Verbotene KI-Praktiken

Verbotene KI-Praktiken

Einige KI-Systeme können nicht repariert werden. Sie sind komplett verboten.

Was ist Verbotene KI-Praktiken?

The EU AI Act draws clear red lines. Article 5 bans eight categories of AI practices outright, with the highest penalties in the regulation: up to 35 million euros or 7% of global turnover. In this exercise, you recognize prohibited deployments across your organization: including emotion recognition in the workplace, social scoring of customers, and untargeted scraping of facial images for biometric databases: and take the right action before each system goes live.

Was Sie lernen in Verbotene KI-Praktiken

Verbotene KI-Praktiken — Trainingsschritte

  1. Die absoluten roten Linien

    Article 5 of the EU AI Act defines certain AI practices that are outright banned in the EU. No workarounds. Penalties for prohibited practices are the highest tier under the Act: up to 35 million euros or 7% of global annual turnover, whichever is higher. The eight categories of prohibited AI under Article 5(1) are: (a) Manipulative or deceptive AI techniques that distort behavior (b) AI exploiting vulnerabilities of specific groups (age, disability, social or economic situation) (c) Social scoring - evaluating people on social behavior or personal traits, leading to detrimental treatment in unrelated contexts or out of proportion (d) Predicting that a person will commit a crime based solely on profiling or personality traits (e) Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases (f) Emotion recognition in workplace and educational settings (except for medical or safety reasons) (g) Biometric categorization to infer sensitive attributes (race, political opinions, sexual orientation) (h) Real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions)

  2. Tag 1: Die Mood-Tracker-E-Mail

    Alice erhält eine E-Mail vom Personalleiter, der ein neues Pilotprogramm ankündigt. Die E-Mail beschreibt ein KI-Tool, das Mitarbeitende während Video-Meetings beobachtet.

  3. Den Verstoß erkennen

    This is emotion recognition in the workplace , which is explicitly prohibited under Article 5(1)(f) of the EU AI Act. It does not matter that it is framed as a 'wellness initiative' or that participation is described as voluntary. Any AI system that infers emotions from biometric data (facial expressions, voice tone, body language) in the workplace is banned unless it is used for medical or safety reasons - and wellness and morale do not qualify. The level of anonymization and whether employees consent make no difference.

  4. An Compliance eskalieren

    Alice erkennt das Compliance-Risiko sofort. Sie antwortet auf Davids E-Mail, markiert das Problem und setzt die Datenschutzbeauftragte in Kopie.

  5. Wissenscheck

  6. Tag 3: Der Social Scorer

    Zwei Tage später erhält Alice eine WhatsApp-Nachricht von einer Kollegin über eine besorgniserregende neue CRM-Funktion, die das Vertriebsteam aktiviert hat.

  7. Sozialbewertung erkennen

    Alice liest Jamies Nachricht sorgfältig. Zwei Details stechen hervor: Kundinnen und Kunden werden anhand ihrer Social-Media-Aktivitäten bewertet, und solche mit niedrigem Score werden in langsamere Support-Warteschlangen geleitet.

  8. Sozialbewertung verstehen

    This is social scoring , prohibited under Article 5(1)(c). Using AI to evaluate people based on their social behavior or personal characteristics - and then using those scores to treat them detrimentally - is banned. Returns and support tickets on their own are ordinary business data. What crosses the line is scoring customers on their social media activity, behaviour from an unrelated context, and using that score to push them into slower support: detrimental treatment that is unjustified and out of proportion. The prohibition applies regardless of whether the scoring happens to existing customers or prospective ones.

  9. Tag 5: Der Gesichts-Scraper

    Zwei Tage später entdeckt Alice, dass das Marketing-Team eine interne Tool-Demo gebaut hat. Sie öffnet sie im Browser, um zu sehen, woran sie gearbeitet haben.

  10. Ungezieltes Sammeln von Gesichtsbildern

    Das Tool FaceWatch scrapt öffentlich verfügbare Fotos aus Social-Media-Profilen, um eine Gesichtserkennungs-Datenbank aufzubauen. Nach Artikel 5 Absatz 1 lit. e ist das ungezielte Sammeln von Gesichtsbildern aus dem Internet oder CCTV-Aufnahmen zum Aufbau oder Erweitern von Gesichtserkennungs-Datenbanken ausdrücklich verboten.

Abdeckung der Sicherheits-Frameworks

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

EU AI Act

  • Art. 5 Prohibited AI practices