Article 5 of the EU AI Act contains a list of prohibited AI practices that reads, at first encounter, like a comprehensive account of AI’s worst potential applications. Social scoring by public authorities. Subliminal manipulation of human behavior. Exploitation of vulnerabilities to distort behavior. Real-time biometric identification in public spaces. AI-based profiling to predict criminal behavior. Emotion recognition in workplaces and educational institutions.

These prohibitions are real legislative achievements. Several of them represent genuinely novel legal constraints on AI applications that had no previous specific prohibition in EU law. The emotion recognition workplace prohibition, in particular, closes a gap that allowed employers to deploy systems of contested scientific validity — and significant privacy invasiveness — in settings where workers have limited power to object.

The prohibitions are also, eight months into enforcement, substantially unenforced. Not because enforcement is impossible in principle. Because enforcement requires someone to bring a complaint or investigation, and the enforcement bodies capable of acting are both under-resourced and navigating genuinely difficult definitional questions about where prohibited practices end and merely regulated ones begin.

Social Scoring’s Definitional Problem

The prohibition on “social scoring” — AI systems that evaluate or classify people based on social behavior, leading to detrimental or unfavorable treatment — was directed primarily at Chinese-style citizen scoring systems. No EU member state operates such a system, and the prohibition serves as both a legal constraint on future adoption and a normative statement about European values.

But “social scoring” as a concept bleeds into practices that are ubiquitous in commercial Europe. Insurance pricing models that factor behavioral data. Credit scores that incorporate transaction behavior. Employer screening tools that evaluate professional reputation. Platform moderation systems that reduce the reach of accounts based on behavioral patterns. None of these were intended as the targets of the social scoring prohibition — they’re explicitly excluded when they serve the purpose for which the data was collected. But the line between “legitimate credit scoring” and “prohibited social scoring” requires case-specific legal judgment.

The French data protection authority, CNIL, received 14 formal complaints in the first quarter of 2026 alleging that various commercial AI systems constituted prohibited social scoring. CNIL’s initial assessments found that 12 of the 14 were not covered by the Article 5 prohibition, with 9 falling within the legitimate financial risk assessment exception and 3 lacking sufficient evidence to meet the threshold for prohibited practice. One case — involving a landlord screening service that aggregated social media behavior with financial data — was referred to the EU AI Office for further investigation. The 14th complaint remains open.

This isn’t an indictment of CNIL. The complaints are legitimately difficult to adjudicate. But it illustrates how the prohibition, designed to address a specific and dramatic concern (state social scoring), is being interpreted in a commercial environment where closely adjacent practices are pervasive and legally ambiguous.

Emotion Recognition: The Clearest Win So Far

The emotion recognition prohibition may be the Act’s most clearly enforced provision to date — possibly because it’s the most definitionally clean.

AI systems that use emotional inference (inferring psychological states from biometric data — facial expressions, voice tone, body posture) are prohibited in workplaces and educational institutions, with exceptions for safety-critical applications like monitoring driver fatigue. This prohibition applies regardless of the claimed purpose of the system.

Several European companies had deployed emotion recognition tools for various purposes — monitoring employee engagement, assessing interview performance, evaluating student attention — prior to the Act’s enforcement. The prohibition’s implementation has been enforced through a combination of NCA action and company self-removal.

In May 2026, Germany’s Federal AI Office issued a compliance notice to HireVue, the US video interview assessment company, requiring it to disable emotion-based features for EU customers. HireVue had already phased out explicit emotion scoring features in 2021 following criticism, but the German office determined that residual facial movement analysis in their EU product constituted emotion recognition. HireVue complied within the 30-day notice period and removed the features from EU deployments.

The UK-based startup Unily, which had offered workplace wellbeing monitoring using facial analysis, shut down its EU operations in March 2026 rather than rearchitect its product. Their press release cited the “changed regulatory environment” without specifying the AI Act directly. Several similar small companies have made similar moves without public announcement.

The emotion recognition enforcement record is, compared to the social scoring and biometric provisions, actually functional. Complaints have generated investigations; investigations have generated compliance. The reason is partly definitional clarity — emotion recognition is a specific enough capability that the prohibition is less ambiguous — and partly that the primary targets (employer tools) are EU-registered companies that national authorities can reach and compel.

Exploitation of Vulnerabilities: The Darkest Prohibition

The prohibition on AI systems that “exploit vulnerabilities” — including age-related vulnerabilities, disability-related vulnerabilities, and economic vulnerability — to “materially distort behavior in a way likely to cause significant harm” is the Act’s most amorphous provision. It also addresses some of AI’s genuinely concerning applications.

An AI system that identifies financially stressed users and presents them with high-interest loan offers. A system that identifies elderly users and presents them with subscription services designed to be difficult to cancel. A system that identifies depressed users and presents them with content that deepens engagement through emotional exploitation. These are the kinds of practices the vulnerability provision targets.

