Definition: Prohibited AI Practices (EU AI Act)
Prohibited AI practices are eight categories of AI use, defined in Article 5 of the EU AI Act, that the law bans outright regardless of sector, company size, or safeguards applied, because they pose an unacceptable risk to fundamental rights.
Core characteristics of prohibited AI practices
Article 5 lists eight specific practices rather than a general risk test, so an AI system either falls inside one of these categories or it does not. Where a system matches, no technical documentation, human oversight, or conformity assessment can make it legal.
- Binds both providers and deployers, regardless of where the AI system was developed
- Covers subliminal manipulation, exploitation of vulnerabilities, social scoring, and predictive policing based solely on profiling
- Covers untargeted facial-image scraping, workplace and education emotion recognition, and biometric categorization inferring sensitive traits
- Covers real-time remote biometric identification in public spaces for law enforcement, with narrow, judicially authorized exceptions
Prohibited AI Practices vs. High-Risk AI System
A high-risk AI system is legal but conditional: once its provider completes conformity assessment, technical documentation, and human oversight design under Article 16, it may reach the market. A prohibited practice under Article 5 has no such path, since the EU AI Act judges the underlying use case itself, not just the safeguards wrapped around it, to be incompatible with fundamental rights. A hiring tool that screens candidates against job criteria is typically high-risk; a hiring tool that infers a candidate’s emotional state during a video interview to predict reliability crosses into a banned practice. The distinction matters operationally, since misclassifying a banned use case as merely high-risk exposes an organization to the Act’s steepest fines rather than a fixable compliance gap.
Importance of prohibited AI practices in enterprise AI
Article 5 sets the outer boundary of what any organization may build or buy, making it the first filter an AI governance process should apply, before a use case is even scored for risk level. Bitkom’s 2026 research found 69% of German companies say they need support implementing the EU AI Act, while only 24% have engaged seriously with its requirements so far, a gap that is riskiest precisely at the prohibited-practice boundary because no remediation exists once a system is live.
Methods and procedures for prohibited AI practices
Screening for prohibited practices follows a defined legal test rather than a general ethics review.
Article 5 screening test
Before any AI use case reaches procurement or development, it should be checked against each of the eight Article 5 categories individually, since a single system can trigger more than one.
- Map the system’s intended purpose and inference technique against all eight Article 5 categories
- Check for narrow statutory exceptions, such as the judicially authorized law enforcement exception for real-time biometric identification
- Document the screening outcome in writing before the system is built, purchased, or deployed
Legal and technical review
Because several Article 5 categories, such as emotion inference or biometric categorization, depend on the exact inference a model makes rather than its input data type, legal review alone is often insufficient. A technical reviewer needs to confirm what a model actually infers or outputs, since a facial analysis tool built for age verification can silently drift into biometric categorization if it starts inferring ethnicity or political affiliation from the same input.
Vendor and procurement due diligence
Organizations that buy AI rather than build it carry the same Article 5 exposure as the vendor, since deployers are directly bound by the prohibitions. Procurement teams increasingly require vendors to confirm in writing that a product does not perform emotion inference, biometric categorization, or social scoring, particularly for HR, security, and customer analytics tools.
Important KPIs for prohibited AI practices
Tracking Article 5 exposure requires indicators distinct from general compliance metrics.
Screening coverage
- Article 5 screening completion: percentage of AI use cases screened before deployment
- Vendor attestation coverage: percentage of third-party AI tools with a written Article 5 statement
- Screening documentation age: percentage of screenings reviewed within the past 12 months
- Escalation rate: number of use cases flagged for legal review per quarter
Strategic risk exposure
Boards increasingly want visibility into how many AI use cases sit close to an Article 5 boundary, not just how many are formally classified as high-risk, since a prohibited-practice finding carries no remediation window. IAPP reporting found nearly 70% of businesses struggle to understand their specific obligations under the Act, which means many organizations cannot yet answer this question with confidence.
Incident readiness
A defined response plan for a market surveillance authority inquiry, including who can pull screening documentation within days, matters as much as the screening itself. Authorities can act on a complaint from any individual or competitor, so an organization without ready documentation faces a credibility problem even when its underlying use case turns out to be compliant.
Risk factors and controls for prohibited AI practices
Article 5 exposure concentrates in specific, avoidable failure modes.
Feature creep into biometric categorization
Tools built for a narrow, legitimate purpose, such as age estimation for content filtering, can drift into prohibited biometric categorization if a later feature update adds inference of race, religion, or sexual orientation. This risk grows whenever a vendor adds new inferred attributes to an existing model without a fresh Article 5 review.
- Re-run Article 5 screening whenever a vendor releases a model or feature update
- Restrict biometric tools to their documented, narrow purpose in contract terms
- Audit model outputs periodically to confirm no sensitive attributes are being inferred
Unauthorized adoption of consumer AI tools
Employees experimenting with consumer-grade emotion-detection or profiling tools inside HR or customer service workflows can trigger Article 5 exposure without any formal procurement review ever taking place. Because deployers are liable independent of who built the tool, an organization can be exposed by a single team’s unauthorized adoption of a banned technique.
