Article 5: prohibited AI practices
The only tier where the answer is “stop” rather than “document”. These have applied since 2 February 2025 and carry the Regulation’s highest penalty. Two more were added by the Digital Omnibus and apply from 2 December 2026, and unlike the rest, they will bite on general-purpose generative products rather than niche systems.
The prohibitions in force since February 2025
| Practice | Scope and the qualifier that matters |
|---|---|
| Manipulative or deceptive techniques | Subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques, that materially distort behaviour by appreciably impairing the ability to make an informed decision, and cause or are reasonably likely to cause significant harm. |
| Exploiting vulnerabilities | Exploiting vulnerabilities due to age, disability, or a specific social or economic situation. The last limb is broader than most readings assume. |
| Social scoring | Evaluation or classification based on social behaviour or personal characteristics, leading to detrimental treatment in social contexts unrelated to the data’s origin, or treatment that is unjustified or disproportionate to the behaviour. |
| Predictive policing on profiling alone | Assessing the risk of a person committing a criminal offence based solely on profiling or personality traits. Systems supporting a human assessment already based on objective, verifiable facts directly linked to criminal activity are outside. |
| Untargeted facial-image scraping | Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage. |
| Emotion inference at work or in education | Inferring emotions in the workplace and education institutions, except for medical or safety reasons. Not a general ban on emotion recognition. |
| Biometric categorisation on protected traits | Categorising individuals on biometric data to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. |
| Real-time remote biometric ID in public | For law enforcement purposes in publicly accessible spaces, subject to narrow exhaustively listed exceptions with prior authorisation requirements. |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The two new prohibitions — 2 December 2026
These reach general-purpose products
Regulation (EU) 2026/1744 added two prohibitions to Article 5, applying from 2 December 2026:
- AI systems that generate or manipulate realistic non-consensual intimate imagery or material of identifiable individuals without their consent, including so-called “nudifier” applications.
- AI systems that generate child sexual abuse material, subject to a “without right” defence under member state law.
Both placing on the market and use are prohibited.
The scope is what makes this different from the rest of Article 5. A new Article 5(1a) limits provider liability to cases where generation of such material is the intended purpose of the system, or is reasonably foreseeable and reproducible without significant technical modification. Providers are expected to document technical safeguards, refusal training, prompt guardrails, content filtering and abuse detection.
If that reading holds, a general-purpose image or multimodal generation product is in scope of the analysis even though it was not built for the prohibited purpose. The compliance question becomes whether your safeguards, refusal training, output classifiers, content filtering, prompt handling — are reasonable, proportionate and effective.
Why Article 5(1a) matters more than the prohibition itself
Expert analysis. The liability limb is the operative test for a general-purpose product. “Reasonably foreseeable and reproducible without significant technical modification” means a jailbreak requiring significant modification points away from liability, while an output reachable through ordinary prompting points toward it. That makes red-team evidence the artefact: what did you test, what did it take to reproduce, and what did you change. Read the consolidated Article 5 on EUR-Lex and take advice before making a product decision.
What to do if you ship generative features
Practical recommendation. You have until 2 December 2026 and three possible positions. Pick one deliberately and write down why.
- Clearly out of scope. Text-only, no image or video synthesis, no likeness manipulation. Document the reasoning; do not assume it.
- In scope with documented safeguards. Refusal behaviour, output filtering, likeness protections, red-team evidence, and a record of why the set is reasonable, proportionate and effective. Treat the evidence as you would a technical file.
- Withdraw the feature in the EU. A legitimate answer, and the right one for some products.
What is not available is doing nothing and arguing later that misuse was the user’s doing. The foreseeability limb exists precisely to close that.
Status labels on this page
Verified fact: The eight original Article 5 prohibitions and their qualifiers, the 2 December 2026 application date, and the €35M/7% ceiling under Art. 99(3).
Expert analysis: The reading of the safeguards limb and the three-position framing above.
Unsettled: The exact operative wording of the new prohibitions and how enforcement will treat 'reasonable, proportionate and effective safeguards'. No guidance or decisions yet.
Document the position before December
Whichever of the three positions you take, the artefact is the same: a dated determination naming who decided, what the safeguards are, and what evidence supports calling them effective.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What AI practices are prohibited in the EU?
Article 5 prohibits: AI using subliminal, purposefully manipulative or deceptive techniques that materially distort behaviour and cause or are reasonably likely to cause significant harm; exploitation of vulnerabilities due to age, disability or a specific social or economic situation; social scoring leading to detrimental or unfavourable treatment in unrelated contexts or that is unjustified or disproportionate; predicting the risk of a person committing a criminal offence based solely on profiling or personality traits; untargeted scraping of facial images from the internet or CCTV to build facial recognition databases; inferring emotions in the workplace or in education institutions except for medical or safety reasons; biometric categorisation to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation; and real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions. Regulation (EU) 2026/1744 added two further prohibitions applying from 2 December 2026.
What are the new EU AI Act prohibitions from December 2026?
Regulation (EU) 2026/1744 added two prohibitions to Article 5, applying from 2 December 2026. The first targets AI systems that generate or manipulate realistic non-consensual intimate imagery or material of identifiable individuals without their consent, including so-called nudifier applications. The second targets AI systems that generate child sexual abuse material, subject to a without-right defence under member state law. Reporting indicates the prohibitions cover systems designed for those purposes and also systems where such outputs are reasonably foreseeable and reproducible in the absence of reasonable, proportionate and effective safeguards.
What is the penalty for a prohibited AI practice?
Up to 35 million euro or 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(3). This is the highest tier in the Regulation and applies only to Article 5 breaches. For SMEs including start-ups, the lower of the two figures applies.
Is emotion recognition banned in the EU?
Only in specific contexts. Article 5 prohibits inferring emotions of a natural person in the areas of workplace and education institutions, except where the AI system is intended to be put in place or into the market for medical or safety reasons. Emotion recognition outside those two contexts is not prohibited, but it is subject to the Article 50(3) transparency obligation requiring deployers to inform the people exposed to it, and may be high-risk under Annex III.
Obligations, article by article
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 9 risk management
- Art. 10 data governance
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- FRIA template (Art. 27)
- When Annex III does not apply →