What Article 5 bans
Article 5 prohibits ten AI practices outright. No conformity assessment, documentation or disclosure makes them lawful: if a practice is within Article 5, the only compliant response is to stop.
This is what separates Article 5 from the rest of the Regulation. Everywhere else, the Act tells you how to do something responsibly: assess the risk, document the system, disclose to the user, register in the database. Article 5 tells you not to do it at all. That difference changes what a compliance response looks like. There is no evidence pack that helps here, and no remediation plan that ends anywhere other than switching the system off.
| Tier | What sits there | Consequence |
|---|---|---|
| Prohibited | Ten practices banned outright: eight since February 2025, two more from December 2026 | €35m or 7% of turnover |
| High risk | Annex I product safety and eight Annex III use-case areas | Full Chapter III regime and conformity assessment |
| Transparency risk | Article 50: interaction notice, synthetic marking, deep fakes | Disclosure and marking duties |
| Minimal risk | Everything else: the large majority of AI systems | AI literacy duty only |
What the 2026 Omnibus added
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and inserted two new prohibitions at Article 5(1)(ba) and (bb). Both apply from 2 December 2026.
This is the first expansion of Article 5 since the Act was adopted, and it is the part of the Omnibus that got least attention, because the same instrument deferred the high-risk deadlines and that dominated the coverage. The two additions run in the opposite direction to the deferrals: they widen the prohibited tier rather than delay it.
| Provision | What it prohibits | Applies from |
|---|---|---|
| Article 5(1)(ba) | Generating or manipulating realistic depictions of the intimate parts or sexually explicit conduct of an identifiable person without their explicit consent | 2 December 2026 |
| Article 5(1)(bb) | Generating or manipulating child sexual abuse material within the meaning of Directive 2011/93/EU | 2 December 2026 |
Two features make these unlike the original eight. First, there is no grandfathering: a system already on the market on 2 December 2026 is in scope from that date. Second, the new Article 5(1a) and (1b) attach liability to reasonably foreseeable misuse, not only to intended purpose. A provider can be caught by an outcome it did not design for.
The child sexual abuse material prohibition is drafted to catch synthetic output. The material need not depict a real child, which closes the gap that had allowed purely generated content to be argued outside existing criminal provisions. The carve-out is narrow: purposes justified under national law, such as criminal proceedings, and red-teaming carried out under those conditions.
Why the thresholds matter
Most Article 5 paragraphs are narrower than their shorthand names suggest. Several require both a material distortion of behaviour and significant harm before the ban applies, and reading only the headline produces false positives in both directions.
Take Article 5(1)(a). Described as banning “manipulative AI”, it sounds like it captures most of the modern consumer internet. Read properly, it requires a subliminal, purposefully manipulative or deceptive technique, which materially distorts behavior by appreciably impairing the ability to make an informed decision, which causes or is reasonably likely to cause significant harm. Three conditions, all needed. An engagement-optimized feed is not automatically caught.
The inverse error is more dangerous. Article 5(1)(e), on untargeted facial image scraping, has no harm threshold and no balancing test at all. Teams accustomed to the GDPR’s proportionality reasoning look for a legitimate interests argument that does not exist in the provision.
| Prohibition | Requires significant harm? | Trigger |
|---|---|---|
| 5(1)(a) Subliminal manipulation | Yes | Technique + material distortion + significant harm |
| 5(1)(b) Exploiting vulnerability | Yes | Named vulnerability + material distortion + significant harm |
| 5(1)(ba) Non-consensual intimate imagery | No | Realistic depiction + identifiable person + no explicit consent |
| 5(1)(bb) Child sexual abuse material | No | Generation or manipulation of the material, real or synthetic |
| 5(1)(c) Social scoring | No: proportionality test instead | Detrimental treatment that is unrelated, or unjustified and disproportionate |
| 5(1)(d) Predictive policing | No | Prediction based solely on profiling or personality traits |
| 5(1)(e) Face scraping | No | Untargeted scraping that builds or expands a facial recognition database |
| 5(1)(f) Emotion at work | No | Setting: workplace or education, absent medical or safety purpose |
| 5(1)(g) Sensitive-trait inference | No | Biometric categorisation inferring a listed sensitive characteristic |
| 5(1)(h) Live biometric ID | No | Real-time + remote + public space + law enforcement purpose |
Each prohibition in detail
Each prohibition below sets out the threshold that has to be crossed, the carve-outs written into the paragraph, and the adjacent practice that is regulated rather than banned.
