The classic trap
Recital 28 is the interpretive cornerstone of Article 5 of the AI Act, which lists prohibited AI practices. The trap is believing that these prohibitions only target extreme cases such as political deepfakes: in reality, very ordinary use cases (customer behavioural scoring, advertising targeting that exploits economic vulnerability, manipulative gamification of a B2C app) can fall under Article 5 as soon as they exploit a vulnerability or bypass informed consent. The EU AI Office and, for the personal data angle, the Luxembourg CNPD read this recital as a mandate for broad, rights-protective interpretation.
How this recital shapes your compliance in practice
This recital is not normative but it guides the entire interpretation of Article 5 prohibitions. Concretely, it requires every AI deployer to perform a purpose analysis that goes beyond formal compliance with the text and demonstrates the absence of manipulative, exploitative or social-control effects. Points to document:
- Does the AI exploit a vulnerability (age, disability, economic situation, psychological fragility) of the targeted person?
- Does the end user genuinely understand that AI is influencing their decision, or is the manipulation subliminal?
- Does the system produce a social or behavioural ranking effect that restricts access to essential services?
- Does the use respect the Charter of Fundamental Rights, in particular non-discrimination (art. 21), privacy (art. 7) and children's rights (art. 24)?
- Is there a non-AI alternative or a less intrusive AI that would achieve the same legitimate purpose?
This analysis must be written, dated, versioned and retained as accountability evidence, similar to what the GDPR requires for DPIAs.
How Luxgap automates this risk
Our Luxgap Prohibited Practice Sentinel eliminates the risk of unintentionally deploying an AI system that falls under Article 5. The tool continuously scans your Azure AI Foundry, AWS Bedrock, Google Vertex AI, Hugging Face Enterprise environments as well as your Power Automate, Salesforce Einstein and Odoo Studio workflows to identify every deployed AI model, its real purpose and its target audience, without asking your business teams to declare anything.
- Automatically detects every new AI model or agent deployed in your IT environment at activation time, via hyperscaler audit APIs.
- Classifies each use case against the eight prohibited practices of Article 5 (subliminal manipulation, exploitation of vulnerability, social scoring, emotion recognition at work, etc.) using EU AI Office guidelines.
- Alerts in real time on Teams or Slack when a new deployment shows a high risk score of breaching Article 5.
- Generates for each use case a pre-filled purpose analysis aligned with recital 28 and the Charter of Fundamental Rights.
- Produces a time-stamped, cryptographically sealed PDF report, enforceable before the EU AI Office and the CNPD during an audit, demonstrating deployer diligence.
- Cross-references detected deployments with your GDPR records to identify DPIA / AI Act analysis overlaps and avoid duplicate documentation.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual AI deployments, with a free 48-hour white audit to map your Article 5 exposure before any engagement.