Pillaraxis Cyber law, privacy & security — read plainly
Vol. 2 · 2026
Kochi, India
Brief No. 001
Law & Policy

Prohibited by Law: What the EU AI Act Actually Bans

Long before the high-risk rules arrive, a shorter list of AI practices became flatly illegal in the EU from February 2025. Most compliance conversations skip past what's already banned.

Most coverage of the EU AI Act focuses on the high-risk obligations arriving in 2026 and 2027 — the technical documentation, the risk management systems, the human oversight requirements. Less attention goes to the much shorter list of practices that became outright prohibited far earlier, from 2 February 2025, with no phase-in and no compliance pathway. If your AI system falls into one of these categories, the answer is not 'comply' — it is 'stop.'

The prohibitions cover practices the Act's drafters judged to pose unacceptable risk regardless of context or safeguards. Social scoring systems that evaluate people based on behaviour or characteristics unrelated to the context in which the data was gathered are banned outright. So is predictive policing based purely on profiling an individual, without objective, verifiable facts connecting them to a criminal act. Emotion recognition systems in workplaces and educational institutions are banned, except in narrow safety or medical contexts. Biometric categorisation systems that infer sensitive characteristics — race, political opinion, sexual orientation — from biometric data are prohibited, as is untargeted scraping of facial images from the internet or CCTV to build facial recognition databases, a provision written with systems like Clearview AI's in mind.

If your AI system falls into a prohibited category, the answer is not 'comply' — it is 'stop.' No risk classification exercise required.

A ninth prohibition, targeting certain forms of AI-driven manipulation, was added later through the Digital Omnibus process and takes effect in December 2026 — a reminder that even the 'settled' prohibited-practices list is not entirely closed.

For a compliance function, the practical value of this list is that it requires no risk classification exercise, no technical standard, no waiting for further guidance. It is a short, binary checklist: does any system in use fall into one of these categories. Given how much of the Act's remaining timeline is still contested through the Digital Omnibus negotiations, the prohibited-practices list is, for now, the one part of the AI Act that is simply already law.