Free template · Excel · English and Dutch
Prohibited AI practices checklist: Excel template for Article 5 of the EU AI Act
A prohibited AI practices screening checks whether an AI system falls under a prohibition in Article 5 of the EU AI Act, such as emotion recognition in the workplace or social scoring. The prohibitions have applied to providers and deployers since 2 February 2025. Two new prohibitions, on non-consensual intimate images and child sexual abuse material, apply from 2 December 2026.
- Last checked against the law
- Editor
- Zahed Ashkara, jurist, privacy and AI
- Version and template ID
- 2.0 ·
praxikon:template:prohibited-practices-screening - Legal basis
- Articles 2, 3, 5, 99 and 113 of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744; Articles 9 and 22 GDPR
Who is this template for?
- Privacy officer, data protection officer (DPO) or compliance officer who keeps the AI registerScreening per system, record-keeping and review (Art. 5(1); for biometrics also Articles 9 and 35 GDPR)
- Procurement, IT and process owners of purchased AI systems (deployer)The prohibitions also cover use, not only the supplier (Art. 5(1); Art. 3(4))
- Product teams and developers offering AI under their own name (provider)Do not place on the market or put into service; safeguards against intimate images and child sexual abuse material (Art. 5(1a)(a))
- HR, recruitment and selectionEmotion recognition in the workplace, including job candidates (Art. 5(1)(f))
- Education institutions and providers of assessment and learning softwareEmotion recognition of pupils and students (Art. 5(1)(f))
- Marketing, customer service and loyalty programmesManipulation, exploitation of vulnerabilities and social scoring (Art. 5(1)(a), (b) and (c))
What is inside
- Screening tab: for each AI system the scope (Articles 2 and 3) and all ten prohibitions in Article 5(1), with the exact conditions, exceptions and a calculated outcome per prohibition
- Separate questions for provider and deployer under the new prohibitions (ba) and (bb) (Article 5(1a)), plus the editing exception in Article 5(1b)
- Overall outcome STOP, STOP (from 2 Dec 2026), ESCALATE or No prohibited practice; relying on any exception leads to ESCALATE
- Record of the decision, measures, legal opinion and next review, with a check that the decision matches the outcome
- Example tab: a completed fictitious screening of a contact centre conversation coach with an emotion module
- Overview tab: register of all screenings, with four fictitious example rows
- Boundaries and examples tab: for each prohibition a case that is covered, a borderline case that is not, and the rules that apply instead
- Article 5 verbatim tab: consolidated text of Article 5(1), (1a) and (1b) and the definitions used from Article 3
- Dates and fines tab: application dates (Article 113), maximum fines (Article 99) and how supervision is organised
- Back page with three signals that you need legal advice
How to use the template
- Copy the Screening tab for each AI system and name the copy after the ID in your AI register.
- Fill in the system details and check the scope (step 0): is it an AI system, what is your role, and does an exclusion apply? Screen the whole system, including functions that are switched off.
- Answer the conditions of each prohibition with Yes, No or Don't know. One No on a condition is enough: that prohibition then does not apply.
- Read the outcome. With STOP you do not place the system on the market or you stop using it; with ESCALATE you first have a legal adviser assess whether the prohibition applies.
- Record the decision, the measures and the next review at the bottom, and enter the outcome in the Overview tab.
- Screen again with a new function, a new purpose or a new supplier version, and before 2 December 2026 for image, video and voice generators.
Common mistakes
- Looking only at intent. For manipulation and exploitation of vulnerabilities (points (a) and (b)) the effect also counts, and a function that is off now but can be switched on later belongs in the screening.
- Assuming the prohibitions only bind the supplier. If you, as deployer, use emotion recognition in the workplace, you infringe the prohibition yourself; a contract or CE marking does not change that.
- Drawing the line on emotion recognition in the wrong place. The prohibition concerns emotions inferred from biometric data such as voice or face (Article 3(39)). Sentiment analysis of written text and fatigue detection are not covered; voice analysis of employees is.
- Assuming an exception yourself, such as a medical or safety reason or support for a human assessment. Exceptions are narrow and must be substantiated by whoever relies on them; always have this reviewed.
- Forgetting the new prohibitions. The prohibitions on non-consensual intimate images and child sexual abuse material (points (ba) and (bb)) apply from 2 December 2026; providers of systems that can foreseeably produce such material must then have reasonable and adequate safeguards in place.
