All questions

What AI practices does the EU AI Act prohibit?

EU AI ActLegislation verified on Ook in het Nederlands

Short conclusion. Regulation (EU) 2024/1689 (the "AI Act" / AI-verordening) prohibits eight categories of AI practices that the European legislator considers incompatible with EU values. The list sits in Article 5 of the Regulation, applies across the Union from 2 February 2025, and is enforced by national market-surveillance authorities (see Article 5, Regulation (EU) 2024/1689).


The general rule

Under Article 5(1) of Regulation (EU) 2024/1689, the following AI practices are prohibited:

#Prohibited practice (Article 5(1))What it covers
(a)Harmful subliminal/manipulative techniquesAI using subliminal techniques beyond a person's consciousness or purposefully manipulative techniques that materially distort behaviour and cause significant harm.
(b)Exploitation of vulnerabilitiesAI exploiting vulnerabilities of natural persons due to age, disability or specific social/economic situation to materially distort behaviour and cause significant harm.
(c)Social scoring by public authoritiesEvaluating or classifying persons or groups by social behaviour or personal characteristics, leading to detrimental or unfavourable treatment unrelated to the context or disproportionate.
(d)Predictive policing based on profilingAssessing the risk that a natural person will commit a criminal offence solely on profiling or personality/character traits, except when used to support a human assessment based on objective, verifiable facts.
(e)Untargeted scraping of facial imagesBuilding or expanding facial-recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
(f)Emotion recognition in work/educationInferring emotions of natural persons in the workplace or educational institutions, except for medical or safety reasons.
(g)Sensitive biometric categorisationCategorising individuals based on biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation (with limited law-enforcement exceptions).
(h)Real-time remote biometric identification in public spaces by law enforcement"Real-time" remote biometric identification in publicly accessible spaces for law-enforcement purposes, subject to narrow exceptions.

These prohibitions are placed in Chapter II of the Act and are part of the risk-based pyramid: anything prohibited is considered to present an unacceptable risk and may not be placed on the market, put into service or used in the Union (Article 5(1)).


Why each practice is banned

The eight categories cluster around three policy concerns, which the recitals to the Regulation spell out:

  1. Protecting fundamental rights and dignity. Items (a), (b), (f) and (g) target AI that circumvents a person's autonomy or classifies them on protected grounds. The legislator treats these as a form of manipulation or discrimination the user cannot reasonably resist.
  2. Protecting the public sphere from state overreach. Items (c), (d) and (h) concern the use of AI by public authorities - social scoring, predictive policing and mass biometric surveillance - that could lead to systemic violations of privacy, non-discrimination and the presumption of innocence.
  3. Preventing covert data collection. Item (e) addresses the indiscriminate harvesting of biometric data to build identification infrastructures.

Main exceptions and carve-outs

The general prohibition in Article 5(1) is not absolute. The Act carves out a small number of narrowly defined situations:

  • Emotion recognition (f). Permitted when used for medical or safety reasons - for example, systems intended for therapeutic use or to detect fatigue in pilots or drivers. Pure customer-experience or marketing use in the workplace is still prohibited (Article 5(1)(f)).

  • Biometric categorisation (g). Permitted when the categorisation is necessary for sensitive data labelling, anonymisation or law-enforcement filtering of biometric datasets, or when law enforcement needs to categorise images during investigations (Article 5(1)(g)).

  • Predictive policing (d). Not prohibited when an AI system supports, but does not replace, a human assessment of the risk of offending based on objective and verifiable facts beyond the person's profile (Article 5(1)(d)).

  • Real-time remote biometric identification by law enforcement (h). This is the most heavily qualified prohibition. Under Article 5(1)(h) and Article 5(2)–(7), such use is permitted only for:

    • targeted searches for victims of specific crimes (abduction, sexual exploitation, trafficking, missing persons);
    • prevention of an imminent, substantial threat to life or to a critical infrastructure;
    • locating suspects of serious crimes listed in Annex II (e.g. terrorism, murder, rape, armed robbery, drug trafficking, organised crime) where the offence is punishable by at least four years' imprisonment in the Member State concerned;
    • locating convicted persons fleeing from custody or detention in connection with the offences above.

    Each use must be:

    • necessary and proportionate in time, geography and scope;
    • authorised in advance by a judicial authority or an independent administrative authority of the Member State;
    • logged and notified to the relevant market-surveillance authority and the national data-protection authority, with annual transparency reports submitted to the Commission;
    • limited in time to what is strictly necessary (initial authorisation of up to six months, renewable).
  • National security, defence and military AI. AI systems placed on the market or used exclusively for military, defence or national-security purposes fall outside the scope of the Act altogether (Article 2(3)), so the Article 5 prohibitions do not apply to them. Each Member State remains free to provide its own rules in those areas.

  • Research, testing and pre-market activities. Article 2(6)–(8) contains carve-outs for scientific research and development, and for components supplied for testing before placing on the market.


Practical consequences

  • For providers and deployers. Placing a prohibited system on the market, putting it into service or using it in the Union is unlawful from 2 February 2025 (Article 113(a)). National authorities can order withdrawal, recall or destruction, and the Commission can impose fines of up to EUR 35 million or 7 % of worldwide annual turnover (whichever is higher) under Article 99.
  • For affected workers and students. A common practical impact is that employers and education providers must switch off or remove emotion-recognition and similar manipulative systems in workplaces and classrooms.
  • For affected individuals. Where a prohibited practice is suspected, individuals can complain to the national market-surveillance authority designated by their Member State under Article 70 and seek judicial remedies under Article 85. They may also rely on data-protection law (GDPR, Law Enforcement Directive) in parallel.

In one sentence

Under Regulation (EU) 2024/1689, AI that manipulates, exploits vulnerabilities, social-scores by public bodies, predicts crime from personality traits alone, scrapes faces for recognition databases, reads emotions at work or in school, categorises people by sensitive biometric traits, or performs untargeted real-time biometric surveillance in public spaces is prohibited - with only narrow, judicially authorised exceptions for certain law-enforcement uses.

For the official consolidated text, see Regulation (EU) 2024/1689 of the European Parliament and of the Council on EUR-Lex.

This article is informational only and does not constitute legal advice. For a binding assessment of a specific AI system or use case, consult a qualified lawyer in the relevant Member State.