EU AI Act Article 5 — Prohibited AI Practices: What Is Banned and When
Article 5 of the EU AI Act lists eight categories of AI practice that are prohibited outright — not regulated, not risk-classified, but banned with immediate effect from 2 February 2025. The eight prohibitions are: (1) subliminal, manipulative, or deceptive techniques that materially distort behaviour and cause harm; (2) exploitation of vulnerabilities of persons due to age or disability; (3) social scoring by public authorities leading to detrimental treatment; (4) individual criminal risk assessments based solely on profiling; (5) untargeted scraping of facial images for facial recognition databases; (6) emotion recognition in the workplace or education (with medical/safety exceptions); (7) biometric categorisation inferring sensitive characteristics (race, political opinion, religion, sexual orientation); (8) real-time remote biometric identification in publicly accessible spaces for law enforcement (narrow judicial-authorisation exceptions apply). The distinction matters for procurement: a vendor cannot mitigate a prohibited practice with a risk assessment — Article 5 systems are illegal to place on the EU market, period. The Council of AI verified measurement credential tests for Art 5 compliance by checking that no prohibited categorisation, scoring, or manipulation path exists in the evaluated system pipeline — not that it is low risk, but that the prohibited pathway is architecturally absent. For operators uncertain whether a system touches Art 5 territory, the Council containment measurement card provides a boundary audit showing which data flows touch prohibited inference categories.
References
- EU AI Act 2024/1689, Article 5 — Prohibited AI Practices
- Council of AI Containment Incident Index
- CSOAI Verified Measurement Credential (signed GSPC card)
- European Commission AI Act implementation guidelines (draft)
Measurement, not certification. Verify a card at /gspc-verify.