Skip to content

Predictive Policing and the EU AI Act's Article 5 Ban

9 min read · updated August 11, 2026

“The EU banned predictive policing” is one of the most repeated claims about the AI Act and one of the least accurate. One specific shape of prediction is prohibited. Most of what the phrase normally denotes is permitted, as high-risk, with obligations attached.

How narrow the prohibition actually is

Article 5(1)(d) of Regulation (EU) 2024/1689 prohibits AI systems for making risk assessments of natural persons in order to assess or predict the risk of a natural person committing a criminal offence, based solely on the profiling of a natural person or on assessing their personality traits and characteristics.

Four limiting features are built into that sentence and each one excludes a large category of real systems.

  • Natural persons. The object of the assessment must be an identified or identifiable individual. Not an area, not a time window, not a category of offence.
  • Risk of committing a criminal offence. Forward looking and criminal. Assessing whether someone has already committed an offence is not within it; nor is risk of a non-criminal outcome.
  • Based solely on profiling or personality assessment. The basis of the prediction is the operative limitation, and it is where nearly every real system either falls in or out.
  • An express proviso. The provision states that it does not apply to AI systems used to support the human assessment of the involvement of a person in a criminal activity which is already based on objective and verifiable facts directly linked to a criminal activity.
Not legal advice, and this is a page where the gap between the general rule and a specific deployment is unusually wide. Law enforcement use of AI in the EU is governed simultaneously by the AI Act, by Directive (EU) 2016/680 (the Law Enforcement Directive), by national criminal procedure law and by the Charter. A system outside Article 5(1)(d) can be unlawful on any of the other three. Take advice on the actual deployment.

The word “solely” and the human-support proviso

“Solely” is the hinge. A system that predicts individual offending from demographics, associations, location history and inferred personality is inside. Add one objective, verifiable fact directly linked to a criminal activity — an actual investigative lead — and the argument is that the prediction is no longer based solely on profiling.

That argument is available and it is also obviously capable of abuse. A token fact bolted onto an otherwise pure profiling model would defeat the prohibition entirely, which cannot be the intended reading. The proviso’s own wording pushes back: the human assessment must already be based on objective and verifiable facts directly linked to a criminal activity, and the system must be supporting that assessment rather than generating it. The natural reading is that the facts have to be doing the real work, with the system as an aid.

How much objective evidence is enough, and how a market surveillance authority would test whether a fact was load-bearing or decorative, is unresolved. There is no case law and the Commission’s February 2025 guidelines do not supply a threshold. It is a question that will be answered by enforcement practice, and until it is, a deployment resting entirely on this proviso is resting on an untested reading.

Place-based prediction is not prohibited

This is the distinction that most coverage erases. A system that forecasts where and when offences are likely to occur, and directs patrol resources accordingly, assesses no natural person. It is outside Article 5(1)(d) on the face of the text, because the provision requires risk assessment of a natural person.

The criticisms of place-based prediction — that it reproduces the distribution of past enforcement rather than the distribution of offending, and that concentrated patrolling then generates the data that confirms it — are serious, well documented, and not addressed by this prohibition. They are addressed, if at all, through the high-risk regime and through data protection law.

A caveat on the edge: a geographic system fine-grained enough to identify individuals in practice starts to look like individual assessment however it is described. A predicted hotspot the size of one household is a prediction about the people in it. Whether a decision-maker would look through the framing is untested.

What Annex III point 6 permits instead

Annex III point 6 classifies a set of law enforcement uses as high-risk rather than prohibited. It covers, among others, AI systems intended to be used by or on behalf of law enforcement authorities to assess the risk of a natural person becoming the victim of a criminal offence; as polygraphs or similar tools; to evaluate the reliability of evidence during investigation or prosecution; and to profile natural persons in the course of detection, investigation or prosecution of criminal offences.

Read that list next to the prohibition and the legislative choice is clear. Predicting who will offend, from what they are like, is prohibited. Predicting who will be victimised, evaluating evidence, and profiling in the course of an actual investigation are permitted with the full weight of Chapter III attached: a documented risk management system, data governance, technical documentation, logging, human oversight, conformity assessment, registration in the EU database, and a fundamental rights impact assessment under Article 27 because the deployer is a public body. See the Annex III law enforcement category for what that entails.

The two halves are a long way apart in time, and the gap widened in 2026. The Article 5 prohibitions have applied since 2 February 2025. The high-risk obligations that govern the permitted law enforcement uses were due on 2 August 2026 under Article 113 as adopted, but Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, postponed them to 2 December 2027 for stand-alone Annex III systems. So for the time being, predicting who will offend from what they are like is prohibited outright, while the Annex III point 6 uses are lawful without the Chapter III obligations having yet attached to them. That asymmetry is a feature of the timetable rather than of the policy, and it closes on 2 December 2027.

The presumption of innocence rationale

Recital 42 gives the reasoning, and it explains the exact shape of the provision better than any structural account. Natural persons should be judged on their actual behaviour, and never on AI-predicted behaviour based solely on profiling, personality traits or characteristics such as nationality, place of birth, place of residence, number of children, level of debt or type of car, without a reasonable suspicion of involvement in a criminal activity based on objective verifiable facts and without human assessment thereof.

That is a presumption of innocence argument, not a data quality argument. It is not that the predictions are inaccurate; it is that treating a person adversely on the basis of what people like them tend to do is the thing the presumption exists to prevent. The list of example characteristics in the recital is worth noting for how ordinary it is — debt level and type of car are not exotic inputs, and a model using them to predict offending is squarely what the recital describes.

The same instinct runs through the social scoring prohibition in Article 5(1)(c), and through the tight conditions on real-time remote biometric identification. Infringements of Article 5 sit in the top penalty tier under Article 99(3), up to EUR 35,000,000 or 7% of worldwide annual turnover, though Article 99(1) also leaves member states to set the rules on penalties for public authorities and bodies in their own law.