AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001 · EU AI Act deep dive · lesson 3 of 17 · 14 min
Prohibited practices and the AI literacy duty
The first rules to bite
Since 2 February 2025, two parts of the AI Act have applied: the prohibited practices in Article 5 and the AI literacy duty in Article 4. They matter even for small organizations, because breaching a prohibition carries the Act's highest fines: up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher (for SMEs and start-ups, whichever is lower). The Commission published guidelines on prohibited practices in February 2025 to explain how it reads each ban; they are worth skimming because they include many practical examples.
The prohibited practices (Article 5), in plain language
| # | Prohibited | Practical example | Notes | |---|---|---|---| | 1 | Subliminal, manipulative or deceptive techniques that materially distort behavior and cause or are likely to cause significant harm | A shopping app using AI-driven dark patterns that push vulnerable users into debt | Ordinary persuasive marketing is not banned; the test is material distortion plus significant harm | | 2 | Exploiting vulnerabilities due to age, disability or a specific social or economic situation | AI targeting children with manipulative in-game purchase prompts | | | 3 | Social scoring leading to detrimental or disproportionate treatment in unrelated contexts | Scoring citizens' "trustworthiness" from social media to limit access to services | Applies to public and private actors | | 4 | Predicting the risk of a person committing a crime based solely on profiling or personality traits | "Pre-crime" scoring of individuals | Support for human assessment based on objective facts is allowed | | 5 | Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases | Building a face search engine from social media photos | | | 6 | Emotion recognition in the workplace and education institutions | Monitoring employees' facial expressions for "engagement" | Exceptions for medical or safety reasons | | 7 | Biometric categorization inferring race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation | Inferring religion from face images to target ads | Some lawful labeling of lawfully acquired datasets in law enforcement is carved out | | 8 | Real-time remote biometric identification in publicly accessible spaces for law enforcement | Live facial recognition in a shopping center by police | Narrow exceptions with authorization |
New from 2 December 2026: the 2026 Digital Omnibus added a prohibition aimed at AI systems used to create non-consensual intimate imagery and child sexual abuse material ("nudification" tools), covering placing such systems on the market for that purpose or without reasonable safeguards, and deployers using them for that purpose. Check the consolidated text for exact scope and exclusions.
How marketers and agencies can stumble into Article 5
Most businesses will never build a social scoring system. But three patterns deserve a second look:
- Emotion AI in call centers and HR. Tools that score agents' emotional state from voice or video during work can fall under the workplace emotion-recognition ban. Sentiment analysis of customer text is a different thing, but review vendor claims carefully.
- Hyper-personalized persuasion aimed at vulnerable groups. Campaigns for gambling, crypto or payday loans that use AI to find and exploit financial distress signals are high-risk territory, legally and reputationally.
- Biometric inference for targeting. Any tool claiming to infer religion, ethnicity or sexual orientation from images or voice should be rejected outright.
AI literacy (Article 4), after the Omnibus
Article 4 originally required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and others operating AI on their behalf. The 2026 Omnibus rewrote it: providers and deployers must take measures to support the development of AI literacy of their staff and people operating systems on their behalf, taking into account their skills, experience, education and context, and the text clarifies that it does not require guaranteeing any specific level of literacy for any individual. The Commission and Member States are also tasked with supporting organizations, especially SMEs.
The practical message is unchanged: you need a proportionate, documented literacy program. Softer wording does not mean "do nothing", and buyers will still ask.
Hands-on: a proportionate AI literacy plan
ai_literacy_plan:
owner: "AI lead (Operations Director)"
audiences:
all_staff:
content: ["What AI is and is not", "Approved tools list", "Never paste confidential or personal data into unapproved tools", "Checking outputs before use", "How to report an AI incident"]
format: "45-minute session + 1-page cheat sheet"
frequency: "At onboarding and annually"
content_and_marketing:
content: ["Disclosure and labeling rules", "Copyright and brand risk", "Fact-checking workflow", "Synthetic media consent"]
format: "90-minute workshop with real examples"
people_managers_and_hr:
content: ["High-risk uses in employment", "Human oversight duties", "Bias and fairness basics"]
ai_system_owners:
content: ["Inventory upkeep", "Vendor due diligence", "Monitoring and incident response"]
evidence:
- "Attendance records"
- "Short quiz results"
- "Version-controlled training materials"
review: "Every 6 months or when a major tool or law changes"
Worked example: a Manchester contact center
A 120-seat contact center wanted AI that detects agent frustration from voice to trigger supervisor support. Classification: emotion recognition in the workplace, prohibited in the EU context unless a genuine medical or safety reason applies, and a poor fit for UK data protection expectations. The team redesigned the tool to flag call characteristics (long silences, repeated transfers, escalation keywords) rather than inferring emotions, and made it opt-in coaching support. Same business goal, very different legal posture.
Pitfalls
- Treating the ban list as irrelevant because "we are a marketing company".
- Relying on a vendor's marketing claim that their emotion AI is "compliant" without asking how it is used.
- Running one generic AI training and never updating it.
Video lecture: Prohibited practices and the AI literacy duty
Lecture coming soon · 13 chapters · about 9 minutes. Read the full transcript below.
- Banned, not just risky
- Why it matters
- Prohibited practices, part 1
- Analogy: banned ingredients
- Prohibited practices, part 2
- Where businesses drift
- Redesign, don't just drop
- AI literacy after the Omnibus
- A proportionate literacy plan
- Example 2: Dubai lending campaign
- Common mistakes
- Watch me do it: screen + literacy
- Recap and next step
Lecture transcript
Banned, not just risky
Some AI uses are not just risky under the EU AI Act. They are banned outright, and the fines are the highest in the regulation: up to thirty-five million euros or seven percent of worldwide annual turnover. The surprising part is how ordinary some of the banned uses can look inside a normal business, especially in HR, call centers and marketing. In this lesson you'll learn the prohibited practices in plain language, how businesses accidentally drift toward them, and how to run a proportionate AI literacy program, which has been required since February twenty twenty-five.
Why it matters
Why does this matter so much, even for a small business? Because prohibited practices carry the highest fines in the Act, and because the risk often arrives through a vendor feature rather than a deliberate decision. An HR platform switches on engagement scoring. A call-center tool adds agent emotion analytics. A targeting tool offers vulnerability segments. If nobody in your organization knows the banned list, these features get switched on by default. And a documented AI literacy program is also the first thing clients and auditors ask to see, because it shows your people know where the lines are.
Prohibited practices, part 1
Let's walk the list. Banned first: manipulative or deceptive techniques that materially distort behavior and cause significant harm. Ordinary persuasive marketing is fine. The test is material distortion plus significant harm. Second: exploiting vulnerabilities due to age, disability, or someone's social or economic situation. Third: social scoring that leads to unfair treatment in unrelated contexts, whether by governments or companies. Fourth: predicting that a person will commit a crime based solely on profiling or personality traits.
Analogy: banned ingredients
Think of Article five as a short list of things no amount of paperwork can make acceptable, a bit like the list of substances banned in food. You can't get a special license to add them, and it doesn't matter how good your quality system is. That's different from high-risk AI, which is allowed if you meet strict conditions. So the first question for any AI idea isn't how do we comply. It's is this on the banned list at all? If the answer is yes, or maybe, stop and redesign before you spend a single hour on anything else.
Prohibited practices, part 2
Next: untargeted scraping of face images from the internet or CCTV to build facial recognition databases. Then emotion recognition in workplaces and schools, with exceptions for medical or safety reasons. Then biometric categorization that infers sensitive traits like race, religion, political opinions, or sexual orientation. And real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions. Finally, the twenty twenty-six Digital Omnibus added a new ban from the second of December twenty twenty-six, targeting AI systems used to create non-consensual intimate images and child sexual abuse material, the so-called nudification tools.
Where businesses drift
Here's how normal businesses drift toward these lines. Contact centers buy tools that score agents' emotions from their voice during calls. That can fall squarely into the workplace emotion-recognition ban. Performance marketers in gambling, crypto or short-term lending may use AI to find people showing signs of financial distress and push offers at them. That's exploiting vulnerability, and it's also a reputational disaster. And some ad tools claim to infer religion or ethnicity from images. The right answer to those is a firm no.
