
\documentclass[
% twocolumn,
% hf,
]{ceurart}


\sloppy


\usepackage{listings}
\usepackage{tabularx}
\usepackage{minted}

\lstset{breaklines=true}

\providecommand*{\listingautorefname}{Listing}


\begin{document}

\copyrightyear{2025}
\copyrightclause{Copyright for this paper by its authors. Use permitted under Creative
Commons License Attribution 4.0 International (CC BY 4.0).}
\conference{NeXt-generation Data Governance workshop 2025 (NXDG 2025), co-located with SEMANTiCS’25: International Conference on Semantic Systems, September 3–5, 2025, Vienna, Austria}


\title{Semantic Patterns of Prohibited AI Systems in the EU AI Act}


\author[1]{Delaram Golpayegani}[%
orcid=0000-0002-1208-186X,
email=golpayes@tcd.ie,
]
\cormark[1]
%\fnmark[1]
\address[1]{ADAPT Centre, Trinity College Dublin}


\author[1,2]{Harshvardhan J. Pandit}[%
orcid=0000-0002-5068-3714,
email=me@harshp.com,
]
%\fnmark[1]
\address[2]{AI Accountability Lab, Trinity College Dublin}

\author[1]{Dave Lewis}[%
orcid=0000-0002-3503-4644,
email=delewis@tcd.ie,
]
%\fnmark[1]


%% Footnotes
\cortext[1]{Corresponding author.}
%\fntext[1]{These authors contributed equally.}


\begin{abstract}
  The EU AI Act is a landmark piece of legislation that governs deployment and use of AI systems. Within its risk-based regime of regulation, prohibited AI practices face the strictest requirements, being entirely banned to be deployed or used within the Union. The provisions for prohibited systems have been applied since 2 February 2025. While authoritative guidelines have been published for prohibited systems, there is still no systematic approach that facilitates determination of such systems in a simplified and automated manner. To fill this gap, we specify the prohibited AI conditions, articulated in Art. 5, using combination of a minimal set of semantic concepts. We further show how these conditions can be described in a machine-readable format using semantic constraint and rule languages, such as SHACL and N3. 
  This approach to representing prohibited rules supports a more open, interoperable, and transparent implementation of the AI Act, while also enabling partial automation of enforcement processes.
  
\end{abstract}

\begin{keywords}
  EU AI Act \sep
  prohibited AI \sep
  semantic rules \sep
  SHACL \sep
  N3
\end{keywords}


\maketitle

\section{Introduction}

The EU AI Act \cite{eu-ai-act} is the first in the world AI regulation that entered into force on 1 August 2024. Adopting a risk-based approach, the AI Act regulates AI systems according to their potential risks to health, safety, and fundamental rights. Within this risk-based classification, the Act explicitly identifies two categories of AI systems: (1) \textit{prohibited AI practices}, defined in Art. 5, and (2) \textit{high-risk AI system}, specified in Art. 6. In addition, the Act  implies another class of AI systems that impose \textit{transparency} risks in Art. 50. Finally, it refers to \textit{``AI systems other than high-risk''} (Art. 95), which are subject to voluntary compliance with legal obligations and are interpreted as `` minimal risk AI systems''. Within this categorisation, prohibited AI practices face the draconian measure of being entirely banned to be deployed or used within the Union. In case of non-compliance, providers and deployers of such systems face fines up to EUR 35 million or 7 percent of the offender’s total worldwide annual turnover, whichever is higher (Art. 99(3)).

The AI Act outlines eight main categories of prohibited practices in Art. 5. Four of these categories are banned unconditionally, while the remaining four are subject to exceptions. Although the number of conditions is limited, the legal language used to describe them is vague and open to interpretation (see the discussions in~\cite{bermudez2023subliminal, franklin2023strengthening, bulgakova2023prohibited}). To assist with implementation of the Act and as per Art. 96(1b), the Commission published a guideline on prohibited AI practices~\cite{eu_prohibited} in February 2025. While this guideline is a helpful resource to resolve ambiguities, it does not necessarily simplify the critical decision of whether an AI system is prohibited or not. 

