EU AI Act prohibited practices: complete compliance guide for May 2026

You can't risk-assess your way out of EU AI Act prohibited practices. The EU bans these eight categories entirely, and the penalties top out at €35 million or 7% of worldwide annual turnover. Enforcement went live in August 2025, and the challenge goes beyond avoiding prohibited territory at launch: it's maintaining proof that your systems stay compliant as they change in production, especially since the Commission can expand the prohibited list without warning.
TLDR:
- EU AI Act prohibits 8 AI categories outright, with €35M or 7% global revenue fines - no compliance path exists
- Banned systems include subliminal manipulation, biometric scraping, real-time facial recognition, and profiling-based predictive policing
- Article 5 enforcement started August 2025; violations are treated as fundamental rights breaches, not compliance gaps
- Technical compliance requires pre-deployment classification, continuous monitoring for feature drift, and annual reviews as prohibited categories expand
- Openlayer automates Article 5 compliance through real-time monitoring, bias detection, and audit-ready evidence trails
What are prohibited AI practices under the EU AI Act
Prohibited AI practices are specific categories of AI applications that the EU AI Act bans outright: no risk assessment, no exemptions for most actors, no path to compliance. They sit at the top of the Act's risk hierarchy because the potential for harm is considered irreversible or fundamentally incompatible with EU fundamental rights.
The Act identifies eight categories of prohibited practices, covering systems that exploit vulnerabilities, provide for mass surveillance, or manipulate behavior without user awareness.
| Prohibited Practice | Article Reference | Description | Common examples |
|---|---|---|---|
| Subliminal Manipulation | Article 5(1)(a) | AI systems using subliminal techniques below conscious awareness to manipulate behavior or exploit psychological weaknesses | Hidden nudges bypassing rational decision-making, AI-generated synthetic media deceiving users about content origin, personalized manipulation targeting inferred vulnerabilities |
| Exploitation of Vulnerabilities | Article 5(1)(b) | AI systems exploiting vulnerabilities tied to age, disability, or economic hardship to distort behavior causing substantial harm | Predatory lending tools targeting financially distressed users, children's apps using reward mechanics to extract data, AI health tools misleading cognitively impaired users |
| Social Scoring Systems | Article 5(1)(c) | AI systems scoring or classifying people based on social behavior or personal characteristics, imposing detrimental treatment in unrelated contexts | Workplace productivity scores affecting loan eligibility, continuous behavioral scoring without proportionality checks, cross-context score transfer from employment to financial services |
| Emotion Recognition in Workplace and Education | Article 5(1)(f) | AI systems inferring emotions of workers and students in professional and educational contexts | Workplace monitoring tools scoring employee sentiment or stress states, educational software reading student attention or emotional responses to adjust content |
| Biometric Categorization for Sensitive Characteristics | Article 5(1)(g) | AI systems inferring race, political opinion, trade union membership, religious belief, or sexual orientation from biometric data | Facial analysis tools sorting people by perceived ethnicity, emotion-based systems flagging political sympathies, categorization based on physical appearance or behavioral signals |
| Predictive Policing Based on Profiling | Article 5(1)(d) | AI predicting criminal risk based solely on profiling or personality traits without objective, verifiable facts tied to actual criminal activity | Retail systems flagging shoppers as theft risks based on age or ethnicity instead of observed behavior, suspicion generation from demographics without factual evidence |
| Untargeted Facial Image Scraping | Article 5(1)(e) | Creating or expanding facial recognition databases through untargeted scraping of internet images or CCTV footage for biometric identification | Scraping social media profiles to build face-matching databases, aggregating public footage indiscriminately, mass harvesting without explicit authorization per data source |
| Real-Time Remote Biometric Identification | Article 5(1)(h) | Real-time biometric identification in publicly accessible spaces, with narrow law enforcement exceptions requiring prior judicial authorization | Live facial recognition in public spaces for mass surveillance, deployment without fundamental rights impact assessment, use outside narrow exceptions for missing persons or imminent terrorist threats |
Why prohibited practices carry the highest penalties in AI regulation
Violations of Article 5 carry the steepest fines in the EU AI Act: up to €35 million or 7% of total worldwide annual turnover, whichever is higher. High-risk violations cap at €15 million or 3%.
The EU treats prohibited practices as fundamental rights violations, not compliance gaps. These systems conflict directly with the EU Charter of Fundamental Rights, which is why no risk mitigation path exists. You cannot document your way out of a prohibited category.
Enforcement has been live since August 2025, when Article 5 provisions entered into force. National market surveillance authorities across member states are actively empowered to investigate and issue fines. For large enterprises, 7% of global revenue will almost always exceed the flat €35 million cap, making this a material financial exposure.
