Article 5 is the only part of the Regulation that prohibits. Everywhere else the text frames, documents and imposes procedures. Here it closes the door.
It is also the most badly reported part. You will regularly read that “scoring people is banned” or that “facial recognition is banned”, when the Commission writes the opposite, in terms, in its own guidelines.
Eight prohibitions have applied since 2 February 2025. The last two, added by Regulation (EU) 2026/1744, apply from 2 December 2026. The Article 99 penalty regime has only applied since 2 August 2025: the obligation preceded its penalty by six months.
What AI practices are prohibited under the EU AI Act?
Ten, listed in Article 5, eight enforceable since 2 February 2025 and two added by the omnibus, enforceable on 2 December 2026. Each is far narrower than its usual summary.
| Point | What is prohibited | Since |
|---|---|---|
| (a) | Subliminal, purposefully manipulative or deceptive techniques materially distorting behaviour and causing significant harm | 02/02/2025 |
| (b) | Exploiting vulnerabilities due to age, disability or a specific social or economic situation | 02/02/2025 |
| (ba) | Non-consensual intimate material generated or manipulated, realistically depicting an identifiable person’s intimate parts or an identifiable person engaged in sexually explicit activities | 02/12/2026 |
| (bb) | Child sexual abuse material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a without-right defence applies under national law | 02/12/2026 |
| (c) | Social scoring leading to detrimental or unfavourable treatment, in unrelated social contexts and/or where that treatment is unjustified or disproportionate | 02/02/2025 |
| (d) | Assessing or predicting the risk of a person committing a criminal offence, based solely on profiling or personality traits: the prohibition does not apply to systems supporting a human assessment already based on objective and verifiable facts directly linked to a criminal activity | 02/02/2025 |
| (e) | Creating or expanding facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage | 02/02/2025 |
| (f) | Inferring emotions in the areas of workplace and education institutions, except for medical or safety reasons | 02/02/2025 |
| (g) | Biometric categorisation deducing race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation | 02/02/2025 |
| (h) | Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, save three strictly framed objectives | 02/02/2025 |
One word in point (d) deserves a warning. “Solely” is not an easy way out: the Commission considers, at point (202) of its guidelines, that any such other elements “will have to be real, substantial and meaningful”.
One thing to know about the last two. The Commission’s guidelines on prohibited practices are dated 29 July 2025: they predate the omnibus and say nothing about points (ba) and (bb). Checked word by word across their 134 English pages. There is therefore, to date, no official interpretation of these two prohibitions: the Regulation is the only source available.
Does a generative model fall under the two new prohibitions?
Not merely because it is capable of it. Regulation (EU) 2026/1744 inserted points (ba) and (bb) into Article 5 and, at the same time, a filter — paragraphs 1a and 1b — that bounds precisely who is caught. This is the most important point for a provider, and it is missing from most summaries. A model capable of producing such images does not fall under points (ba) and (bb) merely because it is capable of it. The same regulation inserted, alongside the two prohibitions, a filter (Article 5(1a) and (1b)), which bounds precisely who is caught, and which applies on the same date.
On the provider side, two gates only. Placing on the market or putting into service is prohibited only where that generation or manipulation “is the intended purpose of the AI system”; or where “the system’s design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification”, and the system “does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse”.
On the deployer side, one gate: intent. Use is prohibited only where “the deployer uses the system for the purpose of generating or manipulating such material or performance”. Lawful use of a tool without safeguards is not a deployer’s infringement.
And a negative definition, specific to point (ba): a system “that manipulates material in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation”.
These three rules are in the Regulation itself, not in an interpretative document.
Is social scoring prohibited by the EU AI Act?
Not as such. The Commission’s guidelines are explicit: scoring natural persons is not systematically prohibited, only in the few cases where all the conditions of Article 5(1)(c) are met cumulatively. This is the most useful section on the page, because it is where the shortcut costs the most.
“the scoring of natural persons is not at all times prohibited, but only in the limited cases where all of the conditions of Article 5(1)(c) AI Act are cumulatively fulfilled”
Source: Commission guidelines, C(2025) 5052 final, point (175)
And the Commission goes further, naming the trades that are spared:
“credit scoring and risk scoring and underwriting are essential aspects of the services of financial and insurance businesses. Such practices, as well as other legitimate practices (i.e. to improve the quality and efficiency of services, to ensure more efficient claims handling, to perform specific employee evaluations, fraud prevention and detection, law enforcement or scoring of users’ behaviour on online platforms), are not per se prohibited, if lawful and undertaken in line with the AI Act and other applicable Union law and national law, which must comply with Union law”
Source: Same point (175)
These guidelines are not binding: they say what the Commission considers, not what the Regulation requires.