Unlike the power of adopting delegated acts for updating Annex III high-risk AI systems (Art. 7), there is no agile mechanisms to amend the list of prohibited AI systems as the AI technology as well as social preferences change. Therefore, any changes to the prohibited conditions requires following the ordinary legislative procedure, which can take several years~\cite{almada2025eu}. Although the frequent changes to prohibited systems might be unlikely, the rapid pace of changes in AI systems requires adaptable approaches that enable ongoing assessment the system's risk level to avoid any non-compliance. Motivated by the EU's initiatives for regulatory simplification~\cite{Karathanasis2025simplification}, in this paper we aim to facilitate identification of prohibited AI systems by determining the \textit{minimal} set of concepts that enable specifying prohibited AI systems in a way that they can be sufficiently distinguished. After conceptualisation of prohibited conditions, we demonstrate how these can be translated into codified machine-readable rules using Semantic Web technologies, particularly the Shapes Constraint Language (SHACL)~\cite{shacl} and Notation 3 (N3)~\cite{n3}. By leveraging Semantic Web technologies, we develop a standards-based, transparent, and interoperable framework for determining prohibited AI conditions, and thereby supporting automation of compliance-related tasks. As will be discussed later, this work builds upon our previous research on determining high-risk AI systems~\cite{golpayegani2023high}, which has gained considerable traction within the community. 
 
\section{Related Work}

Existing studies on the AI Act's prohibited AI practices (Art.~5) are primarily focused on interpreting the prohibited conditions. Some notable analyses were published prior to the publication of the AI Act in official journal of the EU, including  Neuwirth's analysis of prohibited categories stated in the Commission's proposal~\cite{neuwirth2023prohibited}, Bermúdez et al.'s effort to provide a definition for subliminal techniques~\cite{bermudez2023subliminal}, Franklin et al.'s proposed definitions for subliminal, purposefully manipulative, and deceptive techniques~\cite{franklin2023strengthening}, Bulgakova's analysis of the prohibition on the use of subliminal techniques~\cite{bulgakova2023prohibited}, and Leiser's comparative analysis of prohibited uses that deploy manipulative techniques in different mandates of the Act  \cite{leiser2024psychological}. However, the recent publication of the Commission’s guidelines on prohibited AI systems~\cite{eu_prohibited} has addressed several issues previously highlighted in these studies. Since the official publication of the AI Act and the Commission guidelines on prohibited AI, there are only few studies published including Barkane and Buka's critical analysis of the  prohibitions of surveillance and predictive policing~\cite{barkane2025prohibited}. In general, the body of work on the criteria for prohibited systems is mainly focused on clarification of the wording of the Act's text and none of the aforementioned studies, in addition to the Commission's guidelines, establish a \textit{holistic view} of the prohibited categories, nor do they identify the set of concepts of AI use cases that make them prohibited.

In regard to the \textbf{codification} of rules for AI Act's risk categorisation, the \textit{Decision-Tree-based framework}~\cite{hanif2024navigate} is a static framework that aims to assist in classification of AI systems based on the AI Act. The framework is based on a decision tree comprising 20 questions for determining the risk category associated with an AI system. Our pervious work~\cite{golpayegani2023high} identifies 5 concepts to facilitate identification of high-risk AI systems according to Annex III, which are: domain, purpose, AI capability, deployer, AI subject. We further codified the rules using SHACL to enable automated determination of such systems. Given the interest our work on high-risk AI has attracted, in this paper we follow the same approach for prohibited practices.   

 
\section{Methodology}

Identification of classification rules for the AI Act's prohibited AI practices is guided by our contributions in~\cite{golpayegani2023high}. In this previous work, through manual annotation of Annex III of the AI Act, we identified the minimum set of information elements (the 5 aforementioned concepts) required to determine high-risk applications of AI. Building upon these identified information elements, we take the following steps to create a framework for determining prohibited AI practices (see \autoref{sec:<analysis>}):
\begin{enumerate}
    \item Identify the 5 concepts (domain, purpose, AI capability, deployer, AI subject) from each prohibited condition described in Art.~5(1),
    \item Determine whether the 5 concepts are sufficient to describe prohibited AI practices in a unique way that sufficiently distinguish them from each other,
    \item Where the 5 concepts are not sufficient, identify the minimal set of additional concepts needed for describing the prohibited AI condition.
\end{enumerate}

To be able to provide open data specifications for prohibited systems, we add the identified additional concepts (step 3) to the AI Risk Ontology (AIRO)~\cite{golpayegani2022airo}\footnote{\url{https://w3id.org/airo}} and further populate the Vocabulary of AI Risks (VAIR)\footnote{\url{https://w3id.org/vair}} with the instances identified from the annotation process. 

