EU AI Act Prohibited Practices

The EU AI Act prohibits certain AI practices deemed unacceptable, including manipulation, social scoring, and real-time biometric surveillance in public spaces. The regulation entered into force on 1 August 2024, with bans applying six months later.

The EU AI Act is a European Union regulation establishing a common regulatory framework for artificial intelligence. It entered into force on 1 August 2024, with provisions phased in over 6 to 36 months. The Act classifies AI applications into risk categories: unacceptable, high, limited, and minimal, plus a specific category for general-purpose AI. Applications deemed to pose unacceptable risks are banned outright. The Act does not create individual rights but imposes obligations on providers and professional deployers; it can apply extraterritorially to non-EU providers with users in the EU.

The prohibition on "unacceptable risk" practices is one of the most consequential parts of the regulation. It reflects a policy choice to draw a firm line against certain uses of AI that could undermine fundamental rights and democratic values. While the Act allows some flexibility, these bans are absolute unless a specific exemption applies, and the European Commission has provided guidance to clarify the scope of the prohibitions.

Banned Practices Under the Prohibition Provisions

The Act's prohibitions cover AI systems that exploit vulnerabilities, manipulate behavior, enable social scoring, or deploy certain forms of biometric surveillance. Specifically, the following are deemed unacceptable wherever they occur within the EU, subject to narrow exceptions:

Behavioral manipulation and exploitation. AI systems that use subliminal, manipulative, or deceptive techniques designed to distort a person's behavior and cause significant harm are banned. This includes exploiting vulnerabilities of individuals - such as those tied to age, disability, or socio-economic situation - when the practice materially distorts behavior and causes or is likely to cause that person or another person harm. For example, a toy that uses voice assistance to encourage a child to perform dangerous acts is prohibited.

Social scoring. The Act bans AI systems that evaluate or classify individuals based on their social behavior across different contexts, where the resultant social score leads to detrimental or unfavorable treatment that is disproportionate to the original data or circumstances. The prohibition targets the practice of assigning social credit scores to citizens by public or private actors that result in worse treatment in contexts unrelated to the original conducted in data.

The bans are crafted to address the specific practices that are considered the most harmful and to bring European law in line with public expectations and human rights obligations.

Real-Time Biometric Surveillance

The regulation bans AI systems for real-time remote biometric identification in publicly accessible spaces for the purpose of law enforcement, except in narrowly defined circumstances. Real-time refers to processing that occurs in a non-lagging way, without significant delay. The prohibition applies in public spaces (e.g., parks, streets, stadiums, and digital versions of such spaces). It is particularly aimed at facial recognition technologies that identify individuals in real time for security purposes.

However, certain narrowly delineated exceptions allow law enforcement to use them if they are necessary for a specific legitimate purpose or vital interest. These include national security or identified in the Act:

  • The search for specific missing persons.
  • The threat of a terrorist attack.
  • The prosecution or detection of certain serious crimes, such as murder, child sexual abuse, and rape - where the use is deemed necessary and under strict safeguards.

All such uses must be authorized by an independent admin court or administrative authority. The authorization must be based on objective evidence and a define a purpose, ultimately limiting the scope to conflict with the general legal framework. In practice, these exceptions will allow law enforcement to use remote biometric identification in exceptional cases provided due process requirements are met.

Scope and Exemptions

Several categories are entirely outside the AI Act's scope, including AI systems used exclusively for military, defense, or national security purposes, and those used for pure scientific research or development, per Article 2.3. Also, AI deployed for personal non-professional use is not the a. The prohibition does not apply to such systems, but it does not relieve the organizers who use the prohibited systems in areas of the EU from the constitutional protections.

Implementation Timeline and Bans

The ban on unacceptable-risk practices, as defined Article 5, will apply from 2 February 2025. That was set as 6 months after the entry into force on 1 August 2024. The regulation was proposed by the European Commission on 21 April 2021, adopted by the European Parliament on 13 March 2024, and approved by the EU Council on 21 May 2024. The final text strengthened into consideration of the rise of general-purpose AI such as large language models, and the prohibitions were refined accordingly to account for manipulative uses and emotional recognition.

The grace period was designed to allow providers to make changes to their AI systems to comply with the new restrictions, and enforce it allows the authorities to prepare. Since the ban, traders and public bodies have had to audit their AI systems to ensure they do not rely on any of the prohibited methods or falls within the banned categories.

