The Ten Prohibited AI Practices in Europe (and the Two Almost Nobody Has Counted)

TL;DR

What does it actually mean that an AI practice is "prohibited"?

The AI Act classifies AI systems by risk levels. Most fall in categories where you can operate by meeting requirements: documentation, human oversight, transparency, registration. Article 5 is different. There is no paperwork to file. These are unacceptable-risk practices, and what the regulation says is literal: "The following AI practices shall be prohibited".

Two nuances change how to read it substantially.

First: the prohibition covers the placing on the market, the putting into service and the use. Not only the manufacturer. Also the user. A company that buys a tool and deploys it is a "deployer" within the meaning of Article 3(4): someone who "uses an AI system under its own authority, except where that use is made in the context of a personal non-professional activity". If you use it in your business, you are inside.

Second: the definition of "AI system" in Article 3(1) is broad. A machine-based system with varying levels of autonomy that "infers, from the input it receives, how to generate outputs". That verb, infer, is what makes a sentiment analysis module inside an HR suite count as an AI system, even if the vendor sells it as just another feature.

And there is no transition period for the original eight prohibitions: they have applied since 2 February 2025.

What are the eight prohibitions applying since February 2025?

PointProhibited practiceCan it affect an SME?
(a)Subliminal techniques that operate below consciousness, or deliberately manipulative or deceptive techniques that materially distort behaviour and cause significant harmRare, but not impossible in aggressive sales interfaces
(b)Exploiting vulnerabilities arising from age, disability or a specific social or economic situation to materially distort behaviourMarketing targeting vulnerable groups
(c)Social scoring: evaluating or classifying persons based on social behaviour or personal characteristics, with detrimental or disproportionate treatment in unrelated contextsPoorly designed internal scoring of customers or suppliers
(d)Predicting the risk that a person commits a criminal offence based solely on profiling or personality traitsUnusual outside law enforcement contexts
(e)Creating or expanding facial recognition databases through untargeted scraping of images from the internet or CCTV"Lead enrichment" tools using photos
(f)Inferring emotions of a natural person in workplaces and educational settings, except for installation or placing on the market for medical or safety reasonsYes. This is the most probable one
(g)Biometric categorisation to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientationBiometric segmentation in retail or events
(h)Real-time remote biometric identification in publicly accessible spaces for law enforcement purposesNo: this is for law enforcement authorities

Point (h) has a closed set of exceptions (searching for victims of abduction or trafficking, imminent threat to life, locating suspects of certain offences) and requires judicial or independent administrative authority authorisation. It does not apply to private companies.

What two prohibitions has the Digital AI Omnibus added?

Here is the part that has barely circulated. Regulation (EU) 2026/1744, made in Strasbourg on 8 July 2026 and published in the OJEU on 24 July 2026, amends the AI Act in dozens of places. Its point 7 says: "Article 5 is amended as follows: (a) in paragraph 1, first subparagraph, the following points are inserted".

Point (b bis). Prohibits "the placing on the market, putting into service or use of an AI system that generates or manipulates realistic images, videos or audio or similar material of the intimate parts of an identifiable natural person, or of an identifiable natural person engaged in sexually explicit activities, without the free, specific, informed and unambiguous explicit consent of that person for such generation or manipulation".

Point (b ter). Prohibits the same in relation to "material or performances within the meaning of Article 2(c) and (e) of Directive 2011/93/EU" (child sexual abuse material), "except where an 'unlawful conduct' defence applies under national law".

The same point 7 inserts two new paragraphs, 1a and 1b, delimiting when the infringement is deemed to have been committed. This is the technically most precise part and the one that matters to anyone integrating generative models into a product:

Recital 10 of the Omnibus explains the rationale: the widespread deployment and use of systems generating "non-consensual intimate material" made it necessary to amend Article 5.

When do the two new ones apply and why does the gap matter?

