← Back to Blog

Most of the EU AI Act arrives gradually — transparency duties in August 2026, high-risk rules later still. But one part of the law doesn't phase in at all. Article 5 draws a set of hard red lines: AI uses that are simply forbidden, whatever your size or sector. They have been in force since 2 February 2025 and carry the Act's steepest fines.

Most of these bans are aimed at governments and big tech, and you'll never go near them. But a few sit closer to everyday charity work than you'd expect — often hidden inside an HR tool, a fundraising platform, or a "wellbeing" app someone signed up for. This article explains the bans that can realistically reach a small organisation, and gives you a short way to check that you're clear.

This article is general information, not legal advice. It does not constitute legal advice, and Vedomia does not provide legal services. For legal questions about your specific situation, speak to a qualified solicitor.

What Article 5 is — and why it's different

Most of the AI Act works by risk tiers: the higher the risk, the more you must document, oversee and disclose. Article 5 is the exception. It lists eight practices that are prohibited outright — no risk assessment, no paperwork, no "acceptable if handled carefully". If an AI system does one of these things, it cannot be placed on the market, put into service, or used in the EU. Full stop.

Two features make this the part of the Act to know first:

  • No exemptions by size or sector. There is no small-organisation carve-out and no charity carve-out. The ban applies to a two-person nonprofit exactly as it applies to a multinational.
  • The heaviest penalties in the whole regulation. Breaching Article 5 can attract fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher — a higher ceiling than any other obligation in the Act.

The dates that matter

  • 2 February 2025 — the prohibitions took effect. The bans have been legally in force for over a year.
  • 2 August 2025 — enforcement and penalties began. National authorities gained their powers to act on breaches from this date.

So this is not a "getting ready for 2026" topic. It is already live, already enforceable, and unaffected by the recent Digital Omnibus simplification package — which deferred some high-risk deadlines but left the Article 5 prohibitions untouched.

The other AI Act duties ask you to document and explain. Article 5 asks something simpler and stricter: don't do these things at all.

The bans that can actually reach a charity

Four of the eight prohibitions are worth a small organisation's attention, because the technology behind them turns up in ordinary tools.

1. Emotion recognition at work

The Act prohibits AI used to infer emotions of a person in the workplace and in education, except for narrow medical or safety reasons. This is the one most likely to catch an employer off guard. It covers tools that claim to read a person's mood, stress, engagement or attention from their face, voice or physiological signals — sometimes marketed as staff "wellbeing", "engagement" or "productivity" analytics, or built into interview and training software. If a tool profiles how your staff or volunteers feel, treat it as a red flag and check carefully before adopting it.

2. Exploiting people's vulnerabilities

The Act bans AI that exploits the vulnerabilities of a person or group — because of their age, disability, or a specific social or economic situation — to materially distort their behaviour in a way that causes, or is likely to cause, harm. Charities work with exactly the groups this clause names: older people, people with disabilities, people in financial hardship. A fundraising or engagement tool that automatically targets and pressures people because they are vulnerable is precisely what this line is written against. Support your beneficiaries; never let a tool prey on them.

3. Manipulative or deceptive techniques

Also prohibited: AI using subliminal, purposefully manipulative or deceptive techniques that distort someone's behaviour and impair their ability to make an informed decision, causing significant harm. In plain terms — an AI system engineered to trick people into choices they wouldn't otherwise make. Ordinary, honest persuasion is fine; deliberate deception that undermines a person's free choice is not.

4. Social scoring

The Act bans AI that evaluates or classifies people over time based on their social behaviour or personal characteristics, where the resulting "score" leads to detrimental treatment in unrelated contexts or treatment that is unjustified or disproportionate. Most charities won't build such a system — but it's worth knowing if you ever consider ranking service users or applicants by a broad "trustworthiness" or "risk" score drawn from unrelated data.

