This page helps screen an AI system against the original eight Article 5 categories and the new prohibited-content category before launch, procurement, integration, or material product change.
The focus is practical evidence: what the system does, who it affects, which Article 5 limb is relevant, and whether any narrow exception or condition is actually documented.
The original prohibitions have applied since 2 February 2025. Regulation (EU) 2026/1744 enters into force on 27 July 2026 and adds a prohibited-content category that applies from 2 December 2026. These rules ban specified practices rather than treating them as high-risk systems that may proceed with controls. Before launch, procurement, integration, or material change, identify the system and intended use, test every relevant Article 5 limb, document each element of any narrow exception, and preserve the product, data, legal, and approval evidence behind the decision.
1
Section 1
Article 5 categories to screen first
The review should start with the original eight prohibited-practice categories and the new category added by Regulation (EU) 2026/1744. Do not collapse them into a generic high-risk assessment: several categories turn on specific facts such as deception, vulnerability, biometric data, criminal-risk prediction, law-enforcement use in a publicly accessible space, provider safeguards, or a deployer's purpose in generating content.
For each category, record whether the system is placed on the EU market, put into service, or used in the Union, what function is enabled, what data is used, and which people or groups can be affected. Record the application date too: the original categories have applied since 2 February 2025, while the new prohibited-content category applies from 2 December 2026.
Manipulation or deception: AI systems using subliminal techniques or purposefully manipulative or deceptive techniques that materially distort behaviour and cause, or are reasonably likely to cause, significant harm.
Exploitation of vulnerabilities: AI systems exploiting age, disability, or a specific social or economic situation to materially distort behaviour in a way that causes, or is reasonably likely to cause, significant harm.
Social scoring: AI systems evaluating or classifying people or groups over time based on social behaviour or known, inferred, or predicted personal or personality characteristics where the score leads to unrelated, unjustified, or disproportionate detrimental treatment.
Criminal-offence risk assessment: AI systems assessing or predicting an individual's risk of committing a criminal offence based solely on profiling or personality traits and characteristics.
Untargeted facial-image scraping: AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
Emotion inference in workplace or education settings, subject to the medical or safety exception stated in .
Biometric categorisation systems that categorise individuals based on biometric data to deduce or infer protected characteristics listed in .
Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, except within the narrow objectives and conditions stated in .
Prohibited content from 2 December 2026: provider-side placement or putting into service of systems intended to generate or manipulate specified non-consensual intimate material or child sexual abuse material, or systems where that output is reasonably foreseeable and reproducible without reasonable and adequate safeguards; and deployer use of an AI system for that purpose.
Exceptions and conditions that need explicit evidence
Some entries include carve-outs or conditions. Treat those as evidence requirements, not as informal risk arguments. The screening record should quote the relevant Article 5 limb, identify the specific exception being relied on, and show why the facts fit that exception.
The strictest evidence burden is for real-time remote biometric identification in publicly accessible spaces for law enforcement. allows it only when strictly necessary for specified objectives and subject to safeguards, national-law conditions, fundamental-rights impact assessment, EU database registration, authorisation, notification, and reporting steps described in the Article.
The new content prohibition uses different tests for providers and deployers. A provider must assess intended capability, reasonably foreseeable and reproducible outcomes, foreseeable misuse and circumvention, and whether reasonable state-of-the-art safeguards demonstrably prevent or sufficiently reduce the output. A deployer is prohibited when it uses the system for the prohibited purpose; accidental output or lawful use for other material is not the same test. Non-consensual intimate material is limited to realistic intimate or sexually explicit depictions of an identifiable person without the required consent, subject to the provision's stated scope and medical exception.
Criminal-risk support exception: if the system supports a human assessment, keep the objective and verifiable facts directly linked to criminal activity; do not rely on profiling-only or personality-trait-only evidence.
Emotion inference exception: if workplace or education emotion inference is claimed for medical or safety reasons, keep the medical or safety purpose, deployment boundary, and approval evidence.
Biometric dataset handling: where labelling or filtering of lawfully acquired biometric datasets is relied on, keep the lawful acquisition basis, dataset purpose, and why the use is not deducing protected characteristics for individual categorisation.
Law-enforcement remote biometric identification: document the specific objective, targeted individual, necessity and proportionality assessment, time, place, personal scope, prior authorisation or urgency basis, notification, and deletion outcome if authorisation is rejected.
Prohibited-content safeguards: document training-data cleaning, refusal training, prompt and output controls, filters, usage restrictions, abuse detection, notice-and-action routes, consent capture where relevant, circumvention monitoring, and corrective action. A generic acceptable-use policy alone does not prove the provider test.
