Artificial Intelligence in Australia
Prohibited activities
Law / proposed law in Australia
Australia has not enacted a standalone, comprehensive AI Act or another generally applicable AI-specific statute equivalent to the European Union’s AI Act. The current Australian approach is to apply existing technology-neutral laws, sector-specific regulation, enforceable online-safety instruments, public-sector policy and voluntary responsible-AI guidance. Whether a rule applies turns on the use case, the data and parties involved, the sector, the deployment model and the system’s effects.
The National AI Plan, released in early December 2025, sets the Australian Government’s policy direction around three objectives: capturing the opportunity, spreading the benefits, and keeping Australians safe. For regulation, the Government’s stated preference is to build on existing legal and regulatory frameworks. Targeted intervention may still be considered where existing frameworks cannot adequately address a demonstrated risk.
On 15 July 2026, Prime Minister Anthony Albanese announced proposed Australian Standards for AI and the establishment of an Office of AI within the Department of the Prime Minister and Cabinet. The proposal is expected to be considered by National Cabinet in August 2026, with legislation expected in early 2027, and may result in a more targeted mandatory framework for aspects of AI regulation in Australia.
Existing laws potentially relevant to AI include the Privacy Act 1988 (Cth), the Australian Consumer Law, competition law, copyright and other intellectual-property laws, breach of confidence, contract law, defamation, anti-discrimination law, employment and workplace-surveillance law, work health and safety law, product-liability law, directors’ duties, criminal and cybercrime law, the Online Safety Act 2021 (Cth), the Security of Critical Infrastructure Act 2018 (Cth), administrative law, financial-services and prudential regulation, health and therapeutic-goods regulation, education law and state and territory privacy, health-records, surveillance and public-sector laws. The list is not exhaustive, and no single regime governs all AI activity.
AI.gov.au was published in May 2026 as the consolidated Australian Government portal for responsible-AI guidance, tools and resources. It is operated through the National AI Centre within the Department of Industry, Science and Resources.
Automated decision-making transparency under the Privacy Act
From 10 December 2026, an Australian Privacy Principle (APP) entity must include additional information in its privacy policy under APPs 1.7–1.9 where it has arranged for a computer program to make a decision, or to do a thing substantially and directly related to making a decision, that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information about the individual is used in operating that program. The policy must describe the kinds of personal information used, the kinds of decisions made solely by those programs and the kinds of decisions for which those programs do something substantially and directly related to making the decision.
These are transparency obligations. They do not, by themselves, create a general right not to be subject to automated decision-making. The Office of the Australian Information Commissioner (OAIC) consulted on implementation guidance in May 2026; the final guidance should be checked before the provisions commence.
State and territory overlays
State and territory laws can be material, particularly for public-sector, health, education, law-enforcement, surveillance and workplace uses. Relevant overlays may include privacy and health-records statutes, information-sharing laws, surveillance-device and workplace-surveillance legislation, public-records requirements, anti-discrimination law and sector-specific governance duties.
Regulatory guidance / voluntary codes in Australia
The current Australian Government framework for voluntary responsible-AI adoption is the National AI Centre’s Guidance for AI Adoption, which was released in October 2025 and is now hosted through AI.gov.au. It is available in a foundations version for early or lower-risk adoption and an implementation-guidance version for more complex or higher-risk uses. The guidance includes an AI screening tool, AI policy guide and template, AI register template and a glossary. The framework is organised around six essential practices:
- Decide who is accountable;
- Understand impacts and plan accordingly;
- Measure and manage risks;
- Share essential information;
- Test and monitor; and
- Maintain human control.
These practices are voluntary and non-binding guidance. They are designed to help organisations operationalise responsible AI consistently with existing Australian laws and risk-management expectations; they do not create an independent cause of action or substitute for sector-specific legal analysis.
Australia’s AI Ethics Principles were published in November 2019. The Voluntary AI Safety Standard, published in September 2024, later expressed responsible-AI practices through ten voluntary guardrails. The current six-practice Guidance for AI adoption is now the principal economy-wide Australian Government responsible-AI adoption guidance. References to the ten guardrails should therefore be understood as historical rather than as the current government framework.
In September 2024, the Department of Industry, Science and Resources released a proposals paper on mandatory guardrails for AI in high-risk settings. The Government has since stated that it will not proceed with those proposals at this time. The paper is therefore a historical consultation document, not law and not a currently progressing legislative regime. Its suggested high-risk criteria may still be useful as background policy material, but they must not be expressed as mandatory obligations.
The Productivity Commission’s final report, Harnessing data and digital technology, issued on 10 December 2025, recommends that AI-specific regulation be used only as a last resort where existing regulatory frameworks cannot be sufficiently adapted to handle AI related harms and technology-neutral regulation is infeasible or cannot adequately mitigate the risks. That recommendation expressly addresses the previous mandatory-guardrails proposal.
Privacy, automated decision-making and cyber guidance
On 21 October 2024, the OAIC released guidance for organisations using commercially available AI products and separate guidance for developers training or adapting generative-AI models. The OAIC emphasises that Privacy Act obligations may apply to personal information in prompts, training or fine-tuning data, system logs or other records where they contain personal information and outputs, including inferred, inaccurate or artificially generated information where it is about an identified or reasonably identifiable individual. The OAIC advises AI developers to take reasonable steps to ensure accuracy in generative AI models, such as implementing quality assurance controls to mitigate the risk of biased or inaccurate output prior to release. Public availability of data does not, by itself, establish that collection or use for model training is lawful.
