# Social Scoring AI: Why the EU AI Act bans it and what counts > Social scoring, as prohibited under Article 5(1)(c) of the EU AI Act, is the use of an AI system to evaluate or classify people over time based on their social behaviour or inferred personal characteristics, where the resulting score leads to detrimental treatment in situations unrelated to the original purpose, or treatment that is disproportionate to the behaviour itself. The ban applies equally to public authorities and private companies and has been in force since 2 February 2025. **Author:** Maarten Stolk **Last reviewed:** 2 July 2026 **Source:** https://deeploy.ai/eu-ai-act-hub/articles/social-scoring-ai-eu-ai-act-ban/ ## What Article 5(1)(c) actually says The EU AI Act doesn't ban "scoring" as a concept. It bans a specific pattern: an AI system that watches how someone behaves across different areas of their life, builds a running score out of it, and then lets that score follow them into contexts that have nothing to do with where the data came from. Two conditions have to be met for a system to fall foul of the ban: - The score leads to **unfavourable treatment in an unrelated context** (a low score from a retail loyalty scheme affecting a mortgage application, for instance), or - The score leads to treatment that is **unjustified or disproportionate** to the behaviour it's based on. If neither condition applies, the scoring system sits outside Article 5(1)(c), even if it looks superficially similar. This is the distinction most compliance questions come down to. ## Why lawmakers singled this out The ban was written with China's social credit systems in mind, but the text itself is behaviour-neutral. It doesn't matter whether the operator is a government ministry or a private platform. What matters is whether the system builds a portable reputation score from a person's general conduct and then uses that score to gate access to unrelated services, opportunities, or treatment. The European Data Protection Board and European Data Protection Supervisor flagged this risk as early as 2021, warning that general-purpose scoring of this kind is incompatible with EU fundamental rights regardless of who runs it. That joint position carried through into the final text of Article 5. ## Who the ban applies to Public authorities and private companies are both in scope. There's no carve-out for commercial actors, and no size threshold. A public body running a citizen trust score and a private platform running a cross-service "reputation index" face the same prohibition if the behaviour matches the two conditions above. ## What is not covered The prohibition has a narrow trigger, and several common practices sit outside it by design: **Credit scoring.** A bank assessing creditworthiness using financial data, repayment history, and income is not social scoring. It's a lawful, purpose-specific risk assessment, and it's regulated separately as a high-risk AI system under Annex III, with its own set of obligations around data governance, transparency, and human oversight. **Loyalty and rewards programmes.** A retailer scoring customers on purchase history to unlock discounts within that same retail relationship stays within its own context. It only risks crossing into Article 5(1)(c) territory if that score starts to influence unrelated decisions, an insurer using retail loyalty data to set premiums, for example. **Fraud detection.** Scoring transactions or accounts for fraud risk, within the context of that specific service, is a targeted risk assessment rather than general behavioural scoring. **Insurance risk assessment.** Insurers pricing policies based on relevant, sector-specific risk factors are carrying out a lawful assessment, provided the factors used are proportionate to the risk being priced and don't reach into unrelated areas of a person's life. The test in each case is the same: does the score stay inside the context it was built for, and is the resulting treatment proportionate to what the score actually measures? If yes to both, Article 5(1)(c) doesn't apply. ## How this interacts with GDPR Social scoring sits close to territory the GDPR already covers through its rules on profiling, purpose limitation, and automated decision-making. The AI Act doesn't replace those obligations. A scoring system that clears the Article 5(1)(c) bar for the AI Act can still need to satisfy GDPR requirements around lawful basis, purpose limitation, and (where Article 22 GDPR applies) the right not to be subject to a decision based solely on automated processing. Clearing one regime doesn't clear the other. ## Enforcement and penalties Social scoring sits in the highest penalty tier under the AI Act. Breaching Article 5 can trigger fines of up to €35 million or 7% of global annual turnover, whichever is higher. There's no legacy exemption: any system that matches the prohibited pattern should have been withdrawn from the market by 2 February 2025, regardless of when it was originally deployed. ## The Digital Omnibus