Demonstrating how the prohibited AI rule-checking can be automated for supporting compliance tasks, we utilise existing Semantic Web languages and standards with rule-checking capabilities. While there are multiple languages and standards offering such capabilities, including the Shapes Constraint Language (SHACL)~\cite{shacl}, the Semantic Web Rule Language (SWRL)~\cite{swrl}, N3 (Notation3) rules~\cite{n3}, and the Shape Expressions (ShEx) language~\cite{shex}, we use SHACL in this work as it is a W3C recommended language. We also use N3 to express rules in a simplified if-then style manner to address the complexity of expressing the rules using SHACL (see \autoref{sec:<codes>}).

\section{Patterns of Prohibited AI Practices under the AI Act} \label{sec:<analysis>}

The analysis Art. 5(1) aims to identify the minimum set of concepts that are adequate to uniquely describe prohibited AI practices. Following the steps outlined above, Art. 5(1) clauses were manually annotated to identify the 5 following concepts: domain, purpose, AI capability, deployer, AI subject. Then, additional concepts were identified in each clause. An example of annotating Art. 5(1a) is shown in \autoref{fig:<ch3-prohibited-annotation>}. The manual annotation was carried out by the lead author and validated through discussions with co-authors.

\begin{figure}[h!]
    \centering
    \fbox{\includegraphics[width=\textwidth]{annotation.png}}
    \caption{Annotation of prohibited AI practice described in Art. 5(1a)}
    \label{fig:<ch3-prohibited-annotation>}
\end{figure}

The annotation exercise revealed that among the 5 previously identified concepts, AI deployer is not a decisive factor in determining prohibited AI systems. Additionally, we identified the following additional concepts: \textbf{\textit{data processed by the system}}, \textbf{\textit{locality of use}}, \textbf{\textit{consequence}}, \textbf{\textit{impact and its severity}}, and \textbf{\textit{impacted stakeholder(s)}}. 
\textbf{\emph{Locality of use}} defines the environment in which the system is used, e.g. work place. \textbf{\emph{Consequence}} refers to the direct immediate effect of using an AI system, whether it leads to harms to individual, groups, and society or not. 
\textbf{\emph{Impact}} refers to the overall ultimate effect of an AI system on \textbf{\emph{impacted stakeholders}}, such as individual, groups, and society. We treat the combination of consequence, impact and its severity, and impacted stakeholder as \textbf{\textit{(harmful)~risk~requirement}} on the basis that these concepts can only be determined through risk assessment. Our analysis shows that among the prohibited conditions in Art. 5(1), points (a), (b), and (c) depend on the results of a risk assessment process that identifies consequences, associated impacts, their severity, and the stakeholders affected.  


The minimal set concepts for determining prohibited AI systems are expressed in a form of questions in the following:

% AS PER THE GUIDELINES -- point 11, The practices prohibited by Art. 5 AI Act relate to the placing on the market, the putting into service, or the use of specific AI systems.5 As regards real-time remote biometric identification (‘RBI’) systems, the prohibition in Art. 5(1)(h) AI Act only applies to their use. -- so based on this each of these: placing on the market, putting into service and use of AI might have an effect. 

