February 2026
The analysis is based on the AI Act—EU Regulation 2024/1689—and the interpretative guidelines issued by the European Commission concerning the prohibited practices described in Article 5.
W-Moszczynski-PZM-2-2026It is crucial to understand when particular provisions apply. The AI Act as a whole becomes applicable on 2 August 2026, but some parts entered into force earlier. This mainly concerns general provisions and prohibitions, including the prohibited practices in Article 5, which have applied since 2 February 2025. The European Commission’s guidelines confirm this date. At the same time, they emphasize that the guidelines themselves are not legally binding. They are an aid indicating how the provisions should be understood. The final, binding interpretation of the law belongs to the Court of Justice of the European Union. In other words, the Court has the last word on how the AI Act is to be understood and applied.
What does the AI Act say?
Firstly, some things may not be done—the prohibitions in Article 5. Secondly, high-risk systems may be used, but only if specified requirements are met, such as risk management and control of data bias. Thirdly, the AI Act does not replace other European Union law, so consumer-protection and anti-discrimination rules, among others, continue to apply.
The AI Act also identifies where discrimination problems arise. The best example is the prohibition of social scoring—scoring people.
What is this discrimination about?
Under Article 5(1)(c), the AI Act prohibits systems that evaluate or classify people or groups of people over time on the basis of their history of behaviour. Such assessment may be based both on social behaviour and on characteristics that are known, inferred or predicted—for example personality or lifestyle. Such a system is prohibited when it leads to those people being treated worse. This occurs in two situations. The first is when data is used in a context other than that in which it was collected—for example, purchase data used to assess access to another service. The second is when the system’s response is unjustified or disproportionate: too severe in relation to the behaviour, or without rational justification.
The European Commission’s guidelines clarify that the social-scoring prohibition is broad and covers both the public and private sectors, without limitation to a particular industry. They also emphasize that not every form of customer scoring is automatically prohibited. Customer scoring may be used provided it does not meet the conditions described above that lead to unlawful treatment.
The key point is that the guidelines indicate that “personal characteristics” may include sex, race, address, income, economic situation, behaviour, location or manner of movement. Scoring systems based on such characteristics may therefore require analysis under Article 5(1)(c). At the same time, using these characteristics alone is not sufficient to make a system prohibited. It must still be shown that the system leads to adverse treatment either outside the context in which the data was collected or in an unjustified or disproportionate manner.
This is rather enigmatic and difficult to turn into practical conclusions. Suppose an enterprise analyses customers not only from purchase history and preferences, but also from call transcripts from which it infers psychological characteristics such as propensity for risk or manner of making decisions. On this basis, it creates long-term profiles and classifies customers by business value, then differentiates the offer, excluding some customers from more attractive sales conditions. Importantly, this personality analysis is conducted without their knowledge.
From the perspective of Article 5(1)(c), such a practice comes very close to prohibited social scoring. The system evaluates people over time on the basis not only of behaviour but also inferred characteristics, including psychological characteristics. The evaluation then leads to genuinely different treatment because some people are deprived of access to more favourable offers. That effect should be regarded as worse treatment under the regulation.
In addition, data is used in a different context from the original one: conversations conducted for customer service are used to build psychological profiles and make selective business decisions. The system’s response also appears disproportionate because characteristics such as financial caution or decision-making style lead to exclusion from an offer, which is difficult to justify objectively and rationally in the context of selling the product itself.
Consequently, such a system should be regarded as very likely to breach the prohibition in Article 5(1)(c) of the AI Act. This is no longer ordinary personalization, but psychological profiling leading to unjustified and disproportionate differentiation between customers.
Racial discrimination?
A second important prohibition, relevant to characteristics such as skin or eye colour, concerns biometric categorization and follows from Article 5(1)(g). It prohibits systems that use biometric data to assign people to categories in order to infer, for example, race or other sensitive characteristics.
The AI Act explains biometric data as personal data resulting from specific technical processing of a person’s physical, physiological or behavioural characteristics, such as a facial image. It also defines biometric categorization as assigning a person to a category on the basis of biometric data. Examples include sex, age, hair colour and eye colour.
In practice, if a recommendation system can “extract” race, origin or other sensitive characteristics from a facial image or another biometric signal and uses this for profiling, there is an entirely different risk of falling within Article 5(1)(g) than with ordinary marketing segmentation based on data supplied by the user.
If a system is instead classified as high risk, the AI Act does not stop at a one-sentence prohibition of discrimination, but introduces specific obligations concerning design and operation. These include risk management under Article 9 and data-quality and control requirements under Article 10.
Looking for discrimination
Article 10 expressly requires examination of whether data and models contain biases that may lead to discrimination prohibited by EU law. It also requires concrete measures to detect and prevent such biases and limit their effects if they arise.
A recommendation system favouring customers on the basis of fixed characteristics such as sex, race, skin colour, age or place of residence and eliminating others or making benefits harder to access requires further qualification. Specific rules may apply in certain situations, but conduct must always be assessed within those rules, not under one general point.
How should breaches of the AI Act be identified?
