Back to insights
    InsightCommentary

    Article 5 on 2 December 2026: the check a security function runs on its own tooling

    The prohibited-practice list reads as a product problem. A security function's own tooling touches three of its points, and two more start in December.

    AI6 Sept 20265 min read

    Regulation (EU) 2024/1689
    On this page

    What it says

    Article 5 reads like a product problem: things the business must not build or sell. A security function checks the catalogue, finds no social-scoring engine, and moves to the high-risk chapter. That reading skips the estate it runs for itself.

    Article 5(1) prohibits ten lettered practices as consolidated. Points (a) and (b) catch subliminal technique beyond awareness, manipulative or deceptive technique, and the exploitation of age, disability or a social or economic situation, where behaviour is distorted and significant harm follows. Point (c) catches social scoring whose score produces unfavourable treatment out of context or out of proportion. Point (d) catches predicting an offence from profiling or personality traits alone 1.

    Four points sit closer to a security function's own shelves. Point (e) catches systems that create or enlarge a facial recognition database by scraping faces, with no target, from the internet or from CCTV footage. Point (f) catches inferring the emotions of a person at work or in an education institution, unless the intended use is medical or safety 2. Point (g) catches biometric categorisation that deduces race, political or union affiliation, religious or philosophical conviction, sex life, or sexual orientation. It does not cover labelling or filtering of biometric datasets lawfully acquired, nor categorisation of biometric data in law enforcement. Point (h) catches real-time remote biometric identification by law enforcement in spaces open to the public, outside three stated objectives 3.

    Regulation (EU) 2026/1744, the Digital Omnibus on AI, added two points. Point (ba) catches a system that generates or manipulates intimate imagery of an identifiable person without that person's explicit consent. A manipulation adding no exposure and leaving the depicted activity unchanged is not manipulation. Point (bb) catches systems generating child sexual abuse material within Directive 2011/93/EU, Article 2, points (c) and (e), unless a national-law defence applies 4. Placing such a system on the market, or bringing it into service, is caught only where the generation is the intended purpose, or a reasonably foreseeable outcome without adequate safeguard. Use is caught only where the deployer uses it for that purpose 5.

    Chapters I and II have applied since 2 February 2025; the two added points, with Article 5(1a) and (1b), apply from 2 December 2026 6. Article 5 carries the Regulation's heaviest penalty: a ceiling of EUR 35 000 000. For an undertaking it is 7 % of worldwide annual turnover in the previous financial year, whichever is higher 7.

    Read the list as an inventory question. Our reading: three of those points and both new ones reach tooling a security function buys for itself. Identity verification whose gallery was built by untargeted scraping raises point (e); so does collection tooling that harvests faces from open sources. Insider-risk analytics whose stated purpose includes inferring how a person feels raises point (f). Access control that sorts people by biometric traits raises point (g). Article 3 fixes an emotion recognition system and a biometric categorisation system by purpose, not by whether the inference is any good 8. Any generative capability in the security stack raises the two added points.

    What we take from it

    December is a deadline for a screen, not a programme. Before it the security function runs the prohibited-practice test across its own estate and writes the answer down. The scope test orders the questions; Article 5 is the third of them.

    The register row. The AI system register asks for the system owner, the oversight owner, the AI Act role and class, and the triage row that let the system in. A screen with no register row is a conversation. The AI RMF asks the same two things: legal requirements understood, managed and documented, and a resourced mechanism for inventorying systems 9.

    The triage questions. The AI use-case triage form carries an Article 5 screen column already. Four questions belong in it before December. Where did the face gallery come from? Is the stated purpose inference of emotion at work or in education? Which traits does the system deduce? What safeguard stops the two newly prohibited outputs?

    The acceptance record. Article 5 admits no risk acceptance by a deployer: a prohibited practice is not a risk with an appetite, it is a line. The record for a borderline system states the reading, the role that took it, and a review date before December. Article 5 also leaves untouched any prohibition where a practice breaches other Union law 10. So the record carries the data-protection reading beside the AI Act one 11. It also settles what a gallery or training set has to hold at all 12. ISO/IEC 42001 has the place for the result: an AI policy and a documented impact assessment process 13.

    The seam is oversight. Where a system survives on conditions, those conditions are an oversight design, not a policy sentence; human oversight and logging sets out what the design produces. Governance decides which tooling the security function answers for; risk holds the borderline judgement and its review date; compliance later shows the dated screen.

    Where we would push back

    The usual objection: the organisation buys AI rather than building it, so the prohibitions belong to a supplier. Points (e) to (h) reach use directly, and a deployer is an operator like any other. Only the two added points narrow the use prohibition to the deployer's own purpose.

    Two weaknesses in our own argument. The first: the boundaries are contested. Where a security tool sorts a gallery the organisation holds lawfully, point (g)'s carve-out is where honest readers disagree. That is the reason to write the decision down, not postpone it.

    The second is that 2 December 2026 belongs to two points only. Treating it as the Article 5 deadline is the error worth naming: the other eight have bound since February 2025. A first screen run in November is late against a date already passed.

    A board does not need the point letters. One sentence tests it: if a tool the security function bought last year sorts a face gallery by a trait the Act lists, who decided that was lawful, and when?

    Sources

    1. 1EU Publications Office CELEX 02024R1689-20260727 Art. 5(1)(a) to 5(1)(d) · verified 2026-09-06
    2. 2EU Publications Office CELEX 02024R1689-20260727 Art. 5(1)(e) and 5(1)(f) · verified 2026-09-06
    3. 3EU Publications Office CELEX 02024R1689-20260727 Art. 5(1)(g) and 5(1)(h) · verified 2026-09-06
    4. 4EU Publications Office CELEX 02024R1689-20260727 Art. 5(1)(ba), 5(1)(bb) and 5(1b) · verified 2026-09-06
    5. 5EU Publications Office CELEX 02024R1689-20260727 Art. 5(1a) · verified 2026-09-06
    6. 6EU Publications Office CELEX 02024R1689-20260727 Art. 113 point (a) · verified 2026-09-06
    7. 7EU Publications Office CELEX 02024R1689-20260727 Art. 99(3) to 99(5) · verified 2026-09-06
    8. 8EU Publications Office CELEX 02024R1689-20260727 Art. 3(39) and 3(40) · verified 2026-09-06
    9. 9NIST AI 100-1 Table 1, GOVERN 1.1 and GOVERN 1.6, nvlpubs.nist.gov · verified 2026-09-06
    10. 10EU Publications Office CELEX 02024R1689-20260727 Art. 5(8) · verified 2026-09-06
    11. 11ISO/IEC 27002:2022 control 5.34, licensed copy · verified 2026-09-05
    12. 12ISO/IEC 27002:2022 control 8.11, licensed copy · verified 2026-09-06
    13. 13ISO/IEC 42001:2023 Annex A controls A.2.2 and A.5.2, licensed copy · verified 2026-09-05