The prohibition next to manipulative AI
Article 5(1)(b) is the second of the eight prohibited practices in the EU AI Act, and it sits right next to Article 5(1)(a) for a reason: both ban AI that materially distorts a person’s behaviour in a way that causes significant harm, but (b) is narrower and more specific about who it protects. Rather than covering manipulation generally, it bans AI systems that exploit a vulnerability tied to a person’s age, disability, or a specific social or economic situation.
Four things have to be true at once: an AI system is placed on the market, put into service, or used; it exploits a vulnerability falling into one of those three categories; the exploitation has the objective or effect of materially distorting behaviour; and the distorted behaviour causes, or is reasonably likely to cause, significant harm. One detail that surprises people coming from Article 5(1)(a): the exploitation route doesn’t require intent either. A system that ends up exploiting a vulnerability through its effect, rather than its design purpose, still falls within the ban. The European Commission’s guidelines, published 4 February 2025, set out which vulnerabilities currently count and which practices sit outside the prohibition entirely.
The four-part test for exploitation of vulnerabilities
Before the prohibition applies, four traits have to line up:
| Element | What it requires |
|---|---|
| 1. Qualifying trigger | Placing on the market, putting into service, or use of an AI system |
| 2. Protected vulnerability | The system exploits a vulnerability tied to age, disability, or a specific social or economic situation |
| 3. Material distortion | The exploitation has the objective or effect of materially distorting the person's or group's behaviour |
| 4. Significant harm | The distorted behaviour causes, or is reasonably likely to cause, significant harm to that person or another person |
All four have to line up before the prohibition applies, the same structure as Article 5(1)(a). What’s different here is the second element: this route only bites where the vulnerability being exploited falls into one of three specific categories, not any weakness a system happens to find.
Which vulnerabilities count
- Age covers both children and older adults. The concern is the cognitive limitations that can come with either end of that range, which can reduce someone’s ability to recognise or resist an AI system designed to take advantage of it.
- Disability is defined by the Commission as a long-term physical, mental, intellectual, or sensory impairment that hinders full and equal participation in society. Worth noting directly: an AI system that is simply inaccessible to people with disabilities does not fall under this prohibition. Inaccessibility is a separate issue. Article 5(1)(b) is about a system actively exploiting a disability, not failing to accommodate one.
- A specific socio-economic situation covers circumstances that make someone more susceptible to exploitation, and the Commission’s guidelines note this can intersect with other factors, such as belonging to an ethnic, racial, or religious minority group.
- Although the statutory language refers to vulnerability more broadly, current Commission guidance limits the prohibition to these three categories. A vulnerability that falls outside them, however real it is, doesn’t trigger Article 5(1)(b) on its own.
Examples the Commission’s guidelines flag
- An AI-powered toy that keeps a child engaged by encouraging them to complete increasingly risky challenges
- An AI mental-health chatbot that manipulates a person with an intellectual disability into purchasing expensive health-related products
- AI-enabled differential pricing in insurance that charges lower-income customers more, specifically because their socio-economic situation makes them less likely to shop around or recognise the practice
How Article 5(1)(b) differs from Article 5(1)(a)
| Article 5(1)(a) | Article 5(1)(b) | |
|---|---|---|
| Technique | Subliminal, manipulative, or deceptive | Exploitation of a specific vulnerability |
| Who’s protected | Anyone whose decision-making is distorted | People whose age, disability, or socio-economic situation makes them more susceptible |
| Intent required | Only for the manipulative or deceptive route, not the subliminal route | Not required for either the objective or the effect |
| Harm threshold | Significant harm, caused or reasonably likely | Same |
In practice, the two provisions catch different things aimed at the same underlying outcome. A dark pattern that manipulates the general population sits under (a). The same pattern deliberately tuned to target elderly users, or people in financial distress, sits under (b) as well, and often both at once.
Who the prohibition applies to
Both providers and deployers, each within their own responsibilities, are bound by this prohibition directly. There is no split here where one role carries the obligation and the other simply inherits it, the way some other requirements divide between provider and deployer. Deploying a system that someone else built does not shield an organisation if that system’s behaviour meets the four-part test above.
How Deeploy helps prevent vulnerability exploitation
Article 5(1)(b) doesn’t require intent. Only the effect matters. That’s exactly the kind of standard that catches organisations off guard. A pricing model doesn’t need to be built to exploit someone’s age, disability, or financial situation. It only needs to end up doing that in practice. If a system’s outputs quietly drift toward worse terms for older customers, or more aggressive upselling toward people with disabilities or in financial distress, that’s already inside the provision, whether anyone designed it that way or not.
Deeploy’s monitoring is built to catch that drift while it’s still a pattern in the data. Before it hardens into the kind of effect this provision is aimed at.
Frequently asked questions
Both providers and deployers. Building a banned system or simply using one someone else built are both violations.
Mostly no. Only one of the eight prohibited practices, real-time biometric identification by law enforcement, has narrow, tightly conditioned exceptions built in. The rest are banned without exception.
Both. The Act covers AI systems regardless of whether they face customers or are used solely for internal operations such as HR, finance, or IT management. Internal employee monitoring or performance evaluation tools are explicitly within Annex III scope.
Yes. AI agents are not a separate category but fall under the existing definitions of AI systems and GPAI models depending on their architecture. If an agentic system classifies as high-risk, the full Chapter III obligations apply. The AI Office has indicated it is monitoring agentic developments closely and may issue further guidance.
Eight categories of AI practice have been prohibited since 2 February 2025 under Article 5. They are: subliminal manipulation techniques that bypass conscious awareness; exploitation of vulnerabilities of specific groups; social scoring by public or private actors; real-time remote biometric identification in publicly accessible spaces (with narrow law enforcement exceptions); biometric categorisation by sensitive attributes such as race or political opinion; inference of emotions in workplace or educational settings; untargeted scraping of facial images to build recognition databases; and predictive policing based on individual profiling.