What the EU AI Act bans outright
Article 5 is a ban list, not a disclosure regime. These practices carry the highest penalties in the Act — up to €35 million or 7% of worldwide annual turnover — and no amount of transparency makes them lawful.
What the law requires
Prohibited since 2 February 2025: subliminal or purposefully manipulative techniques that materially distort behaviour and cause significant harm; exploitation of vulnerabilities due to age, disability or socio-economic situation; social scoring leading to detrimental treatment in unrelated contexts; predicting criminal offences solely from profiling or personality traits; untargeted scraping of facial images to build recognition databases; emotion recognition in workplaces and education; biometric categorisation inferring protected characteristics; and real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions.
Added by the Digital Omnibus and prohibited from 2 December 2026: generating non-consensual intimate imagery, and generating child sexual abuse material. These additions are not retroactive.
This is the one area where a website scan is least able to reach a conclusion. Signals appear in marketing copy, and a page describing a practice is not evidence of deploying it.
What our scanner looks for
- Keyword signals for the prohibited categories — emotion recognition, social scoring, biometric categorisation, facial-image scraping, and image-manipulation tools of the "nudify" kind.
- The surrounding context, to distinguish selling or deploying such a system from writing about, teaching or opposing it.
- Findings here are always reported as needing review, never as an automated failure, and always at high severity. An automated tool should not accuse anyone of a banned practice.
How to fix it
- 1Treat any finding here as a question for a lawyer, not a checklist item. The penalties are the highest in the Act.
- 2If the signal came from editorial or educational content, no action is needed beyond noting why it was flagged.
- 3If you do deploy something in these categories, the remedy is to stop, then take advice on remediation and notification.
Deadlines and penalties
In force since 2 February 2025 for the founding list, with the non-consensual intimate imagery and CSAM prohibitions from 2 December 2026. Penalties reach €35 million or 7% of total worldwide annual turnover, whichever is higher.
Free, no account needed. We'll show you every page where this applies, with the evidence.
Common questions
We wrote a blog post about social scoring. Will that flag?
It may surface as something to review, which is why the check reads context rather than keywords alone and never reports a failure on its own. Discussing a practice is not deploying one.
Is personalised advertising manipulation under Article 5?
Ordinary personalisation is not. The prohibition targets subliminal or purposefully manipulative techniques that materially distort behaviour and cause significant harm — a far higher bar than relevance targeting.
This page describes technical indicators and the obligations they relate to. It is not legal advice. A website scan detects indicators, not legal compliance — which is why our reports say “no issues detected” and never “compliant”.