GovCompass
ReferenceFairness

Art. 5 EU AI Act: all 8 prohibited AI practices explained

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 5 lists the eight prohibited AI practices, including subliminal manipulation, exploitation of vulnerable groups, social scoring, and untargeted facial-recognition scraping. These prohibitions are absolute, apply to every organization regardless of size, and have been in force since 2 February 2025.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Updated: June 2026

Introduction: absolute prohibitions under the EU AI Act

Article 5 of the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → establishes the only category of AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → that is banned outright, not subject to riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → classification, not eligible for regulatory sandboxes, and not open to proportionalityproportionalityMatching the weight of governance to the risk of the use case (heavy gates for high stakes, a light touch for low stakes), which keeps controls credible and followed.Open full entry → considerations. These are systems whose potential for harmharmHarm is the concrete damage an AI system causes or can cause: to a person, a group, an organization, or society. A risk is that same damage seen in advance, weighed by likelihood and severity; a harm that has occurred is remedied rather than managed.Open full entry → is so severe that the European legislator made an absolute political choice: these practices shall not exist in the EU market.

The eight prohibitions took effect on 2 February 2025, the earliest of all obligations under the EU AI Act. The stakes are correspondingly high: fines of up to €35 million or 7% of global annual turnover, whichever is higher.

This article provides a complete analysis of all eight prohibitions, including borderline cases, practical deployerdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry → implications, and the enforcement risks that Dutch supervisory authorities will prioritize.

The regulatory framework: why these eight?

The eight prohibitions are not random. They share a common characteristic: each involves a fundamental violation of human dignity, autonomy, or fundamental rights, violations that cannot be adequately mitigated by technical measures or human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry →. A risk classification system cannot make social scoringsocial scoringEvaluating people over time across contexts, with detrimental or disproportionate treatment as a result, a prohibited AI practice in the EU.Open full entry → acceptable; a transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → notice cannot make subliminal manipulation harmless.

The structure of Art. 5 is deliberately broad. Each prohibition uses open-ended language ("AI systems that deploy subliminal techniques") rather than narrow technical definitions. This is intentional: the legislator wanted to capture future techniques that were not yet known at the time of drafting.

The eight prohibitions in detail

1. subliminal manipulation (Art. 5.1.a)

What is prohibited: AI systems that deploy subliminal techniques operating below the threshold of human consciousness to materially distort a person's behavior in a way that causes or is likely to cause that person or another person significant harm.

Key elements: The prohibition has three cumulative requirements: (1) subliminal technique, below conscious perception; (2) material distortion of behavior; (3) significant harm. All three must be present.

Borderline: Personalized advertising that exploits known cognitive biases (e.g. scarcity framing, loss aversion) is not automatically prohibited. The technique must operate below the threshold of consciousness, if a user can consciously perceive and resist the influence, it does not meet the subliminal threshold. However, the boundary is contested and enforcement authorities are expected to interpret it broadly.

Deployer risk: Marketing tools using advanced psychological profilingprofilingAutomated processing of personal data to evaluate or predict aspects of a person, such as performance, behavior or location, as defined in the GDPR.Open full entry → at scale deserve careful review. Document your legal analysis explicitly.

2. exploitation of vulnerabilities (Art. 5.1.b)

What is prohibited: AI systems that exploit any of the vulnerabilities of a person or a specific group of persons due to their age, disability, or specific social or economic situation to materially distort behavior in a way that causes or is likely to cause significant harm.

Key distinction from 5.1.a: Here the technique need not be subliminal, the exploitation of vulnerability is itself the wrong. Targeting elderly people with financial products using AI-driven persuasion that exploits cognitive decline is prohibited even if the user is consciously aware of the influence attempt.

Practical examples: AI-driven debt collection targeting people known to be in financial distress with emotionally manipulative messaging. Recommendation algorithmsalgorithmThe learning procedure (e.g. gradient descent, tree induction); running it on training data produces a model. Controls attach to models and systems, not algorithms in the abstract.Open full entry → targeting children with harmful content that exploits developmental vulnerabilities. Gambling platforms using AI to identify and exploit problem gamblers.