Subliminal manipulation and deceptive AI techniques

The EU AI Act bans AI systems that use subliminal techniques operating below conscious awareness to manipulate behavior, or that exploit psychological weaknesses to distort decision-making in harmful ways. These prohibitions cover a wide range of deceptive design patterns. Prohibited techniques include hidden nudges that bypass rational decision-making, AI-generated synthetic media used to deceive users about content origin, and personalized manipulation that targets individuals based on inferred vulnerabilities such as anxiety, loneliness, or financial stress.
Exploitation of vulnerabilities based on age, disability, or economic circumstance
Article 5(1)(b) targets AI systems that exploit vulnerabilities tied to age, disability, or economic hardship to distort behavior in ways that cause substantial harm. Unlike subliminal manipulation, this prohibition does not require that a user be unaware of the system. Harm can occur even when the interaction is visible, if the AI is deliberately designed to exploit diminished capacity or financial desperation. This applies to both public and private actors. A government benefits system that steers vulnerable claimants toward worse outcomes is as prohibited as a commercial app doing the same. Here are some common examples regulators have flagged:
- Predatory lending tools that identify financially distressed users and present misleading loan terms timed to moments of acute stress
- Children's apps that exploit developmental stages, using reward mechanics or social pressure to extract personal data or drive purchases
- AI health tools that target users with cognitive impairments and nudge them toward decisions against their medical interest
The key test is intent combined with effect: does the system identify a vulnerability, and does it act on that vulnerability to produce harm? If yes, no amount of disclosed terms or consent flows will bring the system into compliance. The prohibition is categorical.
Social scoring systems and unjustified detrimental treatment
Article 5(1)(c) targets AI systems that score or classify people based on social behavior or personal characteristics, then use those scores to impose detrimental treatment in unrelated contexts or to a degree disproportionate to the original behavior. The prohibition follows a two-part test: where the scoring occurs matters less than where the consequences land. China's social credit system, for example, is the obvious reference point, but the prohibition is broader. Any system that aggregates behavioral signals into a score, then routes that score into consequential decisions, faces scrutiny.
Workplace monitoring tools are a gray area worth watching closely. Productivity scoring systems that feed into hiring, promotion, or termination decisions may be fine in isolation. The risk appears when:
- Scores pulled from one context (email response times, meeting attendance) influence decisions in another (loan eligibility, insurance pricing)
- Scoring is continuous and cumulative without any proportionality check against the underlying behaviors
- Employees cannot contest or understand how their scores were generated
The key question regulators will ask is simple: does the treatment match the behavior? If an employee's "engagement score" shapes their access to financial services, that link is exactly what Article 5(1)(c) was written to cut.
Emotion recognition in workplace and education settings
The EU AI Act explicitly bans AI systems that infer emotions of workers and students in professional and educational contexts. This prohibition targets a specific concern: emotion recognition tech has shown poor reliability across different demographics and deploying it in high-stakes environments creates coercive conditions where people are effectively surveilled without meaningful recourse. The ban covers workplace monitoring tools that score employee sentiment, engagement, or stress states, as well as educational software that reads student attention or emotional responses to adjust content or flag behavior.
Biometric categorization for sensitive characteristics

Systems that infer a person's race, political opinion, trade union membership, religious belief, or sexual orientation from biometric data fall under the EU AI Act's prohibited practices. This ban covers AI that categorizes individuals into sensitive groups based on physical appearance or behavioral signals, even indirectly.
For example, facial analysis tools that sort people by perceived ethnicity or emotion-based systems used to flag political sympathies both qualify. The prohibition applies regardless of whether the categorization is the system's primary function or a secondary output.
Predictive policing and criminal risk assessment based solely on profiling
Article 5(1)(d) bans AI that predicts criminal risk based solely on profiling or personality traits, without objective, verifiable facts tied to actual criminal activity. Keep in mind that "solely" is the operative word. The prohibition does not ban AI from supporting human investigators who already have verifiable, crime-linked evidence. What is banned is AI generating suspicion from scratch, with no factual anchor beyond demographics, inferred traits, or behavioral tendencies. Retail loss prevention shows the line clearly, requiring ongoing monitoring. A system that flags shoppers as theft risks based on age, ethnicity, or shopping patterns instead of observed behavior like concealing merchandise is prohibited. Suspicion must follow what someone did, not who they appear to be.
Untargeted facial image scraping and database expansion
Article 5(1)(e) bans creating or expanding facial recognition databases through untargeted scraping of internet images or CCTV footage for biometric identification. If collection is indiscriminate and the data feeds a searchable identification system, it is prohibited regardless of the source. The line regulators draw is between untargeted and targeted collection. Gathering facial data from a specific, consented group for a defined, legally grounded security purpose remains permissible. Scraping social media profiles or aggregating public footage to build a face-matching database does not.
