The four EU AI Act risk tiersA pyramid of four tiers. At the apex, ten prohibited practices carrying fines of 35 million euro or 7 percent of turnover. Below that, high-risk systems subject to the full Chapter III regime. Below that, transparency-risk systems owing Article 50 disclosure duties. At the base, minimal-risk systems, the large majority, owing only the AI literacy duty.Prohibited€35m or 7% of turnoverHigh riskFull Chapter III regime and conformity assessmentTransparency riskDisclosure and marking dutiesMinimal riskAI literacy duty only
The prohibited tier is the smallest and the most expensive to get wrong. Most AI systems sit at the base, owing only the Article 4 AI literacy duty.
10Practices prohibited outright
€35mOr 7% of worldwide turnover
+2Added by the Omnibus, from Dec 2026
0Consent-based exemptions

What Article 5 bans

Article 5 prohibits ten AI practices outright. No conformity assessment, documentation or disclosure makes them lawful: if a practice is within Article 5, the only compliant response is to stop.

This is what separates Article 5 from the rest of the Regulation. Everywhere else, the Act tells you how to do something responsibly: assess the risk, document the system, disclose to the user, register in the database. Article 5 tells you not to do it at all. That difference changes what a compliance response looks like. There is no evidence pack that helps here, and no remediation plan that ends anywhere other than switching the system off.

Article 5(1)(a)Subliminal manipulationConsumer apps with engagement-optimized AI, gambling and trading interfaces, and anything using AI to shape decisions in high-stakes contextsArticle 5(1)(b)Exploiting vulnerabilityProducts aimed at children or older adults, subprime lending and debt products, and any AI targeting layer keyed to financial distressArticle 5(1)(ba)from Dec 2026Non-consensual intimate imageryProviders of image, video and avatar generators, so-called nudifier apps, face-swap tools, and any platform hosting or fine-tuning generative image modelsArticle 5(1)(bb)from Dec 2026Child sexual abuse materialProviders of any generative image or video model, and anyone fine-tuning or distributing open-weight image models without safeguardsArticle 5(1)(c)Social scoringAny organization reusing behavioral data from one relationship to make adverse decisions in an unrelated one: platform trust scores applied off-platform, tenant screening drawing on social mediaArticle 5(1)(d)Predictive policingLaw enforcement and criminal justice bodies, and vendors selling individual risk-scoring tools into themArticle 5(1)(e)Untargeted face scrapingFacial recognition vendors, and any team that has built an internal face-matching capability from web-scraped imagesArticle 5(1)(f)Emotion inference at workHR and people-analytics teams, interview and proctoring platforms, contact centers running sentiment analysis on employee calls, and edtech engagement monitoringArticle 5(1)(g)Sensitive-trait inferenceRetail analytics, audience measurement, and security vendors offering attribute inference from faces or voicesArticle 5(1)(h)Live biometric IDLaw enforcement authorities and their suppliers
The ten practices prohibited by Article 5. Eight have been unlawful across the EU since 2 February 2025; the two marked December 2026 were added by the Omnibus. Select any card for the threshold that has to be crossed.
The four EU AI Act risk tiers and what each one costs
TierWhat sits thereConsequence
ProhibitedTen practices banned outright: eight since February 2025, two more from December 2026€35m or 7% of turnover
High riskAnnex I product safety and eight Annex III use-case areasFull Chapter III regime and conformity assessment
Transparency riskArticle 50: interaction notice, synthetic marking, deep fakesDisclosure and marking duties
Minimal riskEverything else: the large majority of AI systemsAI literacy duty only

What the 2026 Omnibus added

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and inserted two new prohibitions at Article 5(1)(ba) and (bb). Both apply from 2 December 2026.

This is the first expansion of Article 5 since the Act was adopted, and it is the part of the Omnibus that got least attention, because the same instrument deferred the high-risk deadlines and that dominated the coverage. The two additions run in the opposite direction to the deferrals: they widen the prohibited tier rather than delay it.

The two prohibitions added by Regulation (EU) 2026/1744
ProvisionWhat it prohibitsApplies from
Article 5(1)(ba)Generating or manipulating realistic depictions of the intimate parts or sexually explicit conduct of an identifiable person without their explicit consent2 December 2026
Article 5(1)(bb)Generating or manipulating child sexual abuse material within the meaning of Directive 2011/93/EU2 December 2026

Two features make these unlike the original eight. First, there is no grandfathering: a system already on the market on 2 December 2026 is in scope from that date. Second, the new Article 5(1a) and (1b) attach liability to reasonably foreseeable misuse, not only to intended purpose. A provider can be caught by an outcome it did not design for.

