Praxikon
All obligations
Applicablev1.0.0

Article 5: prohibited practices

The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.

The official source remains authoritative. This general interpretation is not legal advice.

Status
Applicable
Application date
2 February 2025
Version
1.0.0
Last reviewed
8 August 2026

Who this is relevant to

When this applies

  • Deployer

    An organisation using an AI system under its authority, excluding personal non-professional use.

  • Provider of an AI system

    A party that develops or has an AI system developed and places it on the market under its own name.

  1. 1Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement.

What the official source establishes

The prohibited practices of Article 5 apply since 2 February 2025 and are the only AI Act category enforceable for that entire period. Violations carry the highest fine ceiling in the regulation: up to 35 million euro or 7 percent of worldwide annual turnover.

The Digital Omnibus adds a prohibition on AI for child sexual abuse material and non-consensual intimate synthetic content; the accompanying technical safeguards are required by 2 December 2026.

Our interpretation

The line often sits in the definitional details: the same technique can be prohibited in the workplace and permitted in another context. Screen per concrete use and context, not per technology, and do so before procurement or go-live.

What you can do now

Make the Article 5 screening the first step of every classification and record the outcome per system in the register, including the reasoning why a practice does not fall under the prohibition.

  1. 01

    Screen every use case against Article 5 first

    Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.

What to retain

Article 5 screening record

A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion "no prohibited practice" is evidence too.

Control and reassessment

  • Article 5 gate at intake and change

    Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.

Public tools

Conditions and exceptions

  • The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 5, Article 99(3) and Article 113(a)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amendment to Article 5 and transition to 2 December 2026

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 5(1)(a)-(h)

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 5 read with Article 6 classification order

What changed in this

Moments when this obligation took effect, moved or received official guidance.

  • 2026-12-02 | upcoming

    New prohibitions require technical safeguards

    The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.

  • 2025-07-29 | guidance

    Guidelines on prohibited AI practices

    Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.

  • 2025-02-02 | applicable

    Prohibited practices and AI literacy apply

    Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.

  • 2024-08-01 | applicable

    The AI Act enters into force

    The regulation entered into force on 1 August 2024, after which the obligations followed in phases.

See the full timeline

What member states are doing with this

Dated signals from the enforcement tracker that refer to this obligation.

  • EU | 2026-07-27 | Europees Parlement en Raad

    Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force

    The Digital Omnibus on AI, adopted on 8 July 2026 and published in the Official Journal on 24 July 2026, enters into force on 27 July 2026. The regulation defers the obligations for stand-alone high-risk AI systems (Annex III) from 2 August 2026 to 2 December 2027 and for embedded high-risk systems (Annex I) from 2 August 2027 to 2 August 2028, and adds two prohibitions to Article 5 as of 2 December 2026 (non-consensual intimate imagery and AI-generated child sexual abuse material). This recalibrates the enforcement agenda of the Commission and the Member States.

    EUR-Lex

  • Greece | 2026-07-20 | Grieks parlement

    Law 5321/2026: Greek implementation and sanctions framework for the AI Act

    Law 5321/2026 (Government Gazette A' 114 of 20 July 2026) contains the national implementing measures for Regulation (EU) 2024/1689: designation of competent authorities, supervisory powers and administrative sanctions, with AI literacy (Article 4) as a factor in setting fines, and a criminal provision on stripping transparency markings from synthetic content. This puts Greece among the first Member States with a complete national enforcement framework.

    Ειδική Γραμματεία Τεχνητής Νοημοσύνης (officiële Griekse AI-portal, met link naar de Staatscourant)

  • Greece | 2026-07-20 | Grieks parlement

    HDPA central market surveillance authority, EETT notifying authority

    Law 5321/2026 designates data protection authority HDPA as the principal market surveillance authority for prohibited AI practices, Annex III high-risk systems and the Article 50 transparency obligations among others, and as national contact point towards the AI Office. Telecoms regulator EETT becomes the notifying authority and hosts the AI sandbox together with the Pharos AI Factory.

    Ειδική Γραμματεία Τεχνητής Νοημοσύνης (officiële Griekse AI-portal)

  • Denmark | 2025-10-20 |

    Guidance package on prohibited AI practices

    On 20 October 2025 the Danish Agency for Digital Government published a package of one main guideline and five supplementary guidelines on the Article 5 prohibited AI practices, complementing the European Commission's guidance. The package sets out the rules the authority supervises, including fictional cases.

    Digitaliseringsstyrelsen

  • Denmark | 2025-08-02 |

    Danish authorities operational for Article 5 supervision

    As of 2 August 2025 the enforcement provisions of the Danish implementing act apply. The Danish Agency for Digital Government is the central contact point for the AI Regulation; the Agency for Digital Government, the Data Protection Authority and the Court Administration supervise the Article 5 prohibited AI practices. Supervision of high-risk AI systems and the transparency obligations has not yet been fully assigned.

    Digitaliseringsstyrelsen

Open the enforcement tracker

Version history

  1. v1.0.0

    2 February 2025

    Article 5: prohibited practices

    The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.

Execution

Demonstrably rule out prohibited practices

This prohibition is already enforceable and carries the highest fine ceiling. Embed AI includes the Article 5 screening as the first step of classification and delivers the screening record per system.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.