Prohibited vs High-Risk AI under the EU AI Act
Last reviewed: · By Victor Humenhuk (AIGP certified)
Prohibited AI practices under Article 5 of the EU AI Act cannot be placed on the market, put into service or used at all, and no amount of documentation or oversight makes them lawful. High-risk AI systems under Article 6 are lawful, but only if the provider meets the requirements in Chapter III, passes a conformity assessment, affixes CE marking and registers the system, and the deployer uses it as instructed with human oversight. The practical question is whether your use case sits on the banned list, such as social scoring, untargeted facial-image scraping or emotion inference at work or school, or on the high-risk list, such as recruitment, credit scoring or biometric identification. Prohibitions applied from 2 February 2025 and carry the top fine tier of up to 35 million euro or 7% of total worldwide annual turnover, while most high-risk breaches sit in the 15 million euro or 3% tier.
The risk tiers at a glance
| Tier | Legal basis | Consequence | Fine exposure |
|---|---|---|---|
| Prohibited (unacceptable risk) | Article 5 | Cannot be placed on the market, put into service or used | Up to 35 million euro or 7% of total worldwide annual turnover |
| High risk | Article 6, Annexes I and III | Permitted subject to the Chapter III requirements, conformity assessment, CE marking and registration | Up to 15 million euro or 3% |
| Transparency obligations (often called limited risk) | Article 50 | Permitted, with disclosure duties covering interactive AI systems, synthetic content, deepfakes, emotion recognition and biometric categorisation | Up to 15 million euro or 3% |
| Minimal risk | Not separately regulated | No obligations, with voluntary codes of conduct encouraged under Article 95 | None |
Worth noting: limited risk and minimal risk are convenient labels used in Commission communications and training material rather than defined terms in the Regulation. The text itself sets out prohibitions, high-risk classification, transparency obligations for certain systems, and a separate regime for general-purpose AI models. See the risk classification framework.
What is prohibited under Article 5?
Article 5 lists practices banned outright:
- Subliminal, purposefully manipulative or deceptive techniques that materially distort behaviour and cause or are reasonably likely to cause significant harm.
- Exploiting vulnerabilities due to age, disability or a specific social or economic situation, with the same effect.
- Social scoring: evaluating or classifying people over time on social behaviour or personal characteristics, where the resulting treatment is in an unrelated context, or is unjustified or disproportionate.
- Assessing or predicting the risk that a person will commit a criminal offence based solely on profiling or personality traits. This does not catch systems supporting a human assessment grounded in objective, verifiable facts directly linked to criminal activity.
- Untargeted scraping of facial images from the internet or CCTV to create or expand facial recognition databases.
- Inferring emotions in the workplace and in education institutions, except for medical or safety reasons.
- Biometric categorisation to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, with carve-outs for labelling or filtering lawfully acquired datasets and for law enforcement.
- Real-time remote biometric identification in publicly accessible spaces for law enforcement, save for narrowly listed objectives with prior judicial or administrative authorisation.
The prohibitions apply across the chain and are not cured by consent, documentation or oversight.
What makes a system high-risk under Article 6?
There are two routes in. Article 6(1) catches AI that is a safety component of, or is itself, a product covered by the Union harmonisation legislation in Annex I where that product must undergo third-party conformity assessment: machinery, medical devices, lifts, toys, vehicles and so on. Article 6(2) catches the Annex III use cases:
- Biometrics: remote biometric identification, biometric categorisation by sensitive attributes, emotion recognition.
- Critical infrastructure: safety components in road traffic and in the supply of water, gas, heating and electricity, and critical digital infrastructure.
- Education and vocational training: admission, evaluating learning outcomes, assessing the appropriate level of education, and monitoring prohibited behaviour during tests.
- Employment and worker management: recruitment, targeted job advertising, filtering applications, evaluating candidates, promotion and termination, task allocation and performance monitoring.
- Access to essential private and public services: eligibility for benefits and public assistance including healthcare, creditworthiness and credit scoring (except detection of financial fraud), risk assessment and pricing in life and health insurance, and emergency call triage and dispatch.
- Law enforcement.
- Migration, asylum and border control.
- Administration of justice and democratic processes.
The Article 6(3) filter. An Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, including because it does not materially influence the outcome of decision-making. That covers systems performing a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations without replacing or influencing the human assessment, or performing a preparatory task. But a system that carries out profiling of natural persons is always high-risk. A provider relying on the filter must document its assessment before placing the system on the market and must still register the system in the EU database.
What must you do for a high-risk system?
Providers must satisfy the requirements in Chapter III, Section 2, usually taught as the eight requirements: a risk management system (Article 9); data and data governance (Article 10); technical documentation (Article 11); record-keeping and automatic logging (Article 12); transparency and provision of information to deployers (Article 13); human oversight (Article 14); accuracy, robustness and cybersecurity (Article 15); and, wrapping the lot, a quality management system (Article 17). On top sit conformity assessment (Article 43), the EU declaration of conformity (Article 47), CE marking (Article 48), registration (Article 49), post-market monitoring (Article 72) and serious incident reporting (Article 73).
Deployers have their own, shorter list under Article 26, and some deployers must also carry out a fundamental rights impact assessment under Article 27. See the eight requirements and DPIA for how the assessments interlock.
How do you classify a system in practice?
- Confirm it meets the Article 3(1) definition of an AI system at all. Simple, fully deterministic rule-based software may fall outside it.
- Run the Article 5 screen first. If the intended purpose or a foreseeable use is on the banned list, stop, because there is no compliance route.
- Check Annex I: is the AI a safety component of a regulated product, or the product itself?
- Check Annex III against the intended purpose, not the technology.
- If it is in Annex III, consider the Article 6(3) filter and document the reasoning. Remember the profiling override.
- Check Article 50 separately, because transparency duties can apply to a system that is not high-risk.
- If you build on a general-purpose AI model, treat that as a distinct question under Articles 51 to 56.
- Re-run the analysis whenever the intended purpose changes, since a change can trigger the Article 25 role switch and lift the system into high-risk.
Related study notes
- The risk classification framework
- Prohibited risk and the banned list
- High risk - where most regulation lives
- Limited risk and minimal risk
- The eight requirements for high-risk AI
Frequently asked questions
Is a general-purpose chatbot a high-risk AI system?
Not as such. General-purpose AI models sit in their own regime under Articles 51 to 56, and a general-purpose system is not high-risk by default. What matters is the use case: a deployer that puts a general-purpose tool to work screening job applicants or scoring credit is deploying it in a high-risk area, and under Article 25 may become the provider of a high-risk system.
Who decides whether a system is high-risk?
The provider makes and documents the classification in the first instance, and must keep that assessment available for authorities. Article 6(5) requires the Commission to provide guidelines with practical examples on the classification rules, and market surveillance authorities can challenge a classification after the fact.
What is the penalty for deploying a prohibited AI system?
Article 99(3) sets the top tier: administrative fines of up to 35 million euro or, for undertakings, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs, including start-ups, the lower of the two figures applies.
Does a system escape high-risk classification if a human signs off the decision?
Not automatically. The Article 6(3) filter is narrow: it applies where the system performs a narrow procedural or preparatory task, improves a completed human activity, or detects patterns without replacing or influencing the human assessment. A rubber-stamp review over a system that materially drives the outcome will not qualify, and profiling is always high-risk.
Test yourself
Try the free AIGP practice questions, or read the full AIGP study guide - free.