EU AI Act — prohibited practices in force
Eight unacceptable-risk practices (social scoring, manipulative AI, untargeted face-scraping, most real-time biometric ID) are banned.
The same obligation themes, side by side, from the catalogue that powers the rest of this site — 16 catalogued requirements across 15 themes. Expand any requirement to read it. Free, no login.
Comparing 2 of 38 regulations we track. This URL is the comparison — send it to anyone.
Every theme below appears in exactly one group, so these account for all 15 of them. Sharing a theme means both regimes legislate in that area — it does not mean complying with one discharges the other.
EU AI Act · FCA Consumer Duty
EU AI Actnot: FCA Consumer Duty
A dash means we have not catalogued a requirement for that regulation under that theme — a summary of our catalogue, not a finding that the law is silent. Always check the official text, linked from each regulation's page.
| Theme | EU AI Act | FCA Consumer Duty |
|---|---|---|
| What is forbidden outright | ||
| Outright bans Are some uses forbidden regardless of safeguards? | Art. 5 Prohibited AI practices mustPractices such as social scoring, manipulative/subliminal techniques, exploitation of vulnerabilities, untargeted facial scraping, and (most) real-time remote biometric identification are banned and cannot be placed on the EU market. Read it in context → | — |
| What you must assess first | ||
| Risk management system Must you run a documented, continuous risk process? | Art. 9 Risk-management system mustEstablish, document and maintain a continuous risk-management system across the AI lifecycle. Read it in context → | — |
| Rights impact assessment Must you assess the impact on people before deploying? | Art. 27 Fundamental Rights Impact Assessment mustCertain deployers must perform a Fundamental Rights Impact Assessment before putting the system into use. Read it in context → | PRIN 2A Avoid foreseeable harm from AI mustAssess and prevent foreseeable harm to retail customers before deploying AI (e.g. biased credit models, misleading AI chatbots), and deliver good outcomes on products, price/value, understanding and support. Read it in context → |
| What you owe the data | ||
| Data & training data Are there duties on the data the system learns from? | Art. 10 Data & data governance mustTraining, validation and testing data must meet quality criteria and be examined for bias; document provenance and representativeness. Read it in context → | — |
| What you must build and prove | ||
| Accuracy, robustness & security Must you hit and evidence performance targets? | Art. 15 Accuracy, robustness & cybersecurity mustAchieve appropriate accuracy, robustness and cybersecurity, and declare metrics. Read it in context → | — |
| Technical documentation Must a technical file exist before deployment? | Art. 11 / Annex IV Technical documentation mustDraw up and keep up-to-date technical documentation demonstrating conformity (the Annex IV technical file). Read it in context → | — |
| Conformity assessment Must someone certify it before it goes to market? | Art. 43 Conformity assessment mustUndergo the relevant conformity-assessment procedure and draw up an EU declaration of conformity before market entry. Read it in context → | — |
| Registration & public listing Must the system be registered or published somewhere? | Art. 49 EU database registration mustRegister the high-risk system in the EU database before placing it on the market. Read it in context → | — |
| What you must tell people | ||
| Transparency & explanation Must you explain how it works, and to whom? | Art. 13 Transparency & instructions for use mustProvide deployers with clear instructions: capabilities, limitations, and required human oversight. Read it in context → | — |
| Telling people AI was used Must people be told an AI was involved? | Art. 50 Transparency for certain systems mustInform people they are interacting with an AI system (chatbots) and label AI-generated/manipulated content. Read it in context → | — |
| Labelling AI-generated content Must generated output be marked or watermarked? | Art. 50(2) Marking of synthetic content mustMark AI-generated audio, image, video or text in a machine-readable, detectable way. Read it in context → | — |
| What you must do while it runs | ||
| Human oversight & override Must a person be able to intervene, review or stop it? | Art. 14 Human oversight mustDesign the system so humans can effectively oversee it, intervene, and stop it. Read it in context → | — |
| Logging & records Must the system keep records of what it did? | Art. 12 Record-keeping (logging) mustAutomatically record events (logs) over the system lifetime to ensure traceability. Read it in context → | — |
| Monitoring after deployment Must you keep watching it once it is live? | Art. 72 Post-market monitoring mustOperate a post-market monitoring system to collect and review performance data after deployment. Read it in context → | — |
| Incident reporting Must failures be reported, and to whom? | Art. 73 Serious-incident reporting mustReport serious incidents and malfunctioning to the competent market-surveillance authority. Read it in context → | — |
Every dated obligation attached to these regulations, merged into one timeline.
Eight unacceptable-risk practices (social scoring, manipulative AI, untargeted face-scraping, most real-time biometric ID) are banned.
The final GPAI Code of Practice (Transparency, Copyright, Safety & Security chapters) gives providers a voluntary route to demonstrate compliance ahead of harmonised standards.
National competent authorities and fines (up to 7% of global turnover for prohibited use) become enforceable.
GPAI providers owe transparency, technical documentation, copyright policy, and systemic-risk duties for capable models.
Now live. Chatbots must disclose they are AI; deepfakes and emotion-recognition/biometric-categorisation uses must be disclosed. The Commission adopted final Art. 50 guidelines on 20 July 2026, and the AI Office's enforcement powers over GPAI providers (fines up to €15M or 3% of turnover) became applicable the same day. Providers' machine-readable marking of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.
The Digital Omnibus adds a prohibition on AI systems for non-consensual intimate imagery/CSAM and ends the synthetic-content marking grace period for pre-existing systems.
Providers of high-risk systems must report serious incidents to authorities within 15 days (10 days on a death; 2 days for widespread infringement or critical-infrastructure disruption).
Full high-risk regime (risk management, data governance, logging, human oversight, accuracy, conformity assessment, registration). Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026 and in force since 27 July 2026, so this date is settled law.
High-risk AI embedded in regulated products (machinery, medical devices, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026.