The Commonwealth Ombudsman’s Automated Decision-Making Better Practice Guide was updated in March 2025 in collaboration with the OAIC and the Attorney-General’s Department. It addresses legality, procedural fairness, transparency, accountability, reviewability and system governance in government decision-making. In January 2026, the OAIC also reported on agencies’ publication of automated-decision operational information under the Freedom of Information Act 1982 (Cth) Information Publication Scheme.
On 23 May 2025, the Australian Signals Directorate’s Australian Cyber Security Centre and international counterparts published AI data-security guidance. It addresses risks across the AI lifecycle, including data-supply-chain compromise, maliciously modified or poisoned data, data drift, provenance, access controls, secure storage and integrity protection.
Commonwealth Government use
Version 2.0 of the Policy for the responsible use of AI in government took effect on 15 December 2025. It applies to non-corporate Commonwealth entities subject to specified exclusions, including defence and national-intelligence contexts, and corporate Commonwealth entities are encouraged to adopt it. The policy requires, among other things, accountable officials, transparency statements, a strategic AI-adoption position, operational governance, accountable use-case owners, internal use-case registers, staff training and impact assessment. Additional senior governance applies to higher-risk in-scope uses. These are government-policy requirements, not general economy-wide law.
The Australian Government released the AI Plan for the Australian Public Service 2025 on 12 November 2025. It is organised around the pillars of Trust, People and Tools and aims to expand safe AI capability, access and adoption across the Australian Public Service.
Appointed supervisory authority in Australia
Australia has not appointed a single statutory authority with general enforcement jurisdiction over all AI systems. There is no central Australian AI regulator equivalent to an authority administering a comprehensive AI Act.
The Australian AI Safety Institute has been announced as a key National AI Plan action and sits within the Department of Industry, Science and Resources. It replaced the previously planned AI Advisory Body, which was discontinued in February 2026. It is intended to perform technical analysis, monitoring, testing and policy-support functions and to support government agencies and existing regulators. It is not an enforcement regulator and does not displace statutory regulators or alter their legal remits.
Existing regulators continue to supervise AI-related conduct within their statutory mandates. Depending on the use case, they include the OAIC for privacy and freedom of information; the Australian Competition and Consumer Commission (ACCC) for competition and consumer protection; the eSafety Commissioner for online safety; the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) for financial services, markets and prudential and operational-risk matters; the Therapeutic Goods Administration (TGA) and health regulators for therapeutic goods, medical devices and health uses; workplace, safety and anti-discrimination bodies; cyber security and critical-infrastructure authorities; ombudsmen and administrative-review bodies; and state and territory regulators. A single AI deployment may engage several regulators concurrently.
Definitions in Australia
Australian legislation does not presently contain a single, generally applicable statutory definition of ‘AI system’, ‘AI technology producer’, ‘provider’, ‘deployer’ or ‘user’ for all purposes. Definitions can instead arise within particular statutes, contracts, technical standards or sector-specific rules and must be read in their own context.
The National AI Centre’s current terms page uses an Organisation for Economic Co-operation and Development (OECD)-aligned concept of an AI system: a machine-based system that infers from inputs how to generate outputs, such as predictions, content, recommendations or decisions, capable of influencing physical or virtual environments; AI systems differ in autonomy and post-deployment adaptiveness. The guidance also uses the following non-statutory role descriptions:
- AI deployer: an individual or organisation that supplies or uses an AI system to provide a product or service, whether internally or externally.
- AI technology producer: an organisation or entity that designs, develops, tests and provides AI technologies such as models and components.
- AI platform, product or service provider: an organisation or entity that provides products or services using one or more AI systems.
- AI user: an entity that uses or relies on an AI system.
The OAIC distinguishes the underlying model from the broader AI system in which it is deployed. As an explanatory matter, that broader system may also encompass data, software, interfaces and operational processes. Governance controls and human decision points may be important components of a deployment, but they should be identified as contextual system-design features rather than presented as a verbatim OAIC definition.
Prohibited activities in Australia
Australia has not enacted a comprehensive list of prohibited AI practices equivalent to the prohibited-practices regime in the European Union AI Act. AI-enabled conduct may nevertheless be prohibited, restricted or actionable under existing laws.
Existing legal prohibitions and restrictions
Depending on the facts, existing law may prohibit or regulate unlawful collection, scraping, use or disclosure of personal information; misuse of biometric information; serious invasion of privacy; misleading representations and unfair consumer practices; unlawful discrimination; defamation; copyright infringement; breach of confidence; unauthorised surveillance or workplace monitoring; computer offences, malware and unauthorised access; child sexual exploitation material; financial or professional services supplied without required authorisation; unsafe therapeutic goods or medical devices; and unlawful or procedurally unfair government decision-making.
Online-safety codes, standards and enforcement
The Online Safety Act 2021 (Cth) supports mandatory industry codes and standards for sections of the online industry. The Online Safety Codes and Standards regulate online activities involving class 1 and class 2 material. Phase 1, now referred to as the Unlawful Material Codes and Standards, focuses on class 1A and class 1B material, including seriously harmful content such as child sexual exploitation material, pro-terror material, and extreme crime and violence material. Phase 2, now reflected in the Age-Restricted Material Codes, focuses on class 1C and class 2 material, including online pornography and other age-inappropriate material. AI-generated material is treated in the same way where it falls within the relevant classification category. Requirements can apply to service categories that include designated internet services, including high-impact generative-AI designated internet services where covered by the relevant instrument. The precise obligation depends on the relevant code or standard, service category and risk profile.
The OAIC’s Clearview AI determination remains a leading illustration of existing privacy law being applied to AI-enabled facial recognition and large-scale scraping of images from publicly available online sources.
