Article 5 of the EU AI Act: A Plain-English Guide to Every Prohibited AI Practice

If your AI system falls under Article 5, there is no conformity assessment to complete, no technical documentation to file, and no CE mark to obtain. The system is simply banned - from being placed on the EU market, put into service, or used. Full stop.
That makes Article 5 categorically different from every other tier of the EU AI Act. High-risk systems carry heavy obligations but remain lawful if you meet them. Prohibited practices carry no compliance pathway at all. Understanding where the red lines sit is therefore the first and most urgent task for any compliance lead, legal team, or product owner operating in or serving the EU.
Article 5's prohibitions became legally applicable on 2 February 2025, applying in principle to all AI systems regardless of whether they were placed on the market or put into service before or after that date. The prohibitions went into force on 2 February 2025 and apply in principle to all AI systems regardless of whether they were placed on the market or put into service before or after that date. Starting on 2 August 2025, the provision also became enforceable by designated authorities at Member State level.
Why "Prohibited" Is the Strictest Tier - and Why It Applies to Everyone
The EU AI Act takes a risk-based approach with four tiers: minimal risk, limited risk (transparency obligations), high risk (conformity obligations), and unacceptable risk. Article 5 prohibits the placing on the EU market, putting into service, or use of certain AI systems for manipulative, exploitative, and social scoring practices, which by their inherent nature violate fundamental rights and EU values.
Crucially, Article 5 applies to both providers and deployers. Article 5 applies to both providers and deployers of AI systems and prohibits both the placing on the market, the putting into service, and the use of the listed systems. That means a company that did not build the system but is running it in its operations can still be in breach. If you are a deployer using a third-party AI tool that falls within one of the eight categories, you are liable - not just the vendor.
The Commission emphasises that meeting high-risk obligations is not enough if the system is actually part of a banned practice. Prohibited means banned at market and use levels. If a practice is in Article 5, it cannot be placed on the EU market, put into service, or used.
The Eight Prohibited Practices, Explained
1. Subliminal, Manipulative, or Deceptive Techniques
AI systems that deploy subliminal, manipulative, or deceptive techniques to materially distort a person's behaviour in a way that causes or is likely to cause significant harm are banned. The key word is subliminal - techniques operating below the threshold of conscious awareness.
The Commission guidelines explicitly state that personalised advertising is "not inherently manipulative." Article 5(1)(a) targets AI that uses subliminal techniques - methods the user cannot perceive - to distort behaviour causing significant harm. Transparent personalisation based on stated preferences is fine; AI that invisibly manipulates decision-making below the awareness threshold is not.
Practical example: A recommender system that deliberately exploits cognitive biases to steer users toward harmful financial products without their awareness. Standard A/B testing or preference-based personalisation is not caught.
2. Exploiting Vulnerabilities
AI systems that exploit vulnerabilities arising from a person's age, disability, or socio-economic situation to materially distort their behaviour in a way that causes or is likely to cause significant harm are prohibited.
Practical example: A lending platform that uses AI to identify financially distressed individuals and target them with predatory loan offers designed to exploit their desperation. The prohibition is about exploitation of a known vulnerability - not merely targeting a demographic.
3. Social Scoring
The AI Act prohibits systems used for social scoring of individuals or groups based on their social behaviour or known or inferred characteristics whenever the score leads to detrimental treatment in an unrelated context or to detrimental treatment disproportionate to the social behaviour or its gravity.
In the workplace context, this could include situations where a worker is fired or demoted based on their behaviour and inferred personality traits - such as perceived introversion or aloofness - such that treatment is unjustified or disproportionate to the social behaviour itself or its gravity.
Practical example: An employer aggregating employee behaviour scores across multiple systems (punctuality, communication tone, social media activity) to generate a composite "trustworthiness" score used to determine promotions.
4. Criminal-Offence Risk Assessment Based Solely on Profiling
AI systems used to assess or predict the risk of a person committing a crime based solely on profiling or personality traits are prohibited. Examples include AI predicting future criminal behaviour using personality traits or psychological profiling, rather than objective, verifiable facts directly linked to criminal activity, or AI automatically classifying individuals as potential suspects without human oversight or objective verification.
The word "solely" matters here. A system that incorporates profiling alongside objective, verifiable evidence may not be caught - but any system that relies exclusively on personality traits, social patterns, or demographic proxies to flag individuals as criminal risks is banned outright.
Practical example: A predictive policing tool that scores individuals based on their social network connections, neighbourhood, and inferred personality type, with no grounding in specific criminal conduct.
5. Untargeted Facial Image Scraping
Article 5(1)(e) prohibits "the placing on the market, the putting into service for this specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage."
You cannot build a facial recognition system by harvesting photos from social media, public websites, or surveillance cameras without specific authorisation. Clearview AI is the poster child - now explicitly illegal in the EU.
There is a narrow carve-out: the prohibition does not extend to databases that "are not used for the recognition of persons." This means facial image databases used for AI model training or testing purposes are out of scope "where the persons are not identified."
