Mein kostenloses KI-Audit buchen
    Wir verwenden Cookies, um die Nutzung der Website zu analysieren und Ihr Erlebnis zu verbessern. Ohne Ihre Zustimmung findet kein Tracking statt.

    EU AI Act Article 5: 10 Banned AI Practices in 2026

    (Aktualisiert am )
    AI Compliance
    EU AI Act Article 5: 10 Banned AI Practices in 2026

    Quick answer: Article 5 of the EU AI Act bans eight AI practices outright — among them subliminal manipulation, exploiting vulnerable groups, social scoring, profile-only predictive policing, untargeted facial-image scraping and workplace emotion recognition — and those prohibitions have applied since 2 February 2025. Two more join the list on 2 December 2026, added by Regulation (EU) 2026/1744: AI systems used to generate non-consensual intimate imagery ("nudification" applications) and child sexual abuse material. Article 5 carries the Act's heaviest penalty — up to €35 million or 7% of worldwide annual turnover, whichever is higher, with SMEs facing the lower of the two under Article 99(6). Audit your chatbots, HR tools, marketing optimisers and camera platforms for accidental exposure now.

    Last verified 7 August 2026.

    Most of the Luxembourg AI Act conversation in 2026 has been about high-risk systems, GPAI obligations, and the AI literacy duty. We have covered each in turn — the corrected timeline of what actually applies now, the high-risk systems roadmap, the GPAI / foundation-model breakdown, and the Article 4 AI literacy obligation. The piece almost no Luxembourg company has read closely is the shortest and the strictest part of the Act: Article 5. It does not regulate — it prohibits.

    Two timing points that matter, because they are the opposite of what most 2026 commentary says:

    • Article 5 was never on the August 2026 clock. The prohibitions have bound you since 2 February 2025, and the Article 99 penalty regime has been applicable since 2 August 2025. There was no grace period waiting to expire.
    • The Digital Omnibus on AI deferred the high-risk regime, not this one. Regulation (EU) 2026/1744, in force since 27 July 2026, moved stand-alone Annex III high-risk obligations to 2 December 2027. It moved nothing in Article 5 — it added to it.

    So for any company pursuing AI implementation in Luxembourg, this is the article to check first, not last: it is the one where you can already be non-compliant, at the highest penalty band, inside a chatbot, an HR tool, a marketing optimiser or a security camera platform.

    Unsure how an Article 5 exposure check applies to your systems? Book a free 30-minute assessment — no sales pitch, just a plain-language read on your exposure.

    The penalty makes this the most expensive Article in the Act

    Article 5 carries the heaviest financial sanction in the regulation: up to €35 million or 7% of worldwide annual turnover, whichever is higher. That is materially above the high-risk-systems and Article 50 penalty band (€15 million / 3%) and above the GPAI band — see our guide to the full AI Act penalty ladder in Luxembourg for how the bands stack up. The drafters chose this consciously: these are the uses considered incompatible with EU fundamental rights, full stop.

    One correction worth carrying to your board. Article 99(6) reverses the rule for SMEs and start-ups: they face the lower of the fixed amount and the percentage. A Luxembourg SME with €30 million turnover is exposed to €2.1 million on this tier, not €35 million. The omnibus extended a comparable lower cap to small mid-caps on the second and third tiers. Still existential for most companies here — but the honest number, not the headline one.

    The way to think about Article 5 is not "compliance risk" in the usual sense. It is closer to a hard product-design constraint: a class of features that cannot exist in your AI stack, regardless of how commercially attractive they might appear.

    The eight prohibited practices, in plain language

    The Act is dense; the substance is not. Here is what each prohibition actually means and where Luxembourg companies most often drift toward it.

    1. Subliminal, manipulative or deceptive techniques that materially distort behaviour

    AI systems that use techniques operating below the threshold of a person's awareness — or are deliberately manipulative or deceptive — and that cause the person to make a decision they would not otherwise have made, with significant harm. This is broader than it sounds. Conversion-rate-optimisation AI that personalises against a user's documented biases to push purchases the user genuinely cannot afford is in scope. So is a "support" chatbot designed to appear human, where the deception itself drives a contractual decision.

    Where Luxembourg companies drift: aggressive ML-driven nudging in fintech onboarding flows, or "AI advisor" framing of what is actually a paid-distribution recommendation engine. The fix is usually a transparency redesign rather than killing the product.

    2. Exploiting vulnerabilities (age, disability, socio-economic situation)

    AI systems that exploit a vulnerability of a specific group — minors, people with disabilities, people in precarious economic situations — to materially distort their behaviour with likely harm. This is a stricter cousin of (1) and does not require subliminal techniques: aiming the manipulation at a protected group is enough.

    Where Luxembourg companies drift: insurance and credit cross-sell models that materially over-target people the data flags as financially stretched. The internal "this segment converts 4× better" memo is the smoking gun in the post-incident audit.