\begin{enumerate}
    \item In which \textbf{\emph{domain}} is the AI system used?
    \item What is the \textbf{\emph{purpose}} of using the AI system?
    \item What is the \textbf{\emph{capability}} of the AI system?
    %\item What is the \att{\textbf{\emph{underlying cognitive technique} }}employed by the AI system? 
    \item What \textbf{\emph{data}} is processed by the AI system?
    \item Who is the \textbf{\emph{AI subject}}?
    \item What is the \textbf{\emph{locality of use}}?
    \item what is the \textbf{\emph{harmful risk}} caused by the AI system?
    \begin{enumerate}
    \item What is the \textbf{\emph{consequence}} of using the system? 
    \item What is the \textbf{\emph{impact}} of using the AI system?
    \item{What is the \textbf{\emph{severity} of the impact}?}
    \item Who is the \textbf{\emph{impacted stakeholder}}?
    \end{enumerate}
    
  
\end{enumerate}

These concepts and their relations are modelled in our previously developed ontology for AI risks, AIRO, and are illustrated in \autoref{fig:<prohibited concepts>}. As shown in the figure, concepts from the Data Privacy Vocabulary (DPV)~\cite{pandit2024dpv} are reused for expressing the data processed by the system.


\begin{figure}
    \centering
    \fbox{\includegraphics[width=\linewidth]{concepts.png}}
    \caption{Semantic model of concepts (from AIRO) required for determining prohibited AI systems as per Art. 5(1)}
    \label{fig:<prohibited concepts>}
\end{figure}

The detailed analysis of the prohibited conditions is presented in \autoref{<appendix>} and a summary of the conditions is illustrated in \autoref{fig:<prohibited-summary>}. It should be noted that in our analysis of  Art. 5(1) points (a) and (b), we consider \emph{materially distorting behaviour} as a consequence rather that purpose of the system, even though the wording of the AI Act suggests that it can be either an \textit{objective} or an \textit{effect} of employing the AI system. This interpretation is based on the reality that AI providers rarely, if ever, explicitly state that their system's purpose is ``behaviour distortion'' or ``impairing decision making''. Further, in development of emerging technologies such effects of AI  are often identified after deployment as (unintended) consequences.

\begin{figure}[h]
    \centering
    \fbox{\includegraphics[width=\textwidth]{prohibited_summary.png}}
    \caption{Patterns of prohibited AI practices}
    \label{fig:<prohibited-summary>}
\end{figure}



 
\newpage

\section{Codified Rules for Determining Prohibited AI Practices} \label{sec:<codes>}


In our framework, prior to rule-checking, an RDF-based specification of an AI systems should be created to enable determination of its risk category.  In Listing \ref{lst:<rdf_usecase>}, machine-readable specification of an AI chatbot that impersonates a friend of a person for scamming, described in the Commission's guideline~\cite{eu_prohibited}, is shown\footnote{This use case, along with additional examples, is available at: \url{https://github.com/DelaramGlp/airo/tree/main/usecase}}.
This specification serves as a \textit{data graph} that can be validated against both \textit{shape graphs}, which describe the rules using SHACL for prohibited AI systems, and \textit{N3 rules}. 

\begin{listing}[!]
    \begin{minted}[
    frame=single,
    framesep=1mm,
    baselinestretch=1,
    fontsize=\footnotesize,
    linenos
]{Turtle}
@prefix rdf: <http://www.w3.org/1999/02/22-rdf-syntax-ns#> .
@prefix airo: <https://w3id.org/airo#> .
@prefix vair: <https://w3id.org/vair#> .
@prefix dpv: <https://w3id.org/dpv#> .
@prefix ex: <https://example.com/> .
@prefix risk: <https://w3id.org/dpv/risk#>.

ex:ai_chatbot a airo:AISystem ;
    airo:hasPurpose ex:engage_in_human_like_conversation ;
    airo:hasCapability ex:impersonation ;
    airo:hasAISubject ex:chatbot_user ;
    airo:hasRisk ex:risk_of_fraud;
    dpv:hasProcessing ex:processing_conversation .

ex:engage_human_like_conversation a airo:Purpose .

ex:impersonation a airo:Capability , vair:DeceptiveTechnique .

ex:chatbot_user a airo:AISubject, dpv:DataSubject, vair:NaturalPerson .

ex:processing_conversation a dpv:Processing ;
    dpv:hasData ex:voice .

ex:voice a dpv:PersonalData .    

ex:risk_of_fraud a airo:Risk ;
    airo:hasConsequence ex:victim_tricked_into_transfering_money .

ex:victim_tricked_into_transfering_money a airo:Consequence, vair:ImpairedDecisionMaking ;
    airo:hasImpact ex:financial_loss .

ex:financial_loss a airo:Impact, vair:Harm ;
    airo:hasSeverity risk:ExtremelyHighSeverity ;
    airo:hasImpactOnStakeholder ex:chatbot_user .
    
