Article 5 has no gateway. It does not care whether a system is high-risk, appears in an Annex, or has been classified at all — it attaches to the act of placing on the market, putting into service or using a system in one of the listed ways. That makes it the one part of the Regulation an organisation cannot defer by concluding it operates nothing high-risk — unlike the deployer duties in Article 26, which depend entirely on that classification. The free and open-source exclusion that shelters much of the Act expressly does not reach here either.
The widespread belief that Article 5 is about policing is wrong and expensive. Only the live biometric identification limb and parts of the predictive-policing limb are law-enforcement specific. The prohibition on inferring emotions in the workplace and in education institutions is horizontal and has the widest private-sector reach of anything in the Regulation — it catches sentiment analysis on employee communications, affect detection in interviews, engagement scoring in classrooms — subject only to a narrow exception for medical or safety reasons. Like Article 50, it binds without reference to any Annex — which is why both are missed by programmes that start from a high-risk inventory.
Intent is not the test, and arguing about it wastes the assessment. The manipulation and exploitation prohibitions bite where a practice has the objective or the effect of materially distorting behaviour. What actually filters these provisions is the requirement that the distortion cause or be reasonably likely to cause significant harm — a threshold that reaches accumulated financial and psychological harm, not only acute injury. Establishing that a persuasive design does not cross it is the analysis worth doing.
The prohibitions added by the Digital Omnibus in 2026, covering non-consensual intimate imagery and child sexual abuse material, are considerably narrower than the coverage suggested. A general-purpose image model does not become prohibited merely because it can produce such material: the generation must be the intended purpose, or a reasonably foreseeable and reproducible outcome without significant technical modification and the system must lack adequate safeguards to prevent it and to correct observed misuse. A provider with effective, maintained safeguards sits outside the prohibition on the face of the text — which makes safeguard efficacy the compliance artefact, not a capability disclaimer.