European Union - Prohibited AI Practices Guidelines
European Commission Guidelines regarding prohibited AI practices (guidance on Article 5 prohibitions)
European Union
RAI-EU-NA-ECGRPXX-2025The European Commission published non-binding Guidelines on prohibited artificial intelligence practices on 4 February 2025 to clarify the scope and application of Article 5 of Regulation (EU) 2024/1689 (the AI Act). The Guidelines explain the prohibited categories (manipulation, exploitation of vulnerabilities, social scoring, biometric scraping, emotion inference, certain law‑enforcement biometric ID uses and predictive criminal risk assessments), give practical examples and exceptions, and support consistent enforcement across Member States ahead of the penalties regime coming into application on 2025-08-02.
Summary
On 4 February 2025 the European Commission published non-binding Guidelines on prohibited artificial intelligence practices to accompany and clarify Article 5 of the Artificial Intelligence Act (Regulation (EU) 2024/1689). Article 5 lists AI uses that constitute an unacceptable risk and are therefore prohibited across the Union: (a) systems deploying subliminal, manipulative or deceptive techniques that materially distort behaviour and are reasonably likely to cause significant harm; (b) systems that exploit vulnerabilities arising from age, disability or socio-economic situation to cause significant harm; (c) social scoring systems that classify individuals or groups in ways likely to produce unjustified or disproportionate treatment; (d) AI systems that predict or assess an individual’s likelihood of committing a criminal offence solely through profiling; (e) large-scale untargeted scraping to create facial recognition databases; (f) biometric categorisation that infers protected characteristics (race, political opinions, trade union membership, religion, sexual orientation, etc.); and (g) real‑time remote biometric identification in publicly accessible spaces for law-enforcement purposes, subject to narrow, exceptional carve-outs.
The Guidelines were designed to provide practical, operational definitions and cumulative conditions for each prohibition so providers, deployers, national authorities and courts can apply Article 5 consistently. They emphasize that the prohibitions apply to placing on the market, putting into service and the use or deployment of AI systems and that both objective and effect-based criteria may trigger the ban (i.e., an effect reasonably likely to occur can suffice even if there is no proven intent). The Guidance explains what constitutes "materially distorting behaviour" and "significant harm" (physical, psychological, economic, social, or legal), clarifies the scope of "vulnerabilities", and distinguishes banned biometric categorisation and emotion inference from permitted, narrowly tailored medical, safety or research uses. It also clarifies the meaning of "real-time" and "publicly accessible spaces" for remote biometric identification and the limited law‑enforcement exceptions (e.g., targeted searches for missing victims, imminent threats, or investigations meeting strict authorisation and oversight requirements).
The Commission explicitly notes the Guidelines are non-binding and that authoritative interpretation remains with the Court of Justice of the European Union; nevertheless, they are intended to be persuasive for national competent authorities, market surveillance authorities and courts. The document also explains interactions with other EU instruments (notably the GDPR, the Law Enforcement Directive, anti‑discrimination law and sectoral safety rules) and describes enforcement sequencing: Chapter I and II rules (including Article 5) applied from 2 February 2025, while the full enforcement and penalties regime (and governance obligations) became applicable on 2 August 2025. National market surveillance and supervisory authorities are responsible for enforcement, coordinated by the EU AI Office and the European AI Board. Non‑compliance with Article 5 is subject to the highest-tier administrative fines under the AI Act (up to EUR 35,000,000 or 7% of worldwide turnover), plus other corrective measures, with Member States required to set up penalty rules and notify the Commission. The Guidelines are a living instrument and the Commission plans updates informed by stakeholder feedback, case law and implementation experience.
Full article
Read full text ↗Overview
The European Commission's "Guidelines on prohibited artificial intelligence (AI) practices" (published 4 February 2025) interpret and operationalise Article 5 of Regulation (EU) 2024/1689 (the AI Act). The Guidance identifies and explains the cumulative conditions that make an AI application fall within the AI Act's prohibited category (for example, manipulation using subliminal techniques, exploitation of vulnerabilities, social scoring, biometric scraping and emotion inference in workplaces or educational settings). The document aims to promote consistent application across Member States by providers, deployers and national competent authorities. The Guidelines are non‑binding; the authoritative legal interpretation rests with the Court of Justice of the European Union, but the Commission expects national authorities to rely on these clarifications. For the official publication and downloads see the Commission library page: Commission: Guidelines on prohibited AI practices (4 Feb 2025) and the Commission redirection to the English guideline document: Guidelines on prohibited artificial intelligence practices (English).
