> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 02 AIGO EU AI Act Prohibited AI Practices Mapping v0.1

# AIGO — EU AI Act Prohibited AI Practices Mapping

## 1. Document Purpose

This document provides the AIGO mapping for prohibited AI practices under Article 5 of Regulation (EU) 2024/1689, as amended by subsequent Union legislation including Regulation (EU) 2026/1744.

It translates the prohibited-practice requirements into an operational AIGO governance process covering:

* prohibited-practice identification;
* use-case screening;
* actor and applicability determination;
* intended-purpose analysis;
* reasonably foreseeable misuse analysis;
* exception analysis where legally relevant;
* governance escalation;
* risk assessment;
* decision authority;
* evidence;
* monitoring;
* incident management;
* change management;
* assurance; and
* continual improvement.

The document is an operational governance mapping. It is not legal advice, a legal opinion, or a determination that a specific organization is compliant with the AI Act.

The European Commission describes nine prohibited AI-practice categories in its current AI Act implementation material. Prohibitions 1–8 have applied since February 2025; the ninth prohibition, covering certain non-consensual sexually explicit/intimate content and child sexual abuse material, was introduced by the 2026 AI Omnibus and takes effect in December 2026.

***

## 2. Mapping Information

| Field                | Value                                          |
| -------------------- | ---------------------------------------------- |
| Mapping              | AIGO EU AI Act Prohibited AI Practices Mapping |
| Version              | 0.1                                            |
| Status               | Draft                                          |
| Document Identifier  | `AIGO-MAP-EUAI-002`                            |
| Document Type        | EU AI Act Mapping                              |
| Mapping Package      | `AIGO-MAP-EUAI`                                |
| Primary Legal Source | Regulation (EU) 2024/1689, Article 5           |
| Amendment Baseline   | Regulation (EU) 2026/1744                      |
| Mapping Architecture | `AIGO-MAP-EUAI-ARCH-001`                       |
| Registry             | `00-AIGO-EU-AI-Act-Mapping-Registry-v0.1.json` |

The Commission's published guidelines on prohibited AI practices provide practical and legal explanations, but they are non-binding; authoritative legal interpretation ultimately rests with the Court of Justice of the European Union.

***

## 3. Source Hierarchy

The following source hierarchy applies:

### Tier 1 — Binding Legal Text

* Regulation (EU) 2024/1689;
* applicable amendments, including Regulation (EU) 2026/1744;
* applicable delegated or implementing acts where relevant.

### Tier 2 — Official Implementation Material

* European Commission guidance;
* European AI Office material;
* official FAQs;
* other official implementation instruments.

### Tier 3 — AIGO Mapping

AIGO translates the legal requirement into operational governance mechanisms.

The mapping must not be represented as a substitute for the binding legal provision.

***

## 4. Article 5 Governance Principle

AIGO shall treat potential prohibited-practice use cases as a **pre-deployment and pre-authorization gate**.

The default governance sequence is:

```text id="w1m7x9" theme={null}
Proposed AI Activity
        ↓
AI System / Use-Case Identification
        ↓
Actor and Applicability Review
        ↓
Article 5 Screening
        ↓
Potential Prohibited Practice?
      ┌───┴───┐
     YES      NO
      ↓        ↓
STOP /        Continue
ESCALATE      Classification
```

An organization should not treat prohibited-practice screening as an ordinary post-deployment control.

***

## 5. AIGO Prohibited-Practice Screening Control

Recommended control:

**Control Name:** EU AI Act Prohibited-Practice Screening

**Control Objective:**

Prevent the organization from placing on the market, putting into service, or using an AI system for a prohibited practice within the scope of Article 5.

**Control Owner:**

AI Governance Owner, with Legal/Compliance participation.

**Control Frequency:**

* before initial approval;
* before material change;
* before a new intended purpose;
* when a new prohibited-practice interpretation or amendment is identified;
* when significant capability or misuse risk changes.

**Required Evidence:**

* use-case description;
* intended-purpose statement;
* actor determination;
* Article 5 screening record;
* supporting technical evidence where needed;
* legal/compliance review where appropriate;
* approval or escalation outcome.

