🛡 HLINIX
EU AI Act Implementation Guide — Chapter 4 of 15

Chapter 4: Prohibited AI — The Lines Nobody Can Cross

Published 30 March 2026 · 20 min read

What you will know after reading this chapter:

By the end of this chapter, you will understand every prohibited AI practice under the EU AI Act, be able to assess whether any of your AI systems fall into this category, and know exactly what to do if one does.

Why this chapter comes first in the obligations sequence

Prohibited AI is the only category where there is no compliance pathway. For high-risk systems, you can implement obligations and continue operating. For limited-risk, you add transparency measures. For prohibited AI, the only legal option is to stop. This is why, in the navigation table at the end of Chapter 3, we directed anyone with a potentially prohibited system to read this chapter immediately.

The prohibition has been enforceable since 2 February 2025. There is no transition period, no grace period, and no self-certification process. If you are operating a prohibited AI practice today, you are already in violation.

The fine is the highest in the entire AI Act: up to €35 million or 7% of global annual turnover, whichever is greater. For context, the GDPR maximum fine is €20 million or 4% of turnover. The AI Act deliberately set the bar higher for prohibited practices to signal the severity of these violations.

The eight prohibited practices in detail

Article 5 lists eight categories of AI practices that are banned in the EU. We covered them briefly in Chapter 3 for classification purposes. This chapter goes deeper — explaining not just what is prohibited, but why, what the boundaries are, and how to assess whether your system is at risk.

1. Social scoring

What is prohibited: The placing on the market, the putting into service or the use of AI systems that evaluate or classify natural persons or groups of persons over a period of time based on their social behaviour or known, inferred, or predicted personal or personality characteristics, where the resulting social score leads to either detrimental or unfavourable treatment of those persons in social contexts unrelated to the context in which the data was originally collected, or detrimental or unfavourable treatment that is unjustified or disproportionate to their social behaviour or its gravity.

Why it is banned: Social scoring creates a surveillance infrastructure that fundamentally undermines individual autonomy and dignity. Recital 31 states that social scoring “by public or private actors” may lead to discriminatory outcomes and the exclusion of certain groups. The EU considers this incompatible with the values of a democratic society.

The boundary: The prohibition applies to public and private operators alike — the “public authorities only” limitation that appeared in the 2021 draft was removed before adoption. What separates a prohibited social score from lawful scoring is not who runs it, but two things: the score must be built from social behaviour or personal/personality characteristics observed over time, and it must lead to detrimental treatment either in a context unrelated to where the data was collected or disproportionate to the behaviour scored. Recital 31 confirms that lawful evaluation practices carried out for a specific purpose in accordance with Union and national law are unaffected. So a bank scoring customers’ creditworthiness on financial data to decide loan eligibility is high-risk under Annex III point 5(b), not prohibited — but a private company scoring people on unrelated social behaviour and using that score to deny them services could fall inside Article 5(1)(c).

Self-assessment question: Does your organisation use AI to assign scores or ratings to individuals based on their social behaviour or personal characteristics over time, where those scores lead to detrimental treatment in an unrelated context or out of proportion to the behaviour scored? This applies whether you are a public body or a private company.

2. Exploitation of vulnerabilities

What is prohibited: AI systems that place on the market, put into service, or use techniques that deliberately exploit any of the vulnerabilities of a person or a specific group of persons due to their age, disability, or a specific social or economic situation, with the objective or the effect of materially distorting the behaviour of that person or a group of persons in a manner that causes or is reasonably likely to cause that person or another person significant harm.

Why it is banned: People in vulnerable situations — the elderly, children, people with disabilities, people in financial distress — deserve protection from AI systems designed to exploit their vulnerabilities for commercial or other gain.

The boundary: The key elements are “deliberately exploit,” “vulnerabilities,” and “significant harm.” A general advertising AI that happens to reach elderly people is not prohibited. An AI system specifically designed to detect cognitive vulnerabilities in elderly users and present them with misleading offers is prohibited. The intent or predictable effect of exploitation is what matters, combined with the likelihood of significant harm.

Practical example: An AI-powered lending platform that identifies users showing signs of financial distress and deliberately presents them with high-interest loan products designed to trap them in debt cycles. The system is not simply offering loans — it is targeting vulnerability for profit.

Self-assessment question: Does your AI system specifically identify or target individuals based on age, disability, or socioeconomic vulnerability, and use that identification to influence their behaviour in ways that could cause them harm?

3. Real-time remote biometric identification in public spaces

What is prohibited: The use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement, except in strictly limited situations.

Why it is banned: Mass biometric surveillance in public spaces creates a chilling effect on freedom of assembly, expression, and movement. The EU considers the societal risks of normalising this technology to outweigh the law enforcement benefits in most circumstances.

The exceptions (each requires prior authorisation by a judicial authority or an independent administrative authority whose decision is binding): The prohibition does not apply in three narrowly defined situations. First, the targeted search for specific victims of abduction, trafficking, or sexual exploitation, and the search for missing persons. Second, the prevention of a specific, substantial, and imminent threat to the life or physical safety of natural persons, or a genuine and present or foreseeable threat of a terrorist attack. Third, the localisation or identification of a person suspected of having committed a criminal offence referred to in Annex II and punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years.

