Since February 2, 2025, eight AI practices have been banned outright in the EU: subliminal manipulation, exploitation of vulnerabilities, social scoring, crime prediction based solely on profiling, untargeted facial image scraping, emotion inference at work and school, biometric categorisation of sensitive attributes, and real-time remote biometric identification for law enforcement. The Digital Omnibus (signed July 8, 2026) adds two more — AI generation of non-consensual intimate material and CSAM — with compliance required by December 2, 2026. Violations carry the highest fines in the entire AI Act: up to €35 million or 7% of global turnover. These prohibitions apply now, to providers and deployers, inside and outside the EU.
What Article 5 Prohibits — The Unacceptable Risk Tier
The EU AI Act regulates AI through a risk pyramid. Most systems face no obligations; some face transparency duties (Article 50); high-risk systems face strict controls (Chapter III). At the top sits a category the law refuses to permit at all: unacceptable risk.
Article 5 lists AI practices considered incompatible with fundamental rights and Union values — human dignity, freedom, equality, non-discrimination, and privacy. These practices may not be placed on the market, put into service, or used in the EU. There is no conformity assessment pathway, no registration option, and no grandfathering for systems deployed before the ban.
Three features make Article 5 the sharpest instrument in the AI Act. First, it took effect earlier than any other substantive obligation — on February 2, 2025, six months after entry into force. Second, it carries the highest penalty tier: €35 million or 7% of worldwide turnover under Article 99(3). Third, it binds both providers and deployers — the company that builds the system and the company that uses it.
The prohibitions also reach beyond Europe. Under Article 2, a provider established anywhere in the world is covered if its system is placed on the EU market, and even a non-EU deployer is covered where the output of the system is used in the EU.
Source: Article 5 — artificialintelligenceact.eu →The Eight Original Prohibitions at a Glance
Article 5(1) sets out eight prohibited practices, lettered (a) through (h). Each has precise conditions — and several have narrow, explicitly drafted exceptions.
| Art. 5(1) | Prohibited Practice | Typically Affects | Exception |
|---|---|---|---|
| (a) | Subliminal, manipulative, or deceptive techniques causing significant harm | Consumer apps, marketing tech, dark patterns | Lawful, transparent persuasion |
| (b) | Exploiting vulnerabilities of age, disability, or socio-economic situation | Products targeting children, elderly, or vulnerable groups | None |
| (c) | Social scoring causing unjustified or disproportionate detrimental treatment | Public authorities and private platforms | Justified, proportionate scoring in the original context |
| (d) | Predicting individual criminal offence risk based solely on profiling or personality traits | Law enforcement, risk assessment vendors | Human assessment support based on objective, verifiable facts |
| (e) | Untargeted scraping of facial images from the internet or CCTV for facial recognition databases | Facial recognition database vendors | None |
| (f) | Emotion inference in workplaces and educational institutions | HR software, employee monitoring, proctoring tools | Medical or safety purposes |
| (g) | Biometric categorisation to deduce race, political opinions, union membership, religion, sex life, or sexual orientation | Biometric analytics vendors | Lawful dataset labelling; certain law-enforcement uses |
| (h) | Real-time remote biometric identification in public spaces for law enforcement | Police and public security deployments | Three narrowly defined situations with prior authorisation |
Manipulation and Exploitation — Art. 5(1)(a) and (b)
Subliminal and Manipulative Techniques — (a)
The first prohibition targets AI systems that deploy subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques. Three cumulative conditions must all be met:
- The system uses subliminal, purposefully manipulative, or deceptive techniques
- The technique materially distorts behaviour, appreciably impairing the ability to make an informed decision
- The distorted behaviour causes, or is reasonably likely to cause, significant harm
The Commission guidelines draw the line between unlawful manipulation and lawful persuasion: advertising, recommendation, and personalisation that operate transparently remain permitted. The prohibition bites when techniques work covertly — below the threshold of awareness — and produce significant physical, psychological, or financial harm.
