Where the board's authority can't be delegated.

Every risk elsewhere in this library has a matching control — a way to reduce it to an acceptable level. These eight don't, almost entirely on purpose. Article 5 of the EU AI Act doesn't ask an organisation to manage these practices; it prohibits them outright, in force since 2 February 2025. The correct response to a legal prohibition is a decision not to build the system — not a technical mitigation, and not something a control register can stand in for.

The eight prohibited practices.

Each is assessed individually in the Risk Library, mapped to its specific Article 5 clause.

Why there's no control to point to.

A control register answers "how do we do this safely." These eight are cases where the answer is "we don't do this at all." Building a compensating control here would misstate the position — it would suggest the practice is being managed, when the actual governance decision is not to undertake it.

What the board actually needs to confirm.

Not "do we have a control for this" — instead, "has someone with the authority to say no actually looked at whether any system in use, or proposed, falls into one of these eight categories." That confirmation is the only mitigation Article 5 recognises.

Next: a worked example, not a hypothetical.

This path's closing exhibit tests exactly this kind of governance question against a specific, regulated institution.