Where the board's authority can't be delegated.
Every risk elsewhere in this library has a matching control — a way to reduce it to an acceptable level. These eight don't, almost entirely on purpose. Article 5 of the EU AI Act doesn't ask an organisation to manage these practices; it prohibits them outright, in force since 2 February 2025. The correct response to a legal prohibition is a decision not to build the system — not a technical mitigation, and not something a control register can stand in for.
The eight prohibited practices.
Each is assessed individually in the Risk Library, mapped to its specific Article 5 clause.
- AI-driven social scoring — Evaluating or classifying people over time by social behaviour or inferred characteristics, leading to detrimental treatment.
- Exploitation of vulnerable groups by AI — Exploiting age, disability, or economic vulnerability to distort behaviour and cause significant harm.
- Subliminal or manipulative AI techniques — Deploying subliminal or deceptive techniques that materially distort a person's behaviour and cause significant harm.
- Individual criminal risk profiling — Assessing the risk that a person will commit a crime based solely on profiling or personality traits.
- Untargeted facial recognition scraping — Scraping facial images from the internet or CCTV, without targeting, to build a recognition database.
- Workplace and education emotion recognition — Inferring emotions in the workplace or an education institution, outside narrow medical or safety exceptions.
- Biometric categorisation of sensitive attributes — Inferring race, political opinion, trade union membership, religion, or sexual orientation from biometric data.
- Real-time public biometric identification — Remote biometric identification in public spaces for law enforcement, outside three narrow statutory exceptions.
Why there's no control to point to.
A control register answers "how do we do this safely." These eight are cases where the answer is "we don't do this at all." Building a compensating control here would misstate the position — it would suggest the practice is being managed, when the actual governance decision is not to undertake it.
What the board actually needs to confirm.
Not "do we have a control for this" — instead, "has someone with the authority to say no actually looked at whether any system in use, or proposed, falls into one of these eight categories." That confirmation is the only mitigation Article 5 recognises.
Next: a worked example, not a hypothetical.
This path's closing exhibit tests exactly this kind of governance question against a specific, regulated institution.