Governance & Approval
Prohibited AI Practice Screening and Approval
What this control does
Screen proposed AI systems and use cases for prohibited practices before procurement, development, deployment or material change.
How to implement
Apply this screening before acquiring, developing or materially changing an AI use case.
- Describe what the system will actually do, who may be affected and how it will be used. Do not rely only on a supplier's general product description.
- Compare the proposed use with the relevant Article 5 prohibition and its specific conditions. Record the legal source and version considered.
- Prevent a potentially prohibited use from proceeding until the responsible reviewer resolves the issue. An internal approval cannot authorize a prohibited practice.
- Where a narrow exception is relied on, document why it applies and obtain any required external authorization. Re-screen when the use or the law changes. Application dates and exceptions must be checked in the linked obligation; they are not identical for every prohibited practice.
Suggested timing and triggers
Before procurement, development, release or deployment; after material changes to purpose, capability or applicable requirements.
Evidence examples
Completed use-case screening with system and intended use identified Decision record citing the relevant prohibition and conditions Documented exception analysis and external authorization where required Records of rejected, restricted or redesigned uses Re-screening and escalation records
How to check this control
Select an approved use and a rejected or restricted use. Check whether the decision addresses the actual activity and relevant conditions, and whether restrictions are implemented. Confirm that a changed use case would trigger a new review.
Related EU AI Act obligations
Article 5(1)(a)
Do Not Use Manipulative or Deceptive AI Practices That Cause Significant Harm
Article 5(1)(b)
Do Not Exploit Vulnerabilities Using AI in a Manner That Causes Significant Harm
Article 5(1)(ba), 5(1a)-(1b)
Do Not Generate or Manipulate Non-Consensual Intimate Content Using AI
Article 5(1)(bb), 5(1a)
Do Not Generate or Manipulate Prohibited Child Sexual Abuse Material Using AI
Article 5(1)(c)
Do Not Use Prohibited AI-Based Social Scoring
Article 5(1)(d)
Do Not Predict Individual Criminal Risk Solely From Profiling or Personality Characteristics
Article 5(1)(e)
Do Not Create or Expand Facial Recognition Databases Through Untargeted Image Scraping
Article 5(1)(f)
Do Not Use AI Emotion Recognition in Workplaces or Educational Institutions Except for Permitted Purposes
Article 5(1)(g)
Do Not Use Prohibited Biometric Categorisation to Infer Sensitive Characteristics
Article 5(1)(h), 5(2)-(7)
Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted