Prohibited AI Practices: 8 Things Your Company Must Stop Doing by August
Prohibited AI Practices: 8 Things Your Company Must Stop Doing by August

Prohibited AI Practices: 8 Things Your Company Must Stop Doing by August

Prohibited Practices · 9 min read · Updated March 2026

Article 5 of the EU AI Act prohibits eight categories of AI practices outright — no conformity pathway, no grace period. These bans took effect on 2 February 2025. If your organisation is still operating any of the systems described below, you are already in violation and face the highest penalty tier in the Act.

⚠ Already in Force
  • These prohibitions have been in force since 2 February 2025 — not August 2026.
  • Violations attract fines of up to €35,000,000 or 7% of global annual turnover — the highest tier in the Act, exceeding GDPR maximums.
  • There is no conformity assessment pathway for prohibited practices. Compliance means ceasing the practice entirely.
  • Many organisations have unknowingly deployed systems that fall within these categories through third-party vendors. Vendor audits are essential.

Why Article 5 Exists: The “Unacceptable Risk” Threshold

The EU AI Act’s risk classification system — from minimal risk to unacceptable risk — is built on the premise that some AI applications are so inherently dangerous to fundamental rights, human dignity, and democratic values that no degree of technical safeguarding can make them acceptable. These are not cases where better documentation or stronger oversight suffices. They are cases where the practice itself must be prohibited.

The eight prohibited practices were finalised after intense debate during the Act’s three-year legislative process. The European Parliament pushed for broader prohibitions, while member state governments sought narrower carve-outs for law enforcement. The final text reflects a compromise — but one with genuine teeth.

Here is each prohibited practice in detail, with the legal text, what it actually means in practice, and the grey areas your legal team needs to be aware of.

The 8 Prohibited AI Practices Under Article 5

#1 Subliminal and Subconscious Manipulation

What the Act says: AI that deploys subliminal techniques beyond a person’s consciousness, or other manipulative or deceptive techniques, to materially distort behaviour in a way that causes or is likely to cause significant harm.

What this means in practice: AI systems designed to influence decision-making through mechanisms people cannot detect or consciously resist — including ultra-personalised dark patterns, subliminal audio cues embedded in media, or interface designs that exploit cognitive biases to coerce behaviour. The key tests are: (1) the technique operates below the threshold of conscious awareness; and (2) it causes or is likely to cause significant harm.

Grey area: Standard personalisation and recommendation engines are not prohibited — they influence choices but not subliminally. The prohibition targets techniques that deliberately bypass conscious decision-making. However, highly manipulative dark patterns combined with AI-driven personalisation could attract scrutiny.
#2 Exploitation of Vulnerabilities

What the Act says: AI that exploits any of the vulnerabilities of a specific group of persons due to their age, disability, or specific social or economic situation to materially distort the behaviour of any person belonging to that group in a way that causes or is likely to cause harm.

What this means in practice: Targeted AI systems that specifically identify and exploit vulnerabilities — gambling apps that use AI to detect and target problem gamblers, financial product marketing AI that identifies and exploits people in debt distress, social media AI that escalates emotional distress in people with known mental health conditions.

Grey area: The prohibition requires deliberate exploitation of vulnerability and likely harm. General age-group targeting in marketing is not automatically prohibited. The test is whether the AI is specifically designed to weaponise a vulnerability against the person’s own interests.
#3 Social Scoring by Public Authorities

What the Act says: AI used by or on behalf of public authorities to evaluate or classify natural persons or groups based on their social behaviour or known, inferred, or predicted personal characteristics — where the score leads to detrimental or unfavourable treatment that is unjustified or disproportionate.

What this means in practice: Government or public-body AI systems that assign citizens a score based on behaviour and use that score to determine access to services, impose restrictions, or apply preferential treatment. This directly targets “social credit system” style approaches and any government programme that algorithmically ranks citizens.

Grey area: Private sector credit scoring (banks, insurers) is regulated as high-risk under Annex III, not prohibited. The prohibition applies specifically to public authorities using social behaviour scoring to confer advantages or disadvantages in public service contexts.
#4 Predictive Policing Based Solely on Profiling

What the Act says: AI used by law enforcement to assess the risk of a natural person committing a criminal offence solely based on profiling or on assessing the personality traits and characteristics of that person — without any basis in objective and verifiable facts directly linked to criminal activity.

What this means in practice: Predictive policing tools that generate individual-level risk scores for people who have not yet committed any offence, based purely on demographic profiling, social network analysis, or neighbourhood characteristics. The critical phrase is “solely based on” — AI used to corroborate existing evidence-based investigations is handled differently.

Grey area: AI tools that assist in analysing objective, verifiable facts related to an existing criminal investigation are high-risk (Annex III, Category 6), not prohibited. The prohibition targets pre-crime profiling with no factual basis — a conceptually important but legally narrow distinction.
#5 Untargeted Scraping of Facial Images

What the Act says: AI used to create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage.

What this means in practice: Building facial recognition training datasets or identity databases by mass-scraping images from social media, news sites, public cameras, or any other source without targeted purpose. This directly addresses companies like Clearview AI that built commercial facial recognition products by scraping billions of public images.

Immediate action required: If your AI vendor’s facial recognition system was trained on mass-scraped data, using it may constitute participation in a prohibited practice. Request your vendor’s training data provenance documentation immediately. See the EDPB guidance on facial recognition for additional GDPR context.
#6 Emotion Inference in Workplaces and Educational Institutions

What the Act says: AI used to infer the emotions of natural persons in workplaces and educational institutions — except where the AI system is intended to be put in place for medical or safety reasons.