Even where these exceptions apply, the use must be strictly necessary, proportionate, and subject to prior authorisation by a judicial authority or an independent administrative authority whose decision is binding (Article 5(3)). In a duly justified situation of urgency, use may begin before authorisation, provided the authorisation is requested without undue delay and at the latest within 24 hours; if it is refused, use must stop immediately and the data and outputs must be deleted. The system must also be registered in the EU database under Article 49, and each use must be notified to the relevant market surveillance authority and the national data protection authority (Article 5(4)).

The boundary: This prohibition is specifically about real-time identification in publicly accessible spaces for law enforcement. It does not cover post-identification (analysing recorded footage after the fact, which may be high-risk), private spaces (a company using facial recognition for building access), or non-law-enforcement use (though other rules may apply).

Self-assessment question: Does your organisation use AI to identify individuals in real-time through biometric data in any publicly accessible space for law enforcement or security purposes?

4. Emotion recognition in workplaces and educational institutions

What is prohibited: AI systems that infer the emotions of a natural person in the areas of the workplace and education institutions, except where the AI system is intended to be put into service or placed on the market for medical or safety reasons.

Why it is banned: Monitoring people’s emotional states in environments where there is an inherent power imbalance — employer/employee, teacher/student — creates pressure to perform emotional conformity and undermines the dignity and privacy of individuals in those settings.

The exceptions: AI systems intended for medical purposes (such as detecting signs of pain in patients who cannot communicate) and safety purposes (such as detecting driver drowsiness or fatigue in professional driving contexts) are permitted.

The boundary: This prohibition is context-specific, not technology-specific. The same emotion recognition technology might be prohibited in a workplace, high-risk in a law enforcement context (Annex III point 6), and limited-risk in a consumer entertainment application. Where you deploy it determines the classification.

Practical examples: Prohibited: An AI system that analyses employees’ facial expressions during video calls to generate “engagement scores” for performance reviews. Prohibited: An AI system used in a school to monitor students’ attention levels during classes based on facial expression analysis. Not prohibited: An AI system in a vehicle that monitors the driver’s eye movements and facial expressions to detect drowsiness and trigger an alert. This is a safety application and falls under the exception.

Self-assessment question: Does your AI system analyse or infer the emotions of individuals in a workplace or educational setting? If yes, is it specifically for medical or safety purposes?

5. Biometric categorisation based on sensitive attributes

What is prohibited: AI systems that categorise individually natural persons based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation. This prohibition does not apply to labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric data, or categorisation of biometric data in the area of law enforcement.

Why it is banned: Using biometric data (facial features, voice characteristics, gait, etc.) to infer sensitive personal characteristics enables a form of discrimination that is fundamentally at odds with EU values of equality and non-discrimination.

The boundary: The prohibition specifically covers using biometric data to infer sensitive characteristics. A facial recognition system that identifies who a person is (biometric identification) is a different function and falls under different rules. The prohibited practice is using biometric data to infer what a person is — their race, religion, political beliefs, or sexual orientation.

Self-assessment question: Does your AI system use biometric data (facial features, voice, gait, or other physical characteristics) to categorise people by race, religion, political opinion, sexual orientation, or other sensitive attributes?

6. Untargeted scraping for facial recognition databases

What is prohibited: AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage.

Why it is banned: Building facial recognition databases by mass-scraping images without consent creates an infrastructure for mass surveillance that is incompatible with fundamental rights, particularly the right to privacy and data protection.

The boundary: The key word is “untargeted.” A law enforcement agency that collects facial images of specific suspects through lawful means is not covered by this prohibition. A company that scrapes millions of publicly available photos from social media to build a facial recognition database is prohibited. This practice directly targets companies operating models similar to Clearview AI.

Self-assessment question: Does your AI system collect facial images from the internet or CCTV footage on an untargeted, mass basis to build or expand a facial recognition database?

7. Predictive policing based solely on profiling

What is prohibited: AI systems that make risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics. This does not apply to AI systems used to support the human assessment of the involvement of a person in a criminal activity, where this is already based on objective and verifiable facts directly linked to a criminal activity.

Why it is banned: Predicting criminal behaviour based solely on who a person is — their profile, personality, demographics — rather than what they have done is a form of pre-crime judgment that violates the presumption of innocence.

The boundary: The critical qualifier is “based solely on profiling.” AI systems that assist law enforcement by analysing patterns in crime data, linking evidence, or assessing risks based on objective facts connected to actual criminal activity are not prohibited — though they are likely high-risk under Annex III point 6. The prohibition targets systems that predict criminality from personal characteristics alone.

Self-assessment question: Does your AI system predict the likelihood of an individual committing a crime based on their personal profile, characteristics, or demographics rather than on objective facts linked to criminal activity?

8. Subliminal manipulation

What is prohibited: AI systems that deploy subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques, with the objective or the effect of materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing or being reasonably likely to cause that person or another person significant harm.

