Prohibited AI Practices: where Article 5 draws the line for EU-bound systems
EU AI Act Article 5 prohibits eight AI practices with EUR 35M penalties. Zertia audits Article 5 compatibility under ISO 42001.
Definition
Prohibited AI practices are the categories of AI system use that the EU AI Act bans outright — regardless of technical design, deployment context, or claimed beneficial purpose. Article 5 of the EU AI Act defines these as AI applications that pose unacceptable risks to fundamental rights, human dignity, and democratic values. They have been prohibited since 2 August 2025 — the first enforcement date of the regulation.
The prohibited practices under Article 5 include: subliminal manipulation techniques that exploit unconscious biases or vulnerabilities to distort behavior in ways that harm individuals; exploitation of vulnerabilities of specific groups (age, disability) to distort behavior harmfully; social scoring systems by public authorities that evaluate trustworthiness based on behavior and use those scores to the detriment of individuals; real-time remote biometric identification in publicly accessible spaces by law enforcement (with narrow exceptions for serious crime); biometric categorisation systems that infer sensitive characteristics (political opinions, religious beliefs, sexual orientation) from biometric data; emotion recognition in workplace and educational settings; and AI systems that predict future criminal behavior based on personality or profiling.
Why it matters operationally
Prohibited practices matter because they are the EU AI Act’s hardest line: no legitimate purpose, no proportionality assessment, no risk mitigation measure can justify their deployment. An organization that deploys a prohibited AI practice faces fines of up to 35 million euros or 7% of global annual turnover — the highest penalty tier in the regulation — regardless of whether harm actually materialized.
The practical challenge for many organizations is that some prohibited practices are not obviously recognizable as such. Emotion recognition systems in HR technology may be embedded in performance monitoring platforms. Social scoring features may be components of customer relationship management or creditworthiness systems. Biometric categorization capabilities may be present in security or access management systems. Organizations need to audit their AI systems specifically for prohibited practice components — not just at the system level, but at the feature level.
Regulatory framework
| Framework | Prohibited practices scope |
|---|---|
| EU AI Act — Art. 5 | Defines prohibited AI practices. In force since 2 August 2025. Maximum Regulation penalties: up to €35M or 7% of global turnover. |
| EU Charter of Fundamental Rights | Article 5 prohibitions derive directly from Charter values: human dignity, non-discrimination, data protection, freedom of thought. |
| GDPR | Several EU AI Act prohibited practices also violate GDPR independently (biometric data processing without adequate legal basis, discriminatory scoring). |
How Zertia evaluates it
Zertia’s EU AI Act Assessment includes an explicit screening for prohibited AI practice components as a first-order priority. Before any risk classification or compliance gap analysis, the assessment evaluates whether any feature or function of the organization’s AI systems falls within Article 5’s prohibited categories. A finding of prohibited practice components triggers immediate escalation — these are not gaps to remediate; they are uses to cease.
Definitions that hold up under audit.
Does this term apply to your certification project? Let's talk 30 minutes, no commercial pressure.
