EU AI Act Prohibited AI Practices
Coverage from Future of Privacy Forum, The Record, and others
Articles
14
Active Days
150
The Topic

The material examines how the EU AI Act draws legal red lines around several AI uses considered especially harmful to fundamental rights, including social scoring, untargeted facial-image scraping, individual criminal-risk prediction based solely on profiling, workplace and education emotion recognition, and biometric inference of sensitive traits. The analyses emphasize that most prohibitions are conditional and depend on the system’s purpose, data, context, and resulting treatment, while some narrowly defined uses remain permitted or move into the high-risk regime. Practical application remains dependent on Commission guidance, national enforcement, and further interpretation of overlaps with the GDPR and sector-specific rules.
First Article: 02/11/26
Latest Article: 07/10/26
Summary
- Article 5 prohibitions target specific uses rather than AI scoring, biometrics, or predictive systems generally.
- Social scoring is prohibited when prolonged behavioral or personal-attribute evaluation causes unfavorable treatment in unrelated contexts or treatment that is unjustified or disproportionate.
- Untargeted scraping of facial images from the internet or CCTV to create or expand facial-recognition databases is subject to a blanket prohibition, with targeted collection treated differently.
- Individual criminal-risk assessments based solely on profiling or personality traits are prohibited; systems supporting meaningful human judgment based on objective facts generally shift into the high-risk category.
- Emotion-recognition systems are restricted in workplaces and educational institutions, with narrow medical and safety exceptions and unresolved questions around intentions, voice, and behavioral signals.
- Biometric categorization that infers listed sensitive traits is prohibited, while some dataset labeling, filtering, aggregated analysis, and non-sensitive categorization remain outside the ban.
- The practical boundary between prohibited, permitted, and high-risk systems depends on cumulative legal conditions and interaction with the GDPR, the Law Enforcement Directive, and sector-specific rules.
History
The story shifts from a broad account of EU AI Act enforcement timing and related privacy restrictions to a more precise legal map of Article 5 prohibitions. The current version emphasizes how specific prohibited uses are defined by cumulative conditions, with clearer distinctions between banned, permitted, and high-risk systems.
The story has shifted from general EU AI Act privacy limits to a more operational enforcement phase, with staged deadlines, penalties, and labeling duties now front and center. It also newly foregrounds synthetic media and nudification bans as a separate, concrete enforcement thread.
