Prohibited AI Practices: understanding the restrictions under the AI Act 

The AI Act (Regulation (EU) 2024/1689) is based on a risk-based classification of AI systems. Within this framework, certain practices are considered unacceptable and are therefore explicitly prohibited. 

These practices are defined in Article 5, which establishes a closed list of prohibited uses, based on their impact on fundamental rights, including decision-making autonomy, equal treatment and privacy. 

Following the adoption of the Regulation, the European Commission proposed adjustments through the AI Omnibus. This proposal introduces new prohibited practices, particularly in relation to certain uses of generative AI, to reflect recent technological developments. 

I – Subliminal, manipulative or deceptive techniques 

AI systems that use subliminal techniques, operating below a person’s level of awareness, or deliberately manipulative or deceptive techniques, are prohibited where they have the effect of materially distorting a person’s behaviour

The key criterion is the impairment of the person’s ability to make an informed decision, leading them to take a decision they would not otherwise have taken, with a risk of harm. 

Example: an application that exploits cognitive biases to encourage users to make purchases or investments they would not have made under normal circumstances. 

II – Exploitation of vulnerabilities 

AI systems that exploit vulnerabilities linked to age, disability or a specific social or economic situation are prohibited. 

This applies where such vulnerabilities are used to materially distort the behaviour of a person or group and cause, or are likely to cause, harm. 

Example: a system targeting financially vulnerable individuals with personalised offers encouraging them to take out unsuitable credit may fall within this category. 

III – Evaluation or classification of persons (“social scoring”) 

AI systems used for the evaluation or classification of natural persons based on social behaviour or personal characteristics are prohibited when they lead to specific adverse outcomes. 

Two situations are covered. First, where such evaluations are used in contexts unrelated to those in which the data was originally generated or collected. Second, where they result in unjustified or disproportionate adverse treatment. 

Example: a score assigned to an individual based on online behaviour and later used to deny access to a service unrelated to that behaviour. 

IV – Risk assessment for criminal offences

 The use of AI systems to assess or predict the risk of a natural person committing a criminal offence is prohibited where this assessment is based solely on profiling or personal characteristics. 

A distinction is made where such systems are used to support a human assessment based on objective and verifiable facts directly linked to criminal activity. 

Example: a tool assigning a criminal risk level based on personal traits or general behavioural data, without any direct link to a specific offence. 

V – Creation of facial recognition databases through untargeted scraping 

AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage are prohibited. 

This prohibition addresses the creation of large-scale databases without control over the origin of the data or the consent of the individuals concerned. 

Example: a system trained on millions of images automatically collected from social media platforms without users’ knowledge. 

VI – Emotion recognition in the workplace and education 

The use of AI systems for emotion recognition is prohibited in specific contexts, namely the workplace and educational institutions. Exceptions apply only where the use is justified for medical or safety purposes. 

Example: a system analysing employees’ facial expressions or voice to assess engagement or stress levels in a workplace setting. 

VII – Biometric categorisation based on sensitive characteristics

AI systems for biometric categorisation are prohibited where they are used to infer sensitive attributes, such as race, political opinions, religious beliefs or sexual orientation. 

The objective is to prevent the use of biometric data to analyse or classify protected characteristics. 

Example: a system claiming to infer political opinions from facial features or biometric data. 

VIII – Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes 

The use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes is, generally, prohibited. 

Limited exceptions apply, including the search for missing persons, the prevention of serious and imminent threats, or the identification of suspects in relation to serious criminal offences. These uses are subject to strict requirements, including necessity, proportionality and prior authorisation

IX – New prohibited practices introduced by the AI Omnibus 

The AI Omnibus complements the existing framework by introducing new prohibited uses, particularly in relation to generative AI. These include AI systems capable of generating or manipulating highly sensitive content, such as: 

  • child sexual abuse material, including fully or partially synthetic content 
  • images, videos or audio depicting an identifiable person’s intimate parts or sexually explicit activities without their consent 

A concrete example is so-called “nudification” applications, which generate artificial intimate images from ordinary photographs. 

These practices are considered to constitute a serious infringement of human dignity, privacy and personal integrity. 

X – Sanctions for non-compliance

Non-compliance with the prohibitions relating to AI practices triggers the highest level of penalties under the Regulation. 

Fines can reach up to EUR 35 million or 7% of the total worldwide annual turnover, whichever is higher. This reflects the seriousness of the infringements. 

Conclusion 

The prohibited practices set out in the AI Act reflect a clear regulatory principle: certain uses of AI are not compatible with fundamental rights and cannot be allowed. Identifying these practices requires a structured assessment of the system’s effects, particularly on decision-making autonomy, equal treatment and privacy. 

For organisations, incorrect qualification may result in the deployment of a system that falls within a prohibited category, leading to immediate non-compliance and exposure to maximum sanctions. This makes it essential to identify, document and assess potential use cases at an early stage. 

👉 Need to identify prohibited practices within your AI systems and structure your compliance with the AI Act? 

Discover the Naaia platform, designed to help organisations map AI use cases, assess risks and operationalise compliance over time, within a structured and traceable governance framework.