Do not deploy or provide AI for prohibited practices
Under EU AI Act, Article 5
What does it require?
Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significant harm, exploitation of vulnerabilities, social scoring by public or private actors leading to detrimental treatment, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and education institutions except for medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow exceptions.
Practical action
Add a prohibited-practice screen to your AI intake or design-review process and document the outcome for every system already in use.
Who does it apply to?
Applies to any provider or deployer of an AI system used in the EU, in any sector.
Applies from:
Evidence examples
- Prohibited-practice screening record — Dated checklist for each AI system against each Article 5 practice, with reviewer sign-off. (record)
- AI system inventory — Register of AI systems with owner, purpose and jurisdiction. (register)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 6.1.2 and Annex A control on AI system impact assessment | Original editorial mapping: the AI-impact-assessment process is a natural place to screen for prohibited uses. | medium |
| NIST AI RMF 1.0 | GOVERN 1.1, MAP 1.1 | Original editorial mapping to legal-requirement identification and context mapping. | medium |
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.