Since February 2, 2025, six AI practices are prohibited in the EU. Companies that do not comply with these prohibitions face fines of up to 35 million euros or 7% of their global annual turnover, according to Article 5 of the AI Act.
The European AI Act aims to protect fundamental rights against certain uses of artificial intelligence deemed too risky. It identifies practices presenting an "unacceptable risk" and explicitly prohibits them for all actors, whether they develop or deploy AI systems. The sanctions provided for in Article 99(2) are designed to deter any infringement.
The six prohibitions cover areas such as behavioral manipulation, biometric surveillance, social scoring, or emotional analysis, each addressing major issues of individual and collective protection.
1. Subliminal or Deceptive Manipulation
Article 5(1)(a) prohibits any technique aimed at influencing a person without their knowledge, through subliminal or deceptive means.
What the law says
Any AI system designed to alter a person's behavior without their awareness, via subliminal stimuli or misleading information, with the intent to cause physical or psychological harm, is prohibited.
Illustration
A fitness app that broadcasts subliminal messages encouraging the purchase of dietary supplements without the user's awareness.
Tools concerned
Certain advertising platforms exploiting *dark patterns* algorithms to increase engagement, particularly on social media or in mobile games.
2. Exploitation of Vulnerabilities
Article 5(1)(b) prohibits AI systems that take advantage of the weaknesses of vulnerable individuals.
What the law says
Systems targeting groups such as children, people with disabilities, or those in precarious situations to influence their behavior and cause harm are prohibited.
Illustration
A mobile game designed to push children to make in-app purchases by exploiting their cognitive immaturity and social pressure.
Tools concerned
Quick-loan applications that target fragile populations with high interest rates and algorithms that encourage debt.
3. Social Scoring
Article 5(1)(c) bans social scoring systems implemented by public authorities.
What the law says
It is prohibited to use AI to evaluate or classify citizens based on their social, economic, or personal behavior, whether by public or private actors with similar effects.
Illustration
A system that assigns a score to citizens based on their participation in community life, credit history, or online behavior, and conditions access to certain rights or benefits.
Tools concerned
Tenant or employee rating platforms, similar to certain systems deployed in China, which restrict access to housing or employment based on opaque criteria.
4. Real-Time Remote Biometric Identification
Article 5(1)(d) strictly regulates facial recognition in public spaces.
What the law says
Real-time remote biometric identification in public spaces is prohibited, except for very limited exceptions: counter-terrorism, searching for missing persons, or preventing a serious and specific threat.
Illustration
A facial recognition system installed in a shopping mall to identify customers and send them targeted advertisements in real-time, without explicit consent, is prohibited.
Tools concerned
Solutions like Clearview AI, whose massive collection of faces without consent has already been sanctioned in Europe.
#### Legal Basis
Article 5(1)(d) AI Act
#### Exceptions
See CNIL: Exceptions to the prohibition
5. Emotion Inference
Article 5(1)(f) prohibits the analysis of emotions in certain sensitive contexts.
What the law says
AI systems that seek to infer a person's emotions in professional or educational contexts are prohibited, except for strictly regulated medical or safety exceptions.
Illustration
Facial analysis software used during a job interview to evaluate a candidate's sincerity or motivation based on their expressions.
Tools concerned
Solutions such as *HireVue* or *Affectiva*, which analyze emotions to influence HR decisions.
6. Biometric Categorization
Article 5(1)(g) prohibits systems that classify individuals based on sensitive biometric data.
What the law says
AI systems that categorize people based on their ethnic origin, sexual orientation, or religious beliefs derived from biometric data are prohibited, except in very restricted cases.
Illustration
A recruitment algorithm that sorts candidates based on their origin or gender, detected through voice or facial analysis.
Tools concerned
*Gait analysis* software used to infer personal characteristics without a solid scientific basis.
How to ensure your company complies with these prohibitions?
Compliance requires a structured and regular approach.
1. Inventory all AI tools
Establish an inventory of all AI systems used, including those integrated into third-party solutions. Verify their compliance with Article 5 of the AI Act.
2. Examine each use case
For each tool, analyze the context of use. For example, facial analysis may be permitted in healthcare but prohibited during recruitment.
3. Justify exceptions
If a use falls under an exception (e.g., remote biometrics for security), document the legal grounds and obtain the required authorizations.
4. Train teams
Inform your employees, especially in HR, marketing, and security, about the regulation's prohibitions. Dedicated training limits non-compliance risks.
5. Conduct regular audits
Compliance must be monitored over time. Schedule periodic audits to adapt to regulatory changes.
For further reading: AI Act Glossary