Why it is banned: AI systems capable of influencing behaviour below the level of conscious awareness, or through deliberate manipulation, undermine human autonomy and the ability to make free, informed choices.

The boundary: Normal persuasion, marketing, or recommendation systems are not prohibited, even if they are effective at influencing behaviour. The prohibition targets techniques that operate below conscious awareness or that are purposefully manipulative in a way that impairs informed decision-making and causes significant harm. An AI-powered recommendation engine that suggests products is not prohibited. An AI system that uses micro-targeted psychological manipulation techniques to compel vulnerable users to make purchases they cannot afford, bypassing their conscious decision-making, may be prohibited.

Self-assessment question: Does your AI system use techniques specifically designed to influence people’s behaviour below their level of conscious awareness, or through deliberate deception, in ways likely to cause significant harm?

What to do if your system might be prohibited

If any of the self-assessment questions above gave you pause, take the following steps:

Step 1: Do not ignore it. The prohibition is already in force. Every day of continued operation increases your legal exposure.

Step 2: Conduct a formal assessment. Document your AI system’s functionality, purpose, and the specific Article 5 category you are concerned about. Assess each element of the prohibition against your system’s actual operation.

Step 3: Seek legal advice. The boundaries of several prohibited categories — particularly subliminal manipulation and exploitation of vulnerabilities — involve subjective elements that may require legal interpretation.

Step 4: If prohibited, discontinue immediately. There is no compliance pathway for prohibited AI. Discontinue the practice, document the discontinuation, and retain records showing when you stopped and what steps you took.

Step 5: Assess whether a modified version is permissible. In some cases, the underlying technology may be redirected to a non-prohibited use. An emotion recognition system that is prohibited in the workplace might be permissible as a safety feature in vehicles. However, the new use case must be independently classified.

The relationship between prohibited and high-risk

Several technologies sit near the boundary between prohibited and high-risk. Understanding this boundary is critical:

Emotion recognition: Prohibited in workplaces and educational institutions. High-risk under Annex III point 1(c), which covers AI systems intended to be used for emotion recognition. Limited-risk in other contexts, where Article 50(3) requires the deployer to inform the persons exposed to the system.

Biometric identification: Real-time remote biometric identification in public spaces for law enforcement is prohibited (with exceptions). Post-identification (analysing recorded footage) and non-public-space use may be high-risk.

Predictive policing: Predicting crime based solely on profiling is prohibited. AI systems supporting human assessment based on objective facts linked to criminal activity are high-risk under Annex III point 6.

Social scoring: Social scoring is prohibited for public and private actors alike where the score leads to detrimental treatment in an unrelated context or disproportionate to the behaviour scored. Credit scoring on financial data is high-risk under Annex III point 5(b), not prohibited.

The pattern is consistent: the prohibited category captures the most extreme, rights-threatening applications. When the same technology is used in a less extreme context, it moves to high-risk with compliance obligations rather than a ban.

Self-Check: Article 5 Compliance Assessment

For each AI system in your organisation, answer all eight questions below. If you answer “Yes” or “Possibly” to any question, that system requires immediate further assessment.

#QuestionYes / No / Possibly
1Does the system score or classify individuals based on social behaviour, leading to detrimental treatment in an unrelated context or disproportionate to that behaviour?
2Does the system deliberately target people’s vulnerabilities (age, disability, socioeconomic) to influence behaviour?
3Does the system perform real-time biometric identification in public spaces for law enforcement?
4Does the system infer emotions in a workplace or educational setting (not for medical/safety purposes)?
5Does the system use biometric data to infer race, religion, political opinions, or sexual orientation?
6Does the system scrape facial images from the internet or CCTV on an untargeted basis?
7Does the system predict criminal behaviour based solely on personal profiling?
8Does the system use subliminal or deliberately manipulative techniques likely to cause significant harm?

If all answers are “No,” your systems are clear of Article 5 prohibitions. Proceed based on your classification from Chapter 3: high-risk systems → Chapter 5, limited-risk systems → Chapter 9, minimal-risk systems → Chapter 10, out-of-scope systems → Chapter 11.

If any answer is “Yes” or “Possibly,” do not proceed until you have completed the formal assessment process described above.

Summary

Article 5 of the EU AI Act prohibits eight categories of AI practices that the EU considers fundamentally incompatible with democratic values and fundamental rights. These prohibitions have been in force since 2 February 2025, with no transition period. The maximum fine for operating a prohibited system is €35 million or 7% of global turnover. Several technologies — particularly emotion recognition, biometric identification, and predictive policing — exist on a spectrum from prohibited to high-risk, depending on the specific context and use case. If any of your AI systems may fall into a prohibited category, the priority is immediate assessment and, if confirmed, discontinuation. There is no compliance pathway for prohibited AI — only cessation. Once you have confirmed that none of your systems are prohibited, the next step is to understand what makes a system high-risk and what that means for your obligations, which is the subject of Chapter 5.

← Back to Blog Summary

Check your AI system now

Use our free compliance checker to find out your risk classification in 2 minutes.

Check Your AI Risk Level — Free