The EU AI Act Prohibitions are a set of bans under the European Union's Artificial Intelligence Act (AI Act), which entered into force on 1 August 2024. These prohibitions target AI applications classified as posing unacceptable risks to fundamental rights, safety, and democratic values. They became applicable on 2 February 2025, marking the first major enforcement milestone of the regulation. The bans are part of a broader risk-based framework that also governs high-risk, limited-risk, and minimal-risk AI systems, as well as general-purpose AI models.
The AI Act, proposed by the European Commission on 21 April 2021, was adopted by the European Parliament on 13 March 2024 and approved by the EU Council on 21 May 2024. It establishes a common regulatory framework for AI across the EU, with extraterritorial reach similar to the General Data Protection Regulation. The prohibitions are designed to prevent AI uses that are considered fundamentally incompatible with EU values, while allowing certain narrowly defined exceptions for law enforcement and security purposes.
Scope of Prohibited Practices
The AI Act bans AI systems that deploy subliminal, manipulative, or deceptive techniques to distort behavior and impair informed decision-making, causing significant harm. This includes exploiting vulnerabilities of individuals or groups due to age, disability, or socio-economic situation. Also prohibited are AI-based social scoring systems that evaluate or classify individuals based on their behavior, personal characteristics, or social interactions, leading to detrimental treatment. The use of real-time remote biometric identification in publicly accessible spaces for law enforcement is banned, except for specific serious crime scenarios with judicial authorization. Additionally, AI systems that infer emotions in workplaces or educational institutions are prohibited, as are those that create facial recognition databases by untargeted scraping from the internet or CCTV footage.
Exemptions for Law Enforcement and Security
Certain prohibited practices have narrow exemptions. Real-time remote biometric identification may be used by law enforcement for targeted searches of victims of abduction, human trafficking, or sexual exploitation, or to prevent concrete, substantial threats to life or safety. These uses require prior judicial approval and are subject to strict time and geographic limits. The ban on emotion recognition does not apply to AI systems placed on the market for medical or safety reasons, such as detecting distress in healthcare settings. Military and national security AI systems are entirely exempt from the AI Act, as are systems used for scientific research and development.
Implementation and Enforcement
Member states were required to designate national competent authorities to supervise the application of the prohibitions. The European Artificial Intelligence Board, established by the Act, facilitates cooperation and compliance. Penalties for violations of the prohibited practices can reach up to 35 million euros or 7% of a company's global annual turnover, whichever is higher. The European Commission has published guidelines to clarify the scope of the bans, particularly regarding emotion recognition and biometric categorization.
Impact on AI Development and Deployment
The prohibitions have significant implications for AI developers and deployers. Companies operating in the EU must conduct thorough assessments to ensure their AI systems do not fall into the unacceptable risk category. This has led to adjustments in product design, particularly for Generative AI systems and Artificial intelligence applications that might inadvertently manipulate user behavior. The bans also affect Machine learning models used in social media algorithms, advertising, and human resources, as these could be seen as manipulative or discriminatory. Some non-EU providers have chosen to restrict access to certain AI features in the EU to avoid compliance burdens.
Relationship with Other AI Act Provisions
The prohibitions are distinct from the obligations for high-risk AI systems, which require conformity assessments, transparency, and human oversight. Limited-risk systems, such as Large language model chatbots, must only inform users that they are interacting with AI. Minimal-risk systems, like spam filters, are unregulated. The general-purpose AI category, added in 2023 to address systems like ChatGPT, imposes transparency and copyright duties, with additional evaluations for models requiring over 10^25 floating-point operations. The prohibitions operate independently, meaning any AI system, regardless of its risk category, cannot engage in banned practices.
Global Influence and Comparisons
The EU AI Act Prohibitions have influenced AI regulation worldwide. Other jurisdictions, including Canada and Brazil, have referenced the EU framework in their own legislative proposals. However, the bans are more restrictive than approaches in the United States, which rely on voluntary guidelines and sector-specific rules. The extraterritorial reach of the Act means that AI providers outside the EU, such as those in the OpenAI ecosystem or Google DeepMind, must comply if they offer services to EU users. This has led to global corporate policies that align with EU standards, even in regions without similar laws.
Criticisms and Debates
Legal scholars and industry experts have debated the clarity and feasibility of the prohibitions. Critics argue that terms like "manipulative techniques" and "significant harm" are vague, potentially leading to inconsistent enforcement. Others contend that the exemptions for law enforcement are too broad, allowing for potential misuse. Proponents emphasize that the bans protect fundamental rights and set a global benchmark. The European Commission has committed to issuing further guidance and updating the list of prohibited practices as technology evolves, ensuring the Act remains responsive to emerging risks.
Future Outlook
As of 2025, the prohibitions are being enforced, with national authorities beginning to issue compliance notices. The European Commission plans to review the implementation by 2029, considering technological developments and the need for adjustments. The success of the bans will depend on effective coordination among member states and the ability to adapt to new AI capabilities. The EU AI Act Prohibitions represent a pioneering effort to regulate AI at its most harmful extremes, balancing innovation with the protection of individual rights.