Skip to content

The EU AI Act's Social Scoring Ban, and What It Doesn't Cover

9 min read · updated August 11, 2026

If you have read that the AI Act’s social scoring ban only applies to governments, you have read about the 2021 proposal. The adopted Regulation dropped that limitation, and the boundary of the prohibition now sits somewhere else entirely.

Who it binds, and the draft that says otherwise

The Commission’s April 2021 proposal confined its social scoring prohibition to AI systems put into service by or on behalf of public authorities. That qualifier is not in Article 5(1)(c) of Regulation (EU) 2024/1689 as adopted and published in the Official Journal on 12 July 2024. The adopted provision prohibits the placing on the market, putting into service or use of the system without reference to who is doing it, and recital 31 confirms the point in terms, describing social scoring by public or private actors.

This matters because the claim survives in an enormous quantity of secondary material written between 2021 and 2023 and never updated. A private-sector compliance assessment that concluded “not applicable, we are not a public authority” was reasoning from a superseded draft.

Not legal advice, and this is a provision where the difference between a general account and advice on your facts is large. Whether a particular scoring product is inside Article 5(1)(c) turns on the contexts in which its inputs were generated and the contexts in which its outputs are used — facts specific to your system. Article 5 breaches carry the top penalty tier under Article 99(3): up to EUR 35,000,000 or 7% of worldwide annual turnover.

What counts as a social score

The provision describes AI systems for the evaluation or classification of natural persons or groups over a certain period of time, based on their social behaviour or known, inferred or predicted personal or personality characteristics. Three features of that description do work.

  • Over a certain period of time. A single point-in-time assessment is a poor fit. The provision is aimed at accumulated reputation.
  • Social behaviour or personal characteristics. Not transactions, not contractual performance as such, but how a person behaves and what they are like — including inferred and predicted characteristics, which pulls in personality inference from behavioural traces.
  • Natural persons or groups. Group scoring is expressly covered, so scoring a postcode or a cohort rather than an individual is not an escape route.

Note what the trigger does not require: nothing about scale, nothing about a numeric score, nothing about the system being the sole basis of a decision. The gatekeeping happens at the next stage.

The two detriment limbs

The score has to lead to one or both of two outcomes. This is the real boundary of the prohibition and it is why the provision is narrower than its name suggests.

Limb (i): detriment in an unrelated context

Detrimental or unfavourable treatment of persons or groups in social contexts that are unrelated to the contexts in which the data was originally generated or collected. This is a context-transfer test. The wrong being described is data about you in one part of life following you into another — your shopping into your housing, your social connections into your insurance.

Limb (ii): disproportionate detriment

Detrimental or unfavourable treatment that is unjustified or disproportionate to the social behaviour or its gravity. This limb has no context requirement at all. A response within the original context is still caught if the punishment does not fit the conduct.

Only one limb has to be satisfied. An assessment that checks context transfer, finds none, and stops has answered half the question.

Why ordinary credit scoring is not caught here

Recital 31 says the prohibition should not affect lawful evaluation practices carried out for a specific purpose in accordance with Union and national law. A conventional credit assessment fits: it is based on financial history, used for a credit decision, and the context of collection and the context of use are the same one. Limb (i) fails. Whether limb (ii) fails depends on proportionality, and a refusal of credit proportionate to demonstrated credit risk is not the mischief.

None of which makes credit scoring unregulated. Creditworthiness assessment of natural persons is listed as high-risk in Annex III point 5(b), so it carries the full Chapter III obligations — the Article 9 risk management system, Article 10 data governance, conformity assessment, registration. And GDPR Article 22 applies independently to a solely automated credit decision producing legal or similarly significant effects. The AI Act moves such a system from prohibited to heavily regulated, not to unregulated.

The systems that should worry are the ones that reach outside their own context: a tenant screening product that scores social media behaviour, an insurance model that prices on inferred personality, an employment tool that reads conduct in one setting into suitability in another. Each of those is limb (i) on its face.

What is still unresolved

Three questions have no settled answer, and anyone telling you otherwise is guessing.

  • What a “social context” is. The provision turns on whether two contexts are related, and neither the article nor recital 31 defines the unit. Are consumer lending and insurance the same context? Are two products of the same company? The answer decides a large class of cases and there is no authority on it.
  • How “social behaviour” separates from transactional behaviour. Payment history is behaviour and it is social in a loose sense. A reading that swept it in would prohibit practices recital 31 plainly means to preserve, so it must be narrower — but where it stops is untested.
  • Whether platform trust and safety scoring is inside. Ranking or restricting accounts based on accumulated behaviour is evaluation over time leading to unfavourable treatment. The defence is that the context is the same and the treatment proportionate; whether that holds for cross-service enforcement across a group of companies is exactly the unsettled context question above.

What would settle any of these is a preliminary ruling from the Court of Justice under Article 267 TFEU, or a reasoned national enforcement decision. The Commission’s February 2025 guidelines on prohibited practices discuss the provision but are not binding on a court and can be revised.

The prohibitions have applied since 2 February 2025 under Article 113(a), and the corresponding penalty provisions since 2 August 2025 under Article 113(b). Because interpretation here is moving through guidance and national enforcement rather than legislation, re-check the position rather than relying on a reading fixed at the time of writing.