Read the test in point (c) carefully. The social score must lead to “either or both” of two things: detrimental or unfavourable treatment in social contexts “that are unrelated to the contexts in which the data was originally generated or collected”; and detrimental or unfavourable treatment “that is unjustified or disproportionate to their social behaviour or its gravity”. The two branches are alternative, not cumulative: one is enough.
Three notions drive the analysis. A mere classification (sorting by age, sex or height) is not necessarily an evaluation, which implies a judgement. Unfavourable treatment means being treated worse than others without suffering particular harm, while detrimental treatment implies damage: both open the prohibition, but they are not the same thing.
An interpretative rule that governs the rest
Article 5 is to be read narrowly, and the Commission says so itself. Because the prohibitions carry the heaviest fines and the greatest interference with freedoms, their scope is to be interpreted restrictively. The practical consequence runs through the whole guidance: the conditions of each prohibition are cumulative.
“Since violations of the prohibitions in Article 5 AI Act interfere the most with the freedoms of others and give rise to the highest fines, their scope should be interpreted narrowly.”
Source: Commission guidelines, C(2025) 5052 final, point (57)
The corollary is repeated throughout the document: the conditions of each prohibition are cumulative, they must be met simultaneously, and a plausible causal link must connect them.
What does Article 5 not prohibit, contrary to belief?
Rather more than people assume, and an interpretative rule works in your favour. Because breaches of Article 5 carry the highest fines, the Commission reads the prohibitions narrowly. Five recurring confusions the Commission dispels, and one idea that runs the other way.
AI-driven personalised advertising. The Commission considers that common and legitimate commercial practices such as advertising should not be regarded “in themselves” or by their very nature as harmful manipulative, deceptive or exploitative practices within points (a) and (b). That is not an absolute exclusion: such techniques are “not inherently manipulative if they do not deploy subliminal, purposefully manipulative or deceptive techniques that subvert individual autonomy or exploit vulnerabilities in harmful ways” as prohibited under points (a) and (b).
Hallucinations of a generative AI. Point (73) states that such a system may not be considered to deploy deceptive techniques within the meaning of point (a), “taking into account the limitations and the state of the art of generative AI”. The Commission attaches conditions to that: it “may be the case” where the provider has properly informed users of the system’s limitations, has integrated appropriate safeguards to minimise such outcomes, and where the system “is not intended for, nor deployed in, sensitive contexts (e.g., health, education, elections) where serious harmful consequences are likely to occur”.
Driver fatigue detection. Twice excluded: it is neither emotion recognition within point (f), nor exploitation of a vulnerability within point (b).
Sentiment analysis of text at work. It is not based on biometric data, so it falls outside point (f). What point (f) targets is inferring emotions from biometric data: voice, face, physiological signals.
Facial recognition in a shop. Private use is not caught by point (h): a retailer identifying shoplifters on its own account is outside that prohibition. Points (a) to (g), by contrast, bind private actors squarely.
Two reservations, to be held at both ends. If law enforcement authorities task it with doing so, or ask it to act in support in specific cases (provided those authorities “instruct on all major aspects and supervise the other entity”), the purpose becomes law enforcement and the use is prohibited again.
And being outside the prohibition means neither outside the Regulation nor lawful. The Commission recalls at point (425) that other uses of remote biometric identification systems not covered by the prohibition fall under high risk by virtue of Annex III, point 1(a), “provided they fall within the scope of the AI Act”. It also cites four national precedents, all unfavourable: two French secondary schools, a Dutch supermarket, a football club in France and a spectator-security scheme in Spain.
And the one that runs the other way. Respecting robots.txt does not shelter you from point (e). The Commission says precisely the opposite.
Is real-time facial recognition banned in public spaces?
Point (h) is the most commented and the most distorted. According to the Commission the prohibition requires five cumulative conditions: a remote biometric identification system; its use; in real time; in a publicly accessible space; for law enforcement purposes. And it binds deployers only.
Each of those conditions excludes whole categories of case.
Verification is not identification. Confirming that a person is who they claim to be (unlocking a device, accessing a service, secured access to premises) is expressly outside the prohibition.