***

## 6. Applicability Screening

Before evaluating an individual prohibited practice, AIGO should establish:

| Applicability Question                                             | Required Determination      |
| ------------------------------------------------------------------ | --------------------------- |
| Is the activity an AI system within the AI Act framework?          | Yes / No / Uncertain        |
| Which actor is involved?                                           | Provider / Deployer / Other |
| Is the activity within territorial scope?                          | Yes / No / Uncertain        |
| What is the intended purpose?                                      | Documented                  |
| What capabilities does the system have?                            | Documented                  |
| Could the relevant prohibited outcome occur?                       | Yes / No / Uncertain        |
| Is the outcome intended?                                           | Yes / No                    |
| Is the outcome reasonably foreseeable/reproducible where relevant? | Yes / No / Uncertain        |
| Are legally relevant exceptions applicable?                        | Yes / No / Uncertain        |
| Is an amendment or transition relevant?                            | Yes / No                    |

Unresolved applicability should be escalated rather than treated as "No."

***

## 7. Legal Status of Prohibited Practices

The Commission currently describes the prohibited category as comprising nine practices:

1. harmful AI-based manipulation and deception;
2. harmful AI-based exploitation of vulnerabilities;
3. social scoring;
4. certain individual criminal-offence prediction or risk assessment;
5. untargeted scraping to create or expand facial-recognition databases;
6. emotion recognition in workplaces and education institutions;
7. biometric categorisation to infer certain protected characteristics;
8. real-time remote biometric identification for law-enforcement purposes in publicly accessible spaces, subject to the statutory conditions and exceptions; and
9. AI systems generating certain non-consensual sexually explicit/intimate content or child sexual abuse material.

The first eight became effective in February 2025. The ninth was introduced by the AI Omnibus and takes effect in December 2026.

***

# 8. Prohibited Practice 1 — Harmful AI-Based Manipulation or Deception

## 8.1 Legal Theme

Article 5 prohibits certain AI systems that deploy subliminal techniques beyond a person's consciousness or purposefully manipulative or deceptive techniques when the statutory conditions are met, including where the practice materially distorts behaviour and causes, or is reasonably likely to cause, significant harm.

The Commission's prohibited-practices guidance provides additional practical interpretation and examples.

## 8.2 AIGO Mapping

**AIGO Components:**

* Governance;
* AI System;
* Classification;
* Risk;
* Control;
* Assessment;
* Human Oversight;
* Monitoring;
* Incident;
* Assurance.

**Relationship:**

`DIRECT / CRITICAL`

## 8.3 AIGO Governance Requirement

The organization should assess whether an AI use case involves:

* subliminal techniques;
* intentional manipulation;
* intentional deception;
* material distortion of behaviour;
* significant harm or a foreseeable significant harmful outcome.

## 8.4 AIGO Control

**Manipulation and Deception Screening Control**

The control should require:

* intended-purpose analysis;
* interaction design review;
* behavioural-impact analysis;
* human-factors assessment;
* affected-person impact analysis;
* escalation of potential prohibited use.

## 8.5 Evidence

Potential evidence:

* product requirements;
* UX design;
* interaction flows;
* model/system specifications;
* behavioural testing;
* impact assessment;
* legal/compliance review;
* approval decision.

## 8.6 Escalation

Potentially prohibited use should not proceed to normal production approval until the issue is resolved.

***

# 9. Prohibited Practice 2 — Exploitation of Vulnerabilities

## 9.1 Legal Theme

Article 5 prohibits certain AI systems that exploit vulnerabilities of a person or specific group arising from age, disability, or a specific social or economic situation when the statutory conditions are met, including significant behavioural distortion causing or likely to cause significant harm.

## 9.2 AIGO Mapping

**AIGO Components:**

* Risk;
* Fundamental Rights;
* Human Oversight;
* Assessment;
* Control;
* Assurance;
* Incident.

**Relationship:**

`DIRECT / CRITICAL`

## 9.3 AIGO Governance Requirement

The organization should screen for vulnerability-exploitation risks involving:

* children;
* elderly persons;
* persons with disabilities;
* economic vulnerability;
* social vulnerability;
* other legally relevant vulnerability contexts.

## 9.4 Control

**Vulnerability Exploitation Screening Control**

The control should require:

* affected-person identification;
* vulnerability analysis;
* behavioural-impact analysis;
* use-case restriction;
* escalation.

## 9.5 Evidence

* target-user analysis;
* impact assessment;
* safeguards;
* testing;
* risk assessment;
* approval decision.

***

# 10. Prohibited Practice 3 — Social Scoring

## 10.1 Legal Theme

Article 5 prohibits certain AI-based social-scoring practices where the statutory conditions are met, including specified forms of evaluation or classification of individuals or groups based on social behaviour or known, inferred, or predicted personal or personality characteristics, where the resulting treatment reaches the prohibited forms specified in the Regulation.

