Skip to main content
Deliberate AcademyProfessional AI Education
~19 min left
Lesson 3 of 9
19 min read10 XP

Prohibited and High-Risk AI Use Cases Under the EU AI Act

Deliberate Academy Editorial Team

Reviewed for accuracy and professional relevance

You're 3 lessons in — don't lose your progress.

Sign up free
What you'll learn
  • List the categories of AI practice the EU AI Act prohibits outright, and explain why no conformity measure can make a prohibited practice compliant
  • Apply a prohibited-use screening step as the first gate in any AI system review, before a full risk classification is attempted
  • Identify concrete, domain-specific examples of high-risk AI use cases across employment, essential services, education, and biometric processing
  • Explain the enforcement consequence that distinguishes a prohibited-practice violation from a high-risk conformity gap

The distinction between "prohibited" and "high-risk" is not a matter of degree — it is a different kind of regulatory response entirely. A high-risk system can become compliant: you build the technical file, the risk management process, the human oversight controls, and you proceed. A prohibited practice cannot become compliant by adding controls. No amount of documentation, human oversight, or risk mitigation makes a banned practice lawful — the only remedy is not to deploy it in that form. Getting this distinction wrong in a risk classification workshop is the single most consequential error a compliance team can make, because it treats an unfixable problem as a fixable one.

The Prohibited Practices

The Act sets out a defined list of AI practices considered to carry unacceptable risk. The categories, described structurally rather than by exact legal wording, include:

  • Manipulative or deceptive techniques that materially distort a person's behavior in a way likely to cause significant harm, operating below the threshold of conscious awareness or exploiting a person's inability to make an informed decision
  • Exploitation of vulnerabilities related to age, disability, or specific social or economic situation, in a manner likely to cause significant harm
  • Social scoring by public authorities that evaluates or classifies people based on social behavior or characteristics, leading to detrimental or unfavorable treatment unrelated to the context in which the data was originally generated, or disproportionate to the behavior itself
  • Individual crime-risk prediction based solely on profiling — predictive policing approaches that assess an individual's likelihood of committing a criminal offense based purely on personality traits or characteristics, without an objective, verifiable factual basis tied to actual criminal activity
  • Untargeted scraping of facial images from the internet or CCTV footage to build or expand a facial recognition database
  • Emotion inference in workplace and education settings, with narrow carve-outs for medical or safety purposes
  • Biometric categorization to infer sensitive attributes — race, political opinion, trade union membership, religious or philosophical belief, sex life, or sexual orientation — from biometric data, with a narrow law-enforcement carve-out
  • Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, permitted only in narrowly defined and authorized circumstances such as searching for a specific victim, preventing an imminent and specific threat to life, or pursuing a serious crime
Warning

Enforcement for prohibited-practice violations sits at the Act's highest penalty tier — structured, broadly, as the greater of a large fixed amount or a percentage of global annual turnover, higher than the penalty tier that applies to most high-risk conformity failures. Treat prohibited-use screening as a gate that happens before, and separately from, your risk classification workshop — do not let a system's promising business case carry it into a full conformity build-out before you have confirmed it does not fall on this list. The specific fine figures are subject to periodic regulatory clarification; verify current amounts with official guidance rather than relying on a remembered number.

Clearview AI, a real facial-recognition company, is a useful illustrative case of the kind of practice the untargeted-scraping prohibition targets: the company built a facial recognition database by scraping billions of images from the public internet without the consent of the people pictured, and faced regulatory enforcement action from data protection authorities in several EU member states over this practice — action that, at the time, proceeded primarily under data protection law, and illustrates exactly the pattern the Act's specific prohibition on untargeted facial-image scraping is now designed to address directly.

A Near-Miss on Workplace Emotion Analytics — Contact Center Operator

AI Governance Lead, outsourced contact center operator (18,000 agents across six countries)

Context

A contact center operator evaluated a vendor tool that analyzed agent voice tone and facial expression during customer calls in real time, intended to flag agents who appeared stressed or disengaged so a supervisor could intervene. The business case was framed around agent wellbeing and call-quality improvement, and the pilot had executive sponsorship and a signed vendor contract pending only a compliance sign-off.

Action

The AI Governance Lead ran the tool through the prohibited-use screen before beginning a conformity classification, and identified that the tool performed emotion inference on employees in a workplace setting — squarely within the prohibited-practices category, with no applicable medical or safety carve-out in this deployment. She escalated to legal and paused the vendor onboarding process before contract execution, rather than after a conformity build-out had already consumed budget and stakeholder goodwill. The business case was redirected toward a call-quality analytics tool that assessed call content and adherence to script rather than the agent's inferred emotional state — a design change that avoided the prohibited category entirely while still addressing the underlying quality objective.

Outcome

The redirected tool was deployed nine weeks later with no compliance objection, having avoided a practice the organization would otherwise have had to unwind after a signed contract and an executive-sponsored pilot — a materially more expensive and reputationally damaging outcome than a pre-contract screening catch. The AI Governance Lead's assessment was that the near-miss demonstrated the value of running the prohibited-use screen first, as a fast, cheap gate, rather than folding it into the longer and more resource-intensive full risk classification process.

