The EU AI Act does not merely sort uses by level of risk: it rules eight of them out altogether. These are not uses to be «framed» with paperwork — no compliance file rescues them. This page takes each in turn, with the text as written, the real scope of each prohibition, and an example drawn from the guidelines published by the European Commission.
This page reads the texts; it is not legal advice. It cites its sources so you can check them yourself, and it tells you when a lawyer is the right call.
EUR-Lex consolidated text 02024R1689, version of 27 July 2026 — the one that takes account of Regulation (EU) 2026/1744. Source of every quotation from Article 5, Article 99 (penalties) and Article 113 (dates).
Published in the Official Journal on 24 July 2026. It amends Articles 5 and 113 of the 2024 Regulation. A consolidated text dated before that day does not contain it — that is the first thing to check before quoting any date.
Penalty against the operator of a facial recognition tool fed by image scraping. Based on the GDPR, not on the AI Act, and predating it.
Who is caught
Provider or deployer: the two roles targeted by Article 5 of Regulation (EU) 2024/1689
The prohibitions do not target «people who do AI» in general. They target two roles defined by the Regulation — and one company can hold both at once.
The provider
Whoever develops an AI system, or has it developed, and places it on the market or puts it into service under their own name. A provider established outside the Union is caught as soon as the system is placed on the EU market, or where the system's output is used in the Union. A company building a tool in-house for its own use is the provider of that tool.
Whoever uses an AI system under their authority — the employer, the local authority, the firm. The deployer remains liable even where the provider contractually excluded the use in question in its terms. Put plainly: a contract clause does not get you off the hook.
The prohibitions cover three acts: placing on the market, putting into service, and use. For real-time biometric identification (point h), only use is caught.
Article 5(1), points (a) to (h) — The eight prohibited practices, one by one
Subliminal or deceptive manipulation
Systems that steer behaviour by bypassing awareness or free will, and cause significant harm in doing so.
“the placing on the market, the putting into service or the use of an AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision”
Quoted from the official English text of the Regulation, EUR-Lex consolidated version 02024R1689 of 27 July 2026.
Who is caught
Providers and deployers, in every sector, public and private alike. No sectoral limit: this prohibition is not reserved for policing or public administration.
What the text says, plainly
Three elements must come together: a subliminal, purposefully manipulative or deceptive technique; a material distortion of behaviour, such that a person takes a decision they would not otherwise have taken; and significant harm, caused or reasonably likely to be caused. Intent to harm is not required — the Commission notes that a system may have learned manipulative techniques on its own, without the provider wanting it to.
An example given by the Commission
The Commission cites sensory manipulation: an AI system using background sounds or images that induce mood changes, for instance by heightening anxiety and mental distress to the point of causing significant harm. It also cites personalised manipulation, where the system crafts highly persuasive messages from an individual's personal data.
Lawful persuasion remains permitted. An advertisement, a recommendation or a sales pitch does not become prohibited by being effective: the bypassing of free will and the significant harm are both required.
Exploiting a vulnerability
Systems that trade on age, disability or a specific social or economic situation to make someone act against their own interest.
“the placing on the market, the putting into service or the use of an AI system that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation, with the objective, or the effect, of materially distorting the behaviour of that person or a person belonging to that group”
Quoted from the official English text of the Regulation, EUR-Lex consolidated version 02024R1689 of 27 July 2026.
Who is caught
Providers and deployers. The three categories of vulnerability are exhaustive: age, disability, and a specific social or economic situation. A vulnerability of any other kind falls outside this point.
What the text says, plainly
Unlike point (a), the technique need not operate below awareness: it is enough that the system objectively exploits the weakness of a protected group so as to distort its behaviour and cause, or risk causing, significant harm. The Commission notes that vulnerabilities can be cumulative, and that the combination aggravates the harm.
An example given by the Commission
The Commission gives the example of AI systems used to target older people with deceptive personalised offers or scams, exploiting their reduced cognitive capacity to push them into decisions they would not otherwise have made and that are likely to cause them significant financial harm. It also cites an AI-driven toy that pushes children into ever riskier dares in exchange for digital rewards.
An application that is merely inaccessible to disabled people is not exploiting their vulnerability: it is inaccessible. That is an accessibility failing, not a prohibited practice under Article 5.
Social scoring
Scoring people on their behaviour, then applying that score in an unrelated domain, or out of all proportion.
“the placing on the market, the putting into service or the use of AI systems for the evaluation or classification of natural persons or groups of persons over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, with the social score leading to either or both of the following”
Quoted from the official English text of the Regulation, EUR-Lex consolidated version 02024R1689 of 27 July 2026.
