Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: AI Governance

Prohibited AI Practices

Also known as: Article 5 Prohibited Practices, Banned AI Practices, Prohibited AI Systems
Simply put

Prohibited AI Practices are specific uses of artificial intelligence that the EU Artificial Intelligence Act bans outright because they are considered to pose unacceptable risks to people and society. Examples the European Commission has highlighted include harmful manipulation, social scoring, and certain forms of real-time remote biometric identification. Unlike voluntary standards, this is a legal prohibition, meaning organizations within the Act's scope generally may not place such systems on the market, put them into service, or use them.

Formal definition

Prohibited AI Practices refers to the categorical bans set out in Article 5 of the EU Artificial Intelligence Act, a binding EU regulation. Article 5 prohibits the placing on the market, putting into service, or use of AI systems falling within enumerated categories—reported by the Commission and commentators to include AI that deploys subliminal or otherwise harmful manipulative techniques materially distorting behavior, social scoring, and certain uses of real-time remote biometric identification, among others. The prohibitions function as an outright ban rather than a risk-management or conformity-assessment obligation, and are distinct from the Act's separate regimes for high-risk and limited-risk AI systems. Enforcement began to apply on a staggered timeline, with the prohibited-practices provisions among the earliest to take effect; the European Commission has issued guidelines interpreting these practices. The precise scope, definitions, exceptions (such as narrowly framed law-enforcement carve-outs for biometric identification), and applicability conditions are set by the Act's text and evolving guidance, and readers should verify article-level details, effective dates, and interpretive guidelines against the current official EU sources. This entry is informational and does not address how the prohibitions apply to any particular AI system, which requires case-specific professional judgment.

Why it matters

Prohibited AI Practices represent the strictest tier of the EU Artificial Intelligence Act. Unlike the Act's high-risk regime, which permits deployment subject to conformity assessments and risk-management obligations, the practices enumerated in Article 5 are banned outright—organizations within the Act's scope generally may not place such systems on the market, put them into service, or use them at all. This categorical nature means there is no compliance pathway to legitimize an in-scope prohibited system; the response is to avoid the practice entirely. Because this is a binding EU regulation rather than a voluntary standard, the consequences of non-compliance are legal rather than merely reputational or contractual.

The practical significance is heightened by timing. The prohibited-practices provisions were among the earliest parts of the Act to take effect under its staggered enforcement timeline, meaning organizations faced these obligations before many other requirements applied. The European Commission has published guidelines interpreting these practices, addressing categories such as harmful manipulation, social scoring, and certain real-time remote biometric identification. Firms deploying AI that could touch on behavioral influence, scoring of individuals, or biometric systems should assess exposure early rather than treating the Act as a distant future obligation.

The scope, definitions, and exceptions—including narrowly framed law-enforcement carve-outs for biometric identification—are set by the Act's text and evolving guidance, and interpretation is still developing. Whether a given system falls within a prohibition is fact-specific and often turns on fine distinctions, so readers should verify article-level details and the current Commission guidelines against official EU sources rather than relying on general characterizations.

Who it's relevant to

AI developers and providers
Organizations that build or place AI systems on the EU market need to determine early whether any of their products could fall within an Article 5 category, since a prohibited system cannot be brought into compliance through assessment—it must not be marketed or put into service in scope. Design decisions around manipulation, scoring, or biometric functionality warrant particular scrutiny against the current guidelines.
Deployers and users of AI systems
Article 5 prohibits not only placing systems on the market but also their use, so organizations that deploy third-party AI—not just those that build it—may be exposed. Deployers should evaluate whether their intended use of a system, including how it influences behavior or scores individuals, could fall within a banned category.
Compliance officers and legal counsel
Those responsible for regulatory adherence need to track the staggered enforcement timeline, under which the prohibited-practices provisions took effect among the earliest, and interpret the Commission's guidelines. Because scope and exceptions are still evolving, they should verify article-level details against official EU sources and apply case-specific judgment.
Law enforcement and public-sector bodies
Certain prohibitions, notably around real-time remote biometric identification, involve narrowly framed law-enforcement carve-outs. Public authorities considering such systems should assess whether their intended use falls within any exception and the strict conditions attached, verified against the Act's text and guidance.

Inside Prohibited AI Practices

Unacceptable-Risk Category
Under the EU AI Act, prohibited practices sit at the top of the risk-based tiering as the 'unacceptable risk' category. Unlike high-risk systems (which are permitted subject to strict obligations), practices in this category are banned outright rather than merely regulated. Readers should verify the specific listed practices and any exceptions against the current official text of the Act.
Examples of Prohibited Practices
The Act generally identifies certain AI uses as prohibited, which commonly include practices such as manipulative or deceptive techniques that materially distort behaviour and cause harm, exploitation of vulnerabilities of specific groups, certain forms of social scoring by public authorities, and particular uses of biometric or real-time remote identification. The precise scope, definitions, and carve-outs are fact-specific; confirm against the enacted text and any implementing guidance.
Narrow Exceptions and Conditions
Several prohibitions are not absolute and may be subject to defined exceptions or conditions (for example, limited law-enforcement circumstances for certain biometric identification). Whether a given use falls inside or outside a prohibition typically depends on purpose, context, and safeguards, so a use may be banned in one configuration and permitted or high-risk in another.
Jurisdictional and Extraterritorial Scope
These prohibitions are a feature of the EU AI Act, a binding EU regulation, and are not a universal global standard. The Act can reach providers and deployers outside the EU where their AI systems' outputs are used within the Union. Other jurisdictions (for example the United States or the United Kingdom) address prohibited or restricted AI uses differently or through separate instruments.
Enforcement and Consequences
As binding law, breach of a prohibition carries legal consequences rather than the loss of a voluntary certification. Penalty structures and enforcement mechanisms are set out in the Act, but enforcement practice is still developing; specific amounts and procedures should be verified against the current official text and competent authority guidance.

