Not sure where your AI use stands?
Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.
Why prohibited-practice screening comes first
Before debating controls or documentation, ask whether the planned AI use may be prohibited. If a system falls into a banned category, better documentation will not solve the problem. Stop, document the concern, and get specialist review before continuing.
Examples to screen for
- Harmful manipulation or deception that materially distorts behaviour.
- Exploitation of vulnerabilities such as age, disability or social/economic situation.
- Social scoring by public authorities or equivalent harmful scoring practices.
- Certain individual criminal offence risk assessment or prediction.
- Untargeted scraping of faces from internet or CCTV to build facial-recognition databases.
- Emotion recognition in workplaces or educational institutions, subject to limited exceptions.
- Biometric categorisation to infer protected characteristics.
- Certain real-time remote biometric identification by law enforcement in public spaces, subject to exceptions.
Screening questions
- Could the system manipulate, deceive or exploit vulnerable people?
- Does it score people in a way that affects access, status or treatment?
- Does it infer sensitive traits from biometric data?
- Does it use emotion recognition in work or education?
- Does it create or expand facial-recognition databases through untargeted scraping?
Operational control
Add a prohibited-practice gate to your AI intake form. If any answer is uncertain, the use case should pause until reviewed by qualified legal and compliance teams.
FAQ
Are prohibited AI practices already relevant?
Yes. The AI Act timeline includes earlier application of general provisions, AI literacy and prohibitions.
Can exceptions apply?
Some areas have specific exceptions. Do not assume an exception applies without legal review.
Should small companies screen for prohibited practices?
Yes. The screening step is simple and can prevent serious risk early.
Sources and review method
This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.