The child sexual abuse material prohibition is drafted to catch synthetic output. The material need not depict a real child, which closes the gap that had allowed purely generated content to be argued outside existing criminal provisions. The carve-out is narrow: purposes justified under national law, such as criminal proceedings, and red-teaming carried out under those conditions.

Why the thresholds matter

Most Article 5 paragraphs are narrower than their shorthand names suggest. Several require both a material distortion of behaviour and significant harm before the ban applies, and reading only the headline produces false positives in both directions.

Take Article 5(1)(a). Described as banning “manipulative AI”, it sounds like it captures most of the modern consumer internet. Read properly, it requires a subliminal, purposefully manipulative or deceptive technique, which materially distorts behavior by appreciably impairing the ability to make an informed decision, which causes or is reasonably likely to cause significant harm. Three conditions, all needed. An engagement-optimized feed is not automatically caught.

The inverse error is more dangerous. Article 5(1)(e), on untargeted facial image scraping, has no harm threshold and no balancing test at all. Teams accustomed to the GDPR’s proportionality reasoning look for a legitimate interests argument that does not exist in the provision.

Threshold structure across the ten prohibitions
ProhibitionRequires significant harm?Trigger
5(1)(a) Subliminal manipulationYesTechnique + material distortion + significant harm
5(1)(b) Exploiting vulnerabilityYesNamed vulnerability + material distortion + significant harm
5(1)(ba) Non-consensual intimate imageryNoRealistic depiction + identifiable person + no explicit consent
5(1)(bb) Child sexual abuse materialNoGeneration or manipulation of the material, real or synthetic
5(1)(c) Social scoringNo: proportionality test insteadDetrimental treatment that is unrelated, or unjustified and disproportionate
5(1)(d) Predictive policingNoPrediction based solely on profiling or personality traits
5(1)(e) Face scrapingNoUntargeted scraping that builds or expands a facial recognition database
5(1)(f) Emotion at workNoSetting: workplace or education, absent medical or safety purpose
5(1)(g) Sensitive-trait inferenceNoBiometric categorisation inferring a listed sensitive characteristic
5(1)(h) Live biometric IDNoReal-time + remote + public space + law enforcement purpose

Each prohibition in detail

Each prohibition below sets out the threshold that has to be crossed, the carve-outs written into the paragraph, and the adjacent practice that is regulated rather than banned.

Article 5(1)(a)Prohibited

Subliminal, manipulative or deceptive techniques

AI systems that deploy subliminal, purposefully manipulative or deceptive techniques to materially distort a person's behavior are prohibited, but only where that distortion causes or is reasonably likely to cause significant harm.

The threshold that has to be crossed

Two conditions, both required: the technique must materially distort behavior by appreciably impairing the ability to make an informed decision, and that distortion must cause or be reasonably likely to cause significant harm to that person, another person or a group.

Carve-outs in the paragraph

  • Lawful persuasion that does not impair informed decision-making
  • Ordinary advertising and personalisation that falls short of material distortion
  • Approved therapeutic uses carried out with informed consent

Who is most exposed

Consumer apps with engagement-optimized AI, gambling and trading interfaces, and anything using AI to shape decisions in high-stakes contexts.

Commonly confused with

Persuasive design, dark patterns and recommender optimization

Generally outside Article 5 unless the significant-harm threshold is crossed, but squarely within consumer protection law, the Digital Services Act and the GDPR

Article 5(1)(b)Prohibited

Exploiting vulnerabilities of age, disability or circumstance

AI systems that exploit vulnerabilities arising from a person's age, disability, or specific social or economic situation in order to materially distort their behavior are prohibited where that causes or is reasonably likely to cause significant harm.

The threshold that has to be crossed

The system must exploit a vulnerability of one of the named kinds, materially distort behavior, and cause or be reasonably likely to cause significant harm. Note that economic hardship is expressly a listed vulnerability.

Carve-outs in the paragraph

  • Accessibility and assistive technology designed to help the same groups
  • Targeting that does not exploit the vulnerability to distort behaviour harmfully

Who is most exposed

Products aimed at children or older adults, subprime lending and debt products, and any AI targeting layer keyed to financial distress.

Commonly confused with

Age-based or income-based audience targeting in advertising

Not prohibited by itself. The ban requires exploitation of the vulnerability plus behavioral distortion plus significant harm.

