ibl.ai Agentic AI Blog

Insights on building and deploying agentic AI systems. Our blog covers AI agent architectures, LLM infrastructure, MCP servers, enterprise deployment strategies, and real-world implementation guides. Whether you are a developer building AI agents, a CTO evaluating agentic platforms, or a technical leader driving AI adoption, you will find practical guidance here.

Topics We Cover

Featured Research and Reports

We analyze key research from leading institutions and labs including Google DeepMind, Anthropic, OpenAI, Meta AI, McKinsey, and the World Economic Forum. Our content includes detailed analysis of reports on AI agents, foundation models, and enterprise AI strategy.

For Technical Leaders

CTOs, engineering leads, and AI architects turn to our blog for guidance on agent orchestration, model evaluation, infrastructure planning, and building production-ready AI systems. We provide frameworks for responsible AI deployment that balance capability with safety and reliability.

Back to Blog

European Commission: AI Act Article 5 – Prohibited Practices

Jeremy WeaverFebruary 5, 2025
Premium

The guidelines outline prohibited AI practices under the EU AI Act, including harmful manipulation and deceptive techniques, exploitation of vulnerabilities, social scoring, unauthorized biometric and emotion recognition applications, and real-time biometric identification restrictions. They emphasize transparency, legal safeguards, and a balance between innovation and fundamental rights protection, while also noting the interplay with other EU laws.

European Commission: AI Act Article 5 – Prohibited Practices



Summary of Read Full Report

This document offers Commission Guidelines on the prohibitions of specific Artificial Intelligence (AI) practices outlined in the EU AI Act (Regulation (EU) 2024/1689).

The guidelines clarify the scope and application of these prohibitions, providing examples and explanations to aid authorities in enforcement and to guide AI providers and deployers in ensuring compliance.

These guidelines are non-binding, with final interpretation reserved for the Court of Justice of the European Union. The document addresses key areas such as manipulative AI, exploitation of vulnerabilities, social scoring, and biometric identification, examining their interplay with existing EU law.

Here's a summary of key takeaways from the provided document, which outlines guidelines on prohibited AI practices under the EU's AI Act:

  • Harmful Manipulation, Deception, and Exploitation: The AI Act prohibits AI systems that use subliminal, purposefully manipulative, or deceptive techniques to materially distort behavior and cause significant harm. This includes exploiting vulnerabilities related to age, disability, or socioeconomic status.
  • Subliminal techniques, such as flashing images too quickly for conscious perception, are prohibited when used to manipulate behavior to cause significant harm.
  • Purposefully manipulative techniques are not defined in the AI Act, but they are techniques intended to increase the effectiveness and impact of manipulation, even if the intention to cause harm isn't there.
  • Deceptive techniques such as those that present false or misleading information are prohibited when used to manipulate behavior to cause significant harm. Generative AI systems that "hallucinate" may not be considered deceptive if the provider has informed the user of the system's limitations.
  • The concept of material distortion of behavior involves impairing a person's ability to make an informed decision, causing them to act in a way they wouldn't otherwise.
  • Significant harm includes physical, psychological, financial, and economic harm and must be reasonably likely to occur for the prohibition to apply.
  • Lawful persuasion is not prohibited, but manipulation is. Persuasion involves transparency and respects autonomy, while manipulation exploits vulnerabilities and aims to benefit the manipulator.
  • Social Scoring: The AI Act prohibits AI systems that classify individuals based on social behavior or personality traits, leading to detrimental or disproportionate treatment in unrelated social contexts.
    • This prohibition applies to both public and private actors.
  • Biometric Data and Facial Recognition: The Act prohibits untargeted scraping of facial images to create facial recognition databases. It also prohibits biometric categorization that infers sensitive characteristics like race, political opinions, or sexual orientation.
    • Real-time remote biometric identification (RBI) in public spaces for law enforcement is generally prohibited but allowed in certain exceptions, including targeted searches for victims of specific crimes, prevention of imminent threats, and locating suspects of certain crimes.
    • RBI use requires prior authorization from a judicial or independent administrative authority.
  • Emotion Recognition: AI systems that infer emotions in the workplace and educational settings are prohibited, with exceptions for medical and safety reasons.
  • Exclusions: The AI Act excludes certain areas, including national security, defense, military purposes, research, and personal non-professional activities from its scope.
  • Interplay with Other Laws: The AI Act works alongside other EU laws, including data protection, consumer protection, and non-discrimination laws.
  • Transparency and Oversight: The AI act mandates that the use of real-time RBI systems must be reported to market surveillance and data protection authorities.
  • Member State Flexibility: Member states may introduce stricter or more favorable laws that do not conflict with the AI Act.
  • Safeguards: The Act also highlights the need for fundamental rights impact assessments (FRIA) before deploying RBI systems in law enforcement. These assessments should consider the seriousness of the potential harm, the scale of people affected, and the probability of adverse outcomes.

These guidelines aim to balance innovation with the protection of fundamental rights and safety, setting clear boundaries for AI practices that are considered too risky.

Why does owning the AI stack matter?

ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.

  • You own all the code and the data

    Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.

  • Model-agnostic

    Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.

  • No per-seat pricing

    Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.

  • Deploy anywhere

    Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

See the ibl.ai AI Operating System in Action

Discover how leading universities and organizations are transforming education with the ibl.ai AI Operating System. Explore real-world implementations from Harvard, MIT, Stanford, and users from 400+ institutions worldwide.

View Case Studies
Work with our team

Pilots, deployment, and full ownership

Most enterprise engagements are one-time, not subscriptions. You integrate ibl.ai with your own data, deploy it on your own infrastructure, and the engineering hours scale with the work — so the price tracks the scope, not your headcount.

Start here

Pilot

from $15K

fixed scope · fixed timeline

A time-boxed proof of value on your real data — not a slide deck.

Best for: Teams that want to see ibl.ai working before committing.

  • Deployed on your infrastructure or our cloud
  • 1–2 production agents wired to a slice of your data
  • One integration (LMS / SIS / SSO / data source)
  • Weekly working sessions with our engineers
  • Pilot fee credits toward a full engagement
Scope a pilot
Most common

Integration & Deployment

$25K – $80K

one-time · not a subscription

Full deployment integrated with your data and systems. Engineering hours scale with scope.

Best for: Organizations rolling ibl.ai out across a department, campus, or business unit.

  • Platform deployed in your VPC, on-prem, or air-gapped
  • Integrated with your data + identity (SSO / SAML)
  • Multiple custom agents built to your workflows
  • Engineering hours proportional to scope
  • You own the data · run any LLM you choose
Plan a deployment
Full ownership

Codebase Transfer + Custom AI Engineering

Six figures

perpetual license · you own the stack

We transfer the full source code. You own and self-host the entire platform — outright.

Best for: Government, defense, and enterprises that require perpetual ownership and sovereignty.

  • Complete source-code transfer + perpetual license
  • Dedicated AI engineering team on your roadmap
  • Custom agents, models, and integrations to spec
  • Air-gapped capable · zero vendor lock-in
  • Family-owned, New York–based long-term partner
Talk about ownership
You own the code and data Run any LLM — Claude, GPT, Gemini, Llama Family-owned & operated from New York, NY