Published on This Week in AI

EU AI Act Prohibited Practices: What Businesses Must Stop Doing by August 2026

The EU AI Act classifies AI systems into four risk categories. At the top sits a set of practices so fundamentally incompatible with fundamental rights that the Act prohibits them outright — not regulates, but bans. These prohibited practices under Article 5 of the Act have been enforceable since February 2025. With the Act's high-risk system requirements applying from August 2026, and enforcement frameworks continuing to develop, understanding exactly what Article 5 prohibits — and how to assess whether a system falls within its scope — is now a practical compliance priority.

For businesses, the key distinction is between AI systems that are tightly regulated under the Act's high-risk provisions and those that are simply not permitted at all. No degree of compliance measures, human oversight, or risk assessment will make a prohibited system lawful. The prohibition is absolute.

The Six Prohibited Practices

1. Subliminal manipulation

Article 5 prohibits AI systems that use techniques operating below the threshold of a person's conscious awareness in order to materially distort that person's behavior in a way that causes or is likely to cause significant harm. The prohibition extends to techniques that exploit psychological weaknesses or biases — including systems designed to target children, elderly persons, or others whose susceptibility is known — where significant harm results. The focus is on manipulation of the decision-making process in ways the person cannot recognize or resist, not on persuasion more generally.

2. Exploiting vulnerabilities

AI systems that exploit specific vulnerabilities of groups of persons arising from their age, disability, or social or economic situation are prohibited where doing so is likely to cause significant harm to those persons. This targets systems intentionally designed to identify and exploit disadvantage rather than to address it.

3. Social scoring by public authorities

AI used by or on behalf of public authorities to evaluate or classify individuals based on social behavior or inferred personal characteristics — where this produces detrimental or unfavorable treatment in contexts unrelated to those in which the data was originally generated, or treatment that is unjustified or disproportionate — is prohibited. This addresses systematic government-operated scoring of citizens in ways that affect their access to services, opportunities, or treatment across multiple life domains.

4. Real-time remote biometric identification in public spaces

The use of AI-based real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes is prohibited, subject to a narrow set of exceptions. Those exceptions cover imminent terrorist threats, targeted searches for specific missing persons or victims of serious crimes, and searches for perpetrators of serious criminal offences listed in the Act. Even where an exception applies, prior judicial or independent administrative authorization is required in most cases, and each use must be recorded and subject to retrospective review. Post-remote biometric identification — using footage after an event rather than in real time — is not prohibited but is classified as high-risk.

5. Emotion recognition in workplaces and educational institutions

AI systems used to infer the emotions of natural persons in workplace or educational settings are prohibited, except where the AI is used for medical or safety reasons. This prohibition reflects the particular power imbalance in these settings and the concerns about covert psychological monitoring of employees and students. The prohibition covers systems designed to infer emotional states from facial expressions, voice patterns, physiological signals, or behavioral indicators.

6. Untargeted facial image scraping

The creation or expansion of facial recognition databases through the untargeted scraping of facial images from the internet or from CCTV footage is prohibited. The emphasis on "untargeted" distinguishes this from lawful targeted law enforcement collection and addresses the specific practice of mass harvesting of biometric data without consent or knowledge of the individuals whose data is collected.

Enforcement, Timelines, and Penalties

Article 5 prohibitions became enforceable on 29 February 2025 — the first substantive provisions of the Act to apply. Enforcement is primarily the responsibility of national market surveillance authorities in each EU member state, with the European AI Office taking responsibility for supervising general-purpose AI models and coordinating cross-border enforcement. Penalties for violations of the prohibited practices provisions are the highest in the Act's tiered penalty structure: fines of up to €35 million or 7% of worldwide annual turnover in the preceding financial year, whichever is higher.

Assessing Whether Your System Falls Within Scope

Businesses should conduct a structured self-assessment of any AI system that operates in, or interacts with users in, the EU. The key questions for Article 5 compliance are: Does the system use techniques designed to operate below conscious awareness? Does it identify and target psychological or social vulnerabilities? Does it classify individuals across social domains for public authority use? Does it perform real-time biometric identification in public spaces? Does it monitor emotional states in employment or educational contexts? Does it aggregate biometric data without targeting specific known individuals?

A negative answer across all these questions does not guarantee the system is not regulated — it may still be high-risk. But a positive answer to any of them requires immediate legal review and almost certainly cessation of that functionality. The broad framing of the prohibitions is intentional: the Act's drafters sought to prevent circumvention through narrow technical readings. For a broader overview of how the Act categorizes AI systems and what obligations apply to high-risk AI, see our guide to what the EU AI Act requires from businesses.

General Purpose AI and the Prohibitions

General-purpose AI (GPAI) model providers — those developing large language models and other foundation models — are subject to specific obligations under the Act's GPAI provisions. Being a GPAI provider does not exempt a company from the Article 5 prohibitions. Where a GPAI model is integrated into an application that operates as a prohibited system, the deployer bears primary responsibility. However, GPAI providers who know or should reasonably know of intended prohibited uses have obligations to address this through their terms of service, usage policies, and contractual arrangements with downstream users. This interaction between GPAI obligations and the Article 5 prohibitions is an area where regulatory guidance from the European AI Office is expected to develop. See also our analysis of liability when autonomous AI systems cause harm.

Frequently Asked Questions

When did the EU AI Act prohibited practices take effect?

The prohibited practices under Article 5 became enforceable on 29 February 2025 — six months after the Act entered into force in August 2024. This was the first substantive compliance deadline in the Act's phased implementation timeline.

What is "subliminal manipulation" under Article 5?

It refers to AI techniques that influence a person's behavior through means that operate below the threshold of conscious perception — so the person cannot recognize that their decision-making is being shaped — in ways likely to cause significant harm. It is distinct from persuasive communication, advertising, or personalization that operates at a conscious level, even when those communications are sophisticated or one-sided.

Are there exceptions to the prohibition on real-time biometric identification in public spaces?

Yes, but they are narrow and apply only to law enforcement. Exceptions cover searches for specific missing persons or victims of human trafficking or sexual exploitation, prevention of imminent terrorist threats, and searches for perpetrators of specific serious offences listed in the Act. Each exception requires prior judicial or administrative authorization in most cases and is subject to strict logging and oversight requirements.

What are the penalties for violating the EU AI Act's prohibited practices?

Violations of Article 5 carry the highest penalty tier in the Act: fines of up to €35 million or 7% of the company's total worldwide annual turnover in the preceding financial year, whichever is higher. The penalties apply to both providers and deployers of prohibited AI systems.