Insights · Prohibited AI practices
EU AI Act Article 5: Prohibited AI Practices
Article 5 prohibited AI practices: social scoring, manipulative AI, biometric categorisation, facial scraping, and a practical product-and-legal review lens.
Article 5 and Title II of the EU AI Act define prohibited AI practices — uses considered incompatible with EU values. Unlike high-risk systems, these are not solved with extra paperwork: the deployment itself must change. Product and legal reviews should include a fast Article 5 screen on every feature that touches biometrics, emotion, scoring, or manipulation.
Article 5 themes to assess in design reviews
- Subliminal or manipulative techniques that materially distort behaviour causing harm.
- Exploitation of vulnerabilities (age, disability, social situation) — specific conditions in Article 5.
- Social scoring — evaluation or classification leading to detrimental treatment in unrelated contexts or treatment that is unjustified or disproportionate.
- Certain remote biometric identification in publicly accessible spaces for law enforcement — narrow exceptions and conditions.
- Untargeted scraping of facial images from the internet or CCTV to build databases.
- Emotion inference in workplaces and schools — subject to limited exceptions (safety, medical).
Design and procurement guardrails
Map user journeys, not only model classes: a “harmless” classifier can become problematic when combined with automated decisions affecting workers or students. Vendor contracts should reference compliance with applicable EU AI Act prohibitions for the agreed use case.
Not legal advice
Definitions in Article 5 are legal tests. Always involve qualified counsel for borderline cases; use this article and Agent Mai outputs as structured input to that review, not a substitute for it.
The complete Article 5 screening lens
A practical screen should cover every prohibition, not only the best-known examples. Review harmful manipulation and deception, exploitation of vulnerabilities, social scoring, individual criminal-offence risk assessment based solely on profiling or personality traits, untargeted facial-image scraping, emotion inference in workplaces and education, biometric categorisation using specified sensitive attributes, and real-time remote biometric identification by law enforcement in publicly accessible spaces subject to narrow conditions and exceptions.
Questions product teams should answer
- Does the feature infer, rank, score, predict, categorise, identify, persuade, or alter a person's choices or access to an opportunity?
- Could age, disability, economic hardship, dependence, workplace power, education status, or another vulnerability make a person more susceptible or exposed to harm?
- Are biometric signals used to identify a person, infer emotion, or derive sensitive characteristics, and in what physical or organisational setting?
- Does a score created in one context lead to detrimental or unfavourable treatment in another or to treatment that is unjustified or disproportionate?
- Are images collected from the internet or CCTV at scale to create or expand a facial-recognition database?
- Does a law-enforcement use rely on real-time remote biometric identification in a publicly accessible space, and who has documented the legal authority and safeguards?
Screen the full user journey
Article 5 risk often emerges from the combination of data, model output, interface, incentive, and downstream action. A sentiment model becomes materially different when used to monitor workers; a ranking feature changes when it affects access to education or essential services. Document inputs, inferred attributes, affected people, decision consequences, human discretion, data sources, deployment location, and the stated and foreseeable purposes.
Escalation and release controls
Create a mandatory legal escalation for biometric, emotion, behavioural manipulation, vulnerability, social-scoring, and criminal-risk signals. Block production release until the screen is resolved, record the statutory test and facts, and preserve dissent or uncertainty. Procurement should prohibit suppliers from changing relevant data sources or inference capabilities without notice because an upstream change can alter the Article 5 analysis.
Example signals that require a closer review
- A hiring tool adds webcam-based emotion or personality inference to candidate scoring.
- A learning platform uses behavioural signals to infer attention or emotional state in a classroom.
- A customer platform combines unrelated conduct data into a trust score that changes access to services.
- A sales interface uses personalised pressure techniques aimed at people experiencing financial hardship.
- A security vendor expands a face database through broad scraping rather than a controlled, lawful source.
- A fraud product predicts criminal conduct from profiling without objective and verifiable facts linked to criminal activity.
These signals do not replace the statutory test. They are triage triggers that force the team to gather facts and obtain qualified legal review before release. Article 5 infringements can attract the Act's highest penalty tier, which is another reason to make the screen an auditable product gate rather than an optional policy check.
Frequently asked questions
Can prohibited AI be made compliant with more documentation?
No. If a use falls within an Article 5 prohibition and no narrow statutory exception applies, documentation does not make that use lawful. The feature, purpose or deployment must change or stop.
Is emotion recognition always prohibited?
Article 5 prohibits specified emotion-inference uses in workplaces and education institutions, subject to narrow medical or safety grounds. Other emotion-related uses may still trigger high-risk, transparency, GDPR, employment and fundamental-rights analysis.
When did Article 5 start applying?
The prohibited-practices rules started applying on 2 February 2025. Commission guidelines provide non-binding interpretation, while the Regulation remains the binding legal source.
Related articles
- EU AI Act Article 4: AI Literacy RequirementsUnderstand the EU AI Act Article 4 AI literacy requirement, the people in scope, role-based learning, and practical evidence for providers and deployers.
- EU AI Act Article 50: Transparency RequirementsA practical guide to EU AI Act Article 50 transparency obligations for AI interactions, AI-generated content, deepfakes, and the evidence teams should retain.
- EU AI Act GPAI Obligations: Provider and Buyer GuideGPAI model obligations under the EU AI Act: documentation, copyright policy, systemic risk, and what downstream deployers should verify.
Educational content only — not legal advice. Verify obligations with qualified counsel.