Most of the attention around the EU AI Act goes to high-risk systems and the transparency obligations of Article 50. Understandable, because that is where the 2026 and 2027 deadlines sit. But the sharpest part of the regulation has applied since 2 February 2025: Article 5, the list of prohibited AI practices. Anyone who places such a practice on the market, puts it into service or uses it risks the highest fine category in the entire regulation. And contrary to what many organisations assume, this is not just about law enforcement and governments. At least two of the eight bans directly affect HR tooling and marketing technology that ordinary companies buy today.
Who does Article 5 apply to?
The wording of the prohibition is broad: it bans the placing on the market, the putting into service and the use of the listed AI practices. Article 5 therefore covers not only the party that develops or sells a system, but also the organisation that merely uses it. As a buyer, you cannot hide behind your vendor. If you procure a tool that falls under one of the bans and switch it on, you are violating the regulation yourself.
There is no grandfathering for systems that were already running either. Under Article 113(a), the prohibitions have applied since 2 February 2025, to existing and new systems. The postponement arranged through the Digital Omnibus concerns the obligations for high-risk systems. Article 5 is entirely separate from that and has never been postponed.
The eight prohibitions
Article 5(1) lists eight practices. In essence:
a. Manipulation through subliminal or deceptive techniques. Banned are systems that use techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques, to materially distort people's behaviour, causing them to take a decision they would not otherwise have taken, in a way that causes or is reasonably likely to cause significant harm.
b. Exploitation of vulnerabilities. The same prohibition, but aimed at systems that exploit vulnerabilities related to age, disability or a specific social or economic situation. Think of AI-driven sales practices targeting the elderly or people in debt.
c. Social scoring. Evaluating or classifying people over a period of time based on social behaviour or known, inferred or predicted personal characteristics, where the score leads to detrimental treatment in a context unrelated to where the data was collected, or to a disadvantage disproportionate to the behaviour. This ban applies to private parties as well, not only to governments.
d. Predicting criminal offences based on profiling. Systems that predict the risk of a person committing a criminal offence based solely on profiling or personality traits. Supporting a human assessment that already rests on objective, verifiable facts falls outside the ban.
e. Untargeted scraping of facial images. Building or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
f. Emotion recognition in the workplace and in education. Systems that infer people's emotions in the workplace or in education institutions are banned, with a narrow exception for medical and safety reasons. For ordinary companies this is the most relevant prohibition, more on that below.
g. Biometric categorisation on sensitive characteristics. Systems that categorise individuals based on their biometric data to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. Labelling or filtering of lawfully acquired biometric datasets falls outside the ban, as do certain law enforcement applications.
h. Real-time remote biometric identification in publicly accessible spaces for law enforcement. This ban targets police and judicial authorities and has narrowly defined exceptions, such as searching for victims of abduction or human trafficking and the threat of a terrorist attack, each requiring prior authorisation from a judge or independent authority.
The grey area: emotion recognition and manipulation
Among the organisations we assess, two prohibitions come closest in practice.
The first is emotion recognition in the workplace. More and more contact centre and HR software includes features that map the mood, stress or engagement of employees. Sentiment analysis aimed at the customer in a conversation does not fall under this ban, because the customer is not in your workplace. But once the same tooling also analyses the emotions of your own employee, for example in a dashboard showing stress or frustration per agent, you are in prohibited territory. The exception for medical and safety reasons is narrow and does not cover performance or absence management. We advise establishing explicitly, for every tool with an emotion or sentiment feature, who that feature targets, and switching it off or excluding it contractually where employees come into scope.
The second is manipulation. The threshold of Article 5(1)(a) and (b) is deliberately high: there must be a material distortion of behaviour and significant harm. Ordinary personalisation, recommendations and A/B testing rarely reach that threshold. It becomes different when AI is used to steer the decisions of groups that are poorly equipped to resist, such as children in games with AI-driven purchase prompts or financially vulnerable consumers at credit providers. The guidelines on prohibited practices that the European Commission published in February 2025 provide elaboration and examples. They are not binding, but they are the best available indication of how supervisors look at this.
Enforcement and fines
Violating Article 5 carries the highest fine category in the regulation. Article 99(3) sets a maximum of EUR 35 million or 7% of worldwide annual turnover, whichever is higher. For SMEs and startups, Article 99(6) applies the lower of the two amounts. The power to impose fines has been in force since 2 August 2025 and rests with the national market surveillance authorities.
On top of that, Article 5(8) explicitly states that prohibitions under other Union law continue to apply. Emotion recognition of employees or biometric categorisation almost always touches the GDPR as well, and privacy regulators already had their powers. Waiting until AI Act enforcement gathers pace is not a safe strategy.
How to check your own organisation
The Article 5 check belongs at the start of every AI Act programme, before risk classification. A workable approach in four steps. First, inventory all AI systems, including procured tooling and features that vendors have quietly added. Then screen each system against the eight prohibitions, paying particular attention to emotion and sentiment features, scoring of individuals and targeted behavioural influencing. Next, record the conclusion per system, including where that conclusion is "not applicable", because it is precisely that record that shows a supervisor or auditor you performed the check. Finally, embed the screening structurally: in vendor assessments, in procurement, and, for organisations with an ISO 42001 management system, as a fixed part of the AI inventory and the internal audit.
Want to know quickly where your organisation stands with the EU AI Act, including the prohibited practices? Take the self-assessment at /ai-act-check, or contact us to discuss a full AI Act scan.
Source: this article is based on Regulation (EU) 2024/1689 (the AI Act), in particular Article 5, Article 99(3) and (6), and Article 113(a). The full legal text is available at https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Frequently asked questions
Since when do the prohibited AI practices of Article 5 apply?+
Under Article 113(a), the prohibitions have applied since 2 February 2025, to new and existing systems alike. There is no transition period, and the postponement arranged through the Digital Omnibus only concerns high-risk obligations, not Article 5. The supervisory authorities' power to impose fines has been in force since 2 August 2025.
Does Article 5 apply if we only use a system and did not develop it?+
Yes. The prohibition covers placing on the market, putting into service and use of the listed practices. As the buyer of an off-the-shelf tool, you violate Article 5 yourself the moment you switch on a prohibited feature, such as emotion recognition aimed at your own employees.
Is AI emotion recognition banned everywhere?+
No. The ban in Article 5(1)(f) applies specifically to the workplace and education institutions, with a narrow exception for medical and safety reasons. Outside those contexts, emotion recognition can still fall under the high-risk category or transparency obligations, and the GDPR almost always applies as well.
What is the fine for violating Article 5?+
Article 99(3) sets a maximum of EUR 35 million or 7% of worldwide annual turnover, whichever is higher. For SMEs and startups, Article 99(6) applies the lower of the two amounts. Enforcement rests with the national market surveillance authorities.
Does sentiment analysis of customer conversations fall under the ban?+
Sentiment analysis aimed at the customer does not fall under the workplace ban of Article 5(1)(f). The ban does come into play once the same tooling also analyses the emotions of your own employees, for instance in a per-agent stress dashboard. Establish per tool who the emotion feature targets and exclude employee analysis where needed.
Need help with compliance?
Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.
Explore Compliance ServicesAbout the author
Partner | IT Auditor