Since when do the prohibitions apply – and why this still matters
Art. 5 AI Act (EU) 2024/1689 has already been in force since 02.02.2025 – together with Art. 4 (AI literacy). The “Digital Omnibus on AI”, adopted by Parliament and Council in June 2026, pushes back several other deadlines in the Regulation (Art. 50, high-risk obligations under Annex III and Annex I), but leaves Art. 5 untouched. The list of prohibitions applies without restriction and without any transition period – regardless of whether your system is classified as high-risk AI or not. That makes Art. 5 the sharpest provision in the entire Regulation, and the one that has been in force for the longest.
What Art. 5 specifically prohibits
Art. 5(1) lists eight practices that are banned irrespective of the system’s risk level:
- Subliminal or manipulative influence (Art. 5(1)(a)) that materially distorts decision-making and causes or is likely to cause significant harm.
- Exploitation of vulnerabilities due to age, disability or social or economic situation (point (b)).
- Social scoring: evaluating or classifying people based on social behaviour or inferred personality traits where this leads to unjustified detrimental treatment (point (c)).
- Predicting criminal offences based solely on profiling (point (d)) – except to support human assessments based on objective, verifiable facts.
- Untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases (point (e)).
- Emotion recognition in the workplace and in educational institutions (point (f)), except for medical or safety reasons.
- Biometric categorisation to infer race, political opinions, trade union membership, religion, sex life or sexual orientation (point (g)).
- Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes (point (h)) – subject to narrow exceptions (see below).
For day-to-day business, points (a), (b) and (f) are the most relevant: marketing, recruitment and HR tools that rely on behavioural influence, exploitation of vulnerabilities, or emotion analysis can quickly fall into prohibited territory – even where that was never the intention.
The exception: real-time remote biometric identification
Art. 5(1)(h) prohibits real-time remote biometric identification in public spaces for law enforcement purposes as a rule, but allows three narrowly defined objectives: searching for victims of human trafficking or sexual exploitation, and missing persons; preventing a specific and imminent threat to life or physical safety, or a terrorist attack; and prosecuting offences listed in Annex II that carry a maximum custodial sentence of at least four years. Art. 5(2) additionally requires that use be “strictly necessary” and limited to confirming the identity of a specifically targeted individual. For biometric processing outside law enforcement, Art. 5(1)(h) expressly refers to Art. 9 GDPR – the GDPR rules on special categories of personal data therefore continue to apply in parallel.
Typical gaps in practice
In advisory practice, the same blind spots keep recurring: emotion recognition gets built into call-centre or recruitment software without anyone checking whether a medical or safety exemption under point (f) genuinely applies. Scoring models in lending or HR process “soft” behavioural data without anyone documenting the boundary with Art. 5(1)(c). And A/B testing or personalisation algorithms in marketing are rarely assessed against the “manipulative technique with potential for harm” test under point (a) – yet that is precisely the standard Art. 5 applies. Because these prohibitions are absolute and carry no notification or conformity assessment safety net, after-the-fact documentation is no remedy here – the practice simply has to be stopped from the outset.
Conclusion
Art. 5 is not a future concern – it has been binding law for over a year. Anyone deploying AI systems with behavioural, emotional or biometric components should check them against the list of prohibitions regardless of high-risk classification. For an initial indication of where your system stands and which AI Act obligations apply to you, try our free risk check at /einstufung.