Common questions

Answers to the questions practitioners most commonly ask about Prohibited AI Practices.

Does the prohibition on certain AI practices apply worldwide?
No. The prohibited practices addressed here derive from the EU AI Act, which is EU legislation. Its scope is defined by that regulation, and it may reach providers or deployers established outside the EU where their AI systems affect persons in the EU, giving it a degree of extraterritorial reach. However, it is not a universal global ban. Other jurisdictions such as the United States and the United Kingdom regulate AI through different and often sector-specific mechanisms, and their treatment of comparable practices may differ. Readers should not assume that a practice prohibited under EU law is prohibited elsewhere, or vice versa, and should verify obligations against the law applicable in each relevant jurisdiction.
Are prohibited AI practices simply a category of high-risk AI systems with stricter controls?
No, and this distinction matters. Prohibited practices and high-risk systems are separate categories. High-risk AI systems are permitted subject to conformity requirements, documentation, and other obligations; they can generally be placed on the market once those conditions are met. Prohibited practices, by contrast, are not permitted to be brought into use at all within the regulation's scope, regardless of the controls applied. Treating a prohibited practice as merely a high-risk system to be mitigated misreads the framework. Whether a specific use case falls into the prohibited category or the high-risk category depends on the facts and on the precise wording of the applicable provisions, which should be checked against the current official text.
How can an organization determine whether one of its AI systems falls within a prohibited practice?
The starting point is a fact-specific mapping of the system's purpose, functioning, and intended use against the prohibited categories set out in the applicable text. Because these categories are defined by specific criteria and often carry exceptions or qualifying conditions, classification is rarely mechanical and generally benefits from combined legal, technical, and domain input. Interpretations of some categories are still evolving, and enforcement practice may develop over time. Organizations should document their reasoning, revisit assessments as systems change, and verify their analysis against the latest authoritative sources rather than relying on a one-time determination. Application to a particular system requires professional judgment.
What should an organization do if it discovers an existing system may involve a prohibited practice?
As a general matter, a system that involves a prohibited practice cannot be brought into compliance through additional safeguards, because the practice itself is not permitted within the regulation's scope. Where a system appears to fall into a prohibited category, organizations typically consider whether the prohibited functionality can be removed, whether the use case can be redesigned so it no longer meets the prohibited criteria, or whether the system should be withdrawn. Each of these paths depends on the specific facts and on how the relevant provisions are interpreted. This is informational only; decisions about a particular system require professional judgment and should reflect the current official text.
How does the prohibited practices analysis fit into a broader AI compliance program?
Screening for prohibited practices generally functions as an early, threshold step, because it can determine whether a use case is viable at all before resources are spent on high-risk conformity work, documentation, or other obligations. Many organizations integrate this screening into intake or inventory processes for AI systems, so that classification questions are raised before deployment. It is important to keep this analysis distinct from high-risk classification and from voluntary standards or frameworks an organization may also adopt, since those serve different purposes and do not substitute for the legal prohibition. The appropriate structure depends on organizational context.
Does adopting a recognized AI standard or framework ensure a system avoids prohibited practices?
No. Voluntary standards and frameworks can support good governance, risk management, and documentation, but conformance to a standard does not by itself establish that a system avoids a prohibited practice under applicable law. The prohibition is a legal question determined by the relevant regulation, not by a certification or framework alignment. A system could align with a governance framework and still involve a prohibited practice, or fall outside the prohibited categories without adopting any particular standard. Organizations should treat standards as complementary to, not a replacement for, direct analysis against the applicable legal text, which they should verify against the current authoritative source.

Common misconceptions

Prohibited AI practices are just high-risk systems with extra paperwork.
Prohibited practices and high-risk systems are distinct tiers. High-risk systems are permitted provided obligations are met; prohibited practices are banned outright and cannot be brought into compliance through documentation or safeguards. The two categories should not be conflated.
These prohibitions are a global rule that applies to all AI everywhere.
The prohibitions derive from the EU AI Act, an EU regulation, not a universal standard. They apply within the EU's scope and can extend extraterritorially where outputs are used in the Union, but other jurisdictions regulate AI through different frameworks. Do not assume one region's ban applies universally.
If a practice appears on the prohibited list, it is banned in every circumstance without exception.
Some prohibitions carry defined exceptions or conditions, and classification is fact-specific. A use may be prohibited in one configuration yet fall outside the prohibition or into another risk tier in a different context. Application to particular circumstances requires professional judgment and review of the current text.

Best practices

Verify the current list of prohibited practices, their definitions, and any exceptions directly against the enacted EU AI Act text and official implementing guidance, as scope and interpretation continue to evolve.
Assess AI systems against the risk tiers early, and treat 'unacceptable risk' as a hard boundary that documentation or safeguards cannot cure, rather than a stricter version of high-risk obligations.
Determine jurisdictional reach for each system, including whether outputs are used within the EU, and separately check obligations under other applicable regimes such as those in the US or UK.
Analyze intended purpose and deployment context for each use case, since the same technology may be prohibited, high-risk, or lower-risk depending on configuration and safeguards.
Where a use may sit near a narrow exception (for example limited law-enforcement scenarios), document the legal basis and conditions carefully and obtain qualified legal review before proceeding.
Establish a monitoring process to track amendments, guidance, and enforcement practice over time, and treat classifications as subject to revision rather than permanent.
Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.