Article 5: prohibited practices
The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.
The official source remains authoritative. This general interpretation is not legal advice.
- Status
- Applicable
- Application date
- 2 February 2025
- Version
- 1.0.0
- Last reviewed
- 8 August 2026
Who this is relevant to
When this applies
Deployer
An organisation using an AI system under its authority, excluding personal non-professional use.
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1Placing on the market, putting into service or using AI falls under one of the practices in Article 5(1), including harmful manipulation or exploitation of vulnerabilities, social scoring, predicting criminal offences based on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education, biometric categorisation by sensitive characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement.
What the official source establishes
The prohibited practices of Article 5 apply since 2 February 2025 and are the only AI Act category enforceable for that entire period. Violations carry the highest fine ceiling in the regulation: up to 35 million euro or 7 percent of worldwide annual turnover.
The Digital Omnibus adds a prohibition on AI for child sexual abuse material and non-consensual intimate synthetic content; the accompanying technical safeguards are required by 2 December 2026.
Our interpretation
The line often sits in the definitional details: the same technique can be prohibited in the workplace and permitted in another context. Screen per concrete use and context, not per technology, and do so before procurement or go-live.
What you can do now
Make the Article 5 screening the first step of every classification and record the outcome per system in the register, including the reasoning why a practice does not fall under the prohibition.
- 01
Screen every use case against Article 5 first
Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
What to retain
Article 5 screening record
A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion "no prohibited practice" is evidence too.
Control and reassessment
Article 5 gate at intake and change
Repeat the screening for every new system, procurement and material change of purpose or context; an earlier clearance does not cover a new use.
Public tools
Full text of Article 5
The full legal text of the prohibited practices with all categories and exceptions, in the public AI Act Explorer.
Conditions and exceptions
- The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance.
Official sources and locators
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 5, Article 99(3) and Article 113(a)
Digital Omnibus on AI 2026/1744
European Parliament and Council | official-journal-2026-07-24
Source locator: Amendment to Article 5 and transition to 2 December 2026
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 5(1)(a)-(h)
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 5 read with Article 6 classification order
What changed in this
Moments when this obligation took effect, moved or received official guidance.
2026-12-02 | upcoming
New prohibitions require technical safeguards
The Digital Omnibus prohibits AI for child sexual abuse material and non-consensual intimate imagery.
2025-07-29 | guidance
Guidelines on prohibited AI practices
Worked examples for each Article 5 prohibition, with the line between permitted and prohibited.
2025-02-02 | applicable
Prohibited practices and AI literacy apply
Since 2 February 2025 the Article 5 prohibition and the Article 4 AI literacy duty apply.
2024-08-01 | applicable
The AI Act enters into force
The regulation entered into force on 1 August 2024, after which the obligations followed in phases.
What member states are doing with this
Dated signals from the enforcement tracker that refer to this obligation.
EU | 2026-07-27 | Europees Parlement en Raad
Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force
The Digital Omnibus on AI, adopted on 8 July 2026 and published in the Official Journal on 24 July 2026, enters into force on 27 July 2026. The regulation defers the obligations for stand-alone high-risk AI systems (Annex III) from 2 August 2026 to 2 December 2027 and for embedded high-risk systems (Annex I) from 2 August 2027 to 2 August 2028, and adds two prohibitions to Article 5 as of 2 December 2026 (non-consensual intimate imagery and AI-generated child sexual abuse material). This recalibrates the enforcement agenda of the Commission and the Member States.
Greece | 2026-07-20 | Grieks parlement
Law 5321/2026: Greek implementation and sanctions framework for the AI Act
Law 5321/2026 (Government Gazette A' 114 of 20 July 2026) contains the national implementing measures for Regulation (EU) 2024/1689: designation of competent authorities, supervisory powers and administrative sanctions, with AI literacy (Article 4) as a factor in setting fines, and a criminal provision on stripping transparency markings from synthetic content. This puts Greece among the first Member States with a complete national enforcement framework.
Ειδική Γραμματεία Τεχνητής Νοημοσύνης (officiële Griekse AI-portal, met link naar de Staatscourant)
Greece | 2026-07-20 | Grieks parlement
HDPA central market surveillance authority, EETT notifying authority
Law 5321/2026 designates data protection authority HDPA as the principal market surveillance authority for prohibited AI practices, Annex III high-risk systems and the Article 50 transparency obligations among others, and as national contact point towards the AI Office. Telecoms regulator EETT becomes the notifying authority and hosts the AI sandbox together with the Pharos AI Factory.
Ειδική Γραμματεία Τεχνητής Νοημοσύνης (officiële Griekse AI-portal)
Denmark | 2025-10-20 |
Guidance package on prohibited AI practices
On 20 October 2025 the Danish Agency for Digital Government published a package of one main guideline and five supplementary guidelines on the Article 5 prohibited AI practices, complementing the European Commission's guidance. The package sets out the rules the authority supervises, including fictional cases.
Denmark | 2025-08-02 |
Danish authorities operational for Article 5 supervision
As of 2 August 2025 the enforcement provisions of the Danish implementing act apply. The Danish Agency for Digital Government is the central contact point for the AI Regulation; the Agency for Digital Government, the Data Protection Authority and the Court Administration supervise the Article 5 prohibited AI practices. Supervision of high-risk AI systems and the transparency obligations has not yet been fully assigned.
Version history
v1.0.0
2 February 2025
Article 5: prohibited practices
The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.
Execution
Demonstrably rule out prohibited practices
This prohibition is already enforceable and carries the highest fine ceiling. Embed AI includes the Article 5 screening as the first step of classification and delivers the screening record per system.
See the Embed AI approachFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.