ISHIGHRISK AI
Analysis

What does Article 5 of the AI Act prohibit?

Article 5 has banned eight AI practices since 2 February 2025 and two more from 2 December 2026, and no conformity assessment makes any of them lawful.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Article 5 now carries nine prohibited practices. The original eight, points (a) to (h), have been enforceable since 2 February 2025 under Article 113, third paragraph, point (a), almost three years before Annex III high-risk obligations bite on 2 December 2027. The ninth, on AI that generates child sexual abuse material or non-consensual intimate imagery, was added by Regulation (EU) 2026/1744 and applies from 2 December 2026. Unlike the high-risk tier, Chapter II offers no conformity assessment, CE marking or registration route, so there is nothing to build that makes a prohibited practice lawful. Article 99(3) sets the top penalty ceiling, up to 35,000,000 euro or 7 percent of total worldwide annual turnover, whichever is higher.

Why Article 5 comes before the high-risk question

Most AI Act programmes open at Article 6 and ask whether the system is high-risk. That is the second question. The first is whether the practice is prohibited outright, and it is the cheaper one to answer, because Article 5 is the only tier where the answer cannot be bought with paperwork.

Chapter II contains no conformity assessment, no CE marking, no registration and no documentation route. Nothing in it converts a prohibited practice into a permitted one. Three unrelated provisions confirm it.

  • Article 2(12). The free and open-source licence exclusion does not reach systems placed on the market or put into service as high-risk, or as an AI system falling under Article 5 or 50, as the open-source exemption article works through.
  • Article 60(1). Real-world testing of high-risk systems outside a sandbox is permitted only without prejudice to the prohibitions under Article 5. You cannot pilot your way into a prohibited practice.
  • Article 111(2), as replaced by Regulation (EU) 2026/1744. High-risk systems already on the market come into scope only if they are subject to significant changes in their designs, but the paragraph opens "Without prejudice to the application of Article 5". The legacy relief never reached the prohibitions.

The timing points the same way. Article 113, third paragraph, point (a) applied Chapters I and II from 2 February 2025, so the original eight prohibitions have been live for eighteen months, while Annex III high-risk obligations start on 2 December 2027, as the timeline guide sets out.

2 Feb 2025 The original eight prohibitions, Article 5(1) points (a) to (h), apply under Article 113, third paragraph, point (a).
2 Dec 2026 The ninth prohibition applies, on AI generating child sexual abuse material or non-consensual intimate imagery, under the same provision as amended by Regulation (EU) 2026/1744.

Two limits before the list. Article 5 is not universal, because the Article 2 exclusions cover the whole regulation: exclusive military, defence or national security use (2(3)); development for the sole purpose of scientific research (2(6)); pre-market research, testing and development other than real-world testing (2(8)); and natural persons deploying AI in a purely personal, non-professional activity (2(10)), which matters for the use limb of the new prohibition.

Nor does Article 5 bind identically everywhere. Recitals 40 and 41 record that Ireland, under Protocol No 21, and Denmark, under Protocol No 22, are not bound by point (h), Article 5(2) to (6) and Article 26(10), nor by point (d) so far as it applies to use, nor by point (g) so far as it applies to police and judicial cooperation in criminal matters.

The nine prohibitions, point by point

Eight points, (a) to (h), have stood in the text since 2024, and the Digital Omnibus adds a ninth from 2 December 2026. Three acts can be caught, placing on the market, putting into service and use. Points (d) to (g) catch putting into service only for that specific purpose, and point (h) catches use alone, which is why a provider and a deployer can have very different exposure.

