Article 5 prohibited AI practices — eight banned, a ninth pending
Article 5 of the EU AI Act bans eight specific AI practices outright. Enforceable since February 2025. What's banned, what's allowed, and the narrow exceptions.
Article 5 of the EU AI Act lists eight categories of AI practice that are banned outright. These aren’t risk-tiered or subject to conformity assessment — they’re prohibited. Enforceable since 2 February 2025, with fines up to €35 million or 7% of global turnover (Article 99(3)). This guide walks through each one with concrete examples. A ninth prohibition — targeting AI that generates non-consensual intimate imagery (NCII) or child sexual abuse material (CSAM) — is coming under the Digital Omnibus (politically agreed 7 May 2026, pending formal adoption; see the end of this guide).
The eight prohibitions
1. Subliminal techniques (Art. 5(1)(a))
AI that uses subliminal techniques beyond a person’s consciousness, or manipulative or deceptive techniques, with the objective or effect of materially distorting behaviour in a way that causes or is reasonably likely to cause significant harm.
The catch: the bar is “materially distorting behaviour” with significant harm potential. Standard persuasive UI patterns (“limited time offer,” gamified loops) are not banned. AI that bypasses conscious awareness with personalised manipulation, particularly of vulnerable users, is.
2. Exploitation of vulnerabilities (Art. 5(1)(b))
AI that exploits vulnerabilities of a person or specific group due to age, disability, or social/economic situation, to materially distort behaviour in a way that causes or is reasonably likely to cause significant harm.
This catches AI products designed to target children, the elderly, or financially desperate users in ways that nudge them toward self-harming decisions (predatory lending recommendations, addictive gameplay for minors, exploitative dating apps).
3. Social scoring (Art. 5(1)(c))
AI that evaluates or classifies natural persons based on social behaviour or known/predicted personal characteristics, where the social score leads to:
- Detrimental or unfavourable treatment in unrelated social contexts, or
- Detrimental or unfavourable treatment that is disproportionate to the behaviour
The reference is China’s social credit system, but the prohibition is broader. Cross-context use of behavioural scores — even commercial ones — risks falling here.
4. Predictive policing (Art. 5(1)(d))
AI used solely on the basis of profiling or assessment of personality traits to predict the risk of committing a criminal offence. The exception: when the prediction supports a human assessment of involvement in a criminal activity already supported by objective and verifiable facts.
5. Untargeted facial scraping (Art. 5(1)(e))
AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
This was the article aimed at Clearview AI’s business model. Building a face-recognition product by scraping public photos is banned. Building one from licensed datasets or your own user-uploaded photos is not.
6. Emotion recognition in workplaces and schools (Art. 5(1)(f))
AI for emotion-recognition in workplaces or educational institutions, except for safety or medical reasons.
This catches:
- “Engagement detection” cameras in classrooms
- “Worker mood” tracking systems
- AI that scores employee “candidness” or “stress” from voice/video
The exception is narrow — medical (e.g., detecting driver fatigue in a safety-critical context) or safety (detecting violence about to occur). Marketing surveillance (“how do customers feel about our store?”) is fine; employee surveillance is not.
7. Biometric categorisation of sensitive attributes (Art. 5(1)(g))
AI that categorises natural persons based on biometric data to infer race, political opinions, trade-union membership, religious beliefs, sex life, sexual orientation, or philosophical beliefs.
Narrow exception for law enforcement labelling or filtering lawfully acquired datasets.
8. Real-time remote biometric identification in public spaces (Art. 5(1)(h))
Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes — banned by default. Narrow exceptions for:
- Targeted search for missing persons, including children
- Prevention of imminent threats to life or terrorist attacks
- Localisation of suspects of specific listed serious offences
When used under exception, judicial or independent administrative authorisation is required.
A ninth prohibition coming under the Digital Omnibus (pending)
The Digital Omnibus — politically agreed on 7 May 2026 and not yet formally adopted — adds a new Article 5 prohibition: AI systems that generate non-consensual intimate imagery (NCII) or child sexual abuse material (CSAM), including so-called “nudifier” apps.
It targets systems designed for those purposes, and systems where such outputs are reasonably foreseeable and reproducible in the absence of reasonable, proportionate, and effective safeguards — so “we didn’t intend it” is not a defence if the capability is left unguarded.
Narrow carve-outs: intimate content generated with the explicit consent of the people depicted; lawful tools for detecting, investigating, or moderating CSAM; and the development of the underlying generative capabilities themselves.
Expected to apply from 2 December 2026 once the Omnibus is adopted and published in the Official Journal. Until then it is a provisional agreement, not law — but providers of generative-media systems should build the safeguards now.
What “publicly accessible space” means
For point 8 specifically, the prohibition applies in “publicly accessible spaces” — defined as any physical place accessible to an undefined number of persons. This includes streets, parks, train stations, shopping centres. It excludes private workplaces (where other prohibitions apply via point 6) and members-only locations.
Practical examples — banned vs allowed
| Use case | Verdict | |---|---| | Emotion AI in retail kiosks (consumer mood) | Allowed (not workplace/education) | | Emotion AI scoring sales reps’ empathy on calls | Banned (workplace) | | Emotion AI detecting driver fatigue in trucking | Allowed (safety exception) | | Face-recognition login (your own user database) | Allowed (not untargeted scraping) | | Face-recognition product built from scraped Instagram photos | Banned (Art. 5(1)(e)) | | AI scoring of student attentiveness via classroom camera | Banned (education + emotion) | | AI scoring tutorial completion times in an LMS | Allowed (no emotion or biometric inference) | | Loan AI exploiting financially-desperate applicants with high-rate offers | Banned (vulnerability exploitation) | | Loan AI offering tier-based pricing based on credit score | Allowed (transparent risk-based pricing) |
When prohibitions apply
The prohibitions apply regardless of risk classification — there is no exception for low-confidence systems, internal prototypes, or research. From 2 February 2025 onward, deploying or placing on the market any of the above is a Tier 1 infringement.
For research and academic contexts, Article 2(8) excludes AI systems developed and put into service for the sole purpose of scientific research and development from the Regulation’s scope entirely.
What you should screen for
Before any AI feature ships in the EU:
- Workplace surveillance — is any emotion-recognition involved? If yes, halt
- Vulnerable user targeting — is any behavioural manipulation targeted at age, disability, or socioeconomic status?
- Cross-context scoring — is any output used outside its original context in ways that disadvantage users?
- Biometric data flow — is sensitive attribute inference happening?
- Public-space biometric ID — if your customer is law enforcement, is there judicial authorisation?
If any signal fires, get legal counsel before shipping.
Penalty scale
The Article 5 prohibition is the most heavily penalised band (Article 99(3)):
- Up to €35 million or 7% of global annual turnover, whichever is higher
- For SMEs (Art. 99(6)), the lower of the two amounts applies
This is the band where company-ending fines live. Classify carefully and document the reasoning — a one-time accidental Article 5 deployment is the cleanest path to a Tier 1 enforcement action.