Government announcements about additional or broader restrictions on non-consensual sexually explicit AI-generated content, app distribution or search access should be described as policy proposals unless and until the relevant legislation or instrument is enacted and commenced. They should be kept separate from existing criminal offences, online-safety instruments and regulator enforcement powers.
High-risk AI in Australia
Australia has no generally applicable statutory classification or compliance regime for ‘high-risk AI’. The expression is currently a governance and policy concept, except where a particular sectoral law or instrument independently imposes risk-based obligations.
The September 2024 mandatory-guardrails proposals paper suggested that a future framework could consider adverse impacts on individual rights, health and safety; groups and collective or cultural rights; and the broader economy, society, environment and rule of law, together with the severity and extent of those impacts. Those proposed criteria never became binding law and the proposal is not proceeding at this time.
The current Guidance for AI adoption uses a risk-scaled approach. Its implementation guidance is directed to more complex or higher-risk uses and recommends stronger accountability, impact analysis, risk management, information sharing, testing, monitoring and human control. As a governance matter, indicators warranting enhanced controls may include significant effects on rights or access to services; impacts on vulnerable people or communities; safety-critical functions; opaque or difficult-to-contest outcomes; large-scale or systemic deployment; material cyber or data risks; and serious consequences from error, bias or model failure.
Organisations using AI in higher-impact contexts should, as a governance recommendation rather than a general statutory command, document use cases and accountabilities, conduct proportionate impact and legal assessments, test and monitor performance, manage data quality and provenance, maintain effective escalation and override processes, enable complaints and contestability, and integrate AI controls with existing privacy, cyber, consumer, safety and sectoral compliance systems.
Controls on generative AI in Australia
Australia has not enacted a generally applicable statute devoted exclusively to generative AI. Generative-AI development and use are regulated through existing laws and, where applicable, sectoral instruments including the Online Safety Act codes and standards.
Privacy and data
Developers and deployers should determine whether training, fine-tuning, retrieval-augmented generation, prompting, logging or other records where they contain personal information, or output handling involves personal information; whether collection, use and disclosure are lawful and fair; whether an APP notice or privacy-policy update is required; whether information is accurate and secure; whether cross-border disclosure rules are engaged; and whether access, correction, retention and deletion obligations apply. Public accessibility does not automatically make data lawful to collect or use for training.
Consent is not universally required for every handling of personal information under the Privacy Act. An entity should determine whether consent is required or relied upon, particularly for sensitive information or secondary uses, and whether another applicable permission or exception is available. The analysis depends on the relevant Australian Privacy Principle and the facts.
The OAIC treats personal information entered into an AI system and personal information contained in system output as potentially regulated, including inferred, inaccurate or hallucinated information about an identified or reasonably identifiable person. The OAIC recommends particular caution with sensitive information and publicly available generative-AI tools.
Cyber security and operational control
AI-specific security analysis should address access control, data leakage, prompt injection, insecure output handling, model inversion or extraction, maliciously modified or poisoned data, supply-chain compromise, model drift, logging, provenance, change control and incident response. Organisations subject to critical-infrastructure, prudential or other cyber security regimes must integrate AI controls with those binding requirements rather than treat AI governance as a standalone exercise.
AI-generated content transparency
The National AI Centre first published voluntary best-practice guidance on AI-generated content transparency, covering labelling, watermarking and metadata recording, on 28 November 2025. The current version, published on 22 April 2026, recommends proportionate disclosure methods such as labelling, watermarking and metadata or provenance measures. This is voluntary best-practice guidance, not a generally applicable statutory labelling regime. Separate binding obligations may arise under consumer, electoral, online-safety, privacy or sector-specific law depending on the content and context.
Enforcement / fines in Australia
Australia has no general, cross-economy AI Act enforcement or penalty regime. AI-specific or AI-relevant obligations may nevertheless be enforced under existing legislation and sectoral instruments. The regulator, cause of action, available remedy and maximum penalty depend on the particular provision, the conduct, the date of contravention and the defendant.
- A serious or repeated interference with privacy under the Privacy Act can attract a maximum civil penalty of AUD 2.5 million for a person other than a body corporate. For a body corporate, the maximum is the greater of AUD 50 million, three times the value of the benefit reasonably attributable to the conduct, or, if that value cannot be determined, 30% of adjusted turnover during the breach turnover period. Other Privacy Act contraventions have different consequences. The statutory tort for serious invasions of privacy also creates a private court pathway, subject to its elements, remedies, defences and exemptions.
- Competition and consumer law. AI-related representations, sales practices or product conduct may engage the Australian Consumer Law and competition law. For many offence and civil-penalty provisions, the maximum corporate penalty for conduct on or after 28 March 2026 is the greater of AUD 100 million, three times the reasonably attributable benefit where that value can be determined, or 30% of adjusted turnover during the breach turnover period where it cannot. Other provisions have lower maxima. The general prohibition on misleading or deceptive conduct under the Australian Consumer Law is not itself a pecuniary-penalty provision, although related conduct may contravene civil-penalty provisions and injunctions, damages, compensation and other remedies may be available.
- Online safety. Non-compliance with a standard, or with a direction to comply with a code, can result in civil-penalty proceedings. The maximum identified in eSafety’s regulatory guidance is 30,000 penalty units per contravention for an individual and five times that amount for a corporation. Different Online Safety Act contraventions may carry different maxima.
