EU AI Act prohibited practices (Article 5): what is banned, and the business uses that get caught
Most EU AI Act obligations are still on their way. Article 5 is not. The prohibited-practices list has applied since 2 February 2025, it carries the Act's highest fine tier, and "we only use the tool, we did not build it" gives you no cover: every prohibition covers the use of the system, whoever built it.
It is also shorter and more precise than its reputation suggests. Each prohibition is a chain of conditions, and a use is only banned when every link holds. This guide sets out the list, the qualifiers that decide the question, and where some ordinary business uses actually land.
The prohibited list at a glance
Eight practices in Article 5(1) apply today. The Digital Omnibus — Regulation (EU) 2026/1744 — has inserted two more, points (ba) and (bb), which apply from 2 December 2026 under the amended Article 113(a).
| Point | What is banned, in plain English | The qualifier that decides it | Applies from |
|---|---|---|---|
| 5(1)(a) | Subliminal, purposefully manipulative or deceptive techniques | Must materially distort behaviour and cause, or be reasonably likely to cause, significant harm | 2 Feb 2025 |
| 5(1)(b) | Exploiting vulnerabilities due to age, disability or a specific social or economic situation | Same distortion and significant-harm test | 2 Feb 2025 |
| 5(1)(ba) | Generating or manipulating realistic intimate imagery of an identifiable person without explicit consent | Narrowed by Article 5(1a) and (1b) — see below | 2 Dec 2026 |
| 5(1)(bb) | Generating or manipulating child sexual abuse material | Narrowed by Article 5(1a); "without right" defence under national law | 2 Dec 2026 |
| 5(1)(c) | Social scoring of people based on social behaviour or personal characteristics | The score must lead to detrimental treatment in an unrelated context, or treatment that is unjustified or disproportionate | 2 Feb 2025 |
| 5(1)(d) | Predicting a person's risk of committing a crime | Only where based solely on profiling or personality traits | 2 Feb 2025 |
| 5(1)(e) | Creating or expanding facial recognition databases | Only through untargeted scraping of facial images from the internet or CCTV | 2 Feb 2025 |
| 5(1)(f) | Inferring emotions | Only in the workplace or education institutions; exception for medical or safety reasons | 2 Feb 2025 |
| 5(1)(g) | Biometric categorisation of individuals | Only to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation | 2 Feb 2025 |
| 5(1)(h) | Real-time remote biometric identification in publicly accessible spaces | Only for law enforcement, with three narrow exceptions and prior authorisation | 2 Feb 2025 |
Two things are easy to miss in that table. Point (h) is not a general ban on facial recognition by companies — it concerns law enforcement use only. And emotion recognition is defined by reference to biometric data: under Article 3(39), an "emotion recognition system" identifies or infers emotions or intentions "on the basis of their biometric data".
Who is caught: providers and users
Points (a), (b), (c) and the new (ba) and (bb) cover "the placing on the market, the putting into service or the use" of the system. Points (d) to (g) add the words "for this specific purpose" to putting into service. Point (h) covers only "the use" of real-time remote biometric identification. In every case, use is in the text, which means a deployer running a banned practice is in breach even if a vendor supplied the system. (For everything else a deployer owes, see EU AI Act deployer obligations.)
Three scope rules matter for businesses:
- Open source is no escape. The free and open-source exclusion in Article 2(12) expressly does not apply to AI systems that fall under Article 5.
- Pre-launch R&D is outside the Act. Article 2(8) excludes research, testing and development before a system is placed on the market or put into service. The Commission's guidelines give the example of experimenting with techniques that "could be seen as manipulative" in R&D. The same paragraph is explicit that testing in real-world conditions is not covered by the exclusion.
- Purely personal use is outside the Act. Article 2(10) excludes deployers who are natural persons using AI in a purely personal, non-professional activity. A company is never in that category.
Non-EU companies are caught too, where the system is placed on the EU market or its output is used in the EU — see does the AI Act apply outside the EU.
