EU AI Act Article 5 Substance Matrix
What this page is: A clause-by-clause matrix testing whether each of the 11 GenGA providers’ Terms substantively implements the EU AI Act’s Article 5 prohibited-practices categories, independent of whether the provider names the Act. This operationalizes the wiki’s recommended research question: can regulatory alignment be detected by substance-matching, given that explicit citation is nearly absent (2 of ~56 GenGA documents) even where substantive mirroring is confirmed?
The 8 Article 5 Categories
| # | Category | What Article 5 prohibits (plain-English) |
|---|---|---|
| 1 | Subliminal manipulation | Subliminal, manipulative, or deceptive techniques that distort a person’s behavior in a way that causes harm |
| 2 | Exploitation of vulnerabilities | Exploiting a person’s age, disability, or specific social/economic situation to distort their behavior |
| 3 | Social scoring | Evaluating or classifying people based on social behavior or personal traits in ways that lead to detrimental/unfavorable treatment |
| 4 | Predictive policing / criminal risk assessment | Assessing or predicting an individual’s risk of committing a criminal offense based on profiling or personality-trait assessment |
| 5 | Untargeted facial-image scraping | Building facial recognition databases through untargeted scraping of facial images from the internet or CCTV |
| 6 | Emotion recognition (workplace/education) | Inferring emotions in workplace or educational settings |
| 7 | Biometric categorization | Categorizing people via biometric data to infer race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation |
| 8 | Real-time biometric identification | Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes |
The Matrix
Legend: 🟢 Explicit Citation (names the AI Act and invokes the restriction) · 🟡 Substantive Match (clause mirrors the restriction’s substance, no citation) · ⚪ Absent (no such restriction found) · 🟠 Partial/Adjacent (related but not a clean match — see footnote)
| Provider | 1. Subliminal | 2. Vulnerability | 3. Social Scoring | 4. Predictive Policing | 5. Facial Scraping | 6. Emotion Recognition | 7. Biometric Categorization | 8. Real-Time Biometric ID |
|---|---|---|---|---|---|---|---|---|
| ChatGPT | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ |
| Claude.ai | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ |
| DeepSeek | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | 🟠¹ | 🟠¹ | ⚪ |
| Google Generative AI Services | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ |
| Le Chat | ⚪² | ⚪² | ⚪² | ⚪² | ⚪² | ⚪² | ⚪² | ⚪² |
| Llama API | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ |
| Meta AI | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 |
| Microsoft Copilot | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 | 🟡 |
| Perplexity | 🟢³ | 🟢³ | 🟢³ | 🟢³ | 🟢³ | 🟢³ | 🟢³ | 🟢³ |
| Qwen Chat | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ |
| xAI | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ | ⚪ |
¹ DeepSeek (Partial/Adjacent): DeepSeek’s Privacy Policy (2025-12-23 addition) commits that the company “will not extract or mine voiceprint or facial recognition information or other unique biological patterns or characteristics… from the voice inputs or photos you provided.” This is a genuine biometric-data protection commitment, but it is framed as a data-minimization promise about DeepSeek’s own data handling, not a prohibition on what users/deployers may do the way Article 5 frames categories 6 and 7. Marked Partial/Adjacent rather than Substantive Match because the legal object is different (provider’s data practices vs. a usage restriction on AI system deployment).
² Le Chat (Absent for these 8 categories, despite citing the Act elsewhere): Le Chat’s Terms of Service baseline (2025-11-11) contained the single most detailed named EU AI Act citation found anywhere in this dataset — a full “Additional Terms for AI Laws Responsibilities” annex citing Regulation (EU) 2024/1689 by number, the AI Office, GPAI “systemic risk” classification, Article 53.1(b)/53.2 documentation obligations, and a 48-hour Serious Incident reporting duty. This annex was removed in the 2025-12-15 rewrite and has not reappeared. Critically, even at baseline, this annex concerned GPAI systemic-risk obligations (a different part of the Act), not the Article 5 prohibited-practices list — so Le Chat is marked Absent across all 8 columns here, not because it never engaged with the Act, but because the specific provision it cited and later dropped does not map onto any of these 8 categories. See Le_Chat_Terms_of_Service.md.
³ Perplexity (Explicit Citation, blanket/incorporated-by-reference): Perplexity’s Acceptable Use Policy §2.6 bans “any activity or practice that is prohibited or considered ‘high risk’ under the European Union’s AI Act,” with a direct hyperlink to the regulation’s EUR-Lex text (CELEX:32024R1689). This is marked 🟢 across all 8 columns because it is a blanket incorporation-by-reference to the Act’s prohibited/high-risk practices generally, rather than an itemized, category-by-category restatement the way Meta AI’s and Microsoft Copilot’s clauses are. It is the dataset’s clearest instance of citing-without-itemizing, the structural inverse of Meta AI’s/Microsoft Copilot’s itemizing-without-citing. See Perplexity_Acceptable_Use_Policy.md.
Methodology
Documents consulted: For each of the 11 GenGA providers, every captured document type currently in the wiki was checked (Terms of Service, Acceptable Use Policy, Commercial/Developer Terms, Privacy Policy, Data Processor Agreement, Trackers Policy, Brand Guidelines, Imprint, where applicable) — not just Terms of Service, since Article-5-style restrictions can appear in any conduct-governing document (confirmed: Meta AI’s and Perplexity’s matches are in Terms of Service/AUP; Microsoft Copilot’s is in its AUP; DeepSeek’s adjacent finding is in its Privacy Policy).
