Article 5: Prohibited AI practices
Bans manipulation, social scoring, some biometric uses and scraping (since 2025); from 2 Dec 2026 also AI generating non-consensual intimate content.
Obligations under this article
New from 2 December 2026: two further prohibitions
Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force 27 July 2026) inserts two new points into Article 5(1) and two scope paragraphs, Art. 5(1a) and (1b). Amended Article 113(3)(a) makes them apply from 2 December 2026 — the same day as the Art. 50(2) grace period ends. The original Article 5 prohibitions have applied since 2 February 2025 and are unchanged. This summary is not legal advice.
What is prohibited (Art. 5(1)(ba) and (bb))
- Non-consensual intimate material (Art. 5(1)(ba)): placing on the market, putting into service or using an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable person’s intimate parts, or of an identifiable person engaged in sexually explicit activities, without that person’s freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation.
- Child sexual abuse material (Art. 5(1)(bb)): placing on the market, putting into service or using an AI system that generates or manipulates material or performance within the meaning of Art. 2(c) and (e) of Directive 2011/93/EU, except where a “without right” defence applies under national law (e.g. law-enforcement activity, or red-teaming to test a system’s compliance with this prohibition — recital 13).
Who is caught — the Art. 5(1a) and (1b) scope rules
Providers (placing on the market / putting into service) are prohibited only where (i) that generation or manipulation is the system’s intended purpose, or (ii) the system’s design, training, architecture, capabilities or user-facing functionalities make it a reasonably foreseeable and reproducible outcome without significant technical modification, and the system lacks reasonable and adequate technical safety measures and other safeguards to reliably prevent it (taking reasonably foreseeable misuse into account) and to correct observed or reported misuse. Deployers are prohibited only where they use the system for the purpose of generating or manipulating such material. Under Art. 5(1b), editing that does not increase the exposure of depicted intimate parts or alter the nature of depicted sexually explicit activity does not count as manipulation for point (ba).
Why this matters beyond the obvious: a general-purpose image, video or audio generator is not a “nudification app”, yet it can still fall under (ii) if the prohibited output is a reproducible outcome and the safeguards are inadequate. Article 5 breaches carry the highest fine tier in the Act (Art. 99(3)).
Evidence an auditor or market-surveillance authority would expect
- A dated intended-purpose statement for the generative system and the user-facing functionalities it exposes.
- A misuse risk assessment covering reasonably foreseeable misuse for (ba)/(bb) outputs, with the technical safety measures chosen (input/output filters, prompt and image classifiers, refusal behaviour, provenance controls) and evidence they were tested.
- Records of observed or reported misuse and the corrective action taken — the law expects correction, not just prevention.
- For deployers: documented purpose of use and acceptable-use controls showing the system is not used for the prohibited generation.
Fails an audit
- Relying on terms of service alone, with no technical safeguard against the prohibited output.
- Safeguards exist but there is no test evidence that they reliably prevent the output, or no process to correct reported misuse.
- No record of when the system was placed on the market or of its intended purpose.
- Treating 2 December 2026 as a “grace period” to keep shipping an unsafeguarded generator — the date is when the prohibition starts to apply, and criminal law may apply already (recital 15).
Primary text: Regulation (EU) 2026/1744, points (7) and (40) (Official Journal), amending Regulation (EU) 2024/1689. See the timeline for the 2 December 2026 node.
Legal source
Art. 5 AIA · Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force 27 July 2026
Stay audit-ready as the Act changes
EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.
Subscribe — free, weeklyNot legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.