6. Emotion Recognition in the Workplace and Education
Article 5(1)(f) prohibits "the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons."
This is the prohibition that catches the most companies off guard. If your call centre software analyses agent tone to assess mood - that is prohibited.
The exceptions are narrow. Physical states such as pain and fatigue are not considered emotions, so using an AI system "to infer a professional pilot's or driver's fatigue to alert them and suggest when to take breaks to avoid accidents" is not emotion recognition.
The guidelines provide that "using voice recognition systems by a call centre to track their customers' emotions, such as anger or impatience, is not prohibited by Article 5(1)(f)" - for example, to help employees cope with difficult customers. The distinction is whether the system is inferring the employee's emotions (prohibited) or the customer's emotions (not caught by this provision).
Webcam attention-monitoring tools used in remote work or e-learning are a high-risk area. A corporate training platform that uses webcam monitoring to classify employee attention levels from facial expressions during mandatory training sessions is a textbook example of prohibited emotion recognition in the workplace. Review any engagement-tracking or proctoring tools in your stack immediately.
7. Biometric Categorisation Inferring Sensitive Attributes
The Act prohibits AI systems that categorise individuals based on their biometric data to deduce or infer a series of attributes, including race, political opinions, and trade union membership, among others.
A retail analytics company that uses in-store cameras with AI to categorise shoppers by inferred ethnicity and religion to "optimise product placement" is prohibited - even if no personally identifiable data is stored, the act of biometric categorisation based on sensitive characteristics is prohibited.
The prohibition does not cover the labelling or filtering of lawfully acquired biometric datasets, including in the area of law enforcement.
8. Real-Time Remote Biometric Identification in Public Spaces (Law Enforcement)
Real-time remote biometric identification (RBI) systems enable the automatic identification of individuals as they move through public areas by comparing live biometric data, typically facial images, against databases. These systems can operate continuously, capturing data without consent, raising deep concerns about mass surveillance, privacy, and fundamental freedoms.
The prohibition applies specifically to law enforcement use in publicly accessible spaces. This prohibition does not apply to private actors in non-law-enforcement contexts, but it sets a clear precedent for the EU's approach to real-time biometric surveillance in public life.
Where exceptions apply, the conditions are strict. Article 5(1)(h) permits use only if strictly necessary for: (i) the targeted search of victims of specific crimes such as human trafficking; (ii) the prevention of a threat to life or physical safety of persons, or the threat of a terrorist attack; and (iii) the localisation or identification of a person suspected of having committed a criminal offence, where the offence is listed in Annex II and is punishable by at least four years' imprisonment.
Deployment requires a prior fundamental rights impact assessment under Article 27, judicial or independent administrative authorisation before use, and registration in the EU database.

Coming in December 2026: The Intimate Deepfake Ban
Article 5 is not static. A new prohibition takes effect on 2 December 2026, amending Article 5 to ban AI systems that generate or manipulate non-consensual sexually explicit or intimate content of an identifiable person.
Effective December 2, 2026, the amendment extends Article 5's prohibitions to "nudifier" applications - AI systems that generate or manipulate sexually explicit or intimate images, video, or audio without explicit consent. Providers and deployers may not use or place on the EU market AI systems designed to create intimate deepfakes or CSAM, or that lack reasonable safeguards against such use.
The revised rules explicitly prohibit AI systems on the EU market that are designed to create non-consensual sexually explicit or intimate content, as well as those that fail to implement reasonable safeguards against its production. The ban also covers AI-generated child sexual abuse material.
Crucially, the ban was not part of the European Commission's original proposal; it was introduced as an amendment by the European Parliament, principally at the instigation of the Renew Europe group, and survived into the final agreed text.
Companies will be required to bring systems into compliance with the new prohibition by 2 December 2026, giving providers roughly six months to make necessary changes.
If you build or deploy any generative AI system capable of producing realistic images, video, or audio of real people - including general-purpose models - you need to assess whether your safeguards are adequate before that deadline.
Penalties and Enforcement Status
Penalties for breaching Article 5 are the highest tier in the entire EU AI Act: up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Non-compliance triggers administrative fines of up to €35 million or up to 7% of the total worldwide annual turnover for the preceding financial year, whichever is higher. These are the highest penalties in the entire AI Act. For SMEs and startups, the lower of the fixed amount or percentage applies.
Italy has also introduced criminal penalties, including imprisonment for certain AI offences.
Who Enforces It?
The European AI Office and the national market surveillance authorities are responsible for implementing, supervising, and enforcing the AI Act. Each Member State must designate at least one market surveillance authority, which will be tasked with monitoring companies' compliance with the AI Act and, in the case of non-compliance, enforcing it.
The supervision and enforcement landscape is, however, highly fragmented and decentralised. As of March 2026, only eight out of 27 Member States had designated single contact points.
Where Things Stand
As of early 2026, no public enforcement actions for prohibited AI practices have been announced, though investigations are reportedly underway, particularly around workplace emotion recognition and predictive policing.
As of March 2026, no public enforcement actions for prohibited practices have been announced. However, several investigations are reportedly underway, particularly around workplace emotion recognition and predictive policing. The enforcement landscape is still developing as member states designate competent authorities.
