Summary: Eight categories of AI practice banned outright in the EU. Applicable since 2 February 2025 and carrying the Act’s highest penalty tier.
Sources: raw/AI-regulations/Regulation - EU - 2024_1689.md (Article 5, Article 99(3))
Last updated: 2026-07-28
The eight prohibitions
All quotes from Regulation - EU - 2024_1689.md, Article 5(1).
(a) Subliminal, manipulative or deceptive techniques — deploying “subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques” that materially distort behaviour “by appreciably impairing their ability to make an informed decision,” causing or likely to cause significant harm.
(b) Exploiting vulnerabilities — exploiting vulnerabilities “due to their age, disability or a specific social or economic situation” to materially distort behaviour in a way causing or likely to cause significant harm.
(c) Social scoring — evaluating or classifying people over time based on social behaviour or inferred personal characteristics, where the score leads to detrimental treatment either (i) in contexts unrelated to where the data was collected, or (ii) unjustified or disproportionate to the behaviour.
(d) Predictive policing on profiling alone — risk assessment predicting criminal offending “based solely on the profiling of a natural person or on assessing their personality traits.” Does not apply to systems supporting human assessment already grounded in “objective and verifiable facts directly linked to a criminal activity.”
(e) Untargeted facial-image scraping — creating or expanding facial recognition databases “through the untargeted scraping of facial images from the internet or CCTV footage.”
(f) Emotion inference at work and school — inferring emotions “in the areas of workplace and education institutions,” except for medical or safety reasons.
(g) Biometric categorisation by protected attribute — categorising individuals by biometric data “to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.” Does not cover labelling or filtering of lawfully acquired biometric datasets, or categorisation of biometric data in law enforcement.
(h) Real-time remote biometric identification in public for law enforcement — prohibited unless strictly necessary for: targeted search for abduction/trafficking/sexual-exploitation victims or missing persons; prevention of a specific, substantial and imminent threat to life or of terrorist attack; or localising/identifying a suspect for an Annex II offence punishable by at least four years’ custody.
The (h) safeguards
Point (h) carries the most procedural machinery in the Article — worth noting because it is a template for how the Act layers controls:
- Use limited to confirming the identity of a specifically targeted individual (Art 5(2)).
- Requires a fundamental rights impact assessment (Art 27) and registration in the EU database (Art 49) before use, with urgency allowing registration “without undue delay” after (Art 5(2)).
- Prior authorisation by a judicial or independent binding administrative authority; in urgency, use may start but authorisation must be requested within 24 hours, and if rejected “the use shall be stopped with immediate effect and all the data, as well as the results and outputs of that use shall be immediately discarded and deleted” (Art 5(3)).
- “No decision that produces an adverse legal effect on a person may be taken based solely on the output” (Art 5(3)).
- Notification to market surveillance and data protection authorities; annual Member State reports; annual Commission publication (Arts 5(4)–(7)).
- Member States may legislate more restrictively (Art 5(5)).
Penalty tier
Article 99(3): non-compliance with Article 5 is subject to fines “up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher” (source: Regulation - EU - 2024_1689.md).
This is the Act’s ceiling — higher than GDPR’s 4%. See enforcement-and-penalties.
Dates
Chapter II applies from 2 February 2025 (Art 113(a)) — the first substantive part of the Act to bite, eighteen months before the general application date. See ai-act-timeline.
Not a closed list
Art 5(8): “This Article shall not affect the prohibitions that apply where an AI practice infringes other Union law.” And the Commission must assess the need to amend both Annex III and the Article 5 list “once a year following the entry into force” (Art 112(1) as reproduced in the source at Article 113’s preceding block).
Related pages
- eu-ai-act
- high-risk-ai-systems — biometrics and emotion recognition appear in both Art 5 and Annex III at different thresholds
- article-50-transparency — emotion recognition and biometric categorisation that are not prohibited still carry disclosure duties
- enforcement-and-penalties