Skip to main content
v2026.11,610 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.1

EU AI Act Article 5 (Prohibited AI Practices)

Article 5 of Regulation (EU) 2024/1689 (the EU AI Act) lists AI practices that are banned outright across the EU, regardless of sector, risk classification, or intended purpose — including scientific research. A practice falls under Article 5 if it matches one of eight prohibited categories: (a) subliminal or purposefully manipulative/deceptive techniques that materially distort behaviour and cause significant harm; (b) exploitation of vulnerabilities tied to age, disability, or a specific social or economic situation; (c) social scoring by public or private actors leading to detrimental treatment in a context unrelated to the data that generated the score; (d) predictive policing based solely on profiling or personality-trait assessment, without objective, verifiable facts linked to a criminal activity; (e) untargeted scraping of facial images from the internet or CCTV footage to build or expand facial-recognition databases; (f) emotion inference in workplace or education settings, except for narrow medical or safety reasons; (g) biometric categorisation to infer race, political opinion, trade union membership, religion, sex life, or sexual orientation; and (h) real-time remote biometric identification in publicly accessible spaces for law enforcement, prohibited except for three narrowly defined purposes (searching for specific victims of trafficking or missing persons, preventing an imminent and specific terrorist threat, or locating a suspect in specific serious crimes carrying at least a 4-year custodial sentence), each requiring prior judicial or independent administrative authorisation. These provisions applied from 2 February 2025 — six months ahead of most of the rest of the Act — and unlike the Act's high-risk-system obligations, there is no proportionality test, self-assessment route, or conformity-assessment pathway around them: a matching practice is unlawful outright, and violations sit in the Act's highest penalty tier under Article 99 (administrative fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher).

ByCASRAI Editorial Board
· Last updated 23 Jul 2026

Ask about EU AI Act Article 5 (Prohibited AI Practices)

Answers are drawn from this dictionary entry and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Examples

Worked examples

  • Is an instance

    A university lab building an emotion-recognition system to flag student disengagement or attention during online exams or lectures falls within the Article 5(1)(f) prohibition on inferring emotions in an educational setting — even though the goal is pedagogical research rather than commercial deployment — unless it fits the narrow medical or safety carve-out.

  • Is an instance

    A research consortium scraping publicly posted photographs or CCTV stills, without consent, to assemble a facial-recognition training dataset falls under Article 5(1)(e)'s ban on untargeted scraping of facial images, regardless of whether the resulting model is intended purely for academic benchmarking rather than commercial sale.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A university HR-analytics pilot that scores postdoc candidates against a rubric built from objective, verifiable job-related criteria (verified qualifications, publication record) is not itself an Article 5 social-scoring or predictive-profiling practice. It may still be a high-risk AI system under Annex III (employment-related use), triggering full risk-management, human-oversight, and conformity-assessment duties — but it is not among the outright Article 5 prohibitions unless it also evaluates unrelated social behaviour and applies the resulting score in an unrelated context.

Editorial commentary

Article 5 of Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, is the Act’s list of AI practices the EU treats as unacceptable-risk and bans outright — not regulated, not requiring a conformity assessment, simply prohibited. This sits apart from the Act’s much larger high-risk framework (Annex III), which imposes obligations — risk management, data governance, human oversight, conformity assessment — on AI systems that remain lawful to deploy. Article 5 practices are not eligible for that route: if a system’s function matches one of the eight prohibited categories, deploying it in the EU (or affecting people in the EU) is unlawful regardless of sector, deployer type, or stated purpose.

The eight prohibited categories

  • Subliminal or manipulative techniques that materially distort a person’s behaviour by impairing their ability to make an informed decision, causing significant harm.
  • Exploitation of vulnerabilities due to age, disability, or a specific social or economic situation, again where it materially distorts behaviour and causes significant harm.
  • Social scoring — evaluating or classifying people over time based on social behaviour or inferred personal characteristics, where the resulting score is then used to their detriment in a context unrelated to where the data was generated.
  • Predictive policing based solely on profiling — assessing someone’s risk of committing a criminal offence based only on profiling or personality-trait assessment, without objective, verifiable facts directly linked to criminal activity.
  • Untargeted scraping of facial images from the internet or CCTV footage to build or expand facial-recognition databases.
  • Emotion inference in workplace or education settings, except where used for narrow medical or safety purposes.
  • Biometric categorisation that infers race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation from biometric data.
  • Real-time remote biometric identification (RBI) in publicly accessible spaces for law enforcement — banned by default, with three narrow exceptions (targeted search for victims of trafficking/missing persons, preventing an imminent and specific terrorist threat, or locating a suspect in a specific serious crime carrying at least a 4-year custodial sentence), each requiring prior judicial or independent administrative authorisation and registration in an EU database.

