EU AI Act prohibited practices

A short list of AI uses the Act bans outright. Whether a use is caught is a scope question, not something training or a notice can fix.

Article 5 prohibits a defined list of AI practices. The original eight have applied since 2 February 2025, and Regulation (EU) 2026/1744 added two more that apply from 2 December 2026.

The prohibitions sit in Article 5 of Regulation (EU) 2024/1689, in Chapter II. They bind whoever is within the Act's scope, so settle scope first: a UK organisation with no EU customers, users or outputs used in the EU is not bound today (Article 2). The UK scope guide works through that test.

What does Article 5 prohibit?

The original list, in force since 2 February 2025, covers manipulative or deceptive techniques that could cause significant harm, exploitation of vulnerabilities linked to age, disability or social or economic situation, social scoring of people, predictive policing based solely on profiling, untargeted scraping of facial images to build recognition databases, inferring emotion in a workplace or education setting, biometric categorisation used to infer sensitive attributes, and specified real-time remote biometric identification in public spaces for law enforcement (Article 5).

Several carry narrow, defined exceptions rather than being absolute, so read the exact wording against the use in front of you before deciding it is or is not caught.

What did the omnibus add?

Regulation (EU) 2026/1744 inserted two further prohibitions into Article 5(1). Point (ba) prohibits an AI system that generates or manipulates realistic images, video, audio or similar material of an identifiable person's intimate parts, or of an identifiable person engaged in sexually explicit activities, without that person's freely given, specific, informed, unambiguous and explicit consent. Point (bb) prohibits an AI system that generates or manipulates child sexual abuse material within the meaning of Directive 2011/93/EU, subject to a national-law defence where one applies.

These two entered into force on 27 July 2026 and apply from 2 December 2026, so there is a window where they are on the books but not yet enforceable. New paragraphs added at the same time set out how the duty falls on providers and deployers and a limited safe harbour where effective technical safeguards prevent the output. Treat the practices as out of bounds from now and be ready for the application date.

What does this mean for a UK organisation?

If you are within scope under Article 2, the prohibitions apply to you the same way they apply to an EU organisation. Being registered in the UK does not take a use out of Article 5 if your AI activity reaches the EU through customers, users or outputs used there.

A prohibited practice is not something you manage down with controls or disclose your way past. If a use is caught, it stops. The practical step is to keep a list of what your AI systems actually do and screen each use against Article 5 before it goes live.

How do you tell whether a use is caught?

Start from what the system does and who it affects, not from the tool's marketing. Match the use against the Article 5 list and its defined exceptions, and where a use sits near a line, treat it as needing a documented view before it is introduced.

Prohibition is a scope question that Article 5 decides, so it is separate from the AI literacy duty: training helps people notice a use that needs checking, but it never makes a banned use permitted. The EU AI Act check asks about these practices as part of working out where the Act leaves your organisation.

Common questions

What does Article 5 prohibit?
Article 5 bans a defined list of AI practices outright. The original eight, in force since 2 February 2025, include manipulative or deceptive techniques that cause significant harm, exploitation of listed vulnerabilities, social scoring, predictive policing based solely on profiling, untargeted scraping of facial images, emotion inference in work or education, biometric categorisation to infer sensitive attributes, and specified real-time remote biometric identification. Regulation (EU) 2026/1744 added two more, points (ba) and (bb), which apply from 2 December 2026.
Since when has the ban applied?
The original prohibitions have applied since 2 February 2025 (Article 5). The two added by the omnibus, points (ba) and (bb), entered into force on 27 July 2026 and apply from 2 December 2026, so there is a window where they are on the books but not yet enforceable.
Is a prohibited practice a training question?
No. Whether a use is prohibited is a scope question that Article 5 decides, and no amount of AI literacy makes a banned use permitted. Literacy helps your people notice that a proposed use needs checking against Article 5 before it goes live, which is a governance step, not a defence.