EU AI Act prohibited practices belong at the beginning of use-case intake. If the proposed practice falls within Article 5, the team needs to stop and obtain legal direction. Better logging or a human approval screen cannot convert a prohibition into an ordinary release risk.

The exact wording matters. Article 5 contains conditions, defined effects, and exceptions. Regulation (EU) 2026/1744 also amended the list. Use the consolidated law and current Commission guidelines rather than this operational summary as the legal test.

The prohibition attaches to a practice

A model name rarely reveals whether a use is prohibited. The assessment examines what the system is designed or used to do, how it affects people, which data or techniques it uses, and whether a legal exception applies.

An image model can produce ordinary marketing material or non-consensual intimate content. A camera system can count anonymous footfall or infer sensitive categories from biometric data. A language model can draft a neutral form or apply manipulative techniques aimed at materially distorting a person's decision in a harmful way.

Describe the practice in verbs before reviewing it.

Group Article 5 into practical screening themes

The current framework covers themes including harmful manipulation or deception, exploitation of vulnerabilities, social scoring, specified individual crime-risk assessment, untargeted facial-image scraping, specified emotion recognition in workplaces and education, specified biometric categorization, restricted real-time remote biometric identification by law enforcement, and the 2026 addition concerning non-consensual intimate or child sexual-abuse material.

This grouping is only an intake aid. Each provision has its own legal wording. Some contain purpose, harm, sector, or legal-authorization conditions. A team should never infer permission from a simplified category name.

Use seven questions at intake

  1. What behavior, decision, or output is the system intended to produce?
  2. Which people or groups are observed, categorized, influenced, scored, or affected?
  3. Does the system use biometric, emotional, behavioral, vulnerability, or inferred sensitive information?
  4. Could the practice materially distort a decision or exploit age, disability, or socioeconomic vulnerability?
  5. Does it create a social score or prediction that affects treatment outside an appropriate context?
  6. Does it generate or manipulate intimate, sexual, or child-related content?
  7. Which exact Article 5 paragraph, guidance, exception, and legal owner support the conclusion?

Record “uncertain” as an escalation result. The purpose of the screen is to prevent the team from designing around a legal question nobody has answered.

Turn the answer into technical and contractual limits

A prohibited-use clause should appear in the system record, provider terms, customer contract, user instructions, and monitoring where relevant. Technical controls should constrain the capabilities and data paths that could enable the prohibited use.

Skybridge systems are scoped by workspace, connections, agents, tools, and actions. Compsia defines a contracted production perimeter and withholds unrelated capabilities. These mechanisms enforce use restrictions at the contracted system perimeter, with release tests covering prohibited paths.

Add intake approval before connecting sources associated with employment, biometrics, education, law enforcement, public services, or sensitive profiling. Use denial tests where a proposed tool call or source should remain unavailable.

Apply the screen to an event-company request

Imagine an event company asking for a tool that watches crew members through venue cameras and infers who is stressed, disengaged, or likely to underperform. The intended workplace use immediately raises the Article 5 emotion-recognition prohibition and requires legal review.

A narrower operational need may be legitimate and useful. The company might need staff to report fatigue, supervisors to record safety incidents, or scheduling rules to respect breaks. Those methods address the work without inferring emotion from biometric data.

The redesign should be judged on its own facts. The lesson is to identify the business problem before assuming the requested AI method is necessary.

Keep the register current after the 2026 amendment

The AI Omnibus entered into force in July 2026 and added a prohibition with a later application date identified by the Commission. Future legislation, guidance, and enforcement can change interpretation.

Maintain a prohibited-practices register with the consolidated provision, affected systems, reviewer, decision, enforcement control, and review date. Reopen it when a system receives a new purpose, data type, sensing capability, or affected group.

Procurement should preserve disabled-feature evidence. Capture the configuration, access policy, contract restriction, and test result for any vendor capability the organization will not use. Monitor product updates because a supplier can add a sensing or inference feature after the original review.

Usage monitoring should look for requests that indicate purpose drift without storing unnecessary worker or attendee content. Repeated attempts to rank people through an approved logistics assistant should route to the system owner. The response may be better training, a clearer interface, a technical denial, or a formal review of the new need. The aim is to keep the prohibited-practice decision active after launch.

The EU AI Act risk-classification decision tree shows the next questions after the Article 5 screen.

Prohibited-practice questions

Are all emotion-recognition systems prohibited?

Article 5 targets specified emotion-inference uses in workplaces and education and contains limited exceptions. Other uses may face different AI Act, privacy, employment, and sector rules. Obtain a case-specific legal assessment.

Does human approval make a prohibited practice acceptable?

No general approval exception should be assumed. Human review can support oversight for permitted systems. It does not rewrite Article 5.

Should procurement screen vendor features we have disabled?

Record the purchased capability and the configured state. Verify that the feature remains disabled and that updates cannot enable it without review.

Primary references

  1. Regulation (EU) 2024/1689, the Artificial Intelligence ActEUR-Lex
  2. Regulation (EU) 2026/1744, the 2026 AI OmnibusEUR-Lex
  3. AI Act regulatory framework and implementation timelineEuropean Commission
  4. Guidelines on prohibited AI practicesAI Act Service Desk

Continue reading: EU AI Act Risk Classification: A Decision Tree.