Skip to main content
Category: EU AI Act & GPAI

Prohibited AI Practices

Also known as: Article 5 Prohibitions, Prohibited AI Practices under the EU AI Act, Banned AI Practices
Simply put

Prohibited AI practices are specific uses of artificial intelligence that the EU AI Act bans outright because they are considered to pose unacceptable risks to people's rights and safety. According to guidance published by the European Commission, examples include harmful manipulation, social scoring, and certain uses of real-time remote biometric identification. Unlike AI uses that are merely regulated, these practices are not permitted rather than being subject to compliance conditions.

Formal definition

Under Article 5 of the EU AI Act, 'Prohibited AI Practices' designates a category of AI system uses that the Act bars from being placed on the market, put into service, or used within its scope. As drafted, these include AI systems deploying subliminal or manipulative techniques that materially distort behavior, social scoring, and certain real-time remote biometric identification uses, among others enumerated in the Article. The European Commission published guidelines (dated February 4, 2025 per the evidence) intended to clarify the scope and interpretation of these prohibitions. This is a jurisdiction-specific instrument of EU law and should not be read as equivalent to voluntary standards or supervisory guidance from other bodies; the precise list, exceptions, and definitional boundaries of each prohibited practice are set out in the Act's text and remain subject to interpretive guidance. This entry does not reproduce the full enumerated list or exceptions, and readers should consult the authoritative Article 5 text for the complete and current formulation.

Why it matters

Prohibited AI practices represent the most stringent category in the EU AI Act's risk-based structure. Unlike high-risk AI systems, which may be placed on the market subject to compliance conditions, the practices enumerated in Article 5 are barred outright from being placed on the market, put into service, or used within the Act's scope. For organizations, this means the relevant question is not how to build appropriate controls around such a use but whether the use is permissible at all. Misclassifying a prohibited practice as merely high-risk, or assuming that compliance measures can render it acceptable, is therefore a categorical error rather than a matter of adjusting safeguards.

The distinction matters because the underlying rationale is the protection of fundamental rights and safety rather than the management of model performance or accuracy. The European Commission has described the covered practices as including harmful manipulation, social scoring, and certain real-time remote biometric identification uses. According to the WilmerHale analysis cited in the evidence, Article 5 is aimed at practices that materially distort people's behavior or that raise serious concerns in democratic societies. This framing signals that the prohibitions are grounded in rights-based and societal considerations, which is a different analytical lens from the risk-measurement and monitoring focus of model risk management.

Because this is a jurisdiction-specific instrument of EU law, its reach and definitional boundaries are set by the Act's text and by interpretive guidance rather than by supervisory expectations from other bodies. The European Commission published guidelines on the prohibited practices (dated February 4, 2025 per the evidence) intended to clarify their scope and interpretation. Organizations should treat the precise list, exceptions, and definitional edges as matters to be determined by reference to the authoritative Article 5 text and its accompanying guidance, and should be cautious about extrapolating these prohibitions to jurisdictions where the EU AI Act does not apply.

Who it's relevant to

Compliance officers and legal professionals
Those responsible for determining whether a planned or existing AI use falls within the EU AI Act's scope need to distinguish prohibited practices from merely regulated ones, because a prohibited classification means the use cannot proceed rather than proceed under conditions. They will typically need to work from the authoritative Article 5 text and the Commission's guidelines to assess definitional boundaries and any applicable exceptions.
AI governance functions
Teams establishing organizational policies and oversight for AI systems should incorporate screening for prohibited practices early in the lifecycle, so that categorically barred uses are identified before development or procurement rather than at deployment. This is a governance question about permissibility, distinct from the risk-measurement and monitoring activities of model risk management.
Product and data science teams building or deploying AI within the EU's scope
Teams designing AI systems that could implicate manipulation, social scoring, or biometric identification need to understand that certain designs may be prohibited outright, so that effort is not invested in controls for a use that cannot lawfully be placed on the market or put into service within the Act's scope.
Auditors and model risk reviewers
Reviewers assessing an organization's AI portfolio may need to check whether any use maps to an Article 5 prohibition, treating this as a gating determination separate from performance, validation, or residual-risk assessments. Given that definitional boundaries remain subject to interpretive guidance, findings should reference the authoritative text rather than rely on generalized descriptions.

Inside Prohibited AI Practices

Unacceptable-risk category
In the EU AI Act's risk-tiered structure, prohibited practices sit in the highest tier, above high-risk, limited-risk, and minimal-risk classifications. As commonly described, systems falling into this category are banned outright rather than permitted subject to conformity requirements. The precise enumeration and effective dates should be verified against the official text, as the scope has evolved through the legislative process.
Manipulative and exploitative techniques
Practices commonly cited in discussions of this category include AI systems deploying subliminal, manipulative, or deceptive techniques that materially distort behavior in ways likely to cause harm, and systems exploiting vulnerabilities of specific groups such as those tied to age or disability. Readers should confirm the exact conditions and harm thresholds against the enacted text rather than relying on summary descriptions.
Social scoring
Certain forms of social scoring by or on behalf of public authorities, where scores lead to detrimental treatment disconnected from the context in which data was generated or that is unjustified or disproportionate, are typically discussed as prohibited. The exact actors and conditions covered should be checked against the source text.
Biometric and surveillance-related prohibitions
Discussions of this category often reference restrictions on certain biometric categorization, untargeted scraping to build facial recognition databases, and constraints on real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions. The precise carve-outs, safeguards, and permitted exceptions are detailed and should be verified directly.
Jurisdictional scope
This concept is most prominently associated with the EU AI Act, a binding EU regulation, and is not a universal legal standard. Other frameworks such as the NIST AI Risk Management Framework (voluntary, U.S.) or ISO/IEC 42001 (a management-system standard) do not establish an equivalent list of outright prohibitions, and jurisdictions outside the EU may treat similar practices differently or not at all.

