EU AI Act
AI uses that are banned outright
Some AI uses are not regulated in Europe — they are simply illegal. Four of them catch ordinary businesses, one of them very often. These carry the largest fines in the Act, and they have been enforceable since February 2025.
Written by
Martin Kotze
Attorney, Conveyancer & Notary Public
Last reviewed:
Why this list matters more than the rest of the Act
Most of the EU AI Act is about doing things properly — documenting, testing, disclosing, overseeing. This part is different. It is a list of things you may not do at all, however carefully you do them.
Three features make it the first thing a South African business should look at. It has been in force since February 2025, so there is no runway left. It carries the highest penalties in the Act. And it is the part most likely to be breached by accident, because the exposure usually comes from a feature someone switched on in a platform you bought — not from a decision anyone consciously made.
Several items on the statutory list read as exotic — real-time biometric surveillance in public spaces, predictive policing based on personality. Those are aimed at state actors. Four are not.
The four that catch ordinary businesses
Reading employees’ emotions at work
You may not use AI to infer how someone feels in the workplace or in education, where it does so from their biometric signals — their face, their voice, their physical reactions. There is a narrow exception for medical or safety reasons, such as detecting a driver falling asleep.
This is the prohibition most likely to reach an ordinary South African business, because the capability ships as a standard feature rather than an exotic one. Contact-centre platforms offer agent emotion analytics; video-interview tools offer emotion scoring on candidates. Where those work off voice or facial signals in a workplace or education setting, they are in prohibited territory. The boundary matters, though — see the note below on what is probably not caught.
Scoring people on their behaviour or characteristics
You may not evaluate or classify people over time based on their social behaviour or their personal characteristics where the resulting score leads to them being treated badly — either in a context unrelated to where the data came from, or out of all proportion to what they actually did.
People assume this is aimed at governments. It is not limited to them, and private scoring schemes can be caught. But note that scoring on its own is not the offence: the prohibition requires the score to produce detrimental treatment of one of those two kinds. The realistic risk sits in loyalty, risk-rating and customer-tiering programmes that quietly borrow signals from an unrelated part of the business and then penalise people on the strength of them.
Scraping faces to build a recognition database
You may not build or expand facial-recognition databases by untargeted scraping of facial images from the internet or from CCTV footage.
For most businesses this is a supplier question rather than something they did themselves. If you buy facial recognition, ask where the training images came from and get the answer in writing. "We do not know" is not an acceptable answer when the penalty tier is this high.
Manipulating or exploiting people
You may not use AI techniques that are deliberately manipulative or deceptive, or that exploit someone’s vulnerability — their age, disability, or economic or social situation — in a way that materially distorts their behaviour and causes, or is likely to cause, significant harm.
Ordinary marketing personalisation is not banned, and nothing here stops you from recommending products well. The prohibition targets techniques that operate below a person’s conscious awareness, or that deliberately target vulnerability, and that cause real harm. For most businesses the practical value is simply knowing the boundary exists — it sets an outer limit on how aggressive an optimisation loop is allowed to become, and it is a good question to put to any vendor selling “behavioural” anything.
New from December 2026
The amending regulation that came into force on 27 July 2026 added one further prohibition, applying from 2 December 2026: AI systems that generate non-consensual sexually explicit or intimate content, or child sexual abuse material. It carries the same top penalty tier. For most businesses this raises no operational question — but it is a useful reminder that the banned list is capable of growing, and that a compliance position taken once is not a compliance position forever.
These follow your output into Europe
A South African business might reasonably ask why a European prohibition is its problem. The answer is that the bans apply to providers and deployers in third countries whose systems’ output is used in Europe.
A South African supplier of interview-analytics software used by European employers cannot shelter behind its location. Nor can a South African contact centre whose agent-sentiment scores are delivered to a European client. The prohibitions travel with the output.
And if nothing you produce reaches Europe? The Act’s bans do not apply to you — but check your vendor terms before relaxing. The major AI and cloud providers have written the same restrictions into their global acceptable-use policies, so you may be bound to them by contract regardless of what the law requires. More on the vendor-terms channel.
A five-point screen for your own stack
This is the version to hand your operations team. Go tool by tool through your AI inventory and answer five questions. Anything that returns a yes and touches Europe should stop until it has been properly assessed.
Contact centre and workforce tools
Does any tool infer how your staff feel from their voice, face or physical reactions — tone, stress, frustration, engagement?
The most likely exposure in South Africa, because emotion analytics ships as a standard feature in contact-centre platforms and is often switched on by default. Note the signal it works from: voice and face are biometric and squarely in scope; scoring the words in a written transcript probably is not.
Recruitment
Does your interview or assessment software analyse a candidate’s facial expressions, tone of voice or emotional state?
Video-interview emotion scoring sits squarely in the prohibition where the workplace or an education setting is involved. Ordinary CV screening is not banned — but it is high-risk from December 2027.
Customer scoring and segmentation
Do you score people on general behaviour or personal characteristics, then use that score to treat them worse in an unrelated part of the business?
Social scoring is not limited to governments. A private scheme that penalises someone in one context because of behaviour in a completely different one can be caught.