Redesign, don't just drop
A real-world style example. A contact center in Manchester wanted AI to detect agent frustration from their voice, to trigger supervisor support. That's emotion recognition in the workplace. So they redesigned it. Instead of guessing emotions, the tool flags call characteristics: long silences, repeated transfers, escalation keywords. And they made it opt-in coaching. Same business goal, supporting stressed agents, but a completely different legal posture. When you hit a ban, don't just drop the idea. Ask what signal you actually need.
AI literacy after the Omnibus
Now AI literacy. Article four originally required providers and deployers to ensure, to their best extent, a sufficient level of AI literacy. The twenty twenty-six Omnibus softened the wording. Organizations must now take measures to support the development of AI literacy among staff and people operating AI on their behalf, taking into account their skills and context, and the text clarifies that you don't have to guarantee any particular level for any individual. Don't misread that as optional. You still need a proportionate, documented program, and clients will still ask to see it.
A proportionate literacy plan
What does proportionate look like? Everyone gets a short session: what AI is and isn't, the approved tools list, never pasting confidential or personal data into unapproved tools, checking outputs, and how to report an incident. Content and marketing teams go deeper on disclosure, copyright and synthetic media consent. HR and managers learn about high-risk uses in employment and human oversight. And the people who own AI systems learn inventory upkeep, vendor checks and monitoring. Keep attendance, quiz results and dated materials. There's a ready-made plan in the lesson text.
Example 2: Dubai lending campaign
A second example, from marketing. A Dubai agency pitches a lending app on a campaign that uses AI to find people showing signs of money stress in their app behavior, then pushes urgent loan offers at the moments they seem most desperate. The agency's AI lead stops the pitch. Targeting people because of a financial vulnerability, in a way likely to cause significant harm, sits right next to the Article five line for EU audiences, and it's a reputational disaster everywhere. The redesign: target by stated intent, like people researching loan comparisons, with clear total cost information and no false urgency.
Common mistakes
Common mistakes with this lesson's topics. Treating the ban list as irrelevant because we're a marketing company, when marketing tools are exactly where emotion inference and vulnerability targeting show up. Trusting a vendor's claim that its emotion AI is compliant without asking how you'll actually use it. And running one generic AI training session, then never updating it as tools and laws change. A literacy program is a living thing, reviewed every six months or whenever a major tool or rule changes.
Watch me do it: screen + literacy
Watch me do it. I add a column called Article five screen to the register, and I go row by row asking three quick questions. Does this tool infer emotions of staff or students? Does it target people because of age, disability or financial vulnerability? Does it infer sensitive traits like religion or ethnicity from images or voice? Chat assistant: no, no, no. Image generator: no, no, no. Meeting recorder: here I pause. I open the vendor's settings page and find a feature called engagement insights that scores participants' sentiment. For client calls that's customer sentiment, but on internal team calls it would be scoring employees. I write: disable engagement insights for internal meetings, owner IT, due Friday. Next, I open a second tab called Literacy plan. Three rows: all staff, marketing, system owners. For all staff: forty-five minutes, content from the lesson template, delivered at onboarding and yearly. For marketing: a ninety-minute workshop on disclosure and consent. For system owners: vendor checks and incident reporting. I add an evidence column that links to attendance sheets. Screening plus a literacy plan: two tabs, forty minutes.
Recap and next step
Recap. Eight practices have been banned since February twenty twenty-five, with a ninth, nudification tools, joining in December twenty twenty-six. The ones businesses most often drift toward are workplace emotion recognition, exploiting vulnerable people, and inferring sensitive traits. When you hit a ban, redesign around the signal you actually need. And run a proportionate, documented AI literacy program. Your next step: check your inventory for any emotion, biometric or vulnerability-targeting features, then adapt the literacy plan template to your team.
Key takeaways
- Article 5 prohibitions have applied since 2 February 2025 and carry fines up to EUR 35 million or 7% of worldwide turnover.
- Workplace emotion recognition, exploiting vulnerabilities and sensitive biometric inference are the bans ordinary businesses most often approach.
- The 2026 Omnibus added a ban on AI nudification/CSAM tools applying from 2 December 2026.
- Article 4 now requires measures to support AI literacy; a documented, role-based program remains the practical expectation.
Try it
Scan your AI inventory for any feature involving emotion detection, biometric inference or targeting of vulnerable groups. Then adapt the YAML literacy plan to your team and set a review date.