The eight practices, one by one
Lesson 2 of 4 in Prohibited AI Practices: The Unacceptable Tier.
Work through all eight. For each, hold the same three questions in mind: what exactly is banned (the elements), what escapes the ban (the exceptions and carve-outs), and what real system the drafters were aiming at. The prohibitions are not abstractions — nearly every one has a named scandal behind it.
5(1)(a) — Subliminal, manipulative, or deceptive techniques
Banned: AI deploying subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting behaviour by appreciably impairing informed decision-making, causing the person to take a decision they would not otherwise have taken, in a way that causes or is reasonably likely to cause significant harm.
The element chain matters: technique → material distortion → significant harm. All three, or no prohibition. The Commission guidelines draw the working line between lawful persuasion (appeals to preferences, transparent advertising) and prohibited manipulation (exploiting cognitive vulnerabilities covertly).
Aimed at: dark-pattern engines at scale, AI companions steering users toward self-harm, voice interfaces exploiting subconscious cues. A/B-tested ad copy survives; an engagement system that learns a user’s emotional breaking points and exploits them to extract spending does not.
5(1)(b) — Exploiting vulnerabilities
Banned: AI exploiting vulnerabilities of a person or group due to their age, disability, or a specific social or economic situation, with the objective or effect of materially distorting behaviour in a way that causes or is reasonably likely to cause significant harm.
Where 5(1)(a) protects everyone from covert techniques, 5(1)(b) protects specific groups from targeted exploitation — and the techniques need not be subliminal. Note the third category: specific social or economic situation covers people in poverty, over-indebtedness, or crisis, not only children and disabled persons.
Aimed at: toys nudging children toward dangerous behaviour, predatory-lending funnels targeting people flagged as financially desperate, scam systems tuned to cognitive decline in elderly users.
5(1)(c) — Social scoring
Banned: AI evaluating or classifying people over a certain period of time based on social behaviour or known/inferred/predicted personal characteristics, where the score leads to detrimental treatment that is either (i) in social contexts unrelated to where the data was generated, or (ii) unjustified or disproportionate to the behaviour.
Two details defeat common misreadings. The ban covers public AND private actors — "social scoring is only banned for governments" is wrong. And it does not ban all scoring: credit scores built on financial behaviour, applied to credit decisions, stay in the high-risk tier. What is banned is the context jump (your social-media conduct lowering your housing eligibility) and the disproportionate consequence.
Aimed at: the generalised citizen-scoring model made famous by pilot programmes in China — and, closer to home, the Dutch toeslagenaffaire pattern of opaque risk scores producing devastating, disproportionate treatment.
5(1)(d) — Predictive policing by profile alone
Banned: AI making risk assessments of natural persons to assess or predict the risk of them committing a criminal offence, based solely on profiling or on assessing personality traits and characteristics.
The load-bearing word is solely. The carve-out preserves AI that supports human assessment already grounded in objective, verifiable facts directly linked to a criminal activity — analysing evidence in an actual investigation is fine; flagging someone as a future criminal because of their profile is not.
Aimed at: Minority Report-style person-based prediction — systems like the Dutch SyRI welfare-fraud profiler struck down in court in 2020. Note the boundary: place-based crime-pattern forecasting is not caught by this ban (though it may be high-risk under Annex III point 6).
5(1)(e) — Untargeted scraping for facial-recognition databases
Banned: creating or expanding facial-recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
This is the Clearview prohibition, written for a named business model: Clearview AI scraped billions of face images from social media and the open web to sell face-search to police, collecting GDPR fines across Europe (Italy, Greece, France — €20M each) while operating from outside the Union. Art 5(1)(e) bans the practice — building or growing the database — so the extraterritorial hooks from the previous module do real work here.
The boundary: untargeted is the operative word. Targeted collection with a lawful basis (enrolling consenting employees in an access-control system) is untouched by this ban.
5(1)(f) — Emotion recognition at work and school
Banned: AI to infer emotions of a natural person in the areas of workplace and educational institutions — except where intended for medical or safety reasons.
The ban is place-based, and that design is deliberate: the power asymmetry of employment and education makes "consent" to emotional surveillance illusory. A call-centre dashboard scoring agents’ enthusiasm, a proctoring tool flagging "suspicious anxiety" — banned. A driver-fatigue monitor in a truck cab, or a clinical tool monitoring a patient — the safety/medical exception applies.
The interplay to remember: emotion recognition outside work and school is not prohibited — it is high-risk (Annex III point 1) and carries an Art 50(3) duty to inform exposed persons. Same technology, three regimes, depending on where it points.
5(1)(g) — Biometric categorisation of sensitive attributes
Banned: biometric categorisation systems that categorise individuals based on their biometric data to deduce or infer race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation.
The list deliberately mirrors the GDPR’s special categories: attributes history has weaponised. A system claiming to infer sexuality from face geometry — a genre of research that keeps resurfacing — is banned outright.
The carve-out: labelling or filtering of lawfully acquired biometric datasets, including for law-enforcement purposes (e.g. organising a lawful evidence database by objective properties) — a narrow data-management exception, not a licence to profile people.
5(1)(h) — Real-time remote biometric identification for law enforcement
Banned (as a rule): the use of real-time remote biometric identification (RBI) systems in publicly accessible spaces for law-enforcement purposes — live facial recognition scanning crowds against watchlists.
Unlike the other seven, this ban carries three exhaustive exceptions: (1) targeted search for victims of abduction, trafficking, or sexual exploitation, and for missing persons; (2) prevention of a specific, substantial and imminent threat to life or physical safety, or a genuine and present or genuine and foreseeable threat of a terrorist attack; (3) localisation or identification of a suspect of one of a list of serious offences punishable by at least four years’ detention.
Even inside an exception, use is lawful only through the procedural machinery of Arts 5(2)–5(7) — prior authorization, a Member State opt-in law, impact assessment, registration, and reporting. That machinery is the next lesson, because it is where exam questions and real deployments both live.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.