How matches were determined: A keyword sweep (subliminal, manipulat, exploit.*vulnerab, social scoring, predictive policing, criminal risk, facial recognition, emotion recognition/inference, biometric) was run across every platform page’s existing quoted clause text already in this wiki (not the raw source archive — per CLAUDE.md, this wiki’s own pages are the citable layer), then each hit was read in full context to rule out false positives (e.g., “biometric” appearing only in a generic personal-data-category list, or “exploit” referring to security-vulnerability exploitation rather than exploitation of a vulnerable person).
Definition of “Substantive Match”: A clause counts as a Substantive Match only if it restricts the same conduct Article 5 restricts (an AI system or its users being banned from a specific practice), using language specific enough to plausibly satisfy that category’s intent — not merely adjacent or thematically related language. This is why DeepSeek’s biometric-data-protection commitment is marked Partial/Adjacent rather than a full match: it protects data, but does not prohibit AI-driven biometric categorization or emotion inference as a practice.
Definition of “Explicit Citation”: The document must name the Act by number/title (“Regulation (EU) 2024/1689,” “the AI Act”) or hyperlink directly to its legal text, and the citation must function as an operative restriction (not merely background/informational text).
Analysis
- The core gap is confirmed and is starker than the citation count alone suggests. Only 2 of ~56 GenGA documents cite the AI Act explicitly (Le Chat’s now-removed annex, Perplexity’s AUP) — but neither of those 2 actually itemizes the Article 5 list the way this matrix tracks it. Le Chat’s citation concerned a different Article entirely (GPAI systemic risk) and was withdrawn; Perplexity’s is a blanket reference, not category-specific. The only two providers with confirmed, category-by-category substantive alignment with Article 5 — Meta AI and Microsoft Copilot — cite the Act by name nowhere in their documents. This is the cleanest possible demonstration of “compliance by content, not by citation”: the providers doing the most substantively AI-Act-aligned work are invisible to a citation search, and the providers visible to a citation search are not the ones doing the category-specific work.
- Meta AI and Microsoft Copilot are both 8-for-8 — every category in the matrix is a Substantive Match for both. Their two clauses are independently worded but functionally near-identical restatements of the same statutory list, which is itself notable: this is not one company’s idiosyncratic drafting choice, but a repeatable pattern, suggesting a shared external source (most plausibly the Act’s own text or a shared legal-template/compliance vendor) rather than independent convergent drafting.
- 6 of 11 providers (ChatGPT, Claude.ai, Google Generative AI Services, Llama API, Qwen Chat, xAI) show no engagement with this specific list at all — neither citation nor substance — across every document type currently in this wiki. This does not mean these providers are not AI-Act-compliant in some other way (Article 5 is only one part of the Act, and compliance could exist in documentation not captured by Open Terms Archive’s snapshots), but within this dataset, it means a substance-matching audit would find these 6 providers’ consumer-facing legal text silent on the EU’s specific prohibited-practices categories.
Research Significance
- For regulators: A citation-based compliance sweep (searching provider Terms for “AI Act” or “2024/1689”) would flag only Le Chat and Perplexity — and would miss Meta AI and Microsoft Copilot entirely, the two providers whose actual restrictions most closely track Article 5’s substance. Worse, it would flag Le Chat for a citation that, on inspection, concerns the wrong part of the Act and has since been withdrawn. A substance-matching methodology, of the kind this matrix demonstrates at small scale, would be necessary to detect real alignment.
- For journalists: The gap between Meta AI/Microsoft Copilot’s silent substantive alignment and Le Chat’s loud-then-withdrawn citation is a concrete, reportable contrast — “the providers talking about the AI Act aren’t the ones following its specific list; the ones following the list aren’t talking about it.”
- For future AI Act enforcement: Davidson et al. (2026) document that GenAI providers’ Terms already create “regulatory gray areas” that complicate enforcement and legitimate research access; this matrix extends that concern specifically to prohibited-practices enforcement — if citation and substance are this decoupled, self-disclosure-based monitoring (asking providers to declare compliance) cannot be the primary enforcement mechanism. Pandit et al. (2026)‘s finding that GenAI terms uniformly “discard assurances regarding the quality, availability and appropriateness of the service” reinforces why a regulator cannot rely on a provider’s own framing of its compliance posture. Edwards et al. (2025)‘s “platformisation paradigm” — providers positioning themselves as neutral intermediaries while retaining contractual control — offers a structural explanation for why substantive alignment might be implemented quietly rather than announced: naming a specific binding regulation invites scrutiny of compliance gaps, while substantive mirroring without citation preserves the appearance of voluntary, discretionary house rules.
Limitations
- This matrix covers only Article 5’s 8 prohibited-practices categories — one part of a much larger Act. A provider’s overall AI Act compliance posture cannot be inferred from this matrix alone.
- “Substantive Match” was assessed by this wiki’s own LLM-assigned reading, consistent with every other GenGA judgment in this wiki (see methodology.md), not by a qualified legal review. A genuine compliance audit would require legal expertise this wiki does not claim to provide.
- Coverage is bounded by what Open Terms Archive’s
genai-eusnapshots captured; a provider’s compliance documentation outside these specific document types (e.g., a separate AI Act conformity statement not captured as a Terms/Privacy/AUP document) would not appear here. - Sample size is small (11 providers, 2 clean substantive-match cases) — this matrix demonstrates a methodology and a real, citable finding, not a statistically generalizable claim about the AI industry.
See also: genga_vs_pgav2_comparison.md · related_work.md · Meta_AI_Terms_of_Service.md · Microsoft_Copilot_Acceptable_Use_Policy.md · Perplexity_Acceptable_Use_Policy.md · Le_Chat_Terms_of_Service.md