Evidence to keep for a prohibited-practice screening record
The most useful record is short but factual. It should let a reviewer reconstruct the system purpose, user journey, data sources, affected persons, and exception analysis without interviewing the product team again.
Keep separate evidence for negative conclusions. A statement that does not apply is weak unless it explains, for example, why a scoring feature is not social scoring, why biometric processing is not covered by the prohibited biometric categories, or why behavioural nudging does not meet the manipulation or vulnerability tests.
System description: intended purpose, provider or deployer role, EU market or use connection, affected users, affected groups, and release or procurement context.
matrix: one row per prohibited category, with facts, conclusion, reviewer, source citation, and unresolved questions.
Data proof: source of facial images, biometric data, behavioural data, profiling inputs, vulnerability indicators, workplace or education context, and law-enforcement context where relevant.
Impact proof: evidence considered for significant harm, detrimental treatment, unrelated context, unjustified or disproportionate outcome, or impairment of informed decision-making.
Exception proof: medical or safety rationale, human-assessment facts, lawfully acquired dataset basis, targeted search basis, authorisation request, notification, and urgency record where relevant.
Change trigger: require re-screening when data sources, target population, user interface, scoring logic, law-enforcement use, biometric function, or supplier terms materially change.
Article 5 screening questions for product, procurement, and model review
Use these questions before approving a feature, buying a vendor system, changing a data source, or enabling a biometric or profiling capability. A yes, unclear, or vendor-only answer should stop approval until the record is completed.
The review should be repeated when the same AI model is embedded in a new workflow. can turn on deployment context, especially workplace, education, law enforcement, public accessibility, vulnerable groups, and the consequences of a score or prediction.
Does the system intentionally influence decisions through subliminal, manipulative, or deceptive techniques, and could that cause significant harm?
Does the system target or rely on age, disability, or social or economic vulnerability to materially distort behaviour?
Does the system rank, score, classify, or otherwise evaluate people over time in a way that can lead to unrelated, unjustified, or disproportionate detrimental treatment?
Does any criminal-risk prediction rely solely on profiling or personality traits rather than objective and verifiable facts directly linked to criminal activity?
Does the system create or expand a facial recognition database from untargeted internet or CCTV scraping?
Does the system infer emotions in workplace or education settings, and if so, is the stated purpose medical or safety-related?
Does biometric categorisation deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation?
Is law enforcement using real-time remote biometric identification in a publicly accessible space, and if so, is every condition documented before use or under a recorded urgency route?
From 2 December 2026, is the provider placing or putting into service a system intended or foreseeably able to produce the prohibited intimate or child sexual abuse material without adequate safeguards, or is a deployer using a system for that purpose?
A prohibited-practices check is an approval gate. The output should be a dated screening record with category-by-category conclusions, not a general AI-risk memo.
If a category is potentially triggered, pause release or procurement until the legal, product, data, and operational owners have either removed the relevant function, narrowed the use case, or documented why the exception and conditions are satisfied.
Does the EU AI Act ban every biometric AI system under ?
No. prohibits specific biometric uses, including certain biometric categorisation to deduce protected characteristics and real-time remote biometric identification in publicly accessible spaces for law enforcement unless strict Article 5 conditions are met. Other biometric systems may still need separate AI Act analysis, but they are not automatically Article 5 prohibited practices.
What should an EU AI Act screening record prove?
It should prove which AI system and use case were reviewed, how the original eight categories and the new prohibited-content category were assessed, what data and user-impact evidence supported each conclusion, which application date controls, and whether any stated exception or condition was relied on.
Name the AI system, supplier, workflow, affected people, EU connection, and current approval request.
Complete the matrix for the original eight categories and the new prohibited-content category, including a clear no, yes, not-yet-applicable, or unresolved conclusion for each.
Attach product screenshots, user journey notes, model cards or supplier documentation, data-source evidence, and testing records that support the conclusion.
For any exception, attach the exact condition, the factual evidence, the approving owner, and the operational control that keeps use inside the exception.
Create a release block for unresolved issues and a re-screening trigger for material changes in purpose, data, users, geography, biometric function, scoring logic, or law-enforcement use.
Turn Article 5 prohibited-practice checks into evidence
Sorena can help turn this Article 5 screening guide into a structured review record with category conclusions, source citations, owners, and release-blocking evidence gaps.
Supports the separate provider and deployer tests, safeguard examples, consent and medical conditions, and exclusions from the new prohibited-content category.