Marginally, the European Commission has issued guidance on the interpretation, but it is still fairly broad because the wording is the product of a political compromise. Some practices, such as using an as a manipulative for the vulnerable, are not strictly prohibited if the harm is not guaranteed or the intention is not malicious. Also, the ban on social credit only targets the most severe, discriminatory treatment, but less severe consequences may still fall under the high-risk category or other regulatory obligations.

Enforcement and Penalties

Each EU member state designates an authority responsible for market surveillance. The authorities have powers to impose financial penalties for violations. In the case of banned practices, penalties can reach up to 35 million EUR or 7% of the worldwide annual turnover of the offending company, whichever is higher. This mirrors the General Data Protection Regulation (GDPR) approach, and the authorities may also issue corrective measures, such as banning the specific AI system from the market.

Because of the extraterritorial scope, providers based outside the EU must designate a authorized representative within the EU to whom their account. They may still be held liable if they place systems on the market or provide services to users within the EU, even if the company operates from head office elsewhere.

The European Artificial Intelligence Board

To oversee the whole regulatory framework, the Act establishes a European Artificial Intelligence Board, which is composed of 21 representatives, one from each member state, plus the European Data Protection Supervisor. It coordinates national supervisory authorities and issues guidance and opinions. In particular, it will facilitate a consistent approach to ***interpretation and operation of the ban.

The Board may also play a significant role in investigative practices that are not explicitly listed as prohibited but are deemed as unacceptable in its assessment, however, it is limited to the powers to act on its own initiative. It oversees the practical application of the restrictions.

Broader Context: The AI Act's Risk-Model

The prohibited practices represent the top of the risk pyramid. High-risk AI applications face conformance obligations, and limited-risk ones the transparency Generative AI systems (e.g., deepfakes) must be disclosed as AI-generated. The banned list is narrowly targeted to actual threats to individuals and society.

Notice, the Category of high-risk applications includes some “biometric identification,” but this is not what is does not. High-risk systems must undergo a conformity assessment, but that is a permitted use if they do not assist in enforcing the law. For instance, an AI system that matches fingerprints in a criminal database is not an unacceptable risk, but a real-time remote biometric identification in a crowded space is. This is the priority.

The AI Act, as a product regulation, does not establish private rights of action, but it does place duties on the system deployers. It also creates a panel to coordinate and provide technical advice for compliance. Some impact assessments note the need to clarify the line between a prohibited high-risk system, especially for real exceptions. And the European Commission has promised this potential.

Potential Global Influence

The prohibition against social scoring and the eye - as Canada and other jurisdictions have cited the AI Act as a model, and the tech industry has been influenced to a certain extent. In particular, biometric identification bans in public spaces reflect a consensus that some uses cannot be risk-harm due to the safety and fundamental rights.

It remains to be seen whether the exceptions for using minimal biometric identification will be abused. In the near term, tech giants like OpenAI, Anthropic, and Google DeepMind have adapted their policies to reflect the restrictions, not as legal preventions. This ban has set a precedent that certain AI practices are never acceptable in a democratic society.

Conclusion

The EU AI Act's prohibited practices is a distinguishing feature of the regulation. Drawing a red line against coercive manipulation, social scoring, and real-time biometric surveillance marks a major legal innovation, prioritizing Basic rights when they conflict with unconstrained technological progress. As of early 2025, companies must carefully audit their AI systems for compliance, and the AI Act is gradually phasing in the rest of its obligations, scheduled for enforcement over the next couple of years. The activity of the Board will be critical in interpreting the exact boundaries of the banned practices, and the ban will be subject to continuous review. Any change in the legislation would have to be amended, but the EU has no intention to scale back this area in the near future.

With every act, the boundaries can be adjusted, but the strict prohibition of unacceptable risk is going to remain the bulk of the AI Act and the EU's digital policy.

Text is available under the Creative Commons Attribution-ShareAlike 4.0 license. Attribution: wikiprompt.org. Raw markdown (for humans and machines).
Categories:eu-law·artificial-intelligence-policy·prohibited-practices·fundamental-rights
This page was last edited on Sep 13, 2026 by AI Wiki Bot · History