Regulation (EU) 2024/1689
Article 5: Prohibited AI practices
Article 5 of the EU AI Act bans a short list of AI practices outright, including social scoring, untargeted scraping of facial images, emotion inference in the workplace, and most real time remote biometric identification in public. It has applied since 2 February 2025 and carries the highest penalty tier in the Act.
Maximum penalty
Up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher.
Article 99(3)
Binds from
2 February 2025
Two further prohibitions, on AI generated non consensual intimate imagery and on AI generated child sexual abuse material, apply from 2 December 2026 under the Digital Omnibus.
Enforced by
National market surveillance authorities designated under Article 70. The European Data Protection Supervisor enforces against Union institutions under Article 100.
Plain reading
What Article 5 actually requires
A prohibited practice is not a high risk practice with extra paperwork. There is no conformity assessment that makes it lawful, no registration that permits it and no risk management system that mitigates it. The practice is banned, and the only compliant response is not to do it. Article 5 covers manipulative techniques that materially distort behaviour, exploitation of vulnerability, social scoring by public or private actors, predicting criminal offending from personality traits alone, untargeted scraping of facial images from the internet or CCTV to build recognition databases, inferring emotions in workplaces and schools, biometric categorisation to deduce protected characteristics, and real time remote biometric identification in publicly accessible spaces for law enforcement outside narrow authorised exceptions. The Digital Omnibus added two further prohibitions from 2 December 2026, covering AI generated intimate imagery of real people without consent and AI generated child sexual abuse material.
The penalty tier is Article 99(3): up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher. That is the highest exposure in the Act, higher than the high risk tier and higher than the general purpose model tier, and it is enforced by national market surveillance authorities rather than by the Commission.
The prohibitions have been in force since 2 February 2025, which is eighteen months before the fining machinery that most of the Act runs on. Article 99 penalties became applicable on 2 August 2025. That gap is the reason a prohibited practice running today is exposed today.
The tracker's clearest AI Act record sits here. In May 2026 the Italian data protection authority warned a startup that a Slack plug in inferring employee stress from message content would breach Article 5(1)(f), the workplace emotion inference prohibition. It is the first published European decision to invoke an Article 5 prohibition. It is a warning, not a fine.
Three of the largest AI adjacent fines in Europe, all against Clearview AI, concern conduct that Article 5(1)(e) now prohibits by name: building a facial recognition database by untargeted scraping. Those fines were issued under the GDPR because the Act did not yet apply. The same conduct today would attract both.
The official text, consolidated with the Digital Omnibus applied, with everything that cites it and everything it cites: Article 5 in the EU AI Act Explorer.
Sub paragraphs
What is prohibited, point by point
- 5(1)(a)
- Subliminal, purposefully manipulative or deceptive techniques that materially distort behaviour and cause significant harm.
- 5(1)(b)
- Exploiting vulnerabilities of age, disability or social and economic situation.
- 5(1)(c)
- Social scoring leading to detrimental treatment disconnected from the context in which the data was gathered.
- 5(1)(d)
- Predicting the risk of a person committing a criminal offence based solely on profiling or personality traits.
- 5(1)(e)
- Building or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV.
- 5(1)(f)
- Inferring emotions of a natural person in the workplace or in education institutions, outside medical or safety purposes.
- 5(1)(g)
- Biometric categorisation to deduce race, political opinions, trade union membership, religious beliefs, sex life or sexual orientation.
- 5(1)(h)
- Real time remote biometric identification in publicly accessible spaces for law enforcement, outside the authorised exceptions.
Enforcement
Actions citing Article 5
1 tracked action expressly cites this article. The list below also includes actions where the conduct falls squarely inside it under another regime.
- ConfirmedAI Act directAIT-2026-0002
Garante warns Myndoor over workplace emotion inference, citing AI Act Article 5(1)(f)
14 May 2026 · Warning · GDPR and AI Act · No financial penalty
Formal warning, provvedimento no. 342 of 14 May 2026. No financial penalty.