Where common business uses actually land
This is the part general summaries skip. The examples below are taken from the Commission's Guidelines on prohibited AI practices, C(2025) 5052 final (29 July 2025). The guidelines are, in their own words, "non-binding", and only the Court of Justice can give an authoritative interpretation. They are nonetheless the clearest statement of how the Commission reads the text.
| Use | Where it lands | Basis |
|---|---|---|
| Webcams or voice analysis tracking your own call-centre agents' emotions, such as anger | Prohibited | Art. 5(1)(f); guidelines §7.2.2 |
| Emotion recognition during recruitment or a probationary period | Prohibited — "workplace" includes candidates | Art. 5(1)(f); guidelines §7.2.2 |
| AI reading the emotional tone of hybrid team video calls | Prohibited | Art. 5(1)(f); guidelines §7.2.2 |
| Emotion recognition used only for personal training, with results not shared with HR and no effect on assessment or promotion | Allowed, provided the prohibition is not circumvented | Guidelines §7.2.2 |
| Voice analysis tracking customers' anger or impatience to help staff cope | Not caught by 5(1)(f) — may still fall under 5(1)(a)/(b) if manipulative and harmful | Guidelines §7.2.2 and §7.4 |
| Personalised recommendations with transparent logic and user controls | Lawful persuasion, not manipulation | Art. 5(1)(a); guidelines §3.5.1 |
| Covertly inferring shoppers' emotions to push higher prices at the moment they are most likely to buy | The guidelines' own example of manipulation — prohibited where the harm conditions are also met | Art. 5(1)(a); guidelines §3.5.1 |
| Credit scoring on income, expenses and financial circumstances, in line with sectoral law | Outside 5(1)(c) — but high-risk | Guidelines §4.3; see credit scoring |
| User star ratings of drivers or hosts, simply aggregated | Not social scoring unless combined with other data and analysed by AI to meet every 5(1)(c) condition | Guidelines §4.3 |
| Scraping public web images to build a face-search database | Prohibited | Art. 5(1)(e) |
| Inferring religion or sexual orientation from face photos | Prohibited | Art. 5(1)(g) |
The pattern is consistent. The ban follows the setting and the effect, not the technology. Emotion inference aimed at your staff or applicants is banned; aimed at customers, it is judged under the manipulation and exploitation tests, and under the high-risk and transparency rules. If you sell or use HR tools, the recruitment rows are the ones to check first — see the AI Act for HR software.
For the full Article 5(1)(f) analysis — the biometric-data gate, why text-based sentiment analysis falls outside it, and how narrow the medical-or-safety exception is — see is AI emotion recognition banned at work?
The manipulation test, read properly
Articles 5(1)(a) and (b) are the prohibitions most likely to worry product and growth teams, and they are narrower than they sound. Each requires, cumulatively:
- a manipulative, deceptive or subliminal technique (or, for (b), exploitation of a listed vulnerability);
- with the objective or the effect of materially distorting behaviour (for (a), by appreciably impairing the ability to make an informed decision);
- causing, or being reasonably likely to cause, significant harm.
The guidelines draw the working line between manipulation and lawful persuasion. Manipulation "involves, in most cases, covert techniques undermining autonomy". Persuasion "operates within the bounds of transparency and respect for individual autonomy". Transparency, consent and compliance with laws such as the GDPR all push a practice towards the lawful side.
Two cautions. "Objective or effect" means intent is not required — a system can be caught by what it does. And the conditions are cumulative, so a design pattern you dislike is not automatically a prohibited practice. Document why yours is not.
What changes on 2 December 2026
The Omnibus adds points (ba) and (bb) on AI-generated intimate imagery and child sexual abuse material. New Article 5(1a) decides when a general-purpose generator is caught. Placing such a system on the market or putting it into service is prohibited only where generating that material is its intended purpose, or where two conditions both hold: the system's design, training, architecture, capabilities or user-facing functionalities make it a "reasonably foreseeable and reproducible outcome", without requiring significant technical modification; and the system lacks "reasonable and adequate technical safety measures and other safeguards" to reliably prevent it, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse. For use, the ban applies only where the deployer uses the system for that purpose.
The practical consequence is that safeguard adequacy becomes a prohibition question for anyone offering open-ended image, video or audio generation. The full analysis is in the 2 December 2026 deadline.
Fines, and the SME rule that does not stretch
| Rule | What it says |
|---|---|
| Article 99(3) | Up to €35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher |
| Article 99(6) | For SMEs, including start-ups: whichever is lower |
| Article 99(6a) | The Omnibus's lighter rule for small mid-caps covers fines under Articles 99(4) and (5) only — not Article 5 breaches |
| Article 113(b) | The penalty chapter has applied since 2 August 2025 |
Fines are set nationally by the authorities in each Member State, weighing the factors in Article 99(7), including cooperation and whether you notified the infringement yourself. See the full fine structure and who enforces the Act. If you are a small company, the SME rules explain what relief exists and what does not.