- Other regimes. AI uses may also attract regulatory orders, licence consequences, remediation, compensation, injunctions, enforceable undertakings, disqualification, criminal liability or judicial and merits review under financial-services, health, workplace, discrimination, cybercrime, critical-infrastructure, administrative-law and other sectoral regimes. Penalty figures should be rechecked on the publication date and should never be applied without identifying the specific contravention.
User transparency in Australia
Transparency is a central feature of Australian responsible-AI policy, but its legal source and effect vary. The current Guidance for AI adoption recommends sharing essential information about AI systems and maintaining human control. The National AI Centre’s AI-generated content guidance recommends proportionate disclosure, labelling, watermarking and provenance measures. These recommendations are voluntary unless another law or instrument makes disclosure mandatory in the relevant context.
Under the Privacy Act, APP entities may need to explain personal-information handling through privacy policies and APP 5 collection notices and to facilitate access and correction. From 10 December 2026, the specific automated decision-making privacy-policy disclosures described in the Automated decision-making transparency under the Privacy Act section will apply to qualifying arrangements. The OAIC’s final implementation guidance should be checked before commencement.
For Commonwealth Government entities within scope, the responsible-use policy requires transparency statements, strategic and operational governance, use-case accountability, registers, training and impact assessment. Administrative law may also require lawful authority, procedural fairness, reasons and reviewability. The OAIC’s January 2026 Information Publication Scheme report recommends improved publication of operational information about automated decision-making by government agencies.
Fairness / unlawful bias in Australia
Australia does not have a single AI fairness statute. Unfair or biased AI outcomes can nevertheless engage Commonwealth, state or territory anti-discrimination laws, employment law, consumer protection, privacy, credit, education, health, administrative law and other sector-specific duties. The applicable protected attributes, tests, exemptions, remedies and responsible parties depend on the relevant statute and context.
The current Guidance for AI adoption addresses fairness through impact analysis, stakeholder engagement, risk management, testing, monitoring and human control. The OAIC identifies bias and discrimination risks where data are incomplete, inaccurate, unrepresentative or encode historical disadvantage. These are guidance propositions unless linked to a specific legal obligation.
As a governance matter, organisations deploying higher-impact AI should test for discriminatory or materially inaccurate outcomes before and after deployment; assess performance across relevant cohorts; document limitations; monitor complaints and drift; maintain escalation and contestability pathways; and ensure that human reviewers have the authority and information needed to correct inappropriate outcomes.
Human oversight in Australia
The sixth essential practice in the current Guidance for AI adoption is to maintain human control. The guidance recommends designing systems and operating processes so that people can supervise, intervene, escalate, override or stop AI use where appropriate to the system’s risk and impact.
Human involvement should be meaningful rather than ceremonial. Reviewers need appropriate expertise, authority, information, independence and time; they should understand relevant system limitations and avoid merely endorsing an automated result. The appropriate form of oversight may range from periodic monitoring for low-impact tools to mandatory approval, dual control, escalation or prohibition of autonomous action in higher-impact contexts.
For government decision-making, human oversight must be assessed alongside statutory authority, lawful delegation, procedural fairness, reasons, evidence, recordkeeping and review rights. For private-sector systems, the necessary controls depend on the consequences of the use case and the privacy, consumer, safety, discrimination, professional, cyber security and sectoral laws engaged. Human review does not cure an otherwise unlawful system or decision.
Australia has not enacted a comprehensive list of prohibited AI practices equivalent to the prohibited-practices regime in the European Union AI Act. AI-enabled conduct may nevertheless be prohibited, restricted or actionable under existing laws.
Existing legal prohibitions and restrictions
Depending on the facts, existing law may prohibit or regulate unlawful collection, scraping, use or disclosure of personal information; misuse of biometric information; serious invasion of privacy; misleading representations and unfair consumer practices; unlawful discrimination; defamation; copyright infringement; breach of confidence; unauthorised surveillance or workplace monitoring; computer offences, malware and unauthorised access; child sexual exploitation material; financial or professional services supplied without required authorisation; unsafe therapeutic goods or medical devices; and unlawful or procedurally unfair government decision-making.
Online-safety codes, standards and enforcement
The Online Safety Act 2021 (Cth) supports mandatory industry codes and standards for sections of the online industry. The Online Safety Codes and Standards regulate online activities involving class 1 and class 2 material. Phase 1, now referred to as the Unlawful Material Codes and Standards, focuses on class 1A and class 1B material, including seriously harmful content such as child sexual exploitation material, pro-terror material, and extreme crime and violence material. Phase 2, now reflected in the Age-Restricted Material Codes, focuses on class 1C and class 2 material, including online pornography and other age-inappropriate material. AI-generated material is treated in the same way where it falls within the relevant classification category. Requirements can apply to service categories that include designated internet services, including high-impact generative-AI designated internet services where covered by the relevant instrument. The precise obligation depends on the relevant code or standard, service category and risk profile.
The OAIC’s Clearview AI determination remains a leading illustration of existing privacy law being applied to AI-enabled facial recognition and large-scale scraping of images from publicly available online sources.
Government announcements about additional or broader restrictions on non-consensual sexually explicit AI-generated content, app distribution or search access should be described as policy proposals unless and until the relevant legislation or instrument is enacted and commenced. They should be kept separate from existing criminal offences, online-safety instruments and regulator enforcement powers.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expending facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medial or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Laws specifically addressing AI have not been introduced in Brazil yet. Draft Article 13 of the proposed Brazilian AI Bill prohibits AI systems that employ subliminal techniques, exploit vulnerabilities of specific groups or are used by public authorities for illegitimate or disproportionate social scoring.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
National laws specifically addressing AI have not yet passed in Canada. At the provincial level, using AI for screening and evaluating potential employees or using AI to make decisions based on personal information should be reviewed carefully.