Prefer to work online? Annex III classification check
When do you need legal advice?
- The conclusion rests on an exception. You want to offer or use a system on the basis of an exception, such as medical or safety reasons for emotion recognition (Art. 5(1)(f)) or support for a human assessment based on objective facts (point (d)). The provider or deployer relying on it must be able to substantiate that exception.
- A purchased system has a function that may fall under a prohibition. For example emotion analysis of employees, or an image generator that can create intimate or sexually explicit images of real persons. The provider may not place emotion recognition in the workplace on the market for that purpose, and you may not use it that way (Art. 5(1)(f)). For intimate images and child sexual abuse material (from 2 December 2026), the prohibition applies to the provider under Art. 5(1a)(a); to you as deployer only if you use the system to create such material (Art. 5(1a)(b)). Have the contract and settings reviewed.
- The system processes biometric or other sensitive data. Facial images, voice or inferred characteristics such as religion or health. In addition to Article 5, Art. 9 GDPR then often applies: for biometric data processed to uniquely identify a person (with narrow national exceptions, in the Netherlands Article 29 of the Dutch GDPR Implementation Act, UAVG) or where health, religion or other special categories of data are processed or inferred. A DPIA (data protection impact assessment, Art. 35 GDPR) is often required; you carry those duties as controller.
Frequently asked questions
Which AI practices are prohibited under the EU AI Act?
Article 5(1) prohibits, among other things, manipulation and deception causing significant harm, exploitation of vulnerabilities, social scoring, predicting criminal offences based solely on profiling, untargeted scraping of facial images, emotion recognition in the workplace and in education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement. The Digital Omnibus (Regulation (EU) 2026/1744) adds non-consensual intimate images and child sexual abuse material (points (ba) and (bb)).
Since when do the prohibitions apply?
The prohibitions in Article 5 have applied since 2 February 2025. The two new prohibitions under points (ba) and (bb), together with paragraphs 1a and 1b, apply from 2 December 2026 (Article 113(a), as amended by Regulation (EU) 2026/1744, in force since 27 July 2026). Status: 6 October 2026.
Do the prohibitions apply if we only buy an AI system?
Yes. The prohibitions cover placing on the market, putting into service and using an AI system, so they also bind you as deployer. For the new prohibitions on intimate images and child sexual abuse material, Article 5(1a) divides the duty by role: the provider may not place on the market a system intended for this, or one that can foreseeably produce it without reasonable and adequate safeguards, and the deployer infringes the prohibition if it uses the system to generate such material.
What is the maximum fine for a prohibited AI practice?
Up to EUR 35 million or, for an undertaking, up to 7% of its total worldwide annual turnover, whichever is higher (Article 99(3)). This is a maximum that Member States must build into their own rules on penalties. For SMEs and start-ups the lower amount applies (Article 99(6)); small mid-cap enterprises get no reduction for Article 5, because Article 99(6a) only covers paragraphs 4 and 5. Check which authority supervises in your Member State: the Netherlands, for example, had not designated a market surveillance authority for the AI Act or adopted an implementing act as of 6 October 2026.
Is emotion recognition always prohibited?
No. The prohibition only applies in the workplace and in education, and not where the system is put in place for medical or safety reasons (Article 5(1)(f)). Elsewhere emotion recognition is high-risk (Annex III, point 1(c); obligations from 2 December 2027) and, as deployer, you must inform the persons exposed (Article 50(3), applicable since 2 August 2026).
May I use this template freely?
Yes. You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place. The workbook is a tool, not legal advice; with an ESCALATE outcome or when relying on an exception, have the system assessed by a legal adviser.
Use and credit
You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.
How to cite this template: Source: Praxikon, Prohibited AI practices checklist: Excel template for Article 5 of the EU AI Act, version 2.0, as of 6 October 2026, https://www.praxikon.com/en/templates/prohibited-practices-checklist
This template is a tool, not legal advice for your situation. It reflects the law as of 6 October 2026. Legislation, guidance and supervisory practice may change after that date. Using this template does not guarantee compliance: applying it in your organisation remains your own responsibility.
Praxikon is a trade name of Embed AI · Chamber of Commerce 90283597