The European Union's AI Act introduces stringent regulations on artificial intelligence, aiming to ensure ethical use and prevent harm. Title II of the Act explicitly bans certain AI practices, with enforcement of these prohibitions starting February 2025. This guide outlines these prohibitions, their scope, and the penalties for non-compliance, providing a roadmap for organizations to align their AI strategies with EU regulations.
The European Union's AI Act introduces stringent regulations on artificial intelligence, aiming to ensure ethical use and prevent harm. Title II of the Act explicitly bans certain AI practices, with enforcement of these prohibitions starting February 2025. This guide outlines these prohibitions, their scope, and the penalties for non-compliance, providing a roadmap for organizations to align their AI strategies with EU regulations.
AI Act Enforcement Timeline
The AI Act sets forth a phased enforcement timeline. The prohibitions on specific AI practices under Title II will come into effect on February 2, 2025. This initial phase targets practices deemed highly detrimental to individuals and society. Subsequently, regulations concerning high-risk AI systems will be enforced starting August 2, 2026. Organizations deploying AI technologies must prepare for these deadlines to ensure compliance and avoid significant penalties.
The 8 Prohibited AI Practices
Under Article 5 of the AI Act, eight categories of AI practices are strictly prohibited. These practices are considered to pose unacceptable risks and are thus banned outright:
- 1Manipulative Techniques: AI systems that deploy subliminal techniques beyond a person's consciousness to materially distort a person's behavior in a manner that causes or is likely to cause physical or psychological harm.
- 1Exploitation of Vulnerabilities: AI systems that exploit vulnerabilities of specific groups due to their age, physical or mental disability, in a way that causes or is likely to cause harm.
- 1Social Scoring by Public Authorities: The use of AI by public authorities or on their behalf for social scoring, where trustworthiness is evaluated based on social behavior or known or predicted personal or personality characteristics, leading to detrimental or unfavorable treatment.
- 1Real-Time Remote Biometric Identification: The use of AI systems for real-time remote biometric identification of individuals in publicly accessible spaces for law enforcement purposes, unless certain narrowly defined exceptions apply.
- 1Emotion Recognition in Certain Contexts: AI systems used for emotion recognition in law enforcement, border management, workplace, and educational settings.
- 1Predictive Policing: AI systems used for predictive policing, which involves predicting the occurrence or reoccurrence of criminal offenses based on profiling and other data.
- 1Biometric Categorization: AI systems that categorize individuals based on biometric data into clusters according to ethnicity, gender, political or sexual orientation, or other grounds for discrimination.
- 1Dark Patterns: AI systems that deploy dark patterns, misleading or coercive designs, to influence users' choices without their full awareness.
Social Scoring by Public Authorities
The prohibition of social scoring by public authorities is a critical aspect of the AI Act. Social scoring involves assessing individuals based on their behavior, characteristics, or predicted attributes, often leading to discriminatory outcomes. The Act prohibits such practices due to their potential to infringe on fundamental rights and freedoms. Exemptions are limited and strictly defined, ensuring that public authorities cannot misuse AI for social control.
Real-Time Remote Biometric Identification in Public Spaces
The use of AI for real-time remote biometric identification in public spaces is heavily restricted. This includes technologies such as facial recognition used by law enforcement. The AI Act allows exceptions only under specific conditions, such as for the prevention of a substantial threat to public security. Such uses must be authorized by judicial or independent administrative bodies, with strict safeguards in place to protect individual rights.
Subliminal Techniques and Exploitation of Vulnerabilities
AI systems that manipulate individuals through subliminal techniques or exploit vulnerabilities are banned due to their potential to cause harm. These practices can lead to significant psychological or physical impacts, particularly on vulnerable groups. Organizations must ensure that their AI systems do not employ such techniques, focusing instead on transparency and user consent.
Emotion Recognition in Workplace and Education
The AI Act prohibits the use of emotion recognition technologies in sensitive contexts such as workplaces and educational institutions. These technologies can infringe on privacy and lead to biased or discriminatory outcomes. Organizations using AI in these settings must review their systems to ensure compliance, prioritizing user privacy and ethical considerations.
Penalties: Up to €35M or 7% Global Turnover
Non-compliance with the AI Act's prohibitions can result in severe penalties. Organizations found in violation may face fines of up to €35 million or 7% of their global annual turnover, whichever is higher. These penalties underscore the importance of adhering to the regulations and implementing robust compliance measures.
What to Audit in Your AI Portfolio Before February 2025
To prepare for the AI Act's enforcement, organizations should conduct a comprehensive audit of their AI portfolios. Key areas to assess include:
- Compliance with Prohibitions: Ensure that none of the banned practices are present in your AI systems.
- Risk Assessment: Evaluate AI systems for potential risks and implement mitigation strategies.
- Transparency and Accountability: Establish clear documentation and processes to demonstrate compliance.
- User Consent and Privacy: Review data handling practices to ensure user consent and privacy are prioritized.
By addressing these areas, organizations can align their AI practices with the AI Act, minimizing the risk of penalties and fostering ethical AI use.
Next Step with NexCyber
Ensure your organization is ready for the AI Act's prohibitions by conducting a thorough compliance assessment. Visit [NexCyber](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=ai-act-prohibited-practices-enforcement-guide) to learn more about our AI compliance solutions and how we can help you navigate the regulatory landscape.