Prohibited AI practices (Art. 5)
Binds All providers & deployers of AI systems in the EU. Bans on social scoring, manipulative AI, untargeted scraping.
Stated maximum penalty — Up to 7% global turnover or €35M
Topic dossier
The AI uses that are forbidden outright — manipulative systems, social scoring, non-consensual intimate imagery and algorithmic price coordination — regardless of safeguards. 16 obligations across 5 jurisdictions — 10 in force, 2 proposed. Next dated deadline: 2 Dec 2026.
Above the risk tiers sits a smaller set of outright bans. The EU AI Act’s Article 5 is the broadest: it prohibits social scoring, manipulative and exploitative systems, untargeted facial-image scraping and more. Texas, Peru and the US TAKE IT DOWN Act add their own prohibitions. A second, newer family bans a specific commercial use of algorithms rather than a technique: New Jersey and Illinois forbid software that coordinates residential rents between competing landlords, and Maryland forbids setting retail food prices from an individual shopper’s personal data. These are the lines that hold regardless of safeguards or consent.
Binds All providers & deployers of AI systems in the EU. Bans on social scoring, manipulative AI, untargeted scraping.
Stated maximum penalty — Up to 7% global turnover or €35M
Binds All providers / deployers of such AI systems. New Art. 5 prohibition added by Digital Omnibus (Reg. EU 2026/1744, OJ L 2026/1744 published 24 Jul 2026); prohibits AI generation of CSAM and non-consensual intimate imagery. Applies from 2 Dec 2026.
Prohibition introduced by Regulation (EU) 2026/1744; the new Article 5 prohibition applies from 2 December 2026.
Stated maximum penalty — Up to 7% turnover or €35M
Binds Anyone publishing non-consensual intimate imagery; covered online platforms (notice-and-removal). Bans non-consensual intimate imagery incl. AI deepfakes; covered platforms must remove within 48h (notice-and-removal duty live 19 May 2026).
Stated maximum penalty — FTC enforcement; criminal penalties
Binds Persons developing/deploying AI in Texas or serving Texas residents; state agencies. Bans manipulative/discriminatory AI; AG-enforced.
Stated maximum penalty — Up to $200k/violation; $40k/day
Binds Any person creating, distributing, or facilitating AI-generated/manipulated likenesses of Washington residents. Prohibits creating or using AI-generated forged digital likenesses without consent; amends WA Personality Rights Act.
Stated maximum penalty — $3,000/violation + noneconomic damages; private right of action
Binds Any individual or business providing therapy or psychotherapy services in Rhode Island. Prohibits providing therapy or psychotherapy services in Rhode Island unless conducted by a licensed professional; effectively bans AI-only therapy chatbots.
Signed by Governor McKee June 22, 2026; effective upon passage.
Stated maximum penalty — RI licensing enforcement
Binds Any person creating or deploying AI systems available in Tennessee. Prohibits AI systems from claiming to function as qualified mental health professionals.
Stated maximum penalty — $5,000 per violation (Consumer Protection Act)
Binds Public school evaluators and teachers subject to Illinois teacher evaluation requirements. Prohibits evaluators from using AI to assign numerical scores or qualitative ratings in teacher performance evaluations; prohibits teachers from using AI to generate evaluation evidence. AI may still assist with administrative tasks. Teachers must disclose AI tool name and purpose if used for support.
Signed 2026-07-10 by Governor Pritzker; effective 2027-01-01.
Stated maximum penalty — Administrative enforcement; no direct monetary penalty specified
Binds Residential rental property owners and algorithmic revenue management software coordinators operating in New Jersey. Prohibits residential landlords and algorithmic revenue-management software coordinators from using algorithms that share competing landlords' nonpublic pricing data to recommend rents; bans parallel pricing coordination via software.
Signed 2026-07-20 by Gov. Mikie Sherrill; effective first day of the twelfth month following enactment (2027-07-01).
Stated maximum penalty — NJ Antitrust Act enforcement (P.L.1970, c.73); AG complaint portal required; penalty as provided under NJ Antitrust Act
Binds Health insurance issuers and managed care organizations in Illinois (excludes self-insured ERISA plans and workers' compensation). Prohibits health insurers and managed care organizations from using algorithms or automated tools to downcode medical claims without comprehensive human review; requires AMA CPT coding guideline-compliant physician review of all downcoding determinations; bans discriminatory targeting of providers treating complex/chronic patients.
Signed 2026-07-10 by Governor Pritzker; effective 2028-01-01.
Stated maximum penalty — Fines, restitution, or license suspension (IL Department of Insurance enforcement)
Binds Food retail stores ≥15,000 sq ft selling tax-exempt food, and third-party delivery service providers arranging delivery from such stores, operating in Maryland. First US state law banning AI-driven personalised (surveillance) pricing in food retail and delivery; prohibits setting prices based on individual consumer personal data.
