Prohibited AI practices
Article 5 prohibits the placement on the market or putting into service of AI systems that pose an "unacceptable risk" to health, safety, and fundamental rights. Compliance requires ensuring that no AI system deployed by the organization performs any of the specific banned activities listed in the regulation.
What it means
Unlike "High-Risk" AI systems, which are permitted if they meet strict requirements, "Prohibited" practices are strictly forbidden within the EU. The intent is to prevent AI from being used for systemic manipulation or surveillance that violates human dignity and fundamental rights.
In practice, this covers several specific categories: cognitive behavioral manipulation (using subliminal techniques), social scoring by public authorities, certain biometric categorization based on sensitive traits, emotion recognition in workplaces or schools, and untargeted scraping of facial images for databases.
For an organization, this means that simply "optimizing" a system is not enough; if the core functionality falls into these categories, the system cannot be used legally within the EU regardless of how well it is governed.
How to meet it
- Conduct a comprehensive inventory of all AI systems currently in use or under development.
- Map every identified AI system against the specific prohibited practices listed in Article 5.
- Establish an internal "Prohibited AI Policy" that formally bans the development, procurement, and deployment of these technologies.
- Integrate a mandatory compliance check into the procurement process to ensure third-party vendors do not provide tools with prohibited functionalities (e.g., hidden emotion recognition).
- Implement technical guardrails or configuration restrictions to prevent users from repurposing existing AI tools for prohibited uses.
- Provide targeted training to product managers and developers on the legal boundaries of Article 5 to prevent "feature creep" into banned territory.
Evidence an auditor asks for
- A complete AI System Inventory including a classification column that explicitly marks each system as "Not Prohibited."
- Signed compliance assessments or checklists for each deployed AI tool, documenting why it does not fall under the Art. 5 bans.
- An official corporate policy document prohibiting the use of unacceptable-risk AI practices.
- Procurement records and vendor questionnaires containing specific queries regarding prohibited biometric or manipulative capabilities.
Common pitfalls
- Confusing "High Risk" with "Prohibited," leading organizations to try to "mitigate" a practice that is actually banned entirely.
- Relying on vendor claims of compliance without verifying the actual technical capabilities of the AI tool.
- Overlooking "hidden" features in third-party software, such as sentiment analysis tools that cross the line into prohibited emotion recognition in workplace settings.