Skip to main content

Regulation (EU) 2024/1689

Article 5: Prohibited AI practices

Article 5 of the EU AI Act bans a short list of AI practices outright, including social scoring, untargeted scraping of facial images, emotion inference in the workplace, and most real time remote biometric identification in public. It has applied since 2 February 2025 and carries the highest penalty tier in the Act.

Maximum penalty

Up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher.

Article 99(3)

Binds from

2 February 2025

Two further prohibitions, on AI generated non consensual intimate imagery and on AI generated child sexual abuse material, apply from 2 December 2026 under the Digital Omnibus.

Enforced by

National market surveillance authorities designated under Article 70. The European Data Protection Supervisor enforces against Union institutions under Article 100.

Plain reading

What Article 5 actually requires

A prohibited practice is not a high risk practice with extra paperwork. There is no conformity assessment that makes it lawful, no registration that permits it and no risk management system that mitigates it. The practice is banned, and the only compliant response is not to do it. Article 5 covers manipulative techniques that materially distort behaviour, exploitation of vulnerability, social scoring by public or private actors, predicting criminal offending from personality traits alone, untargeted scraping of facial images from the internet or CCTV to build recognition databases, inferring emotions in workplaces and schools, biometric categorisation to deduce protected characteristics, and real time remote biometric identification in publicly accessible spaces for law enforcement outside narrow authorised exceptions. The Digital Omnibus added two further prohibitions from 2 December 2026, covering AI generated intimate imagery of real people without consent and AI generated child sexual abuse material.

The penalty tier is Article 99(3): up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher. That is the highest exposure in the Act, higher than the high risk tier and higher than the general purpose model tier, and it is enforced by national market surveillance authorities rather than by the Commission.

The prohibitions have been in force since 2 February 2025, which is eighteen months before the fining machinery that most of the Act runs on. Article 99 penalties became applicable on 2 August 2025. That gap is the reason a prohibited practice running today is exposed today.

The tracker's clearest AI Act record sits here. In May 2026 the Italian data protection authority warned a startup that a Slack plug in inferring employee stress from message content would breach Article 5(1)(f), the workplace emotion inference prohibition. It is the first published European decision to invoke an Article 5 prohibition. It is a warning, not a fine.

Three of the largest AI adjacent fines in Europe, all against Clearview AI, concern conduct that Article 5(1)(e) now prohibits by name: building a facial recognition database by untargeted scraping. Those fines were issued under the GDPR because the Act did not yet apply. The same conduct today would attract both.

The official text, consolidated with the Digital Omnibus applied, with everything that cites it and everything it cites: Article 5 in the EU AI Act Explorer.

Sub paragraphs

What is prohibited, point by point

5(1)(a)
Subliminal, purposefully manipulative or deceptive techniques that materially distort behaviour and cause significant harm.
5(1)(b)
Exploiting vulnerabilities of age, disability or social and economic situation.
5(1)(c)
Social scoring leading to detrimental treatment disconnected from the context in which the data was gathered.
5(1)(d)
Predicting the risk of a person committing a criminal offence based solely on profiling or personality traits.
5(1)(e)
Building or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV.
5(1)(f)
Inferring emotions of a natural person in the workplace or in education institutions, outside medical or safety purposes.
5(1)(g)
Biometric categorisation to deduce race, political opinions, trade union membership, religious beliefs, sex life or sexual orientation.
5(1)(h)
Real time remote biometric identification in publicly accessible spaces for law enforcement, outside the authorised exceptions.

Enforcement

Actions citing Article 5

1 tracked action expressly cites this article. The list below also includes actions where the conduct falls squarely inside it under another regime.

Answers

Questions about Article 5

Has anyone been fined under Article 5 of the EU AI Act?

No fine has been issued under Article 5. The only published European decision to invoke an Article 5 prohibition is the Italian data protection authority's formal warning to Myndoor of 14 May 2026, which cited Article 5(1)(f) on workplace emotion inference and carried no financial penalty.

What is the fine for a prohibited AI practice?

Up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher, under Article 99(3). For small and medium enterprises Article 99(6) inverts the rule and the lower of the two figures applies, and the Digital Omnibus extended that proportionality to small mid caps for the second and third tiers.

Is emotion recognition banned in the EU?

Not everywhere. Article 5(1)(f) prohibits inferring emotions of a natural person in the workplace and in education institutions, with exceptions for medical or safety reasons. Emotion recognition elsewhere is not prohibited, but it is high risk under Annex III and carries a transparency duty under Article 50(3).

The rest of the Act

Other enforceable provisions

Cite this page

Free to reuse under CC BY 4.0, with attribution.

In a sentence
According to the GAGE EU AI Act Enforcement Tracker (as of 20 August 2026), eu ai act article 5: prohibited ai practices.
APA
GAGE (Global Academy of Generative-AI Education). (2026). EU AI Act Article 5: Prohibited AI practices. EU AI Act Enforcement Tracker. Retrieved 20 August 2026, from https://www.gage.academy/tools/eu-ai-act-enforcement-tracker/provisions/article-5
MLA
"EU AI Act Article 5: Prohibited AI practices." EU AI Act Enforcement Tracker, GAGE (Global Academy of Generative-AI Education), 20 August 2026, https://www.gage.academy/tools/eu-ai-act-enforcement-tracker/provisions/article-5.
Chicago
GAGE (Global Academy of Generative-AI Education). "EU AI Act Article 5: Prohibited AI practices." EU AI Act Enforcement Tracker. Last modified 20 August 2026. https://www.gage.academy/tools/eu-ai-act-enforcement-tracker/provisions/article-5.
Permalink
https://www.gage.academy/tools/eu-ai-act-enforcement-tracker/provisions/article-5

Last updated . Every record re verified . The tracker is checked every Monday, and the same day for any action under the AI Act.