Prohibited AI Practices
Prohibited AI practices are specific uses of artificial intelligence that the EU AI Act bans outright because they are considered to pose unacceptable risks to people's rights and safety. According to guidance published by the European Commission, examples include harmful manipulation, social scoring, and certain uses of real-time remote biometric identification. Unlike AI uses that are merely regulated, these practices are not permitted rather than being subject to compliance conditions.
Under Article 5 of the EU AI Act, 'Prohibited AI Practices' designates a category of AI system uses that the Act bars from being placed on the market, put into service, or used within its scope. As drafted, these include AI systems deploying subliminal or manipulative techniques that materially distort behavior, social scoring, and certain real-time remote biometric identification uses, among others enumerated in the Article. The European Commission published guidelines (dated February 4, 2025 per the evidence) intended to clarify the scope and interpretation of these prohibitions. This is a jurisdiction-specific instrument of EU law and should not be read as equivalent to voluntary standards or supervisory guidance from other bodies; the precise list, exceptions, and definitional boundaries of each prohibited practice are set out in the Act's text and remain subject to interpretive guidance. This entry does not reproduce the full enumerated list or exceptions, and readers should consult the authoritative Article 5 text for the complete and current formulation.
Why it matters
Prohibited AI practices represent the most stringent category in the EU AI Act's risk-based structure. Unlike high-risk AI systems, which may be placed on the market subject to compliance conditions, the practices enumerated in Article 5 are barred outright from being placed on the market, put into service, or used within the Act's scope. For organizations, this means the relevant question is not how to build appropriate controls around such a use but whether the use is permissible at all. Misclassifying a prohibited practice as merely high-risk, or assuming that compliance measures can render it acceptable, is therefore a categorical error rather than a matter of adjusting safeguards.
The distinction matters because the underlying rationale is the protection of fundamental rights and safety rather than the management of model performance or accuracy. The European Commission has described the covered practices as including harmful manipulation, social scoring, and certain real-time remote biometric identification uses. According to the WilmerHale analysis cited in the evidence, Article 5 is aimed at practices that materially distort people's behavior or that raise serious concerns in democratic societies. This framing signals that the prohibitions are grounded in rights-based and societal considerations, which is a different analytical lens from the risk-measurement and monitoring focus of model risk management.
Because this is a jurisdiction-specific instrument of EU law, its reach and definitional boundaries are set by the Act's text and by interpretive guidance rather than by supervisory expectations from other bodies. The European Commission published guidelines on the prohibited practices (dated February 4, 2025 per the evidence) intended to clarify their scope and interpretation. Organizations should treat the precise list, exceptions, and definitional edges as matters to be determined by reference to the authoritative Article 5 text and its accompanying guidance, and should be cautious about extrapolating these prohibitions to jurisdictions where the EU AI Act does not apply.
Who it's relevant to
Inside Prohibited AI Practices
Common questions
Answers to the questions practitioners most commonly ask about Prohibited AI Practices.