Skip to content
AIAC AI ASSURANCE COUNCIL

EU AI Act

Article 5 — Prohibited AI practices

Article 5 lists the uses of AI the Union will not permit at all: manipulation causing significant harm, exploitation of vulnerability, social scoring, untargeted facial scraping, emotion inference at work and in schools, and certain biometric categorisation and live identification. It carries the highest penalties in the Regulation and has applied since February 2025.

§ 1 — Who it binds

Who it binds: every operator, not only providers

ProviderDeployerImporter

Any AI system, at any risk tier, whose placing on the market, putting into service or use amounts to a listed practice. Note the verbs: a distributor that merely makes a system available is not caught unless it also puts it into service, uses it, or becomes a provider. Excluded are systems used exclusively for military, defence or national security purposes, sole-purpose scientific research, and pre-market development — though real-world testing is expressly not covered.

§ 2 — In practice

The eight prohibitions, and where each line actually sits

Article 5 has no gateway. It does not care whether a system is high-risk, appears in an Annex, or has been classified at all — it attaches to the act of placing on the market, putting into service or using a system in one of the listed ways. That makes it the one part of the Regulation an organisation cannot defer by concluding it operates nothing high-risk — unlike the deployer duties in Article 26, which depend entirely on that classification. The free and open-source exclusion that shelters much of the Act expressly does not reach here either.

The widespread belief that Article 5 is about policing is wrong and expensive. Only the live biometric identification limb and parts of the predictive-policing limb are law-enforcement specific. The prohibition on inferring emotions in the workplace and in education institutions is horizontal and has the widest private-sector reach of anything in the Regulation — it catches sentiment analysis on employee communications, affect detection in interviews, engagement scoring in classrooms — subject only to a narrow exception for medical or safety reasons. Like Article 50, it binds without reference to any Annex — which is why both are missed by programmes that start from a high-risk inventory.

Intent is not the test, and arguing about it wastes the assessment. The manipulation and exploitation prohibitions bite where a practice has the objective or the effect of materially distorting behaviour. What actually filters these provisions is the requirement that the distortion cause or be reasonably likely to cause significant harm — a threshold that reaches accumulated financial and psychological harm, not only acute injury. Establishing that a persuasive design does not cross it is the analysis worth doing.

The prohibitions added by the Digital Omnibus in 2026, covering non-consensual intimate imagery and child sexual abuse material, are considerably narrower than the coverage suggested. A general-purpose image model does not become prohibited merely because it can produce such material: the generation must be the intended purpose, or a reasonably foreseeable and reproducible outcome without significant technical modification and the system must lack adequate safeguards to prevent it and to correct observed misuse. A provider with effective, maintained safeguards sits outside the prohibition on the face of the text — which makes safeguard efficacy the compliance artefact, not a capability disclaimer.

§ 3 — What a weak answer looks like

Why “we do not do social scoring” is not an answer

Treating Article 5 as somebody else’s problem because nothing in the estate is high-risk. The prohibitions are the one part of the Regulation that never required a classification exercise, and the organisations most exposed are the ones that concluded early they were out of scope. Emotion analytics in a contact centre, engagement scoring in a training platform, a vendor feature enabled by default — none of these arrive announced as prohibited AI, and none of them is caught by a programme that starts with an Annex III inventory.

§ 4 — What discharges it

How you evidence that a system is not prohibited

The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.

  1. 01

    A recorded assessment against each listed practice

    Because there is no classification gateway, the only way to show Article 5 was considered is to have considered it. A short reasoned conclusion per limb, dated, is the artefact — and the emotion-inference and social-scoring limbs are the two that need real analysis rather than a dismissal.

  2. 02

    The intended purpose, stated tightly enough to bound use

    Several prohibitions attach to putting a system into service *for a specific purpose*. A loosely stated purpose widens exposure; a precise one, enforced by configuration rather than policy, narrows it.

  3. 03

    For generative systems, safeguard efficacy and misuse response

    The qualifying provisions turn on whether adequate technical safeguards prevent the prohibited generation and correct observed or reported misuse. Evidence is red-team results against those specific categories and a record of reports acted on.

  4. 04

    Configuration evidence where an exception is relied on

    Emotion inference for medical or safety reasons, biometric categorisation confined to lawful dataset filtering. The exception has to be visible in how the system is deployed, not only in the justification written for it.

§ 5 — When it applies

Applying since 2 February 2025

  1. 2 February 2025

    Article 5 as originally enacted, together with the AI literacy duty. The prohibitions have been in force since then — though the Union penalty architecture in Chapter XII only followed on 2 August 2025.

  2. 2 December 2026

    The prohibitions on non-consensual intimate imagery and child sexual abuse material inserted by the Digital Omnibus, with the qualifying provisions that narrow them. New prohibitions were given lead time; nothing that already existed moved.

§ 6 — Exposure

The 7% ceiling — the highest exposure in the Act

€35 million or 7% of worldwide annual turnover, whichever is higher

Article 99(3), the only paragraph reaching 7% and reaching nothing but Article 5 — Article 99(4) expressly excludes the practices laid down in Article 5 from its lower ceiling. Under Article 99(6) an SME pays the lower of the two figures. Note that the small mid-cap concession inserted by the Digital Omnibus in Article 99(6a) covers paragraphs 4 and 5 only, so an SMC gets no relief here.

§ 7 — Worked example

Worked example — conversation analytics in a contact centre

A contact-centre operator buys a platform that scores live calls for customer frustration and agent empathy. Supervisors see the agent scores on a dashboard; the scores feed coaching, and over time they inform performance ratings. The vendor markets it as conversation analytics and states that it does not process biometric data.

Is a conversation-analytics product a prohibited practice under Article 5?

It is squarely in the area the prohibition covers, and the vendor’s framing does not settle it. Article 5 prohibits inferring emotions of a natural person in the workplace, and a score for "frustration" or "empathy" attached to a named agent is an emotion inference about an employee whatever the product is called. Two arguments are worth running and neither is comfortable. First, whether the system infers emotions at all or merely classifies conversational features — a real distinction that turns on what the model outputs and how it is labelled, not on marketing copy. Second, the medical-or-safety exception, which will not carry coaching or performance use. The customer-side scoring is on different ground, since the prohibition is framed around the workplace and education. The practical answer is that the agent-facing scores are the exposure, the exception does not reach them, and this is a €35 million or 7% provision that has been in force since February 2025.

§ 8 — Elsewhere

The same requirement elsewhere

Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.

  • GDPR and data-protection law

    The biometric categorisation and live identification prohibitions sit on top of GDPR Article 9, and the Act says the identification limb is without prejudice to it. A practice outside Article 5 can still be unlawful processing.

A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.

§ 9 — Where this is assessed

Where this is assessed

Examined in 2 credentials, in the domains named on each card.

AIAC-EUCFCompliance

Certified AI Compliance Fundamentals — EU AI Act

Scope, definitions, and risk tiers · 20% of the paper

The EU AI Act as enacted: the risk-tier structure, the roles the Act defines, the obligations attaching to each, and the timeline on which they apply.

Compliance
AIAC-RECFAssurance

Certified AI Recruitment Bias — Fundamentals

US recruitment-bias law across states · 25% of the paper

US recruitment-bias law and the employer’s compliance programme: automated employment decision tools under NYC Local Law 144 and the state statutes, adverse impact and the four-fifths rule, and engaging the independent bias audit the law requires.

Employment & hiring

§ 10 — provenance

The provision itself

This page sets out what the instrument requires and what discharges it. The official text is the authority — these go straight to it.