The following is a conditional verdict in four variants.
First variant—the hypothesis is most often false: ordinary marketing and e-commerce. In a conventional online shop or loyalty programme, where the system predicts customer attractiveness and grants discounts or benefits on that basis, this is not automatically prohibited by Article 5(1)(c). The Commission’s guidelines expressly provide examples outside the prohibition. A shopping platform may offer additional privileges to users with a strong purchase history and few returns, while other users retain access to the standard returns procedure. The benefits are then justified and proportionate as a reward for specified behaviour.
Similarly, AI-enabled targeted commercial advertising is outside the prohibition when it uses relevant data such as user preferences, complies with other EU law—consumer protection, personal data and digital services—and does not lead to disproportionately adverse treatment. Recommending promotions to customers with a greater propensity to purchase is therefore not in itself prohibited by the AI Act.
Second variant—the hypothesis may be true: the situation changes when social scoring is involved. The hypothesis may be correct if the scoring system meets Article 5(1)(c): in simplified terms, it evaluates people and leads to one of the two prohibited situations described above.
It is easiest to fall within Article 5(1)(c)(i) when data from one context—online activity, social habits, information about origin or social relationships—is used to make decisions in an entirely different, unrelated context such as granting social benefits, employment decisions or access to housing, and this leads to worse treatment. The guidelines give examples where fraud-risk assessment incorporates irrelevant characteristics, such as a spouse’s nationality or ethnic origin, creating an arbitrary selection mechanism unrelated to the purpose.
The Article 5(1)(c)(ii)1 variant concerning unjustified or disproportionate treatment is more evaluative and harder to determine unequivocally. The Commission’s guidelines state that each situation must be analysed individually, case by case.
Third variant—the hypothesis is true because biometric data and sensitive categories are involved: if skin colour, eye colour or sex is obtained through biometric analysis—for example, from a camera image or photograph—and the system uses it to infer race or another sensitive category in Article 5(1)(g),2 the practice may be prohibited biometric categorization.
This is the clearest and most direct basis in the AI Act relevant to skin colour or race, but only where biometric data is used.
Fourth variant—the problem is not Article 5 but the high-risk-system regime: if a recommendation system is not used only for marketing but makes decisions in areas listed in Annex III—recruitment, employment relationships, creditworthiness or pricing/risk in health or life insurance—it may be classified as high risk.
What actions should be taken?
In those cases, the AI Act does not impose a simple prohibition but specific obligations, including implementation of a fundamental-rights risk-management process under Article 9 and examination and limitation of data biases that may cause discrimination prohibited by EU law under Article 10.
The main conclusion of the first part is that, in a typical e-commerce promotion and discount scenario, customer segmentation or classification—even if ethically questionable—does not automatically breach the AI Act. The Act does not contain a simple “prohibition of discrimination in recommendations” at Article 5 level.
Nevertheless, the conduct may breach the AI Act in specified situations: first, where it meets the social-scoring conditions in Article 5(1)(c);3 second, where biometric data is used to infer sensitive characteristics within Article 5(1)(g); and third, where a high-risk system fails to meet the bias-control requirements in Article 10 and risk-management requirements in Article 9, potentially leading to sanctions.
Regarding recommendation systems, discrimination and other EU law, the AI Act expressly states that it applies without prejudice to other legal acts, particularly consumer-protection and product-safety rules. The Commission’s guidelines also emphasize that the AI Act’s provisions, prohibitions and exceptions cannot be used to circumvent obligations under other EU regulations.
This matters for recommendation systems because, even if a practice is not prohibited under Article 5(1)(c), it may remain problematic under other rules. Decisions based on protected characteristics such as race, ethnic origin or sex may be subject to EU anti-discrimination law. The guidelines state expressly that assessment or classification based on protected grounds, or leading to discrimination, will also be governed by EU non-discrimination provisions.
In practice, the AI Act should be understood as a set of specified boundaries and obligations, not the only source of regulation. It draws clear “red lines”—completely prohibited situations such as specified forms of scoring and biometric use under Article 5. For high-risk systems, it imposes a technical and organizational anti-bias approach under Articles 9 and 10. At the same time, it neither replaces other provisions nor provides the only basis for assessing discrimination between a company and a customer.
1 Article 5(1)(c)(ii): systems may not “score” people and, on that basis, treat them worse in an excessive manner or without a sensible reason.
2 Article 5(1)(g): AI may not be used to analyse, for example, a person’s face or other biometric characteristics in order to “guess” sensitive characteristics and classify the person on that basis.
3 Article 5(1)(c): systems may not “score” people and treat them worse on that basis if they do so outside the context or excessively or without sensible justification.
Wojciech Moszczyński
Wojciech Moszczyński—a graduate of the Department of Econometrics and Statistics at Nicolaus Copernicus University in Toruń; a specialist in econometrics, finance, data science and management accounting. He specializes in optimizing production and logistics processes. He conducts research into the development and application of artificial intelligence. For years, he has been involved in popularizing machine learning and data science in business environments.

Dodaj komentarz