## 10.2 AIGO Mapping

**AIGO Components:**

* Governance;
* Risk;
* Fairness;
* Privacy;
* Assessment;
* Control;
* Approval;
* Monitoring.

**Relationship:**

`DIRECT / CRITICAL`

## 10.3 AIGO Control

**Social-Scoring Screening Control**

The control should identify whether a system:

* creates a social score;
* aggregates behavioural or personality information;
* ranks persons or groups;
* uses the resulting score to determine treatment;
* transfers or reuses scores across contexts;
* produces legally relevant or unjustified adverse treatment.

## 10.4 Evidence

* scoring methodology;
* data sources;
* purpose;
* decision rules;
* affected-person analysis;
* system documentation;
* governance approval.

## 10.5 Governance Rule

A general-purpose risk score must not automatically be classified as prohibited social scoring.

The actual legal conditions must be assessed against the system's design and use.

***

# 11. Prohibited Practice 4 — Certain Individual Criminal-Offence Prediction or Risk Assessment

## 11.1 Legal Theme

Article 5 prohibits certain AI systems that make risk assessments or predictions regarding a natural person's risk of committing a criminal offence based solely on profiling or assessing personality traits and characteristics, subject to the legal conditions of the provision.

## 11.2 AIGO Mapping

**AIGO Components:**

* Risk;
* Classification;
* Fundamental Rights;
* Assessment;
* Evidence;
* Assurance;
* Human Oversight.

**Relationship:**

`DIRECT / CRITICAL`

## 11.3 AIGO Control

**Criminal-Offence Prediction Screening Control**

The organization should determine:

* whether the output concerns an individual's risk of committing a criminal offence;
* whether the system uses profiling;
* whether personality traits or characteristics form the relevant basis;
* whether the system falls within a legally permitted or prohibited use.

## 11.4 Governance Requirement

Potentially prohibited use should be escalated to legal/compliance review before deployment or operational continuation.

## 11.5 Evidence

* intended-purpose document;
* decision logic;
* feature/data documentation;
* profiling methodology;
* legal analysis;
* approval record.

***

# 12. Prohibited Practice 5 — Untargeted Scraping for Facial-Recognition Databases

## 12.1 Legal Theme

Article 5 prohibits certain untargeted scraping of facial images from the internet or CCTV footage to create or expand facial-recognition databases.

## 12.2 AIGO Mapping

**AIGO Components:**

* Data Governance;
* Privacy;
* Security;
* Risk;
* Control;
* Assessment;
* Evidence.

**Relationship:**

`DIRECT / CRITICAL`

## 12.3 AIGO Control

**Facial-Recognition Database Acquisition Control**

The control should require review of:

* source of facial images;
* acquisition method;
* targeting;
* data provenance;
* legal basis;
* purpose;
* database construction;
* reuse;
* retention.

## 12.4 Evidence

* data-source inventory;
* acquisition methodology;
* provenance;
* data protection assessment where applicable;
* technical architecture;
* approval;
* legal review.

## 12.5 Governance Rule

A system must not be treated as permissible merely because the source material is publicly accessible.

Public availability of material does not by itself establish legality of untargeted scraping for facial-recognition database creation.

***

# 13. Prohibited Practice 6 — Emotion Recognition in Workplaces and Education

## 13.1 Legal Theme

Article 5 prohibits certain emotion-recognition AI systems used in workplaces and education institutions, subject to specified exceptions in the Regulation.

## 13.2 AIGO Mapping

**AIGO Components:**

* Classification;
* Risk;
* Privacy;
* Fundamental Rights;
* Human Oversight;
* Control;
* Assessment;
* Monitoring.

**Relationship:**

`DIRECT / CRITICAL`

## 13.3 AIGO Control

**Workplace and Education Emotion-Recognition Screening Control**

The organization should identify:

* whether emotion recognition is being performed;
* deployment context;
* workplace context;
* education context;
* affected persons;
* legal basis and exception, where relevant;
* purpose;
* system capability.

## 13.4 Evidence

* system description;
* deployment context;
* affected-person assessment;
* legal/compliance review;
* exception analysis where applicable;
* approval.

## 13.5 Governance Rule

Where the system appears to fall within the prohibited category, normal AI approval must be suspended pending legal/compliance determination.

***

# 14. Prohibited Practice 7 — Biometric Categorisation to Infer Protected Characteristics

## 14.1 Legal Theme

Article 5 prohibits certain biometric categorisation systems used to infer sensitive or protected characteristics specified in the Regulation, subject to the applicable legal wording and exceptions.

