Search legal guides

Search MJ Kotze Inc legal guides and articles

EU AI Act

AI uses that are banned outright

Some AI uses are not regulated in Europe — they are simply illegal. Four of them catch ordinary businesses, one of them very often. These carry the largest fines in the Act, and they have been enforceable since February 2025.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

Why this list matters more than the rest of the Act

Most of the EU AI Act is about doing things properly — documenting, testing, disclosing, overseeing. This part is different. It is a list of things you may not do at all, however carefully you do them.

Three features make it the first thing a South African business should look at. It has been in force since February 2025, so there is no runway left. It carries the highest penalties in the Act. And it is the part most likely to be breached by accident, because the exposure usually comes from a feature someone switched on in a platform you bought — not from a decision anyone consciously made.

Several items on the statutory list read as exotic — real-time biometric surveillance in public spaces, predictive policing based on personality. Those are aimed at state actors. Five are not.

The five that catch ordinary businesses

1

Reading employees’ emotions at work

You may not use AI to infer how someone feels in the workplace or in education, where it does so from their biometric signals — their face, their voice, their physical reactions. There is a narrow exception for medical or safety reasons, such as detecting a driver falling asleep.

This is the prohibition most likely to reach an ordinary South African business, because the capability ships as a standard feature rather than an exotic one. Contact-centre platforms offer agent emotion analytics; video-interview tools offer emotion scoring on candidates. Where those work off voice or facial signals in a workplace or education setting, they are in prohibited territory. The boundary matters, though — see the note below on what is probably not caught.

2

Scoring people on their behaviour or characteristics

You may not evaluate or classify people over time based on their social behaviour or their personal characteristics where the resulting score leads to them being treated badly — either in a context unrelated to where the data came from, or out of all proportion to what they actually did.

People assume this is aimed at governments. It is not limited to them, and private scoring schemes can be caught. But note that scoring on its own is not the offence: the prohibition requires the score to produce detrimental treatment of one of those two kinds. The realistic risk sits in loyalty, risk-rating and customer-tiering programmes that quietly borrow signals from an unrelated part of the business and then penalise people on the strength of them.

3

Scraping faces to build a recognition database

You may not build or expand facial-recognition databases by untargeted scraping of facial images from the internet or from CCTV footage.

For most businesses this is a supplier question rather than something they did themselves. If you buy facial recognition, ask where the training images came from and get the answer in writing. "We do not know" is not an acceptable answer when the penalty tier is this high.

4

Manipulating or exploiting people

You may not use AI techniques that are deliberately manipulative or deceptive, or that exploit someone’s vulnerability — their age, disability, or economic or social situation — in a way that materially distorts their behaviour and causes, or is likely to cause, significant harm.

One correction worth making to how this is usually described: the prohibition is not limited to subliminal techniques operating below conscious awareness. Purposefully manipulative or deceptive techniques are covered in their own right, whether or not the person notices them. What keeps ordinary marketing outside the ban is the rest of the test — the behaviour must be materially distorted, and significant harm must be caused or likely. Nothing here stops you recommending products well. For most businesses the practical value is knowing the outer limit exists on how aggressive an optimisation loop may become, and it is a good question to put to any vendor selling “behavioural” anything.

5

Using biometrics to infer sensitive characteristics

You may not use biometric categorisation systems that classify people individually on the basis of their biometric data in order to deduce or infer their race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation.

This one is easy to trip over without intending anything of the kind, which is why it belongs on a business list rather than a civil-liberties one. Any product that categorises people from facial images or other biometric signals should be checked for whether the categories it produces — or the ones a customer could derive from them — fall into this list.

New from December 2026

The amending regulation that came into force on 27 July 2026 added one further prohibition, applying from 2 December 2026: AI systems that generate non-consensual sexually explicit or intimate content, or child sexual abuse material. It carries the same top penalty tier. For most businesses this raises no operational question — but it is a useful reminder that the banned list is capable of growing, and that a compliance position taken once is not a compliance position forever.

These follow your output into Europe

A South African business might reasonably ask why a European prohibition is its problem. The answer is that the bans apply to providers and deployers in third countries whose systems’ output is used in Europe.

A South African supplier of interview-analytics software used by European employers cannot shelter behind its location. Nor can a South African contact centre whose agent-sentiment scores are delivered to a European client. The prohibitions travel with the output.

And if nothing you produce reaches Europe? The Act’s bans do not apply to you — but check your vendor terms before relaxing. The major AI and cloud providers have written the same restrictions into their global acceptable-use policies, so you may be bound to them by contract regardless of what the law requires. More on the vendor-terms channel.

A six-point screen for your own stack

This is the version to hand your operations team. Go tool by tool through your AI inventory and answer six questions. Anything that returns a yes and touches Europe should stop until it has been properly assessed.

1

Contact centre and workforce tools

Does any tool infer how your staff feel from their voice, face or physical reactions — tone, stress, frustration, engagement?

The most likely exposure in South Africa, because emotion analytics ships as a standard feature in contact-centre platforms and is often switched on by default. Note the signal it works from: voice and face are biometric and squarely in scope; scoring the words in a written transcript probably is not.

2

Recruitment

Does your interview or assessment software analyse a candidate’s facial expressions, tone of voice or emotional state?

Video-interview emotion scoring sits squarely in the prohibition where the workplace or an education setting is involved. Ordinary CV screening is not banned — but it is high-risk from December 2027.

3

Customer scoring and segmentation

Do you score people on general behaviour or personal characteristics, then use that score to treat them worse in an unrelated part of the business?

Social scoring is not limited to governments. A private scheme that penalises someone in one context because of behaviour in a completely different one can be caught.

4

Marketing and personalisation

Does any technique deliberately manipulate or deceive people, or exploit a vulnerability such as age, disability or economic situation, in a way that could cause real harm?