Article 5(1)(ba)ProhibitedApplies 2 Dec 2026

Generating non-consensual intimate imagery

AI systems that generate or manipulate realistic depictions of the intimate parts, or sexually explicit conduct, of an identifiable person without that person's explicit consent are prohibited from 2 December 2026.

The threshold that has to be crossed

The depiction must be realistic and the person identifiable, and consent must be absent. Consent has to be freely given, specific, informed, unambiguous and explicit: the GDPR standard, not a buried terms-of-service acceptance.

Carve-outs in the paragraph

  • Depictions of people who are not identifiable
  • Use with the subject's freely given, specific, informed, unambiguous and explicit consent
  • Systems with reasonable and adequate technical safeguards against the outcome: the new Article 5(1a) and (1b) safeguards defence

Who is most exposed

Providers of image, video and avatar generators, so-called nudifier apps, face-swap tools, and any platform hosting or fine-tuning generative image models.

Commonly confused with

General-purpose image and video generators

Not prohibited as such, but providers are liable where this misuse is a reasonably foreseeable outcome, even if unintended. The defence is demonstrable technical safeguards, so a general-purpose generator without guardrails is exposed.

Article 5(1)(bb)ProhibitedApplies 2 Dec 2026

Generating child sexual abuse material

AI systems that generate or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU are prohibited from 2 December 2026, with only a narrow carve-out for legitimate purposes authorised under national law.

The threshold that has to be crossed

No harm threshold and no balancing test. The material need not depict a real child: synthetic generation is caught, which closes the gap that had let purely synthetic output be argued outside existing criminal provisions.

Carve-outs in the paragraph

  • Purposes justified under national law, such as criminal proceedings
  • Red-teaming and safety evaluation carried out under those legitimate-purpose conditions

Who is most exposed

Providers of any generative image or video model, and anyone fine-tuning or distributing open-weight image models without safeguards.

Commonly confused with

Safety classifiers trained to detect this material

Outside the ban: the prohibition targets generation and manipulation, not detection. Red-teaming a model to prove its safeguards hold falls within the legitimate-purpose carve-out.

Article 5(1)(c)Prohibited

Social scoring leading to unrelated detrimental treatment

AI systems that evaluate or classify people based on their social behavior or personal characteristics are prohibited where the resulting social score leads to detrimental or unfavorable treatment that is either unrelated to the context in which the data was generated, or unjustified and disproportionate to the behavior.

The threshold that has to be crossed

The detrimental treatment must be either unrelated to the original context of the data, or unjustified or disproportionate to the social behavior. A score used for a purpose properly connected to the data, proportionately, is not caught.

Carve-outs in the paragraph

  • Lawful evaluation practices where the assessment is contextually related and proportionate
  • Sector-specific scoring that Annex III instead classifies as high-risk

Who is most exposed

Any organization reusing behavioral data from one relationship to make adverse decisions in an unrelated one: platform trust scores applied off-platform, tenant screening drawing on social media.

Commonly confused with

Credit scoring and insurance risk pricing

High-risk under Annex III, not prohibited. Creditworthiness assessment and life and health insurance pricing are permitted subject to the full Chapter III regime. The ban targets scores that travel across unrelated contexts.

Article 5(1)(d)Prohibited

Predicting individual criminality from profiling alone

AI systems that assess or predict the risk of a person committing a criminal offence based solely on profiling or on assessing their personality traits and characteristics are prohibited.

The threshold that has to be crossed

The word doing the work is “solely”. The ban does not extend to AI that supports a human assessment already grounded in objective and verifiable facts directly linked to a criminal activity.

Carve-outs in the paragraph

  • AI supporting a human assessment based on objective, verifiable facts directly linked to criminal activity
  • Place-based and offence-based analysis that does not predict individual criminality

Who is most exposed

Law enforcement and criminal justice bodies, and vendors selling individual risk-scoring tools into them.

Commonly confused with

Fraud detection and anti-money-laundering systems

Not caught, because these work from transactional facts rather than personality profiling. Law-enforcement risk assessment tools are separately listed as high-risk in Annex III.

Article 5(1)(e)Prohibited

Untargeted scraping of facial images

Creating or expanding facial recognition databases through the untargeted scraping of facial images from the internet or from CCTV footage is prohibited outright.

The threshold that has to be crossed

No harm threshold and no balancing test. This is among the flattest prohibitions in the Article: if the scraping is untargeted and it builds or expands a facial recognition database, it is banned.

Carve-outs in the paragraph

  • None stated in the paragraph itself

Who is most exposed

Facial recognition vendors, and any team that has built an internal face-matching capability from web-scraped images.