## 14.2 AIGO Mapping

**AIGO Components:**

* Biometrics;
* Privacy;
* Fairness;
* Risk;
* Control;
* Assessment;
* Evidence.

**Relationship:**

`DIRECT / CRITICAL`

## 14.3 AIGO Control

**Biometric Categorisation Screening Control**

The control should identify:

* biometric modality;
* categorisation purpose;
* inferred attributes;
* affected persons;
* data source;
* intended use;
* downstream use.

## 14.4 Evidence

* biometric-system profile;
* data flow;
* feature description;
* purpose statement;
* legal assessment;
* technical safeguards;
* governance decision.

***

# 15. Prohibited Practice 8 — Real-Time Remote Biometric Identification for Law Enforcement

## 15.1 Legal Theme

Article 5 addresses real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes.

The prohibition is subject to specifically defined legal exceptions and conditions. Therefore, AIGO must not implement this as a simple unconditional "all use prohibited" rule.

## 15.2 AIGO Mapping

**AIGO Components:**

* Governance;
* Risk;
* Approval;
* Human Oversight;
* Incident;
* Assurance;
* Evidence.

**Relationship:**

`DIRECT / CRITICAL / CONDITIONAL`

## 15.3 AIGO Control

**Real-Time Remote Biometric Identification Screening Control**

The control should determine:

* whether the system is remote biometric identification;
* whether operation is real-time;
* whether deployment occurs in publicly accessible spaces;
* whether the purpose is law enforcement;
* whether a statutory exception is claimed;
* whether all applicable legal conditions are satisfied;
* which authority is responsible.

## 15.4 Governance Rule

This category requires an enhanced legal/compliance escalation path.

The AIGO governance body should not independently create an exception merely because the use case appears operationally necessary.

## 15.5 Evidence

Potential evidence includes:

* legal basis;
* authority authorization;
* purpose;
* operational scope;
* necessity analysis;
* safeguards;
* system configuration;
* human oversight;
* audit records.

## 15.6 Approval

Where the organization is not the competent authority empowered to authorize the activity, internal AIGO approval does not substitute for statutory authorization.

***

# 16. Prohibited Practice 9 — Certain Non-Consensual Sexual and Child Sexual Abuse Material Generation

## 16.1 Legal Theme

The 2026 AI Omnibus inserted additional prohibited-practice provisions into Article 5 covering certain AI systems that generate or manipulate:

* realistic images, videos, audio, or similar material of an identifiable natural person's intimate parts; or
* realistic material involving an identifiable natural person engaged in sexually explicit activities,

without the person's freely given, specific, informed, unambiguous and explicit consent; and certain material or performances falling within the relevant provisions of Directive 2011/93/EU concerning child sexual abuse material.

The amended provision also specifies conditions concerning intended purpose, reasonably foreseeable and reproducible outcomes, and the absence of reasonable and adequate technical safety measures and safeguards in the circumstances defined by the Regulation.

The Commission currently identifies this as the ninth prohibited category and states that it takes effect in **December 2026**.

## 16.2 AIGO Mapping

**AIGO Components:**

* Governance;
* Risk;
* Security;
* Privacy;
* Safety;
* Human Oversight;
* Control;
* Monitoring;
* Incident;
* Assurance.

**Relationship:**

`DIRECT / CRITICAL`

## 16.3 AIGO Control

**Non-Consensual Sexual Content and CSAM Prevention Control**

The control should require review of:

* intended purpose;
* model capabilities;
* content-generation capability;
* safeguards;
* misuse resistance;
* foreseeable misuse;
* reporting and response mechanisms;
* access controls;
* content filtering;
* incident handling;
* supplier dependencies.

## 16.4 Technical Safeguards

Where legally relevant, the system should be assessed for:

* content-generation restrictions;
* access restrictions;
* detection;
* prevention;
* abuse monitoring;
* incident escalation;
* corrective measures.

## 16.5 Evidence

Potential evidence:

* model capability assessment;
* safety evaluation;
* red-team testing;
* safeguards;
* abuse-prevention testing;
* configuration;
* access-control records;
* incident records;
* remediation evidence.

## 16.6 Effective-Date Control

Because the prohibition applies on a later date than the original Article 5 prohibitions, AIGO must maintain separate current and future applicability states.

The dedicated timeline document is authoritative for dates.

***

# 17. Cross-Cutting AIGO Prohibited-Practice Controls

The nine prohibited categories should be supported by a common governance control framework.

## 17.1 Prohibited-Practice Screening

Required at:

* system registration;
* material purpose change;
* material capability change;
* new deployment context;
* new jurisdiction;
* significant model change.

