Risk screening
Prohibited AI Practices Under the EU AI Act
Some AI use cases should be stopped before a normal product launch checklist begins. This page gives product teams a plain-English way to spot practices that may fall into the EU AI Act prohibited category.
Disclaimer: This guide is for general operational planning. It is not legal advice, and it does not replace review by qualified counsel for a specific product, market, or customer deployment.
Fast stop signals
| Practice to screen | Why it needs immediate review |
|---|---|
| Manipulative or deceptive AI patterns | The system may materially distort a person's behavior or decision-making in a way that can cause significant harm. |
| Exploiting vulnerable people | The feature targets or takes advantage of age, disability, social situation, or economic vulnerability. |
| Social scoring | The system ranks people or groups in a way that affects treatment across contexts or creates unjustified disadvantage. |
| Predictive policing based only on profiling | The system estimates criminal risk mainly from profiling, personality traits, or characteristics instead of objective, verifiable facts. |
| Untargeted facial image scraping | The product builds or expands facial recognition databases from broad web or CCTV scraping. |
| Workplace or education emotion inference | The system infers emotions in work or education settings, except for limited medical or safety reasons. |
| Sensitive biometric categorization | The system uses biometrics to infer sensitive traits such as political opinions, religion, sex life, race, or trade-union membership. |
| Real-time remote biometric identification in public spaces | Law-enforcement use in public spaces is tightly restricted and should not be treated as a normal SaaS feature. |
Product triage questions
- Could the AI pressure, trick, or steer a user without the user understanding what is happening?
- Does the system make or influence decisions about people outside the original context where data was collected?
- Does the feature involve biometric identification, biometric categorization, emotion recognition, or facial image collection?
- Does the system affect vulnerable users, children, workers, students, applicants, tenants, borrowers, or people seeking public services?
- Would a reasonable reviewer describe the feature as surveillance, scoring, profiling, or behavioral control?
What to do when a signal appears
- Pause the launch path for that use case.
- Write the intended purpose, user group, data categories, and real-world decision impact.
- Separate marketing claims from actual system behavior.
- Ask whether a safer, non-biometric, non-scoring, or human-led workflow can meet the product goal.
- Get specialist review before collecting production data or enabling the feature for EU users.
Official sources
Last reviewed: July 3, 2026.