Point Practice Acts caught Distortion and harm threshold Law enforcement only
(a) Subliminal, purposefully manipulative or deceptive techniques All three Distortion, impaired informed decision, significant harm No
(b) Exploiting age, disability or a specific social or economic situation All three Distortion and significant harm, no informed-decision limb No
(c) Social scoring from behaviour or personal characteristics over time All three No significant-harm test, but detrimental treatment out of context, or unjustified or disproportionate No
(d) Predicting criminal offending based solely on profiling or personality traits All three, service for that purpose only None Not on its face
(e) Facial recognition databases built by untargeted scraping of the internet or CCTV All three, service for that purpose only None No
(f) Inferring emotions in the workplace and in education institutions All three, service for that purpose only None No
(g) Biometric categorisation inferring race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation All three, service for that purpose only None No
(h) Real-time remote biometric identification in publicly accessible spaces Use only None Yes
New, from 2 Dec 2026 Generating child sexual abuse material, or intimate or sexually explicit material of an identifiable person without consent All three None No

Only (a) and (b) carry a significant-harm threshold, and they are not the same test. Point (a) has four cumulative limbs: the technique, material distortion of behaviour, appreciable impairment of the ability to make an informed decision such that a decision is taken that would not otherwise have been taken, and significant harm. It reads "with the objective, or the effect of", so a design nobody intended to be manipulative is caught if it manipulates. Art 5(1)(a) Point (b) drops the informed-decision limb, so a pattern aimed at a group in a specific economic situation can fail (b) while surviving (a). Art 5(1)(b) Every other point turns on the practice alone, with no harm to prove.

That threshold is what keeps ordinary commerce off the list. Recital 29 records that common and legitimate commercial practices, advertising among them, which comply with applicable law are not in themselves harmful manipulative AI-enabled practices. A persuasive interface is not a prohibited one.

The carve-outs that decide most real cases

Three points, (d), (f) and (g), carry an exception written into the prohibition itself. Point (h) carries a different structure, three conditional openings and six paragraphs of machinery, and the next section takes it on its own. None of the three is a general reasonableness defence, and they are not interchangeable.

Point The exception, as written What it does not cover
(d) Support for the human assessment of a person's involvement in criminal activity already based on objective and verifiable facts directly linked to a criminal activity Anything where profiling or personality assessment is the sole basis. Recital 42 confirms the point does not reach risk analytics that do not profile individuals
(f) Where use is intended to be put in place or into the market for medical or safety reasons, with recital 44 pointing at therapeutical use Attention monitoring or sentiment scoring on staff or students dressed as wellbeing. It turns on intended purpose, not the dashboard label
(g) Labelling or filtering of lawfully acquired biometric datasets, or categorising biometric data in the area of law enforcement. Recital 30 gives sorting images by hair or eye colour Inference of the sensitive attributes themselves. There is no medical or safety exception in (g), and importing one from (f) is the commonest error here

The word doing the work in point (d) is "solely", and the gate it opens describes a decision process rather than a product feature, so the evidence for it lives in the deployer's procedure, not the vendor's datasheet. Art 5(1)(d)

Point (c) has no written exception, and it is the one most often misread as reaching ordinary scoring. Recital 31 supplies the line: the prohibition should not affect lawful evaluation practices carried out for a specific purpose in accordance with Union and national law. The regulation then routes creditworthiness evaluation and credit scoring into Annex III point 5(b) as high-risk rather than prohibited, with fraud detection carved out of even that, as the credit scoring guide works through. What crosses into (c) is the general score that follows a person out of the context the data came from, or that produces treatment disproportionate to the behaviour it rests on.

Clearing Article 5 clears Article 5 and nothing else: Article 5(8) provides that the Article does not affect the prohibitions applying where an AI practice infringes other Union law. Art 5(8) A practice that survives Chapter II can still fail the GDPR, the Digital Services Act or consumer law, and the AI Act and GDPR article covers the overlap that catches most teams first.

Real-time biometric identification is a conditional ban

Article 5(1)(h) is a prohibition with three narrow openings, buried under six paragraphs of machinery in Article 5(2) to (7). Reading the openings without the machinery is how it gets mistaken for a licence.

