Prohibited AI Practices
Some AI systems cannot be fixed. They are banned outright.
What Is Prohibited AI Practices?
The EU AI Act draws clear red lines. Article 5 bans eight categories of AI practices outright, with the highest penalties in the regulation: up to 35 million euros or 7% of global turnover. In this exercise, you recognize prohibited deployments across your organization: including emotion recognition in the workplace, social scoring of customers, and untargeted scraping of facial images for biometric databases: and take the right action before each system goes live.
What You'll Learn in Prohibited AI Practices
- Identify the eight categories of AI practices prohibited under Article 5 of the EU AI Act
- Recognize prohibited practices even when disguised as beneficial tools or voluntary programs
- Understand that employee consent does not override Article 5 prohibitions
- Know the correct escalation path when discovering a prohibited AI deployment
- Understand the penalty tier for prohibited practices (35M euros / 7% turnover)
Prohibited AI Practices — Training Steps
-
The Absolute Red Lines
Article 5 of the EU AI Act defines certain AI practices that are outright banned in the EU. No workarounds. Penalties for prohibited practices are the highest tier under the Act: up to 35 million euros or 7% of global annual turnover, whichever is higher. The eight categories of prohibited AI under Article 5(1) are: (a) Manipulative or deceptive AI techniques that distort behavior (b) AI exploiting vulnerabilities of specific groups (age, disability, social or economic situation) (c) Social scoring - evaluating people on social behavior or personal traits, leading to detrimental treatment in unrelated contexts or out of proportion (d) Predicting that a person will commit a crime based solely on profiling or personality traits (e) Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases (f) Emotion recognition in workplace and educational settings (except for medical or safety reasons) (g) Biometric categorization to infer sensitive attributes (race, political opinions, sexual orientation) (h) Real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions)
-
Day 1: The Mood Tracker Email
Alice receives an email from the HR Director announcing a new pilot program. The email describes an AI tool that will monitor employees during video meetings.
-
Recognizing the Violation
This is emotion recognition in the workplace , which is explicitly prohibited under Article 5(1)(f) of the EU AI Act. It does not matter that it is framed as a 'wellness initiative' or that participation is described as voluntary. Any AI system that infers emotions from biometric data (facial expressions, voice tone, body language) in the workplace is banned unless it is used for medical or safety reasons - and wellness and morale do not qualify. The level of anonymization and whether employees consent make no difference.
-
Escalating to Compliance
Alice recognizes the compliance risk immediately. She replies to David's email, flagging the issue and copying the Data Protection Officer.
-
Knowledge Check
-
Day 3: The Social Scorer
Two days later, Alice receives a WhatsApp message from a colleague about a concerning new CRM feature the sales team has activated.
-
Spotting Social Scoring
Alice reads Jamie's message carefully. Two details stand out: customers are being scored on social media activity, and low-scoring customers are being routed to slower support queues.
-
Understanding Social Scoring
This is social scoring , prohibited under Article 5(1)(c). Using AI to evaluate people based on their social behavior or personal characteristics - and then using those scores to treat them detrimentally - is banned. Returns and support tickets on their own are ordinary business data. What crosses the line is scoring customers on their social media activity, behaviour from an unrelated context, and using that score to push them into slower support: detrimental treatment that is unjustified and out of proportion. The prohibition applies regardless of whether the scoring happens to existing customers or prospective ones.
-
Day 5: The Facial Scraper
Two days later, Alice discovers that the marketing team has built an internal tool demo. She opens it in her browser to review what they have been working on.
-
Untargeted Facial Scraping
The FaceWatch tool scrapes publicly available photos from social media profiles to build a facial recognition database. Under Article 5(1)(e), untargeted scraping of facial images from the internet or CCTV footage to build or expand facial recognition databases is explicitly prohibited.
Security Framework Coverage
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
EU AI Act
- Art. 5 Prohibited AI practices