Tech & produit

Prohibited AI practices under Article 5 of the AI Act

Article 5 of the AI Act bans a short list of AI practices considered to carry an unacceptable risk. This page summarises those bans and the exceptions explained in the Commission guidelines of July 2025.

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

The eight practices listed in Article 5(1)

Article 5(1) prohibits AI systems that use subliminal, manipulative or deceptive techniques causing or likely to cause significant harm, and systems that exploit vulnerabilities due to age, disability or a specific social or economic situation.

It also bans social scoring leading to detrimental or unfavourable treatment, predicting the risk that a person will commit a crime based solely on profiling or personality traits, creating facial recognition databases through untargeted scraping of images from the internet or CCTV footage, and inferring emotions in the workplace or in education institutions.

Finally, it bans biometric categorisation to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, and real-time remote biometric identification in publicly accessible spaces for law enforcement.

The Service Desk FAQ adds that new prohibitions relating to the generation or manipulation of non-consensual intimate material and child sexual abuse material will apply from 2 December 2026.

Exceptions that narrow the bans

Several bans carry exceptions. Emotion recognition at work or in schools is allowed for medical or safety reasons. Crime risk assessment is allowed to support a human assessment based on objective and verifiable facts directly linked to a criminal activity. Biometric categorisation does not cover labelling or filtering of lawfully acquired biometric datasets.

Real-time remote biometric identification for law enforcement is permitted only where necessary for the targeted search of specific victims, the prevention of specific threats including terrorist attacks, or the search of suspects of specific offences, subject to authorisation and procedural requirements in Article 5(2) to (7).

The guidelines stress that emotion recognition at work exempted for medical or safety reasons still remains subject to data protection law and to Union and national law on employment and working conditions.

Questions fréquentes

Since when are these practices banned?

Chapter II, which contains Article 5, applies from 2 February 2025. The Service Desk FAQ notes that enforcement powers over the prohibitions start to apply on 2 August 2026.

Can a general-purpose chatbot that detects emotions be used with employees?

The Commission guidelines give this example directly: a general-purpose AI system able to infer emotions should not be used by deployers in the workplace or in education institutions, unless the medical or safety exception applies.

What is the maximum fine for a prohibited practice?

Up to EUR 35 000 000 or 7 % of total worldwide annual turnover for the preceding financial year, whichever is higher. This is the highest penalty tier in the AI Act.

Does the real-time biometric identification ban cover selling the system?

No. According to the guidelines, the prohibition in Article 5(1)(h) only applies to the use of real-time remote biometric identification systems, not to placing them on the market.

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=eu-ai-act-essentials
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-eu-ai-act-essentials "https://kopik.io/api/mcp?base=eu-ai-act-essentials" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-eu-ai-act-essentials": {
      "url": "https://kopik.io/api/mcp?base=eu-ai-act-essentials",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-ai-act-essentials/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.