Skip to content
SimpleAct Logo

AI Act · Article 5

As of 6 October 2026, after the Digital Omnibus

Prohibited AI practices under Article 5 of the AI Act

Some AI applications are banned regardless of any risk class. This has applied since 2 February 2025 and carries the highest fine tier of the Regulation. Here is every prohibition with a short explanation, and the steps to check whether you are affected.

Short answer

Article 5 bans placing on the market, putting into service or using certain AI systems, for example subliminal manipulation, exploiting vulnerabilities, social scoring, emotion recognition in the workplace and in education, and untargeted scraping of facial images. The prohibitions have applied since 2 February 2025 (Art. 113(3)(a)). Two new prohibitions on non-consensual intimate depictions and child sexual abuse material (Art. 5(1)(ba) and (bb)) apply from 2 December 2026. Infringements can be fined up to EUR 35 million or 7 % of total worldwide annual turnover, whichever is higher (Art. 99(3)).

The prohibitions

All prohibitions under Article 5(1) at a glance

The summaries reflect the content and do not replace the wording. The exceptions are narrow.

  • Art. 5(1)(a)

    Manipulation

    AI deploying subliminal techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques, to materially distort behaviour and appreciably impair the ability to make an informed decision, causing or reasonably likely to cause significant harm.

  • Art. 5(1)(b)

    Exploiting vulnerabilities

    AI exploiting vulnerabilities due to age, disability or a specific social or economic situation to materially distort behaviour in a way that causes or is reasonably likely to cause significant harm.

  • Art. 5(1)(c)

    Social scoring

    AI evaluating or classifying persons over a period of time based on their social behaviour or personal characteristics, where this leads to detrimental treatment in unrelated social contexts or to unjustified or disproportionate detrimental treatment.

  • Art. 5(1)(d)

    Crime prediction by profiling alone

    AI systems making risk assessments of the likelihood that a person commits a criminal offence based solely on profiling or personal traits. Excluded is support for a human assessment already based on objective, verifiable facts.

  • Art. 5(1)(e)

    Untargeted scraping of facial images

    AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

  • Art. 5(1)(f)

    Emotion recognition in the workplace and in education

    AI to infer emotions of a natural person in the areas of the workplace and education institutions, except where the system is intended to be put in place or placed on the market for medical or safety reasons.

  • Art. 5(1)(g)

    Biometric categorisation of sensitive traits

    Systems categorising persons based on biometric data to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. Excluded are labelling or filtering of lawfully acquired biometric datasets and categorisation in law enforcement.

  • Art. 5(1)(h)

    Real-time remote biometric identification for law enforcement

    Use in publicly accessible spaces for law enforcement, unless strictly necessary for targeted searches for specific victims or missing persons, to prevent a specific, substantial and imminent threat or a terrorist attack, or to locate suspects of certain serious offences (points (i) to (iii)). Paragraphs 2 to 8 set out the conditions.

  • Art. 5(1)(ba) (new)

    Non-consensual intimate depictions

    Added by Regulation (EU) 2026/1744: AI systems generating or manipulating realistic image, video, audio or similar content showing intimate body parts of an identifiable person or an identifiable person engaged in explicitly sexual acts, without that person's freely given, specific, informed, unambiguous and explicit consent. Applies from 2 December 2026; paragraphs 1a and 1b specify the scope.

  • Art. 5(1)(bb) (new)

    Child sexual abuse material

    Added by Regulation (EU) 2026/1744: AI systems generating or manipulating material or performances within the meaning of Art. 2(c) and (e) of Directive 2011/93/EU, unless under national law the "unlawful" conduct is considered justified. Applies from 2 December 2026.

Art. 5(1)(ba) and (bb) and Art. 5(1a) and (1b) apply from 2 December 2026 under Art. 113(3)(a) as amended by Regulation (EU) 2026/1744; all other prohibitions since 2 February 2025.

Application and penalties

Since when, for whom, with which fines?

