Most of the EU AI Act is about documenting and monitoring AI systems you’re allowed to run. Article 5 is different. It’s a short list of AI practices the Act bans outright — no conformity assessment, no technical documentation route to compliance, no grace period. If a system matches one of these eight practices, the only compliant answer is to not run it.

This prohibition has applied since 2 February 2025 — over a year before the high-risk obligations even had their (now-deferred) deadline. It was untouched by the Digital Omnibus. If you’ve been focused on the 2 December 2027 high-risk timeline, it’s worth a separate check against this list, because Article 5 exposure carries the Act’s highest penalty tier regardless of your company’s size or the deadline calendar.

The Eight Prohibited Practices

Article 5 prohibits placing on the market, putting into service, or using AI systems that:

1. Use subliminal or manipulative techniques that cause significant harm. Systems designed to distort a person’s behavior below their conscious awareness, or through purposefully deceptive techniques, in a way likely to cause significant harm.

2. Exploit vulnerabilities due to age, disability, or social/economic situation. AI that targets children, elderly people, people with disabilities, or people in vulnerable economic situations to materially distort their behavior in a harmful way.

3. Run social scoring. Evaluating or classifying people based on social behavior or inferred personal characteristics, where the resulting score leads to unfavorable treatment unrelated to the context the data was collected in, or disproportionate to the conduct itself. This targets public-authority-style social scoring — but “public authority” scope questions come up often enough in private-sector loyalty and risk-scoring tools that it’s worth a deliberate check, not an assumption.

4. Predict criminal offending from profiling alone. Risk-assessment tools that predict whether someone will commit a crime based solely on profiling or personality-trait analysis. (Tools that support human assessment of an already-identified suspect, based on objective facts tied to an actual offense, are carved out.)

5. Scrape facial images to build recognition databases. Untargeted scraping of faces from the internet or CCTV footage to create or expand facial recognition databases.

6. Infer emotions at work or school. Emotion-recognition AI used in workplaces or educational institutions — except where the specific purpose is medical or safety-related.

7. Categorize biometric data to infer protected characteristics. Biometric categorization systems that infer race, political opinion, trade union membership, religious belief, sex life, or sexual orientation from biometric data. (Lawful labeling/filtering of already-lawfully-acquired biometric datasets, and law-enforcement categorization, are carved out separately.)

8. Use real-time remote biometric identification in public for law enforcement — with narrow exceptions for searching for specific trafficking/abduction victims or missing persons, preventing an imminent terrorist threat, or locating a suspect in specific serious crimes, and only under judicial or independent administrative authorization.

Where Mid-Market Companies Actually Get Exposed

The headline examples (social scoring, mass surveillance) sound like government use cases. In practice, the categories that catch ordinary commercial products are:

  • Emotion recognition in HR tools. Interview-analysis software that scores candidate “enthusiasm” or “confidence” from facial expression or tone can fall directly into the workplace emotion-inference ban — even if emotion detection is a minor feature of a broader hiring tool.
  • Vulnerability-targeted personalization. Marketing or pricing engines that specifically identify and target financially vulnerable users to influence purchasing decisions sit close to prohibition #2, depending on intent and effect.
  • Loyalty and risk scores with cross-context consequences. A behavioral score built from one context (e.g. app usage) that is then used to restrict access to an unrelated service can resemble prohibited social scoring, particularly if the link between the data and the consequence is not proportionate.
  • Embedded vendor features. As with high-risk classification, an embedded AI feature in third-party software (a CRM’s “sentiment scoring,” a video platform’s engagement-inference layer) can trigger a prohibition even though your organization didn’t build it — because as a deployer, using the feature is itself in scope.

How to Check Your Systems

  1. List every system with an inference or scoring component — not just ones explicitly branded “AI.” Sentiment analysis, engagement scoring, and personalization engines all count.
  2. Ask what the output is used for, not just what it measures. The same emotion-detection model is prohibited in an HR context and unregulated in, say, an accessibility tool — context and purpose determine the prohibition, not the underlying technique.
  3. Check the deployment surface: is the score or inference used to gate access, adjust pricing, or influence an employment decision? That’s where the harm threshold in prohibitions #1, #2, and #3 tends to bite.
  4. Treat “the vendor says it’s compliant” as a starting point, not an answer — deployers carry independent exposure, as covered in our provider vs. deployer guide.

If a system matches, the fix isn’t documentation — it’s turning the feature off or re-scoping it before enforcement finds it, since Article 5 non-compliance carries the Act’s top fine tier: up to €35,000,000 or 7% of global annual turnover, whichever is higher.

What Comes Next

Once you’ve cleared the Article 5 check, the next question is whether any remaining systems fall into the high-risk Annex III categories, which carry a different, documentation-based compliance path rather than an outright ban. Aikraft’s risk classification runs both checks — prohibited-practice screening and Annex III classification — from the same system inventory. Take the free risk quiz for a first-pass read on where your systems land.