Prohibited AI practices are the only part of the EU AI Act that is already fully in force and carries the largest fine in the Regulation. Article 5 has applied since 2 February 2025, and breaching it costs up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher.
The eight practices are also narrower than their headlines suggest. Nearly every one carries a qualifier that decides whether real-world systems are caught, and reading only the summary produces both false alarms and false comfort.
The eight prohibited AI practices

Article 5(1) prohibits the placing on the market, putting into service or use of AI systems in eight categories. What follows is what each one actually says.
The two prohibited AI practices that turn on harm
(a) Subliminal, manipulative or deceptive techniques. The prohibition is not on persuasion. It applies where techniques operate beyond a person’s consciousness, or are purposefully manipulative or deceptive, with the objective or effect of materially distorting behaviour by appreciably impairing the ability to make an informed decision — causing a decision they would not otherwise have taken — in a manner that causes or is reasonably likely to cause significant harm.
(b) Exploiting vulnerabilities due to age, disability, or a specific social or economic situation, with the same material-distortion and significant-harm tests.
Both of these prohibited AI practices require significant harm. A recommendation engine that nudges purchasing is not caught by (a) merely because it is effective — the question is whether it impairs informed decision-making and risks significant harm. That is a genuinely high bar, and worth stating internally before a project is cancelled unnecessarily.
Social scoring: the consequence, not the score
(c) prohibits evaluating or classifying people over a period of time based on social behaviour or known, inferred or predicted personal characteristics, where the social score leads to either:
- detrimental or unfavourable treatment in social contexts unrelated to the contexts in which the data was originally generated or collected; or
- detrimental or unfavourable treatment that is unjustified or disproportionate to the behaviour.
The prohibition attaches to the consequence, not the scoring. Context transfer is the trigger most likely to catch a commercial system: using behaviour observed in one relationship to disadvantage someone in an unrelated one.
Four prohibited AI practices with explicit carve-outs
(d) Predictive policing based solely on profiling. Assessing or predicting the risk that a person will commit a criminal offence, based solely on profiling or on assessing personality traits. The carve-out is express: this does not apply to AI systems supporting a human assessment of involvement in criminal activity that is already based on objective and verifiable facts directly linked to criminal activity.
(f) Emotion inference in the workplace and education. Prohibited in workplaces and education institutions — except where the system is intended for medical or safety reasons. Note the two settings named: this is not a general ban on emotion recognition.
(g) Biometric categorisation of sensitive traits. Categorising individuals from biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. The prohibition does not cover labelling or filtering of lawfully acquired biometric datasets, such as images, or categorising biometric data in the area of law enforcement.
(h) Real-time remote biometric identification in publicly accessible spaces for law enforcement — unless strictly necessary for defined objectives, including targeted searches for victims of abduction, trafficking or sexual exploitation, searches for missing persons, and preventing a specific, substantial and imminent threat to life or physical safety.
The one prohibited AI practice with no qualifier
(e) Untargeted scraping of facial images. Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
No harm test, no carve-out, no purpose limitation in the text. Of the eight, this is the cleanest prohibition — and the one most likely to be inherited from a vendor whose training data provenance you never asked about.
Why prohibited AI practices are urgent and the rest is not
Article 113 staggers application. The Regulation applies generally from 2 August 2026, but Chapters I and II — which contain Article 5 — applied from 2 February 2025. Article 6(1) and its corresponding high-risk obligations do not apply until 2 August 2027.
So the sequencing for most organisations is the opposite of how they are planning: the high-risk classification work has time, and the prohibition screen does not. It has already been live for over a year.
The fine reinforces it. Article 99(3) sets non-compliance with Article 5 at up to €35 million or 7% of worldwide annual turnover, against €15 million or 3% for most other operator breaches.
How prohibited AI practices fit your AI governance
| Framework | Connection |
|---|---|
| EU AI Act risk categories | Prohibited practices sit above the high-risk tier — a screening question, not a risk rating |
| EU AI Act deadlines | The full staggered timeline, including the 2027 high-risk date |
| ISO 42001 | The management system that makes the screen repeatable rather than a one-off legal review |
| NIST AI RMF | MAP is where a prohibition check belongs in the lifecycle, before design decisions harden |
Where to start screening for prohibited AI practices
- Screen the AI inventory against all eight — including systems you bought rather than built.
- Read the qualifiers before concluding. Most of the practices require harm, context transfer, or a specific setting.
- Check training data provenance for anything involving facial recognition, because (e) has no carve-out.
- Look hardest at workplace tools, where (f) applies by setting rather than by intent.
- Record the screening conclusion per system, with the reasoning — a defensible “not prohibited” is an asset.
- Re-screen on change, since a repurposed system can cross into Article 5 without any new procurement.
This guide reflects Regulation (EU) 2024/1689 as published on EUR-Lex, read at 16 August 2026.
The EU AI Act Toolkit provides 60 editable templates covering the AI system inventory, the prohibited practice and risk classification screening, the technical documentation and the governance records the Regulation expects.