Article 5 classifies uses of AI systems into four risks. The highest risk is an ‘Unacceptable Risk Use’, which covers uses of AI systems that are incompatible with the respect and protection of fundamental rights. The distribution, introduction into the market or into service of AI systems intended for such uses would be prohibited.
Article 6 of the Chilean AI Bill lists the uses that shall be considered as unacceptable risk:
- Subliminal manipulation: AI systems that use techniques that are imperceptible to people and are intended to induce actions that cause physical and/or mental health harm. The government indications broaden this category to include manipulative or deceptive uses that alter behaviour, impair informed decision-making and lead people to decisions they would not reasonably have taken otherwise. Therapeutic uses remain possible when carried out in accordance with the law and subject to specific and express informed consent.
- Systems that exploit people's vulnerabilities to generate harmful behaviours: AI systems that exploit any vulnerabilities of a person or a specific group of persons - including known characteristics of that person's or group's personality traits, social or economic situation, age, and physical or mental capacity - that are intended to substantially alter their behaviour or limit their will and cause actual or potential harm to that person or to third parties.
- Systems of biometric categorisation of persons based on sensitive personal data: biometric categorisation systems that classify and identify natural persons based on sensitive personal data, or that are based on an inference related to such attributes or characteristics, in a way that such categorisation results in prejudicial or unjustified discriminatory treatment against them.
- Generic social rating systems: AI systems whose purpose is to evaluate or classify individuals or groups of individuals based on their social behaviour, socioeconomic status, or known or inferred personal or personality characteristics, in a way that the resulting classification results in prejudicial or unjustifiably discriminatory treatment of such individuals or groups of individuals.
- Remote biometric identification systems in public access spaces in real time: AI systems for video image analysis in public access spaces using real-time remote biometric identification systems.
- Systems for non-selective extraction of facial images: AI systems that create or extend facial recognition databases by non-selectively extracting facial images from the internet or CCTV images.
- Systems for the evaluation of a person's emotional states: AI systems that infer the emotions of a natural person in the fields of criminal law enforcement, criminal procedure and border management, in workplaces and in educational institutions.
Under the GenAI Measures, any organisation or individual is prohibited from:
- using generative AI services to generate any illegal content including content that endanger national security, national sovereignty or the socialist system, etc., or content that propagates terrorism, ethnic hatred, or any violent or obscene content, or false or harmful information; and
- exploiting advantages in terms of algorithms, data, platforms (from an intellectual property perspective) to carry out monopoly or unfair competition practices.
Under the Deep Synthesis Provisions, any organisation or individual is prohibited from:
- using deep synthesis services to engage in illegal activities including those that endanger national security and public interests, disrupt economic and social order, and infringe upon the legitimate rights and interests of others, etc.;
- using deep synthesis services to produce or distribute fake news; and
- using technical means to delete, alter or conceal labels added to information generated or edited using deep synthesis services.
Under the Recommendation Algorithms Provisions, service providers are prohibited from:
- using recommendation algorithm-based services to engage in illegal activities including those that endanger national security and public interests, disrupt economic and social order, and infringe upon the legitimate rights and interests of others, etc.;
- using recommendation algorithm-based services to disseminate information prohibited by laws and administrative regulations (and there is also a positive obligation for service providers to prevent the dissemination of bad information);
- setting up algorithm models that lead users into addiction or excessive consumption, or that are illegal or against ethics and morals;
- creating or producing false or misleading news content or sharing news from sources outside the parameters set by the government;
- using algorithms to create fake accounts, engage in illegal account trading, manipulate user accounts, or generate false likes, comments or shares;
- using algorithms to block information, make excessive recommendations, manipulate rankings in search results, control trends, or otherwise disrupt information presentation in a way that influences public opinion online or evade supervisory or regulatory oversight; and
- engage in monopolistic or unfair competitive practices by using algorithms to place unreasonable restrictions on other internet information service providers or disrupt their lawful operations.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Prohibited activities in Denmark
In accordance with Denmark’s opt-out from EU justice and home affairs, as set out in Protocol (No 22) on the position of Denmark, certain provisions of Article 5 of the EU AI Act do not apply in Denmark. This includes the use of AI for biometric categorization and emotion recognition in the context of police cooperation and criminal justice. Additionally, Article 5(1)(h) and paragraphs 2–6 of Article 5 are excluded. These exemptions reflect Denmark’s specific legal position within the EU.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions except for medical or safety reasons.
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Prohibited activities in France
In France, the CNCDH Opinion recommends to ban: (i) the use of choice interfaces whenever their purpose or effect is to manipulate users to their detriment by exploiting their vulnerabilities; (ii) all types of ‘social scoring’ implemented by public authorities or by any company, public or private; and (iii) the use of emotion recognition technologies, except for their use when they are intended to reinforce the autonomy of individuals, or more broadly the effectiveness of their fundamental rights.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Laws specifically addressing AI have not yet been introduced in Hong Kong.
Although not strictly prohibited due to its non-binding nature, the GenAI Guideline suggests that systems posing existential threats (e.g., uses causing harm or affecting human safety, subliminal manipulation) carry an unacceptable level of risk and should therefore be prohibited. Technology Developers should bear legal liability for creating such unacceptable risks in the development or deployment of generative AI technologies.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
India does not have a specific or standardised list of prohibitory AI uses.
