Let’s talk
Wondering how this plays out in your organisation? Get in touch — I answer personally.
Short answer
From 2 December 2026 the new AI Act prohibitions cover AI systems that generate or manipulate realistic intimate material of an identifiable person without that person’s consent with the five features required by the provision (Article 5(1), first subparagraph, point (ba)). The second prohibition covers systems that generate or manipulate child sexual abuse material, except where national law provides a ‘without right’ defence (point (bb)). Placing a system on the market or putting it into service is prohibited in two situations, which in practice mainly concerns the provider. The first arises where such generation or manipulation is the intended purpose of the system (paragraph 1a(a)(i)). The second arises where it is a reasonably foreseeable and reproducible outcome without significant technical modification and the system lacks reasonable and adequate safeguards (point (ii)). The safeguards are meant to reliably prevent such an outcome, taking into account reasonably foreseeable misuse. They are also meant to correct observed or reported misuse. A deployer infringes the prohibition only where it uses the system itself for the purpose of generating or manipulating such material (paragraph 1a(b)). A private individual in a personal non-professional activity is not a deployer (Article 3(4)), but the provider of the application they use may still be covered by the prohibition (paragraph 1a(a)).
Why this question arises at all
Regulation (EU) 2026/1744 postponed the application of the requirements for high-risk systems (Article 1, point 40). It also added two new prohibitions to Article 5 (Article 1, point 7). The existing prohibited practices have applied since 2 February 2025, and the new ones apply from 2 December 2026 (Article 113(3), point (a)). Among the reasons for the amendment recital 10 of the amending regulation points to the deployment and widespread use of AI systems generating non-consensual intimate material and child sexual abuse material. Recital 11 adds the proliferation of technologies often described as ‘nudification’ applications.
Article 111 provides no transitional period for the new prohibitions. The transitional provisions on components of large-scale IT systems established by the legal acts listed in Annex X and on high-risk systems apply ‘without prejudice to the application of Article 5’ (Article 111(1) and (2)). In my assessment a feature that is live today therefore needs to be assessed before 2 December 2026.
The question also concerns organisations that offer image, video or audio generation in their own products or that use it. It may be a feature in their own product built on another company’s model, a marketing team’s tool or a platform where customers create content. The prohibition should not prevent providers from developing the technical capabilities of AI systems to generate or manipulate images, videos or audio (recital 12 of Regulation 2026/1744).
The new AI Act prohibitions also cover systems released under free and open-source licences. The exclusion in Article 2(12) does not apply to systems that fall under Article 5. The Regulation also applies to providers placing AI systems on the market or putting them into service in the Union irrespective of where they are established (Article 2(1)(a)).
The Commission’s guidelines on prohibited practices (C(2025) 5052) are dated 29 July 2025. They therefore predate the amending regulation. The Commission updates previously adopted guidelines when deemed necessary (Article 96(2)). Until then the scope of the new prohibitions is set by the wording of Article 5, and recitals 10–16 of Regulation 2026/1744 help to interpret it.
What has to be established before a decision
What the intimate material prohibition covers
The prohibition in point (ba) covers AI systems that generate realistic images, videos, audio or similar material. It concerns material depicting the intimate parts of an identifiable natural person or such a person engaged in sexually explicit activities. The prohibition also covers the manipulation of existing material of this kind.
The prohibition does not apply where the depicted person has consented to that generation or manipulation. The provision requires consent with five features. Being freely given, specific, informed and unambiguous mirrors the definition of consent in Article 4(11) GDPR. The fifth feature is that the consent is explicit.
According to recital 12 of Regulation 2026/1744 the prohibition should be limited to realistic depictions of intimate parts (the recital lists them by way of example) or of sexually explicit activity. Realism refers to depicting the person’s face, voice or body in a credible real-life manner. The realism of the context and an exact match with the person’s appearance or voice do not matter.
Recital 12 also indicates what the prohibition does not cover. This includes, among other things, cartoonish or physically impossible depictions and material that does not depict identifiable natural persons. Realistic partially nude depictions where intimate parts are not revealed and no sexually explicit activity is depicted also fall outside the prohibition.
Nor does the prohibition cover generative applications where intimate parts are not exposed or their exposure is subject to consent with the five features. The recital gives try-on applications and medical applications such as anatomical simulations and mammograms as examples. The recital also states that the prohibition does not preclude exceptional use by medical professionals for the diagnosis and treatment of a person incapable of consent. The provision itself contains no such exception. The recital makes it subject to compliance with applicable medical law and with fundamental rights law, including data protection law. As an example of a situation where a person is incapable of consent the recital gives an emergency situation.
