# EU AI Act Article 5: Prohibited AI practices

Source: https://aiexponent.com/eu-ai-act/article-5 · Content verified 2026-10-04

Article 5 of the EU AI Act prohibits eight categories of AI practice: subliminal manipulation (5(1)(a)), exploitation of vulnerabilities (5(1)(b)), social scoring (5(1)(c)), individual criminal-risk profiling (5(1)(d)), untargeted facial-image scraping (5(1)(e)), emotion inference in workplace and education (5(1)(f)), biometric categorisation inferring sensitive attributes (5(1)(g)), and real-time remote biometric identification in publicly accessible spaces for law enforcement, with narrow exceptions (5(1)(h)). The prohibitions are absolute. Applicable from 2 February 2025 (Art. 113(a)); sanctionable under Chapter XII (Articles 99–100) since 2 August 2025 (Art. 113(b)).

- Status: In force
- Who: Anyone placing on the market or using AI in the EU. Eight uses are banned outright, and no consent or mitigation rescues them.
- From when: 2 Feb 2025 (Art. 113(a))
- Maximum fine: €35M or 7% (Art. 99(3))

## What Article 5 says

> **5(1)** 1. The following AI practices shall be prohibited:

> **5(1)(a)** (a) the placing on the market, the putting into service or the use of an AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to take a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm;

> **5(1)(b)** (b) the placing on the market, the putting into service or the use of an AI system that exploits any of the vulnerabilities of a natural person or a specific group of persons due to their age, disability or a specific social or economic situation, with the objective, or the effect, of materially distorting the behaviour of that person or a person belonging to that group in a manner that causes or is reasonably likely to cause that person or another person significant harm;

> **5(1)(e)** (e) the placing on the market, the putting into service for this specific purpose, or the use of AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage;

> **5(1)(f)** (f) the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons;

Selected paragraphs, quoted exactly from Regulation (EU) 2024/1689: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (checked 4 Oct 2026).

## What changed

Regulation (EU) 2026/1744, in force since 27 Jul 2026. Removed and context lines quote Regulation (EU) 2024/1689 as adopted; added lines quote the amending Regulation.

### Article 5(1), first subparagraph, points (ba) and (bb)

```diff
+ (ba) the placing on the market, the putting into service or the use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person’s intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation;
+ (bb) the placing on the market, the putting into service or the use of an AI system that generates or manipulates material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a “without right” defence applies under national law;
```

The same point also inserts paragraphs 1a and 1b into Article 5. These apply from 2 Dec 2026.

Source: Regulation (EU) 2026/1744, Article 1, point (7), https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 4 Oct 2026).

### Article 113, third paragraph, point (a)

```diff
- (a) Chapters I and II shall apply from 2 February 2025;
+ (a) Chapters I and II shall apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b) which shall apply from 2 December 2026;
```

Source: Regulation (EU) 2026/1744, Article 1, point (40), https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified 4 Oct 2026).

## What you must produce

Nothing. Article 5 bans practices outright; it does not ask for a document.

A summary to help you plan. The quoted text above is the law.

## The tool: LitmusAI

Coverage: Covered.

LitmusAI screens an AI system description against all eight Article 5 prohibitions and returns Red / Amber / Clear verdicts with primary-source citations. The reference ruleset shipped with v1.0 is UNREVIEWED (no external EU AI Act lawyer review yet); a Bring-Your-Own signed-ruleset path is available for teams that need lawyer-reviewed output today.

```bash
pip install litmus-screener
```

Writes: Prohibited-practices verdict (SARIF).

Tool docs and tool FAQ: https://aiexponent.com/docs/litmusai.md

For coding agents:

Install litmus-screener from PyPI into a virtual environment (Python 3.11 or newer); the command is `litmus`. Run `litmus init` to create system.yaml, fill in the fields that describe the AI system, then run `litmus screen system.yaml --output report.json`. Exit code 1 means a RED finding. Export SARIF with `litmus export report.json -o report.sarif --format sarif` and check integrity with `litmus verify report.json system.yaml`. The default ruleset is unreviewed and the result is not legal advice. Docs: https://aiexponent.com/docs/litmusai.md

## Questions about Article 5

### When does Article 5 apply?

It has applied since 2 Feb 2025 (Art. 113(a)). Points (ba) and (bb), added by Regulation (EU) 2026/1744, apply from 2 Dec 2026 (Art. 113(a), as amended).

### What is the maximum fine for breaching Article 5?

Up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher (Art. 99(3)). For SMEs, including start-ups, the fine is capped at whichever of the two is lower (Art. 99(6)).

### Did the Digital Omnibus change Article 5?

Yes. Regulation (EU) 2026/1744, in force since 27 Jul 2026, makes these changes. Two new prohibitions: points (ba) and (bb). Points (ba) and (bb) apply from 2 Dec 2026. The section "What changed" quotes the old and new text.

### Is there an AiExponent tool for Article 5?

Yes. LitmusAI is released and open source. It writes a Prohibited-practices verdict (SARIF).

---

Not legal advice. Not a notified body. The tools produce evidence, not conformity assessment.
All docs as Markdown: https://aiexponent.com/llms.txt · Guide for coding agents: https://aiexponent.com/agents.md