    3. Social scoring by public authorities or on their behalf

    AI-driven evaluation or classification of natural persons based on social behaviour or personal characteristics, where the scoring leads to detrimental or unfavourable treatment in unrelated contexts or in a way that is unjustified or disproportionate.

    Where Luxembourg drifts: this is mostly a public-administration concern (see our communes AI guide for the cleaner side). Private firms rarely meet the "by or on behalf of public authorities" trigger, but a CSSF-supervised firm running cross-product, cross-context customer-quality scoring should still pressure-test it against this language — even if Article 5(3) does not formally apply, the spirit of it foreshadows where enforcement attention will land.

    4. Predictive policing of individuals based solely on profiling

    AI used to assess or predict the risk of a person committing a criminal offence, solely on the basis of profiling or personality traits. The word "solely" matters — there is a narrow carve-out where the assessment supports a human investigator working from objective, verifiable facts directly linked to a criminal activity. The blanket profile-only system is banned.

    Where Luxembourg drifts: AML/fraud monitoring is not prohibited — but if your AML model produces a "high-risk person" output that drives a customer-life-cycle decision without a verifiable factual nexus, you are in dangerous territory. Document the factual basis, document the human-in-the-loop.

    5. Untargeted scraping of facial images for biometric databases

    Building or expanding facial-recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

    Where Luxembourg drifts: rarely intentionally, but the retail-security and physical-security sectors sometimes inherit vendor stacks that quietly do this. A short audit of any computer-vision vendor's training-data provenance is the right safeguard — the vendor due-diligence checklist covers exactly this kind of question.

    6. Emotion recognition in the workplace and in education

    AI inferring emotions of natural persons in workplaces or educational institutions — outside narrow medical or safety carve-outs. This bites broader than HR-tech vendors realise.

    Where Luxembourg drifts: "engagement scoring" in remote-work monitoring tools, sentiment-analysis dashboards over Teams/Zoom calls for sales coaching, AI proctoring in employee training platforms. Any of these in a Luxembourg workplace context are already prohibited — this is not a future deadline, and the remediation is removal or restructuring, not disclosure.

    7. Biometric categorisation inferring sensitive attributes

    Biometric categorisation systems that categorise individuals based on biometric data to infer race, political opinions, trade-union membership, religious or philosophical beliefs, sex life, or sexual orientation. Filtering of legally acquired biometric datasets in law-enforcement contexts has a narrow carve-out; everything else is prohibited.

    Where Luxembourg drifts: marketing-tech audience-builder products that quietly use facial analysis to infer demographic attributes. Rare in Luxembourg-headquartered stacks but common in inherited US-built ad-tech components. Worth a deliberate vendor scan.

    8. Real-time remote biometric identification in publicly accessible spaces (for law enforcement)

    This one is overwhelmingly a public-sector concern with narrow law-enforcement carve-outs subject to judicial authorisation. Private Luxembourg firms are almost never the deployer — but they can be the provider if their product is sold into that use case. If you are building computer-vision tooling and any of your buyers are in this category, the obligations on you as a provider are significant.

    The two new prohibitions — applicable 2 December 2026

    Regulation (EU) 2026/1744 added two entries to Article 5, applicable from 2 December 2026:

    9. AI systems used to generate non-consensual intimate imagery

    The so-called "nudification" applications: systems whose purpose or effect is to produce sexualised imagery of a real person without their consent. Prohibited outright, top penalty band.

    10. AI systems used to generate child sexual abuse material

    Also prohibited outright, at the same band.

    Where Luxembourg firms should pay attention: almost no Luxembourg business is anywhere near either of these deliberately. The exposure is indirect and it belongs to one specific group — companies that expose general image-generation capability to third parties. If you ship a product with an image model behind it, or resell one under your own brand, your abuse-prevention controls stopped being a trust-and-safety nicety on 2 December 2026 and became a matter of Article 5 exposure at 7% of turnover. Document the controls, document the testing, and put the evidence in the same defence file as the rest of this audit. If you are the provider of that system under the provider/deployer test, the exposure is yours and not your model vendor's.

    How to run an Article 5 audit in three meetings

    A pragmatic, week-long internal sweep:

    Meeting 1 — Inventory (60 minutes, product + IT + DPO). List every AI feature in production and in pilot, including the ones built by marketing and HR without IT involvement. The undocumented "shadow AI" is where Article 5 problems almost always sit. The AI literacy framework from Article 4 helps here: the team that has had the training is the team that surfaces these.

    Meeting 2 — Map (90 minutes, same group + a legal reviewer). Walk each item against the eight prohibitions. Most items are obviously safe; a small number trigger the "let's check" instinct. Document the reasoning either way — that document is your defence file.

    Meeting 3 — Decide (60 minutes, with the management member who can shut a feature down). For each flagged item: keep with documented justification, restructure to remove the prohibited element, or kill. Budget questions sometimes resurface here — see our AI implementation cost guide for the framing.

