← All pages

EU AI Act Article 5 Substance Matrix

What this page is: A clause-by-clause matrix testing whether each of the 11 GenGA providers’ Terms substantively implements the EU AI Act’s Article 5 prohibited-practices categories, independent of whether the provider names the Act. This operationalizes the wiki’s recommended research question: can regulatory alignment be detected by substance-matching, given that explicit citation is nearly absent (2 of ~56 GenGA documents) even where substantive mirroring is confirmed?


The 8 Article 5 Categories

#CategoryWhat Article 5 prohibits (plain-English)
1Subliminal manipulationSubliminal, manipulative, or deceptive techniques that distort a person’s behavior in a way that causes harm
2Exploitation of vulnerabilitiesExploiting a person’s age, disability, or specific social/economic situation to distort their behavior
3Social scoringEvaluating or classifying people based on social behavior or personal traits in ways that lead to detrimental/unfavorable treatment
4Predictive policing / criminal risk assessmentAssessing or predicting an individual’s risk of committing a criminal offense based on profiling or personality-trait assessment
5Untargeted facial-image scrapingBuilding facial recognition databases through untargeted scraping of facial images from the internet or CCTV
6Emotion recognition (workplace/education)Inferring emotions in workplace or educational settings
7Biometric categorizationCategorizing people via biometric data to infer race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation
8Real-time biometric identificationReal-time remote biometric identification in publicly accessible spaces for law enforcement purposes

The Matrix

Legend: 🟢 Explicit Citation (names the AI Act and invokes the restriction) · 🟡 Substantive Match (clause mirrors the restriction’s substance, no citation) · ⚪ Absent (no such restriction found) · 🟠 Partial/Adjacent (related but not a clean match — see footnote)

Provider1. Subliminal2. Vulnerability3. Social Scoring4. Predictive Policing5. Facial Scraping6. Emotion Recognition7. Biometric Categorization8. Real-Time Biometric ID
ChatGPT
Claude.ai
DeepSeek🟠¹🟠¹
Google Generative AI Services
Le Chat⚪²⚪²⚪²⚪²⚪²⚪²⚪²⚪²
Llama API
Meta AI🟡🟡🟡🟡🟡🟡🟡🟡
Microsoft Copilot🟡🟡🟡🟡🟡🟡🟡🟡
Perplexity🟢³🟢³🟢³🟢³🟢³🟢³🟢³🟢³
Qwen Chat
xAI

¹ DeepSeek (Partial/Adjacent): DeepSeek’s Privacy Policy (2025-12-23 addition) commits that the company “will not extract or mine voiceprint or facial recognition information or other unique biological patterns or characteristics… from the voice inputs or photos you provided.” This is a genuine biometric-data protection commitment, but it is framed as a data-minimization promise about DeepSeek’s own data handling, not a prohibition on what users/deployers may do the way Article 5 frames categories 6 and 7. Marked Partial/Adjacent rather than Substantive Match because the legal object is different (provider’s data practices vs. a usage restriction on AI system deployment).

² Le Chat (Absent for these 8 categories, despite citing the Act elsewhere): Le Chat’s Terms of Service baseline (2025-11-11) contained the single most detailed named EU AI Act citation found anywhere in this dataset — a full “Additional Terms for AI Laws Responsibilities” annex citing Regulation (EU) 2024/1689 by number, the AI Office, GPAI “systemic risk” classification, Article 53.1(b)/53.2 documentation obligations, and a 48-hour Serious Incident reporting duty. This annex was removed in the 2025-12-15 rewrite and has not reappeared. Critically, even at baseline, this annex concerned GPAI systemic-risk obligations (a different part of the Act), not the Article 5 prohibited-practices list — so Le Chat is marked Absent across all 8 columns here, not because it never engaged with the Act, but because the specific provision it cited and later dropped does not map onto any of these 8 categories. See Le_Chat_Terms_of_Service.md.

³ Perplexity (Explicit Citation, blanket/incorporated-by-reference): Perplexity’s Acceptable Use Policy §2.6 bans “any activity or practice that is prohibited or considered ‘high risk’ under the European Union’s AI Act,” with a direct hyperlink to the regulation’s EUR-Lex text (CELEX:32024R1689). This is marked 🟢 across all 8 columns because it is a blanket incorporation-by-reference to the Act’s prohibited/high-risk practices generally, rather than an itemized, category-by-category restatement the way Meta AI’s and Microsoft Copilot’s clauses are. It is the dataset’s clearest instance of citing-without-itemizing, the structural inverse of Meta AI’s/Microsoft Copilot’s itemizing-without-citing. See Perplexity_Acceptable_Use_Policy.md.


Methodology

Documents consulted: For each of the 11 GenGA providers, every captured document type currently in the wiki was checked (Terms of Service, Acceptable Use Policy, Commercial/Developer Terms, Privacy Policy, Data Processor Agreement, Trackers Policy, Brand Guidelines, Imprint, where applicable) — not just Terms of Service, since Article-5-style restrictions can appear in any conduct-governing document (confirmed: Meta AI’s and Perplexity’s matches are in Terms of Service/AUP; Microsoft Copilot’s is in its AUP; DeepSeek’s adjacent finding is in its Privacy Policy).

How matches were determined: A keyword sweep (subliminal, manipulat, exploit.*vulnerab, social scoring, predictive policing, criminal risk, facial recognition, emotion recognition/inference, biometric) was run across every platform page’s existing quoted clause text already in this wiki (not the raw source archive — per CLAUDE.md, this wiki’s own pages are the citable layer), then each hit was read in full context to rule out false positives (e.g., “biometric” appearing only in a generic personal-data-category list, or “exploit” referring to security-vulnerability exploitation rather than exploitation of a vulnerable person).

Definition of “Substantive Match”: A clause counts as a Substantive Match only if it restricts the same conduct Article 5 restricts (an AI system or its users being banned from a specific practice), using language specific enough to plausibly satisfy that category’s intent — not merely adjacent or thematically related language. This is why DeepSeek’s biometric-data-protection commitment is marked Partial/Adjacent rather than a full match: it protects data, but does not prohibit AI-driven biometric categorization or emotion inference as a practice.

Definition of “Explicit Citation”: The document must name the Act by number/title (“Regulation (EU) 2024/1689,” “the AI Act”) or hyperlink directly to its legal text, and the citation must function as an operative restriction (not merely background/informational text).


Analysis


Research Significance


Limitations


See also: genga_vs_pgav2_comparison.md · related_work.md · Meta_AI_Terms_of_Service.md · Microsoft_Copilot_Acceptable_Use_Policy.md · Perplexity_Acceptable_Use_Policy.md · Le_Chat_Terms_of_Service.md