Adventure Spirit d.o.o. · Zagreb, Croatia +385 95 504 1496 info@adventurespirit.hr GRC Portal
Home›Knowledge base›Artificial intelligence
Artificial intelligence

Prohibited practices and AI literacy: two provisions already in force

While the debate runs on high-risk systems, two provisions of the AI Act apply first. One bans certain practices outright, the other requires that the people using these systems know what they are doing.

Daniel Bara, PhD30 June 20266 min read

The AI Act applies in stages. Two groups of provisions arrive first, and both apply to anyone using these systems, not only to those building them.

Prohibited practices

Article 5 lists practices that must not be used, with no risk assessment available and no way to justify them. Among them:

  • Manipulative techniques that materially impair a person's ability to make an informed decision and thereby cause significant harm.
  • Exploiting vulnerabilities arising from age, disability or a social or economic situation.
  • Social scoring leading to detrimental treatment in a context unrelated to the one in which the data was collected.
  • Predicting criminal offences based solely on profiling or personality traits.
  • Untargeted scraping of facial images from the internet or CCTV to build recognition databases.
  • Emotion recognition in the workplace and in education, subject to narrow medical and safety exceptions.
  • Biometric categorisation to infer sensitive attributes about a person.
Where this touches ordinary business

Most of the prohibitions sound remote from an average company until you look at two entries. Emotion recognition in the workplace appears in call analytics tools for contact centres and in employee engagement monitoring. Biometric categorisation appears in video surveillance analytics. Neither is procured under that name.

The AI literacy obligation

Article 4 requires organisations to ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf. The level is set against those people's technical knowledge, experience and education, and against the context in which the systems are used.

The provision is short and deliberately open. It prescribes no hours, no curriculum and no exam. It requires that people understand what the tool does, where it fails, and what must not be done with it.

How to satisfy it without a separate programme

In organisations that already run security awareness training, this is an addition rather than a new project:

  1. An internal usage policy - what may and may not be entered into external tools. This is the shortest path to the largest benefit.
  2. Short role-based training. Someone using a tool to draft text and someone using it in decisions about people do not need the same content.
  3. Concrete failure examples. Fabricated facts presented convincingly, bias in training data, a model's misplaced confidence.
  4. Records. Who completed what and when. Without records the obligation cannot be verified, exactly as with cybersecurity measures.

Overlap with other obligations

The training record produced here simultaneously feeds measure 5 of the Croatian Cybersecurity Regulation, which requires staff awareness. The internal usage policy touches data protection as well, since entering personal data into an external tool is processing with its own lawful basis.

This is the general pattern: the instruments differ, the evidence base is shared.

This text is an informative overview, not legal advice. The precise scope of prohibited practices and the way the literacy obligation applies depend on the specific circumstances and on guidance issued at Union level.

Not sure where you stand?

Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.