EU AI Act Article 5 — Prohibited practices
Note: this explainer is informational and framework references are never a compliance guarantee — align your program with your legal counsel.
What Article 5 requires
Article 5 prohibits AI practices the EU deems unacceptable — among them manipulative techniques that materially distort behavior and cause harm, exploitation of vulnerabilities, social scoring, and untargeted scraping for facial-recognition databases. These prohibitions are already in force, with the AI Act's highest penalty band attached.
What it means for your company
No sane company sets out to deploy a prohibited system — the real risk is unknowingly using one: an employee adopts an unvetted tool whose functionality crosses an Article 5 line, and your organization is the deployer. The practical duty is therefore control over which AI tools enter your environment at all.
How Shield operationalizes it
The Block unsanctioned / high-risk AI tools preset (referenced to Art. 5) fully blocks known high-risk tools, org-wide, for whichever of them appear in your environment. Upstream of that, AI Discovery makes every new tool visible for triage — you decide what is sanctioned before it becomes habit, and the "Ungoverned" metric shows your open exposure at a glance.
Apply it via the preset library; it is part of the EU AI Act & GDPR Starter bundle.
The outcome
Prohibited-class and high-risk tools cannot quietly take root: discovery surfaces them, the block policy stops them, and the audit trail evidences that your organization exercised the control Article 5 assumes.
Was this article helpful?
Related articles
Apply policy presets and bundles
Deploy compliance-ready policies from the preset library — EU AI Act, GDPR, DIFC, Korea AI Basic Act, US AI in Employment, and ISO 42001/NIST bundles.
Read articleEU AI Act Article 26 — Deployer obligations
Article 26 defines your duties when deploying high-risk AI — applicable from December 2027 under the Digital Omnibus. What paragraphs (1), (5), and (6) require and how Shield prepares you now.
Read articleDIFC Regulation 10 — AI & autonomous systems
DIFC Regulation 10 governs personal data processed through autonomous and semi-autonomous systems. Who counts as Deployer and Operator, the core duties, and how Shield helps you meet them.
Read articleEU AI Act — Provider vs deployer (roles & when the line shifts)
EU AI Act provider vs deployer: what separates a deployer (Betreiber) from a provider (Anbieter) under Article 3, and the Article 25 triggers that turn a deployer into a provider of a high-risk system.
Read articleStill stuck?
Send us the details — we answer within one business day.