# Prohibited AI Practices — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/prohibited-ai-practices
> Sources are cited per item. Verify against the official texts before relying on them.

The content specifically addresses prohibited AI practices under the AI Act, which is a distinct regulatory concept not adequately covered by existing topics. This requires its own topic to capture the specific restrictions, enforcement mechanisms, and compliance requirements.

## Overview

## Legal Framework

Article 5 of the AI Act establishes the catalogue of prohibited AI practices — the most severe tier of the Act's risk-based architecture. These are practices deemed to create unacceptable risk, warranting outright prohibition rather than mitigation. The prohibition covers several distinct categories: AI systems deploying subliminal or manipulative techniques that cause significant harm; systems exploiting vulnerabilities of specific groups based on age, disability, or socio-economic circumstances; untargeted facial image scraping to build identification databases; social scoring by public or private actors that evaluates persons based on behaviour across multiple contexts and leads to detrimental treatment; predictive policing based solely on profiling; biometric categorisation inferring sensitive attributes; and certain real-time remote biometric identification uses in public spaces by law enforcement.

Recital 31 elaborates the rationale for the social scoring prohibition specifically: such systems evaluate natural persons based on multiple data points concerning social behaviour across diverse contexts, producing discriminatory outcomes and exclusion of particular groups. The prohibition targets systems that aggregate behavioural data across unrelated domains to generate scores that then determine access to services, opportunities, or rights. The concern is not merely privacy intrusion but the structural erosion of dignity, equality, and justice.

The accountability principle familiar from Article 5(2) GDPR applies analogously: deployers and providers must implement appropriate and effective measures and be able to demonstrate compliance with each prohibition. Transparency obligations reinforce this — affected individuals must be informed when they interact with AI systems, and the rights of data subjects (access, rectification, objection, and protection against automated decision-making under GDPR Articles 15–22) remain fully applicable alongside the AI Act's specific prohibitions.

## Key Developments

Enforcement of the prohibited practices provisions will fall to national market surveillance authorities and the AI Office, with penalties reaching up to EUR 35 million or 7% of global annual turnover — the highest tier under the Act. The February 2026 call by civil society organisations to EU legislators to preserve transparency safeguards signals ongoing political pressure around the boundary between prohibition and permitted use, particularly regarding manipulative systems and the transparency exemptions sought by certain industry actors.

The social scoring prohibition draws implicit interpretive guidance from GDPR enforcement against automated decision-making. The CJEU's reasoning in *Schufa* (C-634/21), which classified automated credit scoring as a decision producing legal effects, provides a practical threshold: where an AI system's output triggers consequential treatment of an individual based on cross-contextual behavioural data, it falls squarely within the prohibition's scope.

## Practical Guidance

- **Map AI use cases against each Article 5 category before deployment.** Systems that aggregate behavioural data across unrelated contexts to produce scores or rankings require particular scrutiny, as the social scoring prohibition captures both public and private actors.

- **Assess vulnerability exploitation rigorously.** If a system adapts its persuasive or decision-making logic based on identified characteristics of users (age, disability, socio-economic status), document why the technique does not constitute prohibited exploitation rather than assuming exemption.

- **Maintain demonstrable accountability records.** Following the Article 5(2) GDPR accountability logic, organisations must not only comply but evidence the effectiveness of their compliance measures — including how they verified that a system does not employ subliminal manipulation.

- **Ensure transparency mechanisms operate alongside prohibition compliance.** Individuals must be informed when interacting with AI systems, and GDPR data subject rights (Articles 15–22) must remain exercisable. Where a system approaches a prohibited category, transparency alone is insufficient — the practice must cease.

- **Review biometric system deployments against both the prohibition and the narrower law-enforcement exceptions.** Real-time remote biometric identification in public spaces is prohibited except under strictly circumscribed conditions requiring prior judicial or administrative authorisation.

## Legislation (full text of key provisions)

### Prohibited AI practices

*Source: AI Act, aiact-art-5-en, 2024-06-12 — https://overview.legal/posts/91996*

### Recital 31 — prohibition of social scoring AI

*Source: AI Act, aiact-rec-31-en, 2024-06-12 — https://overview.legal/posts/93744*

AI systems providing social scoring of natural persons by public or private actors may lead to discriminatory outcomes and the exclusion of certain groups. They may violate the right to dignity and non-discrimination and the values of equality and justice. Such AI systems evaluate or classify natural persons or groups thereof on the basis of multiple data points related to their social behaviour in multiple contexts or known, inferred or predicted personal or personality characteristics over certain periods of time. The social score obtained from such AI systems may lead to the detrimental or unfavourable treatment of natural persons or whole groups thereof in social contexts, which are unrelated to the context in which the data was originally generated or collected or to a detrimental treatment that is disproportionate or unjustified to the gravity of their social behaviour. AI systems entailing such unacceptable scoring practices and leading to such detrimental or unfavourable outcomes should therefore be prohibited. That prohibition should not affect lawful evaluation practices of natural persons that are carried out for a specific purpose in accordance with Union and national law.