The remaining prohibitions — untargeted scraping of facial images to build recognition databases, biometric categorisation to infer sensitive traits like race, religion or sexual orientation, predictive-policing profiling, and real-time remote biometric identification in public spaces by law enforcement — are far less likely to appear in charity work. Biometric categorisation is the one to keep a distant eye on if you ever use face- or voice-based analytics.

A five-minute screening you can run

You don't need legal training to do a first pass. For each AI tool your organisation uses — or is about to buy — ask:

  • Does it claim to read emotions, mood, stress or attention of staff, volunteers or learners? → Stop and check.
  • Does it target or pressure people specifically because they are old, disabled, or in financial difficulty? → Stop and check.
  • Is it designed to nudge people through hidden or deceptive means rather than honest information? → Stop and check.
  • Does it build a general "score" about people that could be used against them in unrelated situations? → Stop and check.
  • Does it categorise people by biometric data (face, voice) to guess sensitive traits? → Stop and check.

A "yes" or "not sure" doesn't automatically mean the tool is illegal — some have narrow lawful uses, and the wording matters. It means the tool needs a proper look before you rely on it, ideally with the vendor's written answer and, where the stakes are real, professional advice.

The one-line test: could you explain, in a sentence, why each AI tool you use is not doing any of the five things above? If you can't for a particular tool, that tool is your next thing to check.

Keep a short record of the check

As with the rest of the AI Act, the point isn't just to be clear — it's to be able to show you looked. A single lightweight record does that. It's not filed anywhere; it lives with your own governance notes.

Prohibited-Practice Screening — Internal Record

AI tool What it does for us Any Article 5 flag? Outcome / date checked
[e.g. Fundraising CRM AI] [Suggests donation asks] [Check: does it target vulnerability?] [Confirmed with vendor — no; 20 Jul 2026]
[e.g. HR / wellbeing app] [Staff pulse surveys] [Check: emotion inference?] [Turned off mood-detection feature; 20 Jul 2026]

Review whenever you adopt or change an AI tool, and at least once a year.

Mostly, this is about your suppliers

Very few charities would set out to build a prohibited system. The realistic risk is buying one without realising — a feature buried in a bigger platform, switched on by default, described in marketing language rather than plain terms. That makes Article 5 as much a procurement question as a technical one: before you sign, ask the vendor in writing what the AI does and how, and keep the answer. Knowing exactly where AI sits in your organisation — and what each tool actually does — is the same groundwork the transparency duties will ask of you in August 2026.

How Vedomia can help

Vedomia is an Irish company focused on one thing: helping organisations make their processes and their use of AI visible, explainable and auditable. We work mainly with charities, nonprofits and publicly funded organisations.

Staying clear of prohibited practices starts with the same foundation as every other AI Act duty: knowing exactly where AI lives in your organisation and what each tool really does. That's where we start.

  • Transparency Self-Audit (free). Around 20 questions across four pillars — Visibility, Sequence, Justification, Auditability. It helps you surface where AI is used and where you're thin on understanding, review and evidence.
  • Mapped with you (€1,450, one-off). A single 90-minute session: you describe how one key process really runs, Sandra maps it live, and you leave with a finished, official document — the process end to end, where AI enters it, the evidence to keep and a prioritised 30–90 day plan. No homework, and it begins with a free Clarity Call.

To be clear about what we do and don't do: Vedomia supports readiness, helps you document your AI use, and identifies transparency gaps. We do not certify compliance, we do not assess the legality of any particular tool, and nothing we provide guarantees legal conformity. This is not legal advice.

The good news is that Article 5 mostly tells you what to avoid, not what to build. A short screen of your tools, an answer from each vendor, and a one-line record is enough to know you're on the right side of the hardest line in the Act.

This article is general information about the EU AI Act and does not constitute legal advice.

Prepared with the help of an AI assistant, reviewed by Sandra Fedakova.

Want to see where AI is used across your organisation — and where the gaps are?

Take the Free Transparency Self-Audit