They do not apply from 27 July 2026, even though the Regulation is already in force. Point 40 of the Omnibus replaces point (a) of the third paragraph of Article 113 of the AI Act, which now reads:

"Chapters I and II shall apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (b bis) and (b ter), and Article 5, paragraphs 1a and 1b, which shall apply from 2 December 2026."

That means: a window of roughly four months for providers and deployers to adapt safeguards, detection mechanisms and consent flows. If you sell or integrate image or video generation, that date is your real deadline.

ProhibitionApplies from
Points (a) to (h) of Art. 5(1)2 February 2025
Points (b bis) and (b ter), and paragraphs 1a and 1b2 December 2026

Developing the capability is not prohibited: selling it without guardrails is

Recital 12 of the Omnibus is unambiguous: the prohibition "should not prevent providers from developing the technical capabilities of AI systems to generate or manipulate images, videos, audio or similar material". A model capable of generating realistic human bodies is not, by itself, a prohibited system. The line is drawn at placing it on the market or putting it into service in the two circumstances of paragraph 1a: where generating that material is its intended purpose, or where it is a reasonably foreseeable and reproducible outcome and the system is released without guardrails to prevent it.

The same recital adds two operational nuances. For providers that maintain "effective control" over the system — those serving it via platform or web interface — safeguards may include tracking and reporting of misuse, in compliance with privacy and data protection law. And if the provider observes, or is notified, that its barriers are being circumvented, it must take appropriate corrective measures, assessed against the system and its distribution strategy; the text expressly mentions open-source releases as a factor to weigh.

Translated to practice: a provider that opens an image generation endpoint and ignores what comes out of it has a problem from 2 December. A provider that documents its guardrails, monitors for circumvention and fixes it when notified has a file to show.

Technical safeguards the regulation itself cites

You do not need to guess what counts as "reasonable and adequate technical safety measures": Recital 12 provides the list. It deserves to be read as a menu of evidence, because it is what a provider or integrator will need to be able to demonstrate:

The sufficiency bar is also defined: measures are reasonable if appropriate to the specific system, and adequate if they are state-of-the-art and demonstrably prevent or sufficiently reduce the probability of generating that material, accounting for reasonably foreseeable circumvention. Two consequences: the bar will move with the state of the art, so 2026 safeguards cannot remain frozen forever; and "demonstrably" implies a dated record of what filters exist, what circumvention tests have been done and what was corrected after each notification.

The "unlawful conduct" defence: who it really applies to

Point (b ter) has an exception with disconcerting wording: the prohibition does not apply "where an 'unlawful conduct' defence applies under national law". In quotation marks, exactly as it appears in the OJEU in English; it refers to the defences in Article 5(1) of Directive 2011/93/EU.

Recital 13 specifies who it covers: authorities generating or manipulating such material legitimately for criminal proceedings or to prevent, detect and investigate offences, and the use of "red teams" and evaluations aimed at verifying that the system itself complies with the prohibition. The exception exists so that law enforcement can work and so that a model's barriers can be tested without committing the very infringement being prevented. It is not a route for platforms or anyone acting outside a national-law authorisation.

Labelling a deepfake does not legalise it: the relationship with Article 50

It is worth keeping the planes separate. Article 50 of the AI Act imposes transparency obligations — marking synthetic content in machine-readable format (paragraph 2) and disclosing deepfakes (paragraph 4) — applicable from 2 August 2026. Point (b bis) is a different thing: a prohibition. A non-consensually generated intimate video is not de-prohibited by carrying a synthetic content label; the label does not substitute consent, and consent does not exempt from the label.

And there is the double date. Omnibus point 39 adds paragraph 4 to Article 111: providers of AI systems — including general-purpose ones — generating synthetic audio, image, video or text content placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2) marking. The same day the new prohibitions apply, the transitional marking period for all installed generative systems expires.