Marketing and personalisation
Does any technique deliberately exploit a person’s vulnerability, or work below their conscious awareness, in a way that could cause real harm?
Ordinary personalisation is fine. The boundary sits at manipulation that materially distorts behaviour and causes significant harm — a line personalisation teams should know exists.
Identity and security
Does any system you use build or expand a facial-recognition database by scraping faces from the internet or CCTV?
Untargeted scraping is banned outright. This is usually a vendor question rather than something you built — ask where their training images came from.
Frequently asked
Which banned practices realistically affect a South African business?
Four, and one of them far more than the rest. Inferring employees’ emotions from their voice or face is the common one, because emotion analytics ships as a standard feature in contact-centre and video-interview platforms and is often enabled without anyone making a decision about it. The other three are social scoring where the score leads to detrimental treatment, untargeted scraping of facial images to build recognition databases, and manipulative or exploitative techniques that cause significant harm. Everything else on the list — real-time biometric surveillance by police, predictive policing on personality profiling — is aimed at state actors and will not touch an ordinary company.
We are in South Africa. Do the bans really apply to us?
They apply to third-country providers and deployers whose systems’ output is used in the EU. So a South African supplier of interview-analytics software used by European employers cannot shelter behind its location. If your AI output is used in Europe, the prohibitions travel with it. If nothing you produce reaches Europe, the Act’s bans do not apply — but note that your AI and cloud vendors have written the same restrictions into their global terms, so you may well be bound to them by contract anyway.
Is contact-centre sentiment analysis really illegal?
It depends on what the tool actually analyses, and the distinction is worth getting right before anyone panics. The prohibition bites where an AI system infers the emotions of a person in the workplace, and the Act defines emotion recognition as inferring emotions "on the basis of their biometric data". Analysing an agent’s voice — tone, pitch, stress — is biometric, so voice-based emotion analytics on staff is squarely in prohibited territory where the output reaches Europe. Analysing the words in a written chat transcript generally is not biometric, so plain text-based sentiment scoring is probably outside the ban — though the Commission has not resolved the point and the safer course is not to assume. Things like call transcription, keyword spotting and talk-time analysis infer no emotions at all and are not caught. The practical step for a South African BPO serving European clients is to establish exactly which analytics are switched on and what signal each one works from, then decide item by item.
What is the fine?
The top tier: up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Worldwide — not European. For a South African group that means global revenue is the base. Smaller businesses get the gentler reading, where the cap is the lower of the two figures rather than the higher. These prohibitions have been enforceable since 2 February 2025, so this is not a future problem.
What changes in December 2026?
A new prohibition was added by the amending regulation that came into force on 27 July 2026, and it applies from 2 December 2026: AI systems for generating non-consensual intimate imagery or child sexual abuse material. It carries the same top penalty tier as the rest of the list. For most businesses this is not an operational issue, but it is worth knowing the list is capable of growing.
How do we check our own systems?
Run a screen rather than an audit. Go tool by tool through your AI inventory and ask five questions: does anything score how staff sound or feel; does any recruitment tool read faces or voices; do you score people as people and then penalise them elsewhere; does any personalisation exploit vulnerability; and does any facial-recognition vendor build its database by scraping. Anything that returns a yes and touches Europe should stop until it has been properly assessed. The five-point screen on this page is the version to hand your operations team.
Has anyone actually been fined yet?
Not as at early August 2026 — no fines had been publicly reported against any company, European or foreign. But read that in context rather than as reassurance. The Commission’s AI Office only became entitled to exercise its investigation and enforcement powers over prohibited practices on 2 August 2026, and many national regulators are still being stood up. The absence of enforcement reflects a machine that has only just been switched on, not a regulator that has looked and shrugged. The prohibitions themselves have been legally binding since 2 February 2025, and the bans and transparency duties are the two areas where the first actions are widely expected.
Can you screen our AI stack?
Yes. A prohibited-practice and transparency screen runs from R9,500: we work through your AI inventory tool by tool, identify anything inside the banned list or requiring disclosure, and give you a written record of the assessment and the fixes. It usually pays for itself on the contact-centre analytics question alone. Where a broader picture is needed, the full exposure assessment runs from R15,000.
The other rules already in force are the transparency duties. For the bigger picture, start with the overview of the EU AI Act for South African businesses.
Sources & authorities
- 1.AI Act, Article 5 — prohibited AI practices
- 2.AI Act, Article 99 — penalties
- 3.AI Act, Article 2 — scope
- 4.European Commission — guidelines on prohibited AI practices, C(2025) 884 (4 February 2025) — non-binding
- 5.AI Act, Article 3(39) — definition of “emotion recognition system”
- 6.European Commission — AI Omnibus enters into force (new prohibition from 2 December 2026)
- 7.Regulation (EU) 2024/1689 (the AI Act) — full text, EUR-Lex
- 8.Protection of Personal Information Act 4 of 2013 (POPIA)
Every authority above was checked against its primary source in August 2026. This page is general information about South African law, not legal advice.
For the businesses we act for
The Keystone Workspace
The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.
Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.
This guide is general information, not legal advice for your specific matter.