Risk screening

Prohibited AI Practices Under the EU AI Act

Some AI use cases should be stopped before a normal product launch checklist begins. This page gives product teams a plain-English way to spot practices that may fall into the EU AI Act prohibited category.

Disclaimer: This guide is for general operational planning. It is not legal advice, and it does not replace review by qualified counsel for a specific product, market, or customer deployment.

Fast stop signals

Practice to screenWhy it needs immediate review
Manipulative or deceptive AI patternsThe system may materially distort a person's behavior or decision-making in a way that can cause significant harm.
Exploiting vulnerable peopleThe feature targets or takes advantage of age, disability, social situation, or economic vulnerability.
Social scoringThe system ranks people or groups in a way that affects treatment across contexts or creates unjustified disadvantage.
Predictive policing based only on profilingThe system estimates criminal risk mainly from profiling, personality traits, or characteristics instead of objective, verifiable facts.
Untargeted facial image scrapingThe product builds or expands facial recognition databases from broad web or CCTV scraping.
Workplace or education emotion inferenceThe system infers emotions in work or education settings, except for limited medical or safety reasons.
Sensitive biometric categorizationThe system uses biometrics to infer sensitive traits such as political opinions, religion, sex life, race, or trade-union membership.
Real-time remote biometric identification in public spacesLaw-enforcement use in public spaces is tightly restricted and should not be treated as a normal SaaS feature.

Product triage questions

What to do when a signal appears

Run the risk classifier

Official sources

Last reviewed: July 3, 2026.