Prohibited AI practices (AI Act Article 5)
What are prohibited AI practices?
Prohibited AI practices are the uses of AI that the EU AI Act bans outright. They sit in Article 5, at the top of the risk pyramid, and they have applied since 2 February 2025. The rest of the regulation tells you how to use AI properly. Article 5 tells you what you may not do at all.
That difference is bigger than it sounds. For a high-risk AI system you build a file: risk management, documentation, human oversight, a conformity assessment, and then you are allowed to run it. For a banned practice there is no file. No consent, no paperwork and no vendor certificate makes it legal.
The ban covers the whole chain. Article 5 prohibits placing such a system on the market, putting it into service, and using it. A company that buys a banned tool and switches it on is caught just as much as the company that built it, so the provider and the deployer are both on the hook.
On 4 February 2025 the Commission published guidelines on prohibited practices, with worked examples for each ban. They are not binding, the Court of Justice has the last word, but they show how narrowly the Commission reads the exceptions.
The eight practices that are banned
Each ban has its own wording and its own carve-outs. This is the short version, in the order of Article 5(1).
Subliminal or manipulative techniques. AI that works below a person's awareness, or through purposefully manipulative or deceptive techniques, and so distorts their behaviour that they take a decision they would not otherwise have taken, causing significant harm. The Commission's examples are images flashed too briefly to notice and hidden audio. Personalised advertising with rules the reader can see is not caught.
Exploiting vulnerabilities. The same distortion and harm test, but where the system works by exploiting age, disability, or a specific social or economic situation. Think a credit product aimed at people already in financial trouble, or an app that pushes expensive treatments at older users.
Social scoring. Evaluating people over a period of time on their social behaviour or inferred personal characteristics, where the score leads to worse treatment in a context unrelated to where the data came from, or to treatment out of all proportion to the behaviour. It applies to private companies as much as to public bodies. Assessing creditworthiness on relevant financial data is fine. Using someone's shopping habits to decide whether they get life insurance is the Commission's own example of what is banned.
Predicting crime from profiling alone. Assessing the risk that a person will commit a criminal offence based solely on profiling or on personality traits. AI that supports a human assessment already grounded in objective, verifiable facts about criminal activity stays allowed.
Untargeted scraping of facial images. Creating or expanding facial recognition databases by scraping face images from the internet or from CCTV footage without a target. Clearview AI is the textbook case: a database of tens of billions of photos, and a fine of 30.5 million euros from the Dutch data protection authority in September 2024, handed down under GDPR before this ban existed.
Emotion recognition at work and in education. Inferring emotions or intentions of people from their biometric data in the workplace or in an education institution. Medical and safety reasons are the only way out, and the guidelines read both narrowly: detecting driver fatigue for road safety fits, reading whether an employee sounds frustrated does not.
Biometric categorisation on sensitive traits. Systems that sort people by their biometric data to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. Labelling or filtering a lawfully acquired biometric dataset, and categorisation for law enforcement, are carved out.
Live facial recognition in public for law enforcement. Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes. Three exceptions survive, all needing prior authorisation: a targeted search for victims of abduction, trafficking or sexual exploitation and for missing persons, prevention of a specific and imminent threat to life or physical safety or of a terrorist attack, and locating a suspect in a serious offence. This ban is written for police forces. A company that runs live facial recognition on its own premises falls outside it and lands on GDPR instead, where the answer is usually still no.
Two more bans arrive on 2 December 2026
The Digital Omnibus on AI, Regulation (EU) 2026/1744, added two points to Article 5. From 2 December 2026 it is prohibited to place on the market or use AI systems that generate or manipulate realistic intimate imagery of an identifiable person without their explicit consent, and AI systems that generate child sexual abuse material.
The scope reaches past purpose-built nudifier apps. The ban catches a system where that output is the intended purpose, and also a general image or video generator where such output is a reasonably foreseeable and reproducible result and the provider has put no reasonable safeguards in place. For a deployer the ban bites when you use the system for that purpose. If you offer image generation to customers or staff, check what your filters block before that date.
Where an ordinary company walks into one
Six of the eight bans concern police forces, states and deliberately abusive products. Two of them sit inside software a Belgian company buys without thinking twice.
Emotion analysis in HR. The workplace test covers recruitment, so a video interview tool that scores a candidate's facial expressions or tone of voice for enthusiasm, stress or honesty is banned. So is a staff monitoring tool that infers mood or stress from webcam images or typing behaviour. The line runs at biometric data: scoring the wording of a written answer is sentiment analysis on text and is not emotion recognition at all.
The call-centre nuance. The ban protects the people at work, not the people on the other end of the line. A quality tool that reads the caller's tone of voice is outside Article 5(1)(f). The same tool pointed at your own agents is inside it. Plenty of products do both, and the demo rarely says which.
Marketing that infers sensitive traits. A tool that takes photos or voice recordings and sorts people into segments that amount to political leaning, religion or sexual orientation is the biometric categorisation ban, whatever the segment is called in the interface. Building the same segments from purchase history is allowed, because no biometric data goes in.
Access control on a scraped face database. The ban is on creating or expanding such a database. A face recognition access system that keeps topping up its reference set from public sources is doing exactly that, and you are the one running it. Ask where the reference images came from before the pilot.
Prohibited versus high-risk
Both categories come from the same regulation and both are about serious uses of AI. What separates them is whether compliance is possible at all.
A high-risk AI system is allowed. It costs you a heavy file and a conformity assessment, and the deadline for stand-alone Annex III systems moved to 2 December 2027, but there is a path. Whether you can carry those obligations is a budget question you can answer later.
A prohibited practice has no path. No documentation, DPIA, human oversight or supplier certificate changes the answer. The only compliant move is to stop, or to change the system until the practice is gone. That makes it a go or no-go question before the pilot, because a pilot already counts as use.
The same technology can move between the two depending on where you point it. Emotion recognition on your staff is prohibited. The same engine measuring reactions of shoppers in a store is a high-risk system under Annex III and owes the people involved a disclosure under Article 50. And clearing Article 5 settles only the AI Act. Biometric data stays special category data under GDPR, which asks its own questions.
The check to run, and what a breach costs
The control that catches most of this is a written question to every HR, security and marketing supplier, asked before the pilot.
Does the product infer emotions or intentions from a face, a voice or typing behaviour, for anyone at all, and can that be turned off for a specific group of people?
Does it derive any characteristic from biometric data that could amount to race, political opinion, trade union membership, religion, sex life or sexual orientation?
Where do the reference images and voice prints come from, and was any part of that set scraped?
What is the legal basis under GDPR, and is there a data protection impact assessment we can read?
Keep the answers in writing, in the file next to the tool. A verbal reassurance from an account manager is no control. If the answer to the first two questions is yes, the project stops there.
Breaching Article 5 carries the heaviest fine tier in the regulation. Article 99(3) puts it at up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher. For SMEs and start-ups Article 99(6) flips the comparison to whichever is lower, so a company with 4 million euros of turnover faces a ceiling of 280,000 euros. The prohibitions have applied since 2 February 2025 and the penalty rules since 2 August 2025.
Belgium had not yet formally designated its market surveillance authority when this was written. BIPT is the candidate, FOD Economie is preparing the law, and FOD Economie itself calls the current situation a legal vacuum. That only settles who can fine you. Article 5 applies directly, and someone harmed by a banned practice can go to court over it today.