Prohibited AI Practices
Prohibited AI Practices are specific uses of artificial intelligence that the EU Artificial Intelligence Act bans outright because they are considered to pose unacceptable risks to people and society. Examples the European Commission has highlighted include harmful manipulation, social scoring, and certain forms of real-time remote biometric identification. Unlike voluntary standards, this is a legal prohibition, meaning organizations within the Act's scope generally may not place such systems on the market, put them into service, or use them.
Prohibited AI Practices refers to the categorical bans set out in Article 5 of the EU Artificial Intelligence Act, a binding EU regulation. Article 5 prohibits the placing on the market, putting into service, or use of AI systems falling within enumerated categories—reported by the Commission and commentators to include AI that deploys subliminal or otherwise harmful manipulative techniques materially distorting behavior, social scoring, and certain uses of real-time remote biometric identification, among others. The prohibitions function as an outright ban rather than a risk-management or conformity-assessment obligation, and are distinct from the Act's separate regimes for high-risk and limited-risk AI systems. Enforcement began to apply on a staggered timeline, with the prohibited-practices provisions among the earliest to take effect; the European Commission has issued guidelines interpreting these practices. The precise scope, definitions, exceptions (such as narrowly framed law-enforcement carve-outs for biometric identification), and applicability conditions are set by the Act's text and evolving guidance, and readers should verify article-level details, effective dates, and interpretive guidelines against the current official EU sources. This entry is informational and does not address how the prohibitions apply to any particular AI system, which requires case-specific professional judgment.
Why it matters
Prohibited AI Practices represent the strictest tier of the EU Artificial Intelligence Act. Unlike the Act's high-risk regime, which permits deployment subject to conformity assessments and risk-management obligations, the practices enumerated in Article 5 are banned outright—organizations within the Act's scope generally may not place such systems on the market, put them into service, or use them at all. This categorical nature means there is no compliance pathway to legitimize an in-scope prohibited system; the response is to avoid the practice entirely. Because this is a binding EU regulation rather than a voluntary standard, the consequences of non-compliance are legal rather than merely reputational or contractual.
The practical significance is heightened by timing. The prohibited-practices provisions were among the earliest parts of the Act to take effect under its staggered enforcement timeline, meaning organizations faced these obligations before many other requirements applied. The European Commission has published guidelines interpreting these practices, addressing categories such as harmful manipulation, social scoring, and certain real-time remote biometric identification. Firms deploying AI that could touch on behavioral influence, scoring of individuals, or biometric systems should assess exposure early rather than treating the Act as a distant future obligation.
The scope, definitions, and exceptions—including narrowly framed law-enforcement carve-outs for biometric identification—are set by the Act's text and evolving guidance, and interpretation is still developing. Whether a given system falls within a prohibition is fact-specific and often turns on fine distinctions, so readers should verify article-level details and the current Commission guidelines against official EU sources rather than relying on general characterizations.
Who it's relevant to
Inside Prohibited AI Practices
Common questions
Answers to the questions practitioners most commonly ask about Prohibited AI Practices.

