Social Scoring
AI systems that evaluate or rank people by social behaviour or personal traits and produce scores that cause unfair, disproportionate, or unrelated negative treatment.
Definition
Official/legal definition: Under the EU Artificial Intelligence Act, social scoring is encompassed by the prohibition in Article 5(1)(c) — the placing on the market, putting into service or use of AI systems for the evaluation or classification of natural persons or groups over a certain period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, where the resulting social score leads to either (i) detrimental or unfavourable treatment in social contexts unrelated to where the data were generated or collected, or (ii) detrimental or unfavourable treatment that is unjustified or disproportionate to the person’s social behaviour or its gravity. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
Context and scope: The prohibition is part of the AI Act’s “unacceptable risk” category and is intended primarily to prevent large-scale, systemic use of automated scoring that produces pervasive social effects (often described in policy debate as "social credit" systems). The European Commission’s non‑binding Guidelines on Prohibited AI Practices clarify that the ban targets systems which (a) evaluate or classify people over time, (b) aggregate behaviour or characteristics across multiple contexts without a legitimate, proportionate link to the purpose, and (c) produce a score or classification that leads to detrimental or disproportionate consequences in contexts unrelated to the original data. The Guidelines were published to support consistent application of Article 5 and give practical examples of covered and non‑covered uses. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act))
Practical implications for businesses and public bodies: For any organisation operating in or offering services to the EU market, the prohibition means that deploying, putting into service, or marketing an AI system that meets the cumulative legal criteria of Article 5(1)(c) is unlawful. Developers, deployers and integrators must therefore:
- assess whether an AI scoring or classification feature aggregates social behaviour or personality traits across contexts and over time;
- determine whether downstream uses of a score can lead to treatment in social domains unrelated to the data’s origin; and
- remove, redesign or avoid use-cases that would produce unjustified or disproportionate adverse outcomes.
Organisations should treat social‑scoring risk as a cross-functional compliance issue (legal, privacy, product, risk, and ethics), document purpose and provenance of inputs and uses, and apply risk‑management processes (for example by following voluntary frameworks such as the NIST AI RMF to identify and mitigate societal harms even where that standard does not itself define "social scoring"). ([nvlpubs.nist.gov](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf))
Key requirements / criteria (cumulative) that bring an AI system within the prohibition:
- Temporal element: evaluation or classification occurs over a certain period of time (not a one‑off isolated assessment).
- Content of the evaluation: based on social behaviour or known, inferred or predicted personal or personality characteristics.
- Adverse consequence: the social score leads to (i) detrimental/unfavourable treatment in social contexts unrelated to where the data were generated, and/or (ii) treatment that is unjustified or disproportionate to the behaviour in question.
- Purpose and link: lack of a legitimate, proportionate link between the data sources or the aggregated score and the downstream decision intensifies the risk that the prohibition applies.
These criteria are interpreted in the Commission Guidelines and recital material supporting the Act; whether a particular system is prohibited depends on the concrete combination of these elements. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act))
Examples: Prohibited examples include large‑scale government or delegated systems that aggregate behavior from multiple domains (social media, mobility, public records) to rank "trustworthiness" and then restrict access to housing, travel, benefits or services; or deploying a score created by one authority or firm that another authority uses to deny or reduce access to unrelated social services. By contrast, narrowly targeted, purpose‑limited assessments (e.g., a bona fide creditworthiness check using finance‑relevant data subject to existing sector rules) may fall outside the prohibition but can still trigger other AI Act or sectoral obligations. The OECD and other international bodies highlight social scoring as a governance concern to be addressed by policy and risk frameworks. ([cambridge.org](https://www.cambridge.org/core/journals/international-legal-materials/article/regulation-20241689-of-the-eur-parl-council-of-june-13-2024-eu-artificial-intelligence-act/64F1F6734F8C66CA3EEA149C9759194E?utm_source=openai))
Cross-references and further guidance: See Regulation (EU) 2024/1689, Article 5(1)(c) for the statutory prohibition and the European Commission’s "Guidelines on Prohibited Artificial Intelligence Practices" (4 Feb 2025) for operational interpretation and examples. Organisations should also map social‑scoring risks into lifecycle risk management (for example via the NIST AI RMF) and consider related EU instruments such as data‑protection law (GDPR) and sectoral rules which may be engaged where scoring uses personal data. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
Sources
- •EU AI Act Article 5(1)(c)
- •EU AI Act Recital 31