These provisions applied from 2 February 2025 — the earliest compliance date in the whole Act, six months ahead of most other obligations — and the European Commission issued draft guidelines on 4 February 2025 to clarify their scope and give worked examples ahead of the Article 99 penalty regime taking effect. Violations of Article 5 sit in the Act’s highest penalty tier: administrative fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher — more than double the tier applied to most other AI Act non-compliance.

Why the Act’s research exemptions do not reach Article 5

Research institutions are used to the AI Act carving out space for pure research: Article 2(6) excludes AI systems or models developed and put into service solely for scientific research and development from the Regulation entirely, and Article 2(8) excludes research, testing, and development activity prior to an AI system being placed on the market or put into service. Neither exemption reaches Article 5. Article 2(8)’s own text limits the research/testing exclusion to activity that does not amount to real-world testing — the moment a prohibited-practice-shaped system is tested on real people (student cohorts, research participants, job applicants, the public), that exclusion no longer applies, and Article 5 governs the activity directly. In practice this means the purpose-based exemptions that meaningfully soften the Act’s high-risk obligations for university and institute research programmes (see CASRAI’s guide to EU AI Act obligations and exemptions for research organisations) do essentially nothing for a project that falls within Article 5 — a research purpose does not make an otherwise-prohibited practice lawful.

Worked examples for research institutions

Article 5 issues surface most often in research contexts that involve behavioural inference, biometric data, or scoring of people, even when framed as academic rather than commercial work:

  • An emotion-recognition tool built to flag student attention or disengagement during online exams or lectures falls within the Article 5(1)(f) education-emotion-inference ban, regardless of research intent, unless it genuinely fits the narrow medical/safety exception.
  • Scraping publicly available photographs or CCTV stills without consent to build a facial-recognition training or benchmarking dataset falls under the Article 5(1)(e) prohibition on untargeted facial-image scraping, whether or not the resulting model is ever commercialised.

By contrast, an AI-assisted evaluation tool that scores candidates or applicants against objective, verifiable, job- or study-related criteria is not itself an Article 5 social-scoring or profiling-based practice — it may still land in the Act’s high-risk category under Annex III (for example, employment- or education-access-related AI systems), which brings its own risk-management, human-oversight, and conformity-assessment obligations, but that is a materially different (and less absolute) compliance path than an outright Article 5 ban.

Related CASRAI content

This is a fast-moving area of EU regulation. The Commission’s Article 5 guidelines were issued as non-binding draft guidance in February 2025; institutions with an Article 5-adjacent research activity should confirm current status directly against the AI Act Service Desk rather than relying on a static summary.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="EU AI Act Article 5 (Prohibited AI Practices)"
      vocab-term-identifier="https://casrai.org/dictionary/term/eu-ai-act-article-5-prohibited-ai-practices" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/eu-ai-act-article-5-prohibited-ai-practices",
  "name": "EU AI Act Article 5 (Prohibited AI Practices)",
  "identifier": "https://casrai.org/dictionary/term/eu-ai-act-article-5-prohibited-ai-practices",
  "description": "Article 5 of Regulation (EU) 2024/1689 (the EU AI Act) lists AI practices that are banned outright across the EU, regardless of sector, risk classification, or intended purpose — including scientific research. A practice falls under Article 5 if it matches one of eight prohibited categories: (a) subliminal or purposefully manipulative/deceptive techniques that materially distort behaviour and cause significant harm; (b) exploitation of vulnerabilities tied to age, disability, or a specific social or economic situation; (c) social scoring by public or private actors leading to detrimental treatment in a context unrelated to the data that generated the score; (d) predictive policing based solely on profiling or personality-trait assessment, without objective, verifiable facts linked to a criminal activity; (e) untargeted scraping of facial images from the internet or CCTV footage to build or expand facial-recognition databases; (f) emotion inference in workplace or education settings, except for narrow medical or safety reasons; (g) biometric categorisation to infer race, political opinion, trade union membership, religion, sex life, or sexual orientation; and (h) real-time remote biometric identification in publicly accessible spaces for law enforcement, prohibited except for three narrowly defined purposes (searching for specific victims of trafficking or missing persons, preventing an imminent and specific terrorist threat, or locating a suspect in specific serious crimes carrying at least a 4-year custodial sentence), each requiring prior judicial or independent administrative authorisation. These provisions applied from 2 February 2025 — six months ahead of most of the rest of the Act — and unlike the Act's high-risk-system obligations, there is no proportionality test, self-assessment route, or conformity-assessment pathway around them: a matching practice is unlawful outright, and violations sit in the Act's highest penalty tier under Article 99 (administrative fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher).",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/eu-ai-act-article-5-prohibited-ai-practices",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-23T08:50:56",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →