# Prohibited AI Practices Under the AI Act, Examples for Swiss SMEs

> Which AI practices Art. 5 of the EU AI Act prohibits, explained with examples from Swiss SMEs: manipulation, social scoring, emotion recognition, biometrics.

- Source: https://www.sidd.swiss/en/insights/ai-act-prohibited-practices/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dr. Nino Jibuti
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Since 2 February 2025, the AI practices listed in Art. 5 of the EU AI Act have been banned across the EU, with the strictest sanctions in the entire regulation: up to EUR 35 million or 7 percent of global annual turnover (Art. 99(3)). On 4 February 2025 the Commission published guidelines C(2025) 884 final clarifying interpretation. Swiss SMEs are in scope as soon as they place a prohibited system on the EU market, put it into service there, or its output is used in the EU (Art. 2(1)(c)).

This article walks through each of the eight prohibition categories with realistic Swiss SME examples:

- Subliminal manipulation (Art. 5(1)(a))
- Exploitation of vulnerability (Art. 5(1)(b))
- Social scoring (Art. 5(1)(c))
- Predictive policing on a profiling basis (Art. 5(1)(d))
- Untargeted scraping of facial images (Art. 5(1)(e))
- Emotion recognition in the workplace and education (Art. 5(1)(f))
- Biometric categorisation by protected attributes (Art. 5(1)(g))
- Real-time remote biometrics in public spaces for law enforcement (Art. 5(1)(h))

The eight prohibitions are not academic: workplace emotion AI and HR scoring tools are widespread in the SME market, often without the deploying organisations knowing they are using a prohibited practice.

## Subliminal manipulation

Art. 5(1)(a) prohibits AI systems that deploy subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting the behaviour of a person or group by appreciably impairing their ability to make an informed decision, thereby causing or likely to cause significant harm. Three elements must be met cumulatively: subliminal/manipulative, material behavioural distortion, significant harm.

Realistic Swiss SME example: a chatbot AI for debt-counselling acquisition that subliminally embeds litigation threats in rhythmic speech patterns to force contract signatures. Clearly prohibited. Borderline: dark-pattern optimisation in e-commerce checkouts. The Commission guidelines clarify that classic UX optimisation (A/B tests, cognitive load reduction) is not caught by the prohibition unless it systematically causes harm. Personalised pricing in competitive scenarios is not subliminal within (a) but can fall under (b) if it deliberately exploits vulnerable groups.

## Exploitation of vulnerability

Art. 5(1)(b) prohibits exploiting vulnerability based on age, disability or a specific social or economic situation of a person or group of persons, with the objective or effect of materially distorting behaviour and likely to cause significant harm. Unlike (a), the manipulation does not have to be subliminal, it is sufficient that a vulnerable group is deliberately targeted.

Swiss SME examples: an AI-assisted debt collection tool that systematically pressures over-indebted individuals into further loans, prohibited. Ad targeting that singles out "seniors without digital experience" with opaque subscription models, prohibited. A health insurer telephone AI that steers mentally vulnerable insureds towards unsuitable additional cover, prohibited. Borderline: target-group advertising to families with small children for age-appropriate products, not prohibited as long as no harm is inflicted.

## Social scoring

Art. 5(1)(c) prohibits AI-based social scoring by public or private bodies that evaluates or classifies natural persons or groups over time based on social behaviour or known, inferred or predicted personal characteristics, leading to detrimental or unfavourable treatment in contexts unrelated to those in which the data was originally generated or collected, or to unjustified or disproportionate treatment.

The classic example: the Chinese social-credit system. Swiss SME relevance: a customer loyalty programme that uses online behaviour in one context (forum complaint posts) for detrimental pricing in unrelated areas (e.g. insurance premiums of the sister company) falls within the prohibition. Important: not every scoring is social scoring, credit scoring on clearly defined financial criteria within the financial context is allowed (but high-risk under Annex III). What is prohibited is the context crossover with detrimental treatment.

## Emotion AI in the workplace and education

Art. 5(1)(f) prohibits AI systems to infer emotions in the workplace and in education, except for medical or safety purposes. The prohibition is broad and hits SMEs unexpectedly hard. Workplace surveillance tools that use voice analysis on call-centre staff to measure stress or engagement are prohibited. Tools that analyse webcams in online meetings to measure attention of pupils or trainees are prohibited. Recruiting AI that analyses facial expressions in application videos is prohibited.

Exceptions: medical applications (e.g. mood monitoring in a burnout coaching app under medical prescription, certified accordingly) and safety applications (e.g. fatigue detection for machine operators in steel production for accident prevention). The line is narrow: "wellbeing apps" for employees used without a diagnostic indication fall within the prohibition. Swiss SMEs using such tools in HR or online training must review their configuration and, if necessary, change supplier.

## Biometric categorisation and real-time biometrics

Art. 5(1)(g) prohibits biometric categorisation systems that individually classify natural persons based on their biometric data to infer race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation. Sorting biometric datasets in law enforcement contexts remains permitted under strict conditions. Practical relevance for Swiss SMEs: AI tools used in advertising or recruiting platforms with facial recognition to balance the ethnic composition of data pools are affected.

Art. 5(1)(h) prohibits the use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes, subject to three narrow exceptions (targeted search for victims, prevention of an imminent threat of a terrorist attack, identification of suspects of serious offences on a closed list). This provision primarily affects public authorities, not Swiss SMEs. SME relevance: anyone supplying camera infrastructure as a vendor to authorities must verify whether the configuration meets the conditions, supplier obligations under Art. 25 may apply.

## Predictive policing and scraping

Art. 5(1)(d) prohibits AI systems for risk assessment of natural persons to assess the risk of committing a criminal offence based solely on profiling or evaluation of personality traits. Not prohibited is support for human assessments based on objective and verifiable facts directly linked to a criminal activity. Swiss SME relevance is primarily as a supplier of police or judicial software.

Art. 5(1)(e) prohibits untargeted scraping of facial images from the internet or CCTV footage to create or expand facial recognition databases. Best-known example: the Clearview AI model. Swiss SME relevance: every tool combining web scraping with facial analysis is affected. Even a seemingly "soft" use case such as collecting employee photos from LinkedIn to build an internal facial database falls within the prohibition if the scraping is not targeted (with the consent of the individual employee).

## How SIDD supports you

SIDD reviews your AI tools and suppliers for Art. 5 risks. We perform initial classification per system, document the borderline analysis with reference to Commission guidelines C(2025) 884, and, where a prohibition threatens, work out alternative configurations or supplier switches. Where a violation is established, we manage an orderly withdrawal (shutdown, recall, communication to data subjects, authority communication).

More on our AI compliance offering at [Swiss data protection adviser](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) and for EU subsidiaries at [GDPR DPO mandates](https://www.sidd.swiss/en/services/data-protection-officer-eu). For staff awareness, a critical building block, because violations often originate from operational procurement decisions, we combine with [data protection workshops](https://www.sidd.swiss/en/services/data-protection-workshop-sme). To request a fast triage of your deployed AI tools against Art. 5 risks, reach us via the [contact form](https://www.sidd.swiss/en/contact); for a concrete mandate, use our [quote form](https://www.sidd.swiss/en/quote). Anyone placing a prohibited practice on the market risks not only EUR 35 million in fines but also the EU market viability of future AI products.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