Commonly confused with

Training a model on a licensed or consented face dataset

Outside this ban, though still subject to the GDPR and, where the system is a biometric identification system, to the Annex III high-risk regime.

Article 5(1)(f)Prohibited

Emotion inference in workplaces and education

AI systems that infer the emotions of a person in the workplace or in an education institution are prohibited, except where the system is intended to be put in place for medical or safety reasons.

The threshold that has to be crossed

Setting rather than harm is the trigger. The same emotion recognition system may be lawful in a retail context and prohibited in an office or a classroom.

Carve-outs in the paragraph

  • Systems intended for medical reasons
  • Systems intended for safety reasons: for example fatigue detection where alertness is a safety-critical factor

Who is most exposed

HR and people-analytics teams, interview and proctoring platforms, contact centers running sentiment analysis on employee calls, and edtech engagement monitoring.

Commonly confused with

Emotion recognition in other settings

Permitted, but it triggers the Article 50(3) duty to notify the people exposed to it, and it is high-risk where Annex III applies.

Article 5(1)(g)Prohibited

Biometric categorisation to infer sensitive characteristics

Biometric categorisation systems that categorise people in order to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation are prohibited.

The threshold that has to be crossed

The prohibited element is inference of one of the listed sensitive characteristics from biometric data. Biometric categorisation on other attributes is not caught by this paragraph.

Carve-outs in the paragraph

  • Labelling and filtering of lawfully acquired biometric datasets, including in the field of law enforcement
  • Categorisation of biometric data by law enforcement within the limits the Regulation sets

Who is most exposed

Retail analytics, audience measurement, and security vendors offering attribute inference from faces or voices.

Commonly confused with

Demographic estimation for analytics

Outside this specific ban where it does not infer a listed sensitive characteristic, but still a biometric categorisation system for Annex III and Article 50(3) purposes.

Article 5(1)(h)Prohibited

Real-time remote biometric identification in public

Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes is prohibited, subject to three narrowly drawn exceptions that themselves require prior authorisation and a fundamental rights impact assessment.

The threshold that has to be crossed

All of real-time, remote, publicly accessible space, and law enforcement purpose must be present. Post-event identification and non-law-enforcement uses fall outside this paragraph, though they may be high-risk under Annex III.

Carve-outs in the paragraph

  • Targeted search for specific victims of abduction, trafficking or sexual exploitation, or for missing persons
  • Prevention of a specific, substantial and imminent threat to life or physical safety, or a genuine and present or foreseeable threat of a terrorist attack
  • Localisation or identification of a person suspected of an offence listed in Annex II and punishable by a custodial sentence of at least four years

Who is most exposed

Law enforcement authorities and their suppliers. Private operators of public spaces should note that acting at the request of law enforcement can bring them within scope.

Commonly confused with

Biometric access control at your own premises

Not a law enforcement use in a publicly accessible space, so outside this ban, but it is a biometric system with GDPR and, potentially, Annex III high-risk consequences.

Five things that are not banned

The most expensive Article 5 mistakes run in both directions: stopping a lawful product on a misreading, or continuing a prohibited one because it resembles something lawful.

Practices commonly assumed to be prohibited, and what they actually are
PracticeNot prohibited becauseWhat actually applies
Credit scoringIt assesses creditworthiness on financially relevant data, not social behavior repurposed across contextsHigh-risk under Annex III: full Chapter III regime from 2 December 2027
Fraud and AML detectionIt works from transactional facts, not personality profiling, so Article 5(1)(d) is not engagedOften high-risk; always subject to the GDPR
Emotion recognition in retailThe Article 5(1)(f) ban is limited to workplaces and education institutionsArticle 50(3) notification duty, and Annex III where applicable
CV screening and candidate rankingEmployment AI is listed as high-risk, not prohibited, unless it infers emotion or sensitive traitsHigh-risk under Annex III point 4
Post-event biometric identificationArticle 5(1)(h) is confined to real-time identificationHigh-risk under Annex III, with its own safeguards

Why this tier is different

Article 5 breaches carry up to €35 million or 7% of total worldwide annual turnover, whichever is higher: more than double the ceiling for high-risk and transparency failures.

Two features compound that exposure. The turnover limb is calculated on groupworldwide turnover, so a small EU entity carries its parent’s size. And because the prohibitions have applied since February 2025, exposure is not prospective: it accrues for as long as the practice runs. An organization discovering a prohibited practice today is not late for a deadline, it is already in breach.