QuestionAnswerSource
Since when do the prohibitions apply?Since 2 February 2025; exception: points (ba) and (bb) and paragraphs 1a and 1b from 2 December 2026Art. 113(3)(a) as amended
Who is affected?Placing on the market, putting into service (in part only for the specific purpose) and use: providers as well as deployersArt. 5(1)
What fine applies?Up to EUR 35 million or, for undertakings, up to 7 % of total worldwide annual turnover of the preceding financial year, whichever is higherArt. 99(3)
Is there relief for SMEs?For SMEs, including start-ups, the lower of the percentage and the amount applies. For small mid-caps this relief does not apply to infringements of Art. 5 (Art. 99(6a) covers only paragraphs 4 and 5)Art. 99(6), (6a)
Who imposes penalties?Member States lay down the rules on penalties; they must be effective, proportionate and dissuasiveArt. 99(1)

When setting the fine, the nature, gravity and duration of the infringement, the purpose of the system and the size of the operator are among the factors to consider (Art. 99(7)).

Guidelines

Commission guidelines on prohibited practices

The Commission develops guidelines on the practical implementation of the Regulation, expressly including the prohibited practices in Article 5 (Art. 96(1)(b)). It published guidelines on prohibited AI practices on 4 February 2025. Guidelines are not a binding interpretation, but they show how the Commission understands the prohibitions and are the first port of call in cases of doubt.

In practice

Where companies come close to the prohibitions

  • Art. 5(1)(f)

    Mood analysis in call centres or HR

    Software that infers employees' emotions from voice or face is banned in the workplace, except for medical or safety reasons.

  • Art. 5(1)(a) and (b)

    Manipulative chatbots and sales assistants

    An assistant that deliberately exploits vulnerabilities or uses deceptive techniques to force purchase decisions causing significant harm may fall under the prohibitions. Ordinary recommendations and advertising are not automatically covered.

  • Art. 5(1)(c)

    Scoring of customers or employees

    Scoring based on social behaviour or personality traits that leads to unrelated or disproportionate detrimental treatment is banned.

  • Art. 5(1)(e)

    Facial databases from the web

    Anyone who scrapes facial images untargeted from the internet or CCTV footage to build or expand a recognition database infringes the prohibition.

Check steps

How to check your AI systems for prohibitions

  • Record all AI systems, including purchased features and in-house builds (AI inventory)
  • Document the intended purpose per system: what does it do, to whom, with which data?
  • Check every intended purpose against Art. 5(1)(a) to (h) and (ba) and (bb)
  • Look separately at emotion recognition, biometric categorisation and scoring of persons
  • On a hit or doubt: do not use or switch off the system, get a legal assessment
  • Document the result and reasoning, with date and responsible person
  • Repeat the check whenever the intended purpose changes and for new features
  • Train staff who procure or use AI (Art. 4)

Implementation

How SimpleAct helps with the prohibition check

  • Classification

    Check prohibitions first

    The AI check starts with the prohibited practices and only then moves on to high-risk and transparency. Every classification therefore begins with the question of whether a prohibition applies.

  • Inventory

    Keep the result on the system

    Each system in the register carries its intended purpose, classification and reasoning, so the prohibition check stays traceable.

FAQ

Frequently asked questions on prohibited AI practices

The prohibitions under Article 5 have applied since 2 February 2025 (Art. 113(3)(a)). The new prohibitions in Art. 5(1)(ba) and (bb) and paragraphs 1a and 1b apply from 2 December 2026 under Regulation (EU) 2026/1744.
Up to EUR 35 million or, for undertakings, up to 7 % of total worldwide annual turnover of the preceding financial year, whichever is higher (Art. 99(3)). For SMEs the lower of the two amounts applies (Art. 99(6)). For small mid-caps this relief does not apply to infringements of Art. 5 (Art. 99(6a) covers only paragraphs 4 and 5).
Banned is inferring emotions of a natural person in the workplace and in education institutions, unless the system is intended for medical or safety reasons (Art. 5(1)(f)). In other areas other rules apply, such as the deployer information duty under Art. 50(3).
No. Art. 5(1) lists placing on the market, putting into service and use. Anyone who merely uses a prohibited system can also infringe the ban.
Yes. The Commission published guidelines on prohibited AI practices on 4 February 2025. The legal basis is Art. 96(1)(b). Binding interpretation ultimately rests with the Court of Justice of the European Union.
They are not banned in general. Deployers must disclose the artificial origin (Art. 50(4)). However, Art. 5(1)(ba) bans, from 2 December 2026, AI systems for generating or manipulating non-consensual intimate depictions.

More questions? We're happy to help. Send email · Get started

Sources and status

As of · SimpleAct editorial team

Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.

Check prohibitions first, then everything else

Record your AI systems and have each one checked for prohibited practices first. We will show you what that looks like in SimpleAct.