EU AI Act Art. 5 — Prohibited artificial intelligence practices
Article 5 bans AI practices that the EU considers an unacceptable threat to people. If your system falls into any of these categories, you cannot lawfully put it on the market or use it in the EU — regardless of safeguards.
At a glance
What this article requires
- Subliminal or manipulative AI that causes significant harm is banned.
- Social scoring by public or private actors is banned outright.
- Real-time remote biometric identification in public spaces is banned for law enforcement, with very narrow exceptions.
- Emotion inference in the workplace and education is banned (with narrow medical exceptions).
- Untargeted scraping of facial images from the internet or CCTV for biometric databases is banned.
- The prohibitions applied from 2 February 2025 — the earliest deadline in the Act.
Scope
Who this applies to
Anyone placing AI on the EU market, putting it into service, or using it in the EU — providers and deployers alike. If a practice is prohibited, there is no compliance path; there is only removal.
Obligations
What you must actually do
Remove, don't mitigate
Unlike high-risk obligations, Article 5 is not a compliance framework. Banned practices cannot be made compliant through documentation or oversight — the system or use must be discontinued.
Check the narrow law-enforcement exception
Real-time remote biometric identification is prohibited except for listed serious-crime searches with prior judicial authorisation, strictly limited in time, geography, and data subjects. These uses require a valid legal basis under national law.
Watch the emotion-inference carve-out
Emotion recognition in workplace and education is banned, but AI for medical or safety reasons (e.g. detecting a patient's pain or distress) can remain lawful where the purpose is demonstrably medical or safety-related.
Action plan
Practical first steps
- 1
Audit every AI system or planned system against the Article 5 list before any design investment.
- 2
Flag any feature that infers emotion, scores people socially, manipulates behaviour, or profiles for predictive policing.
- 3
For biometric systems, document the lawful basis, necessity, and proportionality — and get legal advice before any real-time public-space use.
- 4
If you market an AI feature in the EU that matches a prohibited practice, remove it and record the decision.
Penalty exposure
Violations of Article 5 draw the Act's highest fine tier: up to €35 million or 7% of global annual turnover, whichever is higher.
FAQ
Questions about Art. 5
Is all facial recognition prohibited by Article 5?
No. Article 5 bans real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions) and untargeted scraping of facial images for databases. It does not ban verification (one-to-one matching) or lawful access control, which sit in Annex III high-risk territory instead.
When did the Article 5 bans start applying?
The prohibitions have applied since 2 February 2025 — six months after the Act entered into force on 1 August 2024. This was deliberately the first deadline so banned practices would be removed from the market quickly.
Does emotion recognition always violate Article 5?
Emotion inference in the workplace and in education is prohibited, but the ban is not absolute: AI that detects a medical or safety state (such as a patient in distress) can be lawful if the purpose is genuinely medical or safety-related.
Sources
Citations & further reading
Related
More article explainers
Wondering which articles apply to your AI?
Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.
Check my use casePreliminary EU AI Act clarity summary. Not legal advice.