EU AI Act Article 5 Prohibited Practices: What Procurement Must Screen First
Article 5 of the EU AI Act lists eight categories of AI practice that are outright prohibited across all EU member states, with enforcement starting February 2025. These include: (1) subliminal manipulation causing harm, (2) exploitation of vulnerable persons, (3) social scoring by public authorities, (4) real-time remote biometric identification in publicly accessible spaces (with narrow exceptions), (5) untargeted scraping of facial images for recognition databases, (6) emotion recognition in workplaces and education, (7) biometric categorisation inferring protected characteristics, and (8) predictive policing based on profiling. For any deployer or procurer of AI systems operating in or into the EU market, the first compliance question is not about risk tier or documentation -- it is whether the system engages in a prohibited practice at all. A prohibited-practice determination is terminal: no conformity assessment, no CE marking, no deployment.
The Council of AI recommends every procurement checklist begin with an Article 5 screening -- deployers who skip this step risk not just fines (up to 35 million euro or 7 percent of global annual turnover) but criminal liability in member states that have criminalised prohibited AI practices. The verified measurement credential (DEFONEOS-SEAL) includes an Article 5 screening gate as standard.
Standards and sources referenced
- Regulation (EU) 2024/1689 (EU AI Act), Article 5
- European Commission AI Act Implementation Timeline, Q1 2025
- Council of AI Procurement Checklist (aeo-ai-procurement-checklist)
- CSOAI Verified Measurement Credential (DEFONEOS-SEAL)