Common questions

Answers to the questions practitioners most commonly ask about Prohibited AI Practices.

Do 'prohibited AI practices' refer to a single, universal list that applies to all organizations everywhere?
No. The phrase is most commonly associated with a specific regulatory instrument—the EU AI Act, which is issued by the European Union and identifies certain AI practices it treats as unacceptable. That designation is scoped to that instrument's jurisdiction and its own definitions and conditions; it is not a universal or globally harmonized list. Other frameworks, standards, and jurisdictions may address harmful uses differently or not use the concept of 'prohibited practices' at all. When using this term, professionals should specify which instrument they mean rather than assuming a single authoritative list applies across all contexts.
Does avoiding prohibited practices mean an AI system is compliant or low-risk overall?
No, and this is a frequent error. A prohibition is typically a threshold determination that a particular use is not permitted; steering clear of prohibited uses does not, by itself, establish that a system is compliant with other obligations that may apply to permitted uses, nor that it is low-risk. A system can fall outside any prohibited category and still carry significant risk, trigger other requirements, or require governance controls and risk management. Treating 'not prohibited' as equivalent to 'compliant' or 'safe' conflates a categorical eligibility question with the broader, ongoing task of managing risk and meeting applicable obligations.
How should an organization determine whether one of its AI use cases falls within a prohibited category?
As commonly practiced, this involves mapping the specific use case—its purpose, deployment context, affected persons, and the manner of use—against the precise wording and conditions of the applicable instrument, since prohibitions often turn on narrow qualifying elements rather than the technology alone. Because definitions can be contested and interpretation may evolve, organizations typically involve legal counsel familiar with the relevant jurisdiction rather than relying solely on a technical or business-side reading. Where the analysis is uncertain, documenting the reasoning and any qualifying assumptions supports later review. This assessment sits within AI governance—establishing who is accountable for the determination—while any residual permitted-use risks are handled through model risk management processes.
Who within an organization should be accountable for identifying and screening out prohibited practices?
This is primarily an AI governance question about accountability and oversight rather than a purely technical one. In many organizations that adopt a lines-of-defense structure, the business or development function (first line) surfaces the intended use, a risk or compliance function (second line) provides independent review and challenge against applicable prohibitions, and internal audit (third line) provides assurance over the process. The precise allocation varies by organization and sector, and the term itself does not mandate any particular structure; what matters is that responsibility for the determination is clearly assigned and documented, with legal involvement where the classification is legally significant.
How does screening for prohibited practices fit within a broader AI governance and model risk framework?
Screening for prohibited practices is typically an early gate: it addresses whether a use is permissible at all before other governance and risk activities proceed. It does not replace subsequent steps such as risk classification, validation, monitoring, and controls for uses that are permitted. In practice, organizations often integrate a prohibition check into intake or approval workflows so that ineligible uses are stopped before development or deployment, while permitted uses continue into the risk management lifecycle. Distinguishing this categorical gate from ongoing risk measurement helps avoid collapsing a one-time eligibility question into continuous performance and risk monitoring, which serve different purposes.
What should an organization do if an existing AI system may fall within a prohibited category?
The concept does not itself prescribe a remediation procedure, so responses depend on the applicable instrument and legal advice. In general practice, organizations first confirm the classification with qualified counsel, then assess options such as discontinuing the use, altering the design or deployment context so the qualifying elements no longer apply, or otherwise addressing the exposure. Because such determinations can carry legal consequences, organizations commonly document the analysis, decisions, and any changes made. It should not be assumed that governance controls or mitigations can convert a genuinely prohibited use into a permitted one; where a use is prohibited, the typical outcome is to stop or fundamentally change it rather than to manage residual risk around it.

Common misconceptions

Prohibited AI practices are a globally recognized, uniform list that applies to any organization using AI.
The most cited enumeration of prohibited practices derives from the EU AI Act, which is EU law with defined territorial and material scope. It is not interchangeable with voluntary frameworks like the NIST AI RMF or standards like ISO/IEC 42001, and other jurisdictions may not prohibit the same practices. Applicability depends on the specific legal regime.
If a use case is not on the prohibited list, it is automatically low-risk or unregulated.
Falling outside the prohibited category does not mean a system is unregulated. In a risk-tiered structure, a practice may still fall into high-risk or other categories carrying substantial obligations. The absence of a prohibition addresses only the outright-ban question, not the full set of governance, risk-management, or conformity requirements that may apply.
The prohibitions are absolute with no exceptions.
Several prohibitions are commonly described as subject to narrowly defined conditions, thresholds, or exceptions rather than being unconditional. The exact wording of conditions and carve-outs matters significantly and should be read from the authoritative text, because summaries can overstate or understate the breadth of a ban.

Best practices

Confirm the applicable jurisdiction and legal regime before treating any practice as prohibited; do not assume the EU AI Act's prohibitions apply to activities outside its scope or substitute for other jurisdictions' rules.
Verify the specific prohibited-practice definitions, conditions, thresholds, and exceptions against the authoritative enacted text and current official guidance rather than relying on secondary summaries, as scope and effective dates can evolve.
Screen AI use cases against the prohibited category early in development, and maintain documentation of the assessment so that classification decisions are traceable and reviewable.
Do not treat exclusion from the prohibited tier as a clearance; continue to assess whether the system falls into high-risk or other categories with their own obligations.
Engage legal counsel or qualified compliance specialists for borderline cases, since manipulation, exploitation, and biometric provisions turn on fact-specific and contested interpretive questions.
Integrate prohibition screening into governance structures (policies and accountability) and coordinate with model risk functions where relevant, while recognizing these controls reduce and manage compliance risk rather than eliminate it.