What Are Prohibited AI Practices Under the EU AI Act?

6 min readAbleneo AI transformation team

Short answer. Prohibited AI practices are the 8 uses the EU AI Act bans outright under Article 5, including social scoring, manipulation, exploitation of vulnerabilities, and untargeted facial-image scraping. The ban has applied across the EU since 2 February 2025. There is no high-risk pathway and no compliance fix: a prohibited system must stop. Breaches carry fines up to 35 million euros or 7% of worldwide annual turnover, whichever is higher.

1What This Means in Practice

Most of the EU AI Act sorts systems by risk and tells you what to do at each level. Article 5 is different. It draws a hard line. Eight categories of AI use are forbidden regardless of accuracy, consent, or business value. You cannot register, audit, or insure your way back across that line. The only legal response is to not build the system, or to switch it off.

The prohibitions matter most where an AI system acts on people rather than documents or machines. Three quick examples show the shape:

For a bank running 1 or 2 AI pilots, the practical task is simple to state and easy to get wrong: confirm that none of them sits inside Article 5 before any other compliance work begins. A high-risk control plan built on top of a prohibited system is wasted effort.

2Why This Matters for Regulated Industries

Financial services and insurance carry the highest concentration of people-facing AI: credit decisions, claims triage, fraud screening, customer profiling. Each one touches the categories Article 5 restricts, which puts FS&I closer to the prohibition line than almost any other sector. The Commission published its Guidelines on Prohibited AI Practices on 4 February 2025 to interpret the boundaries, and the penalty regime under the Act took effect on 2 August 2025. The window for “we will check later” closed in 2025.

The exposure is concrete in Central Europe. A Slovak or Czech bank deploying a third-party scoring engine inherits Article 5 risk from its vendor, because the prohibition applies to the deployer as well as the provider. National market-surveillance authorities, designated by each member state, can order immediate withdrawal. For a regulated entity, an enforced shutdown of a live decisioning system is an operational and reputational event, not just a fine.

Article 5 bans 8 AI practices outright, with the prohibition applying across the EU since 2 February 2025.

3What Are the Eight Prohibited Practices?

Article 5 bans: harmful manipulation using subliminal or deceptive techniques; exploitation of vulnerabilities tied to age, disability, or socio-economic situation; social scoring that leads to detrimental treatment in unrelated contexts; predicting an individual’s risk of committing a crime based solely on profiling or personality traits; untargeted scraping of facial images from the internet or CCTV to build recognition databases; emotion recognition in workplaces and schools; biometric categorization that infers sensitive attributes such as race or political opinion; and real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions.

Four of these eight touch FS&I directly. Social scoring, vulnerability exploitation, emotion recognition, and biometric categorization all appear in real banking and insurance workflows, from collections to onboarding to workforce analytics.

4Is Credit Scoring Banned by the EU AI Act?

No. Credit scoring is not prohibited. An AI system that assesses a borrower’s creditworthiness using relevant financial data is classified as high-risk under Annex III, not banned under Article 5. It must meet the high-risk obligations: risk management, data governance, transparency, human oversight, and logging. The line is crossed only when scoring drifts into social scoring, meaning it uses unrelated social-context data and produces detrimental treatment that is disproportionate to the behavior assessed.

The boundary is thinner than many teams assume. A model that mixes credit history with location patterns, shopping habits, and social-media signals to penalize people in unrelated contexts moves toward the prohibited side. Keeping inputs tied to genuine financial relevance is what keeps a scoring system in the high-risk lane rather than the banned one.

5What Are the Penalties for a Prohibited AI System?

Article 5 breaches sit in the top penalty tier of the Act. The maximum is 35 million euros or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. That ceiling is above the 15 million euro or 3% tier that applies to most high-risk obligations, which signals how seriously the legislator treats the red lines. Beyond the fine, there is no remediation path: the system cannot be brought into compliance and must cease operation.

6How Is a Prohibited Practice Different From a High-Risk System?

A high-risk system is allowed if you meet a defined set of controls. A prohibited practice is not allowed at all. High-risk AI, such as a credit or insurance-pricing model, requires conformity assessment, technical documentation, human oversight, and registration before and during use. A prohibited practice has no such menu. The two tiers also differ in penalty exposure, 7% of turnover for prohibitions against 3% for most high-risk breaches, and in timing, since the prohibitions applied from February 2025 while many high-risk obligations phase in through 2026 and 2027.

7What Should a Bank Do First?

Inventory every AI system that touches a person, then test each one against the eight Article 5 categories before any high-risk work starts. Prioritize collections, fraud, onboarding, marketing, and HR analytics, because these are where social scoring, emotion recognition, and biometric categorization tend to appear. For each vendor system, get written confirmation of the data sources and the inference targets, since deployer liability means a supplier’s design choice becomes the bank’s legal exposure. Clear Article 5 first. Then move stalled pilots into the high-risk control track.

8The Ableneo Perspective

Ableneo works inside this exact boundary for Central European financial institutions, where the difference between a banned system and a governed one decides whether a project ships. Across a 2025 portfolio of 34 production AI projects, 94% of them using large language models, the pattern holds: the systems that reach production are the ones built with governance designed in from the first sprint, not retrofitted after a pilot. Our AI transformation FAQ sets out how we map regulatory lines onto live workflows so banks and insurers can act on AI without crossing the red lines. Clarity first, then production.

Key takeaways

Sources

Planning AI in a regulated business? Ableneo takes systems from classification to governed production.

Talk to Ableneo