Who is caught
Public and private actors alike — the Commission says so expressly. An administration, a bank, a platform, a landlord are all equally caught.
What the text says, plainly
What is prohibited is not the scoring itself but what the score produces. Two situations are covered, separately or together: detrimental treatment in a social context unrelated to the one in which the data was gathered; or detrimental treatment that is unjustified or disproportionate to the behaviour concerned.
An example given by the Commission
The Commission describes a municipality scoring the reliability of its residents from behavioural data gathered across varied contexts. Residents deemed «less reliable» are placed on a blacklist, which strips them of public support and tightens surveillance. Among the factors weighed: insufficient volunteering, library books returned late, bins put out on the wrong day, local taxes paid late.
Assessing a person for a defined purpose set out in law remains lawful: a credit score built on financial data, an assessment mandated by statute. The Commission's own dividing line is that the law designates which data are relevant for that particular assessment.
Predicting offences from profiling alone
Assessing the risk that an individual will commit a criminal offence solely on the basis of profiling or personality traits.
“the placing on the market, the putting into service for this specific purpose, or the use of an AI system for making risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics”
Quoted from the official English text of the Regulation, EUR-Lex consolidated version 02024R1689 of 27 July 2026.
Who is caught
Law enforcement above all, but not only: the Commission notes the text does not reserve the prohibition to the police, since that would make it easy to circumvent. A private company supplying predictive crime analytics can fall within it.
What the text says, plainly
The decisive word is «solely». If the assessment rests exclusively on profiling or personality traits, it is prohibited. If it also draws on objective and verifiable facts directly linked to criminal activity, it falls outside — but those other elements must, the Commission says, be real, substantial and meaningful, not window dressing.
An example given by the Commission
The Commission describes a law enforcement authority predicting terrorism-related criminal behaviour with a system built solely on individuals' age, nationality, address, type of car and marital status. People are deemed more likely to commit future offences purely on the strength of their personal characteristics. Such a system, it writes, «may be presumed to be prohibited».
Place-based prediction — mapping areas where burglaries are likely — targets no individual and falls outside this prohibition. Likewise a system that supports a human assessment already grounded in objective facts: it then becomes a high-risk system, with obligations of its own.
Untargeted scraping of facial images
Building a facial recognition database by indiscriminately harvesting faces from the internet or from CCTV.
“the placing on the market, the putting into service for this specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage”
Quoted from the official English text of the Regulation, EUR-Lex consolidated version 02024R1689 of 27 July 2026.
Who is caught
Providers and deployers. The prohibition does not cover every scraping tool, only those placed on the market or put into service for that specific purpose: the untargeted scraping of facial images.
What the text says, plainly
Four cumulative conditions: an AI system; the creation or expansion of a facial recognition database; untargeted collection; and a source that is either the internet or CCTV. «Untargeted» means, in the Commission's words, hoovering up as many images as possible without aiming at any particular person or group. Two useful points: honouring a robots.txt file does not make the scraping targeted, and slicing the harvest into stages so as to look targeted still falls within the prohibition where the end result is the same.
An example given by the Commission
The Commission describes a facial recognition software company harvesting photographs of faces from social media using an automated image crawler. It extracts facial features, converts them into indexed mathematical representations, and lets a user find a person by uploading their photo. It adds that someone who has posted their own photo on a social network has not thereby consented to sit in a facial recognition database.
Scraping biometric data other than facial images — voice samples, say — falls outside this point. So does genuinely targeted collection: the Commission cites crawlers retrieving images of trafficking victims posted by the traffickers themselves.
Emotion recognition at work and in education
Inferring the emotional state of employees or students, save on medical or safety grounds.
“the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons”
Quoted from the official English text of the Regulation, EUR-Lex consolidated version 02024R1689 of 27 July 2026.
Who is caught
Two settings, and only two: the workplace and education institutions. The Commission states that recruitment is covered, and so is the probationary period. It includes private and public institutions, vocational and continuing training, and extends the prohibition to candidates during admission procedures.
What the text says, plainly
The system must infer an emotion. The medical or safety exception is read narrowly: the Commission states that a system designed to detect burnout or depression does not fall within the exception and remains prohibited.
An example given by the Commission
The Commission writes that a call centre's use of webcams and voice recognition systems to track its employees' emotions, such as anger, is prohibited. It likewise prohibits systems monitoring the emotional tone of hybrid teams during video calls, and a supermarket's use of cameras to track its employees' emotions.
