Skip to content
AIRAS Cloud

Article 5

Which AI practices are prohibited in the EU?

The one part of the Act with no compliance pathway. If a practice is prohibited, the only remediation is to stop.

Short answer

Article 5 of the EU AI Act prohibits placing on the market, putting into service or using AI systems that deploy subliminal or purposefully manipulative techniques causing significant harm, exploit vulnerabilities of age, disability or social or economic situation, perform social scoring leading to unjustified detrimental treatment, predict criminal offending based solely on profiling or personality traits, create facial recognition databases through untargeted scraping, infer emotions in the workplace or in education outside safety or medical purposes, or use biometric categorisation to infer protected characteristics. Real-time remote biometric identification in publicly accessible spaces for law enforcement is prohibited except in narrowly defined, authorised circumstances. These provisions have applied since 2 February 2025.

Reviewed 2026-08-02. General information for governance planning, not legal advice.

Key points

  • Prohibitions have applied since 2 February 2025
  • Highest penalty tier: up to EUR 35 million or 7% of global turnover
  • Workplace emotion inference is prohibited outside safety and medical purposes
  • Social scoring leading to unjustified detrimental treatment is prohibited
  • Untargeted scraping to build facial recognition databases is prohibited
  • There is no control set that makes a prohibited practice acceptable

Why screening comes before classification

Risk classification asks how heavily a system should be controlled. Prohibition asks whether it may exist at all. Running classification first wastes effort on systems that must be withdrawn, and worse, it can leave a prohibited practice operating while a control framework is designed around it.

Prohibited-practice screening should therefore run across the entire estate as a distinct, recorded step, with its own decision and its own evidence.

Where prohibited practices show up unintentionally

  • Sentiment or engagement scoring of employees from video or voice
  • Attention or emotion monitoring in training and education settings
  • Vendor features that infer characteristics from biometric data
  • Behavioural scoring used to restrict access to unrelated services
  • Face-matching built on scraped image sets
  • Personalisation that exploits vulnerability rather than preference

Recording a clean screen

A screen that finds nothing is still evidence, provided it is recorded. The useful record states which prohibitions were considered for which systems, the basis on which each was excluded, the ruleset version applied and the reviewer who signed it.

AIRAS Cloud runs prohibited-practice screening as a discrete stage with a recorded outcome per system, so a clean estate can be demonstrated rather than asserted.

Frequently asked questions

Is emotion recognition banned outright?
It is prohibited in the workplace and in education institutions except where used for medical or safety reasons. Other contexts may still be permitted but can attract transparency and high-risk obligations.
Are all biometric systems prohibited?
No. Biometric categorisation inferring protected characteristics and untargeted scraping for facial recognition databases are prohibited, while other biometric uses are typically treated as high-risk with strict requirements.
What if we discover a prohibited practice in use?
Stop the practice, record the decision and the date, assess whether harm occurred, and retain the evidence. There is no control-based mitigation that makes a prohibited practice lawful.

Primary sources

How AIRAS Cloud supports this

Complete AI inventory, including embedded vendor AI
Role and applicability determination per system
Deterministic, versioned classification reasoning
Append-only audit record of every decision

Related answers

Turn the regulation into an operating record

AIRAS Cloud gives Irish and EU organisations one accountable place to discover AI, determine scope, classify defensibly, assign controls and evidence every decision.

No pricing commitment. No confidential information required.