The objectives are a targeted search for specific victims of abduction, trafficking or sexual exploitation and for missing persons; prevention of a specific, substantial and imminent threat to life or physical safety, or a genuine and present or genuine and foreseeable threat of a terrorist attack; and localisation or identification of a person suspected of an Annex II offence punishable in that member state by a custodial sentence or detention order of a maximum of at least four years. Art 5(1)(h)

None of that operates by itself. Article 5(5) makes the regime opt-in: a member state "may decide to provide for the possibility" to authorise such use, must lay down detailed national rules on requests, issuance, exercise, supervision and reporting, must specify which objectives and Annex II offences it covers, and must notify those rules to the Commission within 30 days of adoption. It may legislate more restrictively, and where it has not legislated the practice is simply prohibited. Where it has, three layers apply.

  1. Prior authorisation, per use. Article 5(3) requires authorisation from a judicial authority or an independent administrative authority whose decision is binding, in the member state of use, on reasoned request. In duly justified urgency use may start without it, provided authorisation is requested at the latest within 24 hours; if it is refused, use stops with immediate effect and all data, results and outputs must be discarded and deleted. No decision producing an adverse legal effect may be taken based solely on the output.
  2. Substantive limits. Article 5(2) confines the system to confirming the identity of the specifically targeted individual, and requires account to be taken of the seriousness, probability and scale of the harm if it were not used, and of the consequences for the rights of all persons concerned, within the temporal, geographic and personal limits set by national law. It also conditions use on a fundamental rights impact assessment under Article 27 and registration in the EU database under Article 49.
  3. Notification and reporting. Article 5(4) requires each use to be notified to the market surveillance authority and the national data protection authority, excluding sensitive operational data. Article 5(6) then requires those authorities to send the Commission annual reports on a template the Commission provides, and Article 5(7) requires the Commission to publish an aggregated annual report of its own, again without sensitive operational data.

One timing question the text leaves open. Article 5(2) has applied since 2 February 2025 and conditions real-time identification on a fundamental rights impact assessment as provided for in Article 27, which sits in Chapter III, Section 3, and arrives with the rest of the standalone Annex III regime on 2 December 2027. Neither regulation reconciles the two dates, so how the Article 5(2) condition operates in the meantime is not something either instrument answers.

What the Digital Omnibus added: intimate imagery and CSAM

Regulation (EU) 2026/1744 of 8 July 2026, at OJ L, 2026/1744, 24.7.2026 and in force since 27 July 2026, made the first substantive addition to the list: one new entry, applying from 2 December 2026. The eight existing points were untouched, and so were Article 5(2) to 5(8) and the Article 99 tiers. The Digital Omnibus guide covers the rest.

The new prohibition covers two subjects at once. The first is an AI system that generates or manipulates images, video or audio depicting an identifiable person in an intimate or sexually explicit way without their consent. The so-called nudifier tools are the obvious target, but the drafting is not confined to them. The second is an AI system that generates child sexual abuse material, defined by reference to Directive 2011/93/EU rather than in the AI Act itself.

Two features separate it from everything else in Chapter II. It is the only entry with a compliance date still ahead, and it binds deployers as well as providers, so a company with no generative product of its own can still be inside it.

The provider limb is where the engineering argument will happen. Published analysis of the agreed text takes the provider test to reach any system where such generation is a reasonably foreseeable and reproducible outcome without significant technical modification, rather than only systems built or marketed for the purpose, with adequate technical safeguards the thing that keeps a general-purpose generator outside it. That is interpretation of a provision no court has construed, and an assessment should record it as such. The practical consequence holds either way: your safeguards are what the position rests on, so document them, test them against the failure mode, and read the Official Journal wording against what you actually ship.

The date comes from one place. The omnibus amended Article 113, third paragraph, point (a), which now provides that Chapters I and II apply from 2 February 2025 with the exception of the new prohibition and the paragraphs scoping it, which apply from 2 December 2026. That is a different provision from the transitional giving generative systems already on the EU market until the same day to meet the Article 50(2) marking duty, a four-month period set by recital 38 and treated in the machine-readable marking article. Two duties, one date, no connection.