Paragraph 1b narrows the concept of manipulation in the prohibition in point (ba). Altering material in a way that does not increase the exposure of intimate parts or alter the nature of the depicted activities is not manipulation. Recital 12 gives examples of such changes. They are changing the background, adding a text heading and enhancing contrast or brightness. According to that recital any manipulation that increases the level of exposure or alters the nature of the activities falls within the prohibition. This also applies to material that already depicted intimate parts or sexually explicit activity.
What the child sexual abuse material prohibition covers
The prohibition in point (bb) concerns AI systems that generate or manipulate material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU. The amending regulation calls it child sexual abuse material (recital 10). The provision provides no exception based on consent. The provision contains a different exception for situations where a ‘without right’ defence applies under national law. Recital 13 links it to Article 5(1) of that Directive.
Recital 13 gives examples of such situations. They include activities by the authorities under domestic legal powers to conduct criminal proceedings or to prevent crime. The recital also mentions the legitimate use of an AI system in red-teaming and evaluation activities for the purpose of assessing the system’s compliance with the prohibition. The conduct covered by the prohibitions may moreover violate criminal law as well (recital 15). Without an explicit basis in national law a provider should not run tests that may produce material of this category.
When the new AI Act prohibitions cover the provider
A provider is a person or body that develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge (Article 3(3)). Putting into service also includes supplying a system for own use (Article 3(11)). An organisation that builds its own image generation tool on another company’s model may therefore be its provider. The same may apply to a feature built on a third-party model called through an API and to a tool used only by the organisation’s staff. The takeover of the obligations of a high-risk system provider is described in When does an organisation using AI become the provider of a system?.
Article 5(1a)(a) prohibits placing a system on the market and putting it into service in two situations. In practice this mainly concerns the provider. In my assessment the prohibition also covers an importer of a system from a non-EU provider, because the importer also places the system on the market (Article 3(6)).
The first situation arises where generating or manipulating prohibited material is the intended purpose of the system. The second concerns systems intended for something else and requires three conditions to be met at the same time.
- Foreseeable outcome. Such generation or manipulation is a reasonably foreseeable and reproducible outcome of the system. The provision links that outcome to the features of the system, from design and training to user-facing functionalities.
- No significant modification. Achieving that outcome does not require significant technical modification.
- No safeguards. The system does not have reasonable and adequate technical safety measures and other safeguards. These are measures that would reliably prevent such generation or manipulation, taking into account reasonably foreseeable misuse. They are also meant to correct observed or reported misuse.
In the second situation the mere ability of the model to produce prohibited material does not decide the infringement. What decides it is the absence of safeguards when the first two conditions are met. According to recital 12 of Regulation 2026/1744 technical measures and other safeguards ‘could include’ the following solutions.
- data cleaning;
- refusal training;
- safe prompt design and output controls;
- runtime prompt guardrails;
- content classification and filtering mechanisms;
- usage restrictions;
- abuse detection mechanisms;
- notice and action mechanisms.
Recital 12 also states that the measures should be reasonable for the specific system. According to the recital they are considered adequate if they align with the state-of-the-art measures and demonstrably prevent the prohibited generation or sufficiently reduce its likelihood in each specific case. Article 5(1a)(a)(ii), by contrast, requires safeguards that ‘reliably prevent’ the prohibited outcome. Until the Commission issues guidelines it is worth designing safeguards to the standard in the provision and treating the recital as an aid to interpretation.
The AI Act does not define significant technical modification. According to recital 12 the assessment of measures takes into account reasonably foreseeable circumvention of safeguards without significant technical modification. In my assessment a significant modification starts only with interference with the model weights or the system’s code. On that reading a safeguard test reproduces the actions of an ordinary user of the interface. Such a test covers text prompts and their rewording as well as known filter bypass methods. It also covers uploading a photo of an adult who has given consent with the five features to the generation or manipulation of intimate material depicting them.
The test itself calls for care. The Regulation does not apply to research, testing or development activity before a system is placed on the market or put into service (Article 2(8)). Such activity must be conducted in accordance with Union law, and the exclusion does not cover testing in real world conditions. In my assessment a test carried out after the system has been placed on the market or put into service may itself be a use prohibited by paragraph 1a(b). It is safer to start with images of non-existent persons who are clearly adults, because material without identifiable persons falls outside the prohibition in point (ba) (recital 12). Photos of real people for tests under point (ba) should come from adults who have given consent with the five features required by the provision. A test under point (bb) requires a basis in national law (point (bb), recital 13).
The documentation a provider shows the authority can have a simple structure.
- test scenarios and their results, with an assessment of reproducibility;
- a description of the measures in place mapped to the examples in recital 12;
- a log of misuse reports and corrective actions;
- the result of a repeat test after each change of model version.