Definitions
The Guidelines provide working definitions to reduce ambiguity: "materially distorting behaviour" is framed as influence that appreciably impairs a person's ability to make an informed, autonomous decision and causes or is reasonably likely to cause "significant harm" (which includes physical, psychological, financial, social or legal harms). "Subliminal techniques" are defined as inputs beyond a person's conscious perception; "purposefully manipulative or deceptive techniques" cover engineered persuasion tactics that go beyond lawful persuasion and lead to appreciable impairments. "Vulnerabilities" are understood functionally (e.g., cognitive, developmental, socio-economic) and not limited to medical conditions. "Real-time" denotes negligible delay between capture and identification; "publicly accessible spaces" include streets and open squares but exclude controlled-access environments such as prisons and certain online spaces. These working definitions guide the cumulative tests applied to each Article 5 subparagraph.
Governance and Institutional Framework
The Guidelines situate Article 5 within the AI Act's phased application: Chapters I and II (including Article 5) have applied since 2 February 2025, while governance, enforcement and penalties fully applied as of 2 August 2025. Member States must designate national market surveillance authorities and notify the Commission; the Commission's European AI Office and the European AI Board coordinate implementation, provide further guidance and support consistency across Member States. Enforcement actors include national competent authorities, market surveillance authorities, data protection authorities (where GDPR issues intersect), the European Data Protection Supervisor (for Union institutions) and courts. The Guidance stresses cooperation and information exchange, and references the AI Act's requirement that Member States notify national rules on penalties and enforcement measures to the Commission. See the AI Act authoritative text at EUR-Lex: Regulation (EU) 2024/1689 (AI Act) — EUR-Lex and the AI Act Service Desk explanatory pages at AI Act Service Desk – Article 5.
Key Focus Areas
The Guidelines break Article 5 into discrete prohibited practices and explain each with cumulative conditions and examples. Key focus areas include: (1) Manipulation and deception (Art. 5(1)(a)) — AI that uses subliminal or engineered persuasive techniques to materially distort behaviour; (2) Exploitation of vulnerabilities (Art. 5(1)(b)) — targeting persons because of age, disability or socio‑economic status; (3) Social scoring (Art. 5(1)(c)) — assigning social reliability scores leading to unjustified discrimination; (4) Predictive criminal risk assessments (Art. 5(1)(d)) — profiling individuals to predict criminality solely on automated inference; (5) Untargeted scraping for facial recognition databases (Art. 5(1)(e)) — mass collection of biometric images from the internet or CCTV without consent or a lawful basis; (6) Biometric categorisation of protected attributes (Art. 5(1)(g)) — systems inferring race, religion, political opinions, sexual orientation, trade union membership and similar sensitive traits; (7) Emotion inference in workplaces and educational institutions (Art. 5(1)(f)) — inference of a specific individual's emotions (distinct from aggregate mood analysis), except narrowly for medical or safety reasons; and (8) Real-time remote biometric identification in public spaces for law enforcement (Art. 5(1)(h)) — banned except for strict, narrowly defined exceptions like locating missing persons or preventing an imminent threat subject to authorisation and oversight. The Guidelines detail the interplay of objective and effect-based tests and provide use case examples to help providers assess compliance.
Implementation Framework
The Guidance recommends an implementation approach for providers and deployers: (1) early legal and technical screening to determine whether an AI system falls within Article 5 prohibitions; (2) lifecycle documentation and records to show decisions and assessments; (3) obligations to cease placing on the market, to withdraw, or to prevent use where a system constitutes a prohibited practice; (4) cooperation with national competent authorities, including providing requested information and, where required, assistance in mitigation or withdrawal; and (5) embedding AI literacy and governance measures among staff and contractors. The document emphasises that even where a practice is not expressly listed in Article 5, providers should evaluate whether a given system meets the cumulative criteria (objective/effect, material distortion, significant harm) and should take a precautionary approach where uncertainty exists. The guidelines also identify permitted narrow exceptions (medical/safety, strictly necessary law enforcement cases with authorisation, research/testing under safeguards, and certain tagging or annotation activities) and clarify that free/open-source development may still be captured if actual deployment constitutes a prohibited practice.