Subliminal, manipulative or deceptive techniques
AI systems that deploy subliminal, purposefully manipulative or deceptive techniques to materially distort a person's behavior are prohibited, but only where that distortion causes or is reasonably likely to cause significant harm.
The threshold that has to be crossed
Two conditions, both required: the technique must materially distort behavior by appreciably impairing the ability to make an informed decision, and that distortion must cause or be reasonably likely to cause significant harm to that person, another person or a group.
Carve-outs in the paragraph
- Lawful persuasion that does not impair informed decision-making
- Ordinary advertising and personalisation that falls short of material distortion
- Approved therapeutic uses carried out with informed consent
Who is most exposed
Consumer apps with engagement-optimized AI, gambling and trading interfaces, and anything using AI to shape decisions in high-stakes contexts.
Commonly confused with
Persuasive design, dark patterns and recommender optimization
Generally outside Article 5 unless the significant-harm threshold is crossed, but squarely within consumer protection law, the Digital Services Act and the GDPR
Exploiting vulnerabilities of age, disability or circumstance
AI systems that exploit vulnerabilities arising from a person's age, disability, or specific social or economic situation in order to materially distort their behavior are prohibited where that causes or is reasonably likely to cause significant harm.
The threshold that has to be crossed
The system must exploit a vulnerability of one of the named kinds, materially distort behavior, and cause or be reasonably likely to cause significant harm. Note that economic hardship is expressly a listed vulnerability.
Carve-outs in the paragraph
- Accessibility and assistive technology designed to help the same groups
- Targeting that does not exploit the vulnerability to distort behaviour harmfully
Who is most exposed
Products aimed at children or older adults, subprime lending and debt products, and any AI targeting layer keyed to financial distress.
Commonly confused with
Age-based or income-based audience targeting in advertising
Not prohibited by itself. The ban requires exploitation of the vulnerability plus behavioral distortion plus significant harm.
Generating non-consensual intimate imagery
AI systems that generate or manipulate realistic depictions of the intimate parts, or sexually explicit conduct, of an identifiable person without that person's explicit consent are prohibited from 2 December 2026.
The threshold that has to be crossed
The depiction must be realistic and the person identifiable, and consent must be absent. Consent has to be freely given, specific, informed, unambiguous and explicit: the GDPR standard, not a buried terms-of-service acceptance.
Carve-outs in the paragraph
- Depictions of people who are not identifiable
- Use with the subject's freely given, specific, informed, unambiguous and explicit consent
- Systems with reasonable and adequate technical safeguards against the outcome: the new Article 5(1a) and (1b) safeguards defence
Who is most exposed
Providers of image, video and avatar generators, so-called nudifier apps, face-swap tools, and any platform hosting or fine-tuning generative image models.
Commonly confused with
General-purpose image and video generators
Not prohibited as such, but providers are liable where this misuse is a reasonably foreseeable outcome, even if unintended. The defence is demonstrable technical safeguards, so a general-purpose generator without guardrails is exposed.
Generating child sexual abuse material
AI systems that generate or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU are prohibited from 2 December 2026, with only a narrow carve-out for legitimate purposes authorised under national law.
The threshold that has to be crossed
No harm threshold and no balancing test. The material need not depict a real child: synthetic generation is caught, which closes the gap that had let purely synthetic output be argued outside existing criminal provisions.
Carve-outs in the paragraph
- Purposes justified under national law, such as criminal proceedings
- Red-teaming and safety evaluation carried out under those legitimate-purpose conditions
Who is most exposed
Providers of any generative image or video model, and anyone fine-tuning or distributing open-weight image models without safeguards.
