Why Article 5 comes before the high-risk question
Most AI Act programmes open at Article 6 and ask whether the system is high-risk. That is the second question. The first is whether the practice is prohibited outright, and it is the cheaper one to answer, because Article 5 is the only tier where the answer cannot be bought with paperwork.
Chapter II contains no conformity assessment, no CE marking, no registration and no documentation route. Nothing in it converts a prohibited practice into a permitted one. Three unrelated provisions confirm it.
- Article 2(12). The free and open-source licence exclusion does not reach systems placed on the market or put into service as high-risk, or as an AI system falling under Article 5 or 50, as the open-source exemption article works through.
- Article 60(1). Real-world testing of high-risk systems outside a sandbox is permitted only without prejudice to the prohibitions under Article 5. You cannot pilot your way into a prohibited practice.
- Article 111(2), as replaced by Regulation (EU) 2026/1744. High-risk systems already on the market come into scope only if they are subject to significant changes in their designs, but the paragraph opens "Without prejudice to the application of Article 5". The legacy relief never reached the prohibitions.
The timing points the same way. Article 113, third paragraph, point (a) applied Chapters I and II from 2 February 2025, so the original eight prohibitions have been live for eighteen months, while Annex III high-risk obligations start on 2 December 2027, as the timeline guide sets out.
Two limits before the list. Article 5 is not universal, because the Article 2 exclusions cover the whole regulation: exclusive military, defence or national security use (2(3)); development for the sole purpose of scientific research (2(6)); pre-market research, testing and development other than real-world testing (2(8)); and natural persons deploying AI in a purely personal, non-professional activity (2(10)), which matters for the use limb of the new prohibition.
Nor does Article 5 bind identically everywhere. Recitals 40 and 41 record that Ireland, under Protocol No 21, and Denmark, under Protocol No 22, are not bound by point (h), Article 5(2) to (6) and Article 26(10), nor by point (d) so far as it applies to use, nor by point (g) so far as it applies to police and judicial cooperation in criminal matters.
The nine prohibitions, point by point
Eight points, (a) to (h), have stood in the text since 2024, and the Digital Omnibus adds a ninth from 2 December 2026. Three acts can be caught, placing on the market, putting into service and use. Points (d) to (g) catch putting into service only for that specific purpose, and point (h) catches use alone, which is why a provider and a deployer can have very different exposure.
| Point | Practice | Acts caught | Distortion and harm threshold | Law enforcement only |
|---|---|---|---|---|
| (a) | Subliminal, purposefully manipulative or deceptive techniques | All three | Distortion, impaired informed decision, significant harm | No |
| (b) | Exploiting age, disability or a specific social or economic situation | All three | Distortion and significant harm, no informed-decision limb | No |
| (c) | Social scoring from behaviour or personal characteristics over time | All three | No significant-harm test, but detrimental treatment out of context, or unjustified or disproportionate | No |
| (d) | Predicting criminal offending based solely on profiling or personality traits | All three, service for that purpose only | None | Not on its face |
| (e) | Facial recognition databases built by untargeted scraping of the internet or CCTV | All three, service for that purpose only | None | No |
| (f) | Inferring emotions in the workplace and in education institutions | All three, service for that purpose only | None | No |
| (g) | Biometric categorisation inferring race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation | All three, service for that purpose only | None | No |
| (h) | Real-time remote biometric identification in publicly accessible spaces | Use only | None | Yes |
| New, from 2 Dec 2026 | Generating child sexual abuse material, or intimate or sexually explicit material of an identifiable person without consent | All three | None | No |
Only (a) and (b) carry a significant-harm threshold, and they are not the same test. Point (a) has four cumulative limbs: the technique, material distortion of behaviour, appreciable impairment of the ability to make an informed decision such that a decision is taken that would not otherwise have been taken, and significant harm. It reads "with the objective, or the effect of", so a design nobody intended to be manipulative is caught if it manipulates. Art 5(1)(a) Point (b) drops the informed-decision limb, so a pattern aimed at a group in a specific economic situation can fail (b) while surviving (a). Art 5(1)(b) Every other point turns on the practice alone, with no harm to prove.
That threshold is what keeps ordinary commerce off the list. Recital 29 records that common and legitimate commercial practices, advertising among them, which comply with applicable law are not in themselves harmful manipulative AI-enabled practices. A persuasive interface is not a prohibited one.
