Prohibited AI Practices

Prohibited AI Practices

Some AI systems cannot be fixed. They are banned outright.

What Is Prohibited AI Practices?

The EU AI Act draws clear red lines. Article 5 bans eight categories of AI practices outright, with the highest penalties in the regulation: up to 35 million euros or 7% of global turnover. In this exercise, you recognize prohibited deployments across your organization: including emotion recognition in the workplace, social scoring of customers, and untargeted scraping of facial images for biometric databases: and take the right action before each system goes live.

What You'll Learn in Prohibited AI Practices

Prohibited AI Practices — Training Steps

  1. The Absolute Red Lines

    Article 5 of the EU AI Act defines certain AI practices that are outright banned in the EU. No workarounds. Penalties for prohibited practices are the highest tier under the Act: up to 35 million euros or 7% of global annual turnover, whichever is higher. The eight categories of prohibited AI under Article 5(1) are: (a) Manipulative or deceptive AI techniques that distort behavior (b) AI exploiting vulnerabilities of specific groups (age, disability, social or economic situation) (c) Social scoring - evaluating people on social behavior or personal traits, leading to detrimental treatment in unrelated contexts or out of proportion (d) Predicting that a person will commit a crime based solely on profiling or personality traits (e) Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases (f) Emotion recognition in workplace and educational settings (except for medical or safety reasons) (g) Biometric categorization to infer sensitive attributes (race, political opinions, sexual orientation) (h) Real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions)

  2. Day 1: The Mood Tracker Email

    Alice receives an email from the HR Director announcing a new pilot program. The email describes an AI tool that will monitor employees during video meetings.

  3. Recognizing the Violation

    This is emotion recognition in the workplace , which is explicitly prohibited under Article 5(1)(f) of the EU AI Act. It does not matter that it is framed as a 'wellness initiative' or that participation is described as voluntary. Any AI system that infers emotions from biometric data (facial expressions, voice tone, body language) in the workplace is banned unless it is used for medical or safety reasons - and wellness and morale do not qualify. The level of anonymization and whether employees consent make no difference.

  4. Escalating to Compliance

    Alice recognizes the compliance risk immediately. She replies to David's email, flagging the issue and copying the Data Protection Officer.

  5. Knowledge Check

  6. Day 3: The Social Scorer

    Two days later, Alice receives a WhatsApp message from a colleague about a concerning new CRM feature the sales team has activated.

  7. Spotting Social Scoring

    Alice reads Jamie's message carefully. Two details stand out: customers are being scored on social media activity, and low-scoring customers are being routed to slower support queues.

  8. Understanding Social Scoring

    This is social scoring , prohibited under Article 5(1)(c). Using AI to evaluate people based on their social behavior or personal characteristics - and then using those scores to treat them detrimentally - is banned. Returns and support tickets on their own are ordinary business data. What crosses the line is scoring customers on their social media activity, behaviour from an unrelated context, and using that score to push them into slower support: detrimental treatment that is unjustified and out of proportion. The prohibition applies regardless of whether the scoring happens to existing customers or prospective ones.

  9. Day 5: The Facial Scraper

    Two days later, Alice discovers that the marketing team has built an internal tool demo. She opens it in her browser to review what they have been working on.

  10. Untargeted Facial Scraping

    The FaceWatch tool scrapes publicly available photos from social media profiles to build a facial recognition database. Under Article 5(1)(e), untargeted scraping of facial images from the internet or CCTV footage to build or expand facial recognition databases is explicitly prohibited.

Security Framework Coverage

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

EU AI Act

  • Art. 5 Prohibited AI practices