Social Scoring AI: Why the EU AI Act bans it and what counts

5 min readLast reviewed 2 July 2026
In short

Social scoring, as prohibited under Article 5(1)(c) of the EU AI Act, is the use of an AI system to evaluate or classify people over time based on their social behaviour or inferred personal characteristics, where the resulting score leads to detrimental treatment in situations unrelated to the original purpose, or treatment that is disproportionate to the behaviour itself. The ban applies equally to public authorities and private companies and has been in force since 2 February 2025.

What Article 5(1)(c) actually says

The EU AI Act doesn’t ban “scoring” as a concept. It bans a specific pattern: an AI system that watches how someone behaves across different areas of their life, builds a running score out of it, and then lets that score follow them into contexts that have nothing to do with where the data came from.

Two conditions have to be met for a system to fall foul of the ban:

  • The score leads to unfavourable treatment in an unrelated context (a low score from a retail loyalty scheme affecting a mortgage application, for instance), or
  • The score leads to treatment that is unjustified or disproportionate to the behaviour it’s based on.

If neither condition applies, the scoring system sits outside Article 5(1)(c), even if it looks superficially similar. This is the distinction most compliance questions come down to.

Why lawmakers singled this out

The ban was written with China’s social credit systems in mind, but the text itself is behaviour-neutral. It doesn’t matter whether the operator is a government ministry or a private platform. What matters is whether the system builds a portable reputation score from a person’s general conduct and then uses that score to gate access to unrelated services, opportunities, or treatment.

The European Data Protection Board and European Data Protection Supervisor flagged this risk as early as 2021, warning that general-purpose scoring of this kind is incompatible with EU fundamental rights regardless of who runs it. That joint position carried through into the final text of Article 5.

Who the ban applies to

Public authorities and private companies are both in scope. There’s no carve-out for commercial actors, and no size threshold. A public body running a citizen trust score and a private platform running a cross-service “reputation index” face the same prohibition if the behaviour matches the two conditions above.

What is not covered

The prohibition has a narrow trigger, and several common practices sit outside it by design:

Credit scoring. A bank assessing creditworthiness using financial data, repayment history, and income is not social scoring. It’s a lawful, purpose-specific risk assessment, and it’s regulated separately as a high-risk AI system under Annex III, with its own set of obligations around data governance, transparency, and human oversight.

Loyalty and rewards programmes. A retailer scoring customers on purchase history to unlock discounts within that same retail relationship stays within its own context. It only risks crossing into Article 5(1)(c) territory if that score starts to influence unrelated decisions, an insurer using retail loyalty data to set premiums, for example.

Fraud detection. Scoring transactions or accounts for fraud risk, within the context of that specific service, is a targeted risk assessment rather than general behavioural scoring.

Insurance risk assessment. Insurers pricing policies based on relevant, sector-specific risk factors are carrying out a lawful assessment, provided the factors used are proportionate to the risk being priced and don’t reach into unrelated areas of a person’s life.

The test in each case is the same: does the score stay inside the context it was built for, and is the resulting treatment proportionate to what the score actually measures? If yes to both, Article 5(1)(c) doesn’t apply.

How this interacts with GDPR

Social scoring sits close to territory the GDPR already covers through its rules on profiling, purpose limitation, and automated decision-making. The AI Act doesn’t replace those obligations. A scoring system that clears the Article 5(1)(c) bar for the AI Act can still need to satisfy GDPR requirements around lawful basis, purpose limitation, and (where Article 22 GDPR applies) the right not to be subject to a decision based solely on automated processing. Clearing one regime doesn’t clear the other.

Enforcement and penalties

Social scoring sits in the highest penalty tier under the AI Act. Breaching Article 5 can trigger fines of up to €35 million or 7% of global annual turnover, whichever is higher. There’s no legacy exemption: any system that matches the prohibited pattern should have been withdrawn from the market by 2 February 2025, regardless of when it was originally deployed.

The Digital Omnibus and this prohibition

The Digital Omnibus, the package of amendments agreed between Parliament and Council through 2026, doesn’t touch Article 5(1)(c). Parliament gave its final vote on 16 June 2026, the Council followed with formal approval on 29 June 2026, and the regulation, published as Regulation (EU) 2026/1744, entered into force on 27 July 2026. None of that changes the social scoring ban, which has applied since 2 February 2025 and stays exactly as written.

For a full breakdown of every deferred and unaffected deadline, see the EU AI Act penalties, enforcement and timeline chapter.

A quick self-check

Before assuming a system is in the clear or in trouble, run it through these four questions:

  • Does the system build a score from a person’s general social behaviour or inferred characteristics, rather than data specific to one service?
  • Does that score persist and follow the person over time, rather than resetting per transaction?
  • Is the score used to make decisions in a context unrelated to where the data came from?
  • Is the resulting treatment disproportionate to the behaviour the score is based on?

A system that triggers question 1 or 2 alone usually isn’t a problem. A system that also triggers question 3 or 4 needs a proper legal review before it goes any further.

How Deeploy helps

Where scoring or profiling models sit close to this line, whether it’s a customer risk model, an internal HR ranking tool, or anything that classifies people based on behaviour, Deeploy gives compliance and MLOps teams visibility into what the model is actually doing in production: which features drive a score, how that score changes over time, and whether it’s being used in ways that match its original documented purpose.

That audit trail is exactly what a market surveillance authority or internal legal team will ask for if a scoring system is ever questioned.

Frequently asked questions

Disclaimer

This is general information, not legal advice. Please consult your legal/compliance team to confirm your organisation’s specific obligations. Deeploy supports your governance process; it does not constitute a guarantee of regulatory compliance.

Reading about compliance is step one. Operating it is Deeploy.See how teams use Deeploy to monitor, document and govern their AI against the EU AI Act.
Book a Demo

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one