Since 2 February 2025, eight uses of artificial intelligence have been outright banned across the European Union. Article 5 of Regulation EU 2024/1689 classifies them as unacceptable risk: there is no compliance path, only stopping the use. Here is the exact list and what it means in practice for a small business or a nonprofit.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Since 2 February 2025, eight uses of artificial intelligence have been outright banned across the European Union. Article 5 of Regulation EU 2024/1689 classifies them as unacceptable risk: there is no compliance path, only stopping the use. Here is the exact list and what it means in practice for a small business or a nonprofit.
A prohibited practice is a use of AI deemed contrary to fundamental rights, regardless of sector or organisation size. The AI Act sorts AI systems on a four-tier risk scale: minimal, limited, high, and unacceptable. The practices listed in Article 5 sit at the top tier, unacceptable risk. They are not regulated or subject to authorisation: they are banned, full stop.
The contrast with high-risk systems is sharp. A high-risk system (hiring, credit scoring, medical devices) stays legal provided it meets documentation, human-oversight and risk-management obligations. An Article 5 practice has no regulatory way out. To place your organisation within these tiers, our AI Act compliance guide for SMEs and nonprofits lays out the full pyramid, and the article AI Act: who is affected clarifies whether you are a provider or a deployer.
Article 5 bans eight families of uses, from the most manipulative to the most intrusive. Here is what the text says, translated into operational language.
| Practice | What is banned | Concrete example |
|---|---|---|
| 1. Subliminal manipulation | Techniques beyond awareness that distort behaviour and cause harm | An interface covertly pushing a purchase against the person's interest |
| 2. Exploiting vulnerabilities | Targeting age, disability, or social or economic status to manipulate | A chatbot preying on a user's financial distress |
| 3. Social scoring | Rating or ranking people on social behaviour, with disproportionate unfavourable treatment | A citizen score gating access to a service |
| 4. Individual predictive policing | Predicting the risk that a person will commit an offence based solely on profiling | A tool labelling someone a future offender with no factual basis |
| 5. Untargeted facial scraping | Building facial recognition databases by scraping web images or CCTV | Software scraping millions of faces online |
| 6. Emotion recognition at work | Inferring the emotions of employees or students, except for medical or safety reasons | A camera measuring emotional engagement in meetings |
| 7. Sensitive biometric categorisation | Inferring ethnicity, political views, religion or sexual orientation via biometrics | A system sorting faces by presumed group membership |
| 8. Real-time remote biometric identification | Live facial recognition in public spaces for law enforcement, outside strict exceptions | Blanket facial surveillance of a public square |
Two nuances matter for a small business. First, the ban targets the use, not the raw technology: a camera is not illegal, analysing employees' emotions is. Second, several of these practices in fact apply only to public authorities (real-time remote biometric identification for law enforcement, for instance). The cases that most affect the private sector are manipulation, exploiting vulnerabilities, and emotion recognition at work.
Article 5 has applied since 2 February 2025, ahead of most other AI Act obligations. The regulation phased in its rules: the bans first, then general-purpose AI model rules (August 2025), then the bulk of high-risk obligations. That timeline, reshaped in late 2026 by the so-called Digital Omnibus package, is detailed in our full AI Act timeline.
In other words, if you use an Article 5 system today, you are already outside the law. There is no transition period on this specific point.
A prohibited practice exposes you to a fine of up to 35 million euros or 7% of total worldwide annual turnover, whichever is higher. That is the highest ceiling in the whole regulation, set in Article 99. For comparison, breaches of high-risk obligations cap at 15 million euros or 3% of turnover.
For a small business the percentage rarely works against you, but the fixed 35 million figure remains theoretically applicable. Beyond the fine, the real exposure is reputational and contractual: an enterprise client who spots a banned use in your chain can terminate on the spot.
Yes, as soon as it deploys an AI system falling under one of the eight cases, even bought off the shelf. The AI Act does not distinguish by size. A deployer (the one using the system) bears its share of responsibility, just like the provider. Many leaders assume Article 5 is reserved for tech giants or governments. In practice, emotion-recognition tools sold as workplace wellbeing solutions, or certain aggressive behavioural-targeting features, can slip into banned territory without the buyer realising.
The real issue is not whether you built an AI, but whether you know what the tools you already use actually do.
Inventory your AI systems, then test each use against the list of eight practices. A simple three-step method:
This critical reading assumes your teams can recognise a risky use. That is exactly the point of the AI literacy obligation in the regulation, which we cover in Article 4 of the AI Act on training. A trained team spots a banned use before it becomes a problem.
Is a standard chatbot a prohibited practice? No, as long as it does not use manipulative techniques beyond the user's awareness or exploit a vulnerability. A transparent conversational agent is limited-risk, with a simple duty to inform.
Is emotion recognition always banned? No. It is banned in the workplace and in education, except for medical or safety reasons. In other contexts it may be allowed but subject to transparency obligations.
Who enforces Article 5 in France? The national supervision framework is being set up, with a central role expected for the designated competent authorities. The European Commission guidelines, published on 4 February 2025, serve as the interpretation reference.
What if one of my tools is concerned? There is no compliance path for an Article 5 practice: the use must stop. The priority is to halt it, document the decision, and discuss an alternative with the vendor.
Does the ban apply to the US tools I use? Yes, if the system is used in the European Union, whatever the provider's origin. The user's location matters, not the vendor's.
Are nonprofits subject to the same rules? Yes. The AI Act provides no exemption based on nonprofit status. A social-economy organisation deploying a concerned system has the same obligations as a company.
At GrowthPerf, we help small businesses and nonprofits in the Paris region inventory their AI uses and spot risky practices before they cause trouble. Our approach is hands-on: an audit of your existing tools, a map of sensitive uses, and training so your teams stay in control. The full framework is set out in our AI Act compliance guide.
Want to know whether one of your tools tips into banned territory? Book a free 30-minute audit, we run your AI uses through Article 5 and you leave with a clear action list.