EU AI Act's Prohibited Practices Now In Force: What You Need to Know
A new era for artificial intelligence governance has officially begun in the European Union. As of February 2, 2025, the European Commission Guidelines regarding prohibited AI practices are officially “In Force,” marking a critical milestone for companies developing or deploying AI systems within the EU market. These guidelines clarify the specific AI practices that are now banned under the landmark EU AI Act, demanding immediate attention from businesses worldwide.
What's changing
The core of this regulatory shift lies in Article 5 of the EU AI Act, which outlines a series of AI practices deemed too risky or harmful for the EU market. The European Commission's recent guidelines, published concurrently with the prohibitions becoming applicable, serve as a vital interpretative tool. While non-binding, these guidelines are crucial for ensuring a consistent understanding and enforcement of these bans across all EU member states. National authorities are expected to rely heavily on them when assessing compliance.
At the heart of the prohibitions are AI systems that manipulate individuals or exploit their vulnerabilities. Specifically, the guidelines clarify bans on:
-
Manipulative AI (Article 5(1)(a)): AI systems that deploy subliminal techniques beyond a person's conscious awareness, or intentionally deceptive techniques, to materially distort a person's behavior. The key here is that this distortion must cause or be likely to cause significant harm. "Significant harm" is broadly defined to include physical, psychological, financial, social, or legal detriment. "Subliminal techniques" refer to methods that influence a person without them being aware of it, such as flashing images too quickly to be consciously registered but still processed by the brain.
-
Exploitative AI (Article 5(1)(b)): AI systems that exploit specific vulnerabilities of a group of persons due to their age, physical or mental disability, or socio-economic situation. This exploitation must also materially distort their behavior in a way that causes or is likely to cause significant harm. For example, an AI system designed to target vulnerable individuals with predatory financial products would fall under this prohibition.
-
Social Scoring (Article 5(1)(c)): AI systems that evaluate or classify people based on their social behavior or personal characteristics, leading to an unjustified or disproportionate detrimental treatment in social contexts. This aims to prevent the creation of systems that assign 'social reliability scores' that could lead to discrimination or exclusion.
-
Untargeted Biometric Scraping: The untargeted scraping of biometric images from the internet or CCTV footage to create or expand facial recognition databases. This prohibition addresses mass surveillance concerns and the privacy implications of collecting vast amounts of biometric data without consent.
-
Emotion Recognition in Sensitive Settings: AI systems used to infer emotions in workplaces and educational institutions. There are narrow exceptions for medical or safety reasons, but the general principle is to prevent intrusive monitoring of emotional states in environments where individuals may feel pressured or coerced.
-
Real-time Remote Biometric Identification in Public Spaces: The use of real-time remote biometric identification systems by law enforcement in publicly accessible spaces is also prohibited, except in very specific, authorised circumstances, such as searching for victims of crime or preventing a specific, substantial and imminent threat.
It's crucial to understand the timeline: while these prohibitions became applicable on February 2, 2025, the full enforcement regime, including the imposition of severe penalties, will only kick in on August 2, 2025. This six-month grace period is intended to give companies time to adapt, but proactive compliance is essential.
Who is affected
The reach of these guidelines and the underlying AI Act is extensive. It applies to both "providers" (developers) and "deployers" (users) of AI systems. Crucially, this includes entities based outside the European Union if their AI systems are intended for use or produce effects within the EU market. This means a company in the US, Asia, or anywhere else, developing an AI product offered to customers in Germany or France, must comply.
Virtually any sector using AI could be affected, from marketing and advertising (due to subliminal techniques) to human resources (emotion recognition), finance (vulnerability exploitation), and public safety (biometric identification). The broad definitions of "significant harm" and "material distortion" mean that even seemingly innocuous systems could inadvertently fall under a prohibited category if they meet the cumulative conditions.
Non-compliance carries severe financial penalties: up to €35 million or 7% of a company's total worldwide annual turnover, whichever is higher. Authorities can also order corrective measures, such as withdrawing a non-compliant system from the market. Given these stakes, a precautionary approach and thorough documentation are highly advisable.
Three things to do this week
With the prohibitions now applicable, immediate action is paramount. Here are three critical steps your organization should take:
- Audit for Subliminal or Deceptive Techniques: Immediately review all AI systems, particularly those involved in customer interaction, marketing, or behavioral analysis. Ensure none use subliminal or intentionally deceptive techniques to materially distort user behavior in a way that could cause significant harm, as prohibited by Article 5(1)(a).
- Assess Vulnerability Exploitation: Conduct a rigorous assessment of your AI systems to ensure they do not exploit vulnerabilities related to age, disability, or socio-economic status to materially distort behavior leading to significant harm, as outlined in Article 5(1)(b). This requires understanding your user base and the potential impact of your AI on vulnerable groups.
- Verify No Social Scoring: Confirm that no AI systems within your organization are used to assign social reliability scores that could lead to unjustified discrimination or detrimental treatment, a practice explicitly banned under Article 5(1)(c). This is particularly relevant for systems involved in credit scoring, employment screening, or public services.
Beyond these specific checks, maintain thorough documentation of your AI systems' design, purpose, and risk assessments. Engage legal counsel to interpret the guidelines in the context of your specific AI applications.
Related context
These guidelines are a direct extension of the broader regulatory framework established by the European Union. To fully understand their implications, it's beneficial to cross-reference them with:
- Regulation (EU) 2024/1689 — Artificial Intelligence Act: This is the foundational legislation that these guidelines elaborate upon. Understanding the full scope of the AI Act is crucial for comprehensive compliance. You can find more information here: [/regulations/RAI-EU-NA-E2AIXXX-2024]
- European Commission Guidelines regarding the definition of an 'AI system': These guidelines clarify what constitutes an 'AI system' under Article 3(1) of the AI Act, which is fundamental to determining whether your systems fall under the regulation's scope at all. Learn more here: [/regulations/RAI-EU-NA-ECGRDXX-2025]
The "In Force" status of these guidelines signals a clear message: the EU is serious about regulating AI. Companies must not only understand the letter of the law but also embrace the spirit of responsible AI development and deployment to navigate this evolving landscape successfully.
Note: this article was drafted by AI - Google Gemini