After the fact is not real time. Post-remote biometric identification is not prohibited: it is high-risk, and governed by Article 26(10). The switch is temporal: a delay is significant “at least when the person is likely to have left the place where the biometric data was taken”.
Not every open place is a publicly accessible space. Border control zones of an airport are excluded, and so is a badge-controlled workplace. The Commission does not rule on schools, and it holds that assessing whether a space is accessible to the public “should be done based on a case-by-case analysis”, a rule for every space, not a position on schools.
And the three exceptions are not an authorisation. Targeted search for victims of abduction, trafficking or sexual exploitation and for missing persons; prevention of “a specific, substantial and imminent threat to the life or physical safety of natural persons” or of “a genuine and present or genuine and foreseeable threat of a terrorist attack” (two limbs, each with its own standard); and locating or identifying a person suspected of an Annex II offence, for the purpose of a criminal investigation or prosecution or of executing a criminal penalty, punishable by a custodial sentence or detention order “for a maximum period of at least four years”, the maximum incurred, not the sentence handed down. These objectives open a possibility, but they are not a legal basis. Without a national authorising law, the use has been prohibited since 2 February 2025.
What is the penalty for breaching a prohibition?
Article 5 carries the highest penalty in the Regulation: administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(3)).
For SMEs the rule reverses: the lower figure applies. But that reversal does not extend to small mid-cap companies as regards Article 5: Article 99(6a), added by the omnibus, covers only paragraphs 4 and 5. They remain exposed to the highest ceiling.
What should you check in your own organisation?
A prohibited practice is not found in a specification. It is found in a use.
Do we score or classify people, and does that produce detrimental or unfavourable treatment? If so, two branches remain to examine, and the text does not cumulate them: does the treatment occur in social contexts unrelated to those in which the data was generated or collected, and/or is it unjustified or disproportionate to the social behaviour?
Do we infer emotions from biometric data, at work or in training? The text targets biometric inference, not text analysis, and the medical or safety exception is narrow.
Do we build a facial recognition database from untargeted collection? Point (e) admits no exception, and respecting robots.txt is not one.
What this page rests on
Article 5 of Regulation (EU) 2024/1689 in its consolidated version of 27 July 2026, as amended by Regulation (EU) 2026/1744, the authentic text remaining the one published in the Official Journal. The Commission’s guidelines on prohibited AI practices, C(2025) 5052 final of 29 July 2025, in their official English version: non-binding, and predating the two prohibitions added in 2026. Quotations from both are reproduced from the official English texts, never translated. The penalty figures come from Article 99, paragraphs 3, 6 and 6a.
Sources. Regulation (EU) 2024/1689, consolidated text of 27 July 2026 and Regulation (EU) 2026/1744, both consulted on 27 August 2026.
Frequently asked questions
Is scoring people prohibited by the AI Act?
No, and this is the most expensive misreading of the subject. The Commission writes that the scoring of natural persons is not at all times prohibited, but only in the limited cases where all of the conditions of Article 5(1)(c) are cumulatively fulfilled. It names credit scoring, risk scoring, underwriting and specific employee evaluations as practices that are not per se prohibited, provided they are lawful and undertaken in line with the AI Act and other applicable Union law and national law, which must comply with Union law.
Since when do these prohibitions apply?
Eight of them since 2 February 2025. The last two (non-consensual intimate material, and child sexual abuse material or performance) were added by Regulation (EU) 2026/1744 and apply from 2 December 2026, together with the filter in Article 5(1a) and (1b). The penalty regime, for its part, has only applied since 2 August 2025: an obligation can bind before its penalty does.
Is facial recognition prohibited?
Only in one precise case. The prohibition in point (h) covers the use of real-time remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement. It binds deployers. Biometric verification (confirming that a person is who they claim to be) is outside it, as are unlocking a device and secured access to premises. Post-remote identification is not prohibited either: it is high-risk, and it is governed by Article 26(10).
What does a company breaching Article 5 risk?
The highest ceiling in the Regulation: up to EUR 35 000 000 or 7 % of total worldwide annual turnover, whichever is higher, under Article 99(3). For SMEs the rule reverses and the lower figure applies, but that reversal does not extend to small mid-cap companies on Article 5, since Article 99(6a) covers only paragraphs 4 and 5.
This content is a technical and regulatory information resource. It does not constitute legal advice.