GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-024 Prohibited AI Practices

Tier 2+AIGenerativePredictiveProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A prohibited-use list exists naming the AI use cases the organisation will not build, acquire or operate, aligned with applicable law and with the AI policy. The list names at minimum: manipulation of persons through subliminal or deliberately deceptive techniques; exploitation of vulnerabilities arising from age, disability or social or economic situation; social scoring of persons; prediction of criminal offending from profiling alone; untargeted scraping of facial images to build recognition databases; inference of emotion in workplaces and educational settings; biometric categorisation of persons by protected characteristic; real-time remote biometric identification in publicly accessible spaces; generation or manipulation of intimate or sexually explicit material depicting an identifiable person without that person's explicit consent; and generation or manipulation of child sexual abuse material. Every product or feature launch record and every third-party AI tool acquisition record references a completed check against the list, with an outcome recorded against each named category.

Rationale

A prohibited-use list turns regulatory red lines and the organisation's own ethical commitments into something a product manager can check a feature against before it ships, which is the only point at which the check is cheap. The enumerated minimum tracks the EU AI Act Article 5 prohibitions, including the two added by Regulation (EU) 2026/1744 that apply from 2 December 2026; an organisation outside that regime keeps the list and aligns it to the law that does bind it. The list is a design-time gate. Detection and response when a deployed system is pushed toward a prohibited use at runtime is AIG-031. Generation-time prevention for a named content class is a safeguard AIG-031 does not yet require.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore

Art.5 binds every provider, whatever the risk class of its other systems.

Enterprise AI Deployerstablerequiredcore

Art.5 binds use as well as placing on the market. The acquisition-record check is the deployer's main artefact.

GPAI Model Providerstablerequiredcore

Art.5 binds every provider, whatever the risk class of its other systems.

High-Risk Provider (EU)stablerequiredcore

Art.5 binds every provider, whatever the risk class of its other systems.

Public Body Deployer (EU)stablerequiredrole duty

Art.5(1)(h) is the one prohibition whose exceptions only a public authority can reach: real-time remote biometric identification in publicly accessible spaces for law enforcement is prohibited except for locating victims of abduction or trafficking, preventing a specific and imminent terrorist threat or detecting and locating the perpetrator of a serious criminal offence. A body that could use one records against that entry which exception is relied on and, for each use, the four Art.5(2) conditions (the use confined to confirming the identity of the targeted individual, the situation and the consequences for the rights of everyone concerned weighed, the national law's temporal, geographic and personal limits applied, the Art.27 assessment and the Art.49 registration completed first), the Art.5(3) prior authorisation from a judicial or independent administrative authority with the 24-hour urgency clock and the stop and deletion on a refusal, and the Art.5(4) notification to the market surveillance authority and the data protection authority. Those three paragraphs are extract rows since migration 065 (EU-AI-Art.5.2 to 5.4), each partial on this control with the regime named as the gap; Art.5(5) to (7) bind the Member State and the Commission and are excluded. Art.5 binds use as well as placing on the market, which the base already states.

Art.5 binds every provider, whatever the risk class of its other systems.

DORA ICT Provider (EU)stablerequiredcore

Art.5 binds every provider, whatever the risk class of its other systems.

Art.5 binds every provider, whatever the risk class of its other systems.

NIS2 Cloud Provider (EU)stablerequiredcore

Art.5 binds every provider, whatever the risk class of its other systems.

Framework Mappings (23)