    Three meetings, one short defence file. That is the entire Article 5 compliance exercise for the typical Luxembourg SME or mid-cap.

    Not sure which obligations are yours? Book a free 30-min call and we'll map an Article 5 exposure check to your systems in one conversation.

    How this fits inside the wider AI Act file

    Article 5 is the prohibition layer. Everything else sits on top of it, governing the much larger universe of AI uses that are permitted but regulated. The right mental model is concentric, and each ring now has its own date:

    • Innermost circle — Article 5 prohibitions: uses that cannot exist. Live since 2 February 2025; two additions on 2 December 2026.
    • Second ring — Article 50 transparency: disclosure duties on providers and deployers of systems that interact with people or generate content. Live since 2 August 2026.
    • Third ring — high-risk systems (Annex III): uses that must be heavily documented and governed. Deferred to 2 December 2027 by the omnibus; product-embedded AI to 2 August 2028 (see the high-risk roadmap).
    • Outer ring — GPAI obligations: duties on foundation-model providers, enforceable by the Commission since 2 August 2026 (see the GPAI breakdown).
    • All of it — Article 4 literacy: the staff-readiness baseline, live since February 2025 and softened to a duty of means by the omnibus.

    For CSSF-supervised firms, the DORA + AI Act overlap sits parallel to all of this and the documentation expectations compound rather than substitute.

    Führen Sie ein Luxemburger KMU?

    Buchen Sie ein kostenloses 30-minütiges KI-Audit — wir sagen Ihnen ehrlich, wo sich KI für Sie lohnt und wo nicht.

    Kostenloses KI-Audit buchen

    The Luxembourg context: who will actually ask

    An earlier version of this article put ILNAS in the lead. That was wrong, and it is worth correcting plainly.

    Luxembourg's designation runs through bill of law n°8476, deposited on 23 December 2024 and still in the parliamentary process at the time of writing. Under it:

    • The CNPD is the national competent authority, the single point of contact, and the market surveillance authority by default — including for Article 5 questions where no sectoral regulator has the file. The CNPD would also operate Luxembourg's Article 57 regulatory sandbox.
    • The CSSF covers AI systems in the financial sector, the CAA covers insurance, and the ILR covers high-risk AI at NIS2 essential and important entities.
    • ILNAS is the notifying authority for conformity assessment bodies — a specific and narrower role than general market surveillance.

    Practical implication for a regulated Luxembourg firm: expect Article 5 questions to arrive through the CNPD and, in parallel, through your sectoral regulator via the existing supervisory relationship.

    The early-enforcement profile we expect — based on how the DSA and DMA played out — is targeted, high-profile, and used to set the tone rather than to fill a quota. The first published Luxembourg enforcement action under Article 5 will be a calibration message. The right place to be is two steps away from it, with the defence file already written.


    Get the Article 5 sweep done — inside a register you can actually use

    The Article 5 sweep is a week of work. Done on its own it produces a defence file. Done as the first cut of a full AI inventory it produces a defence file and the register that every other part of the AI Act needs.

    The 20 More AI Act Readiness Assessment. Ten working days, fixed scope:

    1. The AI system register — an inventory of every AI use in the organisation, including the tools marketing and HR bought without IT, with the provider-or-deployer determination per system.
    2. The Article 5 defence file — an explicit prohibition assessment per item across all ten prohibitions, the decision (keep / restructure / kill), the reasoning, and the record of management approval. Dated and signed.
    3. The Article 50 gap report — the disclosures legally due on your products today, mapped to the exact chatbots, voice agents, screens and published content missing them.
    4. The Annex III exposure list — what becomes high-risk on 2 December 2027, which systems the Article 6(3) filter removes and why, and a costed work programme against that date.

    The same exercise typically surfaces the next two or three highest-ROI AI workloads to add — because a complete inventory is also a roadmap.

    See the AI Act readiness service, or book the 30-minute scoping call. Almost no Luxembourg company we have walked into in 2026 has run an Article 5 sweep. It takes a week and it closes the most expensive article in the regulation.


    Related reading:

    Ist Ihr KI-Projekt für bis zu 70 % Luxemburger Förderung qualifiziert?

    Bis zu 17.500 € pro Projekt. Sofortige Schätzung — 4 kurze Fragen, keine E-Mail nötig.

    Förderung prüfen (2 Min.)

    Bereit, das umzusetzen?

    Zwei Wege zum Start — wählen Sie, was zu Ihrem Zeitplan passt.

    Tags:
    Luxembourg
    EU AI Act
    Article 5
    Compliance
    Governance

    Verwandte Ressourcen

    KI-Implementierung in Luxemburg

    Unser umfassender Leitfaden zu KI-Einführung, Implementierung und Governance in Luxemburg.

    Leitfaden lesen

    Mit einem KI-Berater in Luxemburg arbeiten

    Sehen Sie, was wir bauen, was es kostet und wie Projekte bis zu 70 % KMU-Kofinanzierung erhalten.

    KI-Berater in Luxemburg