AI uses that may trigger liability include the creation of deepfakes without consent, use of AI for spreading misinformation, identity theft, fraud, creation of unlawful content, and unlawful personal data processing or use of third-party content for AI training without the requisite consents (such as scraping). Liability may arise under the IT Act, the DPDPA, the Copyright Act, 1957, and other applicable laws, depending on the nature of the offence.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Prohibited activities in Ireland
The Irish Data Protection Commission has been active in opening a number of consultations and investigations on certain AI systems.
- In 2024 it ordered X to suspend training of an AI chatbot after issuing High Court proceedings pursuant to Section 134 of the Data Protection Act 2018.
- In 2024, it launched a statutory inquiry into Google Ireland under Section 110 of the DPA 2018, re compliance with DP obligations pursuant to Article 35 GDPR for its Pathways Language Model 2 (PaLM 2).
- In 23/24 the DPC engaged with Meta in relation to the training of its LLM using public content shared across the EU, which lead to the DPC seeking a formal GDPR opinion on the matter from the EDPB. Engagement with Meta and oversight of its implemented measures and improvements is ongoing.
In February 2025, the DPC also became one of five signatory data protection authorities on Paris declaration to reaffirm their commitment to implementing data governance that promotes innovative and privacy-protecting AI.
Israel has not adopted an AI‑specific list of prohibited practices. Instead, existing laws continue to apply to AI‑enabled conduct (e.g., privacy, consumer protection, non-discrimination, sectoral rules, cyber/security obligations). For personal data uses, the PPA’s draft guidance maps how the PPL applies to model training, testing and deployment; unlawful processing, excessive collection or incompatible use of personal data would contravene the PPL irrespective of whether AI is involved.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Currently, there are no laws in Japan that specifically address this point.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Prohibited activities in Malta
Malta has not introduced any additional categories of prohibited AI practices beyond those set out in Article 5 of the EU AI Act. The enforcement of the prohibitions contained in the EU AI Act falls within the remit of the competent Maltese authorities designated under Subsidiary Legislation 591.05 and Subsidiary Legislation 586.14, depending on the AI system concerned.
Laws specifically addressing AI have not been introduced in Mauritius yet (see the Definitions section).
Laws specifically addressing AI have not been introduced in Mexico yet. Article 9 of the AI Bill establishes that certain AI systems that can cause or cause serious physical or psychological harm to people when used, including use for biometric identification, are considered to be of unacceptable risk. This includes the marketing, sale, distribution and use, even free of charge, of AI systems of unacceptable risk specifically intended to:
- Alter the behaviour of any person, in such a way that causes, or is likely to cause, physical or psychological harm.
- Take advantage of the vulnerabilities of specific groups of people, whether due to age or physical or mental disability, to substantially alter their behaviour in a way that causes, or is likely to cause, physical or psychological harm.
- Classify people, in such a way that results in harm or damage to one or more people.
- Carry out remote biometric identification in real time in public access spaces without authorisation of the affected person, except in cases of public interest or national security.
- Alter in any way voice or image files of any person in order to modify their original content without authorisation of the affected person or whoever is the owner of the property rights.
Laws specifically prohibiting activities in relation to AI have not been introduced in Morocco yet. However, conduct carried out by means of AI may be caught by laws of general application, including Law No. 07-03, which criminalises fraudulent access to, and interference with, automated data processing systems, and the unauthorised alteration or deletion of data; Law No. 09-08, which prohibits the processing of personal data without a declaration or a prior authorisation from the data protection authority; and Law No. 17-97 and Law No. 2-00, under which infringement of industrial property and copyright is actionable.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Prohibited activities in the Netherlands
In 2024, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) opened a consultation on certain categories of prohibited AI systems within the Netherlands. On its website, the Dutch Data Protection Authority published summaries of the consultation regarding prohibited AI systems for emotion recognition in the workplace or educational institutions and for manipulative and exploitative AI systems. The Dutch Data Protection Authority has indicated they will provide additional guidance, which has not yet been published. No results are published yet of the consultation for prohibited AI systems for risk assessment of criminal offenses and for social scoring.
Laws specifically addressing AI have not been introduced in New Zealand yet. However, the Biometrics Code prohibits certain biometric processing activities by placing ‘safe limits’ on highly intrusive uses of biometrics, including predicting health, emotion or attention, or categorising into categories protected by the Human Rights Act 1993 (e.g., sex, race, age, disability). Although the Biometrics Code is not AI-specific, it imposes strict requirements around the deployment of AI-powered biometric systems.
Separately, the Crimes Act 1961 and Harmful Digital Communications Act 2015 create criminal offences for causing harm by posting digital communications and posting intimate visual recordings without consent, which is relevant to AI-generated harmful content. However, ‘deepfake’ images do not clearly fall within this definition. The Deepfake Digital Harm and Exploitation Bill is progressing through Parliament and proposes to expand these provisions to cover created or synthesised intimate images.
A standalone AI law has not yet been enacted in Nigeria, so there are no statutory prohibitions specific to AI.
The content on Prohibited activities in the European Union applies in Norway.
The AI Regulation introduces a risk-based regulatory framework and classifies certain uses of artificial intelligence as “improper use”, which are prohibited.
Prohibited uses include:
- AI systems intended to influence individuals’ decision-making in a deceptive or manipulative manner.
- AI systems with autonomous lethal capabilities in civil settings without human oversight.
- Mass surveillance without a legal basis or with disproportionate effects on fundamental rights.
- The use of biometric data to analyse, classify or infer sensitive characteristics, or to classify individuals or groups in a manner that generates discriminatory or disproportionate outcomes.
- Real-time biometric identification for the categorisation of individuals in public spaces, subject to limited exceptions.
