EU AI Act Prohibited Practices and New Omnibus Ban

Article 5 prohibited practices page covering existing bans and the new NCII and CSAM generation prohibition from the Digital Omnibus on AI.

Legal status. The Digital Omnibus on AI was published in the Official Journal of the EU on July 24, 2026 as Regulation (EU) 2026/1744 and entered into force on July 27, 2026. The deferred dates below are now binding law.
Status last verified:

What the obligation actually requires

The prohibited-practices page is different from the other obligation pages. This is not a normal roadmap item where a company can plan toward a future compliance date. The deadline data says core banned AI practices are already in effect, alongside AI literacy obligations for providers and deployers. It also says the Digital Omnibus on AI adds a new prohibition on AI systems for generating non-consensual intimate imagery and child sexual abuse material.

Operationally, a flagged company should treat this as a stop-and-escalate issue. The immediate work is to identify whether the product, feature, dataset, or customer workflow has been flagged as a possible prohibited-practice issue, then pause risky deployment until counsel and senior product owners have reviewed it. This can include how a system is designed, marketed, configured, and monitored, especially where the system affects people directly or generates covered harmful material.

Who usually triggers it

A consumer app whose product review raises a banned-practice concern is one realistic case. A B2B platform whose customer workflow uses AI in a way the vendor did not expect can also trigger review, because providers and deployers both appear in the deadline data. A generative media tool with weak controls around non-consensual intimate imagery or child sexual abuse material also needs immediate escalation.

The common misunderstanding

The common mistake is asking, “When do we need to comply?” For core prohibited practices, the deadline data already marks the milestone as in effect. Another mistake is treating the new Omnibus prohibition as only a content-moderation issue. If a system is designed, marketed, or configured around generating the covered material, the problem is the product itself, not just the takedown queue.

What to do next

Create a short prohibited-use review for every AI feature that affects people directly or generates intimate or child-safety-related media. Give product teams a clear escalation path. If a flag appears, stop shipping the feature until the business has written down the use case, users, safeguards, and legal review result. AI literacy training should also cover the fact that some AI use cases are not simply “higher risk” but off-limits.

Use the deadline checker View full timeline