Short answer. Prohibited AI practices are the 8 uses the EU AI Act bans outright under Article 5, including social scoring, manipulation, exploitation of vulnerabilities, and untargeted facial-image scraping. The ban has applied across the EU since 2 February 2025. There is no high-risk pathway and no compliance fix: a prohibited system must stop. Breaches carry fines up to 35 million euros or 7% of worldwide annual turnover, whichever is higher.
Most of the EU AI Act sorts systems by risk and tells you what to do at each level. Article 5 is different. It draws a hard line. Eight categories of AI use are forbidden regardless of accuracy, consent, or business value. You cannot register, audit, or insure your way back across that line. The only legal response is to not build the system, or to switch it off.
The prohibitions matter most where an AI system acts on people rather than documents or machines. Three quick examples show the shape:
For a bank running 1 or 2 AI pilots, the practical task is simple to state and easy to get wrong: confirm that none of them sits inside Article 5 before any other compliance work begins. A high-risk control plan built on top of a prohibited system is wasted effort.
Financial services and insurance carry the highest concentration of people-facing AI: credit decisions, claims triage, fraud screening, customer profiling. Each one touches the categories Article 5 restricts, which puts FS&I closer to the prohibition line than almost any other sector. The Commission published its Guidelines on Prohibited AI Practices on 4 February 2025 to interpret the boundaries, and the penalty regime under the Act took effect on 2 August 2025. The window for “we will check later” closed in 2025.
The exposure is concrete in Central Europe. A Slovak or Czech bank deploying a third-party scoring engine inherits Article 5 risk from its vendor, because the prohibition applies to the deployer as well as the provider. National market-surveillance authorities, designated by each member state, can order immediate withdrawal. For a regulated entity, an enforced shutdown of a live decisioning system is an operational and reputational event, not just a fine.
Article 5 bans 8 AI practices outright, with the prohibition applying across the EU since 2 February 2025.
Article 5 bans: harmful manipulation using subliminal or deceptive techniques; exploitation of vulnerabilities tied to age, disability, or socio-economic situation; social scoring that leads to detrimental treatment in unrelated contexts; predicting an individual’s risk of committing a crime based solely on profiling or personality traits; untargeted scraping of facial images from the internet or CCTV to build recognition databases; emotion recognition in workplaces and schools; biometric categorization that infers sensitive attributes such as race or political opinion; and real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions.
Four of these eight touch FS&I directly. Social scoring, vulnerability exploitation, emotion recognition, and biometric categorization all appear in real banking and insurance workflows, from collections to onboarding to workforce analytics.
No. Credit scoring is not prohibited. An AI system that assesses a borrower’s creditworthiness using relevant financial data is classified as high-risk under Annex III, not banned under Article 5. It must meet the high-risk obligations: risk management, data governance, transparency, human oversight, and logging. The line is crossed only when scoring drifts into social scoring, meaning it uses unrelated social-context data and produces detrimental treatment that is disproportionate to the behavior assessed.
The boundary is thinner than many teams assume. A model that mixes credit history with location patterns, shopping habits, and social-media signals to penalize people in unrelated contexts moves toward the prohibited side. Keeping inputs tied to genuine financial relevance is what keeps a scoring system in the high-risk lane rather than the banned one.
Article 5 breaches sit in the top penalty tier of the Act. The maximum is 35 million euros or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. That ceiling is above the 15 million euro or 3% tier that applies to most high-risk obligations, which signals how seriously the legislator treats the red lines. Beyond the fine, there is no remediation path: the system cannot be brought into compliance and must cease operation.
A high-risk system is allowed if you meet a defined set of controls. A prohibited practice is not allowed at all. High-risk AI, such as a credit or insurance-pricing model, requires conformity assessment, technical documentation, human oversight, and registration before and during use. A prohibited practice has no such menu. The two tiers also differ in penalty exposure, 7% of turnover for prohibitions against 3% for most high-risk breaches, and in timing, since the prohibitions applied from February 2025 while many high-risk obligations phase in through 2026 and 2027.
Inventory every AI system that touches a person, then test each one against the eight Article 5 categories before any high-risk work starts. Prioritize collections, fraud, onboarding, marketing, and HR analytics, because these are where social scoring, emotion recognition, and biometric categorization tend to appear. For each vendor system, get written confirmation of the data sources and the inference targets, since deployer liability means a supplier’s design choice becomes the bank’s legal exposure. Clear Article 5 first. Then move stalled pilots into the high-risk control track.
Ableneo works inside this exact boundary for Central European financial institutions, where the difference between a banned system and a governed one decides whether a project ships. Across a 2025 portfolio of 34 production AI projects, 94% of them using large language models, the pattern holds: the systems that reach production are the ones built with governance designed in from the first sprint, not retrofitted after a pilot. Our AI transformation FAQ sets out how we map regulatory lines onto live workflows so banks and insurers can act on AI without crossing the red lines. Clarity first, then production.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.