Most of the debate about the EU AI Act focuses on high-risk systems and paperwork. But the Act also draws a hard line: a short list of AI practices are banned outright, whatever safeguards you put around them. These prohibitions have applied since February 2025 and carry the Act’s heaviest fines. Every business using or buying AI should know what is on the list. This guide explains the Article 5 prohibited practices in plain terms.
Why some AI is banned outright
The AI Act takes a risk-based approach. Most systems are low risk and lightly regulated; a defined set are high risk and heavily regulated; and a small category are considered an unacceptable risk to safety, livelihoods and fundamental rights. Those in the last group are simply prohibited. Unlike high-risk systems, there is no compliance route that makes a prohibited practice lawful — the answer is not to do it.
What Article 5 prohibits
The banned practices include AI that uses subliminal or purposefully manipulative techniques to materially distort behaviour and cause harm, and AI that exploits the vulnerabilities of a person or group due to age, disability or social or economic situation. Also prohibited are social scoring that leads to unjustified detrimental treatment, and, in most cases, untargeted scraping of facial images from the internet or CCTV to build recognition databases.
The workplace and biometric bans
Two prohibitions are especially relevant to ordinary businesses. Using AI to infer emotions in the workplace or in education is banned, except for narrow medical or safety reasons. And biometric categorisation systems that infer sensitive attributes such as race, political opinions or sexual orientation are prohibited. Certain law-enforcement uses of real-time remote biometric identification in public spaces are also banned, subject to narrow exceptions.
Practical example: monitoring staff sentiment
Suppose a company considers a tool that analyses employees’ facial expressions and tone on video calls to score their engagement or mood. That is emotion recognition in the workplace and falls squarely within the prohibition. No consent form or policy makes it lawful. The safe course is to abandon the idea and, if the underlying goal is legitimate, to pursue it through means that do not rely on inferring emotions.
Vanliga misstag som företag gör
The most common error is assuming these bans only concern governments or big tech. Ordinary HR, marketing and security tools can stray into prohibited territory, particularly around emotion recognition and manipulative design. Others include relying on a vendor’s assurances without checking, and confusing prohibited practices with high-risk ones — the former cannot be fixed with documentation, they must simply not be used.
Rekommenderade åtgärder
Inventory the AI tools your business uses or is considering, and screen each against the Article 5 list, paying attention to anything touching emotions, biometrics, vulnerable groups or behavioural manipulation. Put a simple check into your procurement process so new tools are screened before purchase. Where a tool is borderline, take advice before deploying it, because the penalties for getting this wrong are the Act’s most severe.
Vanliga frågor
When did the AI Act’s prohibitions start applying?
The Article 5 prohibitions have applied since 2 February 2025, ahead of most of the Act’s other obligations. They are among the first parts of the AI Act to bite.
What are the penalties for a prohibited practice?
Breaching the prohibitions carries the Act’s highest fines, up to 35 million euro or 7 per cent of total worldwide annual turnover, whichever is higher. This is a strong reason to screen tools early.
Does this apply to my business if we only use AI tools we bought?
Yes. Deployers, not just developers, can fall foul of the prohibitions. If you use a prohibited system, you are exposed even if someone else built it, so screening what you buy matters.
Slutsats
The prohibited practices are the AI Act’s brightest line: a handful of uses that are simply off-limits, backed by its toughest penalties. Screening your tools against Article 5 is quick, and it prevents the most serious compliance failures. Lawgent helps businesses map their AI use, screen tools against the prohibitions and build AI Act checks into procurement. Contact us for an AI Act readiness review.