Algorithmic bias mistaken for a technical fix
Predictive policing and social scoring practices are banned specifically because bias correction cannot neutralize the underlying harm; the EU AI Act treats them as unacceptable regardless of accuracy. Teams that discover algorithmic bias in a scoring or profiling system should first check whether the use case itself sits inside Article 5 before investing in a fairness fix the law would not accept as a remedy anyway.
Practical example
A 90-employee logistics and warehousing company in North Rhine-Westphalia piloted a camera-based access-control system on its loading-dock floor that included a vendor-supplied “engagement scoring” feature inferring workers’ emotional state from facial expressions during shifts. Before rollout, the company’s compliance lead ran the tool through an Article 5 screening as part of a broader compliance review and found the engagement-scoring feature fell squarely inside the workplace emotion-recognition ban, since none of the narrow medical or safety exceptions applied. The company kept the access-control function, which was unaffected, and required the vendor to fully disable the emotion-inference module before signing the contract. It also added an Article 5 checkpoint to its standard AI procurement process so the same issue could not resurface with a different vendor.
- Written Article 5 screening completed before any new AI tool goes live
- Vendor contract clause requiring written confirmation of no biometric categorization or emotion inference
- Procurement checklist covering all eight Article 5 categories
- Quarterly review of AI tools already in use against updated Commission guidance
Current developments and effects
Three developments are shaping how organizations manage Article 5 exposure.
Full enforcement machinery active since August 2026
Article 5’s prohibitions have applied since February 2, 2025, but the EU AI Act’s general enforcement architecture, including national market surveillance authorities and the formal complaint procedure, became fully active on August 2, 2026. This closed the gap between a legally binding ban and a fully operational mechanism for investigating and penalizing violations of it.
- Any individual, competitor, or organization can now file a formal complaint with a national market surveillance authority
- Authorities can require corrective action within days once a system is found non-compliant
- No cure period exists comparable to the one high-risk systems get for documentation gaps
European Commission guidance on Article 5
The European Commission has published interpretive guidance clarifying edge cases such as where legitimate age-verification tools end and biometric categorization begins. Organizations operating biometric, HR-analytics, or scoring tools should treat this guidance as the reference interpretation rather than relying solely on vendor assurances.
Growing scrutiny of HR and security AI tools
Works councils and labor representatives in Germany are increasingly asking employers to demonstrate that AI tools touching employee monitoring or performance scoring do not cross into workplace emotion recognition. This pressure is pushing Article 5 screening from a legal back-office exercise into a standard step in HR technology procurement.
Conclusion
Article 5 sets a hard boundary around eight AI use cases that no amount of documentation, oversight, or fairness tuning can make legal, which is what separates it from every other risk tier in the EU AI Act. With the enforcement machinery fully active since August 2026, organizations can no longer treat a prohibited-practice gap as a theoretical risk, since any individual or competitor can now trigger a market surveillance investigation. Mittelstand companies that build an Article 5 screening step into procurement and product development close the exposure before a tool ever reaches employees or customers. Treating this screening as a first filter, ahead of any high-risk classification work, keeps an organization’s AI portfolio inside the law from the start.
Frequently Asked Questions
What exactly does Article 5 of the EU AI Act ban?
Article 5 bans eight AI practices: subliminal or manipulative techniques causing harm, exploitation of vulnerabilities tied to age or disability, social scoring, predictive policing based solely on profiling, untargeted scraping of facial images to build recognition databases, emotion inference in workplaces and schools, biometric categorization inferring sensitive traits, and real-time remote biometric identification in public spaces for law enforcement. Each category is banned outright, with only narrow, specifically defined exceptions for law enforcement in the profiling and biometric identification categories.
How is a prohibited practice different from a high-risk AI system?
A high-risk AI system, such as a hiring or credit-scoring tool, is legal once its provider meets Article 16 obligations like documentation and human oversight. A prohibited practice under Article 5 has no such path, since the EU AI Act bans the use case itself, so the only compliant option is not to deploy it.
Does this apply to a Mittelstand company with under 250 employees?
Yes. Article 5 applies based on the AI practice itself, not on company size or sector, so a small logistics firm or regional retailer carries the same prohibition as a large enterprise. Company size affects the resources available to run a screening, not the underlying legal obligation.
What does an Article 5 screening cost for a Mittelstand company?
A single-tool screening typically takes a few days of legal and technical review time and costs a low four-figure sum, since it draws on existing product documentation rather than new technical work. Building a repeatable screening step into procurement costs more upfront but avoids repeating the review for every new AI purchase.
Do we need our own compliance team to handle this?
No. Most Mittelstand organizations combine existing legal or data protection staff with external counsel for the initial Article 5 screening. Providers like Superkind that build custom AI agents on top of existing enterprise systems scope each use case against known regulatory boundaries as part of the build, which gives an Article 5 review a documented starting point instead of a blank page.
How does Article 5 relate to GDPR?
A prohibited AI practice can trigger GDPR exposure at the same time, since categories like biometric categorization and emotion inference typically process special category personal data under GDPR Article 9. Running an Article 5 screening alongside a data protection impact assessment lets an organization catch both problems in a single review instead of discovering the GDPR issue only after the Article 5 problem is fixed.