## 17.2 Legal/Compliance Escalation

Potential prohibited use should be escalated.

## 17.3 Human Approval Gate

Prohibited-practice screening should require human accountability for material determinations.

## 17.4 Evidence Retention

The screening conclusion should be retained with supporting evidence.

## 17.5 Reassessment

A previous "not prohibited" determination should be reassessed after material change.

***

# 18. Prohibited-Practice Decision Model

The AIGO decision model should be:

```text id="mr8qsn" theme={null}
1. Identify AI system
        ↓
2. Identify intended purpose
        ↓
3. Identify actor
        ↓
4. Identify territorial applicability
        ↓
5. Identify system capabilities
        ↓
6. Screen Article 5 categories
        ↓
7. Evaluate statutory conditions
        ↓
8. Evaluate applicable exceptions
        ↓
9. Evaluate effective date / transition
        ↓
10. Obtain legal/compliance review where required
        ↓
11. Record decision
        ↓
12. Approve / reject / restrict / escalate
```

***

# 19. Decision Outcomes

AIGO should support controlled outcomes:

```text id="x1i6nj" theme={null}
PROHIBITED
NOT_PROHIBITED
CONDITIONAL
NOT_APPLICABLE
PENDING_LEGAL_REVIEW
PENDING_FACTUAL_REVIEW
PENDING_EFFECTIVE_DATE
ESCALATED
```

The precise enumeration should remain aligned with AIGO governance conventions.

***

# 20. Prohibited Outcome

Where the organization determines that an AI activity falls within an applicable prohibition:

```text id="tf9e5s" theme={null}
Status = PROHIBITED
```

The governance record should trigger:

* prevention of deployment;
* cessation where already operating and legally required;
* escalation;
* incident handling if appropriate;
* evidence preservation;
* management notification;
* change or retirement actions where applicable.

***

# 21. Conditional Outcome

Some Article 5 categories contain detailed statutory conditions and exceptions.

Where the legal analysis is not yet completed, AIGO should use:

```text id="un0vpa" theme={null}
CONDITIONAL
```

rather than "approved."

The record should identify the conditions requiring satisfaction.

***

# 22. Pending Legal Review

A pending legal assessment should not be represented as an authorization.

Use:

```text id="ev5t4l" theme={null}
PENDING_LEGAL_REVIEW
```

until the required review is completed.

***

# 23. Not Applicable

An Article 5 prohibition may be determined not to apply because the system or activity does not meet the legal conditions.

The determination should retain:

* rationale;
* source;
* reviewer;
* evidence;
* effective date;
* review trigger.

***

# 24. Evidence Requirements

Every material Article 5 screening decision should retain evidence proportional to risk.

Minimum recommended evidence:

* AI system identifier;
* intended purpose;
* deployment context;
* actor role;
* capability summary;
* prohibited-practice screening;
* outcome;
* rationale;
* reviewer;
* date.

Enhanced evidence may be required for high-impact use cases.

***

# 25. Technical Evidence

Technical evidence may be required when the legal assessment depends on system capability.

Examples include:

* model cards;
* system architecture;
* prompts;
* product functionality;
* model evaluations;
* safety tests;
* red-team results;
* content-generation tests;
* biometric capability tests.

Technical evidence should be managed through the AIGO Evidence model.

***

# 26. Foreseeable Misuse

For the newly added Article 5 provisions concerning non-consensual sexual/intimate content and child sexual abuse material, the amended legal text expressly addresses circumstances in which generation/manipulation is a reasonably foreseeable and reproducible outcome given system design, training, architecture, capabilities, or user-facing functionality and inadequate safeguards.

AIGO should therefore maintain a **Foreseeable Misuse Assessment** where this criterion is relevant.

The assessment should consider:

* system capability;
* default configuration;
* safety controls;
* known misuse patterns;
* reasonable user behavior;
* ease of bypass;
* reproducibility;
* effectiveness of safeguards.

This assessment does not replace legal interpretation.

***

# 27. Safeguard Adequacy

Where Article 5's amended language requires consideration of reasonable and adequate technical safety measures and other safeguards, AIGO should document:

* safeguards implemented;
* safeguard objectives;
* testing;
* bypass resistance;
* observed misuse;
* corrective actions;
* monitoring.

The organization should not rely on a safeguard claim without evidence.

***

# 28. Intended-Purpose Governance

The intended purpose is a critical input to prohibited-practice determination.

