AI Act · Article 5
As of 6 October 2026, after the Digital Omnibus
Prohibited AI practices under Article 5 of the AI Act
Some AI applications are banned regardless of any risk class. This has applied since 2 February 2025 and carries the highest fine tier of the Regulation. Here is every prohibition with a short explanation, and the steps to check whether you are affected.
Short answer
Article 5 bans placing on the market, putting into service or using certain AI systems, for example subliminal manipulation, exploiting vulnerabilities, social scoring, emotion recognition in the workplace and in education, and untargeted scraping of facial images. The prohibitions have applied since 2 February 2025 (Art. 113(3)(a)). Two new prohibitions on non-consensual intimate depictions and child sexual abuse material (Art. 5(1)(ba) and (bb)) apply from 2 December 2026. Infringements can be fined up to EUR 35 million or 7 % of total worldwide annual turnover, whichever is higher (Art. 99(3)).
The prohibitions
All prohibitions under Article 5(1) at a glance
The summaries reflect the content and do not replace the wording. The exceptions are narrow.
Art. 5(1)(a)
Manipulation
AI deploying subliminal techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques, to materially distort behaviour and appreciably impair the ability to make an informed decision, causing or reasonably likely to cause significant harm.
Art. 5(1)(b)
Exploiting vulnerabilities
AI exploiting vulnerabilities due to age, disability or a specific social or economic situation to materially distort behaviour in a way that causes or is reasonably likely to cause significant harm.
Art. 5(1)(c)
Social scoring
AI evaluating or classifying persons over a period of time based on their social behaviour or personal characteristics, where this leads to detrimental treatment in unrelated social contexts or to unjustified or disproportionate detrimental treatment.
Art. 5(1)(d)
Crime prediction by profiling alone
AI systems making risk assessments of the likelihood that a person commits a criminal offence based solely on profiling or personal traits. Excluded is support for a human assessment already based on objective, verifiable facts.
Art. 5(1)(e)
Untargeted scraping of facial images
AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
Art. 5(1)(f)
Emotion recognition in the workplace and in education
AI to infer emotions of a natural person in the areas of the workplace and education institutions, except where the system is intended to be put in place or placed on the market for medical or safety reasons.
Art. 5(1)(g)
Biometric categorisation of sensitive traits
Systems categorising persons based on biometric data to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. Excluded are labelling or filtering of lawfully acquired biometric datasets and categorisation in law enforcement.
Art. 5(1)(h)
Real-time remote biometric identification for law enforcement
Use in publicly accessible spaces for law enforcement, unless strictly necessary for targeted searches for specific victims or missing persons, to prevent a specific, substantial and imminent threat or a terrorist attack, or to locate suspects of certain serious offences (points (i) to (iii)). Paragraphs 2 to 8 set out the conditions.
Art. 5(1)(ba) (new)
Non-consensual intimate depictions
Added by Regulation (EU) 2026/1744: AI systems generating or manipulating realistic image, video, audio or similar content showing intimate body parts of an identifiable person or an identifiable person engaged in explicitly sexual acts, without that person's freely given, specific, informed, unambiguous and explicit consent. Applies from 2 December 2026; paragraphs 1a and 1b specify the scope.
Art. 5(1)(bb) (new)
Child sexual abuse material
Added by Regulation (EU) 2026/1744: AI systems generating or manipulating material or performances within the meaning of Art. 2(c) and (e) of Directive 2011/93/EU, unless under national law the "unlawful" conduct is considered justified. Applies from 2 December 2026.
Art. 5(1)(ba) and (bb) and Art. 5(1a) and (1b) apply from 2 December 2026 under Art. 113(3)(a) as amended by Regulation (EU) 2026/1744; all other prohibitions since 2 February 2025.
Application and penalties
Since when, for whom, with which fines?
| Question | Answer | Source |
|---|---|---|
| Since when do the prohibitions apply? | Since 2 February 2025; exception: points (ba) and (bb) and paragraphs 1a and 1b from 2 December 2026 | Art. 113(3)(a) as amended |
| Who is affected? | Placing on the market, putting into service (in part only for the specific purpose) and use: providers as well as deployers | Art. 5(1) |
| What fine applies? | Up to EUR 35 million or, for undertakings, up to 7 % of total worldwide annual turnover of the preceding financial year, whichever is higher | Art. 99(3) |
| Is there relief for SMEs? | For SMEs, including start-ups, the lower of the percentage and the amount applies. For small mid-caps this relief does not apply to infringements of Art. 5 (Art. 99(6a) covers only paragraphs 4 and 5) | Art. 99(6), (6a) |
| Who imposes penalties? | Member States lay down the rules on penalties; they must be effective, proportionate and dissuasive | Art. 99(1) |
When setting the fine, the nature, gravity and duration of the infringement, the purpose of the system and the size of the operator are among the factors to consider (Art. 99(7)).
Guidelines
Commission guidelines on prohibited practices
The Commission develops guidelines on the practical implementation of the Regulation, expressly including the prohibited practices in Article 5 (Art. 96(1)(b)). It published guidelines on prohibited AI practices on 4 February 2025. Guidelines are not a binding interpretation, but they show how the Commission understands the prohibitions and are the first port of call in cases of doubt.
In practice
Where companies come close to the prohibitions
Art. 5(1)(f)
Mood analysis in call centres or HR
Software that infers employees' emotions from voice or face is banned in the workplace, except for medical or safety reasons.
Art. 5(1)(a) and (b)
Manipulative chatbots and sales assistants
An assistant that deliberately exploits vulnerabilities or uses deceptive techniques to force purchase decisions causing significant harm may fall under the prohibitions. Ordinary recommendations and advertising are not automatically covered.
Art. 5(1)(c)
Scoring of customers or employees
Scoring based on social behaviour or personality traits that leads to unrelated or disproportionate detrimental treatment is banned.
Art. 5(1)(e)
Facial databases from the web
Anyone who scrapes facial images untargeted from the internet or CCTV footage to build or expand a recognition database infringes the prohibition.
Check steps
How to check your AI systems for prohibitions
- Record all AI systems, including purchased features and in-house builds (AI inventory)
- Document the intended purpose per system: what does it do, to whom, with which data?
- Check every intended purpose against Art. 5(1)(a) to (h) and (ba) and (bb)
- Look separately at emotion recognition, biometric categorisation and scoring of persons
- On a hit or doubt: do not use or switch off the system, get a legal assessment
- Document the result and reasoning, with date and responsible person
- Repeat the check whenever the intended purpose changes and for new features
- Train staff who procure or use AI (Art. 4)
Implementation
How SimpleAct helps with the prohibition check
Classification
Check prohibitions first
The AI check starts with the prohibited practices and only then moves on to high-risk and transparency. Every classification therefore begins with the question of whether a prohibition applies.
Inventory
Keep the result on the system
Each system in the register carries its intended purpose, classification and reasoning, so the prohibition check stays traceable.
FAQ
Frequently asked questions on prohibited AI practices
More questions? We're happy to help. Send email · Get started
Sources and status
As of · SimpleAct editorial team
- Regulation (EU) 2024/1689 (AI Act), Official Journal
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal
- European Commission: Guidelines on prohibited AI practices (4 February 2025)
Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.
Check prohibitions first, then everything else
Record your AI systems and have each one checked for prohibited practices first. We will show you what that looks like in SimpleAct.