The carve-outs that decide most real cases
Three points, (d), (f) and (g), carry an exception written into the prohibition itself. Point (h) carries a different structure, three conditional openings and six paragraphs of machinery, and the next section takes it on its own. None of the three is a general reasonableness defence, and they are not interchangeable.
| Point | The exception, as written | What it does not cover |
|---|---|---|
| (d) | Support for the human assessment of a person's involvement in criminal activity already based on objective and verifiable facts directly linked to a criminal activity | Anything where profiling or personality assessment is the sole basis. Recital 42 confirms the point does not reach risk analytics that do not profile individuals |
| (f) | Where use is intended to be put in place or into the market for medical or safety reasons, with recital 44 pointing at therapeutical use | Attention monitoring or sentiment scoring on staff or students dressed as wellbeing. It turns on intended purpose, not the dashboard label |
| (g) | Labelling or filtering of lawfully acquired biometric datasets, or categorising biometric data in the area of law enforcement. Recital 30 gives sorting images by hair or eye colour | Inference of the sensitive attributes themselves. There is no medical or safety exception in (g), and importing one from (f) is the commonest error here |
The word doing the work in point (d) is "solely", and the gate it opens describes a decision process rather than a product feature, so the evidence for it lives in the deployer's procedure, not the vendor's datasheet. Art 5(1)(d)
Point (c) has no written exception, and it is the one most often misread as reaching ordinary scoring. Recital 31 supplies the line: the prohibition should not affect lawful evaluation practices carried out for a specific purpose in accordance with Union and national law. The regulation then routes creditworthiness evaluation and credit scoring into Annex III point 5(b) as high-risk rather than prohibited, with fraud detection carved out of even that, as the credit scoring guide works through. What crosses into (c) is the general score that follows a person out of the context the data came from, or that produces treatment disproportionate to the behaviour it rests on.
Clearing Article 5 clears Article 5 and nothing else: Article 5(8) provides that the Article does not affect the prohibitions applying where an AI practice infringes other Union law. Art 5(8) A practice that survives Chapter II can still fail the GDPR, the Digital Services Act or consumer law, and the AI Act and GDPR article covers the overlap that catches most teams first.
Real-time biometric identification is a conditional ban
Article 5(1)(h) is a prohibition with three narrow openings, buried under six paragraphs of machinery in Article 5(2) to (7). Reading the openings without the machinery is how it gets mistaken for a licence.
The objectives are a targeted search for specific victims of abduction, trafficking or sexual exploitation and for missing persons; prevention of a specific, substantial and imminent threat to life or physical safety, or a genuine and present or genuine and foreseeable threat of a terrorist attack; and localisation or identification of a person suspected of an Annex II offence punishable in that member state by a custodial sentence or detention order of a maximum of at least four years. Art 5(1)(h)
None of that operates by itself. Article 5(5) makes the regime opt-in: a member state "may decide to provide for the possibility" to authorise such use, must lay down detailed national rules on requests, issuance, exercise, supervision and reporting, must specify which objectives and Annex II offences it covers, and must notify those rules to the Commission within 30 days of adoption. It may legislate more restrictively, and where it has not legislated the practice is simply prohibited. Where it has, three layers apply.
- Prior authorisation, per use. Article 5(3) requires authorisation from a judicial authority or an independent administrative authority whose decision is binding, in the member state of use, on reasoned request. In duly justified urgency use may start without it, provided authorisation is requested at the latest within 24 hours; if it is refused, use stops with immediate effect and all data, results and outputs must be discarded and deleted. No decision producing an adverse legal effect may be taken based solely on the output.
- Substantive limits. Article 5(2) confines the system to confirming the identity of the specifically targeted individual, and requires account to be taken of the seriousness, probability and scale of the harm if it were not used, and of the consequences for the rights of all persons concerned, within the temporal, geographic and personal limits set by national law. It also conditions use on a fundamental rights impact assessment under Article 27 and registration in the EU database under Article 49.
- Notification and reporting. Article 5(4) requires each use to be notified to the market surveillance authority and the national data protection authority, excluding sensitive operational data. Article 5(6) then requires those authorities to send the Commission annual reports on a template the Commission provides, and Article 5(7) requires the Commission to publish an aggregated annual report of its own, again without sensitive operational data.
One timing question the text leaves open. Article 5(2) has applied since 2 February 2025 and conditions real-time identification on a fundamental rights impact assessment as provided for in Article 27, which sits in Chapter III, Section 3, and arrives with the rest of the standalone Annex III regime on 2 December 2027. Neither regulation reconciles the two dates, so how the Article 5(2) condition operates in the meantime is not something either instrument answers.
What the Digital Omnibus added: intimate imagery and CSAM
Regulation (EU) 2026/1744 of 8 July 2026, at OJ L, 2026/1744, 24.7.2026 and in force since 27 July 2026, made the first substantive addition to the list: one new entry, applying from 2 December 2026. The eight existing points were untouched, and so were Article 5(2) to 5(8) and the Article 99 tiers. The Digital Omnibus guide covers the rest.
The new prohibition covers two subjects at once. The first is an AI system that generates or manipulates images, video or audio depicting an identifiable person in an intimate or sexually explicit way without their consent. The so-called nudifier tools are the obvious target, but the drafting is not confined to them. The second is an AI system that generates child sexual abuse material, defined by reference to Directive 2011/93/EU rather than in the AI Act itself.