GRC-09Acceptable Use of the AI Serviceinformative
EU-AI-Art.5.1aProhibited — Subliminal and Manipulative Techniquesfull
EU-AI-Art.5.1bProhibited — Exploitation of Individual Vulnerabilitiesfull
EU-AI-Art.5.1cProhibited — Social Scoring Systemsfull
EU-AI-Art.5.1dProhibited — Criminal Risk Assessment by Profiling Alonefull
EU-AI-Art.5.1eProhibited — Facial Recognition Database Scrapingfull
EU-AI-Art.5.1fProhibited — Emotion Inference in Workplaces and Educationfull
EU-AI-Art.5.1gProhibited — Biometric Categorisation for Protected Characteristicsfull
EU-AI-Art.5.1hProhibited — Real-Time Remote Biometric Identification in Public Spacesfull
EU-AI-Art.5.1iProhibited — Non-Consensual Intimate or Sexually Explicit Materialfull
EU-AI-Art.5.1jProhibited — Child Sexual Abuse Materialfull
EU-AI-Art.5.1kProhibited Practices — Scope Conditions for Intimate and Child Sexual Abuse Materialinformative
EU-AI-Art.5.2Prohibited Practices — Conditions on the Law Enforcement Use of Real-Time Remote Biometric Identificationpartial
EU-AI-Art.5.3Prohibited Practices — Prior Authorisation of Each Real-Time Remote Biometric Identification Usepartial
EU-AI-Art.5.4Prohibited Practices — Notification of Each Real-Time Remote Biometric Identification Usepartial
GV-1.3-004Risk Management Activity Level Determination | GV-1.3-004partial
GV-1.4-001Transparent Risk Management Policies | GV-1.4-001informative
GV-1.4-002Transparent Risk Management Policies | GV-1.4-002informative
MG-2.2-001Deployed AI System Value Maintenance | MG-2.2-001informative
MG-2.2-005Deployed AI System Value Maintenance | MG-2.2-005informative
MG-3.2-005Pre-Trained Model Monitoring | MG-3.2-005informative
MP-1.1-004AI System Purpose and Deployment Context | MP-1.1-004informative
MS-2.6-006AI System Safety Risk Evaluation | MS-2.6-006informative

Evidence (3)

policydocumentmanual

Prohibited-use list aligned with applicable law and the AI policy, naming the prohibited categories and the organisation's own additional exclusions.

Example: AI Prohibited Use Register v2.0 (Confluence), listing 12 prohibited categories including subliminal manipulation, social scoring, real-time biometric ID in public spaces, and 4 organisation-specific prohibitions; reviewed by Legal and approved by CTO 2025-11-01

Test: Request the prohibited-use list. Verify: (1) each of the categories the control names is enumerated, including generation of non-consensual intimate material and of child sexual abuse material, (2) any additional organisational prohibitions carry a recorded rationale, (3) the list is approved and carries a review date within the defined interval, (4) the list names the review step that applies it to a product, a feature or an acquired tool.

recorddocumentmanual

Pre-launch review records for AI products and features demonstrating that each was assessed against the prohibited use list before release.

Example: Product Launch Review · AI Hiring Filter v1.2 (Jira AI-LAUNCH-2025-009): prohibited use checklist completed, social scoring and biometric categorisation criteria confirmed not applicable, legal sign-off recorded 2025-08-20

Test: Request the launch and acquisition review records for the most recent AI product releases, features and third-party AI tools. Verify: (1) the check against the prohibited-use list was completed before launch or acquisition, (2) an outcome is recorded against each named category rather than left blank, (3) legal or compliance sign-off is recorded, (4) any borderline case was escalated and closed with a recorded rationale.

configurationtechnicalautomated

Launch workflow configuration in the product tracker showing the prohibited-use check as a required field on the release template.

Example: Product tracker workflow export, release template v7, 2026-08-05: field prohibited_use_check required, transition to Released blocked while unset

Test: Read the launch or release workflow configuration in the product tracker. Verify: (1) the prohibited-use check is a required field on the template used for every product and feature launch, (2) the workflow blocks the transition to released while the field is unset, (3) the field references the current version of the prohibited-use list rather than free text, (4) the requirement applies to every project that ships an AI feature rather than to one project, (5) releases completed in the period carry the field set, with no bypasses recorded.

Questions (2)

boolean

Does your organisation maintain a documented list of AI use cases that are prohibited?

A prohibited use list translates regulatory red lines (EU AI Act Art. 5) and organisational ethics commitments into concrete guardrails that engineering and product teams can evaluate against during design and launch review.

multi

Which of the following categories are named in your prohibited AI use list?

Manipulation through subliminal or deliberately deceptive techniquesExploitation of vulnerabilities arising from age, disability or social or economic situationSocial scoring of personsPrediction of criminal offending from profiling aloneUntargeted scraping of facial images to build recognition databasesInference of emotion in workplaces and educational settingsBiometric categorisation of persons by protected characteristicReal-time remote biometric identification in publicly accessible spacesGeneration or manipulation of intimate or sexually explicit material depicting an identifiable person without their consentGeneration or manipulation of child sexual abuse materialNone of the above

The ten categories are the minimum the control asks for. The last two were added to the EU AI Act Article 5 prohibitions by Regulation (EU) 2026/1744 and apply from 2 December 2026, so a list written before that date will usually be missing them. Organisational prohibitions beyond the ten are expected and are not scored here.