Enforcement here is practically extremely difficult. These systems don’t announce their exploitation logic. The training data, optimization targets, and behavioral outputs that constitute “exploitation” are embedded in systems whose internal workings companies are not required to disclose under normal commercial confidentiality. The system’s effect — financially stressed people taking out expensive loans — is observable. Whether that effect results from prohibited AI exploitation or from the person’s own decision-making is the contested question.

The EU AI Office has not announced any formal enforcement action under the vulnerability prohibition as of August 2026. This may reflect the genuine difficulty of building a compliance case that can survive legal challenge. Or it may reflect a de facto decision to focus enforcement resources on more tractable provisions first. Several civil society organizations have submitted formal complaints alleging that specific social media advertising systems and financial services marketing AI constitute prohibited vulnerability exploitation. These complaints are under review.

What Prohibition Actually Requires

There is a view, held by some regulatory pragmatists, that the value of the prohibited practices list lies less in enforcement than in prohibition itself. The argument: by definitively legislating that these applications are illegal, the EU has changed the legal risk calculus for companies considering deploying them. A company that might have deployed a social scoring system if the legal status was uncertain will not deploy one when it’s explicitly illegal, because legal liability extends to directors and executives, not just organizations. The deterrence effect operates before enforcement, not because of it.

This argument has merit. Several planned European government AI projects were restructured in 2024-2025 specifically to avoid the prohibited AI categories, in anticipation of enforcement that the organizations’ legal teams advised was coming. The act of prohibition — independent of enforcement — shaped behavior.

But deterrence-without-enforcement has limits. It deters the cautious and the compliant. It does not deter the confident and the legally well-resourced. A company advised by skilled lawyers that their system is defensible within the exceptions will not self-restrict on deterrence grounds. They’ll deploy, and wait to see if enforcement materializes.

For prohibited AI practices as written, enforcement must eventually follow prohibition or the prohibition loses credibility. The EU AI Act is in a critical credibility window. The first major enforcement actions under Article 5 — whatever they are — will define what the prohibited list actually means. The longer that window extends without consequential action, the more the prohibition becomes a statement of values rather than a constraint on behavior. Both have value. Only one actually stops the harmful AI.

The Predictive Crime Provision and Its Discontents

There is one additional prohibition that deserves specific attention, both because of its historical weight and its current enforcement ambiguity: the ban on AI systems used for profiling of individuals to “predict or assess the likelihood of criminal behavior.”

This provision directly addresses “predictive policing” — the use of AI to identify people or locations likely to be involved in criminal activity based on historical crime data and demographic variables. PredPol (now Geolitica) in Los Angeles, ShotSpotter in Chicago, and various European equivalents in the Netherlands, Sweden, and Germany have all faced civil liberties criticism for producing racially and geographically biased predictions that concentrated policing in certain communities while providing scientific-sounding cover for decisions that were essentially statistical discrimination.

The prohibition sounds clear. It’s actually narrow. It prohibits profiling individuals based on characteristics to predict criminal behavior — it does not prohibit all predictive crime analytics. Location-based risk modeling (predicting where crimes might occur, rather than who might commit them) is probably not covered. Pattern analysis on prior criminal behavior — identifying recidivists — is probably not covered if the predictor is prior criminal record rather than demographic inference. The provision prohibits the most egregious version of the practice while leaving adjacent, similarly criticized practices unaddressed.

Dutch police in Rotterdam have been operating a “Top 400” program — identifying and intensively monitoring the 400 individuals assessed as most likely to commit serious crimes — for over a decade. A legal review commissioned by the Rotterdam municipality in March 2026 concluded that the program, as currently structured, did not trigger the EU AI Act’s criminal profiling prohibition because the risk assessment was based primarily on documented prior criminal behavior rather than demographic characteristics. Civil liberties organizations dispute this conclusion and have appealed to the Dutch NCA.

The Rotterdam case will be instructive. If the NCA upholds the municipality’s interpretation, the prohibition’s practical scope is narrow. If it challenges it, the regulatory territory expands significantly — and several other European police forces will need to reassess programs they considered outside the Act’s reach. This is the kind of test case that determines whether Article 5 is a genuine constitutional constraint on police AI or a symbolic restriction on its most extreme application.

Either way, the prohibited list’s first year is revealing a pattern: the provisions with definitional clarity (emotion recognition) are being enforced. The provisions with definitional ambiguity (social scoring, vulnerability exploitation, predictive crime) are being contested. The regulation is doing meaningful work in the first category. In the second, it’s mostly generating legal fees and waiting for its day in court.

Get the best of Think Different in your inbox

One email a month: new articles, reviews and the upcoming live webinar + free recording. No spam, unsubscribe anytime.