Subliminal, Manipulative and Deceptive Techniques Under Article 5

The first prohibited category covers techniques designed to manipulate behaviour by working below the level of conscious awareness. Subliminal manipulation is communication that appeals to the unconscious mind without the person’s knowledge or attention. A manipulative technique is one that deliberately distorts or subverts a person’s natural decision making process. Deceptive techniques rely on falsehood or misleading representation presented in a way that undermines the person’s ability to evaluate the truth.

Article 5 targets AI systems that use these methods to cause a person to act against their interests. The harmful behaviour is defined narrowly: the person must take an action they would not have taken if they had full information and understood what was happening. This is a high bar to meet, which gives organisations some scope for persuasive AI. It is not enough to say a technique is persuasive or that most people might be susceptible to it. The AI system must actively and deliberately distort judgment in a way that causes concrete harm to the person’s interests.

An example of a subliminal technique would be an AI system that times notifications at moments when a person is known to be in a vulnerable mental state, exploiting neuroscience research about decision making. Another example would be an AI notification system that uses language patterns known to trigger anxiety or urgency in a particular person. An example of manipulation would be an AI system in a banking app that presents false urgency, using language the bank knows will trigger a specific person’s anxiety response, to make them transfer money quickly without thinking through the consequences. These examples share a common feature: the AI system is designed to work on emotion or unconscious response rather than rational evaluation.

The EU’s prohibition does not cover all persuasive AI or all use of psychology in design. It does not ban personalisation algorithms or recommender systems that suggest content to a user. It does not ban honest advertising that appeals to emotions. It does not ban A/B testing or conversion optimisation to improve user experience. The distinction is that prohibited techniques deliberately distort decision making by circumventing rational evaluation, while permitted persuasion preserves the person’s agency and awareness.

Lesson concept diagram

This raises a practical challenge for organisations. Many digital products and AI systems use psychological insights about what keeps people engaged. They may optimise notifications for maximum engagement, personalise content to what a user will spend time with, or adapt interface design to increase interaction. Knowing when something crosses the line from engagement to prohibited manipulation requires careful judgment. However, the bright line is intent and harm. If the AI system is designed to make a person act against their interests by triggering unconscious responses or bypassing their awareness, it is prohibited. If the system is designed to present information persuasively while the person retains full agency and knowledge of what they are doing, it is not prohibited.

There is a narrow exception for law enforcement and security authorities. Police, border control and other criminal justice authorities can use AI systems that rely on manipulative or deceptive techniques if they are investigating a specific criminal offence, pursuing a specific suspect, and the technique is proportionate to the suspected crime. For example, law enforcement might use deceptive communications in an undercover operation to investigate trafficking or organised crime.

For commercial and public services organisations, the rule is absolute. You cannot use subliminal, manipulative or deceptive AI techniques even if you believe your motives are good or the harm is minor. This applies to HR departments, customer service teams, marketing functions, financial services, retail and e-commerce, and any other business area. The only exception is the narrow law enforcement carve-out. If you are unsure whether your system crosses the line, the safe approach is to assume it does and escalate to your compliance team.

Examples of systems that would violate this prohibition include: an AI system that learns when a person is tired or stressed and times high-pressure sales notifications then; an AI system in a loan application interface that uses specific language or image phrasing designed to subtly trigger financial urgency; an AI system that analyses a person’s browser history to identify vulnerabilities and times persuasion attempts accordingly; an AI system that learns patterns of indecision and automatically advances to “confirm” buttons as the person wavers. In contrast, a system that recommends relevant products based on past purchases, that explains the benefits of a service clearly, or that offers flexible timing for important decisions would not violate Article 5.