-time remote biometric identification in publicly accessible spaces for law enforcement. The 2026 Omnibus amendment adds two more: AI systems generating non-consensual intimate material and child sexual abuse material.
The eight original prohibitions have applied since February 2, 2025 — six months after the AI Act entered into force, and earlier than any other substantive obligation in the Act. Financial penalties for violations became applicable on August 2, 2025, when Member States were required to have designated market surveillance authorities and laid down penalty rules. The two new prohibitions added by the Digital Omnibus (non-consensual intimate material and CSAM generation) are subject to a transitional period running until December 2, 2026.
Article 99(3) sets the highest penalty tier in the entire AI Act for Article 5 violations: administrative fines of up to €35 million or, for an undertaking, up to 7% of total worldwide annual turnover for the preceding financial year — whichever is higher. By comparison, most other violations (including Article 50 transparency and high-risk obligations) carry a maximum of €15 million or 3%, and supplying incorrect information carries €7.5 million or 1%. For SMEs and startups, the lower of the fixed amount or the percentage applies.
Yes. Under Article 2, the AI Act applies to providers placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is established, and to providers and deployers located outside the EU where the output produced by the AI system is used in the EU. A US or Asian company whose AI system reaches EU users — directly or through a distributor — is fully subject to the Article 5 prohibitions and the €35M/7% penalty tier.
Three cumulative conditions must be met: the AI system deploys subliminal techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques; the technique materially distorts the behaviour of a person or group, appreciably impairing their ability to make an informed decision; and the distorted behaviour causes or is reasonably likely to cause significant harm. The Commission guidelines clarify that lawful persuasion — ordinary advertising, personalisation, or nudging that operates transparently — falls outside the prohibition. The line is crossed when techniques operate covertly and cause significant physical, psychological, or financial harm.
Both. Article 5(1)(c) applies to social scoring by any actor — public authorities and private companies alike. The prohibition covers AI systems that evaluate or classify people based on their social behaviour or known, inferred, or predicted personality characteristics, where the score leads to detrimental treatment in social contexts unrelated to where the data was generated, or treatment that is unjustified or disproportionate to the behaviour. Ordinary credit scoring or insurance pricing based on relevant financial data is not automatically prohibited — the key test is unjustified or disproportionate detrimental treatment based on unrelated social data.
Yes, with narrow exceptions. Article 5(1)(f) prohibits AI systems that infer emotions of natural persons in the areas of workplace and educational institutions. The only exceptions are AI systems intended for medical or safety reasons — for example, detecting driver fatigue in professional transport or supporting clinical care. Emotion inference for hiring decisions, employee monitoring, performance evaluation, or student proctoring is prohibited. Outside workplaces and schools, emotion recognition is not banned outright but is classified as high-risk AI under Annex III.
Not based on profiling alone. Article 5(1)(d) prohibits AI systems that assess or predict the risk of a natural person committing a criminal offence based solely on profiling or on assessing personality traits and characteristics. There is an explicit carve-out: AI systems used to support the human assessment of a person's involvement in criminal activity, where that assessment is already based on objective and verifiable facts directly linked to a criminal activity, remain permitted. Place-based or event-based predictive policing that does not target identified individuals also falls outside the prohibition.
Not entirely — but two specific uses are prohibited. First, Article 5(1)(e) bans creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage — the business model behind services like Clearview AI. Second, Article 5(1)(h) bans real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, subject to three narrow exceptions. Other facial recognition uses — such as post (retrospective) identification or verification with consent — are regulated as high-risk AI rather than prohibited.
Article 5(1)(h) allows law enforcement use of real-time remote biometric identification in public spaces only in three situations: (i) the targeted search for specific victims of abduction, trafficking, or sexual exploitation, and the search for missing persons; (ii) the prevention of a specific, substantial, and imminent threat to life or physical safety, or a genuine and foreseeable threat of a terrorist attack; and (iii) the localisation or identification of a suspect of a serious criminal offence listed in Annex II punishable by at least four years of custody. Even then, Articles 5(2) and 5(3) require a fundamental rights impact assessment, registration in the EU database, and prior authorisation by a judicial or independent administrative authority — with a 24-hour emergency procedure.
The Digital Omnibus on AI — adopted by the European Parliament on June 16, 2026, approved by the Council on June 29, 2026, and signed on July 8, 2026 — adds a prohibition on AI systems that generate or manipulate non-consensual intimate images, video, audio, or similar material, and child sexual abuse material (CSAM). The provider-side obligation applies where such generation is a reasonably foreseeable and reproducible outcome of the system that cannot be avoided without substantial technical modification. A transitional period runs until December 2, 2026, giving providers time to implement technical safeguards.
National market surveillance authorities, which Member States were required to designate by August 2, 2025. Unlike GPAI model obligations — enforced centrally by the European Commission through its AI Office — prohibited practices are policed at national level under each Member State's penalty framework, within the maximum amounts set by Article 99. Data protection authorities also play a role where prohibited practices involve personal data, since the GDPR applies in parallel. The Omnibus additionally expanded the AI Office's supervisory powers over AI systems built on general-purpose AI models.
Yes. The European Commission approved Guidelines on Prohibited AI Practices on February 4, 2025 (C(2025) 884), two days after the prohibitions took effect, and formally adopted the all-language version on July 29, 2025 (C(2025) 5052). The guidelines run to over 130 pages and give concrete examples for each prohibition — clarifying, among other things, the boundary between lawful persuasion and unlawful manipulation, the scope of the workplace emotion-inference ban, and how the social scoring conditions interact. The guidelines are non-binding; authoritative interpretation of the AI Act rests with the Court of Justice of the EU.
Yes. The prohibitions are technology-neutral and apply to any AI system, including general-purpose AI systems built on large language models. A chatbot that deploys manipulative techniques causing significant harm, infers emotions of employees, or generates prohibited material falls under Article 5 regardless of the underlying architecture. The Commission guidelines note that providers of general-purpose systems should implement safeguards against reasonably foreseeable prohibited uses — a principle the Omnibus made explicit for non-consensual intimate material and CSAM generation.
Prohibited practices (Article 5) represent unacceptable risk: they may not be placed on the EU market or used at all, and violations carry the top penalty tier of €35M or 7%. High-risk AI systems (Chapter III, Annex III) are permitted but heavily regulated — requiring risk management, data governance, technical documentation, human oversight, and conformity assessment, with penalties up to €15M or 3%. The Omnibus deferred most Annex III high-risk obligations to December 2, 2027, but did not touch the Article 5 prohibitions, which remain fully applicable now.
Yes. Unlike some other AI Act obligations, the prohibitions apply to the use of AI systems regardless of when they were placed on the market. A legacy system that performs social scoring or workplace emotion inference does not benefit from grandfathering — deployers had to cease prohibited uses by February 2, 2025. The only transition currently running is for the two new Omnibus prohibitions, where compliance is required by December 2, 2026.
Five steps: (1) Inventory every AI system you provide or deploy, including embedded third-party tools; (2) Screen each system against the ten prohibited practices, paying particular attention to emotion inference in HR tools, scoring systems, and generative capabilities; (3) Where a practice resembles a prohibition, check the exceptions — medical or safety purposes for emotion inference, objective-facts support for crime risk assessment — and document the legal basis; (4) Remediate or withdraw non-compliant systems immediately, since the prohibitions are already enforceable; (5) Monitor the Commission guidelines, the Omnibus transitional deadline of December 2, 2026, and national enforcement practice.