    \end{minted}
    \caption{RDF-based specification of the AI chatbot example}
    \label{lst:<rdf_usecase>}
\end{listing}

To show how SHACL can be used for describing prohibited rules, we provide an example of a shape graph specifying Art. 5(1a) condition in \autoref{listing:<shacl-51a>}. As it is clear in the listing, the shape graph is expressed as negation of the condition using \texttt{sh:not}. This is due to the fact that SHACL's validation report (\texttt{sh:ValidationResult}) is only generated in case of non-conformance. We used the validation report to enhance transparency by providing guiding information about the clause based on the which the system is determined to be prohibited. The SHACL shapes for prohibited AI systems are published on GitHub\footnote{\url{https://github.com/DelaramGlp/airo/tree/main/prohibited-shacl}} under permissive licences.



\begin{listing}[!]
    \begin{minted}[
    frame=single,
    framesep=1mm,
    baselinestretch=1,
    fontsize=\footnotesize,
    breaklines,
    linenos
]{Turtle}
@prefix rdf: <http://www.w3.org/1999/02/22-rdf-syntax-ns#> .
@prefix rdfs: <http://www.w3.org/2000/01/rdf-schema#> .
@prefix sh: <http://www.w3.org/ns/shacl#> .
@prefix airo: <https://w3id.org/airo#> .
@prefix vair: <https://w3id.org/vair#> .
@prefix terms: <http://purl.org/dc/terms/> .
@prefix ex: <https://example.com/ns#> .
@prefix risk: <https://w3id.org/dpv/risk#>.
ex:Art5-1-a
    a sh:NodeShape ;
    sh:targetClass airo:AISystem ;
    sh:message "Prohibited as per AI Act, Art. 5(1a): AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques, with the objective, or the effect of materially distorting the behaviour of a person or a group of persons by appreciably impairing their ability to make an informed decision, thereby causing them to take a decision that they would not have otherwise taken in a manner that causes or is reasonably likely to cause that person, another person or group of persons significant harm"@en ;
    sh:description "AI systems that AI system that deploys subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques"@en ;
    sh:not [
        sh:and (    
                sh:property [
                    a sh:PropertyShape ;
                    sh:path airo:hasCapability ;
                    sh:class vair:DeceptiveTechnique ; ]
                sh:property [
                    a sh:PropertyShape ;
                    sh:path airo:hasAISubject ;
                    sh:or (
                        [ sh:class vair:NaturalPerson ; ]
                        [ sh:class vair:Group; ] )]
                sh:property [
                    a sh:PropertyShape ;
                    sh:path airo:hasRisk ;
                    sh:node [
                        a sh:NodeShape ;
                        sh:targetClass airo:Risk ;
                        sh:property [
                            sh:path  airo:hasConsequence ;
                            sh:class vair:ImpairedDecisionMaking ;
                            sh:node [
                                a sh:NodeShape ; 
                                sh:targetClass airo:Consequence ;
                                sh:property [
                                    sh:path airo:hasImpact ;
                                    sh:class vair:Harm ;
                                    sh:node [
                                        a sh:NodeShape ;
                                        sh:targetClass airo:Impact ;
                                        sh:property [
                                            sh:path  airo:hasSeverity ;
                                            sh:hasValue  risk:ExtremelyHighSeverity ;]  ;
                                        sh:property [
                                            sh:path airo:hasImpactOnStakeholder;
                                            sh:class vair:NaturalPerson ; 
                                            #For brevity, vair:Group is omitted
                                            ]  ] ]]]]])].
        