Article 5(1a)(a) refers to the AI system and its safeguards. An organisation that builds another company’s model into its product may therefore rely on that model’s safeguards. What is assessed, however, is the system placed on the market or put into service under its name together with what the organisation has added to the model. In the contract with the model provider it is worth securing a description of its safeguards, information on known bypasses and advance notice of version changes.
Recital 12 adds that for providers retaining effective control over the system the safeguards could include following and reporting methods for misuse cases. This refers to control exercised for instance through a platform or a web interface. Such monitoring is to be in full compliance with Union privacy and data protection law. In cases of observed or reported circumvention of safeguards adequate corrective measures should be taken, provided they are reasonable. Reasonableness is assessed taking into account the specific system and its release and distribution strategy, such as open-source releases.
A separate indication concerns systems intended to generate or manipulate intimate material of identifiable persons. The safeguards should then include appropriate means for the distribution of the system aimed at enabling the reliable collection and demonstration of the depicted person’s consent in compliance with the GDPR (recital 12). For such a provider a consent record therefore becomes part of the evidence that the system operates outside the prohibition.
When the new AI Act prohibitions cover the deployer
A deployer is a person or body using an AI system under its authority, except where the system is used in the course of a personal non-professional activity (Article 3(4)). Use of a system is prohibited only where the deployer uses it for the purpose of generating or manipulating prohibited material (Article 5(1a)(b)).
Recital 12 sets out the limits of this rule. The prohibition covers use of a system for the purpose of generating or manipulating such material. The recital gives three examples. They are using a system without reasonable and adequate safeguards, circumventing safeguards or using a lawful system for such purposes. The prohibition does not cover using a system for lawful purposes, even where the provider has not put in place the safeguards it should have. Nor does it cover the accidental generation of such content.
For an organisation using generative tools the conclusion is reassuring. A marketing team does not infringe the prohibition merely because its image generator is poorly secured. Staff reports of such content in response to ordinary prompts are, however, a signal that the tool’s safeguards may not meet Article 5(1a)(a). It is then worth reporting this to the provider and considering a change of tool.
The hardest question concerns an employee who uses a work tool to produce prohibited material. In my assessment the Regulation does not settle expressly when this is use by the organisation as deployer and when it is the employee acting on their own account. A pointer is the authority over the system to which Article 3(4) links the deployer role. On that reading the rules on tool use, access control and the organisation’s response to a report will matter.
The rules on using generative tools are worth supplementing with three elements. The first is an explicit ban on producing material covered by Article 5 and on uploading photos of colleagues, customers or other people to generators without a legal basis. The second is a misuse reporting channel. The third is a description of the organisation’s response, including securing data on use of the tool without copying the material itself.
The Regulation does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity (Article 2(10)). A private individual who uses an application generating intimate material without consent is not a deployer (Article 3(4)). The prohibition on use in paragraph 1a(b) therefore does not cover them. This does not exclude liability under other law, including criminal law, where its conditions are met. The provider of such an application may still be covered by the prohibition (paragraph 1a(a)). The prohibitions are also without prejudice to remedies available under national law for individuals to protect their fundamental rights. These include rights to their image, privacy and human dignity (recital 16).
Who infringes the new AI Act prohibitions and from when
| Situation | Covered by the prohibition | Exceptions and limits | From when |
|---|---|---|---|
| Provider of a system whose intended purpose is generating or manipulating prohibited material | yes (Article 5(1a)(a)(i)) | consent of the depicted person in point (ba); ‘without right’ defence under national law in point (bb); in point (ba) a change that does not increase exposure or alter the nature of the activities is not manipulation (paragraph 1b) | 2 December 2026; Article 111 provides no transitional period |
| Provider of a generative system with a different intended purpose | yes, where the prohibited outcome is reasonably foreseeable and reproducible without significant modification and the system lacks reasonable and adequate safeguards that reliably prevent it and correct observed or reported misuse (Article 5(1a)(a)(ii)) | the same exceptions as for an intended-purpose system; the prohibition should not prevent the development of technical capabilities (recital 12) and is limited to requiring reasonable and adequate safeguards (recital 14) | 2 December 2026; Article 111 provides no transitional period |
| Importer of a system from a non-EU provider | in my assessment yes, because it places the system on the market (Article 3(6)) | as for the provider | 2 December 2026 |
| Organisation using a generative tool | only where it itself uses the tool to generate or manipulate prohibited material (Article 5(1a)(b)) | lawful purposes and accidental generation fall outside the prohibition (recital 12) | 2 December 2026 |
| Natural person in a purely personal non-professional activity | no — not a deployer (Article 3(4)), and the Regulation does not apply to the obligations of such persons (Article 2(10)) | the tool’s provider may be covered by the prohibition (paragraph 1a(a)); liability under other law, including criminal law, remains possible | not applicable |
Labelling material does not lift the prohibition
Under Article 50(4) deployers must, as a rule, disclose that deep fake content has been artificially generated or manipulated. Compliance with transparency obligations should not, however, be interpreted as indicating that the use of the system or its output is lawful (recital 137 of Regulation 2024/1689). The Commission refers to this recital in its guidelines on Article 50 and states that a system covered by that Article may fall under the prohibition in Article 5 (paragraph 25). In paragraph 129 it adds that the transparency obligation in Article 50(4), first subparagraph, does not imply that harmful and unlawful deep fakes may be generated and disseminated. The examples given include child sexual abuse material and non-consensual intimate images.