3. social scoring (Art. 5.1.c)

What is prohibited: AI systems used for the evaluation or classification of natural personsnatural personA living human individual, as distinct from a legal person such as a company; the holder of data-protection and AI-Act rights.Open full entry → over a period of time based on their social behavior or personal characteristics, where the resulting social score leads to detrimental or unfavorable treatment in social contexts unrelated to those in which the data was generated, or to treatment that is unjustified or disproportionate to the social behavior. This applies to public and private actors alike.

Scope: Social scoring under Art. 5(1)(c) applies to both public and private actors. The limitation to public authorities existed in the 2021 proposal but was removed from the final text. What the prohibition targets is detrimental or unfavorable treatment of people based on social behavior or personal characteristics, where that treatment occurs in a social context unrelated to the context in which the data was generated, or is unjustified or disproportionate to the behavior. Scoring on relevant, proportionate data within the same context (for example a credit score based on financial history) remains legitimate. A private organization is therefore fully within scope, and treating unrelated-context scoring as merely an Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry → high-risk matter understates the exposure: a prohibited practice carries the €35M / 7% penalty tier.

Dutch context: The SyRI system used by Dutch municipalities for benefit fraud detection was ruled unlawful by Dutch courts in 2020, before the EU AI Act. Under Art. 5.1.c, similar systems would now be prohibited at EU level.

4. risk assessment for criminal prediction (Art. 5.1.d)

What is prohibited: AI systems used by law enforcement for risk assessments of natural persons to predict the probability of committing a criminal offense, based solely on profiling or personality traits, not based on objective, verifiable facts directly linked to criminal activity.

Nuance: This does not prohibit all predictive policing. AI tools that assess risk based on documented behavioral evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry → are not automatically prohibited. The prohibition targets pure profile-based prediction, the "pre-crime" model, without factual grounding.

5. untargeted scraping for facial recognition databases (Art. 5.1.e)

What is prohibited: AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage.

Why this matters for deployers: Deployers who use third-party identity verification or facial recognition tools should verify that the vendor's training datasets were not built through untargeted scraping. Using such a system, even without direct knowledge, may expose a deployer to liability.

6. emotion recognition in workplace and education (Art. 5.1.f)

What is prohibited: AI systems that infer emotions of natural persons in the workplace and educational institutions. Limited exceptions exist for medical and safety purposes.

Practical scope: This prohibition is broader than it may appear. Employee monitoring tools that claim to measure "engagement" or "attention" through facial analysis are covered. Proctoring software used in online education that analyses facial expressions is covered. The prohibition applies regardless of whether the emotional inferenceinferenceThe stage where a trained model produces outputs on new inputs, as opposed to the training stage where it learns its parameters.Open full entry → is a primary or secondary function of the system.

7. biometric categorization based on sensitive characteristics (Art. 5.1.g)

What is prohibited: AI systems that categorize natural persons individually using biometric data to deduce or infer race, political opinion, trade union membership, religious or philosophical beliefs, or sexual orientation.

Note: This does not prohibit biometric identity verification. The prohibition targets the inference of sensitive characteristics from biometric data, not biometric identification itself.

8. real-time remote biometric identification in public spaces (Art. 5.1.h)

What is prohibited: Real-time remote biometric identificationreal-time remote biometric identificationIdentifying people from biometric data live in publicly accessible spaces; its use by law enforcement is sharply restricted under the AI Act.Open full entry → systems in publicly accessible spaces for law enforcement purposes.

Exceptions: Art. 5.2 provides three narrow exceptions: searching for missing persons including child victims of trafficking; prevention of specific, imminent terrorist threats; identification of criminal suspects in serious crimes (as listed). All exceptions require prior judicial authorization (or urgent post-hoc authorization) and are subject to strict conditions.

Private sector scope: The prohibition explicitly covers "law enforcement purposes." Private organizations using facial recognition in retail or offices are not prohibited by Art. 5.1.h, though they face other legal requirements under the GDPRGDPRRegulation (EU) 2016/679, the General Data Protection Regulation, the EU's law on the processing of personal data. It applies to AI wherever personal data enters training, inputs, outputs, or logs, and it operates alongside the EU AI Act rather than being replaced by it. See controller, processor, lawful basis, DPIA.Open full entry → and potentially Annex III.

Enforcement and sanctions

Violations of Art. 5 carry the highest sanctions in the EU AI Act: up to €35 million or 7% of global annual turnover, whichever is higher. For a multinational with €10 billion in revenue, this amounts to €700 million per violation.