Knowledge check

A retailer wants to deploy an AI tool that analyzes in-store camera footage to infer customers' emotional state as they browse, in order to tailor promotional displays in real time. How should a compliance team classify this proposal?

Select one answer.

High-Risk Use Cases, Domain by Domain

Building concrete pattern recognition for high-risk domains speeds up classification meaningfully. Common, illustrative examples include:

Employment and worker management. CV-screening and candidate-ranking tools, automated interview scoring (the kind of function HireVue's platform performs), algorithmic task allocation and performance monitoring systems, and AI used in promotion or termination decisions.

Access to essential services. Credit scoring and loan underwriting tools, insurance risk pricing and claims-eligibility tools, AI used to determine eligibility for public benefits, and AI used in emergency-service dispatch triage.

Education and vocational training. AI used to score exams or assessments, AI used in university or program admissions decisions, and AI used to evaluate or monitor students during testing.

Biometric identification and categorization. Systems that identify individuals from biometric data outside the narrow law-enforcement exceptions, and categorization systems that infer sensitive attributes, where they fall outside the prohibited-practices carve-outs described above.

Critical infrastructure. AI systems functioning as safety components in the management or operation of critical infrastructure such as water, energy, or transport networks.

Law enforcement, migration, and the administration of justice. AI tools used to assess evidence reliability, assist in individual risk assessment in criminal proceedings, support migration and asylum decision-making, or assist judicial authorities in researching or interpreting facts and law.

Tip

Build a short, memorable domain checklist your organization can apply quickly during intake for any new AI project: employment, credit or insurance, education, biometric processing, critical infrastructure, law enforcement or justice, and migration. If a proposed AI use case touches any of these domains, route it directly into the full classification and conformity process before any procurement commitment is made — treating domain match as a fast triage signal, not a final determination, keeps the compliance team from becoming the deployment bottleneck for the vast majority of use cases that do not touch these areas.

Quick check

A university deploys an AI proctoring tool that monitors students during remote exams via webcam and flags unusual eye movement or background noise as potential indicators of cheating, with a human reviewer making the final academic integrity determination. How should this be classified?

Select one answer.

Exercise

~15 min

Your Task

Review the following five proposed AI use cases and classify each as prohibited, high-risk, or neither, with one sentence of reasoning: (1) an AI tool that infers a job applicant's likely tenure and flight risk from social media activity scraped without consent; (2) an AI chatbot that answers customer billing questions and clearly discloses it is an AI system; (3) an AI tool used by a public authority to assign a general trustworthiness score to citizens based on unrelated past behavior, used to determine eligibility for a range of unrelated government services; (4) an internal AI tool that drafts first-pass marketing copy for a retailer, reviewed by a human editor before publication; (5) an AI tool used by a mortgage lender to generate an automated approve/decline recommendation reviewed by an underwriter.

Success looks like

  • Use case 1 is identified as raising a serious prohibited-practice or exploitation concern requiring urgent legal escalation, not treated as a routine high-risk classification
  • Use case 3 is correctly identified as matching the social-scoring prohibition pattern
  • Use cases 2 and 4 are correctly identified as not high-risk (limited-risk transparency and minimal-risk respectively), while use case 5 is correctly identified as high-risk

Watch out for

  • Treating every use case involving personal data as automatically high-risk or prohibited — the domain and mechanism matter, not the mere presence of personal data
  • Missing the social-scoring pattern in use case 3 because it is described using a business term like "trustworthiness score" rather than the word "social score"
  • Assuming a human review step automatically resolves classification concerns for use case 5, rather than treating it as one required control within the high-risk regime

Hint

For use case 3, ask whether the score is being used for a purpose unrelated to the context in which the underlying behavior was observed, and whether it leads to broadly disadvantageous treatment across unrelated services — that combination is the core of the social-scoring prohibition pattern.

Key takeaways
  • Prohibited practices and high-risk use cases require fundamentally different responses — a high-risk system can be made compliant through conformity controls, while a prohibited practice has no compliant version and must not be deployed in that form.
  • The prohibited-practices list covers manipulative or exploitative techniques, social scoring, individual crime-risk profiling, untargeted facial-image scraping, workplace and education emotion inference, sensitive-attribute biometric categorization, and real-time remote biometric identification in public spaces outside narrow law-enforcement exceptions.
  • Run a fast prohibited-use screen as the first gate on any new AI proposal, before committing to procurement or a full conformity build-out — catching a prohibited practice before contract signature is far cheaper than unwinding it afterward.
  • High-risk domains recur across employment, essential services, education, biometric processing, critical infrastructure, and law enforcement/justice — building pattern recognition across these domains speeds up accurate classification significantly.
  • Enforcement consequences differ by category — prohibited-practice violations sit at the Act's highest penalty tier — which is exactly why the prohibited-use screen deserves priority attention over general risk triage.