EU AI Act Art. 5: prohibited practices (incl. new NCII and CSAM bans)
Prohibited practices; new bans on AI-generated non-consensual intimate imagery (NCII) and CSAM
AIGE-OBL-EUAIA-ART5. Drawn from chapter 08.
Text alternative
- Clause: EU AI Act, Art. 5.
- Duty holder: Provider + deployer.
- Applies from: 2025-02-02, In force.
- Artefact: Policy-as-code blocklist.
- Layers: Layer 01, Layer 04.
- Evidence record: Classification decision record.
- Record schemas: Classification decision record .
- The same topic in 12 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-EUAIA-ART5- Instrument
- EU AI Act (post-Omnibus) law
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs EU AI Act
- Clause
- Art. 5
- Duty holder
- Provider + deployer
- Authority
- National MSA
- Applies from
- In force · 2026-12-02 (new bans); earlier prohibitions from 2025-02-02
- Later dates
-
- New bans on AI-generated NCII and CSAM apply
- System class
- Prohibited practice
The artefact that evidences it
Policy-as-code blocklist; input/output guardrails; refusal and abuse detection.
Patterns that build it
- Use-Case Intake & Risk Tiering (layer 1 and 2)
- Deactivation, Localisation & Retirement Runbook (layer 4 and 2)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Runtime guardrails
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2 MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by relevant AI actors (core)
- TC260 Framework 3.0 TC260 App. 2 II.5 Dynamic runtime management (core)
- TC260 Framework 3.0 TC260 3.2.1 Technological countermeasures for agentic AI (core)
- China GenAI Measures GenAI Art. 10 Guided, bounded use (core)
- China GenAI Measures GenAI Art. 14 Stop unlawful generation (core)
- China Deep Synthesis DeepSyn Art. 10 Input and output review (core)
- CSA AICM TVM-13 Guardrails (core)
- CSA AICM AIS-09 Input Validation (core)
- CSA AICM AIS-10 Output Validation (core)
- OWASP LLM LLM01:2026 Prompt Injection (core)
- OWASP LLM LLM10:2026 Improper Output Handling (core)
- Singapore Agentic Agentic 2.3.1 During design and development, use technical controls (core)
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity
- ISO 42001 A.6 AI system life cycle
- China Algo. Rec. AlgoRec Art. 8 Periodic algorithm review
- China Algo. Rec. AlgoRec Art. 9 Feature database for unlawful content
- GPAI Code Safety C5 Commitment 5: Safety mitigations
- OWASP LLM LLM06:2026 Unbounded Consumption
Prohibited practices
- CoE Convention CoE Art. 16(4) Assess the need for a moratorium, ban or other measures for incompatible uses (core)
- ISO 42001 A.9.4 Intended use of the AI system (clause not verified)
- NIST AI RMF GOVERN 1.1 GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented
- CSA AICM GRC-09 Acceptable Use of the AI Service
- CSA AICM HRS-15 AI Acceptable Use
- Singapore Agentic Agentic 2.1.1 Determine suitable use cases for agent deployment
- China GenAI Measures GenAI Art. 4 Prohibited content and baseline duties
Cases that cite this article
- Dutch childcare benefits: nationality as a risk indicator (2021)
- Clearview AI: a face database built by scraping (2024)
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-DEPLOY-012Deactivation triggers, degraded modes and suspension (Deployment and monitoring profile)
Source
Chapter 08, section EU AI Act, post-Omnibus, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-euaia-art5.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). EU AI Act Art. 5: prohibited practices (incl. new NCII and CSAM bans) (AIGE-OBL-EUAIA-ART5). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{EU AI Act Art. 5: prohibited practices (incl. new NCII and CSAM bans) (AIGE-OBL-EUAIA-ART5)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5},
note = {Version 0.5.0}
}