- Predicting that an individual will commit a crime based on profiling, personality traits or other individual characteristics.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
There is no general list of AI‑specific prohibited practices in Saudi Arabia.
However, prohibited uses of AI may include:
- Unlawful processing and disclosure of personal data contrary to the PDPL (e.g., processing without a valid legal basis, purpose incompatibility, or disclosure without authority).
- Breaches of records, classification, and disclosure duties for official documents and information, including preservation and lawful communication requirements.
- The use of AI to store or generate content which impinges on ‘public order, religious values, public morals, or privacy’. Such conduct is a criminal offence under the Anti-Cyber Crime Law (Royal Decree No. M/17, 2007).
Under SDAIA's non-binding AI Ethics Principles, AI systems that pose an ‘unacceptable risk’ to people’s safety, livelihood, and rights (such as AI systems used to conduct social profiling or child exploitation) should not be allowed.
Laws specifically addressing AI have not yet been introduced in Singapore.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Prohibited activities in the Slovak Republic
The draft law does not introduce additional categories of prohibited AI practices beyond those established under the EU AI Act. Instead, it empowers Slovak supervisory authorities to monitor compliance with the prohibitions set out in the EU AI Act and to take corrective actions where violations occur.
Where an AI system is contrary to the requirements of the EU AI Act, the competent authority may require corrective measures, restrict or prohibit the placing of the system on the market, prohibit its deployment, order its withdrawal from the market, or require its recall from users. These measures are intended to ensure effective enforcement of the directly applicable EU prohibitions.
The draft law also establishes inspection powers enabling authorities to obtain access to premises, technical documentation, information systems, logs and other materials necessary to verify compliance.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
While not AI-specific legislation, section 71 of the Protection of Personal Information Act, 2013, South Africa's data privacy law, regulates automated decision-making and generally prohibits decisions based solely on the automated processing of personal information where those decisions have legal effects on individuals, subject to certain exceptions.
Other laws specifically prohibiting AI activities have not been introduced in South Africa. Conduct carried out by means of AI will, however, also be subject to laws of general application.
The AI Act does not specifically enumerate or stipulate any specific prohibited actions (in contrast to the treatment of prohibited AI practices under the EU AI Act). However, actions that are already prohibited under existing laws and regulations, such as infringement of copyright or privacy, and distribution and publication of illegal information and contents, may still be problematic in relation to AI-related services.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Prohibited activities in Spain
The Spanish Draft AI Bill builds on the substantive prohibitions established in the EU AI Act and introduces a national supervisory and enforcement framework, with particular attention to the use of biometric systems and AI applications in sensitive areas such as law enforcement, migration, justice and democratic processes.
In relation to real-time remote biometric identification systems used for law enforcement purposes in publicly accessible spaces, the Spanish Draft AI Bill reinforces compliance with the EU AI Act by establishing specific obligations linked to authorisation, accountability and oversight. In particular:
- The use of such systems is only permitted in cases expressly allowed under the EU AI Act.
- Prior authorisation is generally required before deployment, except in duly justified situations of urgency.
- Where an emergency deployment takes place before authorisation is obtained, the authorisation request must be submitted within the legally prescribed timeframe.
- The operation must comply with the temporal, geographical and personal limitations established in the relevant authorisation.
- If authorisation is ultimately refused following an emergency deployment, the data, results and outputs generated during the operation must be deleted.
- Each operation must be notified to the competent authorities in accordance with the applicable legal requirements.
The Spanish Draft AI Bill also establishes a specialised supervisory framework for biometric systems. Depending on the sector and intended use of the AI system, market surveillance responsibilities are allocated between AESIA, the Spanish Data Protection Agency (AEPD) and the General Council of the Judiciary (CGPJ). Particular supervisory arrangements apply to biometric systems used in migration and border management, law enforcement, the administration of justice and democratic processes.
In addition, the Spanish Draft AI Bill designates AESIA as the market surveillance authority for certain high-risk AI systems intended to influence electoral outcomes, referendums or voting behaviour, as well as for certain biometric systems used in democratic processes. Systems used solely for administrative or logistical campaign purposes, and biometric verification systems whose sole purpose is to confirm a person's claimed identity, are excluded from these specific provisions.
Certain AI practices are banned outright under Article 5 of the EU AI Act due to their potential for harm and ethical concerns. These prohibitions aim to protect EU citizens from the most intrusive and potentially abusive uses of AI.
Under Article 5, these uses and technologies include:
- Subliminal techniques: Deploying subliminal techniques or techniques that are manipulative or deceptive and have the effect or objective of materially distorting those people by impairing their ability to make an informed decision, causing them to make a decision they would not otherwise have taken, in a manner that causes significant harm to them or others (or is reasonably likely to).
- Exploiting vulnerabilities: Exploiting vulnerabilities of specific groups due to age, disability, or social or economic situation – as with subliminal techniques, this must have the effect or objective of materially distorting behaviour and cause significant harm to them or others (or be reasonably likely to).
- Social scoring: Evaluating or classifying natural persons or groups based on their social behaviours or personality characteristics (known, inferred or predicted) leading to either or both, unfavourable treatment of them or others in social contexts unrelated to the context in which the data was originally gathered or that is unjustified or disproportionate to their social behaviour or its gravity.
- Crime profiling: Assessing the risk of an individual committing a crime, based on the profiling of that person and assessing their personality traits (as opposed to using such systems to support a human assessment of the involvement of a person).
- Facial recognition databases: Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
- Inferring emotions: Inferring emotions in workplaces and educational institutions (except for medical or safety reasons).