Practical calendar

RoleWhat to review before 2 December
Provider of a generative systemRecital 12 safeguards implemented and documented; circumvention tests done and dated; notification-and-action channel operational; Art. 50(2) marking if the system predates 2 August 2026
Integrator (third-party model via API with own features)What guardrails the base model applies and what the own layer adds; contract with the provider on misuse and remediation; how synthetic content marking is propagated
Business userActual purpose of use of contracted generative tools; internal instructions excluding generation of intimate material of identifiable persons; documented consents where working with real persons' images

The closing rule in paragraph 1a, point (b), protects the good-faith user: use is only prohibited where the system is used with the aim of generating that material. But that protection is for accidents, not negligence: a company that has given no instructions to its staff will have a harder time arguing the intent was not there.

Which of the ten actually affects a Spanish SME?

Point (f). By a long way.

The text prohibits "the placing on the market, putting into service for this specific purpose, or use of AI systems to infer the emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or on the market for medical or safety reasons".

Recital 44 of the AI Act makes the reason clear: there is "a great deal of concern about the scientific basis" of these systems, because emotional expression varies across cultures, situations and even within the same person. And it adds the argument that seals the matter in workplaces and classrooms: the power imbalance.

Where this appears without anyone calling it "emotion AI":

What does not fall in, per Recital 18 of the AI Act, which defines "emotion recognition system": physical states such as pain or fatigue are excluded. The regulation's own example is systems for detecting pilot or professional driver fatigue. Nor does "mere detection of expressions, gestures or movements that are obvious" count, unless used to distinguish or deduce emotions.

And there is an express exception in point (f): medical or safety reasons. It is a narrow exception, tied to the purpose for which the system is intended to be installed or marketed, not a cover story for re-labelling a staff climate module as "risk prevention".

How to check if a tool you already have contracted breaches point (f)?

Without opening the code. With four written questions to the vendor and a review of the contractual documentation.

  1. Does any product feature distinguish or infer emotions, moods or intentions of persons from biometric data (voice, face, gestures, gaze)? Ask for a yes or no, not a marketing paragraph.
  2. If yes, does that feature operate on my company's staff or on students, or only on third parties outside the employment relationship?
  3. Can that feature be verifiably disabled at my instance level, and how do I demonstrate it?
  4. Does the vendor declare any medical or safety purpose as the system's destination, within the meaning of Article 5(1)(f) of Regulation (EU) 2024/1689?

Keep the replies. If there is an inspection or complaint tomorrow, the difference between a problem and a scare is having in writing that you asked and what you were told.

Also review the glossary of your contract and the product sheet. Labels that should set off an alarm: sentiment analysis, emotion AI, affective computing, engagement score, mood tracking, attention scoring, voice tone analysis.

What if my software only scores candidates or measures performance? Is it prohibited?

Not necessarily. This is where a lot of people get confused and where precision matters.

Filtering CVs, posting targeted job adverts, evaluating candidates, assigning tasks or monitoring performance are not in Article 5. They are in Annex III, point 4, which classifies those systems as high risk. High risk does not mean prohibited: it means obligations. And the Chapter III, Sections 1, 2 and 3 obligations for Annex III systems apply, after the Omnibus amendment to Article 113, from 2 December 2027.

The dividing line in practice: if the system infers emotions of your staff, it is a prohibition. If it evaluates performance or candidates without inferring emotions, it is high risk with a 2027 date.

A point already in force that is often forgotten: Article 26(7) requires deployers who are employers to inform worker representatives and affected workers before putting a high-risk AI system into service or use in the workplace.

How much does breaching a prohibition cost and who enforces it in Spain?

Article 99(3) of the AI Act: administrative fines of up to €35,000,000 or, for a company, up to 7% of its total worldwide annual turnover for the preceding financial year, "whichever is higher".

Paragraph 6 reverses the comparison for SMEs: in their case, the fine "may be the percentage or the amount referred to in paragraphs 3, 4 and 5, whichever of them is lower". The Omnibus added paragraph 6a with an equivalent rule for small mid-cap companies, referring to paragraphs 4 and 5.