Article 5 exposure compared with the other penalty tiers
BreachCeilingApplies since
Prohibited practices (Article 5)€35m or 7% of turnover2 February 2025, and 2 December 2026 for the two new bans
Most operator obligations, including high-risk and Article 50€15m or 3% of turnover2 August 2026 onward, by obligation
Incorrect or misleading information to authorities€7.5m or 1% of turnover2 August 2025

How to audit for exposure

Screen by capability rather than by product name. Prohibited practices rarely appear in a system’s description, they appear as a feature inside something bought for another purpose.

An organisation that asks “do we run any social scoring systems?” will get no useful answers, because nobody builds a product and calls it that. The productive question is narrower and behavioral: what does this system infer, about whom, and what happens to the person as a result.

Article 5 screening questions by capability
AskFlagsFollow-up
Does anything infer emotional or psychological state?5(1)(f), 5(1)(a)Where is it used? Workplace and education are the trigger settings.
Does anything infer characteristics from a face, voice or body?5(1)(g)Does the inferred attribute appear on the sensitive list?
Where did our biometric training data come from?5(1)(e)Any web-scraped face images in a recognition database, at any point.
Does a score from one relationship affect a decision in another?5(1)(c)Is the detrimental treatment related to the original context, and proportionate?
Does anything predict who will offend?5(1)(d)Is the prediction based solely on profiling, or on verifiable facts?
Do we identify people biometrically in public, in real time?5(1)(h)Is it for law enforcement, and is there an authorisation in place?

Frequently asked questions

When did the EU AI Act prohibitions come into force?
2 February 2025. The Article 5 prohibitions were the first substantive obligations to apply, six months after the Regulation entered into force. They have been enforceable across the EU since that date, which means a prohibited practice running today is a live exposure rather than a future compliance project.
How many practices does the EU AI Act prohibit?
Ten. Eight have applied since 2 February 2025: subliminal or manipulative techniques, exploitation of vulnerability, social scoring, individual criminal-risk prediction from profiling alone, untargeted facial image scraping, emotion inference in workplaces and education, biometric categorisation inferring sensitive characteristics, and real-time remote biometric identification in public for law enforcement. Regulation (EU) 2026/1744 added two more, applying from 2 December 2026: generating non-consensual intimate imagery, and generating child sexual abuse material.
Is credit scoring banned under the EU AI Act?
No. Credit scoring is high-risk under Annex III, not prohibited. The Article 5(1)(c) social scoring ban targets evaluation based on social behavior or personal characteristics that leads to detrimental treatment in an unrelated context, or that is unjustified and disproportionate. Creditworthiness assessment on financially relevant data is a permitted high-risk use subject to the full Chapter III regime.
What is the penalty for a prohibited AI practice?
Up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. This is the highest tier in Article 99 and is reserved for Article 5 breaches. The next tier down, covering most other operator obligations including the high-risk and transparency duties, is €15 million or 3%.
Is emotion recognition banned by the EU AI Act?
Only in workplaces and education institutions, and even there not where the system is intended for medical or safety reasons. Emotion recognition in other settings is permitted but triggers the Article 50(3) duty to inform people exposed to it, and may be high-risk under Annex III. The setting determines the answer, not the technology.
Do the prohibitions apply to companies outside the EU?
Yes. Article 2 extends the Regulation to providers placing AI systems on the EU market wherever they are established, and to providers and deployers outside the EU where the output produced by the system is used in the EU. A prohibited practice operated from outside the EU but affecting people in the EU is in scope.
Does user consent make a prohibited practice lawful?
No. Article 5 states prohibitions on placing on the market, putting into service and using the listed practices. Unlike the GDPR, it provides no consent-based route to lawfulness. Consent may be relevant to the separate question of whether a technique materially distorts behavior, but it does not operate as a defense to the prohibition itself.
Who enforces the Article 5 prohibitions?
National market surveillance authorities designated by each Member State, with the AI Office coordinating at Union level and holding specific powers over general-purpose AI models. Enforcement is decentralised, so the same practice can be pursued differently across Member States, and penalties are set nationally within the Article 99 ceilings.

Sources and verification

Every date and provision cited here was checked against the consolidated text on 11 August 2026. The EU AI Act is being amended as it is implemented; where this page and EUR-Lex disagree, EUR-Lex governs.

This page is an independent information resource. It is not legal advice, and it does not create a lawyer–client relationship. Take advice on your own facts before making a compliance decision.

Next: see where Article 5 sits in the wider schedule in every EU AI Act compliance deadline, read about the duties that attach to permitted systems in the Article 50 transparency guide, or read the provision itself at Article 5.