AIGO should ensure that intended purpose is:

* documented;
* approved;
* versioned;
* linked to the AI System Profile;
* reviewed after material change.

A change in intended purpose should trigger Article 5 re-screening.

***

# 29. Capability-Based Governance

The screening should consider not only stated purpose but relevant system capability.

This is particularly important where a system can reasonably support a prohibited outcome even if the organization does not state that as its purpose.

Capability analysis should be evidence-based.

***

# 30. Change Trigger

The following should trigger re-screening:

* model change;
* new training;
* capability extension;
* new modality;
* new user group;
* new geography;
* new deployment context;
* new integration;
* new intended purpose;
* safety-control modification;
* supplier/model-provider change.

***

# 31. Third-Party AI

Where an organization procures an AI system from a provider, the organization should still perform applicability screening appropriate to its role.

Supplier statements should not automatically substitute for internal governance.

Evidence may include:

* provider documentation;
* provider representations;
* technical documentation;
* contractual commitments;
* independent assessment;
* internal testing.

***

# 32. Prohibited-Practice Supplier Control

Recommended control:

**Third-Party Prohibited-Practice Screening**

The organization should require suppliers to provide information sufficient to determine:

* intended use;
* prohibited-practice exposure;
* known limitations;
* relevant safeguards;
* system changes;
* material incidents.

Contract terms should support notification where material capabilities or risks change.

***

# 33. Procurement Gate

Prohibited-practice screening should be integrated into AI procurement.

Recommended sequence:

```text id="24y0bp" theme={null}
AI Procurement Request
        ↓
AI System Identification
        ↓
Article 5 Screening
        ↓
Risk / Classification
        ↓
Third-Party Review
        ↓
Approval
        ↓
Contract / Acquisition
```

A procurement process should not acquire a system for a use that is already determined to be prohibited.

***

# 34. Deployment Gate

Before deployment:

```text id="g1u5c8" theme={null}
AI System
   ↓
Article 5 Screening
   ↓
Classification
   ↓
Risk Assessment
   ↓
Control Assessment
   ↓
Approval
   ↓
Deployment
```

Article 5 screening should be a gate, not merely a documentation step.

***

# 35. Monitoring for Prohibited Use

Monitoring should detect:

* expansion into prohibited use;
* unauthorized user behavior;
* misuse;
* capability changes;
* circumvention of safeguards;
* new prohibited-practice interpretations.

Monitoring should be proportionate to risk.

***

# 36. Incident Handling

Potential prohibited use discovered after deployment should trigger:

* immediate assessment;
* containment where appropriate;
* legal/compliance escalation;
* incident record;
* evidence preservation;
* risk reassessment;
* change or retirement where required.

Recommended chain:

```text id="z5x1q7" theme={null}
Potential Prohibited Use
      ↓
Incident
      ↓
Containment
      ↓
Legal / Compliance Review
      ↓
Risk
      ↓
Corrective Action
      ↓
Verification
```

***

# 37. Assurance

High-impact Article 5 screening may warrant independent assurance.

Assurance may review:

* legal-source traceability;
* applicability;
* classification;
* screening method;
* technical evidence;
* safeguards;
* decision authority;
* evidence;
* re-screening.

***

# 38. Management Review

Material prohibited-practice findings should be available to management review.

Management should consider:

* unresolved determinations;
* recurring screening failures;
* prohibited-use incidents;
* control weaknesses;
* regulatory developments;
* supplier concerns;
* resource requirements.

***

# 39. Continuous Improvement

Lessons from Article 5 screening should feed improvement.

Potential improvements include:

* stronger procurement gates;
* better screening questionnaires;
* improved technical tests;
* stronger supplier controls;
* improved training;
* enhanced monitoring;
* revised approval authorities.

***

# 40. Relationship to AIGO Schemas

The prohibited-practice mapping should use the existing AIGO schemas.

| Governance Activity      | AIGO Schema            |
| ------------------------ | ---------------------- |
| AI system identification | AI System              |
| Classification           | Assessment / AI System |
| Risk                     | Risk                   |
| Control                  | Control                |
| Screening                | Assessment             |
| Decision                 | Approval               |
| Monitoring               | Monitoring             |
| Incident                 | Incident               |
| Change                   | Change                 |
| Evidence                 | Evidence               |
| Assurance                | Assurance              |
| Management review        | Management Review      |
| Improvement              | Improvement            |
| Retirement               | Retirement             |
| Organizational authority | Governance             |

A dedicated Article 5 schema is not required at this stage.

AIGO should use existing schema families and relate them through references.