In Spain, the sanctions regime is being transposed. The Draft Organic Law for the proper use and governance of artificial intelligence was published in the Official Gazette of the Spanish Parliament (Congress, Series A, No. 97-1) on 12 June 2026. Article 14 classifies prohibited practices as a very serious infringement, listing expressly "Article 5(1) points (a), (b), (c), (d), (e), (f), (g) and (h)". That is, the text as published does not yet include points (b bis) and (b ter), as it predates the Omnibus. It is a bill subject to amendment and not yet in force; its parliamentary progress should be followed before treating any national figure as settled.

What to do this week

  1. Inventory. List the AI tools the company uses, their vendor and what they are used for. A spreadsheet is enough.
  2. Sweep for point (f). Send the four questions above to HR, video surveillance, access control, contact centre and training vendors.
  3. Flag high-risk systems. Everything touching selection, promotion, task assignment or performance assessment goes to Annex III. Note the date: 2 December 2027.
  4. If you generate visual content with AI, review safeguards and consent before 2 December 2026, following the practical calendar above.

Frequently asked questions

Do the two new prohibitions affect my company if we only use generative AI to draft text?

No, if the system does not generate or manipulate images, videos or audio of the intimate parts of identifiable persons. Point (b bis) is limited to that material. Furthermore, the new paragraph 1a, point (b), clarifies that use is only prohibited where the deployer uses the system with the aim of generating that material.

Does a system detecting whether a driver is tired breach point (f)?

Recital 18 of Regulation (EU) 2024/1689 expressly excludes physical states such as pain or fatigue from the concept of "emotion recognition system", giving pilot or professional driver fatigue detection as the example. There will still be data protection obligations and, depending on the case, high-risk obligations.

Can I use sentiment analysis on my customers' comments?

Point (f) prohibits inferring emotions "in the areas of workplace and education institutions". Analysis of public customer reviews does not fit there. Different is if the same tool also scores the emotional tone of your agents: that does happen in the workplace.

If the provider is American, am I exempt?

No. The Regulation applies by the place where the system is used and by who deploys it, not by where the manufacturer is headquartered. If your company is in Spain and uses it with its staff, you are a deployer.

Is disabling the feature in settings enough?

It may be enough, but you must be able to prove it: written confirmation from the vendor, timestamped configuration screenshot, and a contractual clause preventing it from being re-activated in an update. Without stored evidence, you have nothing to show.

Are there official guidelines for interpreting Article 5?

Yes. The European Commission published on 4 February 2025 guidelines on the prohibited AI practices of Regulation (EU) 2024/1689. They are not binding, but they indicate the Commission's interpretation of each case. They were written before the Omnibus and do not cover points (b bis) or (b ter).

Can a production company generate intimate scenes of a performer who has given consent?

Point (b bis) only prohibits generation or manipulation "without the free, specific, informed and unambiguous explicit consent" of the identifiable person. With consent that meets those five adjectives and refers to that specific generation — not a generic image rights assignment — the prohibition is not triggered. Document it in writing.

What happens with "nudification" apps?

Recital 11 of the Omnibus names them expressly as the trigger for the reform. As systems whose intended purpose is to generate non-consensual intimate material, they fit the first circumstance of paragraph 1a: direct prohibition from 2 December 2026, with no room to argue about safeguards.

Does a photo editor with AI that retouches images fall within the prohibition?

Paragraph 1b excludes it: there is no "manipulation" if the system modifies the material without increasing the exposure of any intimate part depicted or altering the nature of any sexually explicit activity depicted. Correcting light, colour or framing does not make an editor a prohibited system. A function that undresses the person in the photo does.

Do the new points count for the €35 million or 7% fine?

Yes. Article 99(3) penalises non-compliance with "the AI practices referred to in Article 5" without distinguishing points: by being inserted into that article, (b bis) and (b ter) inherit the maximum tier. In Spain, the allocation of authorities and national amounts remain under parliamentary consideration.

Sources