A provision built on four moving parts
Article 5(1)(a) is the first of the eight prohibited practices in the EU AI Act and one of the most commonly misunderstood, because the underlying concepts, subliminal, manipulative, deceptive, aren’t defined with much precision in the text itself.
In plain terms, the provision bans AI systems that manipulate people below the level of their own awareness, or through deliberate manipulation or deception, in a way that changes what they decide to do and ends up harming them. Four things all have to be true at once: a qualifying technique, material distortion of decision-making, a resulting decision the person wouldn’t otherwise have made, and significant harm. The European Commission published guidelines on 4 February 2025, two days after the prohibition took effect, to clarify where that line actually sits, including specific examples and a clear statement about what the provision does not reach.
For another of the eight prohibited practices under the same article, read Social Scoring AI: Why the EU AI Act Bans It and What Counts.
The four-part test for manipulative AI techniques
Before the prohibition applies, four traits have to line up:
| Element | What it requires | |
|---|---|---|
| 1. Qualifying technique | Subliminal (operating beyond conscious perception), purposefully manipulative, or deceptive | |
| 2. Material distortion | The technique's objective or effect is to materially distort behaviour by appreciably impairing the ability to make an informed decision | |
| 3. Counterfactual decision | The person takes a decision they would not otherwise have taken | |
| 4. Significant harm | The result causes, or is reasonably likely to cause, significant harm to that person, another person, or a group |
Note that a technique that nudges behaviour without meeting the harm threshold, or one that looks manipulative but doesn’t actually change what someone decides, sits outside the provision, even if it makes people uncomfortable.
What counts as a subliminal AI technique
The Commission’s guidelines give concrete examples: visual and auditory subliminal messages, subvisual and subaudible cueing, embedded images, misdirection, and temporal manipulation. They also flag that emerging technologies such as brain-computer interfaces and virtual reality raise the risk of more sophisticated subliminal manipulation going forward, which is one reason the definition is written broadly rather than tied to a specific technical method.
One detail worth knowing: the guidelines make clear the prohibition covers cases where a person is aware that a subliminal technique is being used but still cannot resist its effect. Awareness of the technique existing is not (on its own) a defence.
What counts as a manipulative or deceptive AI technique
The guidelines describe manipulative techniques as those that exploit cognitive biases, psychological vulnerabilities, or other factors that make a person or group susceptible to influence, which was deployed purposefully.
What the manipulative AI technique ban does not account for
Personalised advertising based on user preferences is, in the Commission’s own words, not inherently manipulative, provided it does not deploy subliminal, purposefully manipulative, or deceptive techniques that subvert a person’s autonomy or exploit their vulnerabilities. The guidelines also treat GDPR compliance in this context as a factor that helps mitigate the risk of the practice crossing into manipulation.
Research and development work has room to breathe as well. Developers can experiment and test functionality that might otherwise look manipulative in a consumer-facing product, because the prohibition attaches once a system is actually placed on the market or put into service, not during internal testing.
Ordinary persuasive marketing, standard sales techniques, and behavioural design choices that fall short of appreciably impairing informed decision-making and causing significant harm sit outside the provision as well, even where the underlying intent is to influence what someone does.
Who the prohibition applies to
Both providers and deployers, each within their own responsibilities, are bound by this prohibition directly. There is no split here where one role carries the obligation and the other simply inherits it, the way some other requirements divide between provider and deployer. Deploying a system that someone else built does not shield an organisation if that system’s behaviour meets the four-part test above.
Enforcement and timing
The prohibition has applied since 2 February 2025, alongside the rest of Article 5. It sits in the highest of the Act’s three fine tiers: up to €35 million or 7% of global annual turnover, whichever is higher, under Article 99. The European Commission’s guidelines, published 4 February 2025, exist specifically because the terms in this provision are broad enough to need interpretive help, and they remain the primary reference point for where the line actually sits in practice.
How Deeploy helps prevent manipulative AI
A model that starts out well within the lines can still drift into territory this provision is aimed at, particularly personalisation and recommendation systems that optimise aggressively for engagement or conversion over time. Deeploy’s platform and drift monitoring is built to surface that kind of shift while it is still a pattern in the data, well before it becomes a question a regulator is asking.
Frequently asked questions
Not inherently. The European Commission's guidelines state that personalising ads based on user preferences is not automatically manipulative, so long as the system does not deploy subliminal, purposefully manipulative, or deceptive techniques that subvert autonomy or exploit vulnerabilities.
It depends which route applies. The manipulative and deceptive route requires the technique to be deployed purposefully. The subliminal route is written without that same explicit intent requirement, focusing instead on whether the technique operates beyond a person's conscious awareness.
Generally yes. The Commission's guidelines indicate that research and development work has room to experiment with functionality that might otherwise look manipulative, since the prohibition attaches once the system is placed on the market or put into service, not during internal testing.
It falls into the highest fine tier under Article 99: up to €35 million or 7% of global annual turnover, whichever is higher, the same tier that applies to every other prohibited practice under Article 5.
Yes. Both providers and deployers are bound directly, each within their own responsibilities. Using a system built by someone else does not exempt a deployer if the system's actual behaviour meets the four-part test and is characterised by using manipulative AI techniques.
The Act does not set a numeric threshold. What has to be shown is that the material distortion of a person's decision-making causes, or is reasonably likely to cause, significant harm to that person, another person, or a group, assessed in the context of the specific technique and decision involved.