Prohibited AI Practices
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The content specifically addresses prohibited AI practices under the AI Act, which is a distinct regulatory concept not adequately covered by existing topics. This requires its own topic to capture the specific restrictions, enforcement mechanisms, and compliance requirements.
Overview
14 sources · Aug 27, 2026Legal Framework
The primary provision governing prohibited AI practices is Article 5 of the AI Act, which establishes a categorical ban on specified AI systems. Unlike the risk-based gradation that characterises the rest of the Regulation, Article 5 draws a hard line: the listed practices may not be placed on the market, put into service, or used at all.
The prohibition targets four broad categories of conduct. First, Article 5(1)(a) bans AI systems deploying subliminal or purposefully manipulative and deceptive techniques that materially distort behaviour. Second, Article 5(1)(b) addresses exploitation of vulnerabilities due to age, disability, or social or economic situation. Third, social scoring systems that evaluate or classify persons over time based on social behaviour or personality traits are prohibited under Article 5(1)(c). Fourth, Article 5(1)(d) bans criminal risk assessment based solely on profiling or personality assessment.
Key definitions in Article 3 — "AI system," "provider," and "deployer" — determine who is subject to these prohibitions. The list of prohibited practices is not static: Article 112 requires annual Commission review.
"The Commission shall assess the need for amendment of the list set out in Annex III and of the list of prohibited AI practices laid down in Article 5, once a year"
— AI Act Art. 112(1)
Key Developments
The EDPB-EDPS Joint Opinion 5/2021 pressed for a broader prohibition scope, arguing that intrusive AI affecting human dignity should fall under Article 5 rather than merely being classified as high-risk. The opinion specifically referenced large-scale data comparisons affecting persons with minimal cause for police observation.
EDPB Opinion 28/2024 confirmed that Article 5(1) and (2) prohibitions on manipulative practices and subliminal techniques operate as absolute data-protection floors, reinforcing that necessity assessments under GDPR cannot justify what the AI Act expressly bans.
Status of the Debate
This topic is contested. The boundaries of Article 5 are actively fought over in three dimensions: the threshold for "materially distorting" behaviour, the scope of "vulnerability" exploitation, and the carve-outs for law enforcement under Article 5(1)(d). No court has yet ruled on these provisions, as the AI Act's application dates are still prospective. The doctrinal debate centres on whether the prohibitions are self-executing or require further implementing acts, and how they interact with GDPR lawful bases. Resolution will likely come from the first wave of national supervisory authority enforcement decisions and subsequent CJ Court rulings on whether specific AI systems cross the prohibition threshold.
Practical Guidance
Map your AI systems against all four Article 5 categories before deployment. Any system that could be characterised as manipulative, vulnerability-exploiting, social-scoring, or criminal-risk-profiling must be flagged immediately.
Document the design rationale showing absence of manipulative intent. Article 5(1)(a) prohibits systems with the objective or effect of materially distorting behaviour — demonstrating that neither element is present requires proactive design documentation.
Treat the law enforcement carve-out narrowly. Article 5(1)(d)'s prohibition on criminal risk assessment applies "solely" on profiling — systems that incorporate additional, non-profiling factors may fall outside the prohibition, but the boundary is untested.
Monitor the annual Article 112 review cycle. The Commission's annual assessment may expand the prohibited list, meaning compliance is not a one-time assessment but an ongoing obligation.
Align Article 5 compliance with GDPR necessity assessments. EDPB Opinion 28/2024 confirms that a practice prohibited under Article 5 cannot be rescued by a GDPR lawful basis — the two frameworks operate as cumulative, not alternative, constraints.
Nothing of this type on this topic.