The same call centre may analyse its customers' emotions — anger, impatience — to help staff handle them: a customer is neither an employee nor a student. Eye-tracking software during an online exam remains permitted where it follows gaze without inferring emotion; if it detects anxiety, it crosses into the prohibition.
Biometric categorisation of sensitive characteristics
Using biometric data to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
“the placing on the market, the putting into service for this specific purpose, or the use of biometric categorisation systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation”
Quoted from the official English text of the Regulation, EUR-Lex consolidated version 02024R1689 of 27 July 2026.
Who is caught
Providers and deployers. The list of inferred characteristics is exhaustive: seven categories, not one more.
What the text says, plainly
People must be categorised individually. Where an entire group is categorised without individualisation, the prohibition does not bite. Categorisation that is purely ancillary to another commercial service and strictly necessary for objective technical reasons falls outside the definition — two cumulative conditions the Commission reads strictly.
An example given by the Commission
The Commission cites a system categorising people active on a social media platform by their presumed political leaning, analysing the biometric data in the photos they have uploaded, in order to send them targeted political messaging. It notes that even if such a system might look ancillary to political advertising, it is not «strictly necessary for objective technical reasons»: the carve-out does not apply.
Labelling and filtering lawfully acquired biometric datasets remains permitted — indeed it is sometimes necessary to correct training bias. An augmented-reality filter that fits a product to your face on a retail site is ancillary to the sale and is not caught.
Real-time biometric identification for law enforcement
Real-time remote biometric identification in public spaces for law enforcement purposes — with three tightly framed exceptions.
“the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement, unless and in so far as such use is strictly necessary for one of the following objectives”
Quoted from the official English text of the Regulation, EUR-Lex consolidated version 02024R1689 of 27 July 2026.
Who is caught
This prohibition covers only law enforcement use, by or on behalf of law enforcement authorities, in publicly accessible spaces, and only in real time. It is the only one of the eight that bites on use alone, not on placing on the market.
What the text says, plainly
Three exceptions only: the targeted search for victims of abduction, trafficking or sexual exploitation, and for missing persons; the prevention of a specific, substantial and imminent threat to life or of a terrorist attack; and the localisation of a person suspected of an offence listed in Annex II and punishable by at least four years. Even then it takes prior authorisation from a judicial or independent administrative authority, a fundamental rights impact assessment, registration in the EU database, and a national law permitting it. In duly justified urgency, use may begin before authorisation, but authorisation must be requested within 24 hours; if refused, use stops and the data is deleted.
An example given by the Commission
The Commission describes a European football championship match: police fit a van parked by the stadium entrance with cameras running real-time facial recognition, to identify people on a watchlist. That list mixes suspects of offences ranging from fraud to burglary, persons of intelligence interest, and vulnerable people with mental health problems. The Commission's conclusion: the list is «not precise enough and is not linked to the event», so the use would be prohibited.
An access check where the person steps up to the camera of their own accord is not identification «at a distance»: the Commission cites access to a nuclear plant, outside the scope of Article 5. And post-remote biometric identification is not caught by this prohibition — it falls under the high-risk regime.
Application dates
Applicable since 2 February 2025 — and what changes on 2 December 2026
This is the easiest thing to get wrong, because answering it means reading two regulations.
Since when has Article 5 applied?
Since 2 February 2025. Article 113 of the 2024 Regulation provides that Chapters I and II — which include Article 5 — apply from that date. The Commission's guidelines confirm it and add that the prohibitions apply to all systems, whether placed on the market before or after.
They have only applied since 2 August 2025: Chapter XII, which carries them, has its own application date. Between the two dates the prohibitions were fully binding, yet no market surveillance authority was yet charged with enforcing them. The Commission stresses that even in that window the prohibitions had direct effect and could be relied on before national courts.
No — not for the eight original practices. Regulation (EU) 2026/1744 rewrites point (a) of the third paragraph of Article 113, but it keeps 2 February 2025 for Chapters I and II. It carves out only the provisions it has itself just added.
What changes on 2 December 2026: the list goes from eight to ten
The Digital Omnibus inserts two new points into Article 5(1): a point (ba) and a point (bb). They cover AI systems generating or manipulating non-consensual intimate content, and those generating child sexual abuse material within the meaning of Directive 2011/93/EU. Those two prohibitions, together with the paragraphs 1a and 1b framing them, apply from 2 December 2026 — not since 2025 like the other eight.
