Skip to content
    Back to Regulatory Radar
    CriticalDeadlineFebruary 2, 2025

    EU AI Act: Prohibited Practices Provisions Apply

    The EU AI Act's provisions on prohibited AI practices became applicable, banning categories of AI systems deemed to pose an unacceptable risk to fundamental rights. Prohibited practices under Article 5 include AI systems that deploy subliminal or manipulative techniques causing significant harm, exploit vulnerabilities of specific groups, perform social scoring by public or private actors, conduct certain forms of predictive policing based solely on profiling, infer emotions in workplaces and educational institutions, build facial recognition databases through untargeted scraping, use biometric categorization to infer sensitive attributes, and use real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions). AI literacy obligations under Article 4 became applicable on the same date. General-purpose AI (GPAI) model provider obligations followed separately on 2 August 2025.

    EU AI ActSaaSHealthcareFinTech

    Key Analytics

    February 2, 2025
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Organizations must have completed their assessment of whether any AI systems or components fall within the prohibited categories and ceased their operation. Although the prohibitions applied from 2 February 2025, the governance framework and penalty regime became applicable on 2 August 2025, giving national authorities and the AI Office the ability to impose fines. Non-compliance with the prohibited practice provisions carries the highest penalty tier under the Act: up to EUR 35 million or 7% of global annual turnover, whichever is higher. GPAI model provider obligations under Article 53, including technical documentation and training data summaries, did not apply on this date; they took effect on 2 August 2025.

    Recommended Actions

    • Confirm that your AI system inventory has been reviewed against the full list of prohibited practices in Article 5, with documented evidence of compliance or discontinuation.
    • Implement AI literacy measures under Article 4, ensuring staff who operate or use AI systems have sufficient competence, with training scoped to their role and documented.
    • Establish internal reporting channels for employees and users to flag potential prohibited AI practices, and document the escalation and remediation procedures.

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate65-135 hours
    Key Workstreams
    • Documented Article 5 review of the AI system inventory
    • Role-scoped AI literacy training under Article 4
    • Escalation and remediation procedure for flagged AI practices

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 65-135 hours
    Start cold under pressureSignificant · 150-320 hours

    Roughly 85 to 185 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events