Prohibited AI Practices
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The content specifically addresses prohibited AI practices under the AI Act, which is a distinct regulatory concept not adequately covered by existing topics. This requires its own topic to capture the specific restrictions, enforcement mechanisms, and compliance requirements.
Overview
14 sources · Jul 23, 2026Legal Framework
Article 5 of the AI Act establishes the catalogue of prohibited AI practices — the most severe tier of the Act's risk-based architecture. These are practices deemed to create unacceptable risk, warranting outright prohibition rather than mitigation. The prohibition covers several distinct categories: AI systems deploying subliminal or manipulative techniques that cause significant harm; systems exploiting vulnerabilities of specific groups based on age, disability, or socio-economic circumstances; untargeted facial image scraping to build identification databases; social scoring by public or private actors that evaluates persons based on behaviour across multiple contexts and leads to detrimental treatment; predictive policing based solely on profiling; biometric categorisation inferring sensitive attributes; and certain real-time remote biometric identification uses in public spaces by law enforcement.
Recital 31 elaborates the rationale for the social scoring prohibition specifically: such systems evaluate natural persons based on multiple data points concerning social behaviour across diverse contexts, producing discriminatory outcomes and exclusion of particular groups. The prohibition targets systems that aggregate behavioural data across unrelated domains to generate scores that then determine access to services, opportunities, or rights. The concern is not merely privacy intrusion but the structural erosion of dignity, equality, and justice.
The accountability principle familiar from Article 5(2) GDPR applies analogously: deployers and providers must implement appropriate and effective measures and be able to demonstrate compliance with each prohibition. Transparency obligations reinforce this — affected individuals must be informed when they interact with AI systems, and the rights of data subjects (access, rectification, objection, and protection against automated decision-making under GDPR Articles 15–22) remain fully applicable alongside the AI Act's specific prohibitions.
Key Developments
Enforcement of the prohibited practices provisions will fall to national market surveillance authorities and the AI Office, with penalties reaching up to EUR 35 million or 7% of global annual turnover — the highest tier under the Act. The February 2026 call by civil society organisations to EU legislators to preserve transparency safeguards signals ongoing political pressure around the boundary between prohibition and permitted use, particularly regarding manipulative systems and the transparency exemptions sought by certain industry actors.
The social scoring prohibition draws implicit interpretive guidance from GDPR enforcement against automated decision-making. The CJEU's reasoning in Schufa (C-634/21), which classified automated credit scoring as a decision producing legal effects, provides a practical threshold: where an AI system's output triggers consequential treatment of an individual based on cross-contextual behavioural data, it falls squarely within the prohibition's scope.
Practical Guidance
Map AI use cases against each Article 5 category before deployment. Systems that aggregate behavioural data across unrelated contexts to produce scores or rankings require particular scrutiny, as the social scoring prohibition captures both public and private actors.
Assess vulnerability exploitation rigorously. If a system adapts its persuasive or decision-making logic based on identified characteristics of users (age, disability, socio-economic status), document why the technique does not constitute prohibited exploitation rather than assuming exemption.
Maintain demonstrable accountability records. Following the Article 5(2) GDPR accountability logic, organisations must not only comply but evidence the effectiveness of their compliance measures — including how they verified that a system does not employ subliminal manipulation.
Ensure transparency mechanisms operate alongside prohibition compliance. Individuals must be informed when interacting with AI systems, and GDPR data subject rights (Articles 15–22) must remain exercisable. Where a system approaches a prohibited category, transparency alone is insufficient — the practice must cease.
Review biometric system deployments against both the prohibition and the narrower law-enforcement exceptions. Real-time remote biometric identification in public spaces is prohibited except under strictly circumscribed conditions requiring prior judicial or administrative authorisation.