Monitoring and Evaluation
The Guidelines set out monitoring expectations: Member States' market surveillance authorities and national competent supervisory bodies are to perform post-market monitoring and cooperate through the European AI Board and the AI Office. The Commission recommends periodic reviews of emerging use cases and invites national authorities to report trends, enforcement actions, and open issues to inform updates. Providers and deployers are encouraged to maintain post-market monitoring logs, incident reporting mechanisms and to perform regular audits for inadvertent drift that could transform a permitted system into one producing prohibited effects. The Guidance also asks national bodies to collect evidence-based case studies to refine legal interpretation and to feed into potential future delegated or implementing acts where needed.
Penalties, Liability, and Appeals
The AI Act's penalties framework is summarised and linked to the Guidelines: non-compliance with Article 5 is subject to the top-tier administrative fines (up to EUR 35,000,000 or up to 7% of the offender's total worldwide annual turnover, whichever is higher). Member States must implement effective, proportionate and dissuasive penalties, and formally notify the Commission of national penalty rules. The Guidelines explain that in addition to fines, authorities may order corrective measures (withdrawal, suspension of operations, orders to bring systems into conformity) and criminal or civil liability may follow under national law. The Guidance details defence and procedural safeguards, including rights to be heard and appeal routes before national courts and, where applicable, referral to the CJEU for legal questions. It notes the GDPR interplay where biometric or sensitive personal data processing also triggers supervisory authority actions and penalties under data protection rules.
Relationship to Other Instruments
The Commission explains how Article 5 interacts with existing EU instruments. The Guidelines stress compliance with the GDPR (Regulation (EU) 2016/679) for personal data processing and with the Law Enforcement Directive where processing is for law‑enforcement purposes; they also reference Union non‑discrimination law, sectoral safety rules (e.g., medical devices, transport safety), and product/supply chain safety legislation. The Guidance clarifies that where other legal regimes already prohibit or regulate certain practices (e.g., national bans on some biometric uses), Article 5 operates alongside and may reinforce those protections. It also underscores that national security, defence, certain judicial cooperation uses and some research activities are excluded from the AI Act's scope, per the Regulation's exclusions.
International Alignment
The Guidelines encourage international cooperation and note that the EU intends these interpretations to inform global approaches. The Commission invites exchanges with partners, standardisation bodies and multilateral fora to promote convergence on unacceptable AI practices and to avoid regulatory fragmentation that could undermine human rights protections. The document references the need to align, where possible, with international human‑rights standards and comparable regulatory developments (including OECD AI principles, Council of Europe work, and multilateral dialogues). However, the Guidance clarifies that extraterritorial application of Article 5 means third-country providers placing AI systems on the EU market or making them available in the Union must comply with the prohibitions.
Implementation Timeline
| Event | Date |
|---|---|
| AI Act (Regulation (EU) 2024/1689) adopted | 2024-06-13 |
| AI Act entered into force | 2024-08-01 |
| Article 5 (Prohibitions) and Chapters I–II came into application | 2025-02-02 |
| Commission publishes Guidelines on prohibited AI practices | 2025-02-04 |
| Full applicability of governance, enforcement and penalties (Member States notify authorities and penalties) | 2025-08-02 |
Sources and References
Requirements for a company
What an organisation has to do under European Union - Prohibited AI Practices Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
14- Do not deploy AI systems that use subliminal or deceptive techniques to materially distort behavior.Providers and deployers of AI systems.
- Do not deploy AI systems that exploit vulnerabilities of persons due to age, disability, or socio-economic status.Providers and deployers of AI systems.
- Do not deploy AI systems that assign social reliability scores leading to unjustified discrimination.Providers and deployers of AI systems.
- Do not deploy AI systems that profile individuals to predict criminality solely on automated inference.Providers and deployers of AI systems.
- Do not deploy AI systems for untargeted scraping of biometric images from public sources for facial recognition databases.Providers and deployers of AI systems.
- Do not deploy AI systems that infer sensitive protected attributes like race, religion, or sexual orientation from biometric data.Providers and deployers of AI systems.
- +8 more in the table below
Must not do
0Nothing in this category.
Should do
1- Embed AI literacy and governance measures among staff and contractors.Providers and deployers of AI systems.
Should not do
0Nothing in this category.
