Prohibited practices
Closed list of AI practices whose placing on the market, putting into service or use is prohibited in the Union (Article 5). Eight from 2 February 2025; ten from 2 December 2026.
It is the only part of the Regulation that admits no risk management: it is not mitigated, not documented — it is not done.
Which obligations it carries
A legal obligation of providers and deployers, applicable from 2 February 2025 for the eight original prohibitions. The two added by Regulation (EU) 2026/1744 — Article 5(1), points (ba) and (bb): non-consensual intimate material and child sexual abuse material — together with the new paragraphs 1a and 1b, are applicable from 2 December 2026. Non-compliance with this prohibition is the highest tier of the penalties regime of Article 99: up to EUR 35 000 000 or 7 % of the total worldwide annual turnover of the preceding financial year, whichever is higher, and for SMEs the lower of the two (Article 99(6)).
What it is not
It is not “dangerous AI”. It is a closed list of described conducts. A system that causes serious harm and fits none of the ten is not prohibited: it will be regulated by another route, or by none. And it is not only for those who build: the prohibition expressly covers use, so a deployer can incur it with a tool it bought.
The nuance almost nobody captures
Of the ten, the one that brushes an ordinary company without anyone having decided it is point (f): it is prohibited to use AI systems to infer the emotions of a natural person in the areas of workplace and education institutions, except where intended for medical or safety reasons. No surveillance project is needed: switching on the sentiment-analysis feature of a productivity tool over the team’s communications is enough. It is the prohibition most often breached by default configuration, not by decision.