EXCLUDED FROM ACTIVE COVERAGE — CEO ruling AIL-136 (2026-08-03): all AI/algorithm language was deliberately struck from HB 895 before enactment. The enacted Ch. 154 prohibits personalized data-driven pricing for tax-exempt food (retailers ≥15,000 sq ft + food delivery); no AI definition, no near-real-time AI dynamic-pricing clause, no §13-322 algorithmic-pricing disclosure. Enacted operative line is personal data, not AI. Narrow food scope, regulatory-only, no private right of action. Fails coverage prong (a): AI is not load-bearing in enacted text. REVERSAL TRIGGER: re-escalate to CEO if AI/algorithm language is re-introduced in a future MD legislative session, or if personalized/surveillance pricing becomes an AI-governance flashpoint with AI-specific statutory language.
Stated maximum penalty — Up to $10,000 per violation; up to $25,000 per violation for repeat offenders (Maryland AG enforcement)
Binds Landlords of residential units in Illinois and third-party algorithmic pricing service providers who facilitate rental price coordination. Amends the Illinois Antitrust Act to prohibit landlords and third-party services from using AI algorithms to coordinate residential rental pricing; specifically targets algorithmic platforms (e.g., RealPage) used by competing landlords to fix or stabilize rents.
The AI rental-pricing language no longer exists in this bill vehicle. Senate Floor Amendment No. 1 (adopted 2026-05-21) had added the algorithmic rental-price-coordination ban described above, but House Committee Amendment No. 1 (filed 2026-05-28, adopted 2026-05-29) replaced that content entirely with unrelated Cook County / Calumet City eminent-domain (quick-take) provisions for economic development. Governor Pritzker signed the bill on 2026-08-07 as Public Act 104-0805; the enacted text contains no AI or algorithmic-pricing provisions.
Stated maximum penalty — Illinois Antitrust Act — civil penalties (enforcement by Illinois AG)
Binds Any person in the UK who creates or requests creation of a non-consensual intimate deepfake image. Section 138 of the Data (Use and Access) Act 2025 inserts ss.66E–66H into the Sexual Offences Act 2003, criminalising the creation of non-consensual 'purported intimate images' (deepfakes) and the act of requesting such creation, even if the image is never distributed.
In force February 6, 2026 per SI 2026/31 (Commencement No. 5 Regulations 2026). Distinct from Crime and Policing Act 2026 (ss.66I–66L) which targets tool suppliers; this section targets end-users who create or request deepfakes.
Stated maximum penalty — Unlimited fine and/or summary imprisonment (Sexual Offences Act 2003)
Binds Individual developers, distributors, and corporate bodies (criminal offences); Ofcom-regulated platforms (OSA priority-content duty). Criminalises making, adapting, possessing, supplying, or offering to supply AI models optimised to generate CSAM (up to 5 years imprisonment). Separately criminalises AI “nudification” tools/deepfake intimate image generators. Upgrades AI-generated intimate image creation to priority offences under the Online Safety Act; Ofcom-regulated platforms must prevent and remove such content (up to £3M penalty for non-compliance).
Royal Assent: 29 April 2026 (2026 c.20). Section 99 (purported intimate image generators) and related provisions commenced 29 June 2026 via UKSI 2026/689 (Commencement No. 1). CSAM generator offences (Pt.3 Ch.3) commenced on same SI.
Stated maximum penalty — 5 years imprisonment (CSA/deepfake AI generator offences); £3M Ofcom fine (platform intimate image duty)
Binds Providers of anthropomorphic AI interactive services (virtual companions, emotional chatbots, human-like AI) publicly available in mainland China. Dedicated compliance regime for AI companion services, virtual chatbots and emotionally interactive AI; mandates AI-identity disclosure, minor protections, usage-time warnings, and prohibits inducing emotional dependence.
In force 15 Jul 2026.
Stated maximum penalty — CAC administrative penalties; service suspension
Binds Public and private AI developers / deployers. Prohibited / high-risk / acceptable tiers; high-risk AI needs prior evaluation, human oversight and transparency.
Stated maximum penalty — Referral to data-protection / Indecopi
Article 5 prohibits, among others, harmful manipulation, exploitation of vulnerabilities, social scoring by public authorities, certain predictive policing, untargeted scraping of facial images and most real-time remote biometric identification in public spaces. The bans have applied since 2 February 2025.
Increasingly, yes. The US TAKE IT DOWN Act bans non-consensual intimate imagery, including AI deepfakes, and requires covered platforms to remove it; the EU has added a new Article 5 prohibition targeting AI-generated CSAM and intimate imagery.
Article 5-style bans generally apply to anyone placing such a system on the market or putting it into service in the jurisdiction, regardless of size. Scope and exemptions differ by instrument — check the linked source.
In a growing number of US states. New Jersey’s FAIR Act and Illinois’ SB 343 prohibit landlords and revenue-management vendors from using algorithms fed with competitors’ nonpublic pricing data to set or coordinate residential rents; Maryland’s Protection From Predatory Pricing Act bans pricing food-retail and delivery items from an individual consumer’s personal data. Illinois’ bill had passed the legislature but was not yet signed as of 28 July 2026 — each row above carries its own status.
We currently track prohibited ai practices obligations across 5 jurisdictions: European Union, United States, United Kingdom, China and Peru. Each is dated and linked to its primary source on this page.
Not legal advice. Each obligation links to its primary source and carries the date it was last checked; verify the legal text before relying on it.