Exploiting Vulnerabilities — (b)
The second prohibition covers AI systems that exploit vulnerabilities of a person or group due to their age, disability, or specific social or economic situation, with the objective or effect of materially distorting behaviour in a manner that causes or is reasonably likely to cause significant harm.
Practical examples from the guidelines include AI toys that nudge children toward dangerous behaviour, and predatory lending or pricing systems that target people in financial distress. Unlike (a), this prohibition has no persuasion carve-out — targeting a protected vulnerability with harmful behavioural distortion is banned outright.
Source: Article 5 — AI Act Service Desk (European Commission) →The Biometric Prohibitions — Art. 5(1)(e), (f), (g)
Untargeted Facial Image Scraping
Creating or expanding facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage is banned. This provision targets the business model of services that harvested billions of face images from social media without consent. The scraping itself is the prohibited act — regardless of how the database is later used.
Article 5(1)(e) • No exceptions
Emotion Inference at Work and School
AI systems that infer emotions of natural persons in the areas of workplace and educational institutions are prohibited. This covers emotion analytics in hiring interviews, employee monitoring dashboards, call-centre agent scoring, and student proctoring. Outside these two contexts, emotion recognition is not banned but is classified as high-risk under Annex III.
Article 5(1)(f) • Exception: medical or safety purposes
Detecting driver fatigue in professional transport or supporting clinical care are the guideline examples of the medical/safety exception. HR analytics do not qualify.
Biometric Categorisation of Sensitive Attributes
Biometric categorisation systems that categorise individuals based on their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation are prohibited.
Article 5(1)(g) • Exceptions: lawful labelling or filtering of biometric datasets; categorisation in the area of law enforcement
Real-Time Remote Biometric Identification — Art. 5(1)(h)
The most heavily negotiated provision of the entire AI Act. The use of real-time remote biometric identification (RBI) systems — live facial recognition — in publicly accessible spaces for law enforcement purposes is prohibited, unless one of three exhaustively listed situations applies:
Targeted Search for Victims
The targeted search for specific victims of abduction, trafficking in human beings, or sexual exploitation, as well as the search for missing persons.
Article 5(1)(h)(i)
Imminent Threats and Terrorism
The prevention of a specific, substantial, and imminent threat to the life or physical safety of natural persons, or a genuine and present or genuine and foreseeable threat of a terrorist attack.
Article 5(1)(h)(ii)
Serious Crime Suspects
The localisation or identification of a person suspected of a criminal offence listed in Annex II, punishable in the Member State concerned by a custodial sentence of a maximum period of at least four years.
Article 5(1)(h)(iii) • Annex II
Safeguards That Apply Even Within the Exceptions
- Art. 5(2) — Use only to confirm the identity of the specifically targeted individual; a fundamental rights impact assessment (Article 27) and registration in the EU database (Article 49) are required
- Art. 5(3) — Prior authorisation by a judicial authority or independent administrative authority; in duly justified emergencies, authorisation may follow within 24 hours or use must stop
- Art. 5(4) — Each use must be notified to the market surveillance authority and the data protection authority
- Art. 5(5) — A Member State may only allow RBI if it has enacted national law; it must notify the Commission within 30 days, and may choose stricter rules — including not allowing RBI at all
New for 2026: Non-Consensual Intimate Material and CSAM
The Digital Omnibus on AI — adopted by the European Parliament on June 16, 2026, approved by the Council on June 29, 2026, and signed on July 8, 2026 — adds a new prohibition to Article 5, the first expansion of the banned list since the AI Act was adopted.
What Is Now Prohibited
AI systems that generate or manipulate non-consensual intimate images, video, audio, or similar material, or child sexual abuse material (CSAM).
The Provider-Side Standard
For providers, the prohibition applies where such generation is a reasonably foreseeable and reproducible outcome of the system that cannot be avoided without substantial technical modification. In practice, this requires generative AI providers to implement and maintain technical safeguards — content filters, safety classifiers, and abuse monitoring — that prevent these outputs from being a reproducible result of ordinary use.
Transition Period
The addition responds to the rapid growth of AI-generated intimate-image abuse and complements existing EU instruments on child sexual abuse and gender-based violence. For deployers, generating such material with any AI system was already unlawful under criminal law across Member States — the Omnibus places responsibility on the systems themselves.
Source: Gibson Dunn — EU AI Act Omnibus Agreement →The Commission Guidelines on Prohibited Practices
Two days after the prohibitions took effect, the European Commission approved Guidelines on Prohibited AI Practices (C(2025) 884, February 4, 2025). The formally adopted all-language version followed on July 29, 2025 (C(2025) 5052). At over 130 pages, the guidelines are the most detailed interpretive document on Article 5 available.
What the Guidelines Clarify
- Lawful persuasion vs. manipulation — transparent advertising, personalisation, and nudging remain permitted; covert techniques causing significant harm do not
- Scope of each prohibition — concrete examples and non-examples for all eight practices, including edge cases like AI companions, games, and wellness apps
- Interplay with other law — how Article 5 operates alongside the GDPR, the Digital Services Act, and consumer protection rules
- The medical/safety exception for emotion inference — interpreted narrowly, covering fatigue detection and clinical support, not HR analytics
- Out-of-scope uses — systems not placed on the EU market, and practices lacking the required harm element
Enforcement and Penalties: The €35M / 7% Tier
Article 99(3) reserves the highest fines in the AI Act for Article 5 violations. Penalties have been applicable since August 2, 2025, when Member States were required to designate market surveillance authorities and lay down their national penalty rules.
How Enforcement Works
- National market surveillance authorities police the prohibitions in each Member State — unlike GPAI model obligations, which the Commission’s AI Office enforces centrally
- Data protection authorities act in parallel where prohibited practices process personal data, since the GDPR applies cumulatively
- Member State penalty laws set the specific rules within the Article 99 maximums; several states also provide criminal sanctions for related conduct
- SME proportionality — for SMEs and startups, the lower of the fixed amount or percentage applies (Article 99(6))
Penalty Tiers Across the AI Act
| Violation Category | Maximum Fine | Article |
|---|---|---|
| Prohibited AI practices | €35M or 7% of global turnover | Art. 99(3) |
| Most other obligations (incl. Art. 50, high-risk) | €15M or 3% of global turnover | Art. 99(4) |
| GPAI model obligations | €15M or 3% of global turnover | Art. 101 |
| Incorrect or misleading information supplied | €7.5M or 1% of global turnover | Art. 99(5) |
Comparison: Prohibited vs High-Risk vs Transparency vs GPAI
The four obligation frameworks of the AI Act differ in who is bound, when, and how hard the penalties bite.
| Aspect | Prohibited (Art. 5) | High-Risk (Ch. III) | Transparency (Art. 50) | GPAI (Ch. V) |
|---|---|---|---|---|
| Nature | Banned outright | Permitted, heavily regulated | Permitted with disclosure | Permitted with documentation |
| Who is bound | Providers & deployers | Providers & deployers | Providers & deployers | Model providers |
| Applicable since / from | 2 Feb 2025 | 2 Dec 2027 (Omnibus deferral) | 2 Aug 2026 | 2 Aug 2025 |
| Penalties from | 2 Aug 2025 | 2 Dec 2027 | 2 Aug 2026 | 2 Aug 2026 |
| Maximum fine | €35M / 7% | €15M / 3% | €15M / 3% | €15M / 3% |
| Enforcement body | National authorities | National authorities | National authorities | AI Office (EU level) |
| Conformity assessment | ✗ None exists | ✓ | ✗ | ✗ |
| Omnibus impact | +2 new prohibitions (2 Dec 2026) | Deferred 16 months | Unchanged; watermarking grace to 2 Dec 2026 | Unchanged |
Read our companion guides: Article 50 Transparency Obligations and GPAI Model Obligations.
