The classic trap
Recital 30 clarifies the Article 5 ban: any AI system that infers political opinions, religious beliefs, sexual orientation or trade union membership from a face or fingerprint is prohibited, with no commercial carve-out. The classic trap is to assume you escape the ban because the categorisation is only a by-product of the model (product recommendation, ad targeting, HR scoring). Yet the EU AI Office and the CNPD read Recital 30's intent extensively: as soon as a vision or voice model produces an inference on these sensitive categories, even indirectly, it tips over into prohibited practice.
The red line between lawful sorting and prohibited inference
Recital 30 draws a distinction you must carry into your technical documentation:
- Lawful: purely descriptive labelling of biometric data (hair colour, eye colour, glasses) to organise a dataset or support image search in a lawful enforcement setting.
- Prohibited: any inference moving from descriptive (a face) to deductive (an opinion, a belief, an orientation), even when the output stays internal to the model.
- Grey zone to challenge: emotion analysis, microexpression or morphopsychology models claiming to predict a personality trait correlated with political or religious views.
- Dataset watchpoint: a lawfully acquired dataset can become unlawful if you use it to train a classifier producing those prohibited inferences, even retroactively.
The governance reflex to install
For every AI system handling biometric data or images of persons, require the data science team to issue an inferential purpose sheet explicitly listing the model outputs and showing none falls into the seven categories prohibited by Recital 30. This sheet must be versioned at every retraining, because a fine-tuning step can silently introduce an inferential capability that was not initially planned.
How Luxgap automates this risk
Our Luxgap Prohibited Inference Sentinel makes it impossible to silently deploy a model that infers prohibited categories under Article 5. The tool plugs a specialised LLM agent into your MLflow registries, private Hugging Face Hub, Azure ML and Vertex AI, reads the model cards, training notebooks and output schemas, then automatically detects any model whose predicted classes overlap with the seven categories prohibited by Recital 30.
- Continuously scans your model registries and flags any classifier whose labels contain terms correlated with political, religious, trade union, racial or sexual categories.
- Analyses referenced training datasets and alerts when a lawfully acquired biometric dataset is reused for a prohibited inferential purpose.
- Generates a preloaded inferential purpose sheet for each model, ready for AI officer sign-off and archiving in your Article 6 AI Act register.
- Produces a cryptographically signed, timestamped PDF report, enforceable during an EU AI Office or CNPD audit, demonstrating the absence of prohibited AI practices.
- Pushes instant Teams or Slack alerts when a new commit in a training notebook introduces a sensitive output class.
Available as a complement to a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will run a demonstration on your actual model registry, with a free 48h blind audit to measure your exposure before any commitment.