The Art. 5(1)(ba) and (bb) prohibition — non-consensual intimate content and CSAM
Regulation (EU) 2026/1744 adds two new prohibited practices to Art. 5(1) of the AI Act — point (ba) for non-consensual intimate content and point (bb) for CSAM. They apply from 2 December 2026. The scope is substantially narrowed by the new Art. 5(1a) and 5(1b).
Source documentWhat was introduced
Regulation (EU) 2026/1744 inserts two new points into Art. 5(1) of the AI Act, after the existing point (b):
-
(ba) — placing on the market, putting into service or using an AI system that generates or manipulates realistic images, video, audio or similar material depicting an identifiable natural person's intimate parts, or that person engaged in sexually explicit activities, without their freely given, specific, informed, unambiguous and explicit consent to that generation or manipulation.
-
(bb) — the same, for material or a performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU (child sexual abuse material), except where a "without right" defence applies under national law.
Application date: 2 December 2026
The prohibitions do not apply immediately. Although Regulation 2026/1744 entered into force on 27 July 2026, the new points (ba) and (bb) apply from 2 December 2026, under the amended Art. 113(3)(a).
The scope is narrower than it first appears
Two paragraphs that substantially narrow liability were added alongside the prohibitions — Art. 5(1a) and 5(1b), with the same application date. Without them the prohibition reads, wrongly, as a blanket ban on generative models.
For providers (Art. 5(1a)(a))
A provider is caught only if one of two conditions is met:
- generating or manipulating such material is the system's intended purpose, or
- the design, training, architecture, capabilities or user-facing functionalities make such an outcome a reasonably foreseeable and reproducible outcome, without requiring significant technical modification,
and at the same time the system lacks reasonable and appropriate technical safeguards that reliably prevent that outcome and allow correction of identified or reported misuse.
In other words there is a safe harbour: a provider that has built in effective safeguards (content filtering, refusal training, training-data cleaning, a reporting and correction mechanism) is not caught merely because the model is theoretically capable of producing such an output.
For deployers (Art. 5(1a)(b))
A deployer is caught only if they use the system for the purpose of generating or manipulating such material. Incidental or unintended generation does not trigger the prohibition.
What does not count as manipulation (Art. 5(1b))
Manipulation that does not increase the exposure of the depicted intimate parts and does not change the nature of the depicted sexual activity is not manipulation within the meaning of point (ba).
Recital 47 states explicitly that the prohibition should not prevent providers from developing the technical capabilities as such.
Practical implications
If you build generative image or video systems
- Assess whether such an outcome is reasonably foreseeable and reproducible without significant technical modification of your system.
- Implement and document technical safeguards — the safe harbour turns on how effective they are, not on their existence on paper.
- Set up a mechanism for reporting and correcting identified misuse; Art. 5(1a)(a) expressly requires a corrective component, not only a preventive one.
- The deadline is 2 December 2026.
If you use AI systems (deployer)
The prohibition reaches you only if you use the system for that purpose. Ordinary business use of generative tools is not covered.
Penalties — an unresolved question
Breaches of Art. 5 fall within the highest penalty tier under Art. 99(3) of the AI Act. However, the date from which the new points (ba) and (bb) become enforceable is not expressly stated: Chapter XII (penalties) has applied since 2 August 2025, while the prohibitions themselves apply only from 2 December 2026. Available expert analyses cite conflicting figures for these specific points.
Do not rely on a specific penalty figure without legal advice. Recital 51 further notes that Member States must respect ne bis in idem where the same conduct is also sanctioned under criminal law (Directive 2011/93/EU, Directive (EU) 2024/1385).
Limits of this overview
- A consolidated official text of the AI Act with the amendments incorporated does not yet exist; this is a reconstruction from the source Official Journal texts.
- Quotations are from the English version of Regulation 2026/1744.
Related articles
- Guidelines on prohibited AI practices — the original Art. 5 prohibitions
- Digital Omnibus on AI — Regulation (EU) 2026/1744 — overview of all amendments
Sources
Need compliance documentation?
Generate AI Inventory, Risk Assessment and other documents automatically — tailored to your system.