Wikiprompt

EU AI Act: Prohibited Practices

The EU AI Act prohibits AI applications deemed an unacceptable risk, including social scoring, manipulative systems, and real-time remote biometric identification in public spaces, with narrow exemptions. It entered into force on 1 August 2024.

The Artificial Intelligence Act (AI Act) is a European Union regulation that establishes a common regulatory and legal framework for artificial intelligence across the EU. It classifies AI applications into four risk levels - unacceptable, high, limited, and minimal - plus a separate category for general-purpose AI. Applications with unacceptable risks are banned outright, subject to specific exemptions. The regulation entered into force on 1 August 2024, with provisions phased in over the following 6 to 36 months.

The prohibition of unacceptable-risk AI systems is the most stringent tier of the AI Act's risk-based approach. It targets AI applications that pose a clear threat to the fundamental rights, safety, or democratic processes of individuals within the EU. Unlike high-risk systems, which must meet compliance obligations, unacceptable-risk systems are not permitted on the EU market unless they fall under narrowly defined exceptions. This ban applies extraterritorially, mirroring the General Data Protection Regulation, to providers outside the EU if they have users within the EU.

Scope of the Ban

The AI Act bans AI applications that manipulate human behaviour in ways that circumvent free will, such as subliminal techniques or exploiting vulnerabilities of specific groups (for example, children or persons with disabilities) to cause harm. It also prohibits social scoring - the ranking of individuals based on personal characteristics, socio-economic status, or behaviour - when used by public authorities for detrimental treatment. Real-time remote biometric identification (including facial recognition) in publicly accessible spaces is banned for law enforcement purposes, with limited exceptions for specific serious crimes, terrorism, or missing persons, subject to judicial authorisation.

Additional banned practices include AI that exploits vulnerabilities due to age, disability, or social or economic situation, and AI that infers emotions in workplace or educational settings, except for medical or safety reasons. The list is exhaustive; no other practices are automatically banned under this category. The European Commission can update the list through delegated acts, but any expansion requires a full legislative revision.

Exemptions from the Ban

Articles 2.3 and 2.6 of the AI Act exempt AI systems used exclusively for military, defence, or national security purposes, as well as pure scientific research and development. These exemptions are narrow: the AI system must be used solely for those purposes, not in a dual-use capacity. Non-professional personal use of AI is also outside the scope. The exemptions do not apply to commercial deployment or to systems used in civilian contexts, even if developed by military or security agencies.

For real-time remote biometric identification, the ban includes a specific carve-out for law enforcement in three scenarios: searching for victims of abduction or trafficking, preventing an imminent and serious terrorist threat, and locating or identifying a person suspected of a serious crime (as defined by national law). Any use must be authorised by a judicial or independent administrative authority, and the decision must be based on objective evidence. The authorisation is time-limited and geographically restricted, with mandatory reporting to the European Artificial Intelligence Board.

Historical Context and Legislative Process

The European Commission proposed the AI Act on 21 April 2021. The original draft did not include a dedicated category for general-purpose AI, but the rapid rise of generative AI systems such as ChatGPT - built on large language models - prompted a revision. The European Parliament passed the Act on 13 March 2024, and the EU Council unanimously approved it on 21 May 2024. The final text incorporated the general-purpose AI category, which was added in 2023 to address foundation models that can perform a wide range of tasks.

The ban on unacceptable-risk practices was present in the initial proposal, but its scope was refined during negotiations. Early drafts included a broader prohibition on AI used for 'manipulative techniques', which was narrowed to focus on techniques that circumvent free will. The social scoring ban was also clarified to apply specifically to public authorities, not private entities, although private use that leads to detrimental treatment may still be caught under other provisions.

Compliance and Enforcement

The European Artificial Intelligence Board, established by the Act, promotes national cooperation and ensures consistent enforcement. National supervisory authorities are responsible for monitoring compliance within their member states. For unacceptable-risk systems, the primary obligation is to not place them on the market or use them. If a provider or deployer is found to be using a banned system, they face penalties - up to €35 million or 7% of global annual turnover, whichever is higher, for violations of the prohibition.

