Template · Article 5 · In force since 2 February 2025 (CSAM/NCII prohibitions from 2 December 2026)

EU AI Act Prohibited Practices Checklist (Article 5)

A prohibited practices screening is a documented check of every AI system against the practices banned outright by Article 5 of the EU AI Act (Regulation (EU) 2024/1689). Most prohibitions — manipulation, social scoring, emotion recognition at work, untargeted facial scraping and others — have applied since 2 February 2025 and carry the Act's highest fines: up to €35 million or 7% of worldwide turnover, with SMEs and small mid-caps paying the lower of the two (Article 99(6)). The CSAM/NCII prohibitions added by the Digital Omnibus (Regulation (EU) 2026/1744) apply from 2 December 2026.

Last reviewed: 26 August 2026 · In force since 2 February 2025 (CSAM/NCII prohibitions from 2 December 2026) · Included in the kit as 10_Prohibited_Practices_Screening.docx

First page of 10_Prohibited_Practices_Screening.docx from the RegShelf EU AI Act Kit
First page of 10_Prohibited_Practices_Screening.docx — the document you receive in the kit.

What this document is

Document 10 of the RegShelf kit is a screening checklist a non-lawyer can run: for each AI system in your inventory, you read nine plain-language practice descriptions and answer Yes / No / Unsure to a set of red-flag questions per practice. Any "Yes" or "Unsure" is a hit — and "Unsure" is treated exactly like "Yes" until resolved, because the fine regime does not reward optimism. The output is not just the answers: it is the dated, countersigned sign-off record showing that you asked the questions at all, which is what a market surveillance authority would look for.

Who needs it

Every company using or providing AI, because the prohibitions apply to organisations of all sizes with no de minimis threshold — and because the ban SMEs trip over most often arrives quietly inside everyday software. A meeting-tool add-on reporting participant "sentiment", interview software scoring candidates' "enthusiasm" from voice, an e-learning platform gauging attention from webcams: all are candidates for the Article 5(1)(f) ban on emotion recognition in the workplace and education, even where the vendor markets the feature as "wellbeing analytics". Screening is needed per system in your inventory, before every new use case goes live, and again whenever a system or vendor changes.

What the law requires — precisely

Article 5 bans specific practices; it does not mandate a screening document — the screen is how you make sure none of the bans applies to you and prove you checked. The practices covered:

  • Since 2 February 2025: manipulative or exploitative techniques causing significant harm (Art. 5(1)(a)–(b)); social scoring leading to unjustified detrimental treatment (5(1)(c)); predicting criminality from profiling or traits alone (5(1)(d)); untargeted scraping of facial images from the internet or CCTV (5(1)(e)); emotion recognition at work and in education outside narrow medical or safety exceptions (5(1)(f)); biometric categorisation by sensitive attributes (5(1)(g)); real-time remote biometric identification in public spaces for law enforcement (5(1)(h)).
  • From 2 December 2026: the CSAM/NCII prohibitions inserted into Article 5 by Regulation (EU) 2026/1744. For providers of generative systems this prohibition is conditional, not absolute: it applies where such generation is the system's intended purpose or a reasonably foreseeable and reproducible outcome in the absence of appropriate and proportionate technical safeguards.

One nuance the template also gets right: a harmful generated output is not automatically a "serious incident" under Article 73 — that term has a narrow statutory definition (Article 3(49)) — though other legal duties may still apply.

What's inside the RegShelf template

Ten sections:

  • How to run the screen — when (per system, per new use case, annual re-screen as a recommended internal control), who (system owner, countersigned by whoever holds compliance responsibility) and how to score;
  • Eight practice sections (Sections 2–9), each with the ban in plain terms, workplace-relevant examples — the emotion-recognition section alone lists four SME scenarios — and three to four red-flag questions;
  • Section 9 on the CSAM/NCII bans, including the safeguards question set for anyone offering generative image, video or audio capability (own or white-labelled) against the 2 December 2026 date;
  • A what-to-do-on-a-hit box — stop immediately, escalate to management the same day, legal review before any restart;
  • The sign-off table — one row per system per screening, with a worked example (a sentiment add-on hit and disabled the same day).

How to use it

Work from your AI system inventory — one screen per row, including AI features inside SaaS you did not build. Most SME systems pass in minutes; the value is the written record. On any hit: switch the feature off, escalate, and let qualified counsel decide whether one of the narrow exceptions applies. Keep each completed sign-off for as long as the system is in use plus a retention period you set (the template suggests five years as an internal control). Re-screen before every launch and whenever a vendor announces new capabilities.

Related reading

Frequently asked

What AI practices are prohibited under the EU AI Act?+

Article 5 bans harmful manipulation and exploitation of vulnerabilities, social scoring, predicting criminal behaviour from profiling alone, untargeted scraping of facial images, emotion recognition in workplaces and education (outside medical/safety exceptions), biometric categorisation by sensitive attributes, and real-time remote biometric identification in public spaces for law enforcement — plus, from 2 December 2026, AI generation or manipulation of CSAM and non-consensual intimate imagery.

When do the Article 5 prohibitions apply?+

The original set has applied since 2 February 2025 with no grace period. The CSAM/NCII prohibitions added by Regulation (EU) 2026/1744 apply from 2 December 2026 — providers of generative systems have until then to have appropriate and proportionate technical safeguards in place.

What are the fines for a prohibited AI practice?+

Up to €35 million or 7% of total worldwide annual turnover — the Act's highest tier. For most undertakings the higher of the two figures is the cap; for SMEs, start-ups and small mid-caps, Article 99(6) caps each fine at the lower of the percentage or the fixed amount.

Is emotion recognition software illegal at work?+

Inferring employees' emotions in the workplace is prohibited by Article 5(1)(f), with narrow exceptions only for medical or safety reasons (such as driver-fatigue detection). This includes 'sentiment' or 'engagement' features inside meeting, HR or call-centre tools — rebranding the feature as wellbeing analytics does not lift the ban.

Primary sources

This template ships in the EU AI Act Kit

24 fill-in documents in Word and Excel — launch price €149, twelve months of updates included.

See the full kit