Two features separate it from everything else in Chapter II. It is the only entry with a compliance date still ahead, and it binds deployers as well as providers, so a company with no generative product of its own can still be inside it.
The provider limb is where the engineering argument will happen. Published analysis of the agreed text takes the provider test to reach any system where such generation is a reasonably foreseeable and reproducible outcome without significant technical modification, rather than only systems built or marketed for the purpose, with adequate technical safeguards the thing that keeps a general-purpose generator outside it. That is interpretation of a provision no court has construed, and an assessment should record it as such. The practical consequence holds either way: your safeguards are what the position rests on, so document them, test them against the failure mode, and read the Official Journal wording against what you actually ship.
The date comes from one place. The omnibus amended Article 113, third paragraph, point (a), which now provides that Chapters I and II apply from 2 February 2025 with the exception of the new prohibition and the paragraphs scoping it, which apply from 2 December 2026. That is a different provision from the transitional giving generative systems already on the EU market until the same day to meet the Article 50(2) marking duty, a four-month period set by recital 38 and treated in the machine-readable marking article. Two duties, one date, no connection.
Penalties and who actually enforces them
Article 99(3) sets the highest ceiling in the regulation for non-compliance with the Article 5 prohibitions: administrative fines of up to 35,000,000 euro or, if the offender is an undertaking, up to 7 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher. Art 99(3)
Article 99(4) sets 15,000,000 euro or 3 percent for the listed operator and notified body obligations expressly "other than those laid down in Article 5", and Article 99(5) sets 7,500,000 euro or 1 percent for supplying incorrect, incomplete or misleading information. The omnibus left Article 99 alone, so the new prohibition inherits the 7 percent tier simply by sitting inside Article 5. The penalties guide has all three tiers.
The reversal for smaller operators repays a careful reading. Article 99(6) provides that for SMEs, including start-ups, each fine is up to whichever of the percentage or the amount in paragraphs 3, 4 and 5 is lower, so on an Article 5 breach that is the smaller of 35,000,000 euro and 7 percent of turnover, not the larger. It is a cap and not a discount: Article 99(1) still requires penalties that are effective, proportionate and dissuasive, and Article 99(7) sends the deciding authority to the gravity and duration of the infringement, the operator's size and turnover, its degree of cooperation, and whether the breach was intentional or negligent.
Enforcement is national by default. Article 99(1) requires member states to lay down the rules on penalties and other enforcement measures, and Article 74(1) applies Regulation (EU) 2019/1020, so designated market surveillance authorities do the work. The national authorities tracker shows how uneven designation has been. Two routing rules are worth knowing. Article 74(8) puts the biometric, law enforcement, migration and justice areas of Annex III with the data protection supervisory authority, or an authority meeting the same conditions, which is where much of the Article 5 subject matter also sits. Article 74(9) makes the European Data Protection Supervisor the market surveillance authority for Union institutions.
A fine is not the only exposure, and on the new prohibition it may not be the first. Article 5(8) preserves the prohibitions that apply where an AI practice infringes other Union law, and the underlying conduct is separately criminal: Directive 2011/93/EU on the sexual abuse and sexual exploitation of children, and Article 5 of Directive (EU) 2024/1385 on combating violence against women, which requires member states to criminalise the non-consensual production, manipulation or sharing of intimate material likely to cause serious harm.
Screening Article 5 in practice
The screen is cheap: nine numbered practices, three written exceptions and one conditional ban, and most systems clear the list in an afternoon against the text. Run it before you touch Article 6.
- Does the system do anything on the nine-point list? Answer against the intended purpose in the documentation and against what the system actually does, because points (d) to (g) catch putting into service for that specific purpose as well as use.
- If it touches (a) or (b), is there material distortion and significant harm? Both are required, and effect is enough without intent. If the answer is arguable, it is not a no.
- If it touches (f) or (g), does a carve-out apply on the wording? For (f), whether the system is intended for medical or safety reasons. For (g), labelling or filtering of lawfully acquired biometric datasets, or categorising biometric data in the area of law enforcement, and nothing else.
- If it is generative, does the new prohibition reach it from 2 December 2026? Ask whether prohibited output is a reasonably foreseeable and reproducible outcome of the system as shipped, and whether the safeguards around it are adequate and actually tested. Thin safeguards plus a reproducible failure mode is the combination that bites.
- Record the finding, dated, with a named owner. "Not in scope of Article 5, because the system does not infer emotions and does not categorise biometric data" is defensible written at the time and much weaker reconstructed later.
The Commission's non-binding guidelines on prohibited artificial intelligence practices, published 4 February 2025, help with borderline cases, with authoritative interpretation expressly reserved to the Court of Justice.
The screen cannot create a compliance route, because there is not one to create, and by Article 5(8) it settles nothing under other Union law. From there the questions are classification and cost: the high-risk classification guide runs the Article 6 test, what high-risk actually means clears up what the label implies, and the classifier places a system in the right tier.