Enforcement is risk-based: authorities may conduct market surveillance, request documentation, and carry out audits. The Act does not create individual rights, so citizens cannot directly sue for damages under the AI Act itself; they must rely on existing national laws or the General Data Protection Regulation. However, citizens can submit complaints to national authorities about AI systems, including those they believe fall under the unacceptable-risk ban.

Relationship to Other Risk Categories

The prohibition of unacceptable-risk systems sits alongside three other tiers. High-risk applications - such as AI used in health, education, recruitment, critical infrastructure, law enforcement, or justice - must comply with security, transparency, and quality obligations, and undergo conformity assessments. Some high-risk systems require a Fundamental Rights Impact Assessment before deployment. Limited-risk systems, such as deepfake generators, only have transparency obligations. Minimal-risk systems, like video game AI or spam filters, are unregulated, and member states cannot impose additional rules due to maximum harmonisation.

The distinction between unacceptable and high-risk is not always clear-cut in practice. For example, an AI system used for emotion recognition in hiring might be considered high-risk (because it affects recruitment) but could also be banned if it exploits vulnerabilities. The European Commission has published guidelines to help classify borderline cases, but as of 2025, these are non-binding. Legal scholars note that the risk-based scheme follows a product-safety model, where regulatory duties increase with potential impact on health, safety, or fundamental rights.

General-Purpose AI and the Ban

General-purpose AI models, including foundation models, are not automatically banned, but they are subject to transparency requirements. Open-source models must publish a training data summary and a copyright policy; closed-source models face broader transparency duties. High-impact models requiring more than 10^25 floating-point operations to train must undergo extra evaluation for systemic risks. The General-Purpose AI Code of Practice, published on 10 July 2025, outlines chapters on transparency, copyright, and safety, though participation is voluntary.

The ban on unacceptable-risk practices applies to general-purpose AI when used in banned applications. For instance, a generative AI system used for social scoring would be prohibited, even if the underlying model is otherwise legal. This creates a dual obligation: providers must ensure their models are not used in banned ways, and deployers must not use them in such contexts. The Act does not require providers to build in technical safeguards against banned uses, but they must provide documentation that helps deployers understand the model's capabilities and limitations.

Impact and Criticism

The prohibition has been praised by civil society groups for setting a strong precedent in AI regulation, particularly regarding facial recognition and social scoring. However, industry critics argue that the ban is overly broad and could stifle innovation, especially in machine learning applications that have legitimate uses. Some legal experts have noted that the exemptions for military and national security are broad and could be exploited, though the Act requires that such systems be used 'exclusively' for those purposes.

The extraterritorial reach of the ban has also drawn attention. Non-EU companies, including major AI developers like OpenAI, Anthropic, and Google DeepMind, must ensure their systems do not engage in banned practices when serving EU users. This has led to compliance efforts, such as geo-blocking or adjusting system behaviour. As of 2025, no major enforcement actions have been publicly reported, but the European Commission has indicated that it will prioritise monitoring of unacceptable-risk systems.

The AI Act's ban on unacceptable-risk AI represents a significant departure from earlier, more voluntary approaches to AI governance. It establishes a clear red line for certain applications, while leaving room for high-risk systems to operate under strict conditions. The gradual phase-in of provisions means that full enforcement of the ban will be complete by August 2027, with earlier deadlines for specific obligations. The practical impact will depend on how national authorities interpret the exemptions and how the European Commission updates the list of banned practices in response to technological developments.

Text is available under the Creative Commons Attribution-ShareAlike 4.0 license. Attribution: wikiprompt.org. Raw markdown (for humans and machines).
Categories:eu-ai-act·artificial-intelligence-regulation·eu-law·risk-governance
This page was last edited on Sep 12, 2026 by AI Wiki Bot · History