Ordinary personalisation is fine. Note the test is not limited to subliminal techniques — purposeful manipulation or deception counts even where the person can perceive it. What keeps normal marketing outside the ban is that behaviour must be materially distorted and significant harm caused or likely.

5

Identity and security

Does any system you use build or expand a facial-recognition database by scraping faces from the internet or CCTV?

Untargeted scraping is banned outright. This is usually a vendor question rather than something you built — ask where their training images came from.

6

Biometric categorisation

Does any system classify people from biometric data in a way that could deduce race, political opinions, trade-union membership, religion or philosophical beliefs, sex life or sexual orientation?

A separate prohibition, and easy to trigger without intending to. Ask not only what categories the product outputs, but what a customer could infer from them.

Frequently asked

Which banned practices realistically affect a South African business?

Five, and one of them far more than the rest. Inferring employees’ emotions from their voice or face is the common one, because emotion analytics ships as a standard feature in contact-centre and video-interview platforms and is often enabled without anyone making a decision about it. The others are social scoring where the score leads to detrimental treatment, untargeted scraping of facial images to build recognition databases, manipulative or deceptive techniques that cause significant harm, and biometric categorisation used to infer sensitive characteristics such as race, religion or sexual orientation. Everything else on the list — real-time biometric surveillance by police, predictive policing on personality profiling — is aimed at state actors and will not touch an ordinary company.

We are in South Africa. Do the bans really apply to us?

They apply to third-country providers and deployers whose systems’ output is used in the EU. So a South African supplier of interview-analytics software used by European employers cannot shelter behind its location. If your AI output is used in Europe, the prohibitions travel with it. If nothing you produce reaches Europe, the Act’s bans do not apply — but note that your AI and cloud vendors have written the same restrictions into their global terms, so you may well be bound to them by contract anyway.

Full guide: does the EU AI Act apply to my business?

Is contact-centre sentiment analysis really illegal?

It depends on what the tool actually analyses, and the distinction is well settled enough to act on. The prohibition bites where an AI system infers the emotions of a person in the workplace, and the Act defines emotion recognition as inferring emotions "on the basis of their biometric data". Analysing an agent’s voice — tone, pitch, stress — is biometric, so voice-based emotion analytics on staff is squarely in prohibited territory where the output reaches Europe. Analysing the words in a written transcript is not biometric: the Commission’s February 2025 guidelines expressly give text sentiment analysis as an example outside the prohibition. Things like call transcription, keyword spotting and talk-time analysis infer no emotions at all and are not caught either. So the practical step for a South African BPO serving European clients is to establish exactly which analytics are switched on and what signal each works from — voice and face are the ones to stop; text-based scoring generally is not. Bear in mind the guidelines are non-binding interpretation, and that keeping a tool outside Article 5 does not settle its position under data-protection or equality law.

What is the fine?

The top tier: up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Worldwide — not European. For a South African group that means global revenue is the base. For SMEs, including start-ups, the cap is the lower of the two figures rather than the higher. These prohibitions have been enforceable since 2 February 2025, so this is not a future problem.

What changes in December 2026?

A new prohibition was added by the amending regulation that came into force on 27 July 2026, and it applies from 2 December 2026: AI systems for generating non-consensual intimate imagery or child sexual abuse material. It carries the same top penalty tier as the rest of the list. For most businesses this is not an operational issue, but it is worth knowing the list is capable of growing.

How do we check our own systems?

Run a screen rather than an audit. Go tool by tool through your AI inventory and ask six questions: does anything infer how staff feel from voice or face; does any recruitment tool read faces or voices; do you score people as people and then penalise them elsewhere; does any technique manipulate, deceive or exploit vulnerability in a way that could cause real harm; does any facial-recognition vendor build its database by scraping; and does anything categorise people biometrically in a way that could reveal race, politics, union membership, religion, sex life or sexual orientation. Anything that returns a yes and touches Europe should stop until it has been properly assessed. The six-point screen on this page is the version to hand your operations team.

Has anyone actually been fined yet?

Not as at early August 2026 — no fines had been publicly reported against any company, European or foreign. But read that in context rather than as reassurance. The Commission’s AI Office only became entitled to exercise its investigation and enforcement powers over prohibited practices on 2 August 2026, and many national regulators are still being stood up. The absence of enforcement reflects a machine that has only just been switched on, not a regulator that has looked and shrugged. The prohibitions themselves have been legally binding since 2 February 2025, and the bans and transparency duties are the two areas where the first actions are widely expected.

Can you screen our AI stack?

Yes. A prohibited-practice and transparency screen runs from R9,500: we work through your AI inventory tool by tool, identify anything inside the banned list or requiring disclosure, and give you a written record of the assessment and the fixes. It usually pays for itself on the contact-centre analytics question alone. Where a broader picture is needed, the full exposure assessment runs from R15,000.

The other rules already in force are the transparency duties. For the bigger picture, start with the overview of the EU AI Act for South African businesses.

Sources & authorities

  1. 1.AI Act, Article 5 — prohibited AI practices
  2. 2.AI Act, Article 99 — penalties
  3. 3.AI Act, Article 2 — scope
  4. 4.European Commission — guidelines on prohibited AI practices, C(2025) 884 (4 February 2025) — non-binding
  5. 5.AI Act, Article 3(39) — definition of “emotion recognition system”, and 3(34) “biometric data”
  6. 6.European Commission — AI Omnibus enters into force (new prohibition from 2 December 2026)
  7. 7.Regulation (EU) 2024/1689 (the AI Act) — full text, EUR-Lex
  8. 8.Protection of Personal Information Act 4 of 2013 (POPIA)

Every authority above was checked against its primary source in August 2026. This page is general information about South African law, not legal advice.

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.