Back to Knowledge Base
Knowledge Base · fundamentals

AI Act Article 5: prohibited AI practices in force since February 2025

7 June 2026 5 min read AI Act

AI Act Article 5 prohibited AI practices have been in force since 2 February 2025. Learn the 8 banned use cases, the penalties, and what counts as a prohibited system.

The short answer

The EU AI Act's prohibited AI practices under Article 5 became enforceable on 2 February 2025 — the first part of the AI Act to apply. Eight categories of AI systems are banned outright in the EU. Deploying, placing on the market, or putting into service any of these systems carries penalties of up to €35 million or 7% of global annual turnover.

1. Subliminal, manipulative, or deceptive techniques

Banned: AI systems that deploy subliminal techniques beyond a person's consciousness, or that exploit psychological weaknesses, biases, or vulnerabilities to materially distort behaviour in a way that causes or is reasonably likely to cause significant harm.

What this covers: AI-powered dark patterns designed to manipulate purchasing decisions; systems that exploit cognitive biases to override rational decision-making; techniques operating below conscious awareness.

What it does not cover: Standard personalisation, recommendation systems, or persuasion that is transparent and not exploitative.

2. Exploitation of vulnerabilities of specific groups

Banned: AI systems that exploit vulnerabilities of specific groups (children, elderly, persons with disabilities) due to their age, disability, or social/economic situation, to materially distort behaviour causing or likely to cause significant harm.

What this covers: AI targeting children with manipulative content; systems exploiting cognitive decline in elderly users; AI that targets financially vulnerable individuals with predatory financial products.

3. Social scoring by public authorities

Banned: AI systems used by or on behalf of public authorities to evaluate or classify individuals over time based on their social behaviour or personal characteristics, leading to detrimental or unfavourable treatment unrelated to the context in which the data was generated, or that is unjustified or disproportionate to the conduct.

What this covers: Government-operated social credit systems; systems that aggregate citizens' behaviour across unrelated contexts to affect their access to public services or benefits.

Note: This prohibition is specific to public authorities. Private-sector loyalty and credit scoring systems are not automatically prohibited under this provision (though they may be subject to other AI Act requirements).

4. Real-time remote biometric identification in public spaces (law enforcement)

Banned: The use of real-time remote biometric identification (RBI) systems in publicly accessible spaces for law enforcement purposes.

Exceptions (narrow): Real-time RBI is permitted only in specific, strictly defined circumstances:

Exceptions require prior judicial or independent administrative authorisation (or post-hoc for urgent cases) and are subject to Member State law enabling the use.

What this covers for most organisations: Any commercial real-time facial recognition deployed in shopping centres, transport hubs, or public events for identification purposes is prohibited.

  • Targeted search for victims of specific serious crimes (abduction, trafficking, sexual exploitation)
  • Prevention of specific, substantial, imminent threat (terrorist attack, serious criminal offence)
  • Identification and prosecution of perpetrators of specific serious crimes (terrorism, trafficking, murder, robbery, drug trafficking, environmental crimes, certain cybercrimes, crimes against persons)

5. Emotion recognition in workplaces and educational institutions

Banned: AI systems that infer emotions of natural persons in the areas of workplaces and educational institutions, except for medical or safety reasons.

What this covers: Employee monitoring systems that detect frustration, engagement, or stress via facial analysis or voice; student attention-tracking systems in classrooms; AI HR tools that analyse emotional state during interviews.

Exceptions: Systems used for medical monitoring (e.g. detecting drowsiness for safety-critical operators) or specific safety applications.

6. Biometric categorisation using sensitive characteristics

Banned: AI systems that categorise individuals based on biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.

What this covers: Systems that infer political affiliation from facial features; AI that categorises job applicants by perceived ethnicity; tools that infer religious belief from appearance.

Note: Biometric categorisation for permitted purposes (e.g. age verification, accessibility features) is not covered by this prohibition.

7. Untargeted scraping of facial images for recognition databases

Banned: AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage.

What this covers: Tools like Clearview AI's original data collection model; automated systems that harvest public social media images to build facial recognition training datasets without individual consent.

8. Post-remote biometric identification (law enforcement — historical data)

Banned: AI systems used by or on behalf of law enforcement for post-remote biometric identification in publicly accessible spaces, except where judicial authorisation is obtained for specific investigations.

What this covers: Retrospective mass matching of CCTV footage against databases for general surveillance purposes without judicial oversight.

What "placing on the market" means for providers

A provider (developer or manufacturer) who places a prohibited AI system on the EU market violates Article 5 regardless of:

Both the provider (making it available) and the deployer (putting it into service) may be liable.

  • Where the provider is based (extraterritorial application)
  • Whether the system is sold, licensed, or provided free of charge
  • Whether the deployer (customer) is the one actually operating the prohibited function

Penalties

Article 5 violations carry the highest AI Act penalties:

Up to €35 million or 7% of global annual turnover (whichever is higher)

This is the maximum in EU digital regulation — higher than GDPR (€20M/4%), CRA (€15M/2.5%), and NIS2 (€10M/2%).

For SMEs and start-ups, penalties must be proportionate to size and economic viability.

Key enforcement date

| Date | Event |

|---|---|

| 2 February 2025 | Article 5 prohibited practices — in force now |

| 2 August 2025 | GPAI model obligations (Art. 51–56) |

| 2 August 2026 | High-risk AI (Annex III) + notified body obligations |

| 2 August 2027 | High-risk AI embedded in regulated products (Annex I) |

If your product or service involves any of the 8 prohibited categories listed above, immediate review is required — this is not a 2027 problem.

What to do if you are uncertain

→ AI Act Risk Classifier — classify your AI system in 5 minutes

  • Map your AI system's function — what decisions does it make, what data does it process, what outputs does it produce?
  • Check against the 8 categories — does any function fall within a prohibited practice?
  • Check for exceptions — narrow exceptions exist for law enforcement (categories 4, 8) and medical/safety (category 5); they require specific legal basis and authorisation
  • Document your assessment — a written analysis that the system does not fall within Article 5 is prudent evidence for regulatory inquiries

Related

This page provides regulatory guidance for informational purposes. It is not legal advice. Article 5 interpretations are subject to national supervisory authority guidance and European AI Office decisions. For compliance decisions, consult a qualified legal adviser.

NexCyber — EU Market Access Compliance Platform

  • AI Act × CRA overlap — dual compliance for AI products
  • AI Act risk classification overview
  • CRA Article 14 — vulnerability reporting for AI products

This is an educational explainer. For the canonical regulation reference, see the dedicated AI Act page — or run an assessment to see how it applies to your product.