Who must do what
The obligations under European Union - Prohibited AI Practices Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Providers and deployers of AI systems. | Do not deploy AI systems that use subliminal or deceptive techniques to materially distort behavior. “AI that uses subliminal or engineered persuasive techniques to materially distort behaviour.” | Since 2025-02-02 | Article 5(1)(a) | Critical |
| 2 | Providers and deployers of AI systems. | Do not deploy AI systems that exploit vulnerabilities of persons due to age, disability, or socio-economic status. “Exploitation of vulnerabilities (Art. 5(1)(b)) — targeting persons because of age, disability or socio‑economic status.” | Since 2025-02-02 | Article 5(1)(b) | Critical |
| 3 | Providers and deployers of AI systems. | Do not deploy AI systems that assign social reliability scores leading to unjustified discrimination. “Social scoring (Art. 5(1)(c)) — assigning social reliability scores leading to unjustified discrimination.” | Since 2025-02-02 | Article 5(1)(c) | Critical |
| 4 | Providers and deployers of AI systems. | Do not deploy AI systems that profile individuals to predict criminality solely on automated inference. “Predictive criminal risk assessments (Art. 5(1)(d)) — profiling individuals to predict criminality solely on automated inference.” | Since 2025-02-02 | Article 5(1)(d) | Critical |
| 5 | Providers and deployers of AI systems. | Do not deploy AI systems for untargeted scraping of biometric images from public sources for facial recognition databases. “Untargeted scraping for facial recognition databases (Art. 5(1)(e)) — mass collection of biometric images from the internet or CCTV.” | Since 2025-02-02 | Article 5(1)(e) | Critical |
| 6 | Providers and deployers of AI systems. | Do not deploy AI systems that infer sensitive protected attributes like race, religion, or sexual orientation from biometric data. “Biometric categorisation of protected attributes (Art. 5(1)(g)) — systems inferring race, religion, political opinions, sexual orientation.” | Since 2025-02-02 | Article 5(1)(g) | Critical |
| 7 | Providers and deployers of AI systems. | Do not deploy AI systems to infer individual emotions in workplaces or educational settings, except for medical or safety reasons. “Emotion inference in workplaces and educational institutions (Art. 5(1)(f)) — inference of a specific individual's emotions.” | Since 2025-02-02 | Article 5(1)(f) | Critical |
| 8 | Providers and deployers of AI systems (especially for law enforcement). | Do not deploy real-time remote biometric identification systems in public spaces for law enforcement, except for strict, authorized exceptions. “Real-time remote biometric identification in public spaces for law enforcement (Art. 5(1)(h)) — banned except for strict, narrowly defined exceptions.” | Since 2025-02-02 | Article 5(1)(h) | Critical |
| 9 | Providers and deployers of AI systems. | Cease placing on the market, withdraw, or prevent use of any AI system constituting a prohibited practice. “obligations to cease placing on the market, to withdraw, or to prevent use where a system constitutes a prohibited practice.” | Immediately upon identification | — | Critical |
| 10 | Providers and deployers of AI systems. | Conduct early legal and technical screening to determine if an AI system falls under Article 5 prohibitions. “early legal and technical screening to determine whether an AI system falls within Article 5 prohibitions.” | Before placing on market or deploying | — | Important |
| 11 | Providers and deployers of AI systems. | Maintain lifecycle documentation and records of decisions and assessments regarding Article 5 compliance. “lifecycle documentation and records to show decisions and assessments.” | Ongoing, throughout the AI system lifecycle | — | Important |
| 12 | Providers and deployers of AI systems. | Cooperate with national authorities by providing requested information and assistance for mitigation or withdrawal. “cooperation with national competent authorities, including providing requested information and, where required, assistance.” | Upon request | — | Important |
| 13 | Providers and deployers of AI systems. | Evaluate AI systems against cumulative criteria (objective/effect, material distortion, significant harm) and take a precautionary approach. “providers should evaluate whether a given system meets the cumulative criteria... and should take a precautionary approach.” | Before placing on market or deploying | — | Important |
| 14 | Providers and deployers of AI systems. | Maintain post-market monitoring logs, incident reporting, and regular audits for prohibited effects. “Providers and deployers are encouraged to maintain post-market monitoring logs, incident reporting mechanisms and to perform regular audits.” | Ongoing, post-market | — | Important |
| 15 | Providers and deployers of AI systems. | Embed AI literacy and governance measures among staff and contractors. “embedding AI literacy and governance measures among staff and contractors.” | Ongoing | — | Recommended |
Related Regulations
European Commission Guidelines regarding the definition of an 'AI system' (clarifying Article 3(1) of the AI Act)
European Union93% similar
European Commission Guidelines on the scope of obligations for providers of General‑Purpose AI models
European Union92% similar
Ethics Guidelines for Trustworthy AI (High-Level Expert Group on AI)
European Union90% similar
European Union AI Regulation Overview
European Union90% similar
White Paper on Artificial Intelligence: A European approach to excellence and trust
European Union90% similar
© Regulations.AI · updated on 21-Jul-2026