A caution about the sources you are reading
Two official sources lag the law on Article 5 (both re-checked on 29 September 2026):
- The AI Act Service Desk's Article 5 page carries the Commission's own notice that the provision "has been amended by the Digital Omnibus on AI" and that the text shown "has not yet been updated". It lists only points (a) to (h), with no (ba), (bb), 5(1a) or 5(1b).
- The Commission's prohibited-practices guidelines date from July 2025, before the Omnibus, and so do not address the two new points. Article 96(2) lets the Commission update guidelines "when deemed necessary", but sets no date.
For the current wording, read the consolidated text and look for the amendment markers. Many summaries also cite C(2025) 884 final. That document is the internal Communication approving the draft content; the guidelines themselves are C(2025) 5052 final.
What to do now
- Inventory by setting, not by vendor. List every AI system that touches employees, applicants, students, or biometric data. Those are the settings where Article 5 bites hardest.
- Switch off workplace emotion inference. If a tool infers emotions of staff or candidates from face, voice or other biometric data, it needs a documented medical or safety basis or it should not be running. The ban has applied since February 2025.
- Write down your persuasion case. For personalisation, pricing and engagement features, record why they are transparent, controllable and not harmful — the guidelines' criteria.
- Check the scoring edge. Any score about people that is reused outside the context it was built for needs a look under Article 5(1)(c).
- If you offer generative media, test your safeguards now. 2 December 2026 turns their adequacy into a prohibition question.
- Then move on to high-risk and transparency. Most business AI is not prohibited. Rule it out, then work out whether your system is high-risk. If you are unsure the software is an AI system at all, that test comes first.
To see which obligations apply to your company, sorted by deadline, answer a few questions about your AI use. To hear when the Commission updates its Article 5 guidelines, when the Service Desk catches up with the Omnibus, or when an authority first acts on a prohibited practice, join the waitlist.
The official text is Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. This article is an information service to help you orient — it is not legal advice.
Frequently asked questions
What AI practices are prohibited under the EU AI Act?
Article 5(1) bans eight practices that have applied since 2 February 2025: harmful manipulative or deceptive techniques; harmful exploitation of vulnerabilities due to age, disability or social or economic situation; social scoring leading to unjustified or out-of-context detrimental treatment; predicting a person's risk of committing a crime based solely on profiling or personality traits; building facial recognition databases by untargeted scraping of facial images from the internet or CCTV; inferring emotions in the workplace or in education, except for medical or safety reasons; biometric categorisation to infer sensitive characteristics such as race, religion or sexual orientation; and real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions. The Digital Omnibus adds two more from 2 December 2026, covering AI-generated non-consensual intimate imagery and child sexual abuse material.
Does Article 5 apply to companies that only use AI, not build it?
Yes. Most of the prohibitions cover the placing on the market, the putting into service or the use of an AI system, so a deployer using a banned practice is caught just as a provider selling it is. The Act does not apply to people using AI in a purely personal, non-professional activity (Article 2(10)), and the free and open-source exclusion in Article 2(12) expressly does not extend to Article 5.
Is personalised pricing or a recommendation engine a prohibited manipulative practice?
Not as such. Article 5(1)(a) prohibits subliminal, purposefully manipulative or deceptive techniques only where they have the objective or effect of materially distorting behaviour by appreciably impairing the ability to make an informed decision, and cause or are reasonably likely to cause significant harm; the conditions are cumulative. The Commission's non-binding guidelines, C(2025) 5052 final, treat personalised recommendations with transparent logic and user controls as lawful persuasion. Their example of manipulation is covertly inferring shoppers' emotions to push higher prices at the moment they are most likely to buy, which is prohibited where the harm conditions are also met.
What is the fine for using a prohibited AI practice?
Up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(3). For SMEs, including start-ups, Article 99(6) caps it at whichever is lower. The newer, lighter rule for small mid-caps in Article 99(6a) covers only the Article 99(4) and (5) fines, not Article 5 breaches. The penalty provisions have applied since 2 August 2025.
See which obligations apply to your company → or join the waitlist
This is an information service, not legal advice.