    \end{minted}
    \caption{SHACL shape for identifying prohibited AI systems from Art. 5(1a)}
    \label{listing:<shacl-51a>}
\end{listing}

\newpage
As shown in the listing expressing the the harm requirement within a SHACL shape graph requires nested \texttt{NodeShape}s which adds to complexity of the shape and further effects its readability and performance. To address this issue, we use N3 to provide more flexible and simplified representation of the rules. \autoref{listing:<n3-51a>} illustrates the encoding of the Art. 5(1a) in N3. For simplicity, the listing is restricted to \texttt{NaturalPerson}s as AI subjects and impacted stakeholders. The N3 rules are made available online\footnote{\url{https://github.com/DelaramGlp/airo/tree/main/prohibited-n3}}.

\begin{listing}[h!]
    \begin{minted}[
    frame=single,
    framesep=1mm,
    baselinestretch=1,
    fontsize=\footnotesize,
    breaklines,
    linenos
]{turtle}
@prefix airo: <https://w3id.org/airo#> .
@prefix vair: <https://w3id.org/vair#> .
@prefix risk: <https://w3id.org/dpv/risk#>.
@prefix ex: <https://example.com/ns#> .

{
   ?system airo:hasCapability ?capability .
   ?capability a vair:DeceptiveTechnique.
   ?system airo:hasAISubject ?subject .
   ?subject a  vair:NaturalPerson .
   ?system airo:hasRisk ?risk .
   ?risk airo:hasConsequence ?consequence .
   ?consequence a vair:ImpairedDecisionMaking .
   ?consequence airo:hasImpact ?impact .
   ?impact a vair:Harm .
   ?impact airo:hasSeverity risk:ExtremelyHighSeverity .
   ?impact airo:hasImpactOnStakeholder ?stakeholder .
   ?stakeholder a vair:NaturalPerson .
    
} => { ?system a ex:prohibited-5-1a . } .
.

\end{minted}
 \caption{N3 rule for identifying prohibited AI systems as per Art. 5(1a) }
    \label{listing:<n3-51a>}

\end{listing}

\newpage
\section{Limitations}

As mentioned earlier, an initial validation of the analysis of prohibited practices, i.e. results of the manual annotation, was conducted. However, further consultation with subject matter experts, including lawyers and policymakers, is required to ensure the validity of our interpretation of the AI Act. Nevertheless, since our proposed framework for determining prohibited practices leverages Semantic Web technologies, it is flexible and can accommodate future enhancements.

In the case of our research, manual annotation of clauses describing prohibited practices was possible given the limited number of these clauses. However, manually annotating a large number of AI use cases to determine their risk level under the AI Act might not be possible. To address this challenge, a combination of Large Language Models (LLMs) and ontologies can provide a scalable solution. However, this requires appropriate measures to avoid hallucinations.


Our proposed framework is designed to support regulatory simplification and automation by adopting an open, standards-based, and interoperable approach. It is important to not that our framework does not substitute legal advice and determining some of the concepts, in particular the risk requirement, require legal interpretation as well as technical analysis. Given the high stakes involved in determining risk levels under the AI Act, our framework should be viewed as a supporting tool to assist in identifying prohibited practices, not as a replacement for legal expertise.


\section{Conclusion and Future Work}

In this paper, we presented a Semantic Web-based framework to assist with determining prohibited AI systems according to the AI Act. This paper followed the approach we took in our previous work for determining high-risk applications~\cite{golpayegani2023high} in terms of both conceptualisation and codification. 
Although these two studies are aligned and complementary, they have not yet integrated to capture the interplay between the two categories. Thus, in our future work, we aim to address this gap by incorporating the exceptions to prohibited systems, given that these exceptions are mostly result in the system being classified as high-risk~\cite{eu_prohibited}. For those AI systems listed in Annex III (high-risk AI systems) but may also meet the prohibited conditions, and therefore be classified as prohibited, a sequential classification wherein determining prohibited AI supersedes high-risk AI may be appropriate. 

