Why Some AI Uses Are Banned Outright in the EU

The EU AI Act takes a fundamentally different approach to certain categories of AI use: rather than asking organisations to manage risks through governance processes, it prohibits these uses entirely. This is the strongest possible regulatory signal. Article 5 of the EU AI Act names four prohibited practices, and these bans have been in force since 2 February 2025 across the European Union.

The reason for outright bans is that the EU concluded these practices create unacceptable risks that cannot be mitigated through better design, transparency or monitoring. No risk management process, however thorough or well-designed, can bring these systems into compliance. The EU made a judgment call: certain AI uses are incompatible with fundamental rights and human dignity, regardless of how they are implemented or governed. An organisation that discovers it is running a prohibited AI system must stop immediately. There is no remediation path, no exemption process and no grace period for transition.

This creates a practical problem for organisations operating across Europe or selling products into the European market. You must screen every AI system you deploy, develop or offer to deployers to check whether it falls into any of the prohibited categories. This screening process is not optional. It is a mandatory part of your governance. The EU’s approach assumes that if you are deploying AI in the European market, you will have checked it against these criteria before launch. Ignorance is not a defence. Regulators will not accept “we did not know” as an explanation for deploying a prohibited system.

The four prohibited categories cover distinct harms. The first covers subliminal and manipulative techniques that work below conscious awareness. The second covers exploitation of vulnerable populations by age, disability or social or economic situation. The third covers social scoring systems that assign ratings based on social behaviour. The fourth covers certain biometric surveillance and identification practices. Within each category, there are specific rules about when a narrow exception might apply, particularly for law enforcement and border control operations, but the core rule is absolute: do not use these systems.

Lesson concept diagram

The penalties for breach are severe enough to make compliance mandatory for most organisations. The EU can fine up to 35 million EUR or 7 percent of global turnover, whichever is higher. For large technology companies, 7 percent of global turnover often exceeds 5 billion EUR and is the binding constraint. For large financial services or telecommunications companies, it can exceed 1 billion EUR. Even for mid-size organisations, 7 percent of turnover frequently exceeds the 35 million EUR floor. Beyond financial penalties, regulators can issue prohibition orders requiring systems to be shut down immediately, ban organisations from deploying AI systems, issue public statements naming the breach, and require products to be withdrawn from the market. The reputational damage from regulatory enforcement compounds the financial penalties.

Understanding Article 5 is not theoretical compliance work. It is a concrete operational requirement that affects your day-to-day operations. You need to know what is banned so that you can build a screening process into your AI procurement, development and deployment workflow. This course teaches you to recognise each banned category with clarity, understand when narrow exceptions might apply and their specific scope, and build evidence that you have conducted the screening properly.

The rest of this course takes you through each prohibited practice one by one. Lessons 2 through 9 cover the eight specific prohibited practices. Lessons 10 and 11 address how to interpret grey areas using official guidance and how common AI techniques like recommender systems fit against the prohibition. Lessons 12 through 15 give you practical tools to screen AI systems, handle vendor products that contain prohibited features, understand enforcement penalties and cost of violations, and document your screening in an AI register that regulators will examine.

By the end of this course, you will be able to assess any AI system against Article 5 criteria and make documented decisions about its compliance status. You will have templates and questions you can use immediately in your organisation. You will understand the business and legal risks of deploying prohibited systems and have the language to explain Article 5 constraints to technical teams and business leaders.


Frequently asked questions

What AI practices are banned under the EU AI Act?

Article 5 of the EU AI Act bans four categories: subliminal and manipulative techniques designed to distort decision making, exploitation of vulnerability by age or disability, social scoring systems that restrict access based on social behaviour or character, and criminal prediction based on personality traits. Also banned are untargeted scraping for facial recognition databases, emotion inference in workplaces and schools, biometric categorisation inferring protected characteristics, and real time remote biometric identification in public spaces (except for narrow law enforcement exceptions).

When did the EU AI Act ban on prohibited practices take effect?

The bans on prohibited practices under Article 5 have been in force since 2 February 2025 across all EU member states. There is no grace period. Organisations must have already stopped using prohibited AI systems.

Is emotion recognition in the workplace illegal in the EU?

Yes, emotion recognition or emotion inference used to make employment decisions about hiring, performance management, promotion or discipline is prohibited under Article 5. The exception is narrow law enforcement use for specific criminal investigations with legal authority.

Is social scoring banned under the EU AI Act?

Yes, social scoring is banned under Article 5. A social scoring system assigns a rating based on social behaviour or character and uses it to restrict access to services or opportunities. This is prohibited for any organisation, public or private. However, systems that rate objective financial capability (like credit scoring) or job-relevant competencies are not social scoring.

Can police use live facial recognition under the EU AI Act?

Law enforcement can use real time remote biometric identification for specific purposes including searching for missing persons, investigating serious crimes, locating crime victims, and preventing imminent threats to public safety or order. Use must be targeted and proportionate. Mass surveillance or general scanning is not permitted.

What is the fine for using a prohibited AI system?

The maximum penalty for violating Article 5 is 35 million EUR or 7 percent of global annual turnover, whichever is higher. For large companies, 7 percent of turnover is typically the binding constraint. Regulators can also issue prohibition orders, corrective orders, publish statements naming the violation, and exclude the organisation from public contracts.

Does the ban on prohibited AI practices apply to companies outside the EU?

Yes, the ban applies to any organisation deploying AI systems that affect residents of the EU. If your product or service is offered to or used by people in the EU and contains a prohibited practice, you must comply even if your company is based outside the EU.

Is AI powered emotion detection allowed in schools?

No, emotion detection or emotion inference AI is prohibited in educational settings when used to make decisions about students, their learning or educational opportunities. The exception is narrow security screening at school entrances to detect threats. Schools cannot use emotion inference to assess whether students are learning effectively.

How do you check whether an AI system is a prohibited practice?

Ask these screening questions: Does the system work below conscious awareness or manipulate behaviour? Does it target and exploit vulnerable populations? Does it assign scores based on social behaviour to restrict access? Does it predict crime from personality traits? Does it involve untargeted facial recognition? Does it infer emotions in employment or education? Does it infer protected characteristics from biometric data? Does it identify people in real time in public space? Document your answers. If any answer raises concern, escalate to legal and compliance teams before deployment.