Real-time remote biometric identification in public spaces
Real-time remote biometric identification in publicly accessible spaces is broadly prohibited under Article 5(1)(h), with narrow carve-outs reserved exclusively for law enforcement:
- Locating missing persons or crime victims
- Preventing a specific and imminent terrorist threat
- Identifying suspects in serious criminal offenses carrying serious penalties
Each exception carries hard procedural requirements: prior authorization from a competent judicial or independent administrative authority, registration in the EU database for high-risk AI systems, and a completed fundamental rights impact assessment before any system goes live. One limited safety valve applies: genuine urgency permits immediate deployment, but retrospective judicial authorization must follow without delay.
Maintaining technical compliance with prohibited practice requirements
Classifying systems against Article 5 starts before a single line of production code ships. Every AI project needs a structured intake that maps its core function against each prohibited category, with that evidence captured before deployment using AI governance platforms. For borderline cases, outputs matter more than stated intent. If a system produces prohibited effects at scale, classification follows what it actually does. Evidence that a system falls outside prohibited categories should capture functional design, intended outputs, and the monitoring records that show real-world behavior matches that design.
Three controls every governance team needs:
- A documented pre-deployment classification review against each Article 5 category
- Monitoring for feature drift that could push a previously compliant system into prohibited territory
- An annual review cycle, since the Commission can expand the prohibited list through delegated acts
That last point is easy to miss. A system compliant today may be prohibited after the Commission acts on new evidence of harm. Static compliance documentation goes stale fast.
How AI governance infrastructure proves Article 5 compliance
Compliance with Article 5 requires live evidence that your AI systems behave within legal boundaries across their full production lifecycle. AI governance infrastructure gives compliance teams the visibility to prove that. Continuous monitoring logs model inputs, outputs, and decisions in real time. Automated evaluation flags behaviors tied to prohibited categories before they reach end users. Audit trails provide regulators with timestamped records of every intervention.
The gap between "we believe our system is compliant" and "here is the evidence" is where regulatory exposure lives.
Final thoughts on Article 5 compliance and prohibited AI systems
Prohibited practices under the AI Act exist because certain applications conflict fundamentally with EU values, not because they lack proper oversight. Your organization needs infrastructure that identifies EU AI Act prohibited AI practices before systems reach production and maintains continuous evidence that deployed models stay within legal boundaries. Classification isn't a one-time checkbox. Systems drift, features expand, and the Commission can add new prohibited categories through delegated acts. If you're looking for governance infrastructure that provides real-time visibility into model behavior and keeps audit trails regulators will accept, contact us.
FAQ
Can you deploy AI systems that predict employee performance based on personality traits under the EU AI Act?
No. Article 5(1)(d) prohibits AI that assesses criminal risk based solely on profiling or personality traits without objective facts tied to actual behavior. While this prohibition directly targets predictive policing, workplace systems that score employees based purely on inferred traits instead of documented performance metrics face similar scrutiny under the exploitation of vulnerabilities provisions and social scoring prohibitions.
EU AI Act prohibited AI practices vs prohibited uses?
Prohibited AI practices under Article 5 are categorical bans on entire categories of AI applications, such as social scoring systems or real-time biometric surveillance in public spaces. These are not conditional - you cannot deploy them regardless of safeguards. In contrast, prohibited uses typically refer to specific applications of otherwise-permissible AI systems that cross into banned territory based on context, like using emotion recognition in workplace settings.
What happens if my AI system starts producing prohibited outputs after deployment?
Monitor for feature drift continuously. A system compliant at launch can drift into prohibited territory through model updates, data changes, or unexpected emergent behavior. If monitoring flags outputs that match prohibited categories, suspend the system immediately and document the detection timeline. The Commission can also expand the prohibited list through delegated acts, which means annual compliance reviews are required even for static systems.
How do I prove my facial recognition system doesn't violate Article 5(1)(e)?
Document that collection is targeted instead of untargeted. If you're scraping internet images or CCTV footage indiscriminately to build or expand a facial database for biometric identification, that's prohibited. Compliant systems gather facial data from specific, consented groups for defined security purposes with legal grounding. Your audit trail should show explicit authorization for each data source and prove no mass harvesting occurred.
When does workplace monitoring cross into prohibited emotion recognition under the EU AI Act?
If your system infers worker emotions - stress, engagement, sentiment - from biometric signals, voice patterns, or behavioral analysis in professional contexts, it's prohibited under Article 5(1)(f). The ban covers both primary emotion classification functions and secondary outputs that feed into performance reviews or management decisions. Productivity metrics based on observable work outputs remain permissible; reading emotional states from those same workers does not.





