Reading the Commission Guidelines on Prohibited Practices

The EU Commission has published detailed guidelines on Article 5 prohibited practices. These guidelines, while not having the force of law itself, provide the official interpretation of what the EU believes constitutes prohibited practices and how organisations should apply the rules in practice. Regulators will refer to these guidelines when investigating potential violations.

The guidelines acknowledge that some of the prohibited categories are complex and require careful interpretation. The Commission recognises that organisations may need to conduct impact assessments and risk analyses to understand whether their specific AI system falls into a prohibited category. The guidelines attempt to provide clarity on borderline cases and edge scenarios that fall between clearly prohibited use and clearly permitted use.

On subliminal and manipulative techniques, the guidelines clarify that not all persuasion or engagement optimisation is prohibited. The distinction is between transparent, informed persuasion (which remains permitted) and techniques deliberately designed to work below conscious awareness or directly against the person’s interests (which are prohibited). A system optimising for relevance is not prohibited. A system learning to time interventions to exploit stress or vulnerability is prohibited.

On exploitation of vulnerability, the guidelines note that the presence of vulnerable people in a user base does not automatically make a system prohibited. The key is whether the AI system deliberately exploits the vulnerability in a way that causes actual harm. A system that simply fails to work well for a disabled user due to poor inclusive design is not prohibited under Article 5, though it may violate other legal obligations like accessibility requirements or equal treatment laws.

On social scoring, the guidelines emphasise that general public administration, taxation, insurance, employment assessment and credit assessment are not prohibited as long as they are based on objective conduct or financial capability, not on social character or behaviour. A credit score based on payment history is not social scoring. A social credit system based on perceived moral worthiness of citizenship is social scoring.

On criminal prediction, the guidelines clarify that AI systems based on objective factors and specific evidence from investigations are permitted. Systems based on general risk indicators derived from demographic factors are not permitted, even if they improve on human judgment in identifying criminals.

Lesson concept diagram

On facial recognition databases, the guidelines address the problem of companies acquiring datasets from third parties. They clarify that the prohibition applies to use of any database built through untargeted scraping, not only to building the database itself.

On emotion recognition, the guidelines note that the prohibition applies specifically to use in employment and education decisions, not to research into emotion recognition or to deployment in other contexts like entertainment or sport.

On biometric characteristic inference, the guidelines emphasise that the prohibition applies to protected characteristics specifically, not to all possible biometric inferences. Inferring age for entertainment purposes is different from inferring race for employment decisions.

The guidelines address the tension between prohibition and legitimate security use. The EU acknowledges that law enforcement and security officials need tools to protect the public. The guidelines set proportionality boundaries around where narrow exceptions can apply.

For organisations, the practical step is to read the official guidelines and assess your AI systems against them. The guidelines are available on the European Commission website and have been developed in consultation with national regulators and industry. They provide more detail than this course and may be essential if your AI system operates in a grey area between clearly prohibited and clearly permitted use. When you encounter a system where compliance is unclear, the guidelines often provide concrete examples that help you understand the intent of the prohibition and where the regulator would draw the line. Consulting the guidelines early in your AI procurement or development process is an investment in compliance and can prevent expensive mistakes.

The Commission has also issued additional guidance on specific topics. For example, there is detailed guidance on what qualifies as biometric data (the definition is broader than many expect), clarification on transparency obligations, explanation of what constitutes systemic risk for General Purpose AI models, and specific guidance on implementation timelines for different obligations. Your compliance team should monitor the Commission website for updated guidance as implementation progresses and as the Commission receives feedback from member states and industry. Regulatory interpretation continues to evolve as organisations deploy systems and regulators gain experience enforcing the rules.