- Biometric categorisation: Categorising natural persons based on their biometric data to deduce or infer sensitive information about them (i.e. their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation) except where based on lawfully acquired datasets (including in law enforcement).
- Biometric identification: Engaging in ‘real-time’ biometric identification systems in publicly accessible spaces for law enforcement purposes, except under specific exempt circumstances.
Although laws specifically addressing AI have not been introduced in Thailand yet, the Draft AI Law Principles (2025) determines that sectoral regulators shall have the authority to issue subordinate regulations on AI prohibited-risks or high-risk, in order to address the specific needs of each authority. The appointed regulator will issue subordinate regulations on AI prohibited-risks or high-risk not otherwise regulated by the sectoral regulators.
Laws specifically addressing AI have not been enacted in Türkiye yet. On the other hand, the novel amendments made to the Advertising Regulation prohibit misleading AI-generated advertising, including the use of AI-generated replicas that falsely imply a real person’s endorsement, and require clear disclosure where AI materially influences consumers or creates realistic digital characters.
There is no unified federal law or emirate level law in the UAE that has a primary focus on regulating AI (and therefore no prohibited activities).
The DIFC’s Data Protection Regulations do not classify AI Systems into unacceptable risk, high risk, limited risk and minimal risk, nor contain any practices that are expressly prohibited. However, the regulations do prohibit the use, operation or provision of an AI System to engage in high risk processing activities unless the DIFC’s Commissioner for Data Protection has established audit and certification requirements for such AI Systems. ’High risk processing activities’ is defined as processing of personal data where one or more of the following applies:
- processing that includes the adoption of new or different technologies or methods, which creates a materially increased risk to the security or rights of a data subject or renders it more difficult for a data subject to exercise their rights;
- a considerable amount of personal data will be processed (including staff and contractor personal data) and where such processing is likely to result in a high risk to the data subject, including due to the sensitivity of the personal data or risks relating to the security, integrity or privacy of the personal data;
- the processing will involve a systematic and extensive evaluation of personal aspects relating to natural persons, based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; or
- a material amount of special categories of personal data is to be processed.
Given no audit and certification requirements have been established at present, there is a de-facto prohibition on the use of AI Systems for high risk processing activities. The Commissioner has confirmed that no AI System may be used for high risk processing activities until the audit and certification requirements have been established.
There is no single UK statute specifically prohibiting AI activities. However, DUAA introduced new criminal offences relevant to the use of AI, including the offences of creating, or requesting the creation of, a ‘purported intimate image of an adult’ (i.e. non-consensual sexual deepfakes). These offences, inserted into the Sexual Offences Act 2003 by section 138 of the DUAA, came into force on 6 February 2026. In addition, the Crime and Policing Act 2026 criminalises the making, adapting, supplying or offering to supply ‘nudification’ tools (software that generates or facilitates the generation of purported intimate images of a person). The Act broadly defines ‘thing’ to include a program, information in electronic form and a service. A defence applies where the defendant proves they took all reasonable steps to prevent the thing being used for creating purported intimate images without consent. These provisions complement existing offences under the Online Safety Act 2023 relating to the sharing or threatening to share intimate content without consent.
As noted in the Law / proposed law section, the US has not enacted a comprehensive federal law that explicitly outlines prohibited uses of AI. However, certain AI-related activities are restricted or prohibited under existing laws and proposed legislation. Enforcement actions have been taken under broader legal authorities such as consumer protection, civil rights, and securities laws.
At the federal level, two of the many proposed bills aiming to prohibit specific AI practices are:
- The Preventing Algorithmic Collusion Act (2025), which would ban the use of pricing algorithms—including those powered by AI—to incorporate nonpublic competitor data to facilitate price-fixing
- The Transparency and Responsibility for Artificial Intelligence Networks Act (TRAIN Act) (2025), which would create an administrative subpoena process allowing copyright owners to compel AI developers to disclose copies of, or records sufficient to identify, copyrighted works used to train generative artificial intelligence models
- The Guidelines for User Age-verification and Responsible Dialogue Act (GUARD Act) (2025), which would require AI chatbots to implement age-verification measures, bar minors from accessing AI “companion” chatbots, mandate disclosures that users are interacting with a non-human system lacking professional credentials, and prohibit chatbots that encourage self-harm or engage minors in sexual conduct. The U.S. Senate Judiciary Committee unanimously advanced the bill on 30 April 2026, and it was reported to the Senate on 11 May 2026.
While these bills have not become law, federal agencies have used existing statutes that prohibit deceptive or harmful AI practices. For example:
- The FTC has taken enforcement action against companies for “AI washing” (misleading claims about AI capabilities) and is studying the business practices of companies that offer companion chatbots, focusing on their effect on children
- The SEC has charged firms for misrepresenting the role of AI in investment strategies
- The DOJ has pursued criminal charges in cases involving fraudulent claims about AI functionality
At the state level, some jurisdictions have enacted laws that explicitly prohibit certain AI uses, such as:
- Utah’s AI Policy Act, which prohibits the undisclosed use of generative AI in regulated occupations (e.g. legal, medical), requires clear disclosure when AI is used in consumer interactions, and holds individuals liable for AI-driven misconduct under state consumer protection laws
- New York City’s Local Law 144, which prohibits the use of automated employment decision tools without prior bias audits and candidate notification
- California and Illinois, which have passed laws restricting the unauthorized use of AI-generated digital replicas and require transparency in political advertising
Overall, while the US lacks a unified list of federally prohibited AI activities, a growing patchwork of federal enforcement actions and state-level statutes is continuing to define the boundaries of acceptable AI use.