***

# 41. Relationship to Templates

The following templates may support Article 5 governance:

* `02-AIGO-AI-System-Registration-Template-v0.1.md`;
* `03-AIGO-AI-System-Profile-Template-v0.1.md`;
* `04-AIGO-AI-Classification-Template-v0.1.md`;
* `05-AIGO-AI-Risk-Assessment-Template-v0.1.md`;
* `07-AIGO-AI-Approval-Template-v0.1.md`;
* `10-AIGO-AI-Incident-Template-v0.1.md`;
* `11-AIGO-AI-Change-Management-Template-v0.1.md`;
* `12-AIGO-AI-Assurance-Template-v0.1.md`;
* `16-AIGO-AI-Evidence-Record-Template-v0.1.md`.

The organization may later introduce a specific Article 5 screening template if operational experience shows that the generic AIGO templates are insufficient.

***

# 42. Relationship to Tools

Article 5 governance should be supported by the AIGO tools.

### Schema Validator

Ensures related records are structurally valid.

### Reference Validator

Ensures Article 5 screening references resolve.

### Traceability Validator

Ensures screening → decision → evidence relationships are complete.

### Control Coverage Validator

Checks required controls.

### Evidence Coverage Validator

Checks evidence requirements.

### Framework Consistency Checker

Checks terminology and legal-source references.

### Document Integrity Checker

Checks mapping and supporting-document integrity.

### Repository Health Checker

Aggregates the overall mapping and governance condition.

***

# 43. Article 5 Traceability Chain

The minimum recommended chain is:

```text id="w25t07" theme={null}
EU AI Act Article 5
        ↓
Prohibited-Practice Category
        ↓
Applicability Determination
        ↓
AI System
        ↓
Intended Purpose
        ↓
Assessment
        ↓
Decision
        ↓
Evidence
        ↓
Approval / Escalation
        ↓
Monitoring
```

Where a prohibited-use event occurs:

```text id="0fmyu4" theme={null}
Monitoring
    ↓
Incident
    ↓
Risk
    ↓
Change / Restriction / Retirement
    ↓
Assurance
    ↓
Improvement
```

***

# 44. Prohibited-Practice Control Matrix

| Prohibited Area                           | Core AIGO Control                   | Assessment                     | Evidence                           | Escalation                       |
| ----------------------------------------- | ----------------------------------- | ------------------------------ | ---------------------------------- | -------------------------------- |
| Manipulation / deception                  | Manipulation Screening              | Use-Case Assessment            | Design / Testing Evidence          | Legal / Governance               |
| Vulnerability exploitation                | Vulnerability Screening             | Impact Assessment              | Affected-Person Evidence           | Legal / Governance               |
| Social scoring                            | Social-Scoring Screening            | Use-Case / Data Assessment     | Scoring Method Evidence            | Legal / Governance               |
| Criminal-offence prediction               | Criminal Prediction Screening       | Legal / Technical Assessment   | Methodology Evidence               | Legal / Governance               |
| Untargeted facial scraping                | Facial Database Acquisition Control | Data Assessment                | Provenance Evidence                | Privacy / Legal                  |
| Workplace / education emotion recognition | Emotion-Recognition Screening       | Context Assessment             | System / Use Evidence              | Legal / Governance               |
| Sensitive biometric categorisation        | Biometric Categorisation Control    | Biometrics Assessment          | Technical / Privacy Evidence       | Legal / Governance               |
| Real-time remote biometric identification | RBBI Screening                      | Legal / Necessity Assessment   | Authorization / Safeguard Evidence | Competent Authority / Governance |
| Non-consensual sexual / CSAM generation   | Content-Safety Prevention Control   | Misuse / Capability Assessment | Safety / Testing Evidence          | Legal / Incident                 |

***

# 45. Criticality

Article 5 controls should generally be treated as critical governance controls because a prohibited practice may create severe legal, rights, safety, and reputational consequences.

A critical control gap should normally:

* block production approval;
* require escalation;
* prevent normal risk acceptance from being used as a substitute for legal prohibition;
* require documented remediation or a formal legal determination.

***

# 46. Risk Acceptance Limitation

A key AIGO rule is:

> Risk acceptance is not a substitute for a legal prohibition.

An organization should not use an internal risk-acceptance record to authorize an AI practice that applicable law prohibits.

Risk acceptance may only address residual organizational risk where the underlying activity is legally permissible.

***

# 47. Exception Handling

Where Article 5 contains a statutory exception or condition, the exception should be treated as a legal applicability question.

It should not be treated as an internal AIGO policy waiver.