Five-Step Article 5 Screening Checklist
Because prohibited practices cannot be fixed with documentation or registration, the only compliance strategy is to make sure none of your systems performs one. Screen systematically:
Inventory Your AI Systems
List every AI system you provide or deploy — including embedded third-party tools, HR and recruitment software, scoring engines, biometric systems, and generative AI applications. Remember: deployers are bound by Article 5 just as providers are.
Screen Against the Ten Prohibitions
Check each system against the eight prohibitions in force since February 2, 2025, plus the two Omnibus additions applicable by December 2, 2026. The highest-frequency corporate risks: emotion inference in HR tools, cross-context scoring, and generative systems lacking abuse safeguards.
Check Exceptions and Document the Legal Basis
Where a use resembles a prohibited practice, verify whether a written exception applies — medical or safety purposes for emotion inference, objective-facts human assessment support for crime risk — and record the analysis. The Commission guidelines are the reference document for these boundary questions.
Remediate or Withdraw Immediately
The prohibitions are enforceable now, with no grandfathering. Disable prohibited functions, reconfigure systems, or withdraw them from the EU market. For generative systems, verify that safety filters make non-consensual intimate material and CSAM generation neither foreseeable nor reproducible.
Monitor Guidelines and Deadlines
Track the Commission guidelines, national market surveillance practice, and the December 2, 2026 deadline for the new prohibitions. Record your screening in a compliance log — documented diligence matters when authorities assess proportionality of fines.
Complete Article 5 Timeline
Frequently Asked Questions
Article 5 Readiness Checklist
Use this checklist to confirm that no system in your organisation crosses an Article 5 line.
| # | Item | Applies To | Status |
|---|---|---|---|
| 1 | Complete AI system inventory (provided and deployed, incl. third-party tools) | All | □ |
| 2 | No subliminal, manipulative, or deceptive techniques causing significant harm | All | □ |
| 3 | No exploitation of age, disability, or socio-economic vulnerability | All | □ |
| 4 | Scoring systems reviewed for cross-context or disproportionate detrimental treatment | All | □ |
| 5 | No individual crime-risk prediction based solely on profiling or personality traits | All | □ |
| 6 | No untargeted scraping of facial images for recognition databases | All | □ |
| 7 | No emotion inference in workplace or educational contexts (or documented medical/safety basis) | HR / EdTech | □ |
| 8 | No biometric categorisation of race, politics, union membership, religion, sex life, or orientation | Biometric | □ |
| 9 | No real-time remote biometric identification, or exception + authorisation documented | Law enforcement | □ |
| 10 | Generative systems safeguarded against non-consensual intimate material output | GenAI | □ |
| 11 | Generative systems safeguarded against CSAM output | GenAI | □ |
| 12 | Exception analyses documented with reference to the Commission guidelines | All | □ |
| 13 | Legacy systems screened (no grandfathering applies) | All | □ |
| 14 | Screening log maintained for market surveillance inquiries | All | □ |
| 15 | December 2, 2026 Omnibus transition deadline tracked | GenAI | □ |
Is Your AI Compliance Ready?
Take the free AI Act readiness diagnosis. Get a personalised compliance score in 2 minutes.
Social Scoring and Crime Prediction — Art. 5(1)(c) and (d)
Social Scoring — (c)
AI systems that evaluate or classify people over time based on their social behaviour or known, inferred, or predicted personal characteristics are prohibited where the resulting score leads to either:
Critically, the ban applies to private companies as well as public authorities. It does not automatically prohibit credit scoring, insurance pricing, or fraud detection based on relevant data in the original context — the test is cross-context misuse or disproportionate treatment based on social data.
Individual Crime Prediction — (d)
AI systems that assess or predict the risk of a natural person committing a criminal offence, based solely on profiling or on assessing personality traits and characteristics, are prohibited.
The provision contains an explicit carve-out: AI systems used to support the human assessment of involvement in criminal activity remain permitted where that assessment is already based on objective and verifiable facts directly linked to a criminal activity. Place-based predictive policing — forecasting where offences may occur rather than who will commit them — also falls outside the prohibition, though it may be high-risk under Annex III.