Penalties and who actually enforces them

Article 99(3) sets the highest ceiling in the regulation for non-compliance with the Article 5 prohibitions: administrative fines of up to 35,000,000 euro or, if the offender is an undertaking, up to 7 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher. Art 99(3)

Article 99(4) sets 15,000,000 euro or 3 percent for the listed operator and notified body obligations expressly "other than those laid down in Article 5", and Article 99(5) sets 7,500,000 euro or 1 percent for supplying incorrect, incomplete or misleading information. The omnibus left Article 99 alone, so the new prohibition inherits the 7 percent tier simply by sitting inside Article 5. The penalties guide has all three tiers.

The reversal for smaller operators repays a careful reading. Article 99(6) provides that for SMEs, including start-ups, each fine is up to whichever of the percentage or the amount in paragraphs 3, 4 and 5 is lower, so on an Article 5 breach that is the smaller of 35,000,000 euro and 7 percent of turnover, not the larger. It is a cap and not a discount: Article 99(1) still requires penalties that are effective, proportionate and dissuasive, and Article 99(7) sends the deciding authority to the gravity and duration of the infringement, the operator's size and turnover, its degree of cooperation, and whether the breach was intentional or negligent.

Enforcement is national by default. Article 99(1) requires member states to lay down the rules on penalties and other enforcement measures, and Article 74(1) applies Regulation (EU) 2019/1020, so designated market surveillance authorities do the work. The national authorities tracker shows how uneven designation has been. Two routing rules are worth knowing. Article 74(8) puts the biometric, law enforcement, migration and justice areas of Annex III with the data protection supervisory authority, or an authority meeting the same conditions, which is where much of the Article 5 subject matter also sits. Article 74(9) makes the European Data Protection Supervisor the market surveillance authority for Union institutions.

A fine is not the only exposure, and on the new prohibition it may not be the first. Article 5(8) preserves the prohibitions that apply where an AI practice infringes other Union law, and the underlying conduct is separately criminal: Directive 2011/93/EU on the sexual abuse and sexual exploitation of children, and Article 5 of Directive (EU) 2024/1385 on combating violence against women, which requires member states to criminalise the non-consensual production, manipulation or sharing of intimate material likely to cause serious harm.

Screening Article 5 in practice

The screen is cheap: nine numbered practices, three written exceptions and one conditional ban, and most systems clear the list in an afternoon against the text. Run it before you touch Article 6.

  1. Does the system do anything on the nine-point list? Answer against the intended purpose in the documentation and against what the system actually does, because points (d) to (g) catch putting into service for that specific purpose as well as use.
  2. If it touches (a) or (b), is there material distortion and significant harm? Both are required, and effect is enough without intent. If the answer is arguable, it is not a no.
  3. If it touches (f) or (g), does a carve-out apply on the wording? For (f), whether the system is intended for medical or safety reasons. For (g), labelling or filtering of lawfully acquired biometric datasets, or categorising biometric data in the area of law enforcement, and nothing else.
  4. If it is generative, does the new prohibition reach it from 2 December 2026? Ask whether prohibited output is a reasonably foreseeable and reproducible outcome of the system as shipped, and whether the safeguards around it are adequate and actually tested. Thin safeguards plus a reproducible failure mode is the combination that bites.
  5. Record the finding, dated, with a named owner. "Not in scope of Article 5, because the system does not infer emotions and does not categorise biometric data" is defensible written at the time and much weaker reconstructed later.

The Commission's non-binding guidelines on prohibited artificial intelligence practices, published 4 February 2025, help with borderline cases, with authoritative interpretation expressly reserved to the Court of Justice.

The screen cannot create a compliance route, because there is not one to create, and by Article 5(8) it settles nothing under other Union law. From there the questions are classification and cost: the high-risk classification guide runs the Article 6 test, what high-risk actually means clears up what the label implies, and the classifier places a system in the right tier.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

What are the prohibited AI practices under the EU AI Act?