The record should distinguish:

```text id="7q5a6e" theme={null}
LEGAL EXCEPTION
```

from:

```text id="r4g9c3" theme={null}
AIGO GOVERNANCE EXCEPTION
```

These are not interchangeable.

***

# 48. Decision Authority

The AIGO Governance arrangement should define who may:

* initiate Article 5 screening;
* review results;
* request legal review;
* escalate;
* stop deployment;
* approve continuation where legally permitted;
* authorize remediation;
* initiate incident management;
* require retirement.

Where external statutory authority is required, the organization's decision authority does not replace it.

***

# 49. Evidence Retention

Article 5 screening records should be retained according to applicable:

* legal requirements;
* regulatory requirements;
* organizational record-retention policy;
* audit requirements;
* incident requirements.

Historical screening records should be preserved when they support previous deployment or governance decisions.

***

# 50. Reassessment Frequency

Article 5 screening should be repeated:

* at registration;
* before deployment;
* after material change;
* after changes in intended purpose;
* after significant model changes;
* after new official guidance;
* after amendments;
* after relevant incidents.

***

# 51. Regulatory Change Monitoring

The Commission is required to review the prohibited-practice list periodically. In May 2026, it published a report on the review of Article 5 and Annex III and identified areas for continued monitoring while noting that the practical evidence base remains developing.

AIGO should therefore monitor:

* Article 5 amendments;
* official guidance;
* enforcement developments;
* Commission review reports;
* AI Office interpretations;
* relevant jurisprudence.

***

# 52. Current Review Baseline

As of this mapping version:

* Prohibitions 1–8 are treated as applicable from **2 February 2025** under the current Commission implementation timeline.
* Prohibition 9, introduced through the 2026 AI Omnibus, is treated as applying from **December 2026**.
* The mapping must be reviewed against the current EUR-Lex legal text before release and whenever Article 5 is amended.

***

# 53. Mapping Quality Requirements

A valid Article 5 mapping should:

* identify the legal provision;
* identify the prohibited-practice category;
* identify applicability conditions;
* distinguish legal exceptions from internal exceptions;
* identify affected AIGO records;
* map controls;
* map evidence;
* map escalation;
* identify effective date;
* preserve source currency;
* state limitations.

***

# 54. Validation Requirements

The document should satisfy:

### Legal Source Validation

Each category references the appropriate Article 5 provision and amendment context.

### Applicability Validation

Conditions are documented.

### Timeline Validation

Effective dates reflect the current legal baseline.

### Control Validation

Mapped controls exist within AIGO.

### Reference Validation

AIGO references resolve.

### Traceability Validation

Article 5 requirement can be traced to operational governance.

### Evidence Validation

Screening decisions have defined evidence requirements.

### Consistency Validation

Terminology is consistent with the master mapping and architecture.

***

# 55. Limitations

This mapping cannot independently determine:

* whether a use case satisfies the precise legal elements of Article 5;
* whether an exception applies;
* whether a specific technical capability is legally relevant;
* whether a safeguard is legally adequate;
* whether a specific practice causes or is reasonably likely to cause significant harm;
* whether a competent authority would reach the same conclusion.

Those determinations may require legal, technical, regulatory, or judicial interpretation.

***

# 56. Document Control

| Field                     | Value                                             |
| ------------------------- | ------------------------------------------------- |
| Document                  | AIGO EU AI Act Prohibited AI Practices Mapping    |
| Version                   | 0.1                                               |
| Status                    | Draft                                             |
| Document Identifier       | `AIGO-MAP-EUAI-002`                               |
| Document Type             | EU AI Act Mapping                                 |
| Primary Source            | Article 5 of Regulation (EU) 2024/1689 as amended |
| Owner                     |                                                   |
| Legal/Compliance Reviewer |                                                   |
| Governance Reviewer       |                                                   |
| Framework Architect       |                                                   |
| Approved By               |                                                   |
| Effective Date            |                                                   |
| Next Review Date          |                                                   |

***

# 57. Document Status

**Document:** AIGO — EU AI Act Prohibited AI Practices Mapping

**Version:** 0.1

**Status:** Draft

**Working Name:** AIGO

**Full Name:** AI Governance Operating Framework

**Document Identifier:** `AIGO-MAP-EUAI-002`

**Document Type:** EU AI Act Mapping

This document maps Article 5 prohibited AI practices to the AIGO AI Governance Operating Framework, including applicability, screening, controls, assessments, evidence, escalation, monitoring, assurance, and continual improvement.

End of Document
