What are the ten prohibited AI practices in Article 5 of the EU AI Act?

Written 20 August 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

Ten, and two of them are new. Article 5(1) carried eight prohibitions from 2 February 2025; Regulation (EU) 2026/1744 inserted points (ba) and (bb), which apply from 2 December 2026. This page is the list itself, in the Regulation's own terms.

The short answer

  • Eight from 2 February 2025, under Article 113, third paragraph, point (a).
  • Two from 2 December 2026 — points (ba) and (bb), inserted by Regulation (EU) 2026/1744.
  • Neither new point stands alone. Articles 5(1a) and (1b) narrow them, and the narrowing decides most cases.
  • A prohibition is not a tier. It is a ban on a practice, and it reaches the practice whoever built the system — what it means for a B2B software company is the guide this list was split out of.
  • Article 5(8): the bans do not displace other law. GDPR, consumer protection and non-discrimination still bite independently.

What are the ten practices?

Article 5(1) lists ten prohibited practices — eight original, two added in 2026. In the Regulation's own terms:

What narrows the two new points?

Neither new point stands on its own. Articles 5(1a) and (1b), inserted by the same amendment and applying from the same date, narrow them, and the narrowing decides most cases. Under Article 5(1a), point (a), placing on the market or putting into service is prohibited only where either (i) that generation or manipulation "is the intended purpose of the AI system", or (ii) the system's "design, training, architecture, capabilities or user-facing functionalities" make it "a reasonably foreseeable and reproducible outcome, without requiring significant technical modification", and the system "does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent that generation or manipulation, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse". Under Article 5(1a), point (b), use is prohibited only where "the deployer uses the system for the purpose of" generating or manipulating such material or performance. And Article 5(1b) — for point (ba) alone, not (bb) — provides that a system manipulating material "in a way that does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities shall not constitute manipulation".

Article 5(8) adds that these prohibitions do not displace other bans that apply where an AI practice infringes other Union law — GDPR, consumer-protection and non-discrimination law still bite independently.

What this means for you

If you're a provider: the list above is a list of practices, not of products, so the question to ask of each system is what it does rather than what it is sold as. Points (f) and (g) are the two that catch ordinary business software most often — an engagement feature that infers emotions in a workplace, a segmentation model that deduces a protected characteristic from biometric data — and both carry a carve-out that decides the case, so read the point in full before deciding it does not apply. Where the answer turns on judgement rather than fact, what our own check will and will not decide says which of these it refuses to answer.

If you're a deployer: a prohibited practice is prohibited for you too. Article 5(1) reaches "placing on the market, the putting into service or the use" of the systems it names, and use is the deployer's act — buying a system that does one of these things does not move the ban onto the vendor. Which duties are yours rather than your vendor's is settled in provider versus deployer; the fine tier for Article 5 is the highest one there is, and it is set out in the penalties guide.

FAQ

When did the prohibitions start applying?

The eight original points from 2 February 2025, under Article 113, third paragraph, point (a). Points (ba) and (bb) apply from 2 December 2026, under the same provision as amended by Regulation (EU) 2026/1744. The dates are the earliest in the Act — the prohibitions came first, not last.

Does a prohibition apply to a system already on the market?

Yes. Both grandfathering paragraphs in Article 111 open "Without prejudice to the application of Article 5", so the transitional relief in the legacy-systems rules never covers a prohibited practice. Placing date and design changes are irrelevant to Article 5.

Is emotion recognition banned everywhere?

No. Point (f) reaches inferring emotions "in the areas of workplace and education institutions", and it excepts medical or safety reasons. Outside those two areas the practice is not prohibited by point (f) — it may still be a transparency obligation under Article 50(3).

What is the fine for a prohibited practice?

The highest tier in the Act: up to €35 million or, "if the offender is an undertaking", up to 7% of total worldwide annual turnover "for the preceding financial year", whichever is higher. Article 99(3) sets it, and it applies to Article 5 alone among the substantive duties.

Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 5, 50, 99, 111 and 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex), which inserted points (ba) and (bb) in Article 5(1) and the qualifying paragraphs Article 5(1a) and (1b). This page was split out of the prohibited AI practices guide on 20 August 2026: the list is a reference, the guide is an argument, and the list was 40% of a page that had to be read from the top to be used.

Where this question meets the product: the AI Act risk classification tool and what it records. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.

Read nextChatbots and voice agents under the EU AI ActArticle 50How to classify your AI systemArticle 6The Annex III high-risk categoriesAnnex III

See which of your AI systems the Act covers.

No account needed. Every answer cites the article it rests on.

Get your free readiness review

Check your AI systems, free