and this prohibition The Digital Omnibus, the package of amendments agreed between Parliament and Council through 2026, doesn't touch Article 5(1)(c). Parliament gave its final vote on 16 June 2026, the Council followed with formal approval on 29 June 2026, and the regulation, published as Regulation (EU) 2026/1744, entered into force on 27 July 2026. None of that changes the social scoring ban, which has applied since 2 February 2025 and stays exactly as written. For a full breakdown of every deferred and unaffected deadline, see the EU AI Act penalties, enforcement and timeline chapter. ## A quick self-check Before assuming a system is in the clear or in trouble, run it through these four questions: - Does the system build a score from a person's general social behaviour or inferred characteristics, rather than data specific to one service? - Does that score persist and follow the person over time, rather than resetting per transaction? - Is the score used to make decisions in a context unrelated to where the data came from? - Is the resulting treatment disproportionate to the behaviour the score is based on? A system that triggers question 1 or 2 alone usually isn't a problem. A system that also triggers question 3 or 4 needs a proper legal review before it goes any further. ## How Deeploy helps Where scoring or profiling models sit close to this line, whether it's a customer risk model, an internal HR ranking tool, or anything that classifies people based on behaviour, Deeploy gives compliance and MLOps teams visibility into what the model is actually doing in production: which features drive a score, how that score changes over time, and whether it's being used in ways that match its original documented purpose. That audit trail is exactly what a market surveillance authority or internal legal team will ask for if a scoring system is ever questioned. ## Frequently asked questions ## Frequently asked questions ### Does the social scoring ban apply to private companies, or only governments? Both. Article 5(1)(c) applies equally to public authorities and private actors. There's no exemption for commercial operators. ### Is credit scoring banned under the EU AI Act? No. Legitimate creditworthiness assessments based on relevant financial data are treated as high-risk AI systems under Annex III, not as prohibited social scoring, provided they don't lead to disproportionate treatment or draw on unrelated social context data. ### What's the difference between social scoring and a loyalty programme? A loyalty scheme that scores customers within one commercial relationship, and only affects benefits within that same relationship, stays outside the ban. It becomes a problem if that score starts influencing unrelated decisions, such as an insurer or lender using it. ### Can an employer score employees on behaviour? An internal system that evaluates employee conduct only within the employment relationship it was built for is unlikely to meet the Article 5(1)(c) test on its own. Risk increases sharply if that score feeds into decisions outside the employment context, or if it overlaps with the Act's separate ban on emotion recognition in the workplace. ### What counts as "unrelated context" under the ban? Any situation where a score built from one type of data or relationship is used to make a decision in a different domain. The clearest example regulators point to is a retail loyalty score influencing an insurance premium. ### Are there exceptions for law enforcement or national security scoring? No general exception exists for social scoring. Unlike the real-time biometric identification ban, Article 5(1)(c) doesn't carry a law enforcement carve-out. ### Did the Digital Omnibus change or soften the social scoring ban? No. The Omnibus, formally approved by the Council on 29 June 2026, leaves Article 5(1)(c) untouched. It adds an unrelated new prohibition on AI-generated non-consensual intimate imagery and CSAM, expected to apply from 2 December 2026. ### What are the maximum fines under the EU AI Act? The Act sets three fine tiers. Violations of the prohibited practices under Article 5 carry fines of up to €35 million or 7% of global annual turnover, whichever is higher. Violations of high-risk system obligations carry fines of up to €15 million or 3% of global annual turnover. Providing incorrect or misleading information to authorities carries fines of up to €7.5 million or 1.5% of turnover. For SMEs, the lower of the two thresholds applies in each case. ### Does the ban apply retroactively to systems built before February 2025? Yes. There's no legacy exemption. Any in-scope system should have been withdrawn from use by 2 February 2025, regardless of when it was first deployed. ### How does this interact with GDPR profiling rules? Separately. A system that avoids the AI Act's social scoring ban can still need to meet GDPR requirements on profiling, purpose limitation, and automated decision-making under Article 22. Compliance with one doesn't imply compliance with the other.