Anatomy of a ban
Lesson 1 of 4 in Prohibited AI Practices: The Unacceptable Tier.
Article 5 is the shortest substantive chapter in the AI Act and the sharpest. It lists eight practices the EU decided no safeguard can redeem — uses of AI judged incompatible with fundamental rights per se. There is no conformity assessment to pass, no oversight design to argue, no documentation to file. If your system falls inside one of the eight, the only compliant action is not to do it.
Three structural facts frame everything in this module. First, timing: the prohibitions were the first substantive obligations to apply — live since 2 February 2025, eighteen months before the Act’s general application date. The EU banned the worst before regulating the rest. Second, who is bound: the prohibitions address the practice — placing on the market, putting into service, or use — so providers and deployers are equally caught, public and private alike. Third, the price: Art 5 violations sit alone in the top penalty tier — €35 million or 7% of total worldwide annual turnover, whichever is higher (Art 99(3)).
| Regime | Top fine | What earns it |
|---|---|---|
EU AI Act — Art 5 | €35M or 7% of worldwide turnover | Any prohibited practice |
EU AI Act — most other breaches | €15M or 3% | Operator and notified-body obligations (Art 99(4)) |
EU AI Act — misleading information | €7.5M or 1% | Supplying incorrect/misleading info to authorities |
GDPR | €20M or 4% | The benchmark every privacy team knows |
DMA | 10% (20% repeat) | Gatekeeper obligations — the only common regime above the AI Act |
Read the table as the legislator’s value judgment: the EU priced a prohibited AI practice at nearly double a GDPR worst case. For an SME, a lower-of rule softens the arithmetic; for a multinational, 7% of group-wide worldwide turnover is a board-level number. This is why "could this possibly be Art 5?" is the first question in any EU AI review — everything else in the Act is a compliance project; Art 5 is an existential one.
One more feature to internalise: most of the eight bans are element tests, not keyword matches. Take 5(1)(a): it prohibits systems deploying subliminal, purposefully manipulative or deceptive techniques that materially distort behaviour and cause (or are reasonably likely to cause) significant harm. Every element must be satisfied. An ad that nudges is not banned; a dark-pattern engine that demonstrably distorts decisions without significant harm is not banned by 5(1)(a) either — though other law may catch it. Lawyers win and lose these cases element by element, and so will you in the drills ahead.
Key terms: prohibited AI practices, subliminal techniques, social scoring, significant harm, penalty tiers
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.