- ConfirmedAI adjacentAIT-2024-0003
Dutch authority fines Clearview AI 30.5 million euro, the largest AI adjacent fine on record
16 May 2024 · Fine · GDPR · 30.5 million euro
Fine of 30.5 million euro, decision dated 16 May 2024, announced 3 September 2024.
- ConfirmedAI adjacentAIT-2024-0001
Garante fines the Municipality of Trento 50,000 euro over three AI street surveillance projects
11 December 2023 · Fine · GDPR · 50,000 euro
Fine of 50,000 euro against a municipality, announced 11 January 2024.
- ConfirmedAI adjacentAIT-2023-0002
CNIL charges Clearview AI a further 5.2 million euro for ignoring the erasure order
13 April 2023 · Corrective order · GDPR · 5.2 million euro
Additional 5.2 million euro, decision of 13 April 2023, announced 10 May 2023.
- ConfirmedAI adjacentAIT-2022-0002
CNIL fines Clearview AI 20 million euro and orders it to stop processing data on people in France
17 October 2022 · Fine · GDPR · 20 million euro
Fine of 20 million euro, decision of 17 October 2022.
- ConfirmedAI adjacentAIT-2022-0001
Garante fines Clearview AI 20 million euro over its facial recognition database
10 February 2022 · Fine · GDPR · 20 million euro
Fine of 20 million euro, decision of 10 February 2022, announced 9 March 2022.
Answers
Questions about Article 5
Has anyone been fined under Article 5 of the EU AI Act?
No fine has been issued under Article 5. The only published European decision to invoke an Article 5 prohibition is the Italian data protection authority's formal warning to Myndoor of 14 May 2026, which cited Article 5(1)(f) on workplace emotion inference and carried no financial penalty.
What is the fine for a prohibited AI practice?
Up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher, under Article 99(3). For small and medium enterprises Article 99(6) inverts the rule and the lower of the two figures applies, and the Digital Omnibus extended that proportionality to small mid caps for the second and third tiers.
Is emotion recognition banned in the EU?
Not everywhere. Article 5(1)(f) prohibits inferring emotions of a natural person in the workplace and in education institutions, with exceptions for medical or safety reasons. Emotion recognition elsewhere is not prohibited, but it is high risk under Annex III and carries a transparency duty under Article 50(3).
The rest of the Act
Other enforceable provisions
- Article 50: transparency obligations for certain ai systems
- Article 51: classification of general purpose ai models with systemic risk
- Article 53: obligations for providers of general purpose ai models
- Article 55: obligations for providers of general purpose ai models with systemic risk
- Article 93: measures the ai office can require of model providers
- Article 99: penalties imposed by member states
- Article 100: fines on union institutions, bodies, offices and agencies
- Article 101: fines on providers of general purpose ai models
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE EU AI Act Enforcement Tracker (as of 20 August 2026), eu ai act article 5: prohibited ai practices.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). EU AI Act Article 5: Prohibited AI practices. EU AI Act Enforcement Tracker. Retrieved 20 August 2026, from https://www.gage.academy/tools/eu-ai-act-enforcement-tracker/provisions/article-5
- MLA
- "EU AI Act Article 5: Prohibited AI practices." EU AI Act Enforcement Tracker, GAGE (Global Academy of Generative-AI Education), 20 August 2026, https://www.gage.academy/tools/eu-ai-act-enforcement-tracker/provisions/article-5.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "EU AI Act Article 5: Prohibited AI practices." EU AI Act Enforcement Tracker. Last modified 20 August 2026. https://www.gage.academy/tools/eu-ai-act-enforcement-tracker/provisions/article-5.
- Permalink
- https://www.gage.academy/tools/eu-ai-act-enforcement-tracker/provisions/article-5
Last updated . Every record re verified . The tracker is checked every Monday, and the same day for any action under the AI Act.