← Back to Resource Center
EU AI Act · Article 5 7 min read

Article 5 prohibited AI practices — ten banned outright

Article 5 of the EU AI Act bans ten AI practices outright. Eight enforceable since February 2025, two more from December 2026. What's banned and the narrow exceptions.


Article 5 of the EU AI Act lists categories of AI practice that are banned outright. These aren’t risk-tiered or subject to conformity assessment — they’re prohibited. The original eight have been enforceable since 2 February 2025, with fines up to €35 million or 7% of global turnover (Article 99(3)). This guide walks through each one with concrete examples. Two further prohibitions — covering AI that generates non-consensual intimate imagery (NCII) and child sexual abuse material (CSAM) — were added by the Digital Omnibus on AI and apply from 2 December 2026 (see the end of this guide), bringing the total to ten.

The original eight prohibitions

1. Subliminal techniques (Art. 5(1)(a))

AI that uses subliminal techniques beyond a person’s consciousness, or manipulative or deceptive techniques, with the objective or effect of materially distorting behaviour in a way that causes or is reasonably likely to cause significant harm.

The catch: the bar is “materially distorting behaviour” with significant harm potential. Standard persuasive UI patterns (“limited time offer,” gamified loops) are not banned. AI that bypasses conscious awareness with personalised manipulation, particularly of vulnerable users, is.

2. Exploitation of vulnerabilities (Art. 5(1)(b))

AI that exploits vulnerabilities of a person or specific group due to age, disability, or social/economic situation, to materially distort behaviour in a way that causes or is reasonably likely to cause significant harm.

This catches AI products designed to target children, the elderly, or financially desperate users in ways that nudge them toward self-harming decisions (predatory lending recommendations, addictive gameplay for minors, exploitative dating apps).

3. Social scoring (Art. 5(1)(c))

AI that evaluates or classifies natural persons based on social behaviour or known/predicted personal characteristics, where the social score leads to:

  • Detrimental or unfavourable treatment in unrelated social contexts, or
  • Detrimental or unfavourable treatment that is disproportionate to the behaviour

The reference is China’s social credit system, but the prohibition is broader. Cross-context use of behavioural scores — even commercial ones — risks falling here.

4. Predictive policing (Art. 5(1)(d))

AI used solely on the basis of profiling or assessment of personality traits to predict the risk of committing a criminal offence. The exception: when the prediction supports a human assessment of involvement in a criminal activity already supported by objective and verifiable facts.

5. Untargeted facial scraping (Art. 5(1)(e))

AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

This was the article aimed at Clearview AI’s business model. Building a face-recognition product by scraping public photos is banned. Building one from licensed datasets or your own user-uploaded photos is not.

6. Emotion recognition in workplaces and schools (Art. 5(1)(f))

AI for emotion-recognition in workplaces or educational institutions, except for safety or medical reasons.

This catches:

  • “Engagement detection” cameras in classrooms
  • “Worker mood” tracking systems
  • AI that scores employee “candidness” or “stress” from voice/video

The exception is narrow — medical (e.g., detecting driver fatigue in a safety-critical context) or safety (detecting violence about to occur). Marketing surveillance (“how do customers feel about our store?”) is fine; employee surveillance is not.

7. Biometric categorisation of sensitive attributes (Art. 5(1)(g))

AI that categorises natural persons based on biometric data to infer race, political opinions, trade-union membership, religious beliefs, sex life, sexual orientation, or philosophical beliefs.

Narrow exception for law enforcement labelling or filtering lawfully acquired datasets.

8. Real-time remote biometric identification in public spaces (Art. 5(1)(h))

Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes — banned by default. Narrow exceptions for:

  • Targeted search for missing persons, including children
  • Prevention of imminent threats to life or terrorist attacks
  • Localisation of suspects of specific listed serious offences

When used under exception, judicial or independent administrative authorisation is required.

Two further prohibitions apply from 2 December 2026

The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, inserts two new points into Article 5(1) — not one. They apply from 2 December 2026:

  • Point (ba) — AI systems that generate or manipulate realistic images, video, audio or similar material of an identifiable person’s intimate parts, or of an identifiable person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent. This is the “nudifier” prohibition.
  • Point (bb) — AI systems that generate or manipulate child sexual abuse material within the meaning of Article 2(c) and (e) of Directive 2011/93/EU, except where a “without right” defence applies under national law.

New paragraphs 5(1a) and 5(1b) narrow how the two points bite, and the detail matters:

  • Placing on the market is prohibited only where generating such material is the system’s intended purpose, or where the system’s design, training, architecture, capabilities or user-facing functionality make it a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks reasonable, adequate safeguards to prevent and correct it. “We didn’t intend it” is not a defence if the capability is left unguarded.
  • Use is prohibited only where the deployer actually uses the system to produce such material.
  • Under 5(1b), manipulation that does not increase the exposure of depicted intimate parts or alter the nature of depicted sexually explicit activity is not “manipulation” for point (ba).

Recital 13 confirms the “without right” defence covers legitimate law-enforcement work, and red-teaming or evaluation carried out to test a system’s compliance with the prohibition itself.

This changes the headline count: Article 5(1) now lists ten prohibited practices, not eight.

What “publicly accessible space” means

For point 8 specifically, the prohibition applies in “publicly accessible spaces” — defined as any physical place accessible to an undefined number of persons. This includes streets, parks, train stations, shopping centres. It excludes private workplaces (where other prohibitions apply via point 6) and members-only locations.

Practical examples — banned vs allowed

Use caseVerdict
Emotion AI in retail kiosks (consumer mood)Allowed (not workplace/education)
Emotion AI scoring sales reps’ empathy on callsBanned (workplace)
Emotion AI detecting driver fatigue in truckingAllowed (safety exception)
Face-recognition login (your own user database)Allowed (not untargeted scraping)
Face-recognition product built from scraped Instagram photosBanned (Art. 5(1)(e))
AI scoring of student attentiveness via classroom cameraBanned (education + emotion)
AI scoring tutorial completion times in an LMSAllowed (no emotion or biometric inference)
Loan AI exploiting financially-desperate applicants with high-rate offersBanned (vulnerability exploitation)
Loan AI offering tier-based pricing based on credit scoreAllowed (transparent risk-based pricing)

When prohibitions apply

The prohibitions apply regardless of risk classification — there is no exception for low-confidence systems, internal prototypes, or research. From 2 February 2025 onward, deploying or placing on the market any of the above is a Tier 1 infringement.

For research and academic contexts, Article 2(8) excludes AI systems developed and put into service for the sole purpose of scientific research and development from the Regulation’s scope entirely.

What you should screen for

Before any AI feature ships in the EU:

  1. Workplace surveillance — is any emotion-recognition involved? If yes, halt
  2. Vulnerable user targeting — is any behavioural manipulation targeted at age, disability, or socioeconomic status?
  3. Cross-context scoring — is any output used outside its original context in ways that disadvantage users?
  4. Biometric data flow — is sensitive attribute inference happening?
  5. Public-space biometric ID — if your customer is law enforcement, is there judicial authorisation?

If any signal fires, get legal counsel before shipping.

Penalty scale

The Article 5 prohibition is the most heavily penalised band (Article 99(3)):

  • Up to €35 million or 7% of global annual turnover, whichever is higher
  • For SMEs (Art. 99(6)), the lower of the two amounts applies

This is the band where company-ending fines live. Classify carefully and document the reasoning — a one-time accidental Article 5 deployment is the cleanest path to a Tier 1 enforcement action.