EU AI Act Art. 5: prohibited practices (incl. new NCII and CSAM bans)

Prohibited practices; new bans on AI-generated non-consensual intimate imagery (NCII) and CSAM

From clause to evidenceThe chain from EU AI Act Art. 5 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseEU AI ActArt. 5Duty holderProvider +deployerApplies from2025-02-02In forceArtefactPolicy-as-codeblocklistLayersLayer 01Layer 04Evidence recordClassificationdecision recordSame topic in 12 frameworks (26 clauses): ISO 42001, NIST AI RMF, TC260 Framework 3.0, China GenAI Measures, China DeepSynthesis, CSA AICM, OWASP LLM and 5 moreAs of 2026-09-24 · illustrative, not a claim of conformity From clause to evidenceThe chain from EU AI Act Art. 5 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseEU AI Act · Art. 5Duty holderProvider + deployerApplies from2025-02-02 · In forceArtefactPolicy-as-code blocklistLayersLayer 01Layer 04Evidence recordClassification decision recordSame topic in 12 frameworks (26 clauses):ISO 42001, NIST AI RMF, TC260 Framework 3.0,China GenAI Measures, China Deep Synthesis…As of 2026-09-24illustrative, not a claim of conformity
From clause to evidence Build the artefact, then file every output it produces as a record that names AIGE-OBL-EUAIA-ART5. Drawn from chapter 08.
Text alternative
  • Clause: EU AI Act, Art. 5.
  • Duty holder: Provider + deployer.
  • Applies from: 2025-02-02, In force.
  • Artefact: Policy-as-code blocklist.
  • Layers: Layer 01, Layer 04.
  • Evidence record: Classification decision record.
  • Record schemas: Classification decision record .
  • The same topic in 12 other frameworks; the crosswalk section below links each clause.
Id
AIGE-OBL-EUAIA-ART5
Instrument
EU AI Act (post-Omnibus) law
Compared side by side
ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
Clause
Art. 5
Duty holder
Provider + deployer
Authority
National MSA
Applies from
In force · 2026-12-02 (new bans); earlier prohibitions from 2025-02-02
Later dates
  • New bans on AI-generated NCII and CSAM apply
System class
Prohibited practice

The artefact that evidences it

Policy-as-code blocklist; input/output guardrails; refusal and abuse detection.

Patterns that build it

The same topic in other frameworks

From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.

Runtime guardrails

Cases that cite this article

Open controls that evidence it

Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.

Source

Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.

Machine-readable

Cite this obligation

García Aibar, J. (2026). EU AI Act Art. 5: prohibited practices (incl. new NCII and CSAM bans) (AIGE-OBL-EUAIA-ART5). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5. CC BY 4.0

BibTeX

@misc{aige2026obligation,
  author       = {Jorge García Aibar},
  title        = {{EU AI Act Art. 5: prohibited practices (incl. new NCII and CSAM bans) (AIGE-OBL-EUAIA-ART5)}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5},
  note         = {Version 0.5.0}
}