Regfortis

EU AI Act Article 5: prohibited AI practices — what SMEs must not do

Article 5 bans specific AI applications outright — with no exceptions for SMEs and penalties up to 7% of global turnover. The original list has applied since February 2025; Regulation (EU) 2026/1744 added two further prohibitions from December 2026.

Last regulatory review: 14 August 2026 · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744

What is Article 5?

Article 5 of the EU AI Act is a hard prohibition list — AI systems that fall within it cannot be placed on the market, put into service, or used in the EU, regardless of the sector, the operator's size, or the stated purpose. Unlike the Annex III high-risk categories (which attract heavy obligations but are not banned), Article 5 practices are simply not permitted.

Violation of Article 5 carries the highest penalty in the EU AI Act: up to €35 million or 7% of worldwide annual turnover, whichever is higher. Ensure your AI deployments do not fall within any of the categories below.

Prohibited practices in force since 2 February 2025

The following prohibitions apply to all providers and deployers. Review each category against your current AI use-cases.

Subliminal manipulation

Banned since Feb 2025

AI systems that use techniques operating beyond a person's conscious awareness — such as subliminal messaging or imperceptible stimuli — to substantially impair a person's autonomy and manipulate their behaviour in ways that cause or are likely to cause significant harm. Standard persuasion, advertising, and recommendation does not fall within this prohibition; it targets techniques specifically designed to circumvent conscious decision-making.

Exploitation of protected group vulnerabilities

Banned since Feb 2025

AI systems that exploit vulnerabilities of specific groups — persons with disabilities, older persons, or persons in situations of economic precarity — due to their age, disability, or specific social or economic situation, in a way that distorts their behaviour in a manner that causes or is likely to cause significant harm.

Social scoring by public authorities

Banned since Feb 2025

AI systems used by public authorities, or on their behalf, to evaluate or classify natural persons based on their social behaviour or personal characteristics over a period of time, producing a social score that leads to detrimental or unfavourable treatment of those persons in social contexts unrelated to the context in which the data was collected. This applies specifically to public-authority social scoring; private-sector creditworthiness assessment using relevant data is not covered by this prohibition (though it may trigger Annex III obligations).

Real-time remote biometric identification in public spaces

Banned since Feb 2025

AI systems for real-time remote biometric identification of natural persons in publicly accessible spaces for law enforcement purposes. This prohibition applies with narrow exceptions — notably post-event identification for serious crimes and targeted searches for missing persons — which apply only to law enforcement authorities under strict conditions. For commercial SMEs, there are effectively no circumstances in which real-time biometric identification of members of the public is permitted.

Biometric categorisation for sensitive attribute inference

Banned since Feb 2025

AI systems that use biometric data to categorise natural persons according to their race, political opinions, trade union membership, religious or philosophical beliefs, sexual orientation, or sex life. This prohibition is absolute — the purpose or context does not create exceptions.

Emotion recognition in workplace and educational settings

Banned since Feb 2025

AI systems that infer the emotions of natural persons in the workplace or in educational institutions. Narrow exceptions apply for AI used for safety reasons — for example, detecting drowsiness in vehicle operators — but emotion recognition for performance monitoring, engagement assessment, or attention tracking in professional or educational contexts is prohibited.

Predictive policing based solely on AI profiling

Banned since Feb 2025

AI systems used for risk assessment or prediction of criminal offences based solely on the profiling of natural persons, or based solely on assessing the personality traits and characteristics of an individual. Law enforcement AI that supplements rather than replaces human assessment, and that draws on multiple verified evidence sources, is not covered by this prohibition.

Additional prohibitions from 2 December 2026 — Regulation (EU) 2026/1744

Deadline: 2 December 2026

Regulation (EU) 2026/1744 (the Omnibus amendment to the EU AI Act) extended the Article 5 prohibited practices list with two further prohibitions. These apply from 2 December 2026. Consult the official text of Regulation (EU) 2026/1744 at EUR-Lex for the precise scope of each prohibition, as legal interpretation of newly enacted provisions continues to develop through supervisory guidance.

New prohibition 1 — added by Regulation (EU) 2026/1744

From 2 Dec 2026

Regulation (EU) 2026/1744 adds a further practice to the Article 5 prohibited list, applying from 2 December 2026. Review the official consolidated text of Article 5 at EUR-Lex to determine whether any of your current or planned AI use-cases fall within this new prohibition.

New prohibition 2 — added by Regulation (EU) 2026/1744

From 2 Dec 2026

A second further practice is prohibited from 2 December 2026 under the Omnibus amendment. Businesses should review both new prohibitions against their AI deployment roadmaps before the December 2026 application date.

Consult EUR-Lex for the official consolidated text of Article 5 including Regulation (EU) 2026/1744 amendments.

What most SMEs need to know

Most SMEs — particularly those using standard commercial AI tools for productivity, customer communication, or content creation — are unlikely to be operating prohibited AI systems. The Article 5 list targets specific, high-harm applications that require deliberate design decisions to implement.

However, you should actively verify three areas where SMEs are more likely to inadvertently approach the prohibited zone:

  • HR and recruitment AI — confirm it does not infer candidate emotions, use biometric data to categorise by protected attributes, or base predictions solely on profiling
  • Customer-facing AI — confirm it does not use techniques designed to circumvent conscious awareness or exploit the vulnerabilities of specific customer segments
  • AI-generated or AI-mediated social scoring — if your business evaluates customers, suppliers, or partners using AI-generated scores, confirm the basis and purpose are compliant

Frequently asked questions

Does Article 5 apply to all businesses or only those in specific sectors?

Article 5 applies to all providers and deployers of AI systems within the scope of the EU AI Act, regardless of sector or size. There are no SME exemptions. If your business uses AI in any of the prohibited ways, Article 5 applies.

We use AI to personalise marketing content. Does that count as "subliminal manipulation"?

Personalised marketing is not automatically prohibited. Article 5's subliminal manipulation prohibition targets AI that operates below the threshold of conscious perception — techniques designed to influence behaviour in ways people are not aware of — and that causes significant harm. Standard personalised advertising, recommendation engines, and targeting tools do not typically meet this definition, though this area remains under active supervisory interpretation.

We use HR software that ranks job candidates with AI. Is that banned by Article 5?

AI-assisted recruitment and candidate ranking is not banned by Article 5. However, it falls under the Annex III high-risk category (employment and worker management), which means the full Chapter III obligations apply from December 2027. Article 5 prohibits the specific practice of using AI to infer emotions of job applicants in an employment context — but not AI-assisted shortlisting or ranking based on objective criteria.

What are the penalties for violating Article 5?

Violations of Article 5 carry the highest penalty tier in the EU AI Act: up to €35 million or 7% of global annual turnover, whichever is higher. These are maximum figures — supervisory authorities have discretion in applying them — but the severity reflects the seriousness with which the EU treats these outright prohibitions.

Check your AI use-cases against Article 5

The Regfortis assessment reviews your AI deployment profile against all prohibited practice categories.

Start free assessment

Annex III high-risk guide →

Official sources

Informational only — not legal advice.