Skip to main content

Prohibited AI Practices Screening — Article 5

How to screen AI systems for prohibited practices under EU AI Act Article 5. All 8 prohibited categories, enforcement timeline, and automated detection.

EU AI Act Article 5 prohibits 8 categories of AI practices that are considered unacceptable risks to fundamental rights. These prohibitions have been in force since February 2, 2025 — the earliest enforcement date in the Act. Any AI system that falls into a prohibited category cannot be placed on the EU market or put into service, regardless of risk mitigation measures. Violations carry fines of up to €35 million or 7% of global turnover — the highest tier in the Act.

All 8 Prohibited AI Practices Under Article 5

Subliminal manipulation below conscious awareness

Art 5(1)(a)

AI systems that deploy subliminal techniques beyond a person's consciousness to materially distort behaviour in ways that cause or are likely to cause harm to the person or another person.

Examples: Subliminal audio/visual stimuli in interfaces; algorithmic nudging below conscious threshold

Exploitation of vulnerabilities

Art 5(1)(b)

AI systems that exploit specific vulnerabilities of persons due to age, disability, or social/economic situation to materially distort their behaviour in a harmful way.

Examples: Predatory targeting of elderly users; manipulative design for people with cognitive disabilities

Social scoring by public authorities

Art 5(1)(c)

AI systems used by or on behalf of public authorities to evaluate or classify individuals based on social behaviour or personal characteristics over time, leading to detrimental or discriminatory treatment in unrelated contexts.

Examples: Government citizen scoring systems; cross-context social credit systems

Real-time remote biometric identification in public spaces

Art 5(1)(d)

Real-time remote biometric identification systems (e.g. facial recognition) used in publicly accessible spaces for law enforcement, except for specific narrowly-defined exceptions (terrorism, missing children, wanted criminals).

Examples: Live facial recognition CCTV; real-time biometric surveillance in public areas

Post-remote biometric identification (with exceptions)

Art 5(1)(e)

Post-remote biometric identification systems used by law enforcement, except where authorised by judicial or independent authority for prosecution of serious offences. Covers retrospective facial recognition in recorded footage.

Examples: Retrospective facial recognition in CCTV archives without judicial authorisation

Biometric categorisation inferring sensitive attributes

Art 5(1)(f)

AI systems that categorise individuals based on biometric data to infer or deduce race, political opinions, trade union membership, religious or philosophical beliefs, sexual orientation, or health status.

Examples: Automated inferral of religion from facial features; biometric profiling for sexual orientation

Emotion recognition in workplaces and education

Art 5(1)(g)

AI systems used to infer the emotions of individuals in workplace and educational institution contexts, except for medical or safety reasons. Covers real-time emotion monitoring of employees and students.

Examples: Employee sentiment/engagement monitoring AI; student emotion analysis in classrooms

Predictive policing based on profiling

Art 5(1)(h)

AI systems used by or on behalf of law enforcement to assess the risk of an individual committing a criminal offence based solely on profiling or personality traits, without objective and verifiable facts directly linked to criminal activity.

Examples: Recidivism prediction from demographic profiling; pre-crime predictive AI without evidential basis

Enforcement Timeline

Aug 1, 2024

EU AI Act entered into force

Regulation (EU) 2024/1689 published in the Official Journal and took effect.

Feb 2, 2025

Article 5 prohibitions enforceable

All 8 prohibited AI practices are banned across the EU. No transitional period applies.

Aug 2, 2026

High-risk AI Act obligations

Articles 9–49 enforcement for high-risk AI systems. GPAI obligations already in force from Aug 2025.

How Scanara Detects Prohibited Practices

Scanara includes a dedicated prohibited practices screening module that scans your AI codebase and system documentation against all 8 Article 5 categories. Unlike manual checklists, Scanara detects code-level indicators of prohibited behaviour — e.g. subliminal stimulus APIs, real-time biometric classification pipelines, emotion-detection integrations in employee-facing applications.

Pattern-based code scanning

Compliance rules tuned to Article 5 — detecting subliminal stimulus libraries, biometric inference pipelines, emotion recognition SDKs, and profiling patterns linked to protected characteristics.

Architecture review flags

Beyond individual code patterns, Scanara flags system architecture characteristics that indicate prohibited use cases — real-time biometric pipelines in public-space contexts, cross-context social scoring data flows.

Zero-tolerance finding severity

Article 5 findings are always classified as Critical severity — they cannot be suppressed or accepted as risk. A finding blocks CI/CD merge gates until the prohibited feature is removed.

Timestamped audit evidence

Each scan records a timestamped result with the policy version and inputs used — attachable to your Annex IV technical documentation as evidence of due diligence on Article 5.

See prohibited practices screening in action →

Frequently Asked Questions


How Scanara Helps

Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.