 In our future work, we also aim to include the specificities from the Commission's guidelines on prohibited systems~\cite{eu_prohibited} and further populate VAIR, for example with instances of subliminal techniques, including visual subliminal messages, subvisual and subaudible cueing, and misdirections. We also plan to propose these concepts for inclusion within DPV.  


\begin{acknowledgments}
This work has received funding from the European Commission's Horizon Europe Research and Innovation Programme under grant agreement No. 101177579 (FORSEE), the European Union’s Horizon 2020 research and innovation programme under the Marie Skłodowska-Curie grant agreement No. 813497 (PROTECT ITN), and from the ADAPT Centre for Digital Media Technology, which is funded by Research Ireland and is co-funded under the European Regional Development Fund (ERDF) through Grant\#13/RC/2106\_P2. Harshvardhan J. Pandit is a member of AI Accountability Lab, which is funded under John D. and Catherine T.
MacArthur Foundation grant with project \#216001 and award \#19034.
\end{acknowledgments}

\section*{Declaration on The Use of Generative AI}
 
 During the preparation of this work, the first author used OpenAI’s ChatGPT and Anthropic’s Claude for language refinement and Microsoft’s Copilot for code debugging assistance. These tools were used in a limited capacity and lead author reviewed and edited the generated content as needed and takes full responsibility for the publication’s content. 


\bibliography{ref.bib}


\newpage
\appendix

\section{Detailed Analysis of Prohibited AI Practices} \label{<appendix>}
\begin{table}[!h]
    \centering
    \caption{Analysis of prohibited AI practices listed in Art. 5, Points (1a) to (1e)}
    \label{tab:<appendix-prohibited-art5-part1>}
    \footnotesize
    \begin{tabularx}{\textwidth}{|p{0.9cm}|X|}
    \hline
      Art. 5 clause  & Concepts \\
      \hline
      
      (1a) & 1. \textbf{Domain}: Any
      
      2. \textbf{Purpose}: Any
      
      3. \textbf{Capability}: \textit{Subliminal Capability},  \textit{Manipulation}, \textit{Deception} 
      
      4. \textbf{Data processed}:	Any 
      
      5. \textbf{AI subject}: \textit{Natural Person}, \textit{Group of Persons} 
      
      6. \textbf{Locality of use}: Any 
      
      7a. \textbf{Consequence}: \textit{Impaired Decision Making}
      
     7b. \textbf{Impact}: \textit{Harm}
     
     7c. \textbf{Severity of impact}: \textit{Severe}

     7d. \textbf{Impacted stakeholder}: \textit{Natural Person} (self or third-party), \textit{Group of Persons} 
     \\
      \hline
(1b) &
      1. \textbf{Domain}: Any
      
      2. \textbf{Purpose}: Any
      
      3. \textbf{Capability}: \textit{Exploitation Of Vulnerability }
      
      4. \textbf{Data processed}: Any 
      
     5. \textbf{AI subject}:  \textit{Vulnerable Person}, \textit{Vulnerable Groups Of Persons }
      
     6. \textbf{Locality of use}: Any 
      
      7a. \textbf{Consequence}: \textit{Materially Distorting Behaviour}, \textit{Exploiting Vulnerability}
      
      7b. \textbf{Impact}: \textit{Harm}

      7c. \textbf{Severity of impact}: \textit{Severe}

     7d. \textbf{Impacted stakeholder}: \textit{Vulnerable Person} (self or third-party)   
      \\ 
     \hline

    (1c) &
      1. \textbf{Domain}: Any
      
     2. \textbf{Purpose}: \textit{Evaluation Of People}, \textit{Classification Of People}
      
     3. \textbf{Capability}: \textit{Social Scoring}
      
      4. \textbf{Data processed}: \textit{Social Behaviour Data},\textit{Known, Inferred or Predicted Personal Characteristics}, \textit{Known, Inferred or Predicted Personality Characteristics}
      
     5.  \textbf{AI subject}: \textit{Natural Person},  \textit{Group of Persons}
      
     6. \textbf{Locality of use}: Any
      
     7a. \textbf{Consequence}: Any
      
     7b. \textbf{Impact}:  \textit{Discriminatory Treatment}, \textit{Detrimental Treatment}, \textit{Unfavourable Treatment}

      7c. \textbf{Severity of impact}: Any

     7d. \textbf{Impacted stakeholder}: \textit{Natural Person}, \textit{Group of Persons}   
      \\
       \hline
    (1d) &
       1. \textbf{Domain}: Any, 
      