What this means in practice: Employee monitoring software that analyses facial expressions, voice tone, or other biometric signals to infer emotional states (stress, engagement, frustration, dishonesty). AI proctoring systems that analyse student facial expressions during exams to infer concentration or suspicious behaviour. “Lie detector”-style AI interview tools that claim to detect deception from facial microexpressions.

High enterprise exposure: Multiple HR technology and video interview platforms marketed “engagement scoring” or “culture fit” features based on emotion inference. Many employers adopted these tools during 2020–2023. If your HR tech stack includes any AI that claims to analyse candidate or employee emotional states, it must be reviewed immediately and disabled if it falls within this prohibition.
#7 Biometric Categorisation by Sensitive Characteristics

What the Act says: AI systems that categorise natural persons individually based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.

What this means in practice: AI that uses facial images, voice recordings, or other biometric inputs to infer or predict sensitive attributes — including systems marketed for “diversity analytics,” systems that claim to detect sexual orientation from photographs, and advertising tech that uses biometric data to infer political affiliation for targeting.

Note: This prohibition applies to inferring these characteristics from biometric data — it is distinct from identity verification systems that use biometrics to confirm a known identity. The harm is in the categorisation of people by protected characteristics without their knowledge or consent.
#8 Real-Time Remote Biometric Identification in Public Spaces (by Law Enforcement)

What the Act says: The use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes — with three narrow exceptions requiring prior judicial authorisation.

The three narrow exceptions (requiring prior judicial or equivalent authorisation):

  • Targeted searching for victims of specific criminal offences (abduction, human trafficking, sexual exploitation)
  • Prevention of a specific, substantial, and imminent threat to life or a terrorist attack
  • Identification of perpetrators of criminal offences carrying a maximum penalty of at least 4 years

What this means in practice: Mass live facial recognition surveillance of the public is prohibited. The exceptions are narrow, require authorisation from a judicial or independent body, and must be time and location limited. Private sector deployment of real-time biometric surveillance in public spaces (airports, shopping centres, events) is entirely prohibited — the exceptions apply only to law enforcement.

Private sector note: This is an absolute prohibition for private organisations. Facial recognition cameras in retail stores, entertainment venues, sports stadiums, or transport hubs operated by private entities are prohibited without exception. Review any smart camera installations that include real-time facial recognition functionality.

What to Do If Your Organisation Is Operating a Prohibited AI System

If you recognise any of the above practices in your organisation’s current AI systems, immediate action is required. These bans have been in force since 2 February 2025 — delay compounds your legal exposure.

1
Cease operation immediately. Suspend or disable the prohibited AI system without waiting for legal advice on alternatives. Operating a prohibited system is an ongoing violation — every day the system runs is a separate exposure. Document the suspension decision with a date and responsible person.
2
Engage qualified legal counsel within 7 days. Article 5 violations carry the highest penalties in the Act. You need a lawyer experienced in EU AI law to advise on self-disclosure strategy, cooperation with authorities, and mitigation. Voluntary disclosure before a formal investigation typically results in significantly reduced penalties.
3
Notify affected deployers or customers. If you are a Provider of a system that turns out to be prohibited, your downstream deployers need to know immediately. Failing to notify them may compound your liability and damage trust with key customers.
4
Assess whether a compliant alternative exists. In many cases, the same business need can be met through a compliant approach: replacing real-time facial recognition with access card systems; replacing emotion inference with structured psychometric assessments; replacing mass profiling with targeted, evidence-based investigation tools.
💡
Not sure whether your AI systems cross the prohibited line or merely fall into the high-risk tier? Use our free 2-minute EU AI Act Risk Assessment Tool to get an instant classification with a personalised explanation.

Frequently Asked Questions

The deadline said “August” — but these bans started in February 2025. Which is it? +
Both are correct for different obligations. The prohibited practices under Article 5 took effect on 2 February 2025 — six months after the Act entered into force. The broader high-risk AI compliance obligations (conformity assessment, technical documentation, EU database registration, etc.) take effect from 2 August 2026. If you are still operating a prohibited AI system, you have been in violation since February 2025, not August 2026.
What if our vendor claims their system doesn’t fall under Article 5? +
Vendor self-certification is not sufficient for Article 5 compliance decisions. Your organisation bears independent responsibility for ensuring the AI systems you deploy are not prohibited. Request written legal analysis from your vendor on why their system does not fall under Article 5, and have your own legal counsel review it. If you cannot obtain satisfactory documentation, treat the system as potentially prohibited until resolved.
Are there any Article 5 exceptions besides the law enforcement carve-outs? +
Limited exceptions exist for specific practices: emotion inference is excepted for medical or safety reasons (e.g. detecting fatigue in vehicle operators or monitoring patients in intensive care). Real-time biometric surveillance has the three narrow law-enforcement exceptions described above. All other exceptions must be read narrowly — they are not intended to create general carve-outs, and regulators are expected to scrutinise exception claims carefully.
What are the fines for Article 5 violations and how are they calculated? +
Article 99(3) sets fines for prohibited AI practices at up to €35,000,000 or 7% of global annual turnover for the preceding financial year — whichever is higher. For large multinationals, the turnover percentage will nearly always be the binding constraint. For SMEs and startups, the lower of the fixed cap or percentage applies. Regulators must also consider proportionality, the nature and gravity of the violation, the duration, and the organisation’s cooperation. See our complete EU AI Act Summary for the full penalty structure.
Check your full compliance status
Beyond Article 5, are your high-risk AI systems ready for the August 2026 deadline? Our compliance checklist covers all four phases of implementation.
View the Compliance Checklist →
Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like