Skip to content
Topic Contested in court

Prohibited AI Practices

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

The content specifically addresses prohibited AI practices under the AI Act, which is a distinct regulatory concept not adequately covered by existing topics. This requires its own topic to capture the specific restrictions, enforcement mechanisms, and compliance requirements.

20 linked items 6 Laws2 Guidance4 News8 Literature

Overview

14 sources · Jul 23, 2026

Legal Framework

Article 5 of the AI Act establishes the catalogue of prohibited AI practices — the most severe tier of the Act's risk-based architecture. These are practices deemed to create unacceptable risk, warranting outright prohibition rather than mitigation. The prohibition covers several distinct categories: AI systems deploying subliminal or manipulative techniques that cause significant harm; systems exploiting vulnerabilities of specific groups based on age, disability, or socio-economic circumstances; untargeted facial image scraping to build identification databases; social scoring by public or private actors that evaluates persons based on behaviour across multiple contexts and leads to detrimental treatment; predictive policing based solely on profiling; biometric categorisation inferring sensitive attributes; and certain real-time remote biometric identification uses in public spaces by law enforcement.

Recital 31 elaborates the rationale for the social scoring prohibition specifically: such systems evaluate natural persons based on multiple data points concerning social behaviour across diverse contexts, producing discriminatory outcomes and exclusion of particular groups. The prohibition targets systems that aggregate behavioural data across unrelated domains to generate scores that then determine access to services, opportunities, or rights. The concern is not merely privacy intrusion but the structural erosion of dignity, equality, and justice.

The accountability principle familiar from Article 5(2) GDPR applies analogously: deployers and providers must implement appropriate and effective measures and be able to demonstrate compliance with each prohibition. Transparency obligations reinforce this — affected individuals must be informed when they interact with AI systems, and the rights of data subjects (access, rectification, objection, and protection against automated decision-making under GDPR Articles 15–22) remain fully applicable alongside the AI Act's specific prohibitions.

Key Developments

Enforcement of the prohibited practices provisions will fall to national market surveillance authorities and the AI Office, with penalties reaching up to EUR 35 million or 7% of global annual turnover — the highest tier under the Act. The February 2026 call by civil society organisations to EU legislators to preserve transparency safeguards signals ongoing political pressure around the boundary between prohibition and permitted use, particularly regarding manipulative systems and the transparency exemptions sought by certain industry actors.

The social scoring prohibition draws implicit interpretive guidance from GDPR enforcement against automated decision-making. The CJEU's reasoning in Schufa (C-634/21), which classified automated credit scoring as a decision producing legal effects, provides a practical threshold: where an AI system's output triggers consequential treatment of an individual based on cross-contextual behavioural data, it falls squarely within the prohibition's scope.

Practical Guidance

  • Map AI use cases against each Article 5 category before deployment. Systems that aggregate behavioural data across unrelated contexts to produce scores or rankings require particular scrutiny, as the social scoring prohibition captures both public and private actors.

  • Assess vulnerability exploitation rigorously. If a system adapts its persuasive or decision-making logic based on identified characteristics of users (age, disability, socio-economic status), document why the technique does not constitute prohibited exploitation rather than assuming exemption.

  • Maintain demonstrable accountability records. Following the Article 5(2) GDPR accountability logic, organisations must not only comply but evidence the effectiveness of their compliance measures — including how they verified that a system does not employ subliminal manipulation.

  • Ensure transparency mechanisms operate alongside prohibition compliance. Individuals must be informed when interacting with AI systems, and GDPR data subject rights (Articles 15–22) must remain exercisable. Where a system approaches a prohibited category, transparency alone is insufficient — the practice must cease.

  • Review biometric system deployments against both the prohibition and the narrower law-enforcement exceptions. Real-time remote biometric identification in public spaces is prohibited except under strictly circumscribed conditions requiring prior judicial or administrative authorisation.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 6
Art. 112(1) The Commission shall assess the need for amendment of the list set out in Annex III and of the list of prohibited AI practices laid down in Article 5,… AI Act Art. 3(42) ‘real-time remote biometric identification system’ means a remote biometric identification system, whereby the capturing of biometric data, the compar… AI Act Art. 3(43) ‘post-remote biometric identification system’ means a remote biometric identification system other than a real-time remote biometric identification sy… AI Act Art. 5(7) The Commission shall publish annual reports on the use of real-time remote biometric identification systems in publicly accessible spaces for law enfo… AI Act art 5 Prohibited AI practices AI Act Jun 2024 rec 31 Recital 31 — prohibition of social scoring AI AI Act Jun 2024 rec 39 Recital 39 — biometric data processing compliance requirements AI Act Jun 2024 rec 34 Recital 34 — responsible use of real-time biometric identification AI Act Jun 2024 rec 38 Recital 38 — real-time biometric identification law enforcement AI Act Jun 2024 rec 179 Recital 179 — regulation phased application dates AI Act Jun 2024
Guidance 2
§2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Cou… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) §27 T he EDPB and the EDPS consider that intrusive forms of AI – especially those who may affect human dignity – are to be seen as prohibited AI system s … EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) 282024 on certain data protection aspects related to Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models EDPB Dec 2024 edps joint opinion 52021 on the proposal for a regulation of the EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) EDPB Jun 2021
News 4
Access Now A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act Access Now Feb 2026 European Digital Rights The AI law is not sufficient: we must address the dangerous loopholes that enable abuse and violate people's rights. European Digital Rights Nov 2025 European Digital Rights The AI Act isn’t enough: closing the dangerous loopholes that enable rights violations European Digital Rights Nov 2025 Gaming Tech Law Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? Gaming Tech Law Mar 2023
Literature 8
Zeszyt Prawniczy UAM Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act Zeszyt Prawniczy UAM Dec 2025 Journal of International Economic Law Compatibility of emerging AI regulation with GATS and TBT: the EU Artificial Intelligence Act Journal of International Economic Law Dec 2024 i-lex Perspectives for Open Source AI i-lex Jul 2026 Ethics & bioethics The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act Ethics & bioethics Jul 2026 SCRIPTed A Journal of Law Technology & Society General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain SCRIPTed A Journal of Law Technology & Society Jun 2026 FR Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026 Studies in Law and Justice The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act Studies in Law and Justice Sep 2023 Journal of Ethics and Emerging Technologies The Magician’s Eye Journal of Ethics and Emerging Technologies Jul 2026