Penalties and the supervisory authority
Non-compliance with the prohibitions in Article 5 is subject to administrative fines of up to EUR 35 000 000 (Article 99(3)). If the offender is an undertaking, the fine may reach 7 % of its total worldwide annual turnover for the preceding financial year. The ceiling is the higher of the two amounts. For SMEs the ceiling is the lower of the two amounts (Article 99(6)).
In Poland fines are imposed by decision of the Commission for the Development and Security of Artificial Intelligence (the AI Commission) as the market surveillance authority (Articles 5 and 104(1) of the Polish Act on artificial intelligence systems). The Act’s provisions on fines enter into force three months after its publication, that is on 28 October 2026 (Article 127, point 2). This happens before the date of the new prohibitions.
What should the board know?
- Does the organisation build or commission an image, video or audio generation feature and put it into service under its own name? If so, it may be the feature’s provider and answer for the effectiveness of its safeguards.
- Who in the organisation is responsible for testing such a feature and for the misuse reporting channel?
- Is the decision to place the feature on the market or put it into service based on test results that can be shown to the authority?
Conclusions and next steps
The new AI Act prohibitions mainly affect providers.
Remember
A provider of a system not intended to generate prohibited material defends itself with reasonable and adequate safeguards whose operation it can demonstrate.
- Identify which of the organisation’s products and tools generate or edit images, video or audio. The inventory should also cover features built on other companies’ models.
- For each of them establish the organisation’s role. Developing a tool and putting it into service under the organisation’s own name, including for own use, may mean the provider role.
- As a provider, check whether the outcome prohibited in point (ba) can be achieved without significant technical modification. Run tests only on images of non-existent persons who are clearly adults or of adults who have given consent with the five features. Do not run tests concerning point (bb) without an explicit basis in national law. Test results and a description of safeguards are worth keeping as evidence.
- As a provider, set up a misuse reporting channel and a correction procedure. For features intended to generate intimate material with consent, build a mechanism for collecting and demonstrating that consent.
- As a deployer, supplement the rules on using generative tools and define how the organisation responds to a report.
- Ask providers of tools and models about their safeguards and how they handle misuse reports.
- Revisit the findings once the Commission updates its guidelines on Article 5.
Related materials
- When does an organisation using AI become the provider of a system? — situations in which an organisation takes on provider obligations.
- What should an AI use register contain? — the inventory from which establishing the role for each tool begins.
- Who is responsible for AI Act transparency obligations? — labelling deep fake content and the division of obligations between provider and deployer.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), consolidated version as at 27 July 2026 — Article 2(1), (8), (10) and (12), Article 3(3), (4), (6) and (11), Article 5(1), (1a) and (1b), Article 50(4), Article 96, Article 99(3) and (6), Article 111 and Article 113 — eur-lex.europa.eu.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council, version published in OJ L of 12 July 2024 — recital 137 — eur-lex.europa.eu.
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 — recitals 10–16 and Article 1, points 7 and 40 — eur-lex.europa.eu.
- Directive 2011/93/EU of the European Parliament and of the Council of 13 December 2011 on combating the sexual abuse and sexual exploitation of children and child pornography — Article 2, points (c) and (e), and Article 5(1) — eur-lex.europa.eu.
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), consolidated version — Article 4(11) — eur-lex.europa.eu.
- Act of 3 July 2026 on artificial intelligence systems, Journal of Laws 2026, item 1003 — Articles 5, 104(1) and 127 (in Polish) — isap.sejm.gov.pl.
- European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689, C(2026) 5054 final of 20 July 2026 — paragraphs 25 and 129 and footnote 8 — digital-strategy.ec.europa.eu.
Establish the organisation’s role for generative tools
The scope of obligations depends on whether the organisation is a provider or a deployer. AI use case review covers establishing the organisation’s role for each generative tool and checking that the use does not fall within prohibited practices.
This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.
Legal status: October 2026.