Key Takeaways: EU AI Act Prohibited AI Practices
The EU AI Act's Article 5 bans eight categories of AI practices outright, with enforcement active since February 2, 2025. Penalties reach up to €35 million or 7% of global annual turnover, the highest tier in the regulation. Compliance teams must inventory all AI systems (including third-party vendor tools), map each against the prohibited practices list, and document assessments before supervisory authorities request evidence. Swiss-hosted platforms like Priverion help multi-entity organisations centralise this process across subsidiaries.
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024. The regulation adopts a risk-based approach, classifying AI systems into four tiers: prohibited, high-risk, limited-risk, and minimal-risk. Source: EUR-Lex, Regulation (EU) 2024/1689
What does Article 5 of the EU AI Act prohibit?
Article 5 of the EU AI Act establishes an absolute ban on eight categories of AI practices deemed to pose unacceptable risks to fundamental rights. These include: (a) subliminal, manipulative, or deceptive techniques causing significant harm; (b) exploitation of vulnerabilities due to age, disability, or social/economic situation; (c) social scoring by public authorities; (d) predictive policing based solely on profiling; (e) untargeted scraping of facial images for facial recognition databases; (f) emotion recognition in workplaces and educational institutions; (g) biometric categorisation systems inferring sensitive attributes such as race, political opinions, or sexual orientation; and (h) real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions. Source: EU AI Act, Article 5(1)(a) to (h)
When did the prohibited practices provisions take effect?
The prohibited practices under Article 5 became enforceable on 2 February 2025, six months after the regulation's entry into force, as specified in Article 113 of the EU AI Act. This was the first enforcement milestone. High-risk AI system obligations follow on 2 August 2026. Source: EU AI Act, Article 113
What are the penalties for prohibited AI practices?
Under Article 99(3) of the EU AI Act, violations of the prohibited practices provisions carry fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher. For comparison, the GDPR's maximum fine is €20 million or 4% of global turnover. According to the IAPP, the AI Act's penalty structure is the most severe of any EU digital regulation to date.
Does the EU AI Act apply outside the European Union?
Yes. Article 2 of the EU AI Act has extraterritorial scope. It applies to providers who place AI systems on the EU market regardless of where they are established, and to deployers located within the EU. It also covers providers and deployers in third countries where the output produced by their AI system is used within the EU. This mirrors the GDPR's extraterritorial reach under Article 3. Source: EU AI Act, Article 2
How does the EU AI Act interact with the GDPR?
The EU AI Act and the GDPR apply simultaneously. Recital 10 of the AI Act explicitly states that the regulation is "without prejudice" to the GDPR. AI systems that process personal data must comply with both frameworks. The European Data Protection Board (EDPB) has noted that data protection impact assessments under GDPR Article 35 and the AI Act's conformity assessments for high-risk systems may overlap, and organisations should coordinate both processes.
What is the difference between prohibited and high-risk AI systems?
Prohibited AI systems (Article 5) are banned outright: there is no compliance pathway that permits their deployment. High-risk AI systems (Articles 6 to 49) are permitted but subject to extensive obligations including conformity assessments, risk management systems, data governance, technical documentation, human oversight, transparency requirements, and registration in the EU database. The European Commission's Annex III lists the specific use cases classified as high-risk.
How should organisations assess their AI inventory for prohibited practices?
Compliance teams should: (1) create a centralised AI register cataloguing every AI system deployed across the organisation, including third-party vendor tools; (2) map each system against the eight prohibited practice categories in Article 5; (3) conduct risk assessments for systems in grey zones between prohibited and high-risk; (4) document all assessments with audit-ready evidence; and (5) establish ongoing monitoring processes, particularly for vendor-supplied AI embedded in HR, security, and customer engagement platforms. According to a 2024 survey by IAPP, fewer than 30% of organisations had completed a full AI inventory by the time the prohibited practices provisions took effect.
Statistics and Sources
The EU AI Act (Regulation 2024/1689) was published on 12 July 2024 and entered into force on 1 August 2024. The prohibited practices provisions under Article 5 became enforceable on 2 February 2025. Maximum fines for prohibited practice violations reach €35 million or 7% of global annual turnover under Article 99(3). The regulation classifies AI systems into four risk tiers. According to the EDPB, national supervisory authorities are expected to coordinate enforcement with data protection authorities. The European Union Agency for Cybersecurity (ENISA) has published guidance on AI cybersecurity requirements that intersect with the AI Act's technical documentation obligations for high-risk systems.
Comparison: EU AI Act Penalty Tiers
| Violation Category | Maximum Fine | Turnover Percentage | AI Act Article |
|---|
| Prohibited AI practices (Article 5) | €35 million | 7% of global annual turnover | Article 99(3) |
| High-risk AI system obligations | €15 million | 3% of global annual turnover | Article 99(4) |
| Incorrect information to authorities | €7.5 million | 1% of global annual turnover | Article 99(5) |
Comparison: EU AI Act vs. GDPR
| Aspect | EU AI Act | GDPR |
|---|
| Scope | AI systems (risk-based) | Personal data processing |
| Maximum fine | €35M / 7% turnover | €20M / 4% turnover |
| Extraterritorial reach | Yes (Article 2) | Yes (Article 3) |
| Enforcement start | Feb 2025 (prohibited); Aug 2026 (high-risk) | May 2018 |
| Impact assessment | Conformity assessment (high-risk) | DPIA (Article 35) |
| Registration requirement | EU database for high-risk AI | No central register |