### Recital 39 — biometric data processing compliance requirements

*Source: AI Act, aiact-rec-39-en, 2024-06-12 — https://overview.legal/posts/93760*

Any processing of biometric data and other personal data involved in the use of AI systems for biometric identification, other than in connection to the use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement as regulated by this Regulation, should continue to comply with all requirements resulting from Article 10 of Directive (EU) 2016/680. For purposes other than law enforcement, Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 prohibit the processing of biometric data subject to limited exceptions as provided in those Articles. In the application of Article 9(1) of Regulation (EU) 2016/679, the use of remote biometric identification for purposes other than law enforcement has already been subject to prohibition decisions by national data protection authorities.

### Recital 34 — responsible use of real-time biometric identification

*Source: AI Act, aiact-rec-34-en, 2024-06-12 — https://overview.legal/posts/93750*

In order to ensure that those systems are used in a responsible and proportionate manner, it is also important to establish that, in each of those exhaustively listed and narrowly defined situations, certain elements should be taken into account, in particular as regards the nature of the situation giving rise to the request and the consequences of the use for the rights and freedoms of all persons concerned and the safeguards and conditions provided for with the use. In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement should be deployed only to confirm the specifically targeted individual’s identity and should be limited to what is strictly necessary concerning the period of time, as well as the geographic and personal scope, having regard in particular to the evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment and, unless provided otherwise in this Regulation, has registered the system in the database as set out in this Regulation. The reference database of persons should be appropriate for each use case in each of the situations mentioned above.

### Recital 38 — real-time biometric identification law enforcement

*Source: AI Act, aiact-rec-38-en, 2024-06-12 — https://overview.legal/posts/93758*

The use of AI systems for real-time remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement necessarily involves the processing of biometric data. The rules of this Regulation that prohibit, subject to certain exceptions, such use, which are based on Article 16 TFEU, should apply as lex specialis in respect of the rules on the processing of biometric data contained in Article 10 of Directive (EU) 2016/680, thus regulating such use and the processing of biometric data involved in an exhaustive manner. Therefore, such use and processing should be possible only in as far as it is compatible with the framework set by this Regulation, without there being scope, outside that framework, for the competent authorities, where they act for purpose of law enforcement, to use such systems and process such data in connection thereto on the grounds listed in Article 10 of Directive (EU) 2016/680. In that context, this Regulation is not intended to provide the legal basis for the processing of personal data under Article 8 of Directive (EU) 2016/680. However, the use of real-time remote biometric identification systems in publicly accessible spaces for purposes other than law enforcement, including by competent authorities, should not be covered by the specific framework regarding such use for the purpose of law enforcement set by this Regulation. Such use for purposes other than law enforcement should therefore not be subject to the requirement of an authorisation under this Regulation and the applicable detailed rules of national law that may give effect to that authorisation.

### Recital 179 — regulation phased application dates

*Source: AI Act, aiact-rec-179-en, 2024-06-12 — https://overview.legal/posts/94040*

This Regulation should apply from 2 August 2026. However, taking into account the unacceptable risk associated with the use of AI in certain ways, the prohibitions as well as the general provisions of this Regulation should already apply from 2 February 2025. While the full effect of those prohibitions follows with the establishment of the governance and enforcement of this Regulation, anticipating the application of the prohibitions is important to take account of unacceptable risks and to have an effect on other procedures, such as in civil law. Moreover, the infrastructure related to the governance and the conformity assessment system should be operational before 2 August 2026, therefore the provisions on notified bodies and governance structure should apply from 2 August 2025. Given the rapid pace of technological advancements and adoption of general-purpose AI models, obligations for providers of general-purpose AI models should apply from 2 August 2025. Codes of practice should be ready by 2 May 2025 in view of enabling providers to demonstrate compliance on time. The AI Office should ensure that classification rules and procedures are up to date in light of technological developments. In addition, Member States should lay down and notify to the Commission the rules on penalties, including administrative fines, and ensure that they are properly and effectively implemented by the date of application of this Regulation. Therefore the provisions on penalties should apply from 2 August 2025.

## Guidance

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

## Recent developments

### A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act

*Source: Access Now, 2026-02-10 — https://overview.legal/posts/52552 — original: https://www.accessnow.org/press-release/a-call-to-eu-legislators-protect-transparency-safeguard-in-ai-act/*

We, the undersigned organisations and individuals, urge you in the strongest possible terms to reject the deletion of the Article 49(2) transparency safeguard for high-risk AI systems that is proposed in the AI Omnibus. This transparency safeguard ensures that providers of AI systems cannot circumvent the core obligations of the AI Act.