Article 5 Readiness Checklist

Use this checklist to confirm that no system in your organisation crosses an Article 5 line.

#ItemApplies ToStatus
1Complete AI system inventory (provided and deployed, incl. third-party tools)All
2No subliminal, manipulative, or deceptive techniques causing significant harmAll
3No exploitation of age, disability, or socio-economic vulnerabilityAll
4Scoring systems reviewed for cross-context or disproportionate detrimental treatmentAll
5No individual crime-risk prediction based solely on profiling or personality traitsAll
6No untargeted scraping of facial images for recognition databasesAll
7No emotion inference in workplace or educational contexts (or documented medical/safety basis)HR / EdTech
8No biometric categorisation of race, politics, union membership, religion, sex life, or orientationBiometric
9No real-time remote biometric identification, or exception + authorisation documentedLaw enforcement
10Generative systems safeguarded against non-consensual intimate material outputGenAI
11Generative systems safeguarded against CSAM outputGenAI
12Exception analyses documented with reference to the Commission guidelinesAll
13Legacy systems screened (no grandfathering applies)All
14Screening log maintained for market surveillance inquiriesAll
15December 2, 2026 Omnibus transition deadline trackedGenAI
TS

Takayuki Sawai

Gyoseishoshi (Certified Administrative Scrivener). AI compliance researcher covering EU AI Act, drone aviation law, and food safety regulations across 14 countries. Over 20 years at Hiroshima Prefectural Government.

Read more →

Is Your AI Compliance Ready?

Take the free AI Act readiness diagnosis. Get a personalised compliance score in 2 minutes.