AI Tools Banned or Restricted in the EU: What to Know in 2026

“Is this AI tool even legal in the EU?” It is a question European users ask more and more often — and with good reason. The EU AI Act, the world’s first comprehensive artificial intelligence law, is now being applied in phases across all 27 member states. Some AI practices are outright banned, others are heavily restricted, and a few familiar tools have quietly changed or withdrawn features for European users.

This guide explains what the EU AI Act actually prohibits and restricts, what it means for you as an everyday user in 2026, and how to stay on the right side of the rules. A quick note: this is a practical overview, not legal advice — if you are deploying AI in a business, talk to a professional.

The EU AI Act in 30 seconds

Unlike the GDPR, which protects personal data, the AI Act regulates AI systems themselves — based on risk. Picture a pyramid:

  • Unacceptable risk (banned): a small set of AI practices prohibited entirely.
  • High risk (restricted): AI used in sensitive areas like hiring, education and law enforcement must meet strict requirements.
  • Limited risk (transparency duties): chatbots and AI-generated content must be identifiable as AI.
  • Minimal risk (mostly free): spam filters, AI in video games — business as usual.

The law entered into force in August 2024 and applies in stages: the bans on prohibited practices took effect in February 2025, obligations for general-purpose AI models followed in August 2025, and most high-risk requirements apply from August 2026, with full application by 2027. Fines are serious — up to €35 million or 7% of global turnover for the worst violations.

What’s actually prohibited in the EU

Since February 2025, these AI practices are banned outright across the EU:

  • Social scoring: AI systems that rank or classify people based on their behaviour or personal characteristics to grant or deny opportunities — the dystopian “citizen score” scenario.
  • Manipulative AI: systems that use subliminal techniques or exploit vulnerabilities (age, disability, economic situation) to distort behaviour and cause harm.
  • Real-time remote biometric identification in public spaces for law enforcement — with only narrow exceptions for serious crimes and missing persons.
  • Emotion inference at work and in schools: AI that claims to read employees’ or students’ emotions is banned in those settings.
  • Biometric categorisation that sorts people by race, political opinions, religious beliefs or sexual orientation.
  • Predictive policing based solely on profiling or personality traits.
  • Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases.

For most readers the practical takeaway is simple: if an app promises to read emotions from faces in a job interview, score your trustworthiness from your social media, or identify strangers in public — it has no legal place in the EU market.

What’s restricted: high-risk AI systems

A much larger category of AI is not banned but classified as high-risk, meaning providers must ensure data quality, human oversight, documentation and robustness before placing it on the EU market. High-risk areas include:

  • CV screening and hiring tools, worker management systems
  • Educational admissions and exam-scoring AI
  • Credit scoring and insurance pricing
  • Law enforcement, border control and migration tools
  • Safety components in medical devices, vehicles and critical infrastructure

This matters to everyday users because it raises the bar for the AI that judges you: the algorithm filtering your job application or scoring your credit must now be documented, tested and overseen by humans. If you are curious how this interacts with data protection rules, our guide GDPR and AI Tools: What European Users Need to Know covers the privacy side.

Transparency rules that affect everyday tools

Even low-risk AI now carries disclosure duties in the EU. Providers must inform you when you are interacting with AI rather than a human — the chatbot on a customer-service page should say so. AI-generated or manipulated images, audio and video (including deepfakes) must be labelled as machine-generated in a machine-readable way. And general-purpose AI models must publish summaries of their training data and respect EU copyright opt-outs.

You will notice this in practice as small labels and disclosures: “AI-generated”, content credentials on images, and clearer notices in apps. These are not cosmetic — they are legal requirements.

What changed for the big AI models

General-purpose models — the ChatGPT, Gemini and Claude class of systems — face their own tier of obligations since August 2025: technical documentation, training-data summaries, and copyright compliance. The most powerful models, deemed to pose “systemic risk”, face additional duties around safety evaluations and incident reporting. Open-source models get lighter treatment, which is one reason the EU ecosystem of open models continues to thrive.

For users, the visible effects have been subtle but real: some features launch later in the EU than in the US while providers complete compliance work, certain biometric or voice features are limited or age-gated, and privacy controls (like opting out of training) are more prominent for European accounts.

What this means for you as an everyday user

Let’s be concrete. As a private individual using AI tools in the EU in 2026:

  • You are not the regulated party. The AI Act primarily obliges providers and deployers (companies), not people chatting with a bot. You won’t be fined for using ChatGPT.
  • You gain rights and protections: to know when you’re dealing with AI, to have high-stakes AI decisions (hiring, credit) made with human oversight, and to complain to national regulators.
  • Some tools may differ or disappear: if an app’s core feature is a prohibited practice, it cannot legally operate in the EU — you may see it withdraw, geoblock, or redesign for Europe.
  • Workplace AI has limits: your employer cannot deploy emotion-recognition or covert worker-scoring AI. If something feels off, your national AI authority and data protection authority are the places to ask.

Six practical tips to stay on the right side

  • Check before you sign up. Before adopting a new AI tool, verify its GDPR compliance and AI Act posture — our checklist How to Check If an AI Tool Is GDPR-Compliant Before You Sign Up walks you through exactly what to look for.
  • Prefer EU-hosted or transparent providers for sensitive uses like HR, education or health — data residency inside the EU simplifies everything.
  • Look for the disclosures. Legitimate providers now label AI interactions and AI-generated content. Absence of any disclosure is a yellow flag.
  • Don’t use AI to do what the law forbids. Scraping faces to build a recognition database or scoring tenants with a black-box model exposes you — especially as a business — to serious liability.
  • Keep humans in the loop for consequential decisions: hiring, grading, lending. The law expects it, and it’s simply better practice.
  • Watch for updates. The Act is still rolling out through 2027, with codes of practice and guidance evolving. Revisit your tools’ terms yearly.

What to do if a tool stops working in the EU

If a favourite tool suddenly geoblocks a feature or withdraws from Europe, don’t reach for a VPN to circumvent it — that can breach the tool’s terms and, for business uses, the law itself. Instead: check the provider’s EU statement (many publish one), look for an EU-compliant alternative, and if you believe a ban is being wrongly applied to a legitimate tool, you can raise it with your national market surveillance authority. In most cases, though, withdrawal signals the feature was genuinely incompatible with EU rules — and an alternative built for this market is the safer bet.

The bottom line

The EU hasn’t banned AI — it has banned a short list of genuinely harmful uses and put guardrails around the rest. For everyday users, that means more transparency, better privacy controls, and human oversight where it counts. Stay informed, choose compliant tools, and keep an eye on the disclosures: the rules are on your side.

Leave a Comment