### The AI law is not sufficient: we must address the dangerous loopholes that enable abuse and violate people's rights.

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/52095*

While the EU's AI legislation aims to regulate high-risk AI systems, it is undermined by significant exceptions that allow for their uncontrolled application in the context of national security and law enforcement. These exceptions risk, among other things, enabling mass surveillance of protests and discriminatory migration practices. To prevent this, the EDRi partner Danes je nov has published recommendations for Slovenia to implement stricter national safeguards and transparent oversight mechanisms. The post "The AI legislation is not..."

### The AI Act isn&#8217;t enough: closing the dangerous loopholes that enable rights violations

*Source: European Digital Rights, 2025-11-13 — https://overview.legal/posts/49203 — original: https://edri.org/our-work/the-ai-act-isnt-enough-closing-the-dangerous-loopholes-that-enable-rights-violations/*

While the EU's AI Act aims to regulate high-risk AI systems, it is undermined by major loopholes that allow their unchecked use in the context of national security and law enforcement. These exemptions risk enabling, among others, mass surveillance of protests and discriminatory migration practices. To prevent this, EDRi affiliate Danes je nov dan has published recommendations for Slovenia to adopt stricter national safeguards and transparent oversight mechanisms. The post The AI Act isn&#8217;t

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

## Literature

### Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act

*Source: Zeszyt Prawniczy UAM, 2025-12-22 — https://overview.legal/posts/132565 — original: https://doi.org/10.14746/zpuam.2025.15.4*

Celem artykułu jest wskazanie przestępstw, w przypadku których służby państwowe mogą korzystać z systemów zdalnej identyfikacji biometrycznej w czasie rzeczywistym w przestrzeni publicznej. Zostanie to uczynione przez analizę przesłanek umożliwiających posługiwanie się tą technologią oraz przyrównanie ich do czynów zabronionych przez polski kodeks karny. Rezultatem powyższego jest stworzenie katalogu przestępstw, odnośnie do których służby mogą zastosować system zdalnej identyfikacji biometryczn

### Compatibility of emerging AI regulation with GATS and TBT: the EU Artificial Intelligence Act

*Source: Journal of International Economic Law, 2024-12-01 — https://overview.legal/posts/132438 — original: https://doi.org/10.1093/jiel/jgae040*

Abstract Governments have recently started to design policies that are specific to artificial intelligence (AI), which is projected to become the dominant technology in the decades to come. AI is increasingly permeating all aspects of the digital economy, including trade in goods and services, giving rise to concerns whether emerging AI-specific regulation may run afoul of international economic law (IEL). However, studies on the law of the World Trade Organization have yet to pay close attentio

### Perspectives for Open Source AI

*Source: i-lex, 2026-07-07 — https://overview.legal/posts/83512 — original: https://doi.org/10.60923/issn.1825-1927/23382*

The world’s first most comprehensive law regulating artificial intelligence, the EU Artificial Intelligence Act, has been enacted in June 2024 and entered into force in August 2024. The AI Act aims to provide transparency and ensure safe use of AI systems by introducing obligations and requirements for developers and deployers based on the risk posed by AI systems. Despite the long legislation process that launched in 2020 and multiple negotiations, the final version of the Act includes a number

### The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act

*Source: Ethics & bioethics, 2026-07-06 — https://overview.legal/posts/83515 — original: https://doi.org/10.2478/ebce-2026-0014*

Abstract The paper provides a critical analysis of the EU AI Act (Regulation 2024/1689) within the broader context of contemporary AI developments. Starting from an historical overview on the development of advanced AI systems, it moves the focus onto the intrinsic meaning of Artificial Intelligence to highlight how, despite such fascinating wording, there cannot be a shift of responsibility onto the systems themselves—as was proposed, for example, by the European Parliament resolution of 16 Feb

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

## Related topics

- **Unacceptable Risk AI Systems** — https://overview.legal/topics/unacceptable-risk-ai
  The content specifically addresses unacceptable-risk AI systems as a distinct category of prohibited practices, warranting a dedicated topic for this specific c
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Identification** — https://overview.legal/topics/identificatie
  Methods and processes for identifying individuals
- **AI Risk Assessment** — https://overview.legal/topics/ai-risk-assessment
  The AI Act employs a risk-based regulatory approach to determine which practices are prohibited, requiring assessment and classification of AI system risks, whi
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Biometric Data** — https://overview.legal/topics/biometric-data
  Processing of biometric data for identification

---
Generated by overview.legal · https://overview.legal/topics/prohibited-ai-practices · 2026-08-22