     2. \textbf{Purpose}: \textit{Assessing  Risk of Committing a Criminal Offence},	
       \textit{Predicting Risk of Committing a Criminal Offence}
      
      3. \textbf{Capability}: \textit{Profiling}, 
       \textit{Personality Trait Analysis,} 
       \textit{Personality Characteristics Assessment}
      
      4. \textbf{Data processed}: Any 
      
      5. \textbf{AI subject}: \textit{Natural Person}
      
      6. \textbf{Locality of use}:  Any
      
      7a. \textbf{Consequence}: Any
      
      7b. \textbf{Impact}: Any
      
      7c. \textbf{Severity of impact}: Any

     7d. \textbf{Impacted stakeholder}: Any
      \\
      \hline

      (1e) & 

       1. \textbf{Domain}: Any
      
      2. \textbf{Purpose}: \textit{Creating Facial Recognition Databases}, \textit{Expanding Facial Recognition Databases}
      
      3. \textbf{Capability}: \textit{Web Scraping}
      
      4. \textbf{Data processed}: \textit{Facial Images From The Internet}, \textit{Facial Images From CCTV Footage} 
      
      5. \textbf{AI subject}: \textit{Natural Person}
      
      6. \textbf{Locality of use}:  Any
      
      7a. \textbf{Consequence}: Any
      
      7b. \textbf{Impact}: Any
      
      7c. \textbf{Severity of impact}: Any

     7d. \textbf{Impacted stakeholder}: Any    
      \\
      \hline
      \end{tabularx}
\end{table} 



\begin{table}[!h]
    \centering
    \caption{Analysis of prohibited AI practices listed in Art. 5, Points (1f) to (1h)}
    \label{tab:<appendix-prohibited-art5-part2>}
    \footnotesize
    \begin{tabularx}{\textwidth}{|p{0.9cm}|X|}
    \hline
      Art. 5 clause   &  Concepts \\
    \hline
(1f) & 
    
      1. \textbf{Domain}: \textit{Employment},  \textit{Education}
      
      2. \textbf{Purpose}: Any
      
      3. \textbf{Capability}: \textit{Emotion Recognition}
      
      4. \textbf{Data processed}: Any 
      
      5. \textbf{AI subject}: \textit{Natural Person}
      
      6. \textbf{Locality of use}:  \textit{Workplace}, \textit{Education Institution }
      
      7a. \textbf{Consequence}: Any
      
      7b. \textbf{Impact}: Any
      
      7c. \textbf{Severity of impact}: Any

     7d. \textbf{Impacted stakeholder}: Any  \\
    
    
   \hline
    
    (1g) &
    1. \textbf{Domain}: Any
      
     2. \textbf{Purpose}: \textit{Deduce Sensitive Information}, \textit{Infer Sensitive Information}
      
     3. \textbf{Capability}: \textit{Biometric Categorisation}
      
     4. \textbf{Data processed}:  \textit{Special Category Data}
      
    5.  \textbf{AI subject}: \textit{Natural Person}
      
    6.  \textbf{Locality of use}:  Any
    
      7a. \textbf{Consequence}: Any
      
      7b. \textbf{Impact}: Any
      
      7c. \textbf{Severity of impact}: Any

     7d. \textbf{Impacted stakeholder}: Any  \\
    \hline
    
    (1h) &  

     1. \textbf{Domain}: \textit{Law Enforcement}
      
      2. \textbf{Purpose}: \textit{Remote Identification} 
      
      3. \textbf{Capability}: \textit{Real-Time Remote Biometric Identification}
      
      4. \textbf{Data processed}: \textit{Biometric Data}
      
      5. \textbf{AI subject}: \textit{Natural Person}	
      
      6. \textbf{Locality of use}:  \textit{Publicly Accessible Space}
      
      \textbf{Consequence}: Any
      
     7a. \textbf{Consequence}: Any
      
      7b. \textbf{Impact}: Any
      
      7c. \textbf{Severity of impact}: Any

     7d. \textbf{Impacted stakeholder}: Any  \\
\hline

    
    

    \end{tabularx}
\end{table}   

\end{document}

%%
%% End of file