Commonly confused with
Safety classifiers trained to detect this material
Outside the ban: the prohibition targets generation and manipulation, not detection. Red-teaming a model to prove its safeguards hold falls within the legitimate-purpose carve-out.
Social scoring leading to unrelated detrimental treatment
AI systems that evaluate or classify people based on their social behavior or personal characteristics are prohibited where the resulting social score leads to detrimental or unfavorable treatment that is either unrelated to the context in which the data was generated, or unjustified and disproportionate to the behavior.
The threshold that has to be crossed
The detrimental treatment must be either unrelated to the original context of the data, or unjustified or disproportionate to the social behavior. A score used for a purpose properly connected to the data, proportionately, is not caught.
Carve-outs in the paragraph
- Lawful evaluation practices where the assessment is contextually related and proportionate
- Sector-specific scoring that Annex III instead classifies as high-risk
Who is most exposed
Any organization reusing behavioral data from one relationship to make adverse decisions in an unrelated one: platform trust scores applied off-platform, tenant screening drawing on social media.
Commonly confused with
Credit scoring and insurance risk pricing
High-risk under Annex III, not prohibited. Creditworthiness assessment and life and health insurance pricing are permitted subject to the full Chapter III regime. The ban targets scores that travel across unrelated contexts.
Predicting individual criminality from profiling alone
AI systems that assess or predict the risk of a person committing a criminal offence based solely on profiling or on assessing their personality traits and characteristics are prohibited.
The threshold that has to be crossed
The word doing the work is “solely”. The ban does not extend to AI that supports a human assessment already grounded in objective and verifiable facts directly linked to a criminal activity.
Carve-outs in the paragraph
- AI supporting a human assessment based on objective, verifiable facts directly linked to criminal activity
- Place-based and offence-based analysis that does not predict individual criminality
Who is most exposed
Law enforcement and criminal justice bodies, and vendors selling individual risk-scoring tools into them.
Commonly confused with
Fraud detection and anti-money-laundering systems
Not caught, because these work from transactional facts rather than personality profiling. Law-enforcement risk assessment tools are separately listed as high-risk in Annex III.
Untargeted scraping of facial images
Creating or expanding facial recognition databases through the untargeted scraping of facial images from the internet or from CCTV footage is prohibited outright.
The threshold that has to be crossed
No harm threshold and no balancing test. This is among the flattest prohibitions in the Article: if the scraping is untargeted and it builds or expands a facial recognition database, it is banned.
Carve-outs in the paragraph
- None stated in the paragraph itself
Who is most exposed
Facial recognition vendors, and any team that has built an internal face-matching capability from web-scraped images.
Commonly confused with
Training a model on a licensed or consented face dataset
Outside this ban, though still subject to the GDPR and, where the system is a biometric identification system, to the Annex III high-risk regime.
Emotion inference in workplaces and education
AI systems that infer the emotions of a person in the workplace or in an education institution are prohibited, except where the system is intended to be put in place for medical or safety reasons.
The threshold that has to be crossed
Setting rather than harm is the trigger. The same emotion recognition system may be lawful in a retail context and prohibited in an office or a classroom.
Carve-outs in the paragraph
- Systems intended for medical reasons
- Systems intended for safety reasons: for example fatigue detection where alertness is a safety-critical factor
Who is most exposed
HR and people-analytics teams, interview and proctoring platforms, contact centers running sentiment analysis on employee calls, and edtech engagement monitoring.
Commonly confused with
Emotion recognition in other settings
Permitted, but it triggers the Article 50(3) duty to notify the people exposed to it, and it is high-risk where Annex III applies.
Biometric categorisation to infer sensitive characteristics
Biometric categorisation systems that categorise people in order to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation are prohibited.
The threshold that has to be crossed
The prohibited element is inference of one of the listed sensitive characteristics from biometric data. Biometric categorisation on other attributes is not caught by this paragraph.
