The EU AI Act's Ban on Subliminal Manipulation, Explained
9 min read · updated August 11, 2026
The first prohibition in the AI Act is usually described as a ban on subliminal advertising. That is the least important word in it. The provision turns on a chain of four elements, and the ones that decide real cases are the causation and harm limbs at the end.
What the provision actually says
Article 5(1)(a) of Regulation (EU) 2024/1689, the AI Act, as published in the Official Journal on 12 July 2024 prohibits the placing on the market, putting into service or use of an AI system that deploys subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques, with the objective or the effect of materially distorting the behaviour of a person or group by appreciably impairing their ability to make an informed decision, thereby causing them to take a decision they would not otherwise have taken, in a manner that causes or is reasonably likely to cause that person, another person, or a group, significant harm.
Read it slowly and the sentence is a chain rather than a list. Each link has to hold. A system that uses a manipulative technique and causes no harm is not caught. A system that causes serious harm through a technique that does not impair informed decision-making is not caught by this provision either, though it may well be caught by consumer law, by the Unfair Commercial Practices Directive, or by the high-risk regime.
The four cumulative elements
- A technique of the listed kind. Subliminal and beyond consciousness, or purposefully manipulative, or deceptive. Note the asymmetry: “purposefully” qualifies the manipulative and deceptive branches, not the subliminal one.
- Objective or effect of materially distorting behaviour. Intent is sufficient but not necessary. A provider who did not set out to distort behaviour but whose system does so is inside the element, which is what makes optimisation-driven systems the interesting case.
- By appreciably impairing the ability to make an informed decision. This is the mechanism limb and it is where most ordinary persuasion falls out. Argument, evidence, price and design preference all change decisions without impairing the capacity to make one.
- Causing significant harm, actually or as a reasonably likely consequence. Harm to the person, to another person, or to a group. The Regulation does not define “significant” here, which is one of the genuinely open questions on the provision.
The elements are cumulative. That is not a drafting nicety; it is the whole shape of the prohibition, and it is what most summaries lose when they compress the sentence into “the AI Act bans manipulative AI”.
Subliminal, manipulative, deceptive
Recital 29 gives the technique limb its texture. It contemplates audio, image or video stimuli that a person cannot consciously perceive, and also machine–brain interfaces and other means of circumventing conscious perception. It then broadens outward: the recital is concerned with systems that subvert or impair autonomy, decision-making and free choice, including where the person is not aware of the manipulation at all or, being aware, is unable to control it.
The deceptive branch is the one that has most obviously grown in practical importance since the text was fixed, because a conversational system that persuades a user of a false premise is deceptive in the ordinary sense without anything subliminal about it. Whether a model that produces a confident falsehood without any design intent to deceive engages Article 5(1)(a) is unresolved. The argument for is that “effect” is expressly enough for the distortion limb. The argument against is that “purposefully” attaches to the deceptive technique itself, so an unintended falsehood is not a deceptive technique at all. No court has ruled, and the Commission guidelines on prohibited practices published in February 2025 do not resolve it either.
A worked example
Take a subscription cancellation flow that uses a model to generate a personalised retention message in real time, optimised against a reward signal for retention. Run the chain.
Technique
If the flow simply offers a discount, no listed technique is present. If the model has learned to assert falsely that the user will lose data they will not lose, that is deceptive. If it has learned to generate time pressure that does not exist, that is at least arguably manipulative, and the question of whether it is “purposeful” when it emerged from optimisation rather than from a written instruction is exactly the open question above.
Material distortion by impairing informed decision
A false statement about data loss goes directly to this element: the user cannot make an informed decision about cancelling because the information they are reasoning from is wrong. A discount does not.
Significant harm
This is where the example most likely fails, and it is the point of running it. A user who stays subscribed for one more month at ten euros has probably not suffered significant harm. Change the facts — a vulnerable user, a debt product, a cumulative pattern across thousands of users — and the analysis changes. The same technique can sit inside or outside the prohibition depending on the stake.
Where an aggressive retention flow does not meet this test, it is still very likely caught by Directive 2005/29/EC on unfair commercial practices and by the Digital Services Act’s dark pattern rules. “Not prohibited under Article 5” is a long way from “lawful”.
What falls outside
Recital 29 states two exclusions that matter commercially. Common and legitimate commercial practices, advertising among them, that comply with applicable law are not in themselves harmful manipulative practices. And lawful medical practice — psychological treatment, physical rehabilitation — carried out in accordance with applicable law and medical standards, with explicit consent where required, is outside. Neither is a safe harbour with a boundary you can survey; both are directions of travel that a decision-maker will weigh.
The neighbouring prohibition in Article 5(1)(b), on exploiting vulnerabilities, has a lower bar in one specific respect: it has no informed-decision-impairment step. A system aimed at a listed vulnerable group can therefore be caught by (b) on facts that would fail (a).
Dates, penalties and who enforces
Article 113(a) brought Chapters I and II — the definitions and the Article 5 prohibitions — into application on 2 February 2025, eighteen months ahead of the bulk of the Regulation. The prohibitions have therefore been live since that date.
Penalties are the Act’s highest tier. Article 99(3) sets fines for infringement of Article 5 at up to EUR 35,000,000 or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. Those penalty provisions applied from 2 August 2025 under Article 113(b), so there was a six-month window in which the prohibitions bound but the fining regime was not yet applicable — a gap that is now closed. Enforcement runs through national market surveillance authorities designated under Article 70, not through the Commission directly, so the practical answer to “who comes asking” is member-state specific.
For where this prohibition sits relative to the rest of the instrument, see the Act’s four risk tiers and how the penalty tiers are structured.