The absence of announced enforcement actions should not be read as a green light. Courts can enforce the prohibitions, and individuals can claim violations, even before the official market surveillance mechanism is fully in place.
The Commission's Guidelines: Your Interpretive Starting Point
On 4 February 2025, the European Commission published a 135-page set of guidelines on prohibited AI practices to aid interpretation of Article 5.
The European Commission published a comprehensive 135-page document outlining AI practices considered unacceptable due to their risks to fundamental rights and values, with the goal of providing companies with insights into how the Commission interprets and defines prohibited AI practices.
Although non-binding, these guidelines provide legal explanations and practical examples to help stakeholders understand and comply with the AI Act, and help foster a consistent, effective, and uniform application across the EU.
The guidelines are the closest thing to an official decoder ring for Article 5. For each prohibition, they set out the cumulative conditions that must all be met for the ban to be triggered - meaning a careful reading can identify where a system falls outside the prohibition's scope.
Practical Checklist: Screening Your AI Portfolio Against Article 5
Use this checklist as a first-pass triage. Any "yes" answer warrants immediate legal review.
Beyond the checklist, here are the structural steps every compliance team should take:
1. Map your AI inventory against all eight categories. Don't rely on vendor descriptions - review what the system actually does, not what it's marketed as.
2. Pay special attention to deployer liability. If you are running a third-party AI tool, you are in the compliance chain. Contractual protections from vendors do not eliminate your regulatory exposure.
3. Read the Commission guidelines for any borderline case. The 135-page document sets out cumulative conditions for each prohibition. A system may fall outside the ban if one condition is not met - but that analysis needs to be documented.
4. Prepare for the December 2026 deepfake prohibition. Any generative AI system capable of producing realistic depictions of real people needs a safeguards review before that deadline.
5. Monitor enforcement developments. With investigations reportedly underway in workplace emotion recognition and predictive policing, the first enforcement decisions will set important precedents for how national authorities interpret the prohibitions in practice.
Free tools on AI Act Navigator:
- Risk-Tier Classifier — answer a short questionnaire and get a provisional tier assessment with a plain-English rationale you can share with stakeholders.
- Obligations Checker — once you know your system's tier, this page maps every relevant obligation to practical compliance steps for both providers and deployers.
Not sure whether your system is prohibited, high-risk, or neither? Start with the Risk-Tier Classifier — it covers Article 5 as the first gate.
Key Takeaways
- Article 5 is already live. The prohibitions have applied since 2 February 2025, to all AI systems regardless of when they were built or deployed.
- There is no compliance pathway. Unlike high-risk AI, prohibited practices cannot be made lawful by adding documentation, oversight, or technical safeguards.
- Both providers and deployers are caught. If you run a prohibited system, you are liable - even if you didn't build it.
- Penalties are the highest in the Act - up to €35 million or 7% of global annual turnover.
- A ninth prohibition arrives 2 December 2026, covering AI systems that generate non-consensual intimate or sexually explicit content of identifiable persons.
- Enforcement is coming. Investigations are reportedly underway. The absence of announced actions is not a safe harbour.
Does Article 5 apply to companies outside the EU?
Yes. The EU AI Act has extraterritorial reach. If an AI system is placed on the EU market, put into service in the EU, or its output is used in the EU, Article 5 applies — regardless of where the provider or deployer is based. US and other non-EU companies serving EU users or customers are in scope.
Can a prohibited AI system be made compliant by adding human oversight?
No. Unlike high-risk AI systems, prohibited practices under Article 5 cannot be rendered lawful by adding human review, technical safeguards, or documentation. The prohibition is absolute (subject only to the narrow exceptions explicitly written into the text, such as the law enforcement carve-outs for real-time biometric ID).
What is the difference between Article 5 and the high-risk AI provisions?
High-risk AI systems (Annex III) are lawful but carry heavy obligations: conformity assessments, technical documentation, human oversight, transparency requirements, and registration. Prohibited AI practices under Article 5 carry no compliance pathway — they cannot be placed on the market or used at all. Article 5 is the first gate to check before any other compliance analysis.
Does the emotion recognition ban apply to customer-facing AI?
The ban under Article 5(1)(f) applies to inferring the emotions of employees and students. A call centre tool that analyses customer emotions (not employee emotions) to help staff manage difficult interactions is not caught by this specific prohibition — though it may trigger other obligations under the Act or GDPR.
When does the intimate deepfake prohibition take effect?
The new prohibition on AI systems that generate or manipulate non-consensual sexually explicit or intimate content of identifiable persons takes effect on 2 December 2026, as part of the AI Omnibus amendments agreed in May 2026. Providers and deployers should begin safeguards reviews now.
Related reading

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.

Article 22 EU AI Act: The Plain-English Guide to Authorised Representatives for Non-EU Providers
If you build high-risk AI outside the EU and want to sell into the EU market, Article 22 requires you to appoint an EU authorised representative by written mandate - before you go live. Here's exactly what that means.