“Chapters I and II shall apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026”
Regulation (EU) 2024/1689, Article 113, third paragraph, point (a), as replaced by Regulation (EU) 2026/1744 — official text ↗(opens in a new tab)
Penalties
What breaching Article 5 costs
The Regulation grades its fines by gravity. Breaching Article 5 is the most serious infringement in the text: it attracts the highest ceiling.
€35,000,000 or 7% of worldwide annual turnover
“Non-compliance with the prohibition of the AI practices referred to in Article 5 shall be subject to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.”
Article 99(6) provides that for SMEs, start-ups included, the fine is capped at the stated percentages or amounts, «whichever is lower». For an SME that means 7% of turnover wherever that figure is below €35 million — which it almost always is.
The Commission writes that, since breaches of Article 5 interfere most with the freedoms of others and carry the highest fines, these prohibitions must be interpreted restrictively as to their scope. In other words: the scope is narrow, but what falls inside it is expensive.
A real case, before the AI Act: the Clearview AI penalty
Point (e) — scraping faces — is no textbook hypothesis. France's data protection authority sanctioned exactly that practice in 2022, before the EU AI Act existed.
The company, established in the United States, had collected more than twenty billion facial images from millions of websites and social networks by indexing freely accessible pages. From each photograph it computed a biometric template, then sold a search engine allowing anyone to find a person from a single photo.
What else was ordered
The CNIL coupled its decision with an order to stop collecting without a legal basis, on penalty of €100,000 per day of delay after a two-month deadline.
That penalty rests on Regulation (EU) 2016/679 (GDPR) — no legal basis (Article 6 GDPR), failures on the rights of access and erasure (Articles 12, 15 and 17 GDPR), failure to cooperate (Article 31 GDPR). It is NOT based on the AI Act, which had not yet been adopted. What it shows is that the conduct now caught by Article 5(e) was already actionable, and is now actionable on two counts.
What the case law says — which is to say, nothing yet
There is to date no published court decision applying Article 5 of the AI Act. The reason is simple, and better stated than left to look like an omission: the prohibitions have applied only since 2 February 2025, the penalties since 2 August 2025, and litigation has not yet had time to reach the courts. Any page offering you «AI Act case law» on Article 5 today is offering you something else: data protection decisions, like the CNIL one above, or earlier national rulings that the Commission itself cites by way of illustration.
Frequently asked
What we get asked most
Which practices does the EU AI Act prohibit?
Article 5 of Regulation (EU) 2024/1689 prohibits eight practices: subliminal or deceptive manipulation causing significant harm; exploitation of vulnerabilities linked to age, disability or precarity; social scoring; criminal offence prediction based solely on profiling; untargeted scraping of facial images to build facial recognition databases; inferring emotions at work and in education; biometric categorisation to infer sensitive characteristics; and real-time remote biometric identification for law enforcement. Regulation (EU) 2026/1744 adds two further practices applying from 2 December 2026.
Is emotion recognition at work prohibited?
Yes, save on medical or safety grounds. Article 5(1)(f) prohibits using an AI system to infer a person's emotions in the workplace. The Commission's guidelines state this covers recruitment, the probationary period, and for instance tracking call centre employees' anger by webcam or voice recognition. Analysing customers' emotions, by contrast, is not caught by this point.
Since when does Article 5 of the AI Act apply?
Since 2 February 2025, under Article 113. The corresponding penalties have applied only since 2 August 2025. Regulation (EU) 2026/1744 did not change those dates for the eight original practices; it set 2 December 2026 only for the two practices it adds.
What fine does a prohibited AI practice attract?
Up to €35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(3)). For an SME or a start-up, the lower of the two figures applies (Article 99(6)).
What is social scoring under the AI Act?
It is the evaluation or classification of people by their social behaviour or personal characteristics, where the resulting score leads to detrimental treatment either in a social context unrelated to the one in which the data was gathered, or in a way that is unjustified or disproportionate. The Commission's example is a municipality scoring residents' reliability from late library books or bins put out on the wrong day, and then withdrawing public support.
Is my company caught if it does not build AI?
Yes, if it uses AI. The Regulation distinguishes the provider, who develops the system, from the deployer, who uses it under their authority. Both are caught by Article 5. The guidelines make clear that a deployer stays liable even where the provider contractually excluded the use in question: a contract clause does not excuse breaching the prohibition.
Check that your uses stay on the right side
Our agents are built to assist work — not to score, predict or read emotions. If you are wondering where a project in progress sits, the fifteen-minute audit is for exactly that: naming what is at stake, and telling you when you need a lawyer rather than a supplier.