National market surveillance authorities have investigative and enforcement powers including access to AI systems, inspection of documentation, and the power to order market withdrawal. In the Netherlands no such authority has been formally designated yet; the draft Uitvoeringswet AI-verordening (UAIV) proposes the AP as market surveillance authoritymarket surveillance authorityThe national body that enforces the AI Act in a member state, with powers to investigate, order corrective action and apply penalties.Open full entry → for prohibited practicesprohibited practicesAI uses banned outright under the AI Act, such as social scoring, manipulative techniques and untargeted scraping of facial images.Open full entry → (Art. 5), transparency (Art. 50) and much of Annex III, with RDI as central contact point and the AFM and DNB for financial institutions.

Under the draft UAIV the AP is proposed as the authority for Art. 5, and prohibited-practice enforcement is expected to be an early priority once designation is in force. Organizations using AI in HR selection, automated decision-makingautomated decision-makingDecisions based solely on automated processing with legal or similarly significant effects. GDPR Article 22 restricts them to three exception grounds, with human-intervention safeguards.Open full entry →, and biometric applications are the most exposed.

Deployer compliance checklist

  1. Have you inventoried all AI systems used in your organization against the eight prohibitions?
  2. Do any marketing or personalization systems use techniques that could constitute subliminal manipulation or exploitation of vulnerability?
  3. If you are a public authority: does any AI system contribute to behavioral evaluation across social areas?
  4. Do any workplace monitoring or proctoring tools include emotion recognitionemotion recognitionAn AI system that infers a person's emotions from biometric data; its use in workplaces and education is restricted under the AI Act.Open full entry → functionality?
  5. Have you verified that facial recognition or identity verification vendor datasets comply with Art. 5.1.e?
  6. Is your legal analysis of any borderline systems documented in writing?
  7. Do you have an escalation procedure for AI systems that approach prohibited use cases?

FAQ

Q: Does Art. 5 apply to AI systems deployed before 2 February 2025?
A: Yes. The EU AI Act does not grandfather existing systems for prohibited use cases. Systems in active use after 2 February 2025 that meet the criteria of Art. 5 must be decommissioned or modified.

Q: Can we use emotion recognition software for customer satisfaction measurement?
A: Not in the workplace or educational context. In other contexts (e.g. consumer research with explicit consent), a legal analysis is required. The prohibition in Art. 5.1.f is specifically scoped to "the workplace and educational institutions."

Q: We use an AI-based employee engagement platform that measures sentiment. Is this prohibited?
A: Depends on the method. If the platform infers emotional states from facial analysis, voice tone, or other biometric signals, even without explicitly labeling it "emotion recognition", it likely falls within Art. 5.1.f. Sentiment analysis based on text input (e.g. survey responses) is not biometric and is not prohibited by Art. 5.1.f, though other obligations may apply.

Legal referencesArt. 5
Share Share on LinkedIn

More on Fairness

AI in recruitment: risks, bias and what the EU AI Act already requires

Analysis

AI recruitment systems fall under Annex III of the EU AI Act as high-risk, which triggers the full deployer obligations of Article 26, human oversight, data quality, monitoring, log retention, and a Fundamental Rights Impact Assessment under Article 27. These duties cannot be transferred to the software vendor.

FRIA step by step: how to conduct a Fundamental Rights Impact Assessment

Guide

A Fundamental Rights Impact Assessment (FRIA) under Art. 27 is conducted step by step: describe the system and its purpose, identify affected persons, assess the impact on each fundamental rights dimension, define mitigation measures, and document the residual risk before deployment.

Art. 10 EU AI Act: data and data governance for high-risk AI

Reference

Art. 10 requires that the training, validation, and testing data for high-risk AI systems meets quality criteria: relevant, sufficiently representative, and as free of errors and complete as possible for the intended purpose. It also requires documented data governance practices covering collection, preparation, bias examination, and gap mitigation, and it permits the limited processing of special-category data where strictly necessary to detect and correct bias, under safeguards.

Art. 27 EU AI Act: Fundamental Rights Impact Assessment (FRIA)

Reference

Art. 27 requires certain deployers, public bodies and private deployers in defined sectors such as credit and insurance, to conduct a Fundamental Rights Impact Assessment (FRIA) before deploying a high-risk AI system, examining the impact on fundamental rights and the mitigation measures.