Nine. Eight have applied since 2 February 2025: subliminal, purposefully manipulative or deceptive techniques that materially distort behaviour and cause significant harm, point (a); exploitation of age, disability or a specific social or economic situation, point (b); social scoring, point (c); predicting criminal offending based solely on profiling or personality traits, point (d); untargeted scraping of facial images to build facial recognition databases, point (e); inferring emotions in the workplace and in education institutions, point (f); biometric categorisation to infer sensitive attributes, point (g); and real-time remote biometric identification in publicly accessible spaces for law enforcement, point (h). Regulation (EU) 2026/1744 added a ninth, on AI systems that generate child sexual abuse material or non-consensual intimate imagery of an identifiable person, and it applies from 2 December 2026.

Is emotion recognition banned in the workplace under the AI Act?

Article 5(1)(f) prohibits placing on the market, putting into service for that purpose, or using an AI system to infer emotions of a natural person in the areas of workplace and education institutions, except where the system is intended to be put in place or into the market for medical or safety reasons. Recital 44 gives therapeutical use as an example of what the exception is for. The prohibition is confined to those two settings, so emotion inference elsewhere is not caught by Article 5, although it may still be classified as high-risk and remains subject to data protection law. The carve-out turns on the intended purpose, not on how a deployer happens to use the output.

Is social scoring illegal under the EU AI Act?

Article 5(1)(c) prohibits AI systems for the evaluation or classification of natural persons or groups over a certain period of time based on social behaviour or known, inferred or predicted personal or personality characteristics, where the resulting social score leads to detrimental or unfavourable treatment in social contexts unrelated to where the data was originally generated or collected, or to treatment that is unjustified or disproportionate to the social behaviour or its gravity. There is no significant harm threshold in the text and no limitation to public authorities, so private operators are inside it on the same terms. The two limbs are alternatives: either one is enough for the prohibition to bite.

When do the new AI Act prohibitions on intimate images and CSAM apply?

From 2 December 2026. Regulation (EU) 2026/1744 added the new entry to the Article 5(1) list together with the paragraphs that scope it, and amended Article 113, third paragraph, point (a), so that Chapters I and II apply from 2 February 2025 with the exception of the new provisions, which apply from 2 December 2026. That amended provision is the source of the date. It is a separate matter from the transitional period that gives generative systems placed on the EU market before 2 August 2026 until 2 December 2026 to meet the Article 50(2) machine-readable marking duty, a four-month period set by recital 38 of the same regulation. Two duties, one date, no legal connection between them.

What is the fine for a prohibited AI practice under the AI Act?

Article 99(3) provides for administrative fines of up to 35,000,000 euro or, if the offender is an undertaking, up to 7 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher. That is the regulation's highest ceiling, above the 15,000,000 euro or 3 percent tier in Article 99(4) for operator and notified body obligations other than those laid down in Article 5, and the 7,500,000 euro or 1 percent tier in Article 99(5) for supplying incorrect, incomplete or misleading information. Article 99(6) reverses the rule for SMEs and start-ups, which pay whichever of the two is lower. The words to hold on to are "up to": the ceiling is not the fine. Amounts are set nationally under Article 99(1), and Article 99(7) lists the factors, gravity, duration, the operator's size and turnover and its degree of cooperation among them.

Can police use live facial recognition under the EU AI Act?

Only where a member state has legislated for it. Article 5(1)(h) prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement unless strictly necessary for one of three listed objectives, and Article 5(5) makes the exception opt-in: a member state may decide to provide for the possibility, must lay down detailed national rules, and must notify them to the Commission within 30 days of adoption. Where it has, Article 5(3) requires prior authorisation for each use by a judicial or binding independent administrative authority, with a 24 hour window in duly justified urgency. Member states may also legislate more restrictively, including not at all.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 4 August 2026. Final classification for ambiguous cases needs qualified counsel.