The EU AI Act bans eight AI practices completely. They are not high-risk-with-conditions; they are forbidden, and no risk management makes them acceptable. They have been prohibited since February 2025 and carry the heaviest fines in the whole Act: up to 35 million euros or 7 percent of worldwide turnover. Most businesses will never touch the exotic ones, but two of them, involving how you treat employees, are traps an ordinary company can fall into without realising.
In the last episode we explained the four risk tiers, and noted that the top tier, unacceptable risk, means outright prohibition. This week we open that box. These are the uses the EU decided are so harmful to people's rights and dignity that no safeguard, audit, or disclosure can make them lawful. Knowing the list matters for one simple reason: everything else in compliance is about doing something correctly, but for these, the only compliance is not doing them at all.
The eight banned practices
The Act prohibits eight categories. The first two concern manipulation: AI that uses subliminal or deceptive techniques to distort someone's behaviour in a way that causes harm, and AI that exploits the vulnerabilities of a specific group, such as age, disability, or economic hardship, to do the same. The third is social scoring: evaluating or classifying people based on their behaviour or characteristics in a way that leads to unfair treatment in contexts unrelated to where the data came from. The fourth is predicting an individual's likelihood of committing a crime based solely on profiling or personality traits, rather than genuine facts.
The remaining four are largely biometric. Building facial-recognition databases by scraping images from the internet or CCTV without any targeting is banned. So is emotion recognition in workplaces and schools. So is biometric categorisation designed to infer sensitive characteristics like race, political views, or sexual orientation. And finally, real-time remote biometric identification in public spaces for law enforcement is prohibited, with only narrow, tightly controlled exceptions. Across all eight, the logic is the same: these uses treat people in ways incompatible with fundamental rights, so they are off the table entirely.
Most companies will never build a facial-recognition database or a predictive-policing tool. But two bans catch normal businesses off guard. The first is emotion recognition in the workplace: software that claims to read employees' feelings from their face, voice, or expressions during work or interviews is prohibited. The second is a subtler form of social scoring: an employee-monitoring system that aggregates behavioural data, attendance, message response times, peer feedback, into a single "performance score" that drives decisions can cross the line if it treats people unjustly relative to the behaviour measured. If you use or are considering either, that is where to look first.
Two new bans arriving in December 2026
The list is not static. The Digital Omnibus, the same package that adjusted other deadlines, adds two further prohibitions taking effect on 2 December 2026. Both target clearly abusive generative AI: systems designed to produce non-consensual intimate imagery of real people, and systems that generate child sexual abuse material. These additions reflect how the banned list evolves as new harms emerge, and they are aimed at abusive tools rather than ordinary business software, but they are worth knowing as part of the current picture.
What is at stake
This tier carries the most serious consequences in the entire Act. Breaching the prohibitions can bring fines of up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher, notably higher than the penalties for the transparency duties in earlier episodes. And this is not theoretical: the prohibitions have been enforceable since February 2025, and the European Commission opened its first formal investigations into potential violations in early 2026, focused on social scoring and manipulative techniques, often triggered by complaints from individuals and civil-society groups. The banned list is being actively policed.
Your action this week
Your task is a focused audit. Look through the AI systems you use or plan to use and ask a blunt question of each: could this fall into any of the eight banned categories? For most systems the answer is a quick and clear no. Pay real attention to two areas in particular: any tool that claims to detect employees' emotions, and any staff-monitoring system that scores people on aggregated behaviour. If either is present, treat it as a priority to review with a qualified professional, because the fix here is not adjusting how you use it, it is likely stopping. For everything else, note that you checked and found no prohibited use. Next week, we move into the high-risk tier and the obligations that come with it.
Frequently asked questions
What AI practices are completely banned in the EU?
Eight: manipulative or subliminal techniques that cause harm, exploiting a group's vulnerabilities, social scoring, predicting crime based solely on profiling, untargeted facial-image scraping, emotion recognition in workplaces and schools, biometric categorisation of sensitive traits, and real-time remote biometric identification in public by law enforcement. They have been prohibited since February 2025, with no safeguards able to make them lawful.
Could my business accidentally use a banned practice?
For most, the risk is low, but two bans catch ordinary businesses. Emotion-recognition software used on employees is prohibited outright. And an employee-monitoring system that aggregates behaviour into a performance score can amount to prohibited social scoring if it treats people unjustly. If you use either, review it with a professional as a priority.
What are the penalties for a banned AI practice?
The highest in the Act: up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher. That is notably more than the fines for the transparency rules covered earlier in this series. The prohibitions have been enforceable since February 2025, and formal investigations began in early 2026.
Are these bans actually enforced, or just on paper?
They are being enforced. The European Commission opened its first formal investigations into suspected Article 5 violations in early 2026, with a focus on social scoring and manipulative techniques. Complaints from individuals and civil-society organisations have been a primary trigger, echoing the early pattern of GDPR enforcement.
Are new practices being added to the banned list?
Yes. The Digital Omnibus adds two prohibitions from 2 December 2026, targeting AI that generates non-consensual intimate imagery of real people and AI that generates child sexual abuse material. These aim at clearly abusive tools rather than ordinary business software, and show that the banned list evolves as new harms appear.
Follow the series, get compliant one rule at a time
This is Part 4 of our weekly guide to AI regulation, breaking down one rule at a time so compliance feels manageable instead of overwhelming. Explore more clear, honest guides on AISetApp and follow along each week.
Explore more on AISetApp- EU AI Act (Regulation (EU) 2024/1689), Article 5 prohibited practices, applicable since 2 February 2025
- Digital Omnibus on AI (Regulation (EU) 2026/1744) on two additional prohibitions from 2 December 2026
- 2026 legal analyses of the eight Article 5 bans, the workplace emotion-recognition and social-scoring traps, and Article 99 penalties, from aiactbase.eu, eyreACT, and the Future of Privacy Forum
- Reporting on the European Commission's first Article 5 investigations, 2026
Reviewed August 2026. This is an explainer, not legal advice. The law is evolving; verify specifics with a qualified professional before acting.
Researched and drafted with AI assistance, reviewed and edited by Yasser El Hardouz, who takes editorial responsibility for this article.