Carve-outs in the paragraph
- Labelling and filtering of lawfully acquired biometric datasets, including in the field of law enforcement
- Categorisation of biometric data by law enforcement within the limits the Regulation sets
Who is most exposed
Retail analytics, audience measurement, and security vendors offering attribute inference from faces or voices.
Commonly confused with
Demographic estimation for analytics
Outside this specific ban where it does not infer a listed sensitive characteristic, but still a biometric categorisation system for Annex III and Article 50(3) purposes.
Real-time remote biometric identification in public
Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes is prohibited, subject to three narrowly drawn exceptions that themselves require prior authorisation and a fundamental rights impact assessment.
The threshold that has to be crossed
All of real-time, remote, publicly accessible space, and law enforcement purpose must be present. Post-event identification and non-law-enforcement uses fall outside this paragraph, though they may be high-risk under Annex III.
Carve-outs in the paragraph
- Targeted search for specific victims of abduction, trafficking or sexual exploitation, or for missing persons
- Prevention of a specific, substantial and imminent threat to life or physical safety, or a genuine and present or foreseeable threat of a terrorist attack
- Localisation or identification of a person suspected of an offence listed in Annex II and punishable by a custodial sentence of at least four years
Who is most exposed
Law enforcement authorities and their suppliers. Private operators of public spaces should note that acting at the request of law enforcement can bring them within scope.
Commonly confused with
Biometric access control at your own premises
Not a law enforcement use in a publicly accessible space, so outside this ban, but it is a biometric system with GDPR and, potentially, Annex III high-risk consequences.
Five things that are not banned
The most expensive Article 5 mistakes run in both directions: stopping a lawful product on a misreading, or continuing a prohibited one because it resembles something lawful.
| Practice | Not prohibited because | What actually applies |
|---|---|---|
| Credit scoring | It assesses creditworthiness on financially relevant data, not social behavior repurposed across contexts | High-risk under Annex III: full Chapter III regime from 2 December 2027 |
| Fraud and AML detection | It works from transactional facts, not personality profiling, so Article 5(1)(d) is not engaged | Often high-risk; always subject to the GDPR |
| Emotion recognition in retail | The Article 5(1)(f) ban is limited to workplaces and education institutions | Article 50(3) notification duty, and Annex III where applicable |
| CV screening and candidate ranking | Employment AI is listed as high-risk, not prohibited, unless it infers emotion or sensitive traits | High-risk under Annex III point 4 |
| Post-event biometric identification | Article 5(1)(h) is confined to real-time identification | High-risk under Annex III, with its own safeguards |
Why this tier is different
Article 5 breaches carry up to €35 million or 7% of total worldwide annual turnover, whichever is higher: more than double the ceiling for high-risk and transparency failures.
Two features compound that exposure. The turnover limb is calculated on groupworldwide turnover, so a small EU entity carries its parent’s size. And because the prohibitions have applied since February 2025, exposure is not prospective: it accrues for as long as the practice runs. An organization discovering a prohibited practice today is not late for a deadline, it is already in breach.
| Breach | Ceiling | Applies since |
|---|---|---|
| Prohibited practices (Article 5) | €35m or 7% of turnover | 2 February 2025, and 2 December 2026 for the two new bans |
| Most operator obligations, including high-risk and Article 50 | €15m or 3% of turnover | 2 August 2026 onward, by obligation |
| Incorrect or misleading information to authorities | €7.5m or 1% of turnover | 2 August 2025 |
How to audit for exposure
Screen by capability rather than by product name. Prohibited practices rarely appear in a system’s description, they appear as a feature inside something bought for another purpose.
An organisation that asks “do we run any social scoring systems?” will get no useful answers, because nobody builds a product and calls it that. The productive question is narrower and behavioral: what does this system infer, about whom, and what happens to the person as a result.
| Ask | Flags | Follow-up |
|---|---|---|
| Does anything infer emotional or psychological state? | 5(1)(f), 5(1)(a) | Where is it used? Workplace and education are the trigger settings. |
| Does anything infer characteristics from a face, voice or body? | 5(1)(g) | Does the inferred attribute appear on the sensitive list? |
| Where did our biometric training data come from? | 5(1)(e) | Any web-scraped face images in a recognition database, at any point. |
| Does a score from one relationship affect a decision in another? | 5(1)(c) | Is the detrimental treatment related to the original context, and proportionate? |
| Does anything predict who will offend? | 5(1)(d) | Is the prediction based solely on profiling, or on verifiable facts? |
| Do we identify people biometrically in public, in real time? | 5(1)(h) | Is it for law enforcement, and is there an authorisation in place? |
Frequently asked questions
- When did the EU AI Act prohibitions come into force?
- 2 February 2025. The Article 5 prohibitions were the first substantive obligations to apply, six months after the Regulation entered into force. They have been enforceable across the EU since that date, which means a prohibited practice running today is a live exposure rather than a future compliance project.
- How many practices does the EU AI Act prohibit?
- Ten. Eight have applied since 2 February 2025: subliminal or manipulative techniques, exploitation of vulnerability, social scoring, individual criminal-risk prediction from profiling alone, untargeted facial image scraping, emotion inference in workplaces and education, biometric categorisation inferring sensitive characteristics, and real-time remote biometric identification in public for law enforcement. Regulation (EU) 2026/1744 added two more, applying from 2 December 2026: generating non-consensual intimate imagery, and generating child sexual abuse material.
- Is credit scoring banned under the EU AI Act?
- No. Credit scoring is high-risk under Annex III, not prohibited. The Article 5(1)(c) social scoring ban targets evaluation based on social behavior or personal characteristics that leads to detrimental treatment in an unrelated context, or that is unjustified and disproportionate. Creditworthiness assessment on financially relevant data is a permitted high-risk use subject to the full Chapter III regime.
- What is the penalty for a prohibited AI practice?
- Up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. This is the highest tier in Article 99 and is reserved for Article 5 breaches. The next tier down, covering most other operator obligations including the high-risk and transparency duties, is €15 million or 3%.
- Is emotion recognition banned by the EU AI Act?
- Only in workplaces and education institutions, and even there not where the system is intended for medical or safety reasons. Emotion recognition in other settings is permitted but triggers the Article 50(3) duty to inform people exposed to it, and may be high-risk under Annex III. The setting determines the answer, not the technology.
- Do the prohibitions apply to companies outside the EU?
- Yes. Article 2 extends the Regulation to providers placing AI systems on the EU market wherever they are established, and to providers and deployers outside the EU where the output produced by the system is used in the EU. A prohibited practice operated from outside the EU but affecting people in the EU is in scope.
- Does user consent make a prohibited practice lawful?
- No. Article 5 states prohibitions on placing on the market, putting into service and using the listed practices. Unlike the GDPR, it provides no consent-based route to lawfulness. Consent may be relevant to the separate question of whether a technique materially distorts behavior, but it does not operate as a defense to the prohibition itself.
- Who enforces the Article 5 prohibitions?
- National market surveillance authorities designated by each Member State, with the AI Office coordinating at Union level and holding specific powers over general-purpose AI models. Enforcement is decentralised, so the same practice can be pursued differently across Member States, and penalties are set nationally within the Article 99 ceilings.
Sources and verification
Every date and provision cited here was checked against the consolidated text on 11 August 2026. The EU AI Act is being amended as it is implemented; where this page and EUR-Lex disagree, EUR-Lex governs.
- Regulation (EU) 2024/1689: consolidated text on EUR-Lex (controlling source)
- Regulation (EU) 2026/1744: Digital Omnibus on AI, amending the AI Act (in force 27 July 2026)
- Article 5: Prohibited AI practices
- Article 99: Penalties
- Article 2: Scope
- Annex III: High-risk AI systems
- European Commission: guidelines on prohibited AI practices
This page is an independent information resource. It is not legal advice, and it does not create a lawyer–client relationship. Take advice on your own facts before making a compliance decision.
Next: see where Article 5 sits in the wider schedule in every